Back to Main

Privacy Policy

1. Zero-Retention Architecture

At Zotork Private Limited, our automation architecture is built on a strict zero-retention philosophy. We act as a conduit for your data, meaning your proprietary information passes through our systems to execute automated tasks but is never stored permanently on our servers.

2. OAuth & Delegated Access

We do not request, require, or store your passwords. All integrations are established using OAuth 2.0 or secure API tokens. Your credentials stay yours, and access can be revoked by your administrators at any time.

3. Data Collection During Audits

When you book an Operations Audit with us, we collect basic contact information (Name, Email, Role) and high-level workflow bottlenecks. This information is used exclusively to prepare for the technical architecture call and map your solution. We do not sell, rent, or distribute this data to any third parties.

4. ISO 27001 Compliance

Our internal processes and infrastructure adhere to the ISO 27001:2022 framework for information security management, ensuring enterprise-grade protection for all data in transit.

5. Data Processing Agreements (DPAs)

When clients hire Zotork Private Limited to build AI agents, automate workflows, or develop custom apps, they often need to hand over their company data or their customers' data so our team can build, train, and test the systems.

The Legal Dynamic: Under privacy laws, you (the client) are the "Data Controller" (you own the data) and our agency is the "Data Processor" (we handle it on your behalf).

The Barrier: By law, a Data Controller cannot legally share personal data with a Data Processor without a signed DPA in place.

The Benefit: Having a standard DPA ready to go prevents deal-stalling legal reviews. It assures enterprise clients that we have a formal, legally binding framework dictating exactly how we handle, protect, and eventually delete their data once a milestone is reached or a subscription ends.

6. Global Privacy Compliance (GDPR, DPDP, CCPA)

While a DPA governs the data your clients give you for projects, a Privacy Policy governs the data we collect directly on our own website.

Legal Compliance: If our website has a contact form, uses analytics, or collects email addresses for sales leads, privacy laws require a public-facing policy explaining exactly what data is collected, why it is collected, and who it is shared with.

Trust and Professionalism: Paired with our ISO 27001 certification, this robust Privacy Policy signals to prospective B2B clients that our agency treats data security and legal compliance as top priorities before a contract is even signed.

Protection from Fines: Having compliant policies under strict frameworks like the EU's GDPR, India's DPDP, or California's CCPA protects our business from regulatory fines if a website visitor from those regions submits their information.