Intake Architecture (What We Collect)
- Telemetry. IP, browser type, interaction heatmaps to optimise UX.
- Acquisition. Corporate emails, phone numbers, job titles captured via B2B/B2C funnels.
- System. Server logs and API payloads from custom software deployments.
- Identity. Passports, national IDs, biometric data for cross-border movement.
- Financial ledgers. Bank statements and tax records for embassy validation.
- Academic / Medical. Transcripts and health clearances for student / work visas.
Operational Utilization
- Algorithmic Bidding. Anonymised telemetry feeds Meta / Google algorithms to lower CPA.
- Embassy Routing. Sensitive personal documents are collected solely to compile legal dossiers for sovereign embassies and BMET.
- System Integrity. Software logs are monitored to preempt server crashes or security vulnerabilities in deployed platforms.
The Vault (Storage & Security)
We do not store sensitive client data on local, unsecured hardware. All identity documents and database schemas are hosted on enterprise-grade cloud infrastructure (AWS / Supabase) using end-to-end AES-256 encryption.
3.1 Data Isolation. Lead generation databases belonging to one client are strictly siloed. Cross-contamination is structurally impossible.
3.2 Breach Protocol. In the unlikely event of a server compromise, automated systems lock down all data vaults and notify affected parties within 24 hours.
Third-Party Transmission
4.1 Strategic Partners. Tracking data routes through verified third parties: GA4, Vercel, Stripe (payment processing).
4.2 Sovereign Entities. For Consultancy clients, your data must be shared with immigration authorities, universities, and international employers to secure placement.
4.3 Zero-Sale Mandate. Miya Group will never broker, sell, or rent your personal identity data to unauthorised third-party data aggregators.
The Override Command (User Rights)
- Right to Audit. Request a complete JSON or PDF export of all personal data we hold on you.
- Right to Erasure. Command the complete deletion of your data from our active marketing servers. Note: legally mandated records (accounting, active visa processing) cannot be deleted until the retention period expires.
- Opt-Out Protocol. All automated marketing communications include a one-click unsubscribe that instantly severs your data from active email logic.
To request a data audit, initiate deletion, or speak with our DPO: privacy@miyagroupbd.com