BNF Digital upholds the following core principles in managing data protection:
Information is collected and handled through fair and transparent means
Data is held strictly for clearly defined, legitimate, and lawful purposes
All data is kept secure and protected at all times
Information is maintained in an accurate, complete, and current state
Only data that is necessary and relevant is collected — nothing beyond that
Data is not held beyond the period for which it is genuinely needed
Data Transfer
All company data in transit is safeguarded against unauthorized access, leakage, or misuse
Personal data of individuals is not shared outside the organization, except in the following situations:
Where the individual has given explicit consent, or where both parties have reached a mutual agreement
When sharing is required by regulatory authorities or auditors
Where disclosure is mandated or permitted under applicable law
Storage of Sensitive Data
Sensitive company data is categorized and managed in accordance with the information handling guidelines outlined in the Asset Management and Information Classification Policy
Physical copies of sensitive data are secured in locked storage cabinets
Sensitive Data
The following categories of organizational information are classified as sensitive and require appropriate protection:
Research and development data
Contracts and agreements with vendors
Annual revenue figures and monthly supply chain plans
Personal data of employees, customers, and clients
Privacy and Protection of Personally Identifiable Information (PII)
Robust privacy measures and consistently enforced information security controls are in place to ensure the protection of personal data
Access to employee personal data is granted only to specifically authorized individuals. These security controls cover:
Ensuring all information is collected, processed, and used fairly, lawfully, and appropriately
Verifying that information remains accurate, complete, current, and proportionate to its purpose
Proper sanitization and deletion of information when no longer required
All personal records are maintained and stored in a secure manner
Guidelines for Data Privacy
Access to sensitive data is granted strictly on a need-to-know basis
Controls are in place to prevent employees and third-party personnel from accessing personally identifiable information for unauthorized purposes
Users responsible for handling personal records are accountable for ensuring their secure storage, appropriate retention, and proper disposal
Backup data stored on removable media must be kept in a safe and controlled environment
Violations involving the breach of privacy or unauthorized access to BNF Digital’s or personal data will be met with appropriate disciplinary measures
Policy for Website Visitors
What we collect and what we don’t:
Information we collect: Name, email address, date of birth, age, device type, device ID, contact details, gender, location, PIN code, area code, and occupation
Information we do not collect: Passwords, bank account details, credit or debit card information, secure PINs, banking credentials, physical or mental health data, sexual orientation, medical history, biometric data, national identification numbers, or any other sensitive personal information
How the collected data is used:
For users: Data is used to improve overall user experience, deliver personalized content, offer premium services, and notify users of new releases or updates
For clients and BNF Digital: Data is used to derive insights, analyze user behavior, generate reports, and inform go-to-market strategies