1. Who is responsible for your data?
For information collected through neoashos.com and related marketing channels, Neo AshOS Software & Solutions is generally the controller/business responsible for determining why and how personal information is processed. For customer-controlled data uploaded into a Neo AshOS SaaS product, the customer may act as the controller/business and Neo AshOS may act as a processor/service provider, depending on the service agreement and applicable law.
2. Information we may collect
- Identity and contact data such as name, business name, email address, phone number, job title and communication details.
- Business and project information you choose to provide when requesting proposals, demos, websites, software, marketing services or consultations.
- Account and authentication data for applicable products.
- Device, browser, IP address, approximate location, log and security information.
- Website interaction data such as pages viewed, referrers, cookies and preference signals.
- Communications, support requests, feedback and documents you voluntarily send to us.
- Transaction, billing and payment-related information handled directly by us or our payment providers, subject to their own terms and privacy notices.
3. Recruitment and job applications
When you apply for a Neo AshOS role, we may process your name, contact details, employment history, software sales experience, CV, portfolio and other information you voluntarily submit. We use this information to evaluate applications, communicate about recruitment, schedule interviews and meet applicable legal or operational requirements. We limit access to recruitment information to people or service providers who need it for hiring operations. Recruitment information is retained only for as long as reasonably necessary for the relevant hiring process and legitimate recordkeeping, subject to applicable law.
Where our recruitment form provider or hosting platform processes an uploaded CV on our behalf, that provider may store the submission and uploaded file under its own technical infrastructure. We take reasonable steps to use appropriate security and data-handling settings for recruitment submissions.
4. Why we process information
- To provide, operate, maintain and secure our websites, services and software.
- To respond to inquiries, proposals, demos and support requests.
- To authenticate users, prevent abuse and protect accounts and systems.
- To process purchases, subscriptions, invoices and commercial administration.
- To send service communications and, where legally permitted, marketing communications.
- To improve products, content, analytics, search visibility and user experience, including aggregate measurement through services such as Google Analytics 4 where applicable.
- To comply with legal obligations, enforce agreements, investigate incidents and protect rights.
5. Lawful bases
Where a law requires a lawful basis, our processing may rely on consent, contract performance, compliance with a legal obligation, legitimate interests, or another lawful basis recognized by the applicable jurisdiction. For EU/EEA and UK users, the applicable lawful basis will be identified according to the processing context; consent will be requested where consent is legally required.
6. Cookies and similar technologies
We may use essential cookies for security and functionality, preference cookies, analytics technologies and—where lawfully permitted and consent is obtained where required—marketing technologies. See our Cookie Policy for more detail and for preference controls.
7. Sharing and service providers
We may share information with service providers that help us host websites, deliver software, manage communications, process payments, provide analytics, prevent abuse, or provide cloud infrastructure. We do not sell personal information as a general business model. We require vendors to protect information according to contractual and legal requirements appropriate to the service.
8. International transfers
Neo AshOS is a global website and may use infrastructure or vendors located in countries different from where you live. When cross-border transfer rules apply, we seek an appropriate legal mechanism, such as an adequacy decision, contractual safeguards or another legally recognized transfer mechanism. UK/EU users may request information about applicable safeguards where required by law.
9. Data retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, for contractual or support needs, for legitimate business records, or to satisfy legal, accounting, security or dispute-resolution requirements. Retention periods vary by data category and applicable law.
10. Security
We use administrative, technical and organizational safeguards appropriate to the nature and sensitivity of the data, including access control, secure configuration, encryption where appropriate, logging, backups and security monitoring. No internet-based service can guarantee absolute security.
11. Your rights
Depending on your jurisdiction, you may have rights including access, correction, deletion/erasure, restriction, objection, portability, withdrawal of consent, and rights regarding certain automated decision-making or profiling. Requests should be sent to info@neoashos.com. We may need to verify identity before acting on a request.
12. Bangladesh privacy framework
For Bangladesh operations, we take account of the Personal Data Protection Act 2026, the Cyber Security Act 2026 and related rules, notifications and sector-specific requirements to the extent applicable to the relevant processing activity. Bangladesh’s government publishes these laws through the ICT Division.
Official references: ICT Division — Laws.
13. EU/EEA GDPR
Where the GDPR applies, we intend this policy to provide the transparency required for data collection and processing, including purposes, lawful bases, retention, recipients, international transfers and data-subject rights. The rights commonly include access, rectification, erasure, restriction, portability and objection.
Official reference: European Commission — Data Protection.
14. UK GDPR and UK privacy rules
Where UK data-protection law applies, we will provide required privacy information, honor applicable individual rights, and account for UK rules governing cookies and electronic marketing. UK rules changed materially in 2026; this policy should be read together with applicable legislation and regulatory guidance in force at the time.
Official reference: UK ICO — UK GDPR guidance.
15. Brazil LGPD
Where Brazil’s LGPD applies, we support applicable rights and transparency requirements concerning personal-data processing, including access, correction and deletion-related rights and other rights recognized by the law.
Official reference: Brazil Government — LGPD.
16. Canada PIPEDA
Where PIPEDA or another Canadian private-sector privacy law applies, we aim to follow principles concerning accountability, identifying purposes, consent, limiting collection/use/retention, safeguards, openness, access and complaint handling.
Official reference: Office of the Privacy Commissioner of Canada — PIPEDA principles.
17. Children
Our general business services are not directed to children. Where applicable law requires parental consent or special protections, we will apply the relevant requirements.
18. Changes to this policy
We may update this policy to reflect new products, technologies, laws, regulators or business practices. The “Effective” date will change when material updates are published.
19. Contact
Privacy requests and questions: info@neoashos.com. Business contact: Neo AshOS Contact.