How Zscaling Pvt. Ltd. collects, uses, shares and protects personal data in connection with the ZsPRM platform, its mobile applications, and our websites.
Version 3.2 · Effective 21 August 2026 · Supersedes Version 3.1
What this Policy covers and who it is for.
Zscaling Pvt. Ltd. (“Zscaling”, “we”, “our” or “us”) provides ZsPRM, a Prospect Relationship Manager for business-to-business revenue teams. This Privacy Policy explains how we collect, use, disclose, transfer and retain personal data, the legal bases on which we do so, and the rights available to you.
This Policy applies to the ZsPRM web application; the ZsPRM applications for iOS and Android; zsprm.com and zscaling.com; and any related service that links to this Policy (together, the “Platform”). It does not apply to any third-party product you connect to the Platform, which is governed by that provider’s own policy, nor to any website we link to but do not operate.
By accessing or using the Platform you confirm that you have read and understood this Policy. If you do not agree with it, please do not use the Platform.
| Effective date | 21 August 2026 |
|---|---|
| Supersedes | Version 3.1, 21 August 2026 |
| Data controller | Zscaling Pvt. Ltd. |
| Privacy contact | [email protected] |
| Security contact | [email protected] |
| Governing language | English. Where this Policy is translated and a conflict arises, the English text prevails. |
The terms used throughout this Policy.
| Personal Data | Any information relating to an identified or identifiable natural person. |
|---|---|
| Customer Data | Personal Data a customer uploads to, or generates within, the Platform — contacts, leads, notes, tasks, events, message threads, and the scores computed against them. |
| Professional Data | Business-contact records about individuals in their professional capacity, assembled from public and licensed sources. See Section 21. |
| Controller | The party that determines the purposes and means of processing. |
| Processor | The party that processes Personal Data on a controller’s documented instructions. |
| Sub-processor | A processor engaged by us to carry out processing on a customer’s behalf. See Section 12.1. |
| Customer | An organisation that subscribes to the Platform. |
| User | An individual who accesses the Platform under a customer’s subscription. |
| You | The reader — a customer, a user, a website visitor, or an individual whose Professional Data we hold. |
Controller identity and the routes to reach us.
| Legal entity | Zscaling Pvt. Ltd. |
|---|---|
| Privacy enquiries and data-subject requests | [email protected] |
| Security vulnerability disclosure | [email protected] · zsprm.com/.well-known/security.txt |
| Data protection contact | Privacy and Data Protection Officer, care of [email protected] |
| Registered address | [to be inserted] |
| EEA / UK Article 27 representative | [to be appointed if required — see Annex A] |
| Response acknowledgement | Within 5 business days of receipt |
If you require this Policy in an alternative format because of a disability — large print, plain text, or screen-reader-friendly HTML — contact us at [email protected] and we will provide one at no charge.
Whether we are controller or processor depends on the context.
IMPORTANT — If a company contacted you using ZsPRM, we are its processor — not its controller.
We cannot unsubscribe you from another organisation’s campaign, and we cannot delete a record that organisation controls. Use the opt-out in the message you received, or contact that organisation directly. If you do not know who they are, write to [email protected] with a copy of the message and we will identify them within 30 days so that you can exercise your rights against them.
Every category of Personal Data we process, at field level.
| Category | Fields |
|---|---|
| Account and identity | Work email address; first, middle and last name; dial code and direct telephone number; department; designation; username; hashed password. Registration requires a business email address; consumer email providers are refused at signup. |
| Organisation | Company name; industry; operating region; headquarters state and country; company dial code and telephone number. |
| Billing | Legal entity name; billing address; billing email address; tax identifiers such as GST, VAT or EIN. We do not collect or store payment card numbers — see Section 12.1. |
| Preferences | Notification settings for activity alerts, task notifications, campaign alerts and contact activity; marketing preferences; interface preferences. |
| Communications | The subject and body of support requests, feedback and correspondence, together with your account email address so that we may reply. |
Contacts imported by file upload; leads generated within a campaign; company and contact attributes such as employer, role, seniority, location, headcount band and revenue band; notes; tasks; calendar events; message threads from connected mailboxes; and the scores, stage history and audit trail the Platform computes against them. We act as processor for all of it.
Where you authorise it: message headers, bodies, attachments metadata and threading identifiers from a connected mailbox; and event titles, times, attendees and locations from a connected calendar. Section 9 describes the scopes requested and how to revoke them.
| Category | Fields |
|---|---|
| Technical | IP address; browser type and version; device type; operating system and version; screen dimensions; language and locale; referring URL. |
| Usage | Pages and features accessed; timestamps and session duration; search terms entered within the Platform; export and import actions; workflow activity. |
| Audit | Field-level change history across campaigns, contacts, leads and billing, recording the actor, the timestamp, the prior value and the new value. |
| Security | Authentication attempts including failures; rate-limit events; session identifiers and rotation events; source addresses associated with suspected abuse. |
| Diagnostic | Error messages, stack traces and performance timings generated when something fails. These may incidentally contain identifiers present in the failing request. |
Business-contact and company records — name, employer, role and seniority, work email address, direct dial, public professional-network profile, company size, industry, headquarters location and publicly reported funding events — together with the intent and market signals scored against them. Section 21 applies.
We do not intentionally collect special categories of personal data as defined by Article 9 of the GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation — nor criminal-offence data under Article 10, nor sensitive personal information as defined by the CCPA. Customers must not upload such data as Customer Data, and Section 22 makes that a contractual obligation. We do not use Personal Data to infer any of these characteristics, and the scoring described in Section 8 operates only on the business attributes listed in Section 5.6.
Where each category comes from, including data we do not obtain from you.
This Section is provided in satisfaction of Article 14 of the GDPR, which requires us to tell you where we obtained your Personal Data when we did not obtain it from you directly.
| Category | Source | Obtained from you? |
|---|---|---|
| Account, organisation, billing, preferences, communications | You, or a colleague administering your workspace | Yes |
| Customer Data | The customer, by upload or by use of the Platform | No — from the customer |
| Mailbox and calendar content | The mail or calendar provider you authorised | Yes, by authorisation |
| Technical, usage, audit, security, diagnostic | Collected automatically from your device | Yes |
| Professional Data | Publicly accessible web pages; public company filings; public professional-network profiles and posts; licensed third-party data providers; customer submissions | No |
| Payment status | Our payment processor, in response to a transaction you initiated | No |
| Enrichment attributes | Licensed data providers, applied to records a customer already holds | No |
We do not acquire Personal Data from data brokers whose collection sources we cannot identify, and we do not build the Professional Data set from cookie tracking, third-party advertising pixels, device fingerprinting, or the content of connected mailboxes.
Every purpose, the data it uses, and the legal basis for it.
The table below states, for each purpose, the categories of Personal Data involved and the legal basis relied upon for individuals in the European Economic Area and the United Kingdom. Section 11 explains the bases themselves.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and authenticate accounts | Account and identity; security | Contract |
| Provide the Platform and its features | Account; Customer Data; mailbox and calendar content | Contract |
| Score and stage prospect records | Customer Data; Professional Data; intent and market signals | Contract, on the customer’s instruction |
| Take payment and manage subscriptions | Billing; commercial | Contract and legal obligation |
| Provide support and investigate faults | Account; usage; diagnostic; communications | Contract |
| Secure the Platform and prevent abuse | Security; technical; usage; audit | Legitimate interests |
| Improve and develop features | Usage; diagnostic, in aggregate | Legitimate interests |
| Send service and administrative messages | Account; preferences | Contract |
| Send marketing about our own products | Account; preferences | Consent, or legitimate interests where permitted |
| Assemble and maintain Professional Data | Professional Data | Legitimate interests |
| Comply with tax, accounting and legal obligations | Billing; account; audit | Legal obligation |
| Establish, exercise or defend legal claims | Any category, as strictly necessary | Legitimate interests |
We do not use Customer Data or connected-mailbox content for our own marketing, and we do not use it to build or enrich the Professional Data set.
How the Platform scores prospects, the logic involved, and the limits of what a score does.
The Platform moves each prospect record through nine sequential stages, S0 to S8, and computes four scores against it: ICP fit, Lead score, BANT and CHAMP. This Section provides meaningful information about the logic involved, as required by Articles 13(2)(f) and 15(1)(h) of the GDPR.
| Stages | What happens |
|---|---|
| S0 — Eliminate noise | Invalid domains, role-based addresses, competitors, existing customers and duplicates are removed. |
| S1 — Firmographic alignment | Industry, headcount band, revenue band, geography and corporate structure are compared with the campaign’s definition. |
| S2 and S3 — Verification | Email address, direct telephone number and professional-network profile are checked for validity and currency. |
| S4 — Ideal customer profile | Surviving records are scored attribute by attribute against the campaign definition, producing an ICP fit score. |
| S5 — Intent scoring | Publicly observable technographic, firmographic, behavioural, social-proof, security and growth signals are scored into a composite. |
| S6 — Market intelligence scoring | News, capital events, hiring velocity and partnership signals are scored per account and folded into the Lead score. BANT and CHAMP are computed at this stage. |
| S7 — Deal momentum | Conversation velocity, meeting density and stakeholder coverage are tracked. |
| S8 — Conversion | Converted records are flagged as customers and may be exported to the customer’s own CRM on instruction. |
OUR POSITION ON ARTICLE 22 — Scores rank prospects. They do not, by themselves, make a decision about you.
Scores order a call list; they do not produce legal effects concerning an individual or similarly significantly affect them, and no score acts without a person. We therefore do not consider this solely automated decision-making within the meaning of Article 22 of the GDPR. If you believe a score has been used to make a decision with legal effect on you, write to [email protected]. We will review it, provide human intervention, explain the outcome, and allow you to contest it.
The most sensitive permission the Platform requests, described in full.
No mailbox or calendar is connected until a user completes the provider’s own OAuth consent screen, or enters IMAP credentials, in Settings. One mail provider and one calendar provider may be active at a time. A connection is made per user, not per organisation, and does not grant other users access to that mailbox.
| Provider | Access requested | Why |
|---|---|---|
| Gmail / Google Workspace | Read, compose, send and modify messages in the connected mailbox | To display threads against the correct lead and to send replies you compose |
| Google Calendar | Read and write events on the connected calendar | To show meetings on the campaign calendar and to create invitations you schedule |
| Microsoft 365 / Outlook | Read and send mail; read and write calendar events | As above |
| IMAP and SMTP | Mailbox credentials supplied by you, used to read and send | For mailboxes not offered through OAuth |
| CalDAV | Calendar credentials supplied by you | For calendars not offered through OAuth |
LIMITS WE PLACE ON MAILBOX CONTENT — We do not read your mail for advertising, and we do not train models on it.
Connected-mailbox content is used to render your inbox, associate conversations with the correct lead, and allow you to reply. It is not used to build or enrich the Professional Data set, not sold, not disclosed to other customers, not used for our own marketing, and not used to train shared machine-learning models.
Three defined uses, and the commitments attached to them.
For individuals in the European Economic Area and the United Kingdom.
| Legal basis | Applied to |
|---|---|
| Performance of a contract — Art. 6(1)(b) | Creating and operating your account, providing the Platform, taking payment and supporting you. |
| Legitimate interests — Art. 6(1)(f) | Securing the Platform, preventing fraud and abuse, improving features, defending legal claims, and assembling Professional Data about individuals in their professional capacity. |
| Consent — Art. 6(1)(a) | Marketing email where consent is required, non-essential cookies, and any connected mailbox or calendar. Withdrawal is available at any time and does not affect prior processing. |
| Legal obligation — Art. 6(1)(c) | Tax, accounting and statutory record-keeping, and responding to lawful requests from authorities. |
Where we rely on legitimate interests we have carried out a balancing assessment weighing those interests against your rights and freedoms, considering the nature of the data, the reasonable expectations of the individual, and the availability of an opt-out. For Professional Data the assessment records that the data concerns individuals acting in a business capacity, is limited to work-related attributes, excludes special categories, and is subject to the unconditional opt-out in Section 21. A summary is available on request from [email protected].
Providing account and billing data is necessary to enter into and perform our contract with you; without it we cannot provide the Platform. Providing marketing consent, and connecting a mailbox or calendar, are entirely optional and refusing them has no effect on your access to the Platform beyond the loss of the feature concerned.
Recipients, their location, and the safeguard applied to each.
We do not sell Personal Data. We disclose it only as set out below. Every sub-processor is engaged under a written contract imposing confidentiality, security obligations and processing limited to our documented instructions, and is assessed for security and privacy practice before engagement.
| Recipient | Purpose | Transfer safeguard |
|---|---|---|
| Razorpay | Payment processing. Receives an order identifier and receipt reference only. Card details are captured by the processor’s hosted checkout and never reach our systems. | Contractual; processing within India |
| Where a user connects Gmail or Google Calendar; and Google Analytics on our public website. | Standard Contractual Clauses | |
| Microsoft | Where a user connects a Microsoft 365 mailbox or calendar. | Standard Contractual Clauses |
| Matomo | Product and website analytics, self-hosted on infrastructure we control. | None required — data remains within our environment |
| Email delivery provider | Transmission of transactional and campaign email. Content is limited to what the sender composed. | Standard Contractual Clauses |
| Cloud hosting provider | Application and database hosting in the region selected for the workspace. | Regional residency; Standard Contractual Clauses where applicable |
We maintain a current list of sub-processors and give at least 30 days’ notice before appointing a new one. A customer may object on reasonable data-protection grounds, in which case we will work in good faith to provide an alternative or permit termination of the affected service without penalty.
Where data is held and the safeguards applied.
| Residency regions | United States · European Union · United Kingdom · Asia-Pacific. The region is fixed for a workspace on the Enterprise package and is selected at provisioning. |
|---|---|
| EEA and UK transfers | Transfers outside the EEA or UK rely on Standard Contractual Clauses, or the UK International Data Transfer Addendum, together with supplementary technical measures including encryption in transit and at rest. |
| Transfer impact assessment | Carried out before engaging a sub-processor in a third country, considering the destination’s legal regime and the practical risk of government access. |
| Onward transfers | Sub-processors are contractually prohibited from transferring Personal Data onward except under equivalent safeguards. |
| Copy of safeguards | Available on request from [email protected]. |
The technical and organisational measures we apply.
| Tenancy | Database isolation per tenant by default; a dedicated private network is available on the Enterprise package. |
|---|---|
| Encryption | AES-256 at rest and TLS in transit. Connected-mailbox tokens and IMAP credentials are encrypted at rest under separately managed keys. |
| Authentication | Session rotation on login to defeat fixation; modern password hashing with transparent upgrade on next sign-in; rate limiting per source address and per account; lockout after repeated failures; HttpOnly and SameSite session cookies. SAML and OIDC single sign-on and SCIM provisioning are available on the Enterprise package. |
| Access control | Per-campaign visibility for users. Internal administrative access is limited to personnel who require it for a defined task, is logged, and is reviewed periodically. |
| Audit logging | Field-level change history recording actor, timestamp, prior value and new value across campaigns, contacts, leads and billing. |
| Backups | Regular backups with periodically tested restoration. |
No system is perfectly secure, and we do not claim otherwise. Section 15 sets out what happens if something goes wrong.
What we do if Personal Data is compromised.
How long each category is kept, and what starts the clock.
| Category | Retention period | Trigger |
|---|---|---|
| Account data | Life of the account, then deleted or anonymised | Account closure |
| Customer Data | 90 days after cancellation to permit export or reinstatement, then permanent deletion within a further 30 days. A certificate of deletion is available on request. | Subscription cancellation |
| Connected-mailbox content | As Customer Data, or immediately on customer deletion | Disconnection does not itself delete logged messages |
| Billing and invoices | As long as tax and accounting law requires, irrespective of account closure | Statutory period from the transaction |
| Audit logs | Up to seven years | Date of the logged event |
| Security logs | Up to 24 months | Date of the event |
| Diagnostic and error logs | Up to 90 days | Date generated |
| Professional Data | Until removal is requested, or until the record ceases to be accurate or useful | Opt-out request under Section 21 |
| Suppression list | Indefinitely, as a hashed email address only | Necessary to prevent a removed record being re-created |
| Marketing preferences | A reasonable period following your last interaction | Last opened message or last sign-in |
| Support correspondence | Up to 36 months | Closure of the request |
| Cookie data | As stated in Section 17 | Set at the time of collection |
Where deletion is not immediately possible for technical reasons — for example within a backup taken before the request — we isolate the data from further processing and delete it when the backup cycles out.
Precisely what runs, for how long, and how to refuse it.
| Cookie or technology | Provider | Purpose | Duration |
|---|---|---|---|
| PHPSESSID | Zscaling — first party | Maintains your session while you are signed in | Session |
| auth | Zscaling — first party | Holds an authentication token so you remain signed in. HttpOnly and SameSite, so it is not readable by scripts. | Until sign-out or expiry |
| _pk_id | Matomo — self-hosted | Distinguishes returning visitors for analytics | Up to 13 months |
| _pk_ses | Matomo — self-hosted | Groups requests into a single analytics session | 30 minutes |
| _ga and _ga_* | Google Analytics | Aggregate measurement of our public website | Up to 24 months |
| Advertising cookies | None | We operate no third-party advertising pixel on the Platform | — |
You may refuse or delete cookies through your browser settings and through the privacy controls your operating system provides. Strictly necessary cookies cannot be disabled because the Platform cannot authenticate you without them; refusing analytics cookies has no effect on your use of the Platform.
Where your browser transmits a Global Privacy Control signal, we treat it as a valid request to opt out of any sale or sharing of personal information. Because we neither sell nor share personal information as those terms are defined by the CCPA, the signal changes nothing in practice, but it is honoured. There is no consensus industry standard for Do Not Track headers and we do not currently respond to them separately.
What we send, on what basis, and how to stop it.
| Message type | Basis | Can you opt out? |
|---|---|---|
| Service and administrative — billing, security, outages, policy changes | Necessary to perform the contract | No, while the account is open |
| Product updates and feature announcements | Legitimate interests, or consent where required | Yes |
| Marketing about our own products | Consent, or legitimate interests where permitted | Yes |
| Event invitations and webinars | Consent | Yes |
| Research and feedback requests | Legitimate interests | Yes |
We do not use postal mail or SMS for marketing, and we do not sell or rent our marketing list to anyone.
What you may ask for, how to ask, and what happens next.
Subject to the law applicable to you, you have the following rights.
| Where to send it | [email protected] |
|---|---|
| What to include | Your name, the email address associated with the data, and what you are asking for. For Professional Data, the employer shown on the record. |
| Verification | We verify identity proportionately to the sensitivity of the request — usually by confirming control of the email address concerned. For broad access or deletion requests we may ask for further evidence. We do not require an account to make a request. |
| Authorised agents | Permitted. We verify the agent’s written authority and the identity of the individual on whose behalf they act. |
| Acknowledgement | Within 5 business days. |
| Response | Within 30 days. Complex or numerous requests may be extended by a further 60 days, with reasons given before the first period expires. |
| Cost | Free. A reasonable fee may be charged only for manifestly unfounded or excessive requests, and we will tell you before charging anything. |
Where an exemption applies we will tell you which one and why, rather than simply declining. You may ask us to reconsider by replying to our response, and a different person will review it. You may also complain to a supervisory authority at any time — you do not need to exhaust our internal process first.
| If you are in | You may complain to |
|---|---|
| The European Economic Area | Your national data protection authority. The European Data Protection Board publishes the current list of members. |
| The United Kingdom | The Information Commissioner’s Office. |
| India | The Data Protection Board of India, established under the Digital Personal Data Protection Act 2023. |
| Singapore | The Personal Data Protection Commission. |
| California | The California Privacy Protection Agency or the Attorney General. |
Where we act as processor, direct your request to the customer that controls the data. We will assist that customer in responding, as our Data Processing Agreement requires, and we will identify the customer to you if you do not know who they are.
Made under the California Consumer Privacy Act as amended by the CPRA.
This Section applies to California residents and supplements the rest of this Policy. Terms used here have the meanings given in the CCPA.
| CCPA category | Collected | Source | Disclosed for a business purpose to |
|---|---|---|---|
| Identifiers — name, email, telephone, IP address | Yes | You; your organisation; public and licensed sources | Hosting, email delivery, payment processor |
| Commercial information — subscriptions, transactions | Yes | You | Payment processor |
| Internet or network activity — usage, interactions | Yes | Collected automatically | Analytics providers |
| Professional or employment information — employer, role, seniority | Yes | You; public and licensed sources | Customers using enrichment features |
| Inferences — ICP, Lead, BANT and CHAMP scores | Yes | Derived by us | The customer whose campaign the record belongs to |
| Sensitive personal information | No | — | — |
| Biometric, geolocation, education, or protected classifications | No | — | — |
We retain each category for the period stated in Section 16. We do not retain personal information for longer than reasonably necessary for the purpose for which it was collected.
We do not sell personal information and we do not share personal information for cross-context behavioural advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve months, and we do not knowingly sell or share the personal information of consumers under 16.
Submit a request to [email protected], or through an authorised agent with written permission and verification of your identity. We will confirm receipt within 10 business days and respond within 45 calendar days, extendable once by a further 45 days with notice. Requests are free of charge.
For individuals who never registered and have found their work details in our dataset.
We assemble business-contact records — name, employer, role and seniority, work email address, direct dial and public professional profile — from publicly accessible web pages, public filings, public professional-network posts and licensed data providers. We rely on legitimate interests, on the basis that work-related contact information carries a lower expectation of privacy than information about private life. You are entitled to disagree and to require us to stop, without giving a reason.
This Section, together with Section 6, constitutes the notice required by Article 14 of the GDPR where we obtain Personal Data other than from the individual concerned.
| How to opt out | Email [email protected] from any address with the subject line “Professional data opt-out”, stating the name and employer shown on the record. |
|---|---|
| What we do | We locate every matching record and remove it from the dataset, retaining a minimal suppression entry — your email address in hashed form — so that the record is not re-created when we next refresh from public sources. |
| Timescale | Within 30 days, and usually sooner. |
| Confirmation | We confirm in writing when removal is complete. |
| What we cannot do | We cannot recall copies a customer exported to its own systems before your request. We will identify which customers received the record so that you may approach them directly. |
| No detriment | Opting out has no consequence for you. We do not maintain any list of individuals who have objected other than the hashed suppression entry. |
What a customer must warrant when it uploads data to the Platform.
Where we act as processor, the customer is the controller and bears the corresponding obligations. By uploading Customer Data a customer warrants that:
These obligations are set out in full in the Data Processing Agreement forming part of the Customer Terms of Service. Breach may result in suspension or termination of the service.
The Platform is not intended for children.
The Platform is a business tool sold to organisations and is not directed to, nor intended for, anyone under the age of 16, or the higher age of consent applicable in your jurisdiction. We do not knowingly collect Personal Data from children. Registration requires a business email address, which makes inadvertent collection unlikely. Customers are contractually prohibited from uploading data relating to children. If you believe we hold data relating to a child, write to [email protected] and we will delete it promptly and confirm that we have done so.
The law that applies and the route to resolution.
| India | Governed by the laws of India, including the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023. The courts at Pune, Maharashtra have exclusive jurisdiction. Unresolved disputes are referred to arbitration under the Arbitration and Conciliation Act 1996, seated in Pune. |
|---|---|
| Singapore | Governed by the laws of Singapore, including the Personal Data Protection Act 2012. Unresolved disputes are referred to arbitration or mediation in Singapore under SIAC or SMC rules. |
| First step | Before either, write to [email protected]. Most complaints are resolved in a single exchange. |
| Your statutory rights | Nothing in this Section limits any right you have to complain to a supervisory authority or to a remedy available to you under applicable data protection law. |
How we tell you when this document moves.
We update this Policy when our practices, the Platform or the law change. Material changes — those that expand the purposes of processing, add a category of recipient, or reduce your rights — are notified by email or by in-product notice at least 14 days before they take effect. Non-material changes take effect on posting.
The effective date at the front of this document identifies the version you are reading. Prior versions are retained and available on request. Continued use of the Platform after a change takes effect constitutes acceptance of the updated Policy; if you do not accept it, you may close your account and request deletion under Section 19.
Monitored addresses, not a form that goes nowhere.
| Privacy enquiries and data-subject requests | [email protected] |
|---|---|
| Security vulnerability disclosure | [email protected] |
| Data protection contact | Privacy and Data Protection Officer, care of [email protected] |
| Legal entity | Zscaling Pvt. Ltd. |
| Registered address | [to be inserted] |
| Effective | 21 August 2026 · supersedes Version 3.1, 21 August 2026 |
Stated here for visibility; the Terms of Service govern.
These are commercial terms rather than data-protection terms. They are set out in full in Sections 6.4 and 7.3 of the Terms of Service, which prevail over this summary if the two ever differ.
Cancelling a subscription does not by itself delete your data. Section 16 sets out how long each category is retained after cancellation, and Section 19 explains how to request deletion.
Where each statutory disclosure requirement is satisfied.
This annex is provided to assist review. It forms part of the Policy for reference only and does not limit the sections to which it refers.
| Requirement | Section |
|---|---|
| 13(1)(a) Identity and contact details of the controller | 3 |
| 13(1)(b) Contact details of the data protection contact | 3 |
| 13(1)(c) Purposes and legal basis | 7, 11 |
| 13(1)(d) Legitimate interests pursued | 11.1 |
| 13(1)(e) Recipients or categories of recipients | 12 |
| 13(1)(f) Transfers to third countries and safeguards | 13 |
| 13(2)(a) Retention period or criteria | 16 |
| 13(2)(b) Rights of access, rectification, erasure, restriction, objection, portability | 19 |
| 13(2)(c) Right to withdraw consent | 19 |
| 13(2)(d) Right to lodge a complaint with a supervisory authority | 19.3 |
| 13(2)(e) Whether provision is statutory or contractual and the consequences | 11.2 |
| 13(2)(f) Automated decision-making, including profiling, and the logic involved | 8 |
| Requirement | Section |
|---|---|
| 14(1)(d) Categories of personal data concerned | 5.6 |
| 14(2)(b) Legitimate interests pursued | 11.1, 21 |
| 14(2)(f) Source of the personal data, including publicly accessible sources | 6, 21 |
| Notice and unconditional opt-out route | 21 |
| Requirement | Section |
|---|---|
| Art. 28 Processor obligations and sub-processor engagement | 12.1, 22 |
| Art. 32 Security of processing | 14 |
| Art. 33 and 34 Breach notification to authority and data subject | 15 |
| Art. 27 Representative in the EEA or UK | 3 — to be appointed if required |
| Art. 12 Transparency, modality and timescales for responses | 19.1 |
| Requirement | Section |
|---|---|
| Categories collected, sources, purposes, recipients | 20.1 |
| Retention disclosure | 16, 20.2 |
| Sale and sharing disclosure | 20.3 |
| Consumer rights and how to exercise them | 20.4, 20.5 |
| Authorised agent | 19.1, 20.5 |
| Non-discrimination and financial incentives | 20.4 |
| Sensitive personal information | 5.7, 20.1 |
| Global Privacy Control | 17.2 |
| Requirement | Section |
|---|---|
| DPDP Act 2023 (India) — grievance route and Data Protection Board | 19.3, 24 |
| PDPA 2012 (Singapore) — complaint route | 19.3, 24 |
| Children | 23 |
| Marketing and anti-spam | 18, 22 |