Privacy Policy

Effective Date: July 25, 2026 • Compliant with International Data Protection Standards (GDPR-aligned)

This Privacy Policy outlines how ZindOps collects, processes, and protects personal data in compliance with applicable international privacy frameworks and recognized global data protection principles.

1. Data Controller vs. Data Processor Roles

  • As Data Controller: ZindOps collects and controls account information, login credentials, and billing records for Organization Owners and administrators.
  • As Data Processor: For customer records, invoices, and operational data created inside your workspace, you are the Data Controller. We act strictly as a Data Processor executing software functions on your instructions.

2. Personal Data We Collect

  • Account Details: Full name, email address, phone number, salted/hashed passwords, and MFA tokens.
  • Organization & Billing: Company name, Tax Identification Number (TIN), billing address, subscription history, and payment reference strings.
  • Verification Proofs: Uploaded payment receipt screenshots, mobile money reference strings, and administrative approval notes.
  • System Telemetry: IP addresses, browser types, session timestamps, and operational audit logs.

3. Legal Grounds for Processing

We process personal data under internationally recognized lawful bases for data processing:

  • Contractual Performance: To provision your workspace, manage plan limits, process payments, and verify subscriptions.
  • Legal Compliance: To maintain financial accounting records required under applicable statutory tax and commercial regulations.
  • Legitimate Interest: To maintain platform security, protect multi-tenant isolation, and prevent subscription fraud.

4. Data Security & Multi-Tenant Isolation

Your data is isolated using strict database tenant filtering (organizationId) and explicit indexing. All data in transit uses TLS 1.3 encryption, and sensitive assets are encrypted at rest using industry-standard cryptography.

5. Your Data Subject Rights

Under international data privacy standards, you hold the right to:

  • Access, inspect, and rectify your personal details.
  • Request data erasure ("Right to be Forgotten") or export your workspace data in standard digital formats (CSV/JSON).
  • Object to non-essential communications or withdraw consent at any time.