Legal
Privacy Policy
This Privacy Policy explains how E GRAHOK (“E GRAHOK”, “we”, “us”) collects, uses, discloses, and safeguards personal data when you visit our websites, use our membership sites, or use our paid subscription mobile applications (together, the “Services”), and describes the rights you have over your data. We are the data controller for the processing described here.
1. Controller & contact
E GRAHOK, House 56, Road 6, Block G, Banasree, Dhaka-1219, Bangladesh, is responsible for your personal data. For any privacy question or to exercise your rights, contact our privacy team at contact@egrahok.com.
If you are in the EU/EEA or UK and believe we are required to appoint a representative or data protection officer, contact us at the address above and we will provide the current details.
2. Data we collect
a. Data you provide
- Account data – name or display name, email address, password (stored hashed), country, and language preference.
- Purchase & billing data – subscription plan, order history, billing country, partial card details (such as card type and last four digits), and transaction identifiers. Full card numbers are collected and processed directly by our payment processors, not stored by us.
- Profile & preferences – playlists, bookmarks, followed topics, playback settings, and other choices you make in the Services.
- Support & communications – messages, attachments, and contact details when you email us, use a contact form, or interact with us on social media.
- User content – reviews, ratings, and feedback you choose to submit.
b. Data collected automatically
- Device & app data – device model, operating system and version, app version, language, mobile network, and device identifiers.
- Usage & listening activity – content you view or play, play duration and progress, features used, referring pages, and interaction events.
- Log data – IP address, access times, crash logs, and diagnostic data.
- Approximate location – derived from your IP address for security, tax, content licensing, and analytics. We do not collect precise GPS location unless you grant permission for a specific feature.
- Cookies & SDKs – see Section 5.
c. Data from third parties
- Payment processors – payment confirmation, fraud signals, and chargeback information.
- App stores – subscription status, renewal and cancellation events, and refund events for Store-billed purchases.
- Sign-in providers – if you register with a third-party login, we receive your name and email as permitted by that provider and your settings.
- Analytics & attribution providers – aggregated install and campaign data.
3. How we use data
- create and manage your Account and provide the Services;
- process payments, manage Subscriptions, renewals, cancellations, and refunds, and prevent payment fraud;
- remember your preferences and personalise content recommendations and playback;
- provide customer support and respond to your requests;
- send service messages (for example, receipts, renewal reminders, security alerts, and policy updates);
- send marketing communications where you have opted in or where otherwise permitted, subject to your right to opt out;
- monitor, secure, debug, and improve the Services, and develop new features;
- produce aggregated and de-identified statistics;
- comply with legal, tax, accounting, and regulatory obligations, and enforce our terms and protect our rights.
4. Legal bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Services and your Account; processing Subscriptions and payments | Performance of a contract |
| Security, fraud prevention, service improvement, aggregated analytics, defending legal claims | Legitimate interests |
| Non-essential cookies, optional analytics/marketing SDKs, marketing emails where consent is required | Consent |
| Tax, accounting, and responding to lawful requests from authorities | Legal obligation |
You can withdraw consent at any time; this does not affect processing already carried out.
7. Service providers & sub-processors
We use vetted providers under data-processing agreements. The categories below reflect the types of providers we use; a current named list is available on request from contact@egrahok.com.
| Category | Purpose |
|---|---|
| Payment processing | Take card and local-method payments, manage billing, detect fraud |
| App distribution & in-app billing | Distribute apps and process Store-billed Subscriptions |
| Cloud hosting & content delivery | Host the Services, databases, and stream audio content |
| Email & notification delivery | Send transactional and (opted-in) marketing messages and push notifications |
| Product analytics & crash reporting | Understand usage, diagnose errors, improve stability |
| Customer support tooling | Manage and respond to support requests |
8. International data transfers
We operate globally, and personal data may be processed in countries other than yours, including Bangladesh and countries where our providers operate. Where we transfer data out of the EEA, UK, or other regions with transfer restrictions, we use a lawful transfer mechanism such as an adequacy decision or the applicable Standard Contractual Clauses (with the UK Addendum where relevant), together with additional safeguards where needed. You can request a copy of the relevant safeguards from contact@egrahok.com.
9. Data retention
We keep personal data for as long as needed for the purposes described in this policy:
- Account & profile data – for the life of your Account, then deleted or de-identified within a reasonable period after closure.
- Transaction, invoice, and tax records – retained for the period required by applicable tax and accounting law (commonly 5–10 years).
- Support communications – typically up to 24–36 months after the matter is resolved.
- Logs and analytics data – typically retained in identifiable form for up to 14 months, then aggregated or deleted.
- Fraud, abuse, and legal-hold data – retained as long as necessary to protect our rights or comply with law.
10. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls and least-privilege permissions, hashed passwords, network protection, logging and monitoring, and staff confidentiality obligations. No method of transmission or storage is completely secure; if we become aware of a personal-data breach that legally requires notification, we will notify the relevant authorities and affected users as required.
11. Your privacy rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- Access – obtain a copy of the data we hold about you;
- Rectification – correct inaccurate or incomplete data;
- Erasure – ask us to delete your data in certain circumstances;
- Restriction – ask us to limit processing in certain circumstances;
- Portability – receive certain data in a structured, machine-readable format;
- Objection – object to processing based on legitimate interests, and to direct marketing at any time;
- Withdraw consent – where processing is based on consent;
- Complain – lodge a complaint with your local data protection authority.
To exercise a right, email contact@egrahok.com from the address on your Account or give us enough information to verify your identity. We respond within the timeframe required by applicable law (for the GDPR, generally within one month). We will not discriminate against you for exercising your rights. An authorised agent may submit a request on your behalf with proof of authorisation.
12. US state privacy rights
If you are a resident of California or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect and how we use and disclose it, to request access to and deletion or correction of your personal information, and to opt out of the “sale” or “sharing” of personal information and of certain targeted advertising. As stated above, we do not sell or share personal information in this sense, and we do not use sensitive personal information for purposes that require an opt-out. To make a request, contact contact@egrahok.com. You may appeal a decision by replying to our response.
13. Children’s privacy
The Services are not directed to children under 13, and we do not knowingly collect personal data from children under 13 (or under 16 in parts of the EEA) without verifiable parental consent. If you believe a child has provided us personal data, contact contact@egrahok.com and we will delete it.
14. Marketing communications
You can opt out of marketing emails at any time using the unsubscribe link in the message or by contacting us. We will still send you non-promotional service messages related to your Account and purchases. You can control push notifications in your device settings.
15. Automated decisions & profiling
We use limited profiling to recommend content and to detect fraud and abuse. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. If this changes, we will update this policy and provide the disclosures required by law.
16. Third-party links
The Services may link to third-party sites and services that we do not control. This policy does not apply to them; please review their privacy policies.
17. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will notify you by email or an in-product notice before it takes effect where required. The “Last updated” date shows the current version.
18. How to contact us & complain
Privacy team: contact@egrahok.com
Postal: E GRAHOK, House 56, Road 6, Block G, Banasree, Dhaka-1219, Bangladesh
If you are in the EEA or UK and are not satisfied with our response, you have the right to complain to your local supervisory authority. We would appreciate the chance to address your concerns first.