Privacy Policy
What we collect, why, where it lives, who processes it on our behalf, and the controls you have over all of it.
Version 3.2 · effective 1 September 2026For our website and sales process we are the data controller. For anything inside your systems during an engagement we are a processor acting only on your documented instructions. We never sell data, never train third-party models on client material, and disclose every sub-processor below.
1. Controller and processor roles
Zynovatechplus Ltd ("Zynovatechplus", "we", "us") operates zynovatechplus.com and provides engineering services to business clients.
1.1 Where we are the controller
We determine the purposes and means of processing for website visitors, sales enquiries, prospective candidates and our own business records. This policy governs that processing.
1.2 Where we are the processor
During a client engagement we may access personal data held in your systems. We act solely on your documented instructions under a Data Processing Agreement executed before work begins. That DPA — not this policy — governs the processing, and you remain the controller.
2. Data we collect
2.1 Provided directly
- Contact details — name, work email, telephone number, company, role.
- Enquiry content — the project brief you submit, plus any documents or repository access shared during scoping.
- Contract records — signatories, billing contacts, purchase-order references and payment details.
- Candidate data — CVs, portfolios and interview notes, where you apply to work with us.
2.2 Collected automatically
- IP address, coarse location, user agent, device and browser characteristics.
- Pages viewed, referrers, session duration and interaction events.
- Server logs retained for security monitoring and abuse prevention.
2.3 Received from others
- Referrals and introductions from existing clients or partners.
- Publicly available business information used to prepare for a first call.
- Identity and sanctions screening results from our compliance provider, where required.
We do not deliberately collect special-category data through this website. Please do not include health, biometric, political or similar information in a project brief.
3. What we use it for
| Purpose | Data | Basis |
|---|---|---|
| Respond to enquiries and scope work | Contact details, brief | Pre-contract steps |
| Deliver contracted services | Contract and project records | Contract |
| Invoicing, tax and accounting | Billing records | Legal obligation |
| Service and security emails | Contact details | Legitimate interests |
| Marketing updates | Email, engagement history | Consent, withdrawable |
| Website analytics | Aggregated usage data | Consent |
| Security monitoring and abuse prevention | Logs, IP addresses | Legitimate interests |
| Recruitment | Candidate data | Pre-contract steps, consent |
We do not carry out automated decision-making with legal or similarly significant effects, and we do not build advertising profiles.
4. Legal bases in detail
- Contract — processing necessary to negotiate, enter into or perform an engagement.
- Legal obligation — retention of financial records, response to lawful requests, sanctions screening.
- Legitimate interests — securing our infrastructure, preventing fraud, improving our services and communicating operationally with clients. We keep a balancing assessment for each and will share it on request.
- Consent — marketing emails and non-essential cookies. Withdrawal is one click and never affects service delivery.
5. Client systems and production data
Our default position is to avoid touching production personal data at all. Where an engagement makes that impossible, the following controls apply:
- Access is granted through your identity provider, never through shared credentials.
- Credentials are short-lived; we hold no standing production access between tasks.
- Development and test environments use synthetic or irreversibly anonymised data wherever technically feasible.
- Every access event is logged in your systems and available to your auditors.
- Client material is never used to train any machine-learning model, ours or a third party's.
- On engagement close, we certify deletion of all client data from our devices and workspaces within 30 days.
6. Sub-processors
We use a deliberately small set of vendors. Clients are notified at least 30 days before we add one, with the right to object.
| Provider | Function | Region |
|---|---|---|
| Cloud hosting provider | Website and internal tooling hosting | EU (Ireland) |
| Email delivery platform | Transactional and subscription email | EU / US |
| CRM | Sales pipeline and contact records | EU |
| Accounting platform | Invoicing and financial records | EU |
| Analytics | Privacy-preserving website measurement | EU |
| Collaboration suite | Documents, chat and video calls | EU / US |
The current named list, with entity details, is available at contact@zynovatech.site and is attached to every DPA.
7. International transfers
Our primary infrastructure is in the European Union. Where a transfer outside the EEA or UK is necessary, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses supplemented by a transfer impact assessment and technical measures including encryption in transit and at rest.
Clients with data-residency requirements can request an EU-only or UK-only configuration; we will confirm in writing whether we can meet it before the engagement starts.
9. Retention
| Record | Retained for |
|---|---|
| Enquiries that do not convert | 24 months from last contact |
| Active client records | Duration of engagement plus 6 years |
| Financial and tax records | 7 years, per statutory requirement |
| Client production data accessed under a DPA | Deleted within 30 days of engagement close |
| Server and security logs | 12 months |
| Marketing subscriptions | Until withdrawal, plus a suppression entry |
| Unsuccessful candidate data | 12 months, with consent; otherwise deleted at decision |
10. Security measures
- ISO 27001 certified information security management system, externally audited annually.
- SOC 2 Type II report available under NDA.
- TLS 1.2+ in transit; AES-256 at rest across all managed stores.
- Mandatory hardware-backed multi-factor authentication for all staff.
- Least-privilege access with quarterly review and automated deprovisioning.
- Managed, encrypted endpoints with remote-wipe capability.
- Background checks and annual security training for every engineer.
- Independent penetration test at least once a year; findings tracked to closure.
11. Your rights
Subject to your jurisdiction, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests, and withdraw consent at any time.
Send requests to contact@zynovatech.site. We respond within 30 days and may extend by a further 60 days for complex requests, telling you why. Verification of identity may be required. There is no charge unless a request is manifestly unfounded or excessive.
Where we act as a processor for a client, forward your request to that client — we will assist them but cannot act on their data without instruction. You may also complain to your supervisory authority at any time.
12. Breach notification
We maintain a tested incident-response plan. If a personal data breach occurs we will notify the relevant supervisory authority within 72 hours of becoming aware where the law requires it, and notify affected clients without undue delay — in practice, within 24 hours of confirmation — with what we know, what it affects and what we are doing. Post-incident reports are shared in full, including the root cause.
13. Changes to this policy
This policy is versioned; the current version and effective date appear at the top of this page. Material changes are announced by email to active clients and subscribers at least 30 days before they take effect. Previous versions are available on request.
14. Contact
- Privacy, security & general — contact@zynovatech.site
- Post — Zynovatechplus Ltd, Data Protection Office, 118 Quay Street, Dublin 2, D02 XY45, Ireland
See also our Terms of Service and Disclaimer.