Main Principles of Data Protection
Handling personal information requires clear limits. Users should be able to understand what types of data may be involved, why that information is needed and how it may be protected.
The website follows several general principles when dealing with user information:
- Data should be used only for relevant and understandable purposes.
- Collection should be limited to information reasonably needed for a particular function.
- Security should be considered whenever personal or technical information is handled.
- Users should receive clear information about important privacy practices.
- Personal information should not be kept longer than necessary for the relevant purpose.
These principles apply to ordinary website use as well as interactions such as sending a message through a contact form.
No online system can guarantee absolute security. The objective is therefore to use reasonable safeguards while remaining transparent about the limits of digital data protection.
Who This Privacy Policy Applies To
This policy may apply to different people depending on how they interact with the website.
It can cover:
- Visitors who read articles or browse public pages.
- Users of any account-based functions that may be available.
- People who send questions, corrections or other messages through contact channels.
- Visitors whose browsers provide technical information during normal website use.
For readers in Bangladesh, the same policy applies whether they visit from a desktop computer, smartphone or another supported device.
Different features may involve different amounts of information. Someone who simply reads an article may generate mainly technical website data, while a person who submits a contact request may voluntarily provide contact details and the contents of the message.
Information We May Collect From Users
The information involved depends on what the visitor chooses to do and which website functions are available.
Possible categories include contact information, profile or account data, transaction-related details, technical information and records of previous interactions.
| Data category | Examples of information that may be involved |
| Contact information | Name, email address or other details voluntarily provided |
| Account information | Profile details connected with an available account feature |
| Verification information | Data used to confirm identity, age or transaction security |
| Payment records | Amount, date, status, payment method and transaction reference |
| Technical data | IP address, browser, device type and language |
| Interaction history | Messages, page visits or previous requests |
The presence of a category in this policy does not mean that every visitor will be asked to provide all of these details.
Details Provided During Registration
Where registration or profile features are available, users may provide information themselves when creating or updating an account.
The exact details can depend on the function being used. They may include basic identifying or contact information and profile details supplied by the user.
This policy does not assume that any particular field is mandatory unless that requirement is clearly presented during the relevant process.
Users should avoid providing unnecessary sensitive information. Details should be limited to what is reasonably required for the specific interaction.
Information Used for Verification Processes
Some services may need information to confirm identity, age or the security of particular operations.
Verification can help reduce misuse, prevent unauthorised activity and confirm that certain actions are being performed by the appropriate person.
Depending on the circumstances, verification information may be used to:
- Confirm that supplied details are consistent.
- Support age-related checks.
- Review activity where fraud or unauthorised access is suspected.
- Protect transactions or account-related functions.
The type of information required can vary, and users should rely on the instructions provided during the relevant process rather than assuming that the same documents are needed in every situation.
Transaction and Payment Records
Where financial activity is relevant to a service or feature, transaction records may contain details connected with the movement or processing of funds.
Information may include the transaction amount, date, current status, chosen payment method and a transaction or reference identifier.
Such records can be useful for processing an operation, investigating a failed transaction, answering a related request or detecting suspicious activity.
Payment data should be handled carefully. Users should not send passwords, complete payment-card credentials or security codes through ordinary contact messages unless a secure process specifically requires them.
Data Collected Through Website Usage
Some information may be generated automatically when a visitor opens or uses the website.
This can include:
- Device type and operating system.
- Browser type or version.
- IP address.
- Browser or device language.
- Pages opened during a visit.
- Approximate date and time of access.
- Technical events connected with website performance.
Such information can help identify technical problems, understand how the website is used and maintain security.
For example, browser and device information may help determine whether a page is displaying correctly on commonly used mobile devices. Visit records may show that a particular section is difficult to navigate or produces repeated technical errors.
Technical information does not necessarily identify a visitor directly on its own, although some data may still be treated as personal information depending on how it is combined or used.
Purposes Behind Data Processing
Information should have a defined purpose rather than being collected without reason.
Depending on the website function involved, information may be used to support account features, respond to messages, maintain security, investigate misuse or improve the technical performance of the resource.
| Purpose | How information may help |
| Account functionality | Maintain available profile or account features |
| Security | Detect suspicious or unauthorised activity |
| User communication | Respond to questions or editorial requests |
| Technical maintenance | Diagnose errors and improve performance |
| Abuse prevention | Investigate misuse or attempts to disrupt the site |
| Website improvement | Understand which functions need attention |
Information may also be processed where reasonably necessary to protect the website, its users or its technical infrastructure.
The purpose should remain connected with the reason for which the information was originally obtained unless another use is permitted under applicable rules.
Cookies are small pieces of information that websites can store through a visitor’s browser. Similar technologies may perform related functions.
They can be used to remember selected settings, maintain a website session or provide information about how pages function.
For example, a cookie may help preserve a language setting between pages. Another may be used to maintain a session so that the user does not need to repeat the same action during every page request.
Cookies may also support technical analysis. This can help identify slow pages, navigation problems or features that do not behave as expected on certain devices.
Not every cookie has the same purpose or duration. Some may disappear when the browser closes, while others can remain for a longer period.
Visitors can usually control cookies through the privacy or site settings of their browser.
A user may be able to:
- Review stored cookies.
- Delete existing cookies.
- Block cookies from particular websites.
- Restrict certain categories of cookies.
- Configure the browser to ask before storing new cookies.
The exact menu depends on the browser and device being used.
Removing or blocking cookies may affect some website functions. Saved preferences might disappear, a session may end or certain features may no longer operate as expected.
Users in Bangladesh who access the website mainly from a mobile browser can usually find similar controls in the browser’s privacy or site-data settings.
Some website functions can depend on third-party service providers.
Information may therefore be shared where necessary with providers that support functions such as technical hosting, security, payment processing or customer communication.
Sharing should be limited to information relevant to the service being provided.
Possible categories of recipients include:
- Payment or transaction-processing services.
- Hosting and technical infrastructure providers.
- Security and fraud-prevention services.
- Communication or support systems.
- Other providers needed to operate a specific website function.
An external provider may handle information under its own contractual, security or privacy obligations.
The website should not be understood as giving every third party unrestricted access to all user information simply because an external service is used.
Data Disclosure for Legal Reasons
Information may sometimes need to be disclosed where a valid legal requirement applies.
This can include situations involving lawful requests from competent authorities or circumstances in which disclosure is reasonably necessary to protect users, investigate misuse or defend the website and its systems.
Any such disclosure should depend on the circumstances and applicable requirements.
This does not mean that user information is automatically released whenever someone asks for it. A request may need to be assessed before any information is provided.
International Handling of Personal Data
Online services often rely on infrastructure and providers operating across different regions.
As a result, information relating to a user in Bangladesh may sometimes be processed or stored by service providers outside the user’s immediate location.
The exact region can depend on the provider, technical system and service involved.
This policy does not state that information is transferred to a particular country unless that detail has been confirmed.
Where international processing takes place, appropriate safeguards should be considered according to the nature of the information and the rules applicable to the relevant processing.
Data Retention and Security Measures
Information should not be stored indefinitely without a reason.
The appropriate retention period may depend on the type of data, why it was collected, whether an ongoing request exists and whether security, dispute or legal considerations require a record to remain available.
A technical log used for short-term troubleshooting may not need the same retention period as information connected with a transaction or unresolved request.
Reasonable security practices can include measures designed to limit unauthorised access, protect website systems and reduce the risk of improper disclosure or alteration.
However, no website, device, network or storage system can provide a guarantee of complete security.
Users also play a role in protecting information. Strong passwords, careful handling of login details and avoiding suspicious links can reduce unnecessary exposure.
User Rights Regarding Personal Data
Depending on the applicable rules and the circumstances of processing, users may have choices regarding their personal information.
These can include requesting information about stored data, correcting inaccurate details, asking for deletion in certain situations, seeking limits on particular processing or changing consent where processing depends on consent.
The availability of an individual request may depend on the type of information and the reason it is being retained.
Accessing and Correcting Information
Where account or profile controls are available, some information may be reviewed or changed directly by the user.
Other corrections may require a request through an available contact channel.
A request should provide enough information to identify the relevant data without including unnecessary sensitive details.
Verification may sometimes be needed before information is changed, particularly where a request involves account security or personal records.
Requesting Removal of Personal Data
A user may be able to request deletion of personal information in situations where the data is no longer required or where removal is otherwise appropriate under applicable rules.
Deletion is not always immediate or absolute.
Some information may need to remain available for a limited period where necessary for security, dispute handling, fraud prevention or other applicable obligations.
Where full deletion cannot be completed, the relevant limitation may depend on the reason the information must still be retained.
Managing Data Processing Consent
Some forms of processing may depend on user consent.
Where this applies, users may be able to change or withdraw that consent for future processing through available controls or by submitting a request.
Changing consent does not necessarily affect processing that was validly carried out before the change.
For visitors in Bangladesh, privacy choices should be considered together with the actual website function involved. A request relating to this independent informational website should be directed to the website’s own contact channel rather than assumed to be a request to Jaya9 itself. The aim of this policy is to make the handling of user information understandable while keeping collection, use and retention proportionate to the purpose involved.

