Legal / Privacy
What BizRP does with your data, in plain language.
No certifications we do not hold, no residency promises we cannot keep, and no advertising trackers. If a section reads like it is hiding something, tell us and we will rewrite it.
Effective
Who we are
BizRP is operated by KaritKarma Limited, a company based in Dhaka, Bangladesh. In this document, we and us mean KaritKarma Limited.
For anything in this policy, write to hello@bizrp.com. A human reads that inbox.
Two roles matter throughout. When you sign up for BizRP, we decide how your account data is handled, so we are the controller of it. When your business puts its own customer, employee and supplier records into BizRP, you decide what goes in and why; we process those records on your instructions and we are the processor of them.
What we collect
Account data: your name, work email, company name, phone number if you give one, and the workspace and plan you chose. We need this to create and bill the account.
Authentication data: sign-in is handled by Wenme, our OAuth 2.1 provider. We receive an identity token and a user identifier. We never receive or store your password.
Billing data: the plan, the amount in Bangladeshi taka, the billing period, and the payment reference returned by the payment provider. We do not store full card numbers.
Operational logs: request timestamps, IP address, user agent, the route called and the result. We use these to run the service, investigate faults and detect abuse.
Tenant business data: everything your business enters into BizRP, which typically includes products, stock, orders, invoices, ledger entries, customer and supplier records, and employee records if you use the HR module. This is your data. We hold it to run the service for you.
We do not buy personal data from brokers, we do not run advertising trackers, and there is no analytics or advertising tag on bizrp.com today. If that changes we will say so here before it ships.
Why we use it
To provide the service you signed up for, including provisioning your workspace, enforcing your plan limits and running the modules you enabled.
To bill you and to keep the financial records a Bangladeshi company is required to keep.
To support you: answering tickets, reproducing bugs, and restoring data when something goes wrong.
To keep the platform safe: rate limiting, abuse detection, audit trails on changes, and investigating security incidents.
We do not sell personal data. We do not share it with advertisers. We do not use your business data to train any machine-learning model of our own.
Who else processes your data
Wenme (KaritKarma Limited): authentication. Darwan (KaritKarma Limited): permission decisions.
Payment providers, currently SSLCommerz and bKash, process the payment itself. Card details go to them, not to us. Where your own business collects payments through BizRP, you bring your own merchant account: funds move between your customer and your gateway, and we record the transaction rather than holding the money.
Groq processes content you explicitly submit to an AI feature, such as generating a product description or reading an uploaded supplier invoice. If you do not use those features, nothing is sent.
Cloudflare R2 stores uploaded media for deployments configured to use it. Object storage for internally hosted tenants runs on infrastructure we operate.
Where a tenant has enabled outbound email, SMS or WhatsApp, the message is handed to the communications provider that tenant configured. The provider is a per-tenant setting, not a fixed vendor.
This list is current at the effective date above. We will update it here when it changes.
Where your data lives
Application servers and databases for BizRP are operated by KaritKarma Limited. Tenants on a dedicated stack get their own database rather than sharing rows with anyone else.
We want to be straightforward about the limits of that. Some of the sub-processors listed above, in particular AI inference and content delivery or object storage, operate infrastructure outside Bangladesh, and data sent to those services is processed outside the country. We do not offer a contractual guarantee that every byte stays inside Bangladesh, and we are not going to imply one.
If in-country residency is a hard requirement for you, tell us before you commit. On-premise and dedicated in-country deployments are available and are scoped per customer.
We hold no security or privacy certification today and we claim none. Where we describe a control, we are describing something we run, not something an auditor has signed off.
How long we keep it
Tenant business data is kept for as long as your workspace is active.
After a workspace is closed, we keep the data for 30 days so an accidental closure can be reversed, then delete it from live systems. Encrypted backups age out on their own schedule, within 90 days of closure.
Billing and tax records are kept for as long as Bangladeshi company and tax law requires, which is longer than the periods above and applies even after an account closes.
Operational logs are retained for 90 days unless a specific security investigation requires holding a subset for longer.
Your choices
You can ask for a copy of the personal data we hold about you as an account holder, ask us to correct it, or ask us to delete it. Write to hello@bizrp.com and we will respond within 30 days.
You can export your tenant business data from within BizRP at any time. If an export you need is not available in the interface, ask and we will produce it.
If you are an employee, customer or supplier of a business that uses BizRP, we hold your record on that business's instructions. Ask them first; we will support them in acting on your request, and we will not delete their records on a third party's say-so.
Deleting your account removes your access. It does not retroactively erase records that Bangladeshi law requires the business or us to retain.
Security
Sign-in runs on OAuth 2.1 with PKCE through Wenme; we never handle passwords. Every permission decision is evaluated per request against Darwan rather than being hardcoded into the application.
Traffic is served over HTTPS. Mutating actions are recorded in an audit trail.
No system is perfectly secure. If we discover a breach affecting your data, we will tell the affected account holders directly and describe what happened, what we know, and what we are doing about it.
If you believe you have found a vulnerability, report it to hello@bizrp.com. We will not pursue anyone who reports a genuine finding in good faith and does not exfiltrate or destroy data.
Children
BizRP is business software. It is not directed at children and we do not knowingly collect data from anyone under 18 as an account holder.
Changes to this policy
When this policy changes we update the effective date at the top of the page. For a change that materially affects how we handle your data, we will also email the account holder before it takes effect.
Questions, complaints and correction requests all go to the same place: hello@bizrp.com.