Services 01 Platform 02 Stack 03 Process 04 Work 05 Engagements 06 Book a call
Data protection

Privacy Policy

What we collect, why, where it lives, who processes it on our behalf, and the controls you have over all of it.

~//privacy
Version 3.2 · effective 1 September 2026
Summary

For our website and sales process we are the data controller. For anything inside your systems during an engagement we are a processor acting only on your documented instructions. We never sell data, never train third-party models on client material, and disclose every sub-processor below.

1. Controller and processor roles

Zynovatechplus Ltd ("Zynovatechplus", "we", "us") operates zynovatechplus.com and provides engineering services to business clients.

1.1 Where we are the controller

We determine the purposes and means of processing for website visitors, sales enquiries, prospective candidates and our own business records. This policy governs that processing.

1.2 Where we are the processor

During a client engagement we may access personal data held in your systems. We act solely on your documented instructions under a Data Processing Agreement executed before work begins. That DPA — not this policy — governs the processing, and you remain the controller.

2. Data we collect

2.1 Provided directly

  • Contact details — name, work email, telephone number, company, role.
  • Enquiry content — the project brief you submit, plus any documents or repository access shared during scoping.
  • Contract records — signatories, billing contacts, purchase-order references and payment details.
  • Candidate data — CVs, portfolios and interview notes, where you apply to work with us.

2.2 Collected automatically

  • IP address, coarse location, user agent, device and browser characteristics.
  • Pages viewed, referrers, session duration and interaction events.
  • Server logs retained for security monitoring and abuse prevention.

2.3 Received from others

  • Referrals and introductions from existing clients or partners.
  • Publicly available business information used to prepare for a first call.
  • Identity and sanctions screening results from our compliance provider, where required.

We do not deliberately collect special-category data through this website. Please do not include health, biometric, political or similar information in a project brief.

3. What we use it for

PurposeDataBasis
Respond to enquiries and scope workContact details, briefPre-contract steps
Deliver contracted servicesContract and project recordsContract
Invoicing, tax and accountingBilling recordsLegal obligation
Service and security emailsContact detailsLegitimate interests
Marketing updatesEmail, engagement historyConsent, withdrawable
Website analyticsAggregated usage dataConsent
Security monitoring and abuse preventionLogs, IP addressesLegitimate interests
RecruitmentCandidate dataPre-contract steps, consent

We do not carry out automated decision-making with legal or similarly significant effects, and we do not build advertising profiles.

4. Legal bases in detail

  • Contract — processing necessary to negotiate, enter into or perform an engagement.
  • Legal obligation — retention of financial records, response to lawful requests, sanctions screening.
  • Legitimate interests — securing our infrastructure, preventing fraud, improving our services and communicating operationally with clients. We keep a balancing assessment for each and will share it on request.
  • Consent — marketing emails and non-essential cookies. Withdrawal is one click and never affects service delivery.

5. Client systems and production data

Our default position is to avoid touching production personal data at all. Where an engagement makes that impossible, the following controls apply:

  • Access is granted through your identity provider, never through shared credentials.
  • Credentials are short-lived; we hold no standing production access between tasks.
  • Development and test environments use synthetic or irreversibly anonymised data wherever technically feasible.
  • Every access event is logged in your systems and available to your auditors.
  • Client material is never used to train any machine-learning model, ours or a third party's.
  • On engagement close, we certify deletion of all client data from our devices and workspaces within 30 days.

6. Sub-processors

We use a deliberately small set of vendors. Clients are notified at least 30 days before we add one, with the right to object.

ProviderFunctionRegion
Cloud hosting providerWebsite and internal tooling hostingEU (Ireland)
Email delivery platformTransactional and subscription emailEU / US
CRMSales pipeline and contact recordsEU
Accounting platformInvoicing and financial recordsEU
AnalyticsPrivacy-preserving website measurementEU
Collaboration suiteDocuments, chat and video callsEU / US

The current named list, with entity details, is available at contact@zynovatech.site and is attached to every DPA.

7. International transfers

Our primary infrastructure is in the European Union. Where a transfer outside the EEA or UK is necessary, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses supplemented by a transfer impact assessment and technical measures including encryption in transit and at rest.

Clients with data-residency requirements can request an EU-only or UK-only configuration; we will confirm in writing whether we can meet it before the engagement starts.

8. Cookies

  • Strictly necessary — session integrity, security and load balancing. Always active.
  • Preference — remembering theme, language and dismissed notices.
  • Analytics — aggregated page measurement, set only after consent.

We use no advertising cookies and no cross-site tracking pixels. You can clear or block cookies in your browser at any time; blocking strictly necessary cookies may break parts of the site.

9. Retention

RecordRetained for
Enquiries that do not convert24 months from last contact
Active client recordsDuration of engagement plus 6 years
Financial and tax records7 years, per statutory requirement
Client production data accessed under a DPADeleted within 30 days of engagement close
Server and security logs12 months
Marketing subscriptionsUntil withdrawal, plus a suppression entry
Unsuccessful candidate data12 months, with consent; otherwise deleted at decision

10. Security measures

  • ISO 27001 certified information security management system, externally audited annually.
  • SOC 2 Type II report available under NDA.
  • TLS 1.2+ in transit; AES-256 at rest across all managed stores.
  • Mandatory hardware-backed multi-factor authentication for all staff.
  • Least-privilege access with quarterly review and automated deprovisioning.
  • Managed, encrypted endpoints with remote-wipe capability.
  • Background checks and annual security training for every engineer.
  • Independent penetration test at least once a year; findings tracked to closure.

11. Your rights

Subject to your jurisdiction, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests, and withdraw consent at any time.

Send requests to contact@zynovatech.site. We respond within 30 days and may extend by a further 60 days for complex requests, telling you why. Verification of identity may be required. There is no charge unless a request is manifestly unfounded or excessive.

Where we act as a processor for a client, forward your request to that client — we will assist them but cannot act on their data without instruction. You may also complain to your supervisory authority at any time.

12. Breach notification

We maintain a tested incident-response plan. If a personal data breach occurs we will notify the relevant supervisory authority within 72 hours of becoming aware where the law requires it, and notify affected clients without undue delay — in practice, within 24 hours of confirmation — with what we know, what it affects and what we are doing. Post-incident reports are shared in full, including the root cause.

13. Changes to this policy

This policy is versioned; the current version and effective date appear at the top of this page. Material changes are announced by email to active clients and subscribers at least 30 days before they take effect. Previous versions are available on request.

14. Contact

  • Privacy, security & generalcontact@zynovatech.site
  • Post — Zynovatechplus Ltd, Data Protection Office, 118 Quay Street, Dublin 2, D02 XY45, Ireland

See also our Terms of Service and Disclaimer.