১. ভূমিকা
Jynx ("আমরা", "আমাদের", "অ্যাপ্লিকেশন") একটি সামাজিক গেমিং প্ল্যাটফর্ম যা খেলোয়াড়দের সংযুক্ত হতে, টিম গঠন করতে এবং একসাথে খেলতে দেয়।
আইনি তথ্য:
- আইনি সত্তা: Jynx Group
- গোপনীয়তা কর্মকর্তা যোগাযোগ: [email protected]
- EU / EEA jurisdiction: France, European Union — this Privacy Policy complies with Regulation (EU) 2016/679 (GDPR) and Directive 2002/58/EC (ePrivacy), as transposed in France.
- Brazilian jurisdiction: This Privacy Policy also complies with Brazilian Law nº 13.709/2018 (Lei Geral de Proteção de Dados, "LGPD"), which applies to Jynx's processing of personal data of data subjects located in Brazil under Art. 3 of the LGPD, regardless of Jynx having no establishment in Brazil.
For the purposes of the LGPD, Jynx Group is the controller (controlador) of your personal data. Our Data Protection Officer acts as the encarregado (DPO) and may be reached at [email protected] for any request relating to the LGPD. Although Jynx qualifies as a pequeno agente de tratamento de dados pessoais (small-scale agent) under ANPD Resolution CD/ANPD nº 2/2022, which exempts Jynx from the obligatory appointment of an encarregado, Jynx voluntarily maintains this published communication channel.
এই গোপনীয়তা নীতি বর্ণনা করে কীভাবে আমরা আপনার ব্যক্তিগত ডেটা সংগ্রহ, ব্যবহার, শেয়ার এবং সুরক্ষিত করি যখন আপনি আমাদের অ্যাপ্লিকেশন ব্যবহার করেন।
২. ন্যূনতম বয়স এবং যাচাইকরণ
আমাদের অ্যাপ্লিকেশন ১৮ বছর এবং তার উপরের ব্যবহারকারীদের জন্য সংরক্ষিত।
আপনার অ্যাকাউন্ট তৈরি করার সময়, আমরা আপনাকে আপনার জন্ম তারিখ প্রদান করতে বলি। যদি আপনার বয়স ১৮ এর কম হয়, আপনি একটি অ্যাকাউন্ট তৈরি বা আমাদের পরিষেবা ব্যবহার করতে পারবেন না।
Marketing to minors. Jynx is restricted to users aged 18 and over and applies an automated age gate. If we subsequently identify that a user is under 18 (LGPD Art. 14; GDPR Art. 8), we will immediately terminate the account, exclude the user from all marketing, re-engagement, and survey communications, and delete the associated marketing data. We never knowingly collect marketing consent from a minor.
৩. সংগৃহীত ডেটা
৩.১. নিবন্ধন এবং প্রোফাইল ডেটা
আপনার অ্যাকাউন্ট তৈরি এবং পরিচালনা করার সময় আমরা নিম্নলিখিত তথ্য সংগ্রহ করি:
প্রমাণীকরণ তথ্য:
- ইমেল (ইমেল/পাসওয়ার্ড অ্যাকাউন্টের জন্য)
- ব্যবহারকারীর নাম/ডাকনাম
- প্রোফাইল ছবি (ঐচ্ছিক)
- সামাজিক লগইন শনাক্তকারী (Google, Apple) যদি আপনি এই পদ্ধতিগুলি ব্যবহার করেন
প্রোফাইল তথ্য:
- জন্ম তারিখ (বয়স যাচাইকরণের জন্য)
- দেশ এবং টাইমজোন
- কথ্য ভাষা
- জীবনী (ঐচ্ছিক)
- গেমিং পছন্দ এবং প্রাপ্যতা
- অনন্য হ্যান্ডেল (ব্যক্তিগত বন্ধু আবিষ্কারের জন্য স্বয়ংক্রিয়ভাবে তৈরি)
৩.২. গেমিং ডেটা
সামঞ্জস্যপূর্ণ সতীর্থ খুঁজে পেতে আপনাকে সাহায্য করতে, আমরা সংগ্রহ করি:
গেম প্রোফাইল:
- আপনি যে গেমগুলি খেলেন
- স্তর, র্যাঙ্ক এবং গেম পরিসংখ্যান
- প্রিয় চ্যাম্পিয়ন/চরিত্র
- খেলার স্টাইল
Riot Games API একীকরণ:
আমরা Riot Games API থেকে পুনরুদ্ধার করি (আপনার সম্মতি সহ):
- সামনার নাম এবং Riot ID
- র্যাঙ্ক এবং ম্যাচ ইতিহাস (League of Legends, Valorant, ইত্যাদি)
- চ্যাম্পিয়ন পরিসংখ্যান
- সাম্প্রতিক ম্যাচ ইতিহাস
সংগ্রহের কারণ: আপনার খেলোয়াড় প্রোফাইল প্রদর্শন এবং অন্যান্য খেলোয়াড়দের সাথে ম্যাচিং উন্নত করুন।
৩.৩. ব্যবহার এবং প্রযুক্তিগত ডেটা
আমরা স্বয়ংক্রিয়ভাবে নির্দিষ্ট প্রযুক্তিগত ডেটা সংগ্রহ করি:
বিশ্লেষণ এবং পারফরম্যান্স:
- Firebase Performance Monitoring: অ্যাপ স্টার্টআপ সময়, ইন্টারফেস সাবলীলতা
- Sentry: ত্রুটি এবং পারফরম্যান্স রিপোর্ট (ব্যক্তিগত ডেটা বেনামীকরণ সহ)
- Firebase Crashlytics: ক্র্যাশ রিপোর্ট
ডিভাইস তথ্য:
- ডিভাইসের ধরন এবং মডেল
- অপারেটিং সিস্টেম সংস্করণ
- অ্যাপ্লিকেশন সংস্করণ
ব্যবহারকারীর আচরণ:
- পরিদর্শিত স্ক্রিন এবং ব্যবহৃত বৈশিষ্ট্য
- অ্যাপ্লিকেশনে ব্যয় করা সময়
- ইন্টারফেস ইন্টারঅ্যাকশন
আপনি সেটিংস > গোপনীয়তা > "বিশ্লেষণ সক্ষম করুন"-এ বিশ্লেষণ ডেটা সংগ্রহ অক্ষম করতে পারেন।
৩.৪. যোগাযোগ ডেটা
- বার্তা: কমিউনিটি চ্যাটে বার্তা, ব্যবহারকারীদের মধ্যে ব্যক্তিগত বার্তা, কথোপকথন ইতিহাস
- বিজ্ঞপ্তি: পুশ বিজ্ঞপ্তির জন্য FCM টোকেন (Firebase Cloud Messaging)
৩.৫. ব্যবহারকারী-উৎপন্ন বিষয়বস্তু
- আপলোড করা ছবি (প্রোফাইল ছবি, অতিরিক্ত ছবি)
- নিরাপত্তা এবং মডারেশন রিপোর্ট
- প্রসাধনী পছন্দ (অ্যাভাটার, ব্যাজ)
3.6. Voice Room Audio Data
Jynx offers real-time voice rooms that let you talk with the other participants while you play. Voice-room audio is captured from your microphone only after you grant the operating-system microphone permission and explicitly join a room; no audio is captured before both of those steps.
Jynx does not enable LiveKit's recording, transcription, Agent Insights, or Egress features. Voice-room audio is routed in real time by the LiveKit SFU (Selective Forwarding Unit) and is not recorded, stored, or persisted by Jynx or by LiveKit.
When you speak in a voice room, your audio is transmitted in real time to the other participants in that room, similar to how voice works in other voice-chat apps.
Voice-room audio is processed with your consent: you grant microphone permission and explicitly join a room before any audio is captured. You can withdraw consent at any time by leaving the room or by revoking microphone permission in your device settings.
৪. তৃতীয় পক্ষের পরিষেবা এবং ডেটা শেয়ারিং
৪.১. Firebase পরিষেবা (Google)
আমরা নিম্নলিখিত Firebase পরিষেবাগুলি ব্যবহার করি, সবগুলি GDPR সম্মত:
- Firebase Authentication: সুরক্ষিত ব্যবহারকারী অ্যাকাউন্ট পরিচালনা
- Cloud Firestore: আপনার প্রোফাইল এবং গেম ডেটা স্টোরেজ
- Firebase Storage: আপনার প্রোফাইল চিত্র হোস্টিং
- Cloud Functions: সুরক্ষিত ব্যাকএন্ড লজিক কার্যকর
- Firebase Cloud Messaging: পুশ বিজ্ঞপ্তি
- Firebase App Check: অপব্যবহার এবং বট থেকে সুরক্ষা
- Firebase Performance Monitoring: অ্যাপ পারফরম্যান্স মনিটরিং
- Firebase Crashlytics: ক্র্যাশ রিপোর্ট
Firebase গোপনীয়তা নীতি: https://firebase.google.com/support/privacy
৪.২. Sentry (ত্রুটি মনিটরিং)
আমরা ত্রুটি এবং পারফরম্যান্স ট্র্যাকিংয়ের জন্য Sentry ব্যবহার করি। সংগৃহীত ডেটা অন্তর্ভুক্ত:
- ত্রুটি ট্রেস
- প্রযুক্তিগত প্রেক্ষাপট (OS, অ্যাপ সংস্করণ)
Sentry গোপনীয়তা নীতি: https://sentry.io/privacy/
৪.৩. Riot Games API
যখন আপনি আপনার Riot Games অ্যাকাউন্ট সংযুক্ত করেন, আমরা অফিসিয়াল Riot Games API এর মাধ্যমে আপনার গেম পরিসংখ্যান পুনরুদ্ধার করি। এই ডেটা শুধুমাত্র আপনার প্রোফাইল প্রদর্শন এবং ম্যাচিং উন্নত করতে ব্যবহার করা হয়।
Riot Games গোপনীয়তা নীতি: https://www.riotgames.com/en/privacy-notice
4.4. Email Service Provider (Marketing & Survey Communications)
To deliver the marketing, re-engagement, and uninstall/churn-survey emails described in §5.6, Jynx uses a third-party email service provider (ESP) acting as a processor (GDPR Art. 28; LGPD Art. 39 — operador). The ESP processes your email address and minimal delivery data (e.g., send/bounce status) solely on Jynx's documented instructions, under a signed Data Processing Agreement.
- ESP identity, role, and location: Brevo (Brevo SAS, Paris, France) — our Email Service Provider and data processor under a signed Data Processing Agreement. Brevo Privacy Policy: https://www.brevo.com/legal/privacypolicy/
- Sub-processors: Brevo's current list of sub-processors is published in its Data Processing Agreement (Terms of Use): https://www.brevo.com/legal/termsofuse/
- International transfer basis: See §9. Brevo is headquartered in France (EU). Transfers to Brevo therefore benefit from the EU's protection regime under GDPR and, for Brazilian users, the ANPD adequacy decision for the EU (Resolution nº 32/2026) — no SCCs or additional mechanism are required.
We do not sell your personal data. No tracking pixels or hidden analytics are embedded in marketing emails without a separate legal basis disclosed in §5.6.
4.5. LiveKit Cloud (Real-Time Voice)
Jynx uses LiveKit Cloud as a processor (GDPR Art. 28; LGPD Art. 39 — operador) under a signed Data Processing Agreement to operate the real-time media infrastructure that routes voice-room audio between participants. LiveKit runs the Selective Forwarding Unit (SFU) that forwards each participant's audio stream to the others in real time.
Jynx does not enable LiveKit's recording, transcription, Agent Insights, or Egress features. Voice-room audio is routed in real time by the LiveKit SFU (Selective Forwarding Unit) and is not recorded, stored, or persisted by Jynx or by LiveKit.
LiveKit does retain operational session metadata — such as participant identities, room identifiers, connection timings, and quality metrics — for billing, abuse-prevention, and operational purposes under its Data Processing Addendum. This metadata is not used to identify you off-platform or for advertising.
৫. ডেটা ব্যবহার
আমরা আপনার ডেটা ব্যবহার করি:
১. আমাদের পরিষেবা প্রদান:
- আপনার অ্যাকাউন্ট তৈরি এবং পরিচালনা
- আপনাকে অন্যান্য খেলোয়াড়দের সাথে সংযুক্ত করতে অনুমতি দিন
- টিম তৈরি এবং গেমিং সেশন সংগঠনে সহায়তা
২. ব্যক্তিগতকরণ:
- সামঞ্জস্যপূর্ণ সতীর্থ সুপারিশ (গেম-ভিত্তিক, র্যাঙ্ক, স্টাইল ম্যাচিং)
- প্রাসঙ্গিক বিষয়বস্তু প্রদর্শন
৩. যোগাযোগ:
- আপনাকে গুরুত্বপূর্ণ বিজ্ঞপ্তি পাঠান (ম্যাচ পাওয়া, বার্তা প্রাপ্ত)
Marketing, re-engagement, and uninstall/churn-survey emails are described separately in §5.6 Marketing Communications and are not covered by this transactional category.
৪. পরিষেবা উন্নতি:
- বৈশিষ্ট্য উন্নত করতে ব্যবহার বিশ্লেষণ
- বাগ সনাক্ত এবং সমাধান
- পারফরম্যান্স অপ্টিমাইজ করুন
৫. নিরাপত্তা এবং সম্মতি:
- প্রতারণা এবং অপব্যবহার প্রতিরোধ
- আমাদের ব্যবহারের শর্তাবলী প্রয়োগ করুন
- আইনি বাধ্যবাধকতা মেনে চলুন
5.6. Marketing Communications
In addition to the operational notifications described in §5.3, we may send you marketing and re-engagement communications by email, including: product updates and feature announcements about the Jynx app; newsletters; re-engagement messages inviting you back to the app; and short uninstall or churn feedback surveys (e.g., "Why did you stop using Jynx?"). These communications are distinct from transactional/service notifications.
Legal basis — European Union / EEA users (GDPR + ePrivacy). Because the Service is currently provided without remuneration (no paid tier is purchasable at the date of this Policy), marketing and re-engagement emails to EU/EEA users are sent only on the basis of your prior explicit opt-in consent (ePrivacy Directive Art. 13(1), transposed in France by Article L. 34-5 of the Code des postes et des communications électroniques; GDPR Art. 6(1)(a) and Art. 7). We do not rely on the "soft opt-in" exception of ePrivacy Art. 13(2) at this time, because that exception requires a "sale" within the meaning of the CJEU judgment C-654/23 (13 Nov 2025) and the Service is not yet remunerated. We will re-assess this analysis if and when a paid premium tier or any other monetization (in-app purchases, advertising, data licensing) goes live, and this Policy will be updated accordingly.
Legal basis — Brazilian users (LGPD). For Brazilian users, marketing and re-engagement communications rely on two alternative legal bases:
- Consent (LGPD Art. 7, I and Art. 8) — captured as a separate, un-ticked, purpose-specific opt-in at signup or in-app, recorded with date, form version, and language; you may withdraw it at any time, free of charge, without losing access to the Service (Art. 8 §5). Consent is the basis used for any communication to prospects, cold outreach, or cross-sell/partner offers beyond the core Jynx app.
- Legitimate interest (LGPD Art. 7, IX, elaborated by Art. 10) — used only for existing or recently-lapsed users receiving re-engagement messages, product updates about the same Jynx app, or a single short churn/uninstall feedback survey. Before relying on this basis, Jynx conducts and documents a Legitimate Interests Assessment (LIA) following the three-phase test of the ANPD Legitimate Interest Guide (2 Feb 2024): (i) purpose, (ii) necessity, and (iii) balancing and safeguards. The LIA records the prior relationship, the user's reasonable expectations, the purpose, the least-intrusive means chosen, and the opt-out channel. Legitimate interest is not used for cold/unsolicited email, unrelated cross-sell, purchased lists, or persistent messaging to departed users after the relationship has clearly ended.
Right to object / opt-out. Brazilian users may at any time oppose this processing and opt out via the mechanisms in §7.5 and §7.6 (one-click unsubscribe in every email, or the in-app communications-preferences toggle), without cost and without terminating the account. We honor opt-out requests in real time. The Brazilian Consumer Defense Code (CDC, Law 8.078/90, in particular Art. 39 III) prohibits unsolicited or abusive commercial messaging; we therefore strictly respect opt-outs and apply frequency caps, since persistent or ignored-opt-out sending may be treated as an abusive practice.
Uninstall / churn surveys. Wherever operationally feasible we ask uninstall/churn questions in-app at the uninstall moment (no email retention required). Where an email survey is sent, the survey contains no promotional or re-engagement content; we send a maximum of one (1) survey per user within approximately 60 days of account deletion or uninstall; the email address is then deleted or anonymized in accordance with §6; and users who have submitted an erasure / right-to-be-forgotten request (§7.3) are never re-contacted and are placed on a permanent suppression list (see §6 and the Terms of Service §7.2).
Email tracking. Marketing emails do not embed tracking pixels or hidden analytics that process personal data without a separate legal basis. Where any open/click tracking is introduced, it will be disclosed here and based on consent (LGPD Art. 8; ePrivacy Art. 5(3)), consistent with the ANPD guidance on tracking technologies (18 Oct 2022).
Frequency. Marketing emails are subject to internal frequency caps; you can reduce or turn them off at any time via the in-app communications-preferences toggle or by clicking unsubscribe in any message.
৬. ডেটা ধারণ
৬.১. ধারণ সময়কাল
- প্রোফাইল ডেটা: যতক্ষণ আপনার অ্যাকাউন্ট সক্রিয় থাকে ততক্ষণ ধরে রাখা হয়
- লগ এবং বিশ্লেষণ: Firebase Analytics: ১৪ মাস (Firebase নীতি)
- Marketing email addresses (consent-based): Retained for as long as you have not opted out or deleted your account, plus a hashed record on the suppression list (see below) to ensure we do not re-contact you
- Uninstall / churn survey email addresses: Retained for a maximum of 60 days after the survey is sent (or, if no survey is sent, 60 days after uninstall/deletion), after which the address is deleted or irreversibly anonymized. No more than one (1) survey email is sent per user
- Re-engagement of recently-lapsed accounts (LGPD legitimate-interest basis, Brazilian users only): Consistent with CNIL guidance and the reasonable-expectations test, Jynx may use the email address of a recently-lapsed (non-erasure) account for re-engagement for up to 3 years after the last meaningful interaction, after which it is deleted or anonymized
৬.২. ডেটা মুছে ফেলা
আপনি যেকোনো সময় আপনার অ্যাকাউন্ট মুছে ফেলার অনুরোধ করতে পারেন (দেখুন ধারা ৭)।
আইনি ধারণ: আমাদের আইনি বাধ্যবাধকতা মেনে চলতে কিছু ডেটা আরও দীর্ঘ সময় ধরে রাখা হতে পারে (যেমন, নিরাপত্তা রিপোর্ট, আর্থিক লেনদেন)।
When you delete your account, we purge your email address from our marketing CRM and email service provider. If you exercise the right to erasure (§7.3 / GDPR Art. 17 / LGPD Art. 18(VI) for consent-based data), your email address is added to a permanent hashed suppression list so that it is never re-used for marketing, re-engagement, or surveys — including protection against re-import via any third-party or purchased list. Note: under the LGPD, Art. 18(VI) deletion applies to data processed on the basis of consent; data processed on the basis of legitimate interest (Art. 7 IX) is instead governed by the purpose-limitation principle (Art. 6 II and §2) and your right to request cessation of processing (Art. 18 §2).
৭. আপনার অধিকার (GDPR)
GDPR এর অধীনে, আপনার নিম্নলিখিত অধিকার রয়েছে:
৭.১. অ্যাক্সেসের অধিকার
আপনি আমাদের কাছে থাকা সমস্ত ডেটার একটি কপি অনুরোধ করতে পারেন।
এই অধিকার প্রয়োগ করার উপায়: সেটিংস > গোপনীয়তা > "আমার ডেটা রপ্তানি করুন"
প্রক্রিয়াটি আপনার সমস্ত ডেটা (প্রোফাইল, বার্তা, পরিসংখ্যান, ইত্যাদি) সম্বলিত একটি JSON ফাইল তৈরি করে। ডাউনলোড লিঙ্ক ৭ দিনের জন্য বৈধ।
৭.২. সংশোধনের অধিকার
আপনি যেকোনো সময় অ্যাপ্লিকেশন থেকে আপনার প্রোফাইল তথ্য সংশোধন করতে পারেন (ব্যবহারকারীর নাম, জীবনী, পছন্দ, ইত্যাদি)।
৭.৩. মুছে ফেলার অধিকার ("ভুলে যাওয়ার অধিকার")
আপনি আপনার অ্যাকাউন্ট মুছে ফেলার অনুরোধ করতে পারেন।
এই অধিকার প্রয়োগ করার উপায়: সেটিংস > বিপদ অঞ্চল > "আমার অ্যাকাউন্ট মুছুন"
স্বয়ংক্রিয় মুছে ফেলার প্রক্রিয়া:
- দুর্ঘটনাজনিত মুছে ফেলা রোধ করতে দুই-পদক্ষেপ নিশ্চিতকরণ
- আপনার ব্যক্তিগত ডেটার তাৎক্ষণিক বেনামীকরণ (Firestore)
- আপনার Firebase Authentication অ্যাকাউন্ট মুছে ফেলা (স্বয়ংক্রিয়ভাবে সমস্ত OAuth টোকেন প্রত্যাহার করে)
- একটি বেনামী ID রেফারেন্স হিসাবে প্রদান করা হয়
- আপনার বার্তা এবং তৈরি বিষয়বস্তু মুছে ফেলার বিকল্প
গুরুত্বপূর্ণ: মুছে ফেলা অপরিবর্তনীয়। কিছু বেনামী ডেটা পরিসংখ্যানগত উদ্দেশ্যে ধরে রাখা হতে পারে (GDPR-সম্মত)।
ম্যানুয়াল মুছে ফেলার অনুরোধ: নির্দিষ্ট ডেটা মুছে ফেলার অনুরোধের জন্য (যেমন, শুধুমাত্র একটি নির্দিষ্ট কমিউনিটি থেকে বার্তা মুছুন, Storage ছবি মুছুন, বা অন্যান্য প্রান্তিক ক্ষেত্রে), অনুগ্রহ করে [email protected] এ আমাদের ডেটা সুরক্ষা কর্মকর্তার সাথে যোগাযোগ করুন। আমরা GDPR দ্বারা প্রয়োজনীয় ৩০ দিনের মধ্যে ম্যানুয়াল অনুরোধ প্রক্রিয়া করব।
৭.৪. ডেটা পোর্টেবিলিটির অধিকার
ডেটা রপ্তানি (ধারা ৭.১) আপনাকে একটি কাঠামোগত, মেশিন-পাঠযোগ্য বিন্যাসে (JSON) আপনার ডেটা পুনরুদ্ধার করতে দেয়।
৭.৫. আপত্তির অধিকার
আপনি সরাসরি বিপণন উদ্দেশ্যে আপনার ডেটা প্রক্রিয়াকরণে আপত্তি জানাতে পারেন।
- One-click unsubscribe: every marketing email includes a one-click unsubscribe link (RFC 8058 List-Unsubscribe-Post) honored in real time
- In-app toggle: Settings > Privacy > Communications Preferences
- Email: [email protected]
৭.৬. সম্মতি প্রত্যাহার করার অধিকার
আপনি আপনার সম্মতি প্রত্যাহার করতে পারেন:
- বিশ্লেষণ: সেটিংস > গোপনীয়তা > "বিশ্লেষণ সক্ষম করুন" অক্ষম করুন
- পুশ বিজ্ঞপ্তি: ডিভাইস সেটিংস
- Marketing Communications: Newsletter, product updates, re-engagement, and uninstall/churn surveys — withdrawable via one-click unsubscribe, the in-app communications-preferences toggle, or [email protected], without terminating your account
নোট: OAuth টোকেন (Google, Apple) স্বয়ংক্রিয়ভাবে প্রত্যাহার করা হয় যখন আপনি আপনার অ্যাকাউন্ট মুছে ফেলেন (ধারা ৭.৩)।
Withdrawal does not affect the lawfulness of processing carried out before withdrawal (GDPR Art. 7(3); LGPD Art. 8 §5), and withdrawing consent never requires you to delete your account.
7.7. Additional LGPD Rights (Brazilian Users)
In addition to the rights above, data subjects located in Brazil have the following rights under LGPD Art. 18: confirmation of the existence of processing; access to the data; correction of incomplete, inaccurate, or out-of-date data; anonymization, blocking, or deletion of unnecessary or excessive data (Art. 18(VI) applies to data processed on the basis of consent); portability to another service or product provider, upon request; deletion of personal data processed with consent; and information about the possibility of denying consent and the consequences of doing so.
You may exercise these rights via Settings > Privacy or by contacting the encarregado at [email protected]. You may also lodge a complaint with the Brazilian data protection authority — the Autoridade Nacional de Proteção de Dados (ANPD) — at https://www.gov.br/anpd.
৮. ডেটা নিরাপত্তা
আমরা আপনার ডেটা সুরক্ষিত রাখতে প্রযুক্তিগত এবং সাংগঠনিক নিরাপত্তা ব্যবস্থা প্রয়োগ করি:
- এনক্রিপশন: HTTPS এর মাধ্যমে সুরক্ষিত যোগাযোগ
- Firebase নিরাপত্তা নিয়ম: Firestore ডেটায় কঠোর অ্যাক্সেস নিয়ন্ত্রণ
- প্রমাণীকরণ: Firebase Auth এর মাধ্যমে সুরক্ষিত সেশন পরিচালনা
- ইনপুট যাচাইকরণ: SecureTextInput এর মাধ্যমে XSS ইনজেকশন প্রতিরোধ
- রেট লিমিটিং: অপব্যবহার থেকে সুরক্ষা (স্প্যাম বার্তা, স্বয়ংক্রিয় ক্রিয়া)
- মডারেশন: বিষয়বস্তু রিপোর্টিং এবং মডারেশন সিস্টেম
- Real-time voice: Voice-room media is encrypted in transit using WebRTC DTLS-SRTP, the same standard used by mainstream voice apps; signaling between the app and our servers is over HTTPS/TLS.
কোনও সিস্টেম ১০০% সুরক্ষিত নয়। ডেটা লঙ্ঘনের ক্ষেত্রে, আমরা GDPR সম্মতিতে (৭২ ঘন্টার মধ্যে) আপনাকে অবহিত করব।
৯. আন্তর্জাতিক ডেটা স্থানান্তর
আপনার ডেটা ইউরোপীয় ইউনিয়নের বাইরে অবস্থিত সার্ভারে স্থানান্তরিত এবং সংরক্ষণ করা হতে পারে, সহ:
- Google Cloud / Firebase: GDPR সম্মতি সহ বৈশ্বিক অবকাঠামো ব্যবহার করে
- Sentry: Privacy Shield সম্মতি সহ US-ভিত্তিক সার্ভার
- Email Service Provider (ESP): Used to deliver the marketing, re-engagement, and survey communications described in §5.6. The ESP is named in §4.4 and acts as a processor under a signed Data Processing Agreement
- LiveKit (real-time voice): LiveKit is our processor for voice-room audio under a signed Data Processing Agreement (see §4.5). As described in §3.6 and §4.5, voice-room audio is routed in real time and is not recorded, stored, or persisted by Jynx or by LiveKit. The applicable international-transfer mechanism for LiveKit will be confirmed before the voice feature is enabled for users. Accordingly, the general EU/EEA and Brazilian transfer guarantees set out below do not yet extend to LiveKit; they will be updated to reflect the confirmed mechanism before voice launches.
Guarantees (GDPR, EU/EEA). All transfers from the EU/EEA are covered by an adequacy decision, the EU-US Data Privacy Framework, or standard contractual clauses, together with supplementary measures where required.
Guarantees (LGPD, Brazil). Transfers of Brazilian users' personal data are governed by LGPD Art. 33:
- To Jynx Group in France (controller): Lawful under LGPD Art. 33(I) by virtue of ANPD Resolution CD/ANPD nº 32/2026 (in force 26 January 2026), which recognizes the European Union — including France — as providing an adequate level of protection. No additional transfer mechanism is required for this leg. (This adequacy decision is subject to reassessment by the ANPD within four years; if suspended, Jynx will implement an alternative Art. 33 mechanism such as the ANPD standard contractual clauses.)
- To Brevo in France (email ESP, processor): Lawful under LGPD Art. 33(I) by virtue of the same ANPD Resolution CD/ANPD nº 32/2026 (in force 26 January 2026), which recognizes the European Union — including France — as providing an adequate level of protection. No additional transfer mechanism is required for this leg. (Subject to the same ANPD reassessment described above; if the adequacy decision is suspended, Jynx will implement an alternative Art. 33 mechanism such as the ANPD standard contractual clauses with Brevo.)
Historical note: the one-year grace period for adapting existing contracts to the ANPD SCCs ended on 23 August 2025; new processor relationships such as the ESP execute the SCCs at onboarding.
১০. কুকিজ এবং অনুরূপ প্রযুক্তি
আমাদের মোবাইল অ্যাপ্লিকেশন ঐতিহ্যগত অর্থে কুকিজ ব্যবহার করে না, তবে ব্যবহার করে:
- প্রমাণীকরণ টোকেন: সুরক্ষিত পদ্ধতিতে স্থানীয়ভাবে সংরক্ষিত
- স্থানীয় ক্যাশ: পারফরম্যান্স উন্নত করতে (প্রোফাইল ডেটা, সাম্প্রতিক বার্তা)
১১. এই নীতির পরিবর্তন
আমরা এই গোপনীয়তা নীতি আপডেট করতে পারি। বড় পরিবর্তনের ক্ষেত্রে, আমরা আপনাকে অবহিত করব:
- একটি ইন-অ্যাপ বিজ্ঞপ্তির মাধ্যমে
- আপনার অ্যাকাউন্টের সাথে সম্পর্কিত ইমেল ঠিকানায়
১২. আমাদের সাথে যোগাযোগ করুন
এই গোপনীয়তা নীতি সম্পর্কে যেকোনো প্রশ্ন বা আপনার অধিকার প্রয়োগ করার জন্য:
তদারকি কর্তৃপক্ষ: If you believe your rights have not been respected, you may lodge a complaint:
- EU/EEA users: with the CNIL (Commission Nationale de l'Informatique et des Libertés), France — https://www.cnil.fr
- Brazilian users: with the ANPD (Autoridade Nacional de Proteção de Dados), Brazil — https://www.gov.br/anpd
Filing a complaint with a supervisory authority does not prejudice your right to seek other judicial remedies available to you, including the mandatory consumer protections that apply in your jurisdiction (e.g., the Brazilian Consumer Defense Code, Law 8.078/90).
১৩. সম্মতি
We process your personal data only where we have a lawful basis. The lawful bases we rely on, and where each is described in this Policy, are:
- Performance of a contract / provision of the Service (GDPR Art. 6(1)(b); LGPD Art. 7, V) — account, matching, and messaging (§5.1–5.3)
- Legitimate interests (GDPR Art. 6(1)(f); LGPD Art. 7, IX and Art. 10) — security, fraud prevention, service improvement, and (for Brazilian users) marketing/re-engagement/survey communications to existing or recently-lapsed users as described in §5.6, each supported by a documented balancing assessment
- Legal obligation (GDPR Art. 6(1)(c); LGPD Art. 7, II) — retention for legal purposes (§6)
- Consent (GDPR Art. 6(1)(a); LGPD Art. 7, I and Art. 8) — analytics where you have enabled them, push notifications, and (for EU/EEA users and for Brazilian prospects/cold/cross-sell sends) marketing communications per §5.6
- Voice-room audio is processed on the basis of your consent (GDPR Art. 6(1)(a); LGPD Art. 7, I and Art. 8) when you grant microphone permission and explicitly join a room (see §3.6); you may withdraw it at any time by leaving the room or by revoking microphone permission in your device settings.
Consent must be specific and informed. Where we rely on your consent, it is given by a clear affirmative act, refers to specified purposes, and is captured separately from your acceptance of these terms (LGPD Art. 8 §1 — cláusula destacada). Generic or bundled authorizations are void under LGPD Art. 8 §4 and invalid under GDPR Art. 4(11) and Art. 7. Using Jynx does not by itself constitute consent to marketing. The burden of proving valid consent rests with Jynx (LGPD Art. 8 §2; GDPR Art. 7(1)); we therefore record the date, form version, language, and scope of each consent we collect.
Withdrawal. You may withdraw any consent at any time, through a procedure that is as easy as giving it and that does not require you to delete your account (LGPD Art. 8 §5; GDPR Art. 7(3)) — see §7.5 and §7.6. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Deleting your account (§7.3) remains available at any time but is not the mechanism for withdrawing a specific consent.