Official Policy

Privacy Policy

Sinan Arcana

Prepared for Sinan Arcana (The Team Phoenix Group Pvt Ltd). This document describes how we operate https://sinanarcana.io and how we handle information in line with responsible cybersecurity and data-protection practice.

Document version
1.3
Effective date
15 September 2026
Last reviewed
15 September 2026

Registered address: BSCIC Electronics Complex, Level-05, Mirpur-11, Dhaka, Bangladesh.

Governing jurisdiction: Bangladesh.

Active incident response: +880 9658-100200 (recorded lines; see Privacy Section 4a).

1. Who we are

Sinan Arcana is the commercial cybersecurity division of The Team Phoenix Group Pvt Ltd. We provide managed detection and response, incident response, forensics, threat intelligence, assessments, and advisory services. This notice covers sinanarcana.io and related marketing forms.

Data protection contact: privacy@sinanarcana.io. Emergency security matters: +880 9658-100200. Recorded hotlines play a disclosure at call start; see Section 4a.

Roles: for sinanarcana.io contact forms, Sinan Arcana (TTPG Pvt Ltd) is the controller. For MDR and incident response under contract, we typically act as processor (or sub-processor) per your Data Processing Agreement; you remain controller for client environment data.

2. Categories of data

  • Business contact data: name, title, organisation, email, phone, and procurement details.
  • Service and incident data: when you engage us, we process technical logs, indicators of compromise, forensic artefacts, and communications necessary to defend your environment (typically under a Data Processing Agreement where we act as processor).
  • Website telemetry: IP, user agent, pages viewed, and security logs including WAF events.
  • Hotline recordings and chat transcripts where you consent or where recording is necessary for quality and legal compliance during active incidents.

3. Purposes

Marketing site data is used to respond to inquiries, scope services, and maintain client relationships. Service data is used strictly for security operations, contractual reporting, regulatory evidence where applicable, and improving detection content. We do not use client telemetry to train public models without contractual permission.

Response-time and recovery statistics shown on the marketing site are illustrative and are not contractual SLAs unless stated in a signed agreement.

3b. Legal bases (website and marketing)

For sinanarcana.io contact forms and marketing leads we rely on: (a) pre-contract steps and legitimate interests to respond to inquiries and scope services; (b) consent where required for optional cookies or non-essential communications; (c) contractual necessity when you become a client; (d) legal obligation for lawful requests and record-keeping. Service and incident data under contract is processed per your DPA and Section 4b.

4. Security and confidentiality

We maintain forensic chain-of-custody procedures, segregated environments for client evidence, encryption in transit and at rest for sensitive artefacts, background checks for personnel with privileged access, and incident response playbooks aligned with NIST SP 800-61. Subprocessors are assessed annually; a summary of subprocessor categories is available on request and listed in client DPAs where applicable.

4a. Hotline and recordings

Purpose: quality assurance, dispute resolution, and continuity during active security incidents. Legal basis: consent where announced at call start; otherwise legitimate interests or contractual necessity for incident response. Callers hear a recording disclosure at the start of recorded lines and may request a non-recorded callback where operationally feasible. Call metadata: twelve (12) months. Recordings: ninety (90) days after case closure unless litigation hold or contract requires longer (up to seven (7) years for regulated engagements). Access is limited to authorized IR and quality staff; telephony subprocessors are bound by contract. No marketing or AI training use without explicit consent.

Website chat transcripts (where offered): collected only after in-chat notice and consent where required; used for inquiry response, quality, and dispute resolution; retained twenty-four (24) months from last message unless an active incident or litigation hold applies; access limited to authorized staff; no marketing or public-model training use without explicit consent; telephony and chat subprocessors are bound by contract.

4b. Incidents affecting client data

Where we process personal data on your behalf, we notify you without undue delay after confirming a personal-data breach affecting your environment, and in any event within forty-eight (48) hours where feasible, with information to support your regulatory notifications.

4c. Law enforcement and forensics

Forensic preservation may involve cooperation with law enforcement under valid Bangladesh legal process, including the Digital Security Act 2018 and ICT Act 2006. We document disclosures and notify clients where contractually required.

4d. Breaches affecting website visitors

Where a personal-data breach affects sinanarcana.io marketing or contact-form data we control, we assess without undue delay and notify affected individuals and relevant authorities when required by law or when the breach poses material risk, targeting seventy-two (72) hours after confirmation.

5. Retention

Marketing leads: twenty-four (24) months after last contact unless a client relationship continues. Incident and forensic records: per contract and legal hold requirements, typically three (3) to seven (7) years for regulated clients. Security logs: twelve (12) months unless needed for investigation.

6. International processing

Client data may be processed in Bangladesh and, where agreed, in regional cloud regions with equivalent controls documented in contracts.

7. Your rights

Contact privacy@sinanarcana.io for access, correction, deletion, restriction, portability where technically feasible, or objection to processing based on legitimate interests where applicable. We respond within thirty (30) days where practicable. You may withdraw consent without affecting prior lawful processing. You may lodge a complaint with a competent supervisory authority. Active incident or forensic evidence may be temporarily exempt where preservation is required for investigation, litigation hold, or law enforcement cooperation.

8. Cookies and website telemetry

We currently use only essential and security cookies (including WAF telemetry) needed to operate sinanarcana.io. If we enable optional analytics later, we will load them only after consent via a site banner and update this policy before activation.

9. Changes

Updates posted on sinanarcana.io with revised effective date.

https://sinanarcana.ioEffective 15 September 2026v1.3