PRIVACY & DATA PROTECTION

Privacy Policy

Effective Date: July 26, 2026

At Zerox, we are committed to safeguarding your privacy and ensuring transparency in how we collect, use, process, and protect your data across our software products, AI services, and enterprise solutions.

GDPR & CCPA Compliant
AES-256 Bit Encryption
Zero Third-Party Data Monetization
SOC2 Security Controls

1. Introduction & Overview

In Plain English:

This privacy policy explains how Zerox manages data when you interact with our website, cloud platforms, and enterprise software services. We value your trust and prioritize data security above all else.

Official Legal Terms:

Zerox ("Company", "we", "us", or "our") respects your personal privacy and is dedicated to complying with applicable data protection laws, including the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the California Privacy Rights Act (CPRA). This policy governs all data collection via our primary website, client portals, APIs, and custom software services.

2. Information We Collect

In Plain English:

We only collect information necessary to deliver, secure, and improve our services — such as contact details, account credentials, technical diagnostics, and system usage metrics.

Official Legal Terms:

We collect information in three ways: direct interactions, automated technologies, and verified third-party partners. • Direct Information: Name, work email address, telephone number, job title, company name, billing details, and inquiry communications submitted via contact forms. • Technical & Usage Data: IP address, browser type, operating system, referrer URL, device identifiers, and session interaction timestamps. • Project Data: Requirements, code repositories, asset files, and API payload configurations shared under NDA for project execution.

3. How We Use Your Information

In Plain English:

Your data powers service delivery, project management, customer support, and system security. We never sell your personal information or use confidential client data to train public AI models.

Official Legal Terms:

Zerox processes collected data based on legitimate business interests, contractual performance, legal compliance, and explicit consent: 1. Provision of Software & Consulting Services: Executing custom software builds, deploying AI integrations, and maintaining enterprise infrastructure. 2. Service Improvement & R&D: Aggregating anonymized performance telemetry to optimize application speed, system uptime, and UI workflows. 3. Security & Fraud Prevention: Monitoring access logs, enforcing authentication protocols, and protecting against cyber threats. 4. Communications: Sending project updates, security advisories, invoice reminders, and service notices.

4. Data Sharing & Third-Party Processors

In Plain English:

We do not sell, rent, or trade your personal data. We only share data with vetted sub-processors (like AWS, Vercel, or Stripe) required to run our infrastructure.

Official Legal Terms:

Zerox strictly limits third-party data sharing. Data is shared exclusively with compliant service providers bound by strict Data Processing Agreements (DPAs): • Infrastructure & Hosting: Amazon Web Services (AWS), Google Cloud Platform (GCP), Vercel. • Analytics & Diagnostics: Sentry, PostHog (anonymized system telemetry). • Payment & Invoicing: Stripe, Wise (processed under PCI-DSS compliance). • Legal Requirements: We may disclose information if required by law enforcement subpoenas, court orders, or statutory obligations.

5. Data Security & Storage Standards

In Plain English:

We protect your information with industry-leading encryption (at rest and in transit), strict role-based access controls, and continuous vulnerability monitoring.

Official Legal Terms:

Zerox employs multi-layered technical, administrative, and physical safeguards designed to prevent unauthorized access, loss, or disclosure: • End-to-End Encryption: TLS 1.3 encryption for data in transit and AES-256 encryption for data at rest. • Access Control: Zero-trust architecture, multi-factor authentication (MFA), and role-based access controls (RBAC). • Infrastructure Security: Regular automated vulnerability scans, penetration tests, and container isolation.

6. Cookies & Tracking Technologies

In Plain English:

We use essential cookies to keep our website functioning smoothly and optional analytics cookies to understand page usage. You can manage preferences anytime.

Official Legal Terms:

Our website utilizes essential session cookies (required for authentication and navigation) and performance cookies. You can adjust your browser settings or opt-out using our cookie preferences panel at any time. We do not use intrusive cross-site tracking or retargeting ad cookies.

7. Your Data Subject Rights

In Plain English:

You own your data. You have full rights to request access, correction, export, or total deletion of your personal data at any time.

Official Legal Terms:

Depending on your jurisdiction (such as EU/EEA, UK, California, or Canada), you enjoy statutory data privacy rights: • Right to Access: Request a copy of all personal data held about you. • Right to Erasure ('Right to be Forgotten'): Request complete deletion of your records. • Right to Rectification: Correct inaccurate or incomplete information. • Right to Data Portability: Receive your data in a structured, machine-readable JSON/CSV format. • Right to Opt-Out: Opt out of non-essential processing or marketing communications.

8. Data Retention & Deletion

In Plain English:

We keep personal information only as long as active projects or legal mandates require. When no longer needed, data is permanently erased.

Official Legal Terms:

Zerox retains personal data for the duration of active service contracts and for up to 7 years following contract termination to satisfy tax, legal, and accounting obligations. Active project scratch data and temporary logs are purged within 90 days.

9. International Data Transfers

In Plain English:

If data moves across international borders, we ensure it is governed by Standard Contractual Clauses (SCCs) and high security standards.

Official Legal Terms:

Zerox operates globally. When personal data originating in the European Economic Area (EEA) or UK is transferred internationally, we rely on EU Standard Contractual Clauses (SCCs) and strict data transfer impact assessments (DTIAs).

10. Contacting Our Privacy Team

In Plain English:

Questions or privacy requests? Our Data Protection Officer (DPO) and privacy engineering team are here to assist.

Official Legal Terms:

If you wish to exercise your privacy rights, submit a data access request, or ask questions regarding this policy, please reach out directly to our Data Protection Officer at [email protected].
GDPR & CCPA RIGHTS

Your Privacy Rights at a Glance

We guarantee clear, friction-free mechanism for exercising your legal privacy rights.

Right to Access & Copy

Request an export of all personal data, system telemetry, and records associated with your account.

Right to Erasure (Delete)

Permanently erase your account, contact records, and stored credentials from our databases.

Right to Correct & Update

Modify out-of-date or inaccurate profile, billing, or organization information immediately.

Right to Restrict & Opt-Out

Opt-out of non-essential communications, analytical tracking, or automated data processing.

DATA PROTECTION OFFICE

Have Privacy Questions or Data Requests?

Our dedicated Data Protection Officer (DPO) and security compliance team respond to all privacy inquiries within 24-48 business hours.