At Sugi Aishodo Co., Ltd., we are committed to protecting your personal information collected through our website and services.
Sugi Aishodo Co., Ltd. (hereinafter designated as "the Company," "we," "us," or "our") is a formally incorporated joint venture established on December 26, 2024, operating strictly under the legal framework and jurisdiction of the People's Republic of Bangladesh. This comprehensive Privacy & Data Protection Policy governs the methodologies by which the Company systematically collects, utilizes, archives, processes, and safeguards the personal data of individuals ("Data Subjects"). This encompasses interactions across our primary digital domain (www.sugiaishodo.com), our retail marque “Aisugi Japan”, mobile applications, and all corollary digital or physical touchpoints.
This document is meticulously formulated to ensure total compliance with the statutory provisions of Bangladesh, explicitly including, but not limited to:
• The Digital Security Act, 2018 (Act No. 46 of 2018).
• The Bangladesh Telecommunication Act, 2001.
• The Consumer Rights Protection Act, 2009.
• The Contract Act, 1872.
• Relevant provisions concerning fraud and misrepresentation under the Penal Code, 1860.
• Prescriptive guidelines and directives issued by the Bangladesh Telecommunication Regulatory Commission (BTRC) and associated governmental authorities.
By accessing or leveraging our digital platforms, products, or services, you formally acknowledge that you have reviewed, comprehended, and consented to the stipulations delineated herein. Individuals withholding consent are respectfully instructed to cease interaction with our platforms and services immediately.
The authorized entity acting as the Data Controller with fiduciary responsibility for your personal data is legally defined as follows:
• Corporate Entity: Sugi Aishodo Co., Ltd.
• Registered Japanese Nomenclature:
• Coporate Domicile: House No. 22, Road No. 06, Gulshan-1, Dhaka-1212, Bangladesh.
• Executive Administration: Himu Uddin, Managing Director.
• Official Contact Coordinates: Telephone: +880 1324 251399 | Email: info@sugiaishodo.com.
• Digital Domain: www.sugiaishodo.com.
All formal inquiries, privacy-related grievances, or statutory requests must be directed to the aforementioned email address utilizing the mandatory subject line "Privacy Inquiry".
The Company maintains a structured approach to data acquisition, categorized by the nature of the Data Subject's interaction:
• Information Actively Furnished by the Data Subject: This includes complete nomenclature, telephonic and postal coordinates, and account authentication credentials (username and password). Furthermore, it encompasses granular transaction data, billing addresses, and communication preferences. Financial instruments are processed via secured third-party gateways; the Company explicitly refrains from storing comprehensive cryptographic card data locally. Participation metrics concerning promotional campaigns or loyalty programs are also aggregated.
• Automated Telemetry and Analytical Data: Passive digital engagement yields essential operational data, including IP addresses, unique device identifiers, browser taxonomies, and operating system profiles. The Company also logs navigational heuristics, session duration, approximate geolocations, and telemetry sourced from cookies and equivalent tracking architectures.
• Data Procured via Third-Party Integrations: To facilitate seamless commercial operations, data is routinely synchronized with authorized payment processors and logistics partners. Where lawful and procedurally requisite, supplementary verification data may be sourced from public registries or our parent conglomerates, Sugi Holdings Co., Ltd. and Aishodo Co., Ltd.
The Company adheres strictly to the principle of purpose limitation, processing personal data solely for legitimate and predefined operational imperatives:
• Execution of Contractual Obligations: Personal data is intrinsically required to orchestrate order fulfillment, manage fiscal transactions, coordinate dispatch logistics, and administrate return protocols. This encompasses the proactive communication of order statuses and comprehensive account management architectures, representing a foundational necessity for contractual performance.
• Client Relations and Statutory Fulfillment: Data utilization is critical for resolving inquiries, managing grievances, and providing post-sale support. This processing is legally validated by our legitimate interest in client retention and our strict adherence to the mandates of the Consumer Rights Protection Act, 2009.
• Regulatory Adherence: The processing of data is mandatory to satisfy Bangladeshi statutory compliance, specifically encompassing the preservation of commercial transaction records, adherence to taxation frameworks, and responsiveness to lawful directives from government authorities.
• Security Architecture and Fraud Preemption: The Company leverages data analytics to detect, investigate, and neutralize unauthorized, fraudulent, or malicious activities. This is an essential pillar in safeguarding the proprietary rights and safety of the Company, its clientele, and the broader public.
• Strategic Marketing Initiatives: Promotional communications regarding inventory or corporate events are disseminated strictly where the Data Subject has granted explicit consent, or where expressly permitted by prevailing law. This consent may be unequivocally revoked at any juncture via designated unsubscribe mechanisms.
The Company categorically prohibits the sale, rental, or unauthorized commercialization of personal data to external entities. Dissemination is strictly confined to the following constrained parameters:
• Vetted Service Providers: We strategically engage specialized third-party entities to support enterprise operations, including logistics conglomerates, IT infrastructure providers, and payment processors. Such entities are governed by rigorous contractual obligations mandating strict adherence to this Policy.
• Parent Entities: Functioning as a synergistic joint venture, the Company may share operational and statistical data with its parent entities based in Japan (Sugi Holdings Co., Ltd. and Aishodo Co., Ltd.) to ensure quality assurance. This exchange is executed under ironclad confidentiality agreements and in full compliance with Bangladeshi law.
• Collaborative Retail Partnerships: Authorized transaction data may be selectively transmitted to our primary retail partner, Unimart, strictly to facilitate collaborative in-store operations. Such transfers are rigidly regulated by bespoke data-sharing agreements.
• Law Enforcement and Judicial Authorities: The Company maintains full compliance with lawful data requests initiated by judicial, regulatory, or law enforcement bodies, as mandated by the Digital Security Act, 2018, and the ICT Act, 2006.
By virtue of the Company's structural relationship with its Japanese parent corporations, selected personal data may necessitate transmission to or processing within the jurisdiction of Japan. To mitigate transnational risk, the Company enforces robust contractual safeguards ensuring the preservation of data at a security parity equal to, or exceeding, the rigorous standards delineated by Bangladeshi jurisprudence, most notably the Digital Security Act, 2018.
The Company retains personal data strictly for the temporal duration requisite to satisfy the defined processing purposes, or as commanded by statutory imperatives.
• Transactional Archives: Commercial and purchasing records are maintained for an irreducible minimum of seven (7) years to guarantee financial compliance under Bangladeshi taxation law.
• Account Lifecycles: Client profile data is sustained throughout the active lifespan of the account, extending to a maximum threshold of three (3) years post-termination.
• Regulatory Directives: Data requisitioned for legal compliance is preserved for the exact duration mandated by the presiding regulatory authority.
• Data Annihilation: Upon the exhaustion of lawful retention cycles, personal data is subjected to secure digital eradication or irrevocable anonymization to permanently prevent re-identification.
In alignment with advanced international privacy frameworks and Bangladeshi law, Data Subjects are inherently vested with the following unalienable rights:
• The Right of Access and Rectification: You possess the entitlement to demand comprehensive copies of your archived data and to mandate the immediate rectification of any inaccurate or partial records.
• The Right of Erasure and Restriction: Subject to superseding legal retention obligations, you may compel the systematic deletion of your data or demand the cessation of specific processing activities.
• The Right to Object and Withdraw Consent: You may actively oppose the utilization of your data for direct marketing objectives. Furthermore, consent-based processing may be rescinded at any time, without prejudice to the lawfulness of activities conducted prior to withdrawal.
• The Right to Regulatory Redress: Should you determine your data has been handled unlawfully, you reserve the right to escalate formal grievances to the Bangladesh Telecommunication Regulatory Commission (BTRC).
Execution of Rights: To activate any aforementioned right, a formal written petition must be submitted to info@sugiaishodo.com. The Company is legally bound to adjudicate and respond to such petitions within a standard timeframe of thirty (30) days. Stringent identity verification protocols may be enforced prior to the execution of any data modification.
To optimize digital functionality and refine enterprise marketing analytics, the Company’s platforms integrate cookies—specialized cryptographic text files deposited onto user hardware.
• Technological Typology: We utilize Strictly Necessary Cookies for essential platform mechanics (e.g., transactional workflows), Performance and Analytics Cookies to audit user engagement metrics, Functional Cookies to preserve localized preferences, and Marketing Cookies to calibrate advertising efficacy.
• User Sovereignty: Data Subjects retain the agency to modulate cookie permissions via localized browser configurations. It must be noted that the truncation of critical cookies may degrade platform operability. Persistent navigation of our domain constitutes informed consent to this technological framework.
The Company has engineered formidable technical and organizational countermeasures designed to inoculate personal data against unauthorized extraction, accidental destruction, or malicious alteration.
• Defensive Protocols: These defenses include pervasive Secure Socket Layer (SSL) encryption for data in transit, strict hierarchical access controls, mandatory personnel compliance training, and exhaustive, systemic security audits.
• Breach Response Dynamics: In the highly unlikely event of a catastrophic data compromise presenting risks to user freedoms, the Company will execute predetermined incident response protocols. This guarantees expedited notifications to affected Data Subjects and pertinent regulatory authorities without undue delay, in strict compliance with the Digital Security Act, 2018.
• Jurisdictional Governance: The interpretation and enforcement of this Policy are governed exclusively by the laws of the People's Republic of Bangladesh. Any arising legal disputes fall strictly under the sole jurisdiction of the Bangladeshi judicial system. The Company advocates for amicable pre-litigation dialogue via info@sugiaishodo.com prior to the initiation of formal legal remedies.
• Dynamic Revisions: The Company reserves the unilateral prerogative to amend, refine, or augment this Policy to mirror technological evolution or shifts in statutory paradigms. Material alterations will be actively communicated via email or prominent digital notifications. Continuous utilization of the Company's services post-modification constitutes irrevocable acceptance of the revised framework.