Legal
Privacy Policy
Your privacy matters. This policy explains what we collect, how we use it, and how we protect it.
Last updated: March 17, 2026
1. Information We Collect
We collect information you voluntarily provide when you:
• Submit a contact form or inquiry (name, email, company name, project details)
• Subscribe to our newsletter (email address)
• Engage us for services (billing name, address, payment information)
• Communicate with us via email, phone, or video call
We also automatically collect limited technical data when you visit our website:
• IP address and approximate geographic location
• Browser type, device type, and operating system
• Pages visited, time spent, and referring URL
• Cookies and similar tracking technologies (see Section 6)
We do NOT collect sensitive personal data such as government IDs, health records, or biometric data unless explicitly required for a contracted project and governed by a separate data processing agreement.
2. How We Use Your Information
We use the information we collect to:
• Respond to your inquiries and provide requested services
• Process payments and manage billing
• Send project updates and deliverables
• Improve our website, services, and user experience
• Comply with legal obligations and enforce our terms
• Send occasional marketing communications (only with your consent, and you can opt out at any time)
We will NEVER sell, rent, or trade your personal information to third parties for their marketing purposes.
3. Client Confidentiality
We take client confidentiality extremely seriously. By default:
• We do NOT publicly disclose the names, logos, or identities of our clients on our website, marketing materials, or any public-facing content without explicit, written consent.
• All project details, business logic, proprietary workflows, data models, source code, and internal processes shared with us during discovery, design, development, and support are treated as strictly confidential.
• Our team members are bound by confidentiality obligations as part of their employment or contractor agreements.
• We do NOT use client data for training, analytics, benchmarking, or any purpose beyond delivering the contracted services.
If we wish to reference a client relationship in a case study, testimonial, or portfolio piece, we will seek your prior written approval. You may revoke this approval at any time, and we will remove the reference promptly.
Any case studies or examples displayed on our website that do not name a specific client use anonymized or fictionalized details and do not represent actual client data.
4. Payment Processing & Financial Data
When you make a payment through our website or invoicing system:
• Payment processing is handled by PCI DSS-compliant third-party processors (such as Stripe). We do NOT store your full credit card number, CVV, or bank account details on our servers.
• We may retain limited transaction records (last four digits of card, transaction ID, amount, date) for accounting, invoicing, and dispute resolution purposes.
• All payment data is transmitted using TLS 1.2+ encryption.
• We will never request payment credentials via email, phone, or chat. If you receive such a request claiming to be from ZAF Technology, do not respond and contact us immediately.
Recurring billing (monthly subscriptions) will be clearly disclosed before any charge is made. You may cancel recurring payments at any time by contacting us or through the payment portal.
5. Data Sharing & Third Parties
We may share your information only in the following limited circumstances:
• Service Providers: We use trusted third-party tools for hosting (AWS/Azure/GCP), email (Google Workspace), analytics (privacy-focused analytics), and payment processing (Stripe). These providers are contractually bound to protect your data and use it only for the services they provide to us.
• Legal Requirements: We may disclose information if required by law, subpoena, court order, or government regulation.
• Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred. We will notify you before your data becomes subject to a different privacy policy.
We do NOT share client project data, proprietary information, or business intelligence with any third party unless explicitly authorized by you in writing.
6. Cookies & Tracking
Our website uses minimal cookies:
• Essential Cookies: Required for site functionality (session management, security). These cannot be disabled.
• Analytics Cookies: We use privacy-respecting analytics to understand how visitors use our site. No personally identifiable information is collected through analytics.
We do NOT use third-party advertising cookies or sell data to ad networks. You can control cookies through your browser settings.
7. Data Security
We implement industry-standard security measures to protect your data:
• TLS/SSL encryption for all data in transit
• Encryption at rest for stored data
• Access controls and role-based permissions
• Regular security audits and vulnerability assessments
• Secure development practices (OWASP guidelines)
• Incident response procedures with notification within 72 hours of any breach affecting your data
While no system is 100% secure, we are committed to protecting your information using commercially reasonable safeguards.
8. Data Retention
• Contact form submissions: Retained for up to 2 years after last communication, then deleted.
• Client project data: Retained for the duration of the engagement plus 1 year after project completion, unless a longer period is agreed upon or required by law.
• Payment records: Retained for 7 years as required by tax and accounting regulations.
• Newsletter subscribers: Retained until you unsubscribe.
You may request deletion of your data at any time (see Section 9).
9. Your Rights
Depending on your jurisdiction, you may have the right to:
• Access: Request a copy of the personal data we hold about you.
• Correction: Request that we correct inaccurate or incomplete data.
• Deletion: Request that we delete your personal data (subject to legal retention requirements).
• Portability: Request your data in a structured, machine-readable format.
• Objection: Object to processing of your data for certain purposes.
• Withdraw Consent: Withdraw consent for marketing communications at any time.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
10. International Data Transfers
ZAF Technology operates globally. Your data may be processed in countries other than your own. When we transfer data internationally, we ensure appropriate safeguards are in place, including standard contractual clauses and compliance with applicable data protection laws (including GDPR for EU residents and CCPA for California residents).
11. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on our website. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
ZAF Technology
Email: [email protected]
Website: https://zaf-tech.io/contact