Home/Trust

Trust

GDPR

How Zeplinix meets its obligations under the UK and EU General Data Protection Regulation, and what we can put in writing for your compliance team.

Draft for legal review. This page is structured and written to be completed by counsel. Bracketed fields are decisions the business has to make; nothing here has been reviewed by a lawyer and it should not be published until it has.

Our role

For customer records we act as a processor and you act as the controller. Our processing instructions are set out in the Data Processing Agreement.

Lawful basis for B2B contact data

[CONFIRM — this is the question enterprise procurement asks first, particularly for Data Services collection. Write a specific, defensible answer with counsel rather than a general statement.]

Data subject requests

Actioned within [CONFIRM] days. Where we hold data as a processor, we forward the request to the controller and assist them in responding.

International transfers

Standard Contractual Clauses for EU and UK transfers, with a transfer impact assessment available on request.

Subprocessors

Published at /subprocessors, with advance notice of additions.

Retention and deletion

Records are used only for validation and deleted when the campaign is removed, or earlier on written request. Deletion is confirmed in writing where you ask for it.

Breach notification

[CONFIRM: notification window and process — must be no longer than 72 hours to the controller.]

Documentation we can provide

DPA, subprocessor list, security overview, transfer impact assessment, and completed security questionnaires. Request them at vidhan@zeplinix.com.

Last updated [CONFIRM date] · Questions: vidhan@zeplinix.com

Free assessment

Questions before you sign anything?

Send your security questionnaire or your paper — we complete both in writing.

No commitment and no card · vidhan@zeplinix.com · +91 84590 17737