Last updated: June 10, 2025 · Operated by IT Myanmar · itmyanmar.com
Contents
Portal.OS is an internal developer infrastructure management platform operated by IT Myanmar. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. By accessing this portal, you acknowledge and agree to the practices described below.
Account Information
Username, email address, hashed password, and assigned role (ADMIN, TEAM_LEAD, DEV, USER). This is provided by an administrator when your account is provisioned.
Authentication Data
Signed JSON Web Tokens (JWT) stored in HTTP-only cookies to maintain your session. If you choose 'Remember Me', the session persists for 30 days; otherwise it expires after 24 hours.
Activity & Audit Logs
Every significant action (login, logout, password changes, project access, user management) is recorded with a timestamp, actor identity, and action category for security and compliance purposes.
Project & Infrastructure Data
Project names, server hostnames, environment types, and assignment relationships between users and projects. No production secrets or credentials are stored in this portal.
Uploaded Files
Database backup files uploaded through the portal are stored in AWS S3 (ap-southeast-1 region). Files are accessible only through time-limited pre-signed URLs.
Code & DevOps Snippets
Snippets and request templates you create are stored and associated with your account. They are only visible to you and administrators.
Authentication & Access Control
To verify your identity and enforce role-based access to portal features and resources.
Security & Audit Trail
Activity logs are retained to detect unauthorized access, investigate incidents, and maintain an auditable record of system changes.
Transactional Email
We send account credentials and password reset links to your registered email address via Resend (resend.com). We do not send marketing emails.
Infrastructure Management
Project and server data is used to display assignments, track backup status, and monitor project health.
Database
All account and application data is stored in a MySQL/MariaDB database hosted on a private server within a controlled network environment.
Password Security
Passwords are hashed using bcrypt (cost factor 10) before storage. Plain-text passwords are never stored or logged.
Password Reset Tokens
Reset tokens are stored as SHA-256 hashes in the database. The raw token is sent only via email and expires after 10 minutes. Each token is single-use.
File Storage
Uploaded files are stored in AWS S3 with separate read/write credentials. Downloads are served through short-lived pre-signed URLs.
Data in Transit
All communication between your browser and this portal is encrypted via HTTPS/TLS in production.
We do not sell, rent, or share your personal data with third parties for commercial purposes. Data is shared only with the following service providers as necessary to operate the portal:
AWS (Amazon Web Services)
File storage via S3 in the ap-southeast-1 (Singapore) region.
Resend
Transactional email delivery. Only your email address, username, and relevant token/credential are shared for this purpose.
Account Data
Retained for as long as your account is active. Deleted accounts have their personal data removed; audit log entries referencing the account are anonymized (actorId set to null).
Audit Logs
Retained indefinitely for security and compliance purposes.
Password Reset Tokens
Automatically expired after 10 minutes and nulled upon use.
Uploaded Files
Database backups are retained in S3 according to the backup configuration set by administrators.
As a user of this internal platform, you have the following rights regarding your personal data:
Access
You can view your own account information and activity within the portal.
Password Change
You can change your password at any time from your account settings.
Data Deletion
Contact your system administrator to request account deletion or data removal.
Correction
Contact an administrator to correct inaccurate account information.
We may update this Privacy Policy as the platform evolves. The 'Last Updated' date at the top of this page reflects the most recent revision. Continued use of the portal after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or how your data is handled, please contact the system administrator at [email protected].
© 2026 IT Myanmar. All rights reserved.
← Return to Portal.OS