Skip to content
Legal

Privacy Policy

Production privacy notice for ResnDevs products, research, and professional services.

Version 1.0.0 · Effective 28 July 2026 · Last updated 28 July 2026

This Privacy Policy explains how ResnDevs collects, uses, stores, shares, and protects personal and related information across our website, products, and professional services — and the rights available to individuals and organisations who deal with us.

1. Introduction and company overview

ResnDevs (“ResnDevs”, “we”, “us”, or “our”) is a research-and-development studio based in Bangladesh. We conduct applied research across data science, artificial intelligence, natural language processing, image processing, computer vision, IoT, and embedded systems, and we design, build, and operate software products and professional services for clients worldwide.

Our public products today include CMS (conference management software) and DrChamber (clinic and chamber management software). We also provide consulting, custom software engineering, and related professional services under contract. Our marketing presence is published at resndevs.com.

We treat privacy as an engineering and governance concern, not only a notice obligation. We design systems with purpose limitation, least privilege, and data minimisation in mind, and we align our practices with internationally recognised privacy, security, and AI-governance frameworks as organisational commitments — without claiming certifications we have not obtained.

This Privacy Policy is published at https://resndevs.com/privacy. Questions may be sent to contact@resndevs.com.

2. Scope of this Privacy Policy

This Policy applies to personal information and related data processed in connection with:

  • the resndevs.com website and related marketing, publications, contact, newsletter, and careers surfaces;
  • CMS and DrChamber product applications, APIs, administrative consoles, and associated cloud infrastructure under ResnDevs control;
  • professional services, consulting engagements, research collaborations, and support interactions under contract or NDA;
  • recruitment and internship applications submitted to ResnDevs;
  • communications with us by email, form, or other channels we operate.

This Policy does not apply to third-party websites, applications, or services that we do not control, even if they are linked from our materials. Those parties have their own privacy practices.

Product deployments may be supplemented by customer-specific data processing agreements, statements of work, NDAs, or in-product notices. Where a binding contract conflicts with this Policy on a processing activity for which the customer is controller, the contract controls for that activity.

Forward-looking offerings (for example additional SaaS products, mobile or desktop clients, IoT or embedded deployments, white-label or marketplace features, games, or beta programmes) are covered by this Policy when offered, subject to any supplemental notice published at launch.

3. Definitions

In this Policy:

  • “Personal Information” means information relating to an identified or identifiable natural person, consistent with applicable privacy law.
  • “Business Information” means information about an organisation, its personnel in a professional capacity, and commercial relationships that may include Personal Information.
  • “Client Data” or “Enterprise Customer Data” means data that a customer or partner provides to ResnDevs, or that we process on their behalf, in the course of providing products or services.
  • “Research Information” means information used in research, evaluation, or publication activities, which may include anonymised, aggregated, or consented personal data.
  • “AI Input” means prompts, files, structured records, or other content submitted to an AI feature or model workflow.
  • “AI Output” means content generated by an AI feature or model workflow in response to AI Input or related instructions.
  • “Controller” means the party that determines the purposes and means of processing Personal Information.
  • “Processor” (or “service provider”) means a party that processes Personal Information on behalf of a Controller.
  • “Subprocessor” means a Processor engaged by ResnDevs to assist in delivering services.
  • “Services” means our website, products, APIs, and professional services collectively.

4. Roles and relationships

4.1 When ResnDevs is a controller

We act as a controller for Personal Information we collect for our own business purposes, including website enquiries and newsletter subscriptions, marketing and community communications, recruitment, security of our own systems, billing and account administration for our direct customers, and research publications we author.

4.2 When ResnDevs is a processor

When a customer uses CMS, DrChamber, or engages us under a services agreement to host, process, or develop systems containing their data, the customer is typically the controller of Client Data, and ResnDevs processes that data as a processor according to the customer’s instructions and the applicable contract. Customers remain responsible for the lawfulness of their instructions, notices to data subjects, and any special-category or regulated data they choose to process in our products.

4.3 Joint and collaborative arrangements

University collaborations, industry partnerships, MoUs, MoIs, joint ventures, and similar arrangements may allocate controllership in writing. Where no allocation is stated, each party remains responsible for the Personal Information it collects through its own channels.

5. Information we collect

We collect information in the categories below, depending on how you interact with us. We do not collect every category for every person.

5.1 Website, marketing, and communications

  • Contact and lead forms: name, email address, organisation, interest, message content, and optional source context (for example which page or scene a submission came from).
  • Newsletter subscriptions: email address and subscription timestamp.
  • Career and internship applications: identity and contact details, CV or résumé content, and any materials you choose to submit when applications are open.
  • Correspondence: the content of emails and other messages you send to us.

5.2 Device, browser, network, and usage data

  • Device and browser information such as user agent, approximate locale, and technical capabilities needed to render the Services.
  • Network and server metadata such as IP address, request timestamps, referring URL, and response status codes in application, CDN, and infrastructure logs.
  • Session and analytics data, including page views collected through Vercel Analytics on resndevs.com (page-view metrics; we do not use that channel to identify you by name).
  • Diagnostic information such as error reports, crash signals, performance metrics, and security or abuse-prevention logs.

5.3 Product and account data (CMS, DrChamber, and related apps)

  • Account and authentication data: identifiers, credentials or credential hashes, roles, permissions, multi-factor authentication status where enabled, and access logs.
  • Profile and organisational data configured by administrators (for example conference, clinic, or tenant settings).
  • Operational content customers enter into the products (for example submissions, schedules, registrations, messages, documents, images, or other files the product accepts).
  • API request and response metadata required to operate and secure the product APIs.
  • Billing and subscription records where ResnDevs invoices the customer directly.

5.4 Professional services, research, and collaborations

  • Project materials shared under NDA or contract: requirements, source code, designs, datasets, credentials you provision for delivery, and meeting notes.
  • Academic or research collaboration materials shared with consent or under agreement.
  • Vendor, partner, and subcontractor contact details needed to deliver engagements.

5.5 AI-related information

Where an AI feature is part of a product or engagement, we may process AI Inputs, AI Outputs, evaluation labels, and telemetry needed to operate, secure, and improve that feature under the applicable contract and this Policy. We do not use customer AI Inputs or Client Data to train foundation models for unrelated commercial use unless a written agreement expressly authorises that use.

5.6 Sensitive and regulated categories

DrChamber and certain consulting engagements may involve health-related or other sensitive information when customers choose to process it. ResnDevs does not invite children to create accounts. We do not seek special-category data through marketing forms. Customers who process regulated data in our products remain responsible for their legal basis, notices, and configuration choices.

5.7 Sources of information

  • Directly from you or your organisation.
  • Automatically from devices and systems when you use the Services.
  • From customers who authorise users on a tenant (for product accounts).
  • From service providers that support hosting, email, analytics, payments, or security, where configured.
  • From publicly available professional sources when relevant to business development or research, used sparingly and lawfully.

6. How we use information

We use information for the following purposes:

  • to operate, maintain, secure, and improve the website, products, APIs, and infrastructure;
  • to respond to enquiries, provide demos, and deliver professional services;
  • to administer accounts, authentication, authorisation, and support;
  • to send transactional messages and, where permitted, newsletters or product updates;
  • to detect, investigate, and prevent fraud, abuse, security incidents, and service misuse;
  • to analyse aggregate usage and reliability (including page-view analytics on the marketing site);
  • to comply with law, enforce agreements, and establish, exercise, or defend legal claims;
  • to conduct research and publish findings only with appropriate legal bases, consent, anonymisation, or contractual rights;
  • to evaluate and improve AI features with human oversight and contractual limits on training use.

6.1 Lawful bases for international readers

Where GDPR, UK GDPR, or similar regimes apply to a processing activity, we rely on one or more of: performance of a contract; legitimate interests (for example securing our services, responding to business enquiries, and improving reliability) balanced against individual rights; consent (for example optional newsletters or certain cookies where required); and legal obligation. Where we act as a processor, the customer’s lawful basis supports the processing.

7. AI and research governance

ResnDevs builds and evaluates AI systems as part of research and product work. We design toward principles reflected in frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 concepts — transparency, accountability, human oversight, safety, and risk management — as organisational commitments, not as a claim of formal certification.

  • Human oversight: material AI-assisted decisions in our own operations are subject to human review where stakes warrant it.
  • Purpose limitation: AI features process data for documented product or engagement purposes.
  • No silent training: we do not train general-purpose models on Client Data or AI Inputs without written authorisation.
  • Evaluation and monitoring: we test and monitor models for quality, drift, and failure modes appropriate to the use case.
  • Bias and fairness: we take reasonable steps to identify and mitigate harmful bias in systems we control, recognising that mitigation is ongoing work.
  • Explainability: we provide documentation of AI feature behaviour to customers where feasible and proportionate.
  • Research ethics: research involving people or their data follows informed consent, anonymisation, or other lawful pathways and applicable institutional requirements.

We do not use Personal Information on the marketing site to make solely automated decisions that produce legal or similarly significant effects about you.

8. Cookies and similar technologies

We use cookies and similar technologies as follows:

  • Essential: required for security, load balancing, session continuity, and remembering theme or similar preferences you set.
  • Analytics: Vercel Analytics on resndevs.com currently provides aggregated page-view insights. We may expand measurement in line with PRD analytics events; we will update this Policy when material new trackers are introduced.
  • Product sessions: authenticated product apps may use cookies or tokens necessary to keep you signed in and enforce access control.

You can control cookies through browser settings. Blocking essential cookies may impair functionality. Where a jurisdiction requires consent before non-essential cookies, we will implement an appropriate consent mechanism before enabling those cookies for users in that jurisdiction.

9. Sharing, processors, and subprocessors

We do not sell Personal Information. We share information only as described below.

9.1 Service providers

We use vetted providers to operate the Services. Current categories and examples include:

  • Hosting, edge, and deployment: Vercel.
  • Databases and backend data stores: Supabase (website leads and newsletter data in a dedicated project; product data in product-specific projects).
  • Transactional email: Resend (for example lead notification email).
  • Other categories as needed for payments, customer support, error monitoring, or security tooling when introduced — disclosed to enterprise customers on request and reflected in this Policy when material.

9.2 Other disclosures

  • Within ResnDevs to personnel and contractors under confidentiality obligations who need access to perform their roles.
  • To professional advisers (legal, accounting) under duty of confidence.
  • To a successor in a merger, acquisition, or asset transfer, subject to appropriate safeguards.
  • When required by law, court order, or to protect rights, safety, and security.
  • With your direction or consent.

Open-source libraries, SDKs, and third-party components embedded in our software run in accordance with their licences; they do not receive your Personal Information unless a separate integration is configured to do so.

10. International data transfers

ResnDevs is based in Bangladesh and serves customers internationally. Infrastructure may process data in multiple regions. For example, website lead storage currently uses Supabase in the Asia-Pacific (Singapore) region, and Vercel may serve and log requests at edge locations near the visitor.

When we transfer Personal Information across borders, we use appropriate safeguards available under applicable law, which may include contractual clauses, vendor commitments, encryption in transit, and access controls. Enterprise customers may specify regional processing constraints in their agreement where technically feasible.

11. Security practices

We implement technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure, or loss. Measures are risk-based and evolve with our systems. They include, as applicable:

  • encryption in transit (TLS) for public endpoints;
  • access control, authentication, and least-privilege administration;
  • segregation of marketing-site data stores from product databases;
  • logging, monitoring, and rate limiting on sensitive endpoints;
  • secure software development practices, code review, and dependency awareness;
  • backup and recovery processes proportionate to the service;
  • vendor due diligence for material subprocessors.

We design toward principles associated with the NIST Cybersecurity Framework, NIST Privacy Framework, and ISO/IEC 27001 / 27701 families. This Policy does not assert that ResnDevs holds SOC 2, ISO, or similar certifications unless we publish a current attestation separately.

No method of transmission or storage is perfectly secure. We encourage strong unique passwords, multi-factor authentication where offered, and prompt reporting of suspected incidents to contact@resndevs.com.

11.1 Incident response

We maintain processes to detect, investigate, contain, and remediate security incidents. Where a personal data breach requires notification under applicable law or contract, we will notify regulators and affected parties as required, and enterprise customers as agreed in their processing terms.

12. Retention and deletion

We retain information only as long as needed for the purposes described in this Policy, including legal, accounting, and dispute-resolution requirements, then delete or anonymise it in a manner appropriate to the system.

  • Website leads and newsletter records: retained while an active relationship or legitimate follow-up interest exists, and for a reasonable period thereafter unless deletion is requested sooner where we are controller.
  • Product tenant data: retained for the life of the customer agreement and any post-termination export or wind-down period stated in the contract, then deleted from active systems according to product procedures.
  • Security and server logs: retained for a limited operational window unless needed longer for investigations.
  • Recruitment materials: retained for the recruitment cycle and any period required by law or legitimate defence of claims, then deleted or archived with restricted access.

Backups and disaster-recovery copies age out on a schedule; residual copies may persist until overwritten.

13. Your rights

Depending on your location and role (individual end user, customer contact, or data subject of a customer controller), you may have rights to:

  • access Personal Information we hold about you;
  • rectify inaccurate Personal Information;
  • request erasure where applicable;
  • restrict or object to certain processing;
  • receive a portable copy of Personal Information you provided to us as controller;
  • withdraw consent where processing is consent-based;
  • request human review of significant automated decisions where such rights apply;
  • lodge a complaint with a competent supervisory authority.

To exercise rights regarding data for which ResnDevs is controller, email contact@resndevs.com with sufficient detail to verify your identity and locate the records. We will respond within a reasonable period consistent with applicable law.

If you are an end user of a customer’s CMS or DrChamber tenant, contact that organisation first. We will support the customer’s response as processor when required by contract or law.

California and similar US state laws: we do not sell or “share” Personal Information for cross-context behavioural advertising as those terms are commonly defined. We process website analytics for our own service improvement. You may contact us to make a verifiable consumer request.

14. Children’s privacy

Our Services are directed to organisations and adults. We do not knowingly collect Personal Information from children under 16 (or the higher age required in a relevant jurisdiction) through the marketing site. If you believe a child has provided Personal Information to us, contact contact@resndevs.com and we will take appropriate steps to delete it.

15. Enterprise, government, healthcare, and education notes

15.1 Enterprise and government

Enterprise and government customers may require additional contractual terms (DPA, security exhibit, audit rights, residency constraints). Those terms supplement this Policy for the covered processing. We process government project data only under the applicable agreement and lawful instructions.

15.2 Healthcare and DrChamber

DrChamber is software for clinic and chamber workflows. ResnDevs is not, by default, your healthcare covered entity or equivalent under every jurisdiction’s health-privacy regime. Clinics and practitioners using DrChamber typically remain controllers of patient and clinical records. Configure access carefully, obtain required consents, and execute any health-data addendum your counsel requires before processing regulated health information.

15.3 Education and research

Educational data and research datasets are processed under the governing MoU, grant terms, ethics approval, or services agreement. We do not publish identifiable research data without authorisation.

15.4 Intellectual property and confidential research

Trade secrets, proprietary algorithms, source code, and confidential research shared with us remain protected under NDA and applicable IP law. This Policy governs personal data; IP ownership is governed by separate agreements.

16. Changes to this Policy

We may update this Policy to reflect product changes, legal requirements, or operational improvements. The “Last updated” date at the top of this page will change when we do. Material changes will be highlighted on this page or communicated to account contacts where appropriate. Continued use of the Services after an update constitutes acceptance of the revised Policy to the extent permitted by law.

Version history begins at 1.0.0 (28 July 2026). Prior informal practices, if any, are superseded by this Policy for the Services it covers.

17. Contact and data protection enquiries

For privacy requests, security reports, or questions about this Policy:

  • Organisation: ResnDevs
  • Email: contact@resndevs.com
  • Web: https://resndevs.com/contact
  • Policy URL: https://resndevs.com/privacy

Please include “Privacy” in the subject line for data-subject requests so we can route them promptly.

18. Governing law, jurisdiction, and general terms

This Privacy Policy is governed by the laws of Bangladesh, without regard to conflict-of-law principles that would require application of another jurisdiction’s laws, except where mandatory local privacy rights cannot be waived.

Subject to those mandatory rights, courts in Bangladesh have jurisdiction over disputes arising from this Policy, unless a written enterprise agreement specifies a different dispute-resolution process for contractual processing.

If any provision of this Policy is held unenforceable, the remaining provisions continue in effect. This Policy, together with applicable product terms and processing agreements, constitutes the privacy-related understanding between you and ResnDevs regarding the Services. In a conflict between this Policy and a signed data processing agreement for a specific engagement, the signed agreement controls for that engagement.

Accessibility: we aim to present this Policy in a readable structure on resndevs.com. If you need an alternative format, contact contact@resndevs.com.

Questions? Contact us or email contact@resndevs.com.