ZOAR VC Privacy Policy
On this page
- 1. INTRODUCTION
- PART I — LEGAL AND CONTRACTUAL FRAMEWORK
- 2. APPLICABLE LAW
- 3. RELATIONSHIP WITH OTHER ZOAR TERMS
- 4. PRIVACY POLICY IS NOT A LIMITATION OF ZOAR’S LAWFUL RIGHTS
- PART II — DEFINITIONS
- 5. PERSONAL DATA
- 6. PROCESSING
- 7. SENSITIVE PERSONAL DATA
- PART III — CATEGORIES OF DATA COLLECTED
- 8. IDENTIFICATION INFORMATION
- 9. CONTACT INFORMATION
- 10. ACCOUNT INFORMATION
- 11. TRANSACTION INFORMATION
- 12. PAYMENT AND FINANCIAL INFORMATION
- 13. DELIVERY AND LOGISTICS INFORMATION
- 14. COMMUNICATIONS
- 15. WEBSITE AND DEVICE INFORMATION
- 16. COOKIE AND TRACKING INFORMATION
- PART IV — ENERGY, IOT AND CONNECTED-PRODUCT DATA
- 17. CONNECTED ENERGY PRODUCTS
- 18. TECHNICAL PRODUCT DATA
- 19. ENERGY-USAGE INFORMATION
- 20. REMOTE DIAGNOSTICS
- 21. PRODUCT LOCATION
- PART V — SOURCES OF PERSONAL DATA
- 22. INFORMATION PROVIDED DIRECTLY BY YOU
- 23. INFORMATION FROM THIRD PARTIES
- 24. INFORMATION GENERATED THROUGH USE
- PART VI — LAWFUL BASIS FOR PROCESSING
- 25. ZOAR DOES NOT RELY EXCLUSIVELY UPON CONSENT
- 26. CONTRACTUAL NECESSITY
- 27. LEGITIMATE INTERESTS
- 28. LEGAL OBLIGATIONS
- 29. LEGAL CLAIMS AND DEFENCE
- 30. CONSENT
- 31. WITHDRAWAL OF CONSENT
- PART VII — PURPOSES OF PROCESSING
- 32. ORDER AND CONTRACT ADMINISTRATION
- 33. CUSTOMER SERVICE
- 34. DELIVERY AND LOGISTICS
- 35. WARRANTY AND TECHNICAL CLAIMS
- 36. SAFETY
- 37. FRAUD PREVENTION
- 38. SECURITY
- 39. ANALYTICS
- 40. PRODUCT DEVELOPMENT
- 41. INTERNAL BUSINESS ADMINISTRATION
- PART VIII — MARKETING
- 42. DIRECT MARKETING
- 43. MARKETING PREFERENCES
- 44. TRANSACTIONAL COMMUNICATIONS ARE DISTINCT
- 45. CUSTOMISED MARKETING
- PART IX — PROFILING AND AUTOMATED PROCESSING
- 46. PROFILING
- 47. SIGNIFICANT AUTOMATED DECISIONS
- PART X — DISCLOSURE OF PERSONAL DATA
- 48. ZOAR DOES NOT TREAT ALL DISCLOSURE AS A “SALE”
- 49. SERVICE PROVIDERS
- 50. MANUFACTURERS AND WARRANTY PROVIDERS
- 51. PROFESSIONAL ADVISERS
- 52. GOVERNMENT AND AUTHORITIES
- 53. PROTECTION OF ZOAR
- PART XI — CORPORATE TRANSACTIONS
- 54. BUSINESS TRANSFER
- 55. SUCCESSOR ENTITIES
- PART XII — PROCESSORS
- 56. DATA PROCESSORS
- 57. PROCESSOR CHANGES
- PART XIII — INTERNATIONAL AND CROSS-BORDER PROCESSING
- 58. INTERNATIONAL OPERATIONS
- 59. CROSS-BORDER TRANSFERS
- 60. SAFEGUARDS
- 61. FOREIGN LEGAL ENVIRONMENTS
- PART XIV — DATA RETENTION
- 62. RETENTION PRINCIPLE
- 63. RETENTION FACTORS
- 64. LONG-LIFE ENERGY PRODUCTS
- 65. LEGAL HOLDS
- 66. ANONYMISED DATA
- PART XV — DATA SECURITY
- 67. REASONABLE SECURITY MEASURES
- 68. POSSIBLE SECURITY CONTROLS
- 69. NO ABSOLUTE SECURITY GUARANTEE
- 70. CUSTOMER SECURITY RESPONSIBILITY
- PART XVI — PERSONAL DATA BREACH
- 71. INCIDENT RESPONSE
- 72. REGULATORY NOTIFICATION
- 73. CUSTOMER COOPERATION
- PART XVII — DATA SUBJECT RIGHTS
- 74. STATUTORY RIGHTS
- 75. RIGHTS ARE SUBJECT TO LEGAL CONDITIONS
- 76. ACCESS REQUESTS
- 77. CORRECTION
- 78. COMPLETION
- 79. ERASURE
- 80. EXAMPLES OF INFORMATION ZOAR MAY LAWFULLY RETAIN
- 81. DATA PORTABILITY
- 82. OBJECTION
- 83. WITHDRAWAL OF CONSENT
- PART XVIII — EXERCISING DATA RIGHTS
- 84. REQUEST PROCEDURE
- 85. IDENTITY VERIFICATION
- 86. FRAUDULENT OR UNVERIFIED REQUESTS
- 87. REQUEST SCOPE
- 88. EXCESSIVE OR REPETITIVE REQUESTS
- PART XIX — CHILDREN AND PERSONS UNABLE TO PROVIDE VALID CONSENT
- 89. NOT DIRECTED TO CHILDREN
- 90. CHILDREN’S DATA
- 91. PERSONS LACKING LEGAL CAPACITY
- PART XX — THIRD-PARTY WEBSITES AND SERVICES
- 92. EXTERNAL SERVICES
- 93. INDEPENDENT PRIVACY PRACTICES
- PART XXI — SOCIAL MEDIA
- 94. SOCIAL-MEDIA INTERACTIONS
- 95. PLATFORM PROCESSING
- PART XXII — CCTV AND PHYSICAL SECURITY
- 96. CCTV
- 97. CCTV RETENTION
- PART XXIII — CALL RECORDING
- 98. CALLS AND SUPPORT QUALITY
- PART XXIV — AGGREGATED AND DE-IDENTIFIED INFORMATION
- 99. AGGREGATED INFORMATION
- 100. DE-IDENTIFICATION
- 101. ENERGY RESEARCH
- PART XXV — AI, MACHINE LEARNING AND ADVANCED ANALYTICS
- 102. ADVANCED TECHNOLOGY
- 103. LEGAL SAFEGUARDS
- PART XXVI — COMMERCIAL RECORDS AND EVIDENCE
- 104. TRANSACTION EVIDENCE
- 105. DISPUTE EVIDENCE
- PART XXVII — FRAUD AND ABUSE RECORDS
- 106. FRAUD-PREVENTION DATABASES
- 107. DECISIONS BASED UPON FRAUD RISK
- PART XXVIII — DATA ACCURACY
- 108. CUSTOMER RESPONSIBILITY
- 109. CONSEQUENCES OF INCORRECT INFORMATION
- PART XXIX — DATA MINIMISATION
- 110. PROPORTIONAL PROCESSING
- PART XXX — PRIVACY BY DESIGN AND SECURITY GOVERNANCE
- 111. SYSTEM DESIGN
- 112. ACCESS CONTROL
- PART XXXI — CHIEF DATA OFFICER OR RESPONSIBLE CONTACT
- 113. DESIGNATION WHERE REQUIRED
- 114. PRIVACY CONTACT
- PART XXXII — REGULATORY COOPERATION
- 115. REGULATORY AUTHORITY
- 116. DISCLOSURE TO AUTHORITIES
- PART XXXIII — CUSTOMER COMPLAINTS
- 117. PRIVACY COMPLAINT
- 118. INVESTIGATION
- 119. STATUTORY REMEDIES
- PART XXXIV — NO REPRESENTATION OF PERFECT PRIVACY
- 120. LIMITATION OF TECHNOLOGICAL CERTAINTY
- 121. THIRD-PARTY INCIDENTS
- PART XXXV — CUSTOMER DUTY TO MITIGATE
- 122. NOTIFICATION OF SECURITY ISSUES
- 123. CUSTOMER NEGLIGENCE
- PART XXXVI — CORPORATE GROUP AND FUTURE BUSINESS DEVELOPMENT
- 124. FUTURE BUSINESS STRUCTURE
- 125. INTERNAL USE ACROSS ZOAR OPERATIONS
- PART XXXVII — CHANGE OF CONTROL
- 126. PRIVACY POLICY FOLLOWING SUCCESSION
- PART XXXVIII — POLICY CHANGES
- 127. AMENDMENT
- 128. MATERIAL CHANGES
- 129. CURRENT VERSION
- PART XXXIX — FUTURE TECHNOLOGIES
- 130. FUTURE-PROOF APPLICATION
- 131. SUPPLEMENTARY PRIVACY NOTICES
- PART XL — INTERPRETATION
- 132. NON-EXHAUSTIVE LANGUAGE
- 133. BUSINESS PURPOSE
- PART XLI — SEVERABILITY
- 134. SEVERABILITY
- PART XLII — NO WAIVER
- 135. NO WAIVER
- PART XLIII — MANDATORY LAW SAVING CLAUSE
- 136. STATUTORY OVERRIDE LIMITED TO NECESSARY EXTENT
- PART XLIV — GOVERNING LAW
- 137. GOVERNING LAW
- PRIVACY ACKNOWLEDGEMENT
- RECOMMENDED ACCOUNT / CHECKOUT PRIVACY NOTICE
- RECOMMENDED OPTIONAL MARKETING CONSENT
- RECOMMENDED CONNECTED-PRODUCT NOTICE
- RECOMMENDED WARRANTY / DIAGNOSTIC CONSENT WHERE REQUIRED
ZOAR VC
Privacy, Personal Data Processing and Information Governance Policy
Effective Date: 1 September 2026
Last Revised: 3 September 2026
ZOAR VC / ZOAR Ventures
15A, 55B, Purana Paltan, Dhaka
Email: info@zoarventures.com
Phone: +8801705358035
1. INTRODUCTION
1.1. This Privacy, Personal Data Processing and Information Governance Policy (“Privacy Policy”) explains how ZOAR VC collects, receives, records, stores, organises, uses, analyses, combines, transfers, discloses, retains, protects and otherwise processes Personal Data in connection with its present and future commercial activities.
1.2. References in this Privacy Policy to “ZOAR VC”, “ZOAR”, “we”, “us”, “our” or the “Company” shall mean ZOAR Ventures and, where applicable, any business unit, division, successor, affiliate, authorised operator or commercial undertaking operating under or in connection with the ZOAR VC brand.
1.3. References to “you”, “your”, “Customer”, “User” or “Data Subject” shall refer to the natural person to whom the relevant Personal Data relates.
1.4. This Privacy Policy shall apply to Personal Data processed through or in connection with:
- ZOAR websites and online stores
- Customer accounts
- Product enquiries
- quotations
- orders and transactions
- Campaigns and Pre-Orders
- delivery and logistics
- installation and commissioning
- warranties
- technical support
- connected Products
- energy monitoring
- mobile or web applications
- customer-service communications
- promotional activities
- physical locations
- commercial and project relationships
- supplier and partner relationships
- fraud-prevention systems
- any future ZOAR Product, platform, service, technology or commercial channel.
PART I — LEGAL AND CONTRACTUAL FRAMEWORK
2. APPLICABLE LAW
2.1. This Privacy Policy shall be governed by the privacy, data-protection, cybersecurity, digital-commerce and other applicable laws and regulations of Bangladesh in force from time to time.
2.2. Without limiting the generality of the foregoing, ZOAR intends to administer Personal Data in accordance with applicable provisions of the Personal Data Protection Act, 2026 and other legally applicable data-governance requirements.
2.3. Where any mandatory law confers upon a Data Subject a right which cannot lawfully be excluded, nothing in this Privacy Policy shall be construed as excluding such right.
3. RELATIONSHIP WITH OTHER ZOAR TERMS
This Privacy Policy shall be read together with the applicable:
- ZOAR VC Master Terms and Conditions;
- Return, Replacement, Cancellation and Refund Policy;
- Warranty Policy;
- Shipping and Delivery Policy;
- Campaign and Pre-Order Terms;
- Product-Specific Terms;
- Project-Specific Terms;
- Cookie Notice or Cookie Policy, if applicable;
- quotation;
- invoice;
- order confirmation;
- warranty documentation;
- and any other applicable contractual documentation.
4. PRIVACY POLICY IS NOT A LIMITATION OF ZOAR’S LAWFUL RIGHTS
Nothing in this Privacy Policy shall prevent ZOAR from processing Personal Data where such processing is lawfully:
- required
- permitted
- reasonably necessary
- justified
under applicable law, notwithstanding that a particular processing activity may not have been exhaustively described herein.
PART II — DEFINITIONS
5. PERSONAL DATA
“Personal Data” means information relating to an identified or reasonably identifiable natural person and shall include such information as falls within the applicable statutory definition from time to time.
Personal Data may include, without limitation:
- name
- telephone number
- email address
- postal address
- delivery address
- online identifiers
- account identifiers
- financial information
- transaction information
- location information
- and other information capable of identifying or being associated with an individual
6. PROCESSING
“Processing” includes any operation performed upon Personal Data, whether or not by automated means, including:
- collection
- recording
- organisation
- structuring
- storage
- retention
- retrieval
- consultation
- use
- analysis
- combination
- adaptation
- alteration
- transmission
- disclosure
- sharing
- restriction
- archiving
- deletion
- and destruction
7. SENSITIVE PERSONAL DATA
“Sensitive Personal Data” means any category of Personal Data afforded heightened protection under applicable law.
Depending upon applicable statutory definitions, such information may include certain:
- financial information
- biometric information
- health information
- genetic information
- religious information
- ethnic information
- political information
- precise location information
- or other specially protected information
ZOAR does not ordinarily seek Sensitive Personal Data except where reasonably necessary for a lawful purpose.
PART III — CATEGORIES OF DATA COLLECTED
8. IDENTIFICATION INFORMATION
ZOAR may collect:
- full name
- username
- Customer number
- business contact information
- signature
- authorised representative information
- or other identification information reasonably necessary for a transaction
9. CONTACT INFORMATION
ZOAR may collect:
- mobile number
- telephone number
- email address
- billing address
- delivery address
- project-site address
- and other contact information
10. ACCOUNT INFORMATION
Where Customer accounts are provided, ZOAR may process:
- account identifier
- login information
- account preferences
- account history
- saved addresses
- saved Products
- order history
- support history
- and security-related information
ZOAR should not store plaintext passwords.
11. TRANSACTION INFORMATION
ZOAR may process information concerning:
- Products purchased
- quantities
- prices
- discounts
- order date
- invoice information
- refunds
- returns
- Campaign participation
- Pre-Orders
- warranty claims
- delivery status
- payment status
- and related commercial history
12. PAYMENT AND FINANCIAL INFORMATION
ZOAR may receive or process information concerning:
- payment method
- transaction reference
- payment confirmation
- partial account information
- billing information
- refund destination
- payment-provider status
- bank transfer reference
- and other payment-related information
Where payment is processed directly by an independent payment service provider, ZOAR may not receive the complete payment-card or financial credential.
13. DELIVERY AND LOGISTICS INFORMATION
ZOAR may process:
- recipient information
- delivery address
- telephone number
- courier tracking
- delivery status
- proof of delivery
- delivery photographs
- OTP verification
- recipient details
- GPS-related carrier records where made available
- and delivery communications
14. COMMUNICATIONS
ZOAR may retain communications exchanged through:
- telephone
- SMS
- Messenger
- social media
- live chat
- support tickets
- web forms
- or other communication channels
Such records may be used for:
- customer support
- quality assurance
- fraud prevention
- transaction verification
- training
- dispute resolution
- and evidentiary purposes
15. WEBSITE AND DEVICE INFORMATION
ZOAR may automatically collect or receive:
- IP address
- device type
- browser type
- operating system
- language
- time zone
- session identifiers
- referral source
- pages visited
- click activity
- session duration
- approximate location
- technical logs
- error logs
- security events
- and similar information
16. COOKIE AND TRACKING INFORMATION
ZOAR may use cookies, pixels, tags, local-storage technologies, SDKs and comparable technologies for purposes including:
- website functionality
- account sessions
- security
- cart persistence
- preferences
- analytics
- performance measurement
- marketing attribution
- advertising
- and fraud prevention
Where consent is legally required for a category of cookie or tracking technology, ZOAR shall seek such consent in the manner required by applicable law.
PART IV — ENERGY, IOT AND CONNECTED-PRODUCT DATA
17. CONNECTED ENERGY PRODUCTS
Certain present or future ZOAR Products may generate, transmit or make available technical information.
Such Products may include:
- inverters
- battery systems
- BESS
- smart meters
- EV chargers
- controllers
- gateways
- energy-management systems
- monitoring systems
- IoT devices
- and other connected equipment
18. TECHNICAL PRODUCT DATA
ZOAR may process Product-generated information including:
- Product identifier
- serial number
- firmware version
- configuration
- operating status
- fault code
- voltage
- current
- temperature
- charge level
- State of Charge
- State of Health
- battery cycle count
- generation data
- consumption data
- charging history
- system uptime
- event history
- diagnostic logs
- and performance information
19. ENERGY-USAGE INFORMATION
Energy-consumption or generation information may, depending upon context, reveal information relating to a particular Customer, household, property or business.
Where such information constitutes Personal Data, ZOAR shall process it accordingly.
20. REMOTE DIAGNOSTICS
Where technically available and lawfully permitted, ZOAR may remotely access or obtain technical Product information for:
- diagnosis
- warranty verification
- preventive maintenance
- safety
- fraud prevention
- Product improvement
- technical support
- performance analysis
- and fault investigation
21. PRODUCT LOCATION
Certain Products may generate or require location-related information for purposes including:
- installation
- delivery
- site support
- device management
- fraud prevention
- theft prevention
- technical functionality
- or regulatory compliance
ZOAR shall process location information only upon an applicable lawful basis.
PART V — SOURCES OF PERSONAL DATA
22. INFORMATION PROVIDED DIRECTLY BY YOU
ZOAR may collect Personal Data when you:
- create an account
- contact ZOAR
- request a quotation
- place an order
- submit a Campaign reservation
- make payment
- request delivery
- register a warranty
- request technical support
- submit a claim
- complete a survey
- participate in a promotion
- or otherwise communicate with ZOAR
23. INFORMATION FROM THIRD PARTIES
ZOAR may lawfully receive information from:
- payment providers
- banks
- couriers
- logistics providers
- manufacturers
- distributors
- warranty providers
- installation contractors
- marketing platforms
- fraud-prevention providers
- identity-verification services
- business partners
- social-media platforms
- and other lawful sources
24. INFORMATION GENERATED THROUGH USE
ZOAR may generate information through:
- transaction history
- website usage
- support interactions
- Product diagnostics
- device usage
- fraud analysis
- Customer preferences
- and internal business analytics
PART VI — LAWFUL BASIS FOR PROCESSING
25. ZOAR DOES NOT RELY EXCLUSIVELY UPON CONSENT
Where permitted by applicable law, ZOAR may process Personal Data without relying solely upon consent where another lawful basis is available.
This provision is important to the administration of ZOAR’s legitimate commercial and legal interests.
26. CONTRACTUAL NECESSITY
ZOAR may process Personal Data where reasonably necessary to:
- take steps at your request before entering into a transaction
- enter into a contract
- perform a contract
- process an order
- deliver a Product
- provide installation
- administer warranty
- provide support
- or otherwise perform obligations owed to you
27. LEGITIMATE INTERESTS
Where permitted by applicable law, ZOAR may process Personal Data where reasonably necessary for ZOAR’s legitimate interests or those of another person, provided the applicable legal requirements are satisfied.
Such legitimate interests may include:
- operating ZOAR’s business
- preventing fraud
- protecting systems
- protecting property
- improving Products
- understanding Customers
- maintaining commercial records
- conducting analytics
- protecting legal rights
- enforcing contracts
- developing Products
- managing supplier relationships
- and defending legal claims
28. LEGAL OBLIGATIONS
ZOAR may process and disclose Personal Data where reasonably necessary to comply with:
- law
- regulation
- court order
- tax requirements
- customs requirements
- regulatory requirements
- governmental directions
- record-keeping obligations
- financial requirements
- or other legally enforceable obligations
29. LEGAL CLAIMS AND DEFENCE
ZOAR may retain, use and disclose information where reasonably necessary for:
- establishing
- exercising
- enforcing
- investigating
or defending
legal rights, contractual rights, claims, complaints, disputes, chargebacks, warranty matters or proceedings.
30. CONSENT
Where consent constitutes the appropriate lawful basis, ZOAR may request consent for specified processing.
Where legally required, consent shall be obtained in a manner that is sufficiently:
- informed
- specific
- voluntary
- clear
- and capable of withdrawal
31. WITHDRAWAL OF CONSENT
Where processing depends exclusively upon consent, a Data Subject may withdraw such consent subject to applicable law.
Withdrawal shall not ordinarily affect the lawfulness of processing undertaken before withdrawal.
Withdrawal shall likewise not require ZOAR to cease processing where another lawful basis independently authorises continued processing.
PART VII — PURPOSES OF PROCESSING
32. ORDER AND CONTRACT ADMINISTRATION
ZOAR may use Personal Data to:
- process orders
- verify Customers
- generate invoices
- confirm transactions
- allocate Products
- administer Campaigns
- manage Pre-Orders
- collect payment
- arrange delivery
- and perform contracts
33. CUSTOMER SERVICE
ZOAR may process Personal Data to:
- answer enquiries
- resolve complaints
- provide after-sales service
- administer warranties
- provide technical assistance
- investigate Product issues
- and maintain service history
34. DELIVERY AND LOGISTICS
Personal Data may be disclosed to and processed by logistics providers where necessary for:
- dispatch
- transport
- customs processing
- delivery
- proof of delivery
- collection
- or return
35. WARRANTY AND TECHNICAL CLAIMS
ZOAR may process:
- purchase records
- serial numbers
- diagnostics
- Product logs
- installation records
- photographs
- videos
- Customer communications
and technical evidence
for determining warranty eligibility and administering remedies.
36. SAFETY
ZOAR may process Customer and Product information where reasonably necessary to:
- investigate safety concerns
- issue safety instructions
- perform Product recalls
- identify affected Products
- or protect persons or property
37. FRAUD PREVENTION
ZOAR may process and analyse information to detect and prevent:
- payment fraud
- refund fraud
- chargeback abuse
- warranty fraud
- identity fraud
- account abuse
- COD abuse
- promotion abuse
- and other dishonest or unlawful conduct
38. SECURITY
ZOAR may use data for:
- authentication
- access control
- intrusion prevention
- security monitoring
- malware prevention
- fraud detection
- system auditing
- incident response
- and preservation of service integrity
39. ANALYTICS
ZOAR may analyse information to understand:
- Customer behaviour
- Product demand
- sales performance
- website usage
- Product reliability
- technical failure patterns
- marketing effectiveness
- and business performance
40. PRODUCT DEVELOPMENT
ZOAR may use information, particularly aggregated or appropriately de-identified technical data, for:
- research
- Product development
- engineering
- forecasting
- quality improvement
- system optimisation
- and development of future energy technologies
41. INTERNAL BUSINESS ADMINISTRATION
ZOAR may process Personal Data for:
- accounting
- auditing
- tax
- compliance
- insurance
- risk management
- business planning
- corporate governance
- supplier management
- and internal reporting
PART VIII — MARKETING
42. DIRECT MARKETING
Where permitted by applicable law, ZOAR may communicate information concerning:
- Products
- Campaigns
- new technologies
- promotions
- services
- warranty programmes
- events
- or related commercial offerings
43. MARKETING PREFERENCES
Where applicable, Customers may unsubscribe or withdraw marketing consent through the method provided in the communication or by contacting ZOAR.
44. TRANSACTIONAL COMMUNICATIONS ARE DISTINCT
Withdrawal from promotional marketing shall not prevent ZOAR from sending communications reasonably necessary for:
- orders
- payments
- delivery
- account security
- warranty
- Product safety
- contract performance
- or legal compliance
45. CUSTOMISED MARKETING
Where lawful, ZOAR may use information concerning:
- Product interests
- order history
- website activity
- location at an appropriate level
and Customer preferences
to make marketing communications more relevant.
PART IX — PROFILING AND AUTOMATED PROCESSING
46. PROFILING
ZOAR may, where lawfully permitted, use automated or semi-automated analysis for purposes including:
- fraud-risk scoring
- Customer segmentation
- Product recommendations
- marketing optimisation
- inventory forecasting
- risk assessment
- and commercial analytics
47. SIGNIFICANT AUTOMATED DECISIONS
Where applicable law grants rights in relation to a decision based solely upon automated processing that produces a significant legal or comparable effect, ZOAR shall administer such rights in accordance with applicable law.
PART X — DISCLOSURE OF PERSONAL DATA
48. ZOAR DOES NOT TREAT ALL DISCLOSURE AS A “SALE”
ZOAR may disclose Personal Data to third parties where reasonably necessary for a lawful business or legal purpose.
Such disclosure does not necessarily constitute a commercial “sale” of Personal Data.
49. SERVICE PROVIDERS
ZOAR may disclose Personal Data to service providers performing functions including:
- website hosting
- cloud infrastructure
- payment processing
- email delivery
- SMS delivery
- Customer support
- analytics
- fraud prevention
- security
- courier services
- logistics
- warehousing
- technical support
- installation
- accounting
- and professional services
50. MANUFACTURERS AND WARRANTY PROVIDERS
Customer and Product information may be disclosed to:
- manufacturers
- distributors
- importers
- service centres
- technical partners
or warranty providers
where reasonably necessary to administer:
- warranty
- repair
- Product support
- recall
- diagnosis
- or replacement
51. PROFESSIONAL ADVISERS
ZOAR may disclose relevant information to:
- lawyers
- accountants
- auditors
- consultants
- insurers
- banks
and other professional advisers
where reasonably necessary.
52. GOVERNMENT AND AUTHORITIES
ZOAR may disclose information to:
- courts
- law-enforcement agencies
- regulators
- tax authorities
- customs authorities
- consumer-protection authorities
- cybersecurity authorities
or other competent authorities
where legally required or lawfully justified.
53. PROTECTION OF ZOAR
ZOAR may disclose information where reasonably necessary to:
- protect ZOAR
- prevent fraud
- investigate misconduct
- enforce contractual rights
- protect intellectual property
- recover debts
- respond to legal proceedings
- or defend ZOAR against claims
PART XI — CORPORATE TRANSACTIONS
54. BUSINESS TRANSFER
In connection with an actual or proposed:
- merger
- acquisition
- investment
- financing
- business sale
- asset sale
- reorganisation
- restructuring
- joint venture
- insolvency
or succession,
ZOAR may disclose or transfer relevant information to prospective or actual:
- purchasers
- investors
- lenders
- advisers
- successors
or counterparties,
subject to applicable law and appropriate confidentiality arrangements where required.
55. SUCCESSOR ENTITIES
If all or part of ZOAR’s business is transferred to another lawful entity, Customer information relating to the transferred business may form part of the transferred assets or operational records.
PART XII — PROCESSORS
56. DATA PROCESSORS
ZOAR may appoint processors or service providers to process Personal Data on ZOAR’s behalf.
ZOAR may require such processors, to the extent required by applicable law and appropriate to the circumstances, to:
- process data for authorised purposes
- maintain reasonable security
- preserve confidentiality
- and comply with applicable contractual requirements
57. PROCESSOR CHANGES
ZOAR may replace or add service providers from time to time as operational requirements evolve.
This Privacy Policy does not constitute a guarantee that any specific third-party service provider shall remain engaged indefinitely.
PART XIII — INTERNATIONAL AND CROSS-BORDER PROCESSING
58. INTERNATIONAL OPERATIONS
ZOAR’s business may involve:
- international manufacturers
- foreign suppliers
- international cloud infrastructure
- software providers
- freight providers
- warranty providers
- and other service providers situated outside Bangladesh
59. CROSS-BORDER TRANSFERS
Accordingly, Personal Data may, where lawfully permitted and reasonably necessary, be:
- accessed
- stored
- processed
- supported
or transferred
outside the jurisdiction in which it was originally collected.
60. SAFEGUARDS
ZOAR shall implement such contractual, organisational, technical, regulatory or other safeguards for international transfers as may be required by applicable law from time to time.
61. FOREIGN LEGAL ENVIRONMENTS
Where information is lawfully processed outside Bangladesh, the foreign jurisdiction may have legal rules differing from those of Bangladesh.
ZOAR shall not be deemed to guarantee that every foreign jurisdiction maintains identical laws, but shall comply with applicable legal requirements governing the transfer.
PART XIV — DATA RETENTION
62. RETENTION PRINCIPLE
ZOAR may retain Personal Data for so long as reasonably necessary for the purposes for which it was lawfully processed and for such additional periods as permitted or required by law.
63. RETENTION FACTORS
Retention periods may take account of:
- transaction history
- warranty duration
- Product life
- project duration
- tax requirements
- accounting requirements
- legal limitation periods
- fraud risk
- litigation risk
- safety considerations
- Product recall requirements
- technical-support requirements
- and regulatory obligations
64. LONG-LIFE ENERGY PRODUCTS
Certain ZOAR Products may have long operating lives or warranties.
ZOAR may therefore retain transaction, Product, serial-number, installation, warranty and technical records for extended periods where reasonably necessary to:
- administer warranty
- verify ownership
- investigate safety
- provide support
- manage recalls
- or defend legal claims
65. LEGAL HOLDS
ZOAR may suspend ordinary deletion where information is reasonably required for:
- litigation
- investigation
- regulatory inquiry
- fraud investigation
- legal claim
- chargeback
- warranty dispute
- or preservation of evidence
66. ANONYMISED DATA
Information which has been irreversibly anonymised so that it no longer constitutes Personal Data may be retained and used for lawful purposes without being subject to Personal Data retention requirements applicable to identifiable information.
PART XV — DATA SECURITY
67. REASONABLE SECURITY MEASURES
ZOAR shall implement reasonable technical and organisational safeguards appropriate to:
- the nature of the data
- the sensitivity of the data
- the risks involved
- the processing environment
- and commercially reasonable security standards
68. POSSIBLE SECURITY CONTROLS
Such safeguards may include, where appropriate:
- access controls
- authentication
- encryption
- pseudonymisation
- network security
- backups
- logging
- monitoring
- role-based permissions
- incident response
- security testing
- and vendor controls
69. NO ABSOLUTE SECURITY GUARANTEE
No electronic system, network, device, transmission method or storage system can be guaranteed to be entirely secure.
Accordingly, while ZOAR shall employ reasonable measures required by applicable law, ZOAR does not represent that unauthorised access, cyberattack, system failure or other security incidents can be prevented in every conceivable circumstance.
70. CUSTOMER SECURITY RESPONSIBILITY
Customers are responsible for:
- maintaining account credentials
- protecting passwords
- protecting OTPs
- securing connected devices
- maintaining secure networks
- and promptly notifying ZOAR of suspected unauthorised account access
PART XVI — PERSONAL DATA BREACH
71. INCIDENT RESPONSE
ZOAR may investigate actual or suspected:
- unauthorised access
- disclosure
- destruction
- loss
- alteration
- cyberattack
- or other compromise of Personal Data
72. REGULATORY NOTIFICATION
Where applicable law requires notification of a Personal Data breach to a competent authority or affected Data Subject, ZOAR shall make such notification in the manner and within the period required by applicable law.
73. CUSTOMER COOPERATION
Where a security event originates from or involves a Customer-controlled:
- account
- device
- network
- installation
or third-party system,
ZOAR may require reasonable Customer cooperation in investigating and mitigating the incident.
PART XVII — DATA SUBJECT RIGHTS
74. STATUTORY RIGHTS
Subject to applicable law, a Data Subject may possess rights relating to Personal Data, including rights concerning:
- access
- data portability
- rectification
- completion
- erasure
- withdrawal of consent
- objection
- and other rights created by applicable law
75. RIGHTS ARE SUBJECT TO LEGAL CONDITIONS
Such rights are not necessarily absolute.
A request may be restricted, deferred or refused where processing remains lawfully necessary for matters including:
- contract performance
- legal obligations
- legal claims
- fraud prevention
- security
- record preservation
- public interest
- another applicable legal basis
- or another lawful statutory exception
76. ACCESS REQUESTS
A Data Subject may request access to eligible Personal Data processed by ZOAR, subject to applicable legal procedures, exceptions and verification requirements.
77. CORRECTION
A Data Subject may request correction of inaccurate Personal Data.
ZOAR may require adequate evidence before altering information relevant to:
- identity
- payment
- ownership
- warranty
- tax
- delivery
- or legal records
78. COMPLETION
Where data is materially incomplete, a Data Subject may request completion where provided by applicable law.
79. ERASURE
A Data Subject may request deletion where applicable legal conditions are satisfied.
ZOAR shall not be obliged to erase information merely upon request where continued retention is lawfully justified.
80. EXAMPLES OF INFORMATION ZOAR MAY LAWFULLY RETAIN
Subject to applicable law, information may remain necessary for:
- financial record-keeping
- tax compliance
- fraud prevention
- warranty administration
- Product safety
- Product recall
- legal defence
- transaction evidence
- debt recovery
- regulatory compliance
- or another lawful purpose
81. DATA PORTABILITY
Where the statutory conditions for data portability are satisfied, ZOAR shall administer an eligible request in the manner required by applicable law.
82. OBJECTION
Where applicable law provides a right to object to a category of processing, ZOAR shall consider an eligible objection in accordance with the statutory criteria.
83. WITHDRAWAL OF CONSENT
Withdrawal of consent shall apply only to processing whose lawful basis depends upon that consent.
Processing independently authorised by contract, law, legitimate interests or another lawful basis may continue notwithstanding withdrawal.
PART XVIII — EXERCISING DATA RIGHTS
84. REQUEST PROCEDURE
Privacy requests should be submitted through the contact method designated by ZOAR for privacy matters.
85. IDENTITY VERIFICATION
Before fulfilling a privacy request, ZOAR may take reasonable steps to verify:
- the identity of the requester
- the authority of an authorised representative
- and the relationship between the requester and the relevant Personal Data
86. FRAUDULENT OR UNVERIFIED REQUESTS
ZOAR may decline to disclose or alter Personal Data where ZOAR cannot reasonably verify that the requester is entitled to the information.
This restriction is intended to protect Data Subjects against unauthorised disclosure and identity fraud.
87. REQUEST SCOPE
ZOAR may ask the requester to provide sufficient information to identify:
- the relevant account
- transaction
- Product
- data category
- or processing activity
88. EXCESSIVE OR REPETITIVE REQUESTS
Manifestly unfounded, abusive, disproportionate or repetitive requests may be treated in accordance with any limitation or procedure permitted by applicable law.
PART XIX — CHILDREN AND PERSONS UNABLE TO PROVIDE VALID CONSENT
89. NOT DIRECTED TO CHILDREN
ZOAR’s commercial Products and services are generally intended for persons capable of entering into lawful commercial transactions.
90. CHILDREN’S DATA
ZOAR does not knowingly seek unnecessary Personal Data from children.
Where processing the Personal Data of a child requires parental or lawful guardian consent under applicable law, ZOAR may require such consent before processing.
91. PERSONS LACKING LEGAL CAPACITY
Where an individual is legally unable to provide valid consent, ZOAR may obtain consent or instructions from a person lawfully authorised to act on that individual’s behalf where required.
PART XX — THIRD-PARTY WEBSITES AND SERVICES
92. EXTERNAL SERVICES
ZOAR websites, Products or communications may link to:
- manufacturer websites
- payment providers
- courier services
- social networks
- third-party applications
- cloud services
- or other independent services
93. INDEPENDENT PRIVACY PRACTICES
ZOAR does not control the independent privacy practices of third-party services merely because ZOAR provides a link, integration or compatibility with them.
Customers should review the applicable third-party privacy terms.
PART XXI — SOCIAL MEDIA
94. SOCIAL-MEDIA INTERACTIONS
Information communicated publicly through social-media platforms may be visible to:
- ZOAR
- the platform
- other users
and the public,
depending upon the Customer’s platform settings.
95. PLATFORM PROCESSING
Personal Data processed independently by a social-media platform shall remain subject to that platform’s own terms and privacy practices.
PART XXII — CCTV AND PHYSICAL SECURITY
96. CCTV
Where ZOAR operates warehouses, offices, showrooms, service facilities or other physical premises, CCTV or similar security systems may be used for:
- security
- fraud prevention
- safety
- loss prevention
- incident investigation
- and protection of property
97. CCTV RETENTION
CCTV records may be retained for a reasonable security period and for longer where required in connection with a specific:
- incident
- investigation
- claim
- or legal proceeding
PART XXIII — CALL RECORDING
98. CALLS AND SUPPORT QUALITY
Where legally permissible and appropriately notified, ZOAR may record or monitor telephone or support communications for:
- quality assurance
- training
- fraud prevention
- transaction confirmation
- complaint resolution
- and evidence
PART XXIV — AGGREGATED AND DE-IDENTIFIED INFORMATION
99. AGGREGATED INFORMATION
ZOAR may create statistical or aggregated information from Customer and Product information.
100. DE-IDENTIFICATION
Where information has been lawfully anonymised or de-identified to a degree that it no longer constitutes Personal Data, ZOAR may use such information for:
- analytics
- research
- Product development
- industry analysis
- engineering
- commercial planning
- and other lawful business purposes
101. ENERGY RESEARCH
Aggregated or appropriately de-identified energy information may be particularly valuable for:
- energy-demand modelling
- battery research
- solar-performance analysis
- system design
- charging behaviour analysis
- grid optimisation
- and development of future energy technologies
ZOAR reserves the right to conduct such lawful analysis.
PART XXV — AI, MACHINE LEARNING AND ADVANCED ANALYTICS
102. ADVANCED TECHNOLOGY
ZOAR may in the future employ:
- artificial intelligence
- machine learning
- predictive analytics
- automation
and other advanced computational methods
for lawful purposes including:
- fraud prevention
- demand forecasting
- Customer support
- Product recommendations
- technical diagnosis
- energy optimisation
- and Product development
103. LEGAL SAFEGUARDS
Where such processing becomes subject to specific legal requirements, ZOAR shall implement such safeguards as applicable law requires.
PART XXVI — COMMERCIAL RECORDS AND EVIDENCE
104. TRANSACTION EVIDENCE
ZOAR may retain information reasonably necessary to establish:
- what was ordered
- what was paid
- what was delivered
- what warranty applied
- what communications occurred
- and what contractual terms were accepted
105. DISPUTE EVIDENCE
Personal Data may be relied upon as evidence in connection with:
- payment disputes
- chargebacks
- refund disputes
- warranty claims
- fraud investigations
- delivery disputes
- legal proceedings
- and regulatory inquiries
PART XXVII — FRAUD AND ABUSE RECORDS
106. FRAUD-PREVENTION DATABASES
Where lawful, ZOAR may maintain internal records relating to:
- confirmed fraud
- suspected fraud
- abusive COD activity
- false refund claims
- false warranty claims
- chargeback abuse
- account abuse
- and other material misconduct
107. DECISIONS BASED UPON FRAUD RISK
Such information may be considered when determining whether to:
- accept an order
- offer COD
- require verification
- require advance payment
- restrict an account
or investigate a transaction,
subject to applicable law.
PART XXVIII — DATA ACCURACY
108. CUSTOMER RESPONSIBILITY
Customers are responsible for providing accurate and current information.
109. CONSEQUENCES OF INCORRECT INFORMATION
ZOAR shall not be responsible for consequences attributable to inaccurate information supplied by the Customer, including:
- failed delivery
- incorrect invoice
- failed verification
- warranty-processing difficulty
- or inability to contact the Customer
PART XXIX — DATA MINIMISATION
110. PROPORTIONAL PROCESSING
ZOAR shall seek to process Personal Data reasonably relevant to legitimate and lawful purposes, taking into account:
- commercial requirements
- legal obligations
- technical needs
- security
- risk
- and the nature of the transaction
PART XXX — PRIVACY BY DESIGN AND SECURITY GOVERNANCE
111. SYSTEM DESIGN
Where reasonably appropriate and legally required, ZOAR may incorporate privacy and security considerations into:
- new systems
- connected Products
- applications
- Customer platforms
- and internal technical infrastructure
112. ACCESS CONTROL
Access to Personal Data may be restricted to personnel and service providers requiring access for legitimate operational purposes.
PART XXXI — CHIEF DATA OFFICER OR RESPONSIBLE CONTACT
113. DESIGNATION WHERE REQUIRED
Where applicable law requires ZOAR to designate a Chief Data Officer, Data Protection Officer or comparable responsible person, ZOAR shall make such designation in accordance with applicable requirements.
114. PRIVACY CONTACT
Privacy enquiries may be submitted to:
ZOAR VC / ZOAR VenturesPrivacy Contact: info@zoarventures.com
Business Address: 15A, 55B, Purana Paltan, Dhaka
Telephone: +8801705358035
ZOAR may update its designated privacy contact without otherwise amending this Privacy Policy.
PART XXXII — REGULATORY COOPERATION
115. REGULATORY AUTHORITY
ZOAR may cooperate with a competent privacy, data-governance, cybersecurity, consumer-protection or judicial authority where legally required.
116. DISCLOSURE TO AUTHORITIES
Such cooperation may include production of Personal Data where lawfully demanded.
PART XXXIII — CUSTOMER COMPLAINTS
117. PRIVACY COMPLAINT
A Customer who believes Personal Data has been processed improperly should first contact ZOAR through the designated privacy contact.
118. INVESTIGATION
ZOAR may request sufficient information to:
- identify the relevant processing
- verify identity
- investigate the complaint
- and determine an appropriate response
119. STATUTORY REMEDIES
Nothing herein prevents a Data Subject from pursuing a remedy before a competent authority where such right exists under applicable law.
PART XXXIV — NO REPRESENTATION OF PERFECT PRIVACY
120. LIMITATION OF TECHNOLOGICAL CERTAINTY
Although ZOAR intends to use reasonable safeguards, no commercial organisation can guarantee that every:
- network
- server
- device
- database
- cloud service
- transmission
- employee
- contractor
or third-party provider
will remain entirely immune from every conceivable security failure or unlawful attack.
121. THIRD-PARTY INCIDENTS
To the fullest extent permitted by applicable law, ZOAR shall not automatically be deemed liable merely because an independent third-party service provider suffers a security incident.
Any liability shall be determined according to:
- applicable law
- the circumstances
- ZOAR’s own conduct
- and the relevant contractual arrangements
PART XXXV — CUSTOMER DUTY TO MITIGATE
122. NOTIFICATION OF SECURITY ISSUES
Customers should promptly notify ZOAR if they become aware of:
- unauthorised account access
- stolen credentials
- suspicious communications
- compromised devices
- or another security concern relating to ZOAR services
123. CUSTOMER NEGLIGENCE
ZOAR shall not be responsible, to the extent permitted by law, for loss caused solely by a Customer:
- sharing an OTP
- sharing a password
- using an insecure device
- providing credentials to a fraudulent third party
- or otherwise failing to take reasonable security precautions
PART XXXVI — CORPORATE GROUP AND FUTURE BUSINESS DEVELOPMENT
124. FUTURE BUSINESS STRUCTURE
ZOAR may establish:
- new business divisions
- subsidiaries
- affiliates
- platforms
- technology businesses
- energy services
- or other commercial undertakings
125. INTERNAL USE ACROSS ZOAR OPERATIONS
To the extent permitted by law, relevant Personal Data may be made available within ZOAR’s lawful business operations where reasonably necessary for:
- Customer service
- account administration
- fraud prevention
- business management
- Product development
- or related legitimate purposes
PART XXXVII — CHANGE OF CONTROL
126. PRIVACY POLICY FOLLOWING SUCCESSION
A lawful successor to ZOAR’s business may continue processing Personal Data relating to the acquired business, subject to applicable law.
PART XXXVIII — POLICY CHANGES
127. AMENDMENT
ZOAR may amend, supplement, replace or update this Privacy Policy from time to time to reflect:
- legal changes
- business changes
- new Products
- new technologies
- new processing activities
- new service providers
- security requirements
- or operational developments
128. MATERIAL CHANGES
Where applicable law requires notification or renewed consent in respect of a particular material change, ZOAR shall comply with such requirement.
129. CURRENT VERSION
The version published through ZOAR’s designated legal or privacy page shall constitute the then-current Privacy Policy.
PART XXXIX — FUTURE TECHNOLOGIES
130. FUTURE-PROOF APPLICATION
This Privacy Policy is deliberately intended to remain applicable as ZOAR expands into future areas including:
- advanced battery technologies
- energy storage
- smart-grid technologies
- EV infrastructure
- solar technology
- wind energy
- tidal energy
- distributed energy systems
- AI-based energy optimisation
- IoT
- connected infrastructure
- and other emerging energy technologies
131. SUPPLEMENTARY PRIVACY NOTICES
ZOAR may issue Product-Specific or Service-Specific privacy notices where a future Product or technology materially changes the nature of Personal Data processing.
Such notice shall supplement this Privacy Policy.
PART XL — INTERPRETATION
132. NON-EXHAUSTIVE LANGUAGE
Expressions including:
- “including”
- “includes”
- “such as”
and similar wording
shall be interpreted as illustrative and not exhaustive.
133. BUSINESS PURPOSE
This Privacy Policy shall, to the fullest extent lawfully permissible, be construed in a manner that permits ZOAR to operate, protect, develop and expand its legitimate commercial activities while respecting mandatory Personal Data protections.
PART XLI — SEVERABILITY
134. SEVERABILITY
If any provision of this Privacy Policy is determined to be invalid, unlawful or unenforceable, such provision shall be restricted, modified or disregarded only to the minimum extent necessary.
The remaining provisions shall continue in full force and effect.
PART XLII — NO WAIVER
135. NO WAIVER
Failure by ZOAR to rely upon any lawful right, basis or protection described herein on one occasion shall not prevent ZOAR from relying upon that right or protection subsequently.
PART XLIII — MANDATORY LAW SAVING CLAUSE
136. STATUTORY OVERRIDE LIMITED TO NECESSARY EXTENT
Where any provision of this Privacy Policy conflicts with mandatory applicable law, such mandatory law shall prevail only to the extent legally necessary.
All remaining provisions, lawful processing grounds, rights, defences and protections available to ZOAR shall remain fully effective.
PART XLIV — GOVERNING LAW
137. GOVERNING LAW
This Privacy Policy shall be governed by and construed in accordance with the laws of Bangladesh in force from time to time.
PRIVACY ACKNOWLEDGEMENT
By interacting with ZOAR, creating an account, submitting information, placing an order, participating in a Campaign, purchasing a Product, requesting delivery, registering a warranty, using a connected Product or otherwise using a ZOAR service, the Customer acknowledges having been provided access to this Privacy Policy.
Where consent is not the applicable legal basis, such acknowledgement shall not be interpreted as converting processing that is independently lawful on another legal basis into consent-based processing.
RECOMMENDED ACCOUNT / CHECKOUT PRIVACY NOTICE
“I acknowledge that ZOAR VC may process my Personal Data for order administration, payment verification, fulfilment, delivery, customer service, fraud prevention, warranty administration, security and other purposes described in the ZOAR VC Privacy Policy. Where a processing activity requires my consent under applicable law, such consent will be obtained as required.”
RECOMMENDED OPTIONAL MARKETING CONSENT
Marketing consent should remain separate from mandatory checkout acceptance:
“I consent to receiving promotional communications from ZOAR VC concerning Products, Campaigns, energy technologies, services and offers. I understand that I may withdraw this marketing consent at any time through the available unsubscribe or contact mechanism.”
RECOMMENDED CONNECTED-PRODUCT NOTICE
For connected inverters, batteries, BESS, EV chargers, monitoring systems or other IoT Products:
“I acknowledge that operation, technical support, warranty administration and remote diagnostic functions of this Product may involve the collection and processing of device identifiers, system status, performance information, fault records, configuration information, energy-related data and other technical information as described in the ZOAR VC Privacy Policy and any applicable Product-Specific Privacy Notice.”
RECOMMENDED WARRANTY / DIAGNOSTIC CONSENT WHERE REQUIRED
“I authorise ZOAR VC and, where reasonably necessary, the relevant manufacturer, distributor or authorised technical provider to access and process the Product information, diagnostics, operating logs and related information reasonably required to investigate my support or warranty request, subject to applicable law and the ZOAR VC Privacy Policy.”