Privacy policy

How Ziro Data collects, uses and protects personal data, in plain language. If anything is unclear, email privacy@zirodata.com and a person will answer.

Last updated[25 September 2026] Effective from[25 September 2026] Version1.0

The short version

1

We collect only what we need to reply to you, run our projects and keep this site working.

2

We never sell personal data, and we don't use it for advertising.

3

Client data stays in the client's own systems. We use read-only access and remove it when the project ends.

4

Analytics cookies run only if you agree. You can change your mind any time.

5

You can ask to see, correct or delete your data. We reply within one month.

6

We follow the EU GDPR, Saudi Arabia's PDPL and the UAE's PDPL for the people they protect.

This summary is here to help. The full policy below is what applies.

1. Who we are

Ziro Data ("we", "us") is a data analytics studio. [Ziro Data legal entity name], registered in [country] under number [registration number], with its registered address at [full address], is responsible for the personal data described in this policy.

Privacy contact
privacy@zirodata.com
Postal address
[Full postal address]
EU representative
[Name and address of your EU representative, if required]
Data protection officer
We are not required to appoint one. Pantea Ebrahimi, CEO, is responsible for privacy at Ziro Data.

[Note for the Ziro Data team: if you have no office in the EU but offer services to people there, GDPR Article 27 may require you to name an EU representative. Delete this note before publishing.]

2. Two ways we handle personal data

The rules that apply depend on whose data it is and why we have it.

We decide how it's used

Visitors, prospects and contacts

When you visit our site, fill in a form, book a call, subscribe to our newsletter or email us, we are the controller of your data. Sections 3 to 9 explain what we do with it.

Our client decides how it's used

Data in client projects

When we analyse a client's data, such as their customers' orders, the client is the controller and we are a processor. We act only on their written instructions, under a data processing agreement. Section 10 explains how.

3. What we collect

Type of dataExamplesWhere it comes from
Contact detailsName, work email, company, job title, phone number if you give itYou, through forms, email or calls
Enquiry detailsThe topics you pick, your timeline, budget range and messageYou, through our contact form
Booking detailsMeeting time, time zone, notes you addYou, through our booking tool
Newsletter dataEmail address, sign-up date, whether you open our emailsYou, and our newsletter tool
Client contract dataNames and work contacts of client staff, contracts, invoicesYou or your employer
Website usagePages viewed, device type, approximate location from IP address, referring siteYour browser, only with your consent for analytics
Security logsIP address, date and time of requests, error logsOur hosting provider, automatically

We don't ask for sensitive data, such as health, religion or political views, and we ask you not to send it to us. You don't have to give us any personal data, but we can't reply to an enquiry without a way to contact you.

4. How we use it, and our legal basis

Data protection laws require a legal reason for each use of personal data. These are ours.

What we doLegal basis
Reply to your enquiry and prepare a proposalSteps you asked for before a contract, and our legitimate interest in answering
Deliver a project and manage the client relationshipPerformance of a contract
Send invoices and keep accounting recordsLegal obligation
Send our newsletterYour consent, which you can withdraw with one click
Measure how our site is used, to improve itYour consent to analytics cookies
Keep the site secure and prevent abuseOur legitimate interest in protecting our systems
Handle legal claims if they ariseOur legitimate interest, and legal obligation

Where we rely on legitimate interests, we have checked that they don't override your rights. You can object at any time (see section 11). We don't make decisions about you based only on automated processing, and we don't profile visitors.

5. Cookies and analytics

Cookies are small files stored on your device. We use as few as possible. Analytics cookies are off until you allow them.

CookieWhat it doesTypeHow long
zd_consentRemembers your cookie choiceNecessary12 months
_ga, _ga_*Google Analytics 4: counts visits and pages viewedAnalytics, only with consent[14 months]
[Booking tool cookie]Keeps the booking calendar workingNecessary, set only when you book[Session]

We set Google Analytics to shorten IP addresses and not to share data for advertising. [Confirm these settings in your GA4 account.] You can change your choice at any time:

6. Who we share it with

We use a small number of trusted providers to run our business. They process data only on our instructions and under contracts that protect it.

ProviderWhat forWhere data is stored
[Website host, e.g. Vercel or Netlify]Hosting this website[Region]
[Form tool, e.g. Formspree or HubSpot]Receiving contact form messages[Region]
[Email, e.g. Google Workspace]Email and documents[Region]
[Booking tool, e.g. Cal.com]Scheduling calls[Region]
Google AnalyticsSite analytics, only with consent[Region]
[Newsletter tool, e.g. MailerLite]Sending the newsletter[Region]
[Accountant]Bookkeeping and tax filing[Country]

We never sell personal data, and we never share it for advertising. We only disclose it to authorities when the law requires us to, and we check each request.

7. International transfers

We work with clients in the United States, Saudi Arabia, the United Arab Emirates and the European Union, and our team works from [country or countries]. This means personal data may be handled in a country other than yours.

When we move personal data across borders, we use the safeguards the law requires:

  • From the EU: an adequacy decision where one exists, otherwise the European Commission's Standard Contractual Clauses, with extra measures where needed.
  • From Saudi Arabia: the conditions in the PDPL and SDAIA's transfer regulation, such as adequate protection in the receiving country or appropriate safeguards.
  • From the UAE: the conditions in the UAE PDPL for transfers outside the country.

For client projects, the client chooses where their data stays. We work inside the client's own accounts and region, and we don't copy their data to our own systems unless the contract says so.

8. How long we keep it

DataHow long
Enquiries that don't become a project12 months after our last contact
Client contacts and project correspondenceThe contract period plus [3] years
Invoices and accounting records[As long as tax law requires where we are registered, e.g. 10 years]
Newsletter subscribersUntil you unsubscribe
Analytics data[14 months]
Security logs[90 days]
Client project dataReturned or deleted within 30 days of the project ending, confirmed in writing

When the time is up, we delete the data or make it anonymous so it can no longer identify you.

9. How we protect it

  • Access is limited to the team members who need it, with two-step sign-in on every account.
  • We use read-only access to client systems wherever possible, through named accounts the client controls.
  • Data is encrypted in transit, and at rest where our providers support it.
  • We sign an NDA before a client shares anything sensitive, and remove our access at the end of every project.
  • If a breach puts your data at risk, we tell the relevant authority within 72 hours where the law requires it, and tell you without undue delay.

No system is perfectly secure, but these steps keep the risk low. We're a small team, not ISO-certified; if your organisation needs a security questionnaire, we'll fill it in.

10. Client data in our projects

When a client shares their data with us for a project, these extra rules apply:

  • We sign a data processing agreement and follow the client's written instructions only.
  • We use the data only for that project. We never use it to train AI models or for any other client.
  • Any subprocessor we use is listed in the agreement, and the client can object to it.
  • We tell the client of a suspected breach without undue delay, and within [48] hours.
  • At the end, we return or delete the data within 30 days and confirm it in writing.

If you are a customer of one of our clients and want to use your privacy rights, please contact that company. We'll help them respond.

11. Your rights

Depending on where you live, you have some or all of these rights:

See your dataAsk what we hold about you and get a copy.
Correct itFix anything that's wrong or incomplete.
Delete itAsk us to erase it, unless we must keep it by law.
Limit or objectAsk us to pause a use, or stop one based on legitimate interests.
Take it with youGet it in a common format to give to someone else.
Withdraw consentFor the newsletter or analytics, at any time.

How to use them

Email privacy@zirodata.com. We may ask you to confirm your identity. We reply within one month. If a request is complex, we'll tell you if we need longer, as the law allows. Using your rights is free.

If you're not happy with our answer

Please tell us first so we can put it right. You can also complain to a data protection authority:

Where you liveAuthority
LuxembourgNational Data Protection Commission (CNPD), cnpd.public.lu
Other EU countriesYour national data protection authority
Saudi ArabiaSaudi Data & AI Authority (SDAIA), sdaia.gov.sa
United Arab EmiratesUAE Data Office

12. Notes for specific regions

European Union and Luxembourg
The GDPR applies when we handle data of people in the EU. The rights in section 11 and the transfer rules in section 7 come from the GDPR. [If Ziro Data has no office in the EU, add the details of your EU representative in section 1.]
Saudi Arabia
The Personal Data Protection Law (PDPL) applies when we handle data of people living in Saudi Arabia, even from outside the Kingdom. You have the right to be informed, to access and get a copy of your data, to correct it, to have it destroyed when it's no longer needed, and to withdraw consent.
United Arab Emirates
The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies to data of people in the UAE. Separate rules apply in the DIFC and ADGM free zones. We follow whichever rules apply to you.
United States
We don't sell personal information or share it for cross-context behavioural advertising. If you live in a US state with a privacy law, such as California, you can ask to know, correct or delete your data using the contact details above. We won't treat you differently for doing so.

13. Children

Our services are for businesses. We don't knowingly collect personal data from anyone under 18. If you think a child has sent us their data, contact us and we'll delete it.

14. Changes to this policy

We'll update this policy when our services or the law change. The date at the top shows the latest version. If a change is significant, we'll tell clients and newsletter subscribers by email before it takes effect.

Version history1.0 · [25 September 2026] · First published

15. Contact us

Post[Ziro Data legal entity name], [full postal address]
Reply timeWithin one month, usually much sooner