Privacy Policy
& Data Protection Policy · Effective January 1, 2026 (Revised: May 24, 2026) · v1.0
1. Organisation Identity & Controller Details
HEART Global (operating under the full name HEART Global — Health, Exploration, Academic, Research & Training) is a youth-led research and educational support organisation headquartered in Dhaka, Bangladesh. HEART Global operates the website located at www.heart-global.org and all associated sub-pages, portals, and communication channels.
▸ Legal Name: HEART Global ▸ Operating Jurisdiction: Bangladesh ▸ Primary Website: www.heart-global.org ▸ Nature of Entity: Youth-led academic support & public health organisation ▸ Primary Service Area: South Asia & international online clients ▸ Data Controller: HEART Global — Executive Management ▸ Contact for Data Matters: See Section 20
HEART Global is a youth-led research and educational support organisation operating in Dhaka, Bangladesh, serving students locally and internationally. The Executive Management serves as our Data Controller.
2. Scope of This Policy
This Policy applies to all personal data processed by HEART Global, including but not limited to data collected through:
▸ The HEART Global website (www.heart-global.org) including all service pages, contact forms, and embedded tools ▸ Direct client communications via email, WhatsApp Business, or any other messaging platform ▸ Service agreements, payment records, and NDA documentation ▸ Voluntary submissions for academic writing services (thesis, dissertation, research proposals, assignments, internship reports, presentations) ▸ Research activities, newsletters, or any other organisational communication
This Policy applies regardless of where you are located in the world. Clients in the European Economic Area (EEA) or United Kingdom benefit from GDPR-equivalent protections as voluntarily adopted by HEART Global.
This policy applies to all personal data collected via our website, email, WhatsApp, NDA agreements, and research pipelines. We voluntarily implement GDPR-equivalent safeguards for all users.
3. Categories of Personal Data Collected
3.1 — Identity & Contact Data ▸ Full name, email address, phone number (including WhatsApp contact number), academic institution name, student status (undergraduate/postgraduate), and city/country of residence.
3.2 — Service & Academic Data ▸ Academic documents, drafts, or materials submitted for reference or support; course/program details, thesis topics, assignment briefs, research themes, deadline dates, and communication history.
3.3 — Financial & Payment Data ▸ Mobile banking transaction reference numbers (bKash, Nagad, Rocket, or equivalent), bank transfer confirmation details, and agreed instalment schedules. *Note: HEART Global does NOT store full bank account numbers, credit/debit card numbers, or PINs at any stage.*
3.4 — Technical & Usage Data ▸ IP address, browser type, pages visited, session duration, device operating system, and referral source.
3.5 — Contractual & Legal Data ▸ Signed Client Service Agreements, NDA records, consent confirmations, and any dispute-related correspondence.
We collect contact details, academic topics/briefs, transaction references (we NEVER store card PINs or full account numbers), browser analytics, and signed NDAs/Client agreements.
4. Legal Bases for Processing
HEART Global processes personal data only where a valid legal basis exists. In alignment with internationally recognised data protection principles (including the EU General Data Protection Regulation and Bangladesh's Cyber Security Act 2023 and ICT Act 2006), our legal bases are as follows:
▸ Contractual Necessity: Processing required to perform a service you have engaged (e.g., delivering academic writing support, honouring agreements). ▸ Legitimate Interests: Analysing website usage, improving service quality, preventing fraud, and internal record-keeping. ▸ Consent: Email newsletters, promotional communications, or any non-essential processing — you may withdraw consent at any time. ▸ Legal Obligation: Retaining financial records where required by Bangladesh tax, financial, or regulatory law. ▸ Vital Interests: Emergency scenarios where processing is necessary to protect life.
We process your data strictly under legal reasons: performing a contract (delivering services), legitimate interests (improving our site), explicit consent (newsletters), or financial law obligations.
5. Purposes of Data Processing
Your data is used exclusively for the following clearly defined purposes:
▸ Service Delivery: Providing the academic support services you have commissioned, including research, writing, and revision support. ▸ Client Communication: Responding to inquiries, confirming orders, sending deliverables, and ongoing project coordination. ▸ Payment Processing: Verifying advance payments, processing instalments, and issuing receipts. ▸ Contract Management: Generating, executing, and storing Client Service Agreements and NDAs. ▸ Legal Compliance: Maintaining records as required under applicable Bangladesh law. ▸ Website Improvement: Analysing traffic patterns to improve user experience. ▸ Marketing (with consent only): Sending updates about new services or offers — always with opt-out capability.
HEART Global does not sell, rent, broker, or commercially exploit your personal data to any third party under any circumstances.
Your data is used to coordinate your academic requests, confirm mobile banking transactions, execute NDAs, comply with local laws, and optimize our platform. We never broker or sell data.
6. Client Confidentiality & NDA Obligations
CONFIDENTIALITY GUARANTEE — HEART Global operates a mandatory Non-Disclosure Agreement (NDA) framework. Your identity, academic details, submitted materials, and the existence of any service engagement are treated as strictly confidential for a minimum period of FIVE (5) YEARS from the date of the executed Client Service Agreement.
Specifically, HEART Global guarantees and contractually commits to the following:
▸ Your name, institution, and personal identity will never be disclosed to any third party without your explicit written consent. ▸ Project details, academic subjects, and submitted materials remain confidential throughout the engagement and the full confidentiality period. ▸ All internal team members and writers working on your project are bound by identical NDA obligations as a condition of their engagement with HEART Global. ▸ HEART Global will not confirm, deny, or comment on whether any specific individual has engaged our services to any external party, including academic institutions, employers, or government bodies. ▸ Confidential materials will not be used as samples, marketing examples, or portfolio pieces without your explicit written consent.
6.1 — Exceptions to Confidentiality Confidentiality obligations do not apply where HEART Global is compelled to disclose information by: ▸ A valid court order issued by a court of competent jurisdiction in Bangladesh; ▸ A lawful directive from a regulatory authority under Bangladesh's Cyber Security Act 2023 or ICT Act 2006; ▸ An emergency situation involving immediate risk to life. In the event of any compelled disclosure, HEART Global will, to the extent legally permitted, notify you prior to disclosure.
MANDATORY NDA: Your name, identity, drafts, and payments are strictly confidential for a minimum of 5 years. Our writers sign identical NDAs. We never proactively reveal your info to any university.
7. Academic Integrity Disclaimer & Legal Liability Shield
ACADEMIC USE DECLARATION — MANDATORY: All work delivered by HEART Global is provided for academic reference, learning support, and skill development purposes only. HEART Global is a lawful academic support and skill-building organisation. The provision of reference materials, writing support, research assistance, and editing services is legal and widely practised globally.
Clients expressly acknowledge and agree to all of the following as a binding condition of service:
▸ All delivered materials are intended exclusively as reference, learning support, or skill development tools — not for direct submission as the client's own original work. ▸ Clients bear sole, complete, and non-transferable responsibility for all work submitted to their educational institution or any other body. ▸ HEART Global explicitly disclaims any and all responsibility for academic integrity violations, disciplinary action, suspension, expulsion, or any other institutional consequences arising from a client's choice of how to use delivered materials. ▸ Clients are independently responsible for reviewing and complying with their institution's academic integrity policy. ▸ HEART Global does not encourage, facilitate, or endorse academic fraud, plagiarism, or dishonest representation of work as one's own. ▸ Any misuse of delivered materials by the client is entirely the client's own decision, made independently and without any direction, encouragement, or facilitation from HEART Global.
7.1 — Legal Position The provision of academic writing, research, and editing assistance is not prohibited under Bangladesh law. HEART Global's services are analogous to those provided by tutors, editing agencies, and writing centres worldwide. Our disclaimer and NDA framework ensure that HEART Global's legal exposure is comprehensively limited.
HEART Global reserves the right to refuse, suspend, or terminate any engagement where there is reasonable evidence that a client intends to use delivered materials in a manner inconsistent with this Policy or the Client Service Agreement.
Tutoring assistance is legal. However, all delivered files are strictly references. You have sole responsibility for what you submit. We are legally shielded from institutional discipline.
8. Data Retention & Deletion
HEART Global retains personal data only for as long as necessary to fulfil the purposes outlined in this Policy, subject to the following retention schedule:
▸ Client Service Agreement & NDA: 5 Years (post-agreement) | Purpose: NDA confidentiality period; legal record ▸ Academic project files & drafts: 5 Years (post-delivery) | Purpose: Aligned with NDA period ▸ Payment records & transaction refs: 7 Years | Purpose: Bangladesh financial law compliance ▸ Communication records (email/WhatsApp): 3 Years (post-project) | Purpose: Dispute resolution ▸ Website analytics & cookies: 12 Months | Purpose: Operational improvement ▸ Marketing consent records: Until withdrawn + 1 Year | Purpose: Audit of consent
Upon expiry of the applicable retention period, data will be securely and permanently deleted or anonymised such that it can no longer be associated with any identifiable individual.
NDAs and project drafts are kept for 5 years (aligned with the confidentiality period). Payment history is kept for 7 years for financial compliance. Web analytics are scrubbed after 12 months.
9. Data Security Measures
HEART Global implements technical and organisational security measures appropriate to the nature of the data processed and the risks involved. These include:
9.1 — Technical Safeguards ▸ SSL/TLS encryption for all data transmitted through www.heart-global.org. ▸ Password-protected document storage and file transfer systems. ▸ Restricted internal access to client data on a strict need-to-know basis. ▸ Regular review and update of access credentials and permissions.
9.2 — Organisational Safeguards ▸ All staff, contractors, and writers engaged by HEART Global are bound by confidentiality obligations. ▸ Internal data handling protocols reviewed annually. ▸ Incident response procedures for data breach scenarios (see Section 9.3).
9.3 — Data Breach Response In the event of a data breach that is likely to result in risk to your rights and freedoms, HEART Global commits to: ▸ Assessing and containing the breach within 24 hours of discovery. ▸ Notifying affected clients without undue delay and no later than 72 hours after becoming aware of the breach. ▸ Providing clear information on the nature of the breach, data affected, likely consequences, and remediation steps taken.
We secure data via SSL encryption, password-protected storage, and restricted internal access. If any data breach happens, we will notify affected clients within 72 hours.
10. Third-Party Disclosure & Data Sharing
HEART Global does not sell, trade, or rent your personal data. We may share data only in the following strictly limited circumstances:
▸ Service Contractors: Writers, researchers, editors, or designers engaged on a project basis — all bound by NDA and this Policy. ▸ IT & Hosting Providers: Platform or cloud service providers who host our website or communication tools — bound by data processing agreements. ▸ Payment Processors: We do not use third-party payment gateways. Payments are made directly via mobile banking (bKash/Nagad) or bank transfer, and HEART Global handles all related records internally. ▸ Legal Compulsion: As described in Section 6.1 — only under valid legal order. ▸ Business Transfer: In the event of a merger, acquisition, or asset transfer, data may be transferred subject to equivalent protections — you will be notified in advance.
Any third-party service providers who handle personal data on our behalf are contractually obligated to comply with data protection standards equivalent to those in this Policy.
We never broker, sell, or rent your private details. We only share data with direct contractors (under strict NDA) and security IT platforms, or if legally ordered by Dhaka courts.
11. International Data Transfers
HEART Global serves clients internationally. If you are located in the European Economic Area (EEA), United Kingdom, or any other jurisdiction with data transfer restrictions, please note the following:
▸ HEART Global is based in Bangladesh, which is not currently designated as an 'adequate' jurisdiction under GDPR. ▸ By engaging HEART Global's services, EEA/UK clients provide explicit consent to the transfer of their personal data to Bangladesh, subject to the protections set out in this Policy. ▸ HEART Global voluntarily implements GDPR-equivalent safeguards as described throughout this Policy. ▸ Where requested, HEART Global can provide Standard Contractual Clauses (SCCs) or equivalent contractual protections for data transfers.
If you are an EEA or UK-based client and have concerns about international data transfers, please contact us before engaging services.
We support global students. While based in Bangladesh, we voluntarily align our data operations with GDPR to ensure equal protections for clients from the EU, UK, and worldwide.
13. User Rights & How to Exercise Them
Subject to applicable law, you have the following rights regarding your personal data: ▸ Right of Access: Obtain a copy of all personal data held about you. ▸ Right to Rectification: Correct inaccurate or incomplete data. ▸ Right to Erasure: Request deletion of your data (subject to retention obligations). ▸ Right to Restriction: Limit how we use your data in certain circumstances. ▸ Right to Portability: Receive your data in a structured, machine-readable format. ▸ Right to Object: Object to processing based on legitimate interests or for direct marketing. ▸ Right to Withdraw Consent: Withdraw consent for marketing or non-essential processing at any time. ▸ Right against Automated Decisions: Not be subject to solely automated decision-making with legal effect.
To exercise any of these rights, submit a written request to the contact details in Section 20. HEART Global will respond within 30 days. Requests are processed free of charge unless manifestly unfounded or excessive.
You can request to view, correct, download, limit, or fully erase your records. We process all valid requests free of charge within 30 days of receiving your message.
14. Children's Privacy
HEART Global's services are designed for university students — adults typically aged 18 and above. We do not knowingly collect or process personal data from individuals under the age of 18.
If you are under 18, you must obtain verifiable parental or guardian consent before using our services. If HEART Global discovers that it has inadvertently collected data from a person under 18 without appropriate consent, such data will be deleted immediately upon discovery.
Parents or guardians who believe their child's data may have been collected should contact us immediately at the details provided in Section 20.
Our services are for students 18 and older. We do not intentionally collect data from minors. Minors must have verified parental or legal guardian consent.
15. Payment Data & Financial Information
HEART Global processes payments through direct mobile banking (bKash, Nagad) and bank transfer. In connection with financial transactions:
▸ HEART Global retains only the minimum financial information necessary to confirm payment receipt (e.g., transaction reference numbers and amounts). ▸ Full account numbers, PINs, and card data are never collected, stored, or processed by HEART Global. ▸ A 35% to 40% advance payment (40% for internship report writing) is required to secure a service slot. This is processed directly through agreed channels and confirmed via written receipt. ▸ Instalment schedules are documented in the Client Service Agreement and stored in accordance with Section 8. ▸ Financial records are retained for 7 years in compliance with Bangladesh financial regulatory requirements.
HEART Global will NEVER request payment through unverified third-party platforms, cryptocurrency, or any channel not specified in the Client Service Agreement. If you receive unusual payment requests claiming to be from HEART Global, treat them as fraudulent and contact us immediately.
We require a 35% to 40% deposit to lock booking slots, accepted via bKash/Nagad/bank transfer. We only save transaction numbers. We NEVER ask for PINs or bank card digits.
16. Communication Channels (WhatsApp/Email)
HEART Global communicates with clients primarily through: ▸ Official email addresses associated with www.heart-global.org. ▸ WhatsApp Business — used for project coordination, file transfer, and client support. ▸ Website contact forms.
By contacting HEART Global through these channels, you consent to receiving communications relating to your service engagement. Please be aware:
▸ WhatsApp messages are transmitted via Meta's infrastructure and subject to WhatsApp's own privacy policy. HEART Global advises clients who require maximum confidentiality to use encrypted email communication instead. ▸ HEART Global will never initiate contact from unofficial or unverified numbers or email addresses. ▸ Communication records may be retained for dispute resolution as per Section 8.
We use official emails and WhatsApp Business for file transfers. Since WhatsApp uses Meta servers, clients who require maximum security should use encrypted email instead.
17. Limitation of Liability
To the maximum extent permitted by applicable law, HEART Global's total liability in connection with this Policy, any data breach, or any claim related to data processing shall be limited to the total fees paid by the relevant client for the specific service engagement to which the claim relates.
HEART Global shall not be liable for: ▸ Indirect, consequential, or incidental damages arising from the use of our website or services. ▸ Academic consequences resulting from a client's choice of how to use delivered materials. ▸ Data loss or security incidents caused by factors outside HEART Global's reasonable control, including cyberattacks, force majeure events, or failures of third-party infrastructure. ▸ Any claim arising from a client's breach of the Client Service Agreement or this Policy.
Nothing in this Policy excludes or limits liability that cannot be lawfully excluded, including liability for death or personal injury caused by negligence, or liability for fraudulent misrepresentation.
Our maximum liability is capped at the service fees paid. We are not liable for academic/grade consequences, hacks, server failures, or third-party telecom downtimes.
18. Governing Law & Dispute Resolution
18.1 — Governing Law This Policy is governed by and construed in accordance with the laws of Bangladesh, including but not limited to the Cyber Security Act 2023 (CSA 2023), the Information and Communication Technology (ICT) Act 2006, and applicable contract law.
18.2 — Dispute Resolution — Three-Stage Process ▸ Stage 1 — Negotiation: Client submits a written complaint. Parties attempt resolution in good faith within 14 days. ▸ Stage 2 — Mediation: If unresolved, parties engage a neutral mediator in Dhaka. Mediation costs shared equally, resolved within 30 days. ▸ Stage 3 — Arbitration/Courts: Binding arbitration under Bangladesh Arbitration Act 2001 in Dhaka, or submission to competent courts of Dhaka, Bangladesh.
For clients in the EEA/UK, HEART Global acknowledges the right to lodge a complaint with the relevant supervisory authority in your country of residence.
This policy aligns with Bangladesh Cyber Security Act 2023. Disputes follow a 3-step path: 14 days Negotiation ➔ 30 days Mediation ➔ Dhaka Courts / Arbitration Act 2001.
19. Amendments to This Policy
HEART Global reserves the right to update or modify this Policy at any time. The 'Effective Date' at the top of this document will reflect the date of the most recent revision.
Material changes — defined as changes that meaningfully alter client rights, data handling practices, or confidentiality commitments — will be communicated to active clients via email or WhatsApp at least 14 days prior to taking effect.
Your continued use of www.heart-global.org or any HEART Global service following the effective date of an updated Policy constitutes your acceptance of the revised terms. If you do not agree with any amendment, you must discontinue use and notify HEART Global in writing.
We review this policy annually and update it as services change. Material updates will be communicated to active clients via email or WhatsApp 14 days in advance.
20. Contact & Data Protection Queries
For any questions, concerns, or requests relating to this Privacy Policy, your personal data, or HEART Global's data practices, please contact:
▸ Organisation: HEART Global ▸ Website: www.heart-global.org ▸ Location: Dhaka, Bangladesh ▸ Data Queries: Submit via the Contact form on www.heart-global.org ▸ Response Time: Within 30 days of receipt of a written request
By using www.heart-global.org or engaging any service offered by HEART Global, you confirm that you have read, understood, and agree to be bound by this Privacy & Data Protection Policy in its entirety. This Policy was prepared with legal advisory input and reflects HEART Global's genuine commitment to responsible, transparent, and lawful data stewardship.
For all privacy queries, data export requests, or erasure demands, submit a query via the website Contact form. We reply to all requests within 30 days.
Concerned about your personal data?
HEART Global is fully committed to absolute privacy. We voluntarially adhere to GDPR-equivalent structures. Contact our operations team for any details regarding data access, corrections, or erasure.