PRIVACY POLICY FOR “CHITRA” - TRADING APPLICATION
Effective Date: 15-July-2026
Last Updated: 15-July-2026
1. Introduction
Chittagong Stock Exchange PLC (“CSE”, “we”, “us”, or “our”) operates the Chitra mobile trading application (“Chitra” or the “App”).
CSE is committed to protecting the privacy, confidentiality, integrity, and security of the personal and sensitive information processed through Chitra.
This Privacy Policy explains:
- what information Chitra accesses, collects, receives, processes, stores, or transmits;
- why such information is required;
- how the information is used and protected;
- with whom information may be shared;
- how long information may be retained;
- the rights and choices available to users; and
- how users may contact CSE regarding privacy or data-protection matters.
This Privacy Policy applies to the use of the Chitra mobile application and related services, systems, interfaces, application programming interfaces, notifications, and support facilities.
By using Chitra, you acknowledge that you have read and understood this Privacy Policy.
2. About Chitra
Chitra is a mobile trading application made available by or on behalf of Chittagong Stock Exchange PLC to eligible users of authorised Trading Members, brokers, dealers, and other approved market participants.
Depending on the services activated for a user, Chitra may allow the user to:
- sign in to an authorised trading account;
- view market information and market depth;
- access portfolio, holdings, balances, limits, orders, trades, and positions;
- submit, modify, or cancel orders;
- receive order, trade, market, account, risk, and system notifications;
- access reports, statements, contract information, announcements, and other trading-related services; and
- communicate with an authorised Trading Member or support service.
Chitra does not independently open a brokerage or trading account unless an account-opening facility is expressly made available within the App. Trading accounts, investor accounts, and associated credentials may be created, approved, maintained, suspended, or closed by the relevant Trading Member, broker, CSE, or another authorised market intermediary in accordance with applicable laws, regulations, and operating procedures.
3. Data Controller and Responsible Organisation
The organisation responsible for Chitra is:
Chittagong Stock Exchange PLC
CSE Building
1080 Sheikh Mujib Road
Agrabad, Chattogram
Bangladesh
CSE may process certain information as the operator of Chitra and the exchange infrastructure. The user’s Trading Member, broker, clearing participant, or another authorised intermediary may separately process information as an independent data controller or responsible organisation under its own privacy policy and legal obligations.
4. Information We May Collect and Process
The exact information processed may depend on the services used, the user’s relationship with the relevant Trading Member, the permissions granted, and the configuration of the App.
4.1 Identity and Account Information
Chitra may process:
- user ID, client code, investor account number, trading account number, dealer ID, or broker-assigned identifier;
- name and account display name;
- Trading Member, broker, branch, dealer, or account relationship;
- user role, account status, trading permissions, and market-segment permissions;
- account registration, activation, suspension, restriction, or closure information;
- login credentials in protected form; and
- authentication and verification information, including one-time passwords, security tokens, or multi-factor authentication status.
Passwords are not intended to be stored or displayed in plain readable form.
4.2 Contact Information
Where required for account management, authentication, notifications, or support, Chitra may process:
- mobile telephone number;
- email address;
- correspondence address or other contact information supplied through the relevant Trading Member or authorised system; and
- communication preferences.
4.3 Financial and Trading Information
As Chitra is a financial trading application, it may process personal and sensitive financial information, including:
- account balance, available balance, buying power, cash limit, exposure limit, and trading limit;
- securities holdings, portfolio details, positions, collateral, margin, and settlement information;
- order details, including instrument, price, quantity, order type, time, status, modification, cancellation, and rejection information;
- trade and transaction history;
- profit and loss information;
- fees, taxes, commissions, levies, and other charges;
- payment, pay-in, pay-out, settlement, and obligation information;
- bank or depository information where supplied by an authorised Trading Member or integrated service; and
- risk alerts, margin shortfalls, account restrictions, and compliance-related information.
Chitra does not access a user’s unrelated financial information stored elsewhere on the device unless such access is expressly required, disclosed, and permitted.
4.4 Market and App Activity Information
Chitra may collect or generate information about how the App is used, including:
- login and logout activity;
- screens, functions, market segments, instruments, reports, and features accessed;
- searches and watchlists;
- order-entry and transaction-related activity;
- date and time of actions;
- notification delivery or interaction status;
- session duration;
- application errors and performance information; and
- audit trails required for security, dispute resolution, regulatory compliance, and market integrity.
4.5 Device and Technical Information
For security, authentication, compatibility, diagnostics, and fraud prevention, Chitra may process:
- device model and manufacturer;
- operating system and application version;
- language and regional settings;
- Internet Protocol address;
- network and connection information;
- browser or embedded web-view information;
- session identifiers;
- application installation identifier;
- device or other identifiers made available through the operating system;
- crash reports, diagnostic logs, and performance information; and
- date and time of access.
CSE does not sell device identifiers. Chitra should not collect persistent hardware identifiers such as IMEI, IMSI, SIM serial number, or device serial number unless their use is legally permitted, necessary for an approved core function, and separately disclosed to the user.
4.6 Security and Authentication Information
Chitra may process:
- failed and successful login attempts;
- password-reset and account-recovery activity;
- one-time-password verification status;
- session and authentication tokens;
- suspicious access indicators;
- security alerts;
- device-registration or device-binding information;
- IP address and login-location indicators derived from network information; and
- information required to detect unauthorised access, account takeover, fraud, manipulation, misuse, or cyber incidents.
4.7 Notifications
Where notifications are enabled, Chitra may use a notification token or similar technical identifier to deliver:
- order and trade confirmations;
- account, margin, balance, position, or risk alerts;
- trading-session and market-status notifications;
- security and login alerts;
- system maintenance or service announcements;
- regulatory notices; and
- other service-related communications.
Users may control general notification permissions through their device settings. Certain important notices may also be communicated through another authorised channel.
4.8 Customer Support and Communications
If a user contacts CSE, a Trading Member, or application support, the following may be processed:
- name and contact information;
- account or client identifier;
- support request details;
- correspondence, complaint, feedback, or inquiry;
- attachments or screenshots voluntarily provided;
- call or communication records where legally permitted and appropriately disclosed; and
- actions taken to investigate and resolve the request.
Users should not send passwords, one-time passwords, PINs, or other confidential authentication credentials through ordinary email, chat, or support correspondence.
4.9 Permissions and Device Features
Depending on the version and functionality of Chitra, the App may request limited access to device features.
Any permission requested by Chitra must be used only for a disclosed and legitimate application function. Possible permissions may include:
- Internet and network access: to connect securely to CSE, Trading Member, market, and supporting systems;
- Notifications: to deliver trading, account, security, and service alerts;
- Biometric authentication: to allow authentication using a fingerprint, face recognition, or another device-supported biometric mechanism. Chitra normally receives only the authentication result and does not receive or store the underlying biometric template;
- Camera or file access: only where users are permitted to capture, select, or upload a document, profile image, complaint attachment, or other authorised material;
- Telephone or SMS-related access: only where strictly necessary for a disclosed feature and permitted under Google Play requirements and applicable law; and
- Location: only where expressly required for a disclosed security, regulatory, or account-protection function and only after obtaining the necessary permission.
Chitra will not access contacts, call logs, messages, photographs, videos, microphone, precise location, or other sensitive device information unless the access is necessary for an active feature, clearly disclosed, and authorised by the user.
Declining an optional permission may prevent the corresponding optional feature from operating but should not affect unrelated application functions.
5. How We Obtain Information
Information may be obtained:
- directly from the user;
- from the user’s Trading Member, broker, dealer, clearing participant, or authorised intermediary;
- from CSE’s trading, market-data, surveillance, clearing, risk-management, reporting, authentication, or support systems;
- automatically from the App and device when Chitra is used;
- from authorised service providers that support Chitra;
- from regulators, law-enforcement authorities, courts, or government agencies where permitted or required; and
- from records generated through the execution, confirmation, clearing, settlement, reporting, or supervision of transactions.
6. Purposes of Processing
CSE may process information for the following purposes:
6.1 Providing the App and Trading Services
- authenticating users and maintaining secure sessions;
- displaying account, portfolio, market, order, trade, position, and settlement information;
- enabling order entry, modification, cancellation, and related trading functions;
- routing requests to the relevant Trading Member, order-management system, matching engine, or authorised service;
- providing reports, statements, alerts, and notifications;
- maintaining watchlists and user preferences; and
- providing technical and customer support.
6.2 Transaction Processing and Recordkeeping
- processing, validating, routing, acknowledging, executing, recording, clearing, and settling orders and trades;
- maintaining transaction and audit records;
- calculating balances, limits, positions, exposure, margins, obligations, charges, and settlement amounts; and
- resolving transaction inquiries, complaints, corrections, and disputes.
6.3 Security and Fraud Prevention
- protecting user accounts and CSE systems;
- detecting suspicious logins, unauthorised activity, fraud, manipulation, abuse, malware, or cyberattacks;
- preventing account takeover;
- investigating security incidents;
- maintaining system and network security; and
- enforcing application, exchange, Trading Member, and security rules.
6.4 Regulatory, Legal, and Market-Supervision Purposes
- complying with applicable laws, regulations, rules, directives, orders, and regulatory requirements;
- monitoring trading activities and maintaining market integrity;
- conducting surveillance, inspection, investigation, and audit activities;
- responding to lawful requests from regulators, courts, law-enforcement agencies, and government authorities;
- meeting anti-money-laundering, counter-terrorist-financing, sanctions, identity-verification, recordkeeping, and reporting obligations where applicable; and
- establishing, exercising, or defending legal rights and claims.
6.5 Application Operation and Improvement
- monitoring application availability, stability, and performance;
- identifying and correcting errors;
- troubleshooting technical problems;
- maintaining compatibility with devices and operating systems;
- improving application functionality, usability, accessibility, and security; and
- producing aggregated or de-identified operational statistics.
6.6 Communications
- sending essential security, account, trading, transaction, market, regulatory, and service communications;
- responding to user inquiries and complaints; and
- communicating updates to this Privacy Policy or other applicable terms.
CSE will not use personal or sensitive financial information for unrelated advertising or sell such information to advertisers or data brokers.
7. Legal and Operational Basis for Processing
CSE processes information where processing is necessary:
- to provide Chitra and perform requested trading-related services;
- to administer the user’s relationship with CSE or an authorised Trading Member;
- to comply with legal, regulatory, exchange, surveillance, clearing, settlement, risk-management, and recordkeeping obligations;
- to protect the legitimate interests of CSE, Trading Members, investors, market participants, and the integrity and security of the capital market;
- to prevent fraud, misuse, security incidents, and unauthorised access;
- with the user’s consent where consent is required; or
- for another lawful purpose permitted under the laws of Bangladesh.
8. Sharing and Disclosure of Information
CSE does not sell personal or sensitive user data.
Information may be shared only as necessary with the following recipients.
8.1 Trading Members and Authorised Intermediaries
Information may be shared with or received from:
- the user’s Trading Member or broker;
- authorised dealers and branches;
- clearing members, clearing participants, custodians, and depository participants;
- settlement banks and payment-service providers;
- central counterparties, clearing and settlement systems, and depositories; and
- other authorised market intermediaries involved in providing services to the user.
8.2 CSE Systems and Authorised Personnel
Information may be processed by authorised CSE employees, officers, contractors, auditors, and systems, including trading, market-data, order-management, clearing, settlement, risk, surveillance, compliance, reporting, security, and support systems.
Access is intended to be limited according to role, responsibility, authorisation, and operational need.
8.3 Technology and Service Providers
CSE may use authorised service providers for:
- application hosting and infrastructure;
- connectivity and networking;
- authentication and one-time-password delivery;
- push notifications;
- system monitoring;
- cybersecurity;
- application maintenance and technical support;
- backup, disaster recovery, and data storage;
- analytics limited to application operation and performance; and
- communication services.
Such providers may process information only for authorised purposes and are expected to apply appropriate confidentiality, privacy, and security protections.
8.4 Regulators and Public Authorities
Information may be disclosed to:
- the Bangladesh Securities and Exchange Commission;
- courts and tribunals;
- law-enforcement agencies;
- government departments;
- tax, financial-intelligence, or other competent authorities; and
- any other body legally authorised to request the information.
Such disclosure may occur when required by law, regulation, legal process, regulatory direction, investigation, or an enforceable governmental request.
8.5 Corporate and Legal Events
Information may be disclosed where necessary:
- to establish, exercise, or defend legal claims;
- during an audit, investigation, restructuring, merger, acquisition, transfer, or reorganisation involving CSE;
- to protect the rights, property, systems, users, market participants, or safety of CSE or another person; or
- to prevent fraud, cyber incidents, misuse, market abuse, or other unlawful activity.
9. Third-Party Services and Software Development Kits
Chitra may contain or use third-party libraries, software development kits, APIs, notification services, security components, analytics components, or links necessary to provide application functions.
These technologies may process limited device, diagnostic, notification, security, or application-usage information.
CSE will seek to use such services only for legitimate application purposes. CSE is responsible for accurately declaring relevant collection and sharing performed through third-party code used in Chitra.
Where Chitra links to an external website or service not controlled by CSE, the privacy practices of that external service will be governed by its own privacy policy. Users should review the relevant third-party policy before providing information.
10. Data Security
10.1 Data Handling Lifecycle
Chitra processes user information throughout its lifecycle to provide secure trading services. Information may be collected directly from users, from authorised Trading Members (Brokers), from CSE systems, or automatically when users access and use the App.
Such information is securely transmitted to CSE systems using encrypted communication channels, processed only for legitimate business purposes including authentication, trading operations, regulatory compliance, customer support, security monitoring, and system administration, and retained only for as long as necessary to provide services and comply with applicable legal, regulatory, audit, security, and record-keeping requirements.
When information is no longer required and retention is not legally or operationally necessary, CSE takes reasonable measures to securely delete, anonymise, or otherwise dispose of such information in accordance with its data retention and security procedures.
10.2 Security Measures
CSE applies reasonable administrative, organisational, physical, and technical safeguards designed to protect personal and sensitive information against:
- unauthorised access;
- unlawful use or disclosure;
- accidental loss;
- alteration;
- destruction;
- misuse;
- malware;
- cyberattacks; and
- other security threats.
Depending on the information and system involved, safeguards may include:
- encryption of data during transmission using HTTPS (TLS/SSL encrypted communication);
- encryption or other protection for sensitive data stored on servers or devices where appropriate;
- secure authentication and session controls;
- password hashing or equivalent credential protection;
- multi-factor or one-time-password authentication where implemented;
- role-based access control and least-privilege access;
- maker-checker or approval controls where applicable;
- device, session, and login monitoring;
- network and infrastructure security controls;
- logging, audit trails, monitoring, and alerting;
- vulnerability management and security testing;
- secure software-development and change-management practices;
- backup, recovery, and business-continuity procedures;
- confidentiality obligations for authorised personnel and service providers; and
- incident-management and response procedures.
Personal and sensitive information transmitted between the Chitra application and CSE systems is protected using HTTPS (TLS/SSL encrypted communication) to help safeguard information against unauthorised access while in transit. Users should not share passwords, PINs, one-time passwords, security codes, or other authentication credentials with any person.
No system can guarantee absolute security. Accordingly, while CSE implements appropriate safeguards to protect personal and sensitive information, it cannot guarantee that unauthorised access or a security incident will never occur. Where required by applicable law or regulatory direction, CSE will take appropriate steps to investigate, mitigate, and respond to confirmed data-security incidents.
11. User Responsibilities for Security
Users should:
- maintain the confidentiality of login credentials;
- use a strong and unique password;
- never disclose a password, PIN, one-time password, or security code;
- keep the registered mobile number and email address secure;
- keep the device operating system and Chitra updated;
- use a secure device protected by a password, PIN, or biometric lock;
- avoid using rooted, jailbroken, compromised, or malware-infected devices;
- avoid trading through unknown or unsecured networks;
- log out after using the App where appropriate;
- immediately report suspected unauthorised access, lost devices, or fraudulent activity; and
- verify that Chitra was obtained from an authorised application store or source.
CSE or an authorised Trading Member will not normally request a user’s password, PIN, or one-time password through a telephone call, email, ordinary message, or social-media communication.
12. Data Retention
CSE retains personal, financial, trading, transaction, security, and audit information only for as long as reasonably necessary for:
- providing Chitra and related services;
- maintaining trading and transaction records;
- completing clearing and settlement;
- resolving complaints and disputes;
- preventing and investigating fraud or security incidents;
- maintaining audit trails;
- enforcing legal rights;
- meeting exchange, regulatory, tax, accounting, anti-money-laundering, surveillance, and legal obligations; and
- complying with directions from competent authorities.
Different categories of information may be retained for different periods.
Trading, financial, surveillance, compliance, audit, security, and transaction records may need to be retained after an account is deactivated or deleted where retention is required by law, regulation, regulatory direction, litigation hold, fraud-prevention requirement, or legitimate recordkeeping obligation.
When information is no longer required, CSE will take reasonable measures to delete, anonymise, aggregate, or securely dispose of it, subject to applicable legal, regulatory, backup, and archival requirements.
Information stored in backups may remain until the relevant backup is securely overwritten or expires under CSE’s backup-retention procedures.
13. Account Deactivation, Account Deletion, and Data-Deletion Requests
13.1 Accounts Managed by Trading Members
A Chitra login or trading account may be issued or managed by the user’s Trading Member or broker. Users seeking to deactivate or close such an account should contact the relevant Trading Member using its official support channel.
Closing or deleting access to Chitra does not automatically cancel pending orders, settle outstanding obligations, close a brokerage relationship, or remove records that CSE, the Trading Member, or another authorised institution must retain.
13.2 Account Deletion Requests
Chitra provides an in-app option informing users how they may request closure of their trading account.
Trading accounts and user relationships are created, maintained, and managed by the user's registered Trading Member (Broker), not by Chittagong Stock Exchange PLC (CSE). Accordingly, CSE cannot directly process requests to delete or close a user's trading account.
Users wishing to close their trading account should contact their registered Trading Member (Broker) through its official customer support channel. Once the Trading Member closes the trading account, the user's access to Chitra will automatically terminate.
Further information regarding account deletion requests is available at:
https://www.cse.com.bd/home/data_deletion_request
Please note that the closure of a trading account does not necessarily require deletion of all associated records. Certain information may continue to be retained where required by applicable laws, regulations, exchange rules, audit requirements, security purposes, fraud prevention, dispute resolution, or other legitimate legal and operational obligations.
13.3 Requesting Deletion or Correction of Data
Subject to applicable laws, regulations, and identity-verification requirements, users may request:
- correction of inaccurate personal information;
- deletion of information that is no longer required;
- deactivation or deletion of an application account;
- information about the categories of data held; or
- withdrawal of consent for optional processing based solely on consent.
Requests may be submitted through:
- the account or privacy function within Chitra, where available;
- the user’s authorised Trading Member;
- the account/data-deletion webpage; or
- CSE’s privacy contact identified below.
CSE or the relevant Trading Member may request sufficient information to verify the requester’s identity and authority before acting on the request.
Deletion requests may not result in deletion of records that must be retained for:
- regulatory compliance;
- legal obligations;
- market surveillance;
- clearing and settlement;
- taxation and accounting;
- fraud prevention;
- security;
- dispute resolution;
- enforcement of agreements; or
- establishment, exercise, or defence of legal claims.
CSE will explain, where reasonably possible, if certain requested information cannot be deleted.
14. User Rights and Choices
Subject to applicable laws and regulatory requirements, users may have the right to:
- request access to personal information relating to them;
- request correction of incomplete or inaccurate information;
- request deletion where retention is not legally or operationally required;
- withdraw consent for optional processing;
- disable optional permissions through device settings;
- control non-essential notifications through device settings;
- object to or inquire about particular processing activities; and
- lodge a complaint with CSE or another competent authority.
Disabling a permission or withdrawing consent may affect a feature that depends on that permission or processing.
Essential trading, security, regulatory, settlement, and transaction communications may continue where they are necessary to provide services or comply with legal obligations.
15. International or Cross-Border Processing
CSE primarily operates in Bangladesh. Certain authorised technology providers, vendors, support personnel, systems, or infrastructure may be located outside Bangladesh.
Where information is processed or supported from another jurisdiction, CSE will seek to implement appropriate contractual, organisational, and security controls and will process the information in accordance with applicable law and this Privacy Policy.
16. Children’s Privacy
Chitra is a financial trading application and is not directed to children.
Users must meet the legal, regulatory, contractual, and Trading Member eligibility requirements applicable to opening and operating a trading account.
CSE does not knowingly permit children to independently use Chitra unless such use is legally authorised, appropriately supervised, and supported by the required guardian, Trading Member, and regulatory arrangements.
If CSE becomes aware that information relating to a child has been processed without proper authority, CSE will take reasonable steps consistent with applicable law and regulatory requirements.
17. No Sale of Personal or Sensitive Data
CSE does not sell, rent, or trade personal or sensitive user data.
CSE does not share personal or sensitive financial information with advertisers or data brokers for targeted advertising.
Information is shared only for the operational, security, legal, regulatory, trading, clearing, settlement, support, and service-provider purposes described in this Privacy Policy.
18. Automated Processing and Risk Controls
Chitra and associated systems may use automated rules and calculations to:
- validate login and session activity;
- check account permissions;
- validate orders;
- calculate balances, margins, limits, exposures, obligations, or positions;
- identify suspicious activity;
- generate security or risk alerts;
- reject orders that breach configured limits or controls; and
- support market-surveillance and compliance functions.
These controls form part of the operation, security, and regulatory management of the trading service. Users may contact their Trading Member regarding an order rejection, restriction, account status, or trading decision.
19. Accuracy of Information
Users should ensure that information supplied to CSE or their Trading Member is accurate, complete, and current.
Users should promptly notify the relevant Trading Member when their registered contact details or other account information change.
Market, account, order, trade, position, and financial information displayed in Chitra may depend on information received from connected exchange, broker, order-management, clearing, settlement, banking, depository, and market-data systems.
20. Changes to This Privacy Policy
CSE may update this Privacy Policy to reflect:
- changes to Chitra;
- new features or services;
- changes in data-handling practices;
- security improvements;
- changes in service providers;
- changes in laws, regulations, or Google Play requirements; or
- regulatory or operational requirements.
The revised policy will be published on an active and publicly accessible webpage and may also be made available within Chitra.
The “Last Updated” date will indicate when the policy was most recently revised. Where required, users may be notified of material changes through the App or another appropriate communication channel.
21. Contact and Privacy Inquiries
For questions, concerns, complaints, correction requests, or data-deletion requests relating to this Privacy Policy or Chitra, users may contact:
Privacy Contact / Data Protection Contact
Chittagong Stock Exchange PLC
CSE Building
1080 Sheikh Mujib Road
Agrabad, Chattogram
Bangladesh
Email: it@cse.com.bd
Telephone: +8801711878386
Users should not include passwords, PINs, one-time passwords, or complete confidential authentication credentials in privacy-related correspondence.
22. Governing Law
This Privacy Policy and the processing of information through Chitra are subject to the applicable laws, regulations, rules, regulatory directions, and lawful requirements of Bangladesh.
23. Relationship with Other Terms
This Privacy Policy should be read together with:
- the Chitra Terms of Use;
- CSE website Usage Terms and Conditions;
- the terms and privacy policy of the user’s Trading Member or broker;
- applicable trading-account agreements;
- applicable exchange, clearing, settlement, and depository rules; and
- any consent, notice, or disclosure presented within Chitra.
Where there is a conflict concerning the processing of personal information, applicable law and regulatory requirements will prevail.
Developer and App Identification
Application Name: Chitra
Responsible Entity: Chittagong Stock Exchange PLC
Registered Office: CSE Building, 1080 Sheikh Mujib Road, Agrabad, Chattogram, Bangladesh
©2024 Chittagong Stock Exchange PLC. All rights reserved.

06:40:47 (BST)