Home/GDPR & DPDP

Trust

Data protection compliance statement

How we meet our obligations under the UK GDPR, the EU GDPR and India's Digital Personal Data Protection Act, 2023 — and what we can put in writing for your compliance team.

DocumentData protection compliance statement
Applies toZeplinix Technologies Private Limited and all its products and services
Version1.0
Effective date15 July 2026
Review cycleAnnually, or on material change to processing or law
OwnerData Protection Officer, Zeplinix Technologies Private Limited
Contacthello@zeplinix.com
FrameworksUK GDPR · EU GDPR · DPDP Act, 2023 (India)

1Purpose of this statement

1.1
This statement is written for compliance, procurement and security teams assessing us as a supplier. It is a summary of our position; the binding terms are in the Data Processing Agreement and the Privacy Policy.
1.2
Where this statement and the DPA differ, the DPA prevails.

2Our role

2.1
For records submitted for validation, verification, enrichment or collection, you are the controller and we are the processor. We process only on your documented instructions.
2.2
For our own website, correspondence and internal operations we act as controller, and our basis for that processing is set out in clause 6 of the Privacy Policy.
2.3
We are not a joint controller with any customer, and we do not act as an independent controller of customer records.

3Lawful basis

3.1
As processor we do not select the lawful basis; you do, as controller. Our obligation is to process only on your instructions and to tell you if an instruction appears to infringe the law.
3.2
For managed collection under Data Services, we work only with publicly available business information, gathered to a written brief, and we name the sources in the delivery note so your compliance team can trace the provenance of every field.
3.3
The specific basis for your use case — commonly legitimate interests for B2B marketing in the UK and EEA, assessed and documented by you — is confirmed in writing at scoping and recorded in the Order.
3.4
We do not rely on consent as a basis for processing customer records, and we do not purport to have obtained consent from the individuals in those records.

4Data minimisation and purpose limitation

4.1
We process only the fields required to deliver the Service you have bought. The field set is agreed with you when your workspace is configured.
4.2
We ask customers not to submit special category data, criminal offence data, payment data, government identifiers or children's data, and we do not knowingly process any of it.
4.3
We do not repurpose customer records. They are not added to a database of ours, not used to enrich another customer's file, and not sold, licensed or shared.

5Data subject and Data Principal rights

5.1
Individuals have the rights set out in Applicable Law: to be informed, of access, to rectification, to erasure, to restriction, to portability, to object, and not to be subject to solely automated decisions with legal or similarly significant effect.
5.2
Where a request reaches us and relates to data we hold as processor, we forward it to you within 5 business days and do not respond substantively ourselves. We then assist you in locating, exporting, correcting or deleting the records.
5.3
Where a request relates to data we hold as controller, we action it within 30 days, without charge.
5.4
We do not carry out automated decision-making within the meaning of Article 22 GDPR. Our output is an advisory verdict with a documented reason, returned to you to act on.

6International transfers

6.1
We are established in India. Transfers of UK and EEA personal data to us are made under the Standard Contractual Clauses, Module Two, with the UK Addendum where the UK GDPR applies. These are incorporated into the DPA.
6.2
A transfer impact assessment is maintained and provided on request. It addresses the legal regime in India, the practical likelihood of public authority access to business contact data of the kind we process, and the supplementary measures we apply.
6.3
We do not onward-transfer customer records to any jurisdiction other than those disclosed in Annex 3 of the DPA.

7Subprocessors

7.1
We use a small number of subprocessors for cloud hosting, email delivery infrastructure and run-time verification services.
7.2
The list — legal entity, service, data processed and country of processing — is provided in full on request. We give 30 days written notice before adding or replacing one, and you may object on reasonable data protection grounds.
7.3
Every subprocessor is bound by terms no less protective than those we owe you, and we remain liable for their performance.

8Retention and deletion

8.1
Records are used only to deliver the Service and are deleted when the campaign is removed, and in all cases within 90 days of receipt.
8.2
On termination all remaining records are deleted within 30 days. Backups clear on their normal rotation, which completes within 35 days.
8.3
Deletion is confirmed in writing where you ask for it. Earlier deletion on written request is actioned within 5 business days.

9Security

9.1
Technical and organisational measures are listed in full in Annex 2 of the DPA. In summary: TLS 1.2+ in transit; AES-256 at rest; a dedicated processing workspace per customer with no shared tenancy; named, least-privilege, logged access with MFA on administrative accounts; annual vulnerability scanning; and no requirement for us to hold credentials to any of your systems.
9.2
Certification status. Our controls are built and documented against the SOC 2 Trust Services Criteria. We have not completed a third-party audit and we do not claim a SOC 2 report. We state this before being asked, and there is no certification badge anywhere on this website.

10Personal data breach

10.1
We notify you of a personal data breach affecting your data without undue delay and in any event within 24 hours of becoming aware of it — well inside the 72-hour window within which you must notify your supervisory authority.
10.2
The notification includes the nature of the breach, the categories and approximate number of records affected, the likely consequences and the measures taken, with further detail supplied in phases as the assessment develops.
10.3
We will not identify you publicly in connection with a breach without your prior written consent, unless legally compelled.

11Records and accountability

11.1
We maintain a record of processing activities carried out on behalf of customers, and make the relevant extract available on request.
11.2
We maintain a data protection policy set, a retention schedule, an access control procedure and an incident response procedure, all reviewed at least annually.
11.3
Personnel receive data protection training on induction and annually thereafter.

12India — Digital Personal Data Protection Act, 2023

12.1
The DPDP Act applies to us as an Indian company. Under the Act, a customer instructing us is the Data Fiduciary and we are the Data Processor; our processing is governed by the DPA between us.
12.2
We support Data Principal rights under the Act, including the right to access, correction and erasure, the right to nominate another individual to exercise rights, and the right of grievance redressal — by forwarding requests to the relevant Data Fiduciary and assisting in the response.
12.3
Grievances may be raised with our Data Protection Officer using the contact details in clause 14. Where a grievance is not resolved to your satisfaction, it may be escalated to the Data Protection Board of India once constituted.
12.4
We will publish the name and direct contact details of a designated Grievance Officer in this clause once that appointment is formalised.

13Documentation we provide

13.1
On request we provide: the signable Data Processing Agreement; the Standard Contractual Clauses with annexes completed; the subprocessor list; the security overview; the transfer impact assessment; the retention schedule; and completed security questionnaires.
13.2
Security questionnaires are completed in 5 business days. We do not require an NDA to answer a questionnaire, though we will sign yours if you prefer.

14Contact and complaints

14.1

How to contact us, and how to complain

Write to the Data Protection Officer, Zeplinix Technologies Private Limited, 310, Tower 1, World Trade Center, Kharadi, Pune 411014, Maharashtra, India, or email hello@zeplinix.com. We acknowledge within 5 business days and respond substantively within 30 days.

If you are not satisfied with our response you may complain to your local supervisory authority. In the EU that is the authority in your country of residence or work; in the UK it is the Information Commissioner's Office. In India you may escalate to the Data Protection Board of India once it is constituted under the Digital Personal Data Protection Act, 2023.

Version 1.0 · effective 15 July 2026 · Zeplinix Technologies Private Limited · hello@zeplinix.com