1. Who we are
Ziro Data ("we", "us") is a data analytics studio. [Ziro Data legal entity name], registered in [country] under number [registration number], with its registered address at [full address], is responsible for the personal data described in this policy.
- Privacy contact
- privacy@zirodata.com
- Postal address
- [Full postal address]
- EU representative
- [Name and address of your EU representative, if required]
- Data protection officer
- We are not required to appoint one. Pantea Ebrahimi, CEO, is responsible for privacy at Ziro Data.
[Note for the Ziro Data team: if you have no office in the EU but offer services to people there, GDPR Article 27 may require you to name an EU representative. Delete this note before publishing.]
2. Two ways we handle personal data
The rules that apply depend on whose data it is and why we have it.
Visitors, prospects and contacts
When you visit our site, fill in a form, book a call, subscribe to our newsletter or email us, we are the controller of your data. Sections 3 to 9 explain what we do with it.
Data in client projects
When we analyse a client's data, such as their customers' orders, the client is the controller and we are a processor. We act only on their written instructions, under a data processing agreement. Section 10 explains how.
3. What we collect
| Type of data | Examples | Where it comes from |
|---|---|---|
| Contact details | Name, work email, company, job title, phone number if you give it | You, through forms, email or calls |
| Enquiry details | The topics you pick, your timeline, budget range and message | You, through our contact form |
| Booking details | Meeting time, time zone, notes you add | You, through our booking tool |
| Newsletter data | Email address, sign-up date, whether you open our emails | You, and our newsletter tool |
| Client contract data | Names and work contacts of client staff, contracts, invoices | You or your employer |
| Website usage | Pages viewed, device type, approximate location from IP address, referring site | Your browser, only with your consent for analytics |
| Security logs | IP address, date and time of requests, error logs | Our hosting provider, automatically |
We don't ask for sensitive data, such as health, religion or political views, and we ask you not to send it to us. You don't have to give us any personal data, but we can't reply to an enquiry without a way to contact you.
4. How we use it, and our legal basis
Data protection laws require a legal reason for each use of personal data. These are ours.
| What we do | Legal basis |
|---|---|
| Reply to your enquiry and prepare a proposal | Steps you asked for before a contract, and our legitimate interest in answering |
| Deliver a project and manage the client relationship | Performance of a contract |
| Send invoices and keep accounting records | Legal obligation |
| Send our newsletter | Your consent, which you can withdraw with one click |
| Measure how our site is used, to improve it | Your consent to analytics cookies |
| Keep the site secure and prevent abuse | Our legitimate interest in protecting our systems |
| Handle legal claims if they arise | Our legitimate interest, and legal obligation |
Where we rely on legitimate interests, we have checked that they don't override your rights. You can object at any time (see section 11). We don't make decisions about you based only on automated processing, and we don't profile visitors.
7. International transfers
We work with clients in the United States, Saudi Arabia, the United Arab Emirates and the European Union, and our team works from [country or countries]. This means personal data may be handled in a country other than yours.
When we move personal data across borders, we use the safeguards the law requires:
- From the EU: an adequacy decision where one exists, otherwise the European Commission's Standard Contractual Clauses, with extra measures where needed.
- From Saudi Arabia: the conditions in the PDPL and SDAIA's transfer regulation, such as adequate protection in the receiving country or appropriate safeguards.
- From the UAE: the conditions in the UAE PDPL for transfers outside the country.
For client projects, the client chooses where their data stays. We work inside the client's own accounts and region, and we don't copy their data to our own systems unless the contract says so.
8. How long we keep it
| Data | How long |
|---|---|
| Enquiries that don't become a project | 12 months after our last contact |
| Client contacts and project correspondence | The contract period plus [3] years |
| Invoices and accounting records | [As long as tax law requires where we are registered, e.g. 10 years] |
| Newsletter subscribers | Until you unsubscribe |
| Analytics data | [14 months] |
| Security logs | [90 days] |
| Client project data | Returned or deleted within 30 days of the project ending, confirmed in writing |
When the time is up, we delete the data or make it anonymous so it can no longer identify you.
9. How we protect it
- Access is limited to the team members who need it, with two-step sign-in on every account.
- We use read-only access to client systems wherever possible, through named accounts the client controls.
- Data is encrypted in transit, and at rest where our providers support it.
- We sign an NDA before a client shares anything sensitive, and remove our access at the end of every project.
- If a breach puts your data at risk, we tell the relevant authority within 72 hours where the law requires it, and tell you without undue delay.
No system is perfectly secure, but these steps keep the risk low. We're a small team, not ISO-certified; if your organisation needs a security questionnaire, we'll fill it in.
10. Client data in our projects
When a client shares their data with us for a project, these extra rules apply:
- We sign a data processing agreement and follow the client's written instructions only.
- We use the data only for that project. We never use it to train AI models or for any other client.
- Any subprocessor we use is listed in the agreement, and the client can object to it.
- We tell the client of a suspected breach without undue delay, and within [48] hours.
- At the end, we return or delete the data within 30 days and confirm it in writing.
If you are a customer of one of our clients and want to use your privacy rights, please contact that company. We'll help them respond.
11. Your rights
Depending on where you live, you have some or all of these rights:
How to use them
Email privacy@zirodata.com. We may ask you to confirm your identity. We reply within one month. If a request is complex, we'll tell you if we need longer, as the law allows. Using your rights is free.
If you're not happy with our answer
Please tell us first so we can put it right. You can also complain to a data protection authority:
| Where you live | Authority |
|---|---|
| Luxembourg | National Data Protection Commission (CNPD), cnpd.public.lu |
| Other EU countries | Your national data protection authority |
| Saudi Arabia | Saudi Data & AI Authority (SDAIA), sdaia.gov.sa |
| United Arab Emirates | UAE Data Office |
12. Notes for specific regions
European Union and Luxembourg
Saudi Arabia
United Arab Emirates
United States
13. Children
Our services are for businesses. We don't knowingly collect personal data from anyone under 18. If you think a child has sent us their data, contact us and we'll delete it.
14. Changes to this policy
We'll update this policy when our services or the law change. The date at the top shows the latest version. If a change is significant, we'll tell clients and newsletter subscribers by email before it takes effect.