Home/Privacy Policy

Legal

Privacy Policy

How Zeplinix Technologies Private Limited handles personal data — as a processor for records our customers submit, and as a controller for our own website and correspondence.

DocumentPrivacy Policy
Applies toZeplinix Technologies Private Limited and all its products and services
Version1.0
Effective date15 July 2026
Review cycleAnnually, or on material change to processing or law
OwnerData Protection Officer, Zeplinix Technologies Private Limited
Contacthello@zeplinix.com

1Who we are and what this policy covers

1.1
This policy is issued by Zeplinix Technologies Private Limited, a company incorporated in India with its registered office at 310, Tower 1, World Trade Center, Kharadi, Pune 411014, Maharashtra, India (“Zeplinix”, “we”, “us”).
1.2
It explains what personal data we process, on what basis, for how long, who we share it with, and what rights individuals have.
1.3
It applies to our website at zeplinix.com, to all products we operate (LeadQC, ZeMail Verify, ZeMail Find, ZeMail Send, Outrix, FormBot and Data Services), and to our business correspondence.
1.4
It does not form part of any contract of employment or services contract. Where a signed Data Processing Agreement is in place with a Customer, that agreement prevails over this policy in the event of conflict.

2Definitions

2.1
TermMeaning in this policy
ControllerThe party that determines why and how personal data is processed.
ProcessorThe party that processes personal data on the controller's instructions. Zeplinix is a processor for all records submitted for validation.
CustomerThe organisation that has entered into a services agreement with us.
RecordsRows of business contact data submitted by a Customer for validation, verification, enrichment or collection.
Data Principal / Data SubjectThe individual to whom personal data relates.
Applicable LawThe UK GDPR, the EU GDPR, and the Digital Personal Data Protection Act, 2023 (India), as each applies.

3The two roles we act in

3.1
As a processor. For Records a Customer submits for validation, verification, enrichment or collection, the Customer is the controller and we act only on its documented instructions. We do not decide the purpose of that processing.
3.2
As a controller. For our own website, marketing correspondence, supplier and recruitment records, and the operation and security of our systems, we act as controller and this policy sets out our own basis and practice.
3.3
Where we act as a processor and receive a request or complaint from an individual, we forward it to the relevant Customer without undue delay and assist them in responding. We do not respond substantively on the Customer's behalf unless instructed to.

4Personal data we process for customers

4.1
The categories of personal data contained in Records are set out below. All of it is business contact data relating to individuals in their professional capacity.
4.2
CategoryTypical fieldsSource
IdentityFirst name, last nameCustomer file; live professional profile
Business contactBusiness email, business phone, business addressCustomer file; live verification
EmploymentEmployer, job title, seniority, tenure, employment statusLive professional profile
OrganisationCompany name, domain, industry, headcount, registered and office addressesCustomer file; live sources
LocationCountry, state, city, postcode, street address, stated location of the individualCustomer file; live verification

We do not seek, and ask Customers not to submit, special category data, financial account data, government identifiers or data relating to children.

4.3
We process Records solely to perform the contracted service and to return results to the Customer. We do not add Records to any database of our own, use them to enrich another Customer's file, or sell, licence or share them with any third party for that third party's own purposes.
4.4
Where a service requires it, individual fields are verified against live public sources at the moment of processing. No copy of that source data is retained beyond the processing log described in clause 7.

5Personal data we collect directly

5.1
Website. We set no advertising cookies and no cross-site tracking cookies. We record standard server logs — IP address, user agent, request path and timestamp — for security, abuse prevention and diagnostics.
5.2
Enquiries. Where you email us or send a file for assessment, we retain your message, your contact details and any file you send so that we can reply and, if you become a Customer, so that we can perform the service.
5.3
Sample files. A file sent for a free assessment is treated exactly as Customer Records under clause 4 and deleted on the same basis under clause 7.
5.4
If we add product analytics or any cookie beyond those described above, this clause will be updated and, where consent is required, consent will be collected before the cookie is set.

6Lawful basis

6.1
Processor processing. We process Records on the documented instructions of the Customer under Article 28 UK/EU GDPR and the corresponding provisions of Applicable Law. The Customer, as controller, determines and is responsible for the lawful basis.
6.2
Controller processing. For our website, security logging and responses to enquiries we rely on legitimate interests — operating and securing our service and responding to people who contact us. A balancing assessment is recorded for each activity and is available to Customers on request.
6.3
Contract. Where processing is necessary to enter into or perform a services agreement with you or your organisation, we rely on performance of a contract.
6.4
Legal obligation. Where we must retain records for tax, accounting or statutory reporting, we rely on compliance with a legal obligation.

7Retention and deletion

7.1
Retention periods are as follows.
7.2
DataRetentionTrigger for deletion
Customer Records submitted for processingDuration of the campaign, and in no case longer than 90 daysCampaign removal, written request, or the 90-day cap
Processing logs (record identifier, verdict, reason, timestamp)12 monthsAutomatic expiry
Business correspondence and enquiries24 months from last contactAutomatic review
Contract and billing recordsAs required by Indian tax and companies legislationStatutory period expiry
Server and security logs90 daysAutomatic expiry
7.3
Deletion is permanent and applies to primary storage and to backups on their normal rotation cycle, which completes within 35 days.
7.4
A Customer may request deletion of its Records at any time in writing. We complete the deletion within 5 business days and confirm it in writing where asked.

8Disclosure and subprocessors

8.1
We use a small number of subprocessors, principally for cloud hosting, email delivery infrastructure and run-time verification services. The current list, including each entity, the service it provides and the country in which it processes, is provided to Customers on request.
8.2
We impose data protection terms on every subprocessor no less protective than those we owe our Customers, and we remain liable for their performance.
8.3
We give Customers written notice before adding or replacing a subprocessor and a reasonable opportunity to object on data protection grounds.
8.4
We disclose personal data to a public authority only where legally compelled. Where we are permitted to notify the Customer of such a request, we do so before disclosing.

9International transfers

9.1
We are established in India. Where personal data originating in the UK or the EEA is transferred to us, that transfer is made under the applicable Standard Contractual Clauses, incorporated into our Data Processing Agreement.
9.2
A transfer impact assessment is maintained and provided to Customers on request.
9.3
We do not transfer Records to any jurisdiction other than those disclosed in the subprocessor list.

10Security

10.1
Technical and organisational measures are set out in Annex 2 of our Data Processing Agreement and summarised on our Security page.
10.2
In outline: encryption in transit (TLS 1.2 or above) and at rest (AES-256); named, least-privilege, logged access; a dedicated processing workspace per Customer with no shared processing tenancy; annual vulnerability scanning; and no requirement for us to hold credentials to any Customer system.
10.3
We notify the affected Customer of a personal data breach without undue delay and in any event within 24 hours of becoming aware of it, with the information then available and updates as the assessment develops.

11Your rights

11.1
Subject to Applicable Law, individuals have the right to be informed, to access, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent where consent is the basis relied on.
11.2
Under the Digital Personal Data Protection Act, 2023, Data Principals in India additionally have the right to nominate another individual to exercise their rights, and the right of grievance redressal.
11.3
To exercise a right, contact us using the details in clause 15. We do not charge a fee and we do not require a specific form. We may ask for information sufficient to identify the records you are asking about.
11.4
Where we hold the data as a processor, we will tell you promptly which Customer is the controller so that you can direct the request, and we will assist that Customer in responding.

12Children

12.1
Our services are directed at businesses and are not intended to process the personal data of children. We ask Customers not to submit such data and we do not knowingly process it.
12.2
If we become aware that Records contain the personal data of a child, we will notify the Customer and delete the affected records on instruction.

13Automated decision-making

13.1
Our products apply documented, deterministic rules to business contact records and return a verdict together with the reason for it. The output is advisory: it is returned to the Customer, who decides what to do with it.
13.2
We do not carry out automated decision-making that produces legal effects concerning an individual or similarly significantly affects them within the meaning of Article 22 GDPR, and we do not profile individuals for our own purposes.

14Changes to this policy

14.1
We review this policy at least annually and whenever our processing or the law materially changes.
14.2
Where a change materially affects Customers, we notify them in writing before it takes effect. The version number and effective date at the head of this document identify the current text.

15Contact and complaints

15.1

How to contact us, and how to complain

Write to the Data Protection Officer, Zeplinix Technologies Private Limited, 310, Tower 1, World Trade Center, Kharadi, Pune 411014, Maharashtra, India, or email hello@zeplinix.com. We acknowledge within 5 business days and respond substantively within 30 days.

If you are not satisfied with our response you may complain to your local supervisory authority. In the EU that is the authority in your country of residence or work; in the UK it is the Information Commissioner's Office. In India you may escalate to the Data Protection Board of India once it is constituted under the Digital Personal Data Protection Act, 2023.

Version 1.0 · effective 15 July 2026 · Zeplinix Technologies Private Limited · hello@zeplinix.com