Zscaling Logo Zscaling
  • Home
  • Services
    • Lead Management
    • Account Based Marketing
    • B2B Appointment Setting
    • Digital Marketing
  • Products
    • Content Syndication
    • PRM
    • Business Development Kit
    • Enterprise Sales Software
  • ZsPRM
  • Careers
  • Contact_Us
  • Whitepapers

How Zscaling Pvt. Ltd. collects, uses, shares and protects personal data in connection with the ZsPRM platform, its mobile applications, and our websites.

Version 3.2 · Effective 21 August 2026 · Supersedes Version 3.1

1. Introduction and Scope

What this Policy covers and who it is for.

Zscaling Pvt. Ltd. (“Zscaling”, “we”, “our” or “us”) provides ZsPRM, a Prospect Relationship Manager for business-to-business revenue teams. This Privacy Policy explains how we collect, use, disclose, transfer and retain personal data, the legal bases on which we do so, and the rights available to you.

This Policy applies to the ZsPRM web application; the ZsPRM applications for iOS and Android; zsprm.com and zscaling.com; and any related service that links to this Policy (together, the “Platform”). It does not apply to any third-party product you connect to the Platform, which is governed by that provider’s own policy, nor to any website we link to but do not operate.

By accessing or using the Platform you confirm that you have read and understood this Policy. If you do not agree with it, please do not use the Platform.

Effective date21 August 2026
SupersedesVersion 3.1, 21 August 2026
Data controllerZscaling Pvt. Ltd.
Privacy contact[email protected]
Security contact[email protected]
Governing languageEnglish. Where this Policy is translated and a conflict arises, the English text prevails.

2. Definitions

The terms used throughout this Policy.

Personal DataAny information relating to an identified or identifiable natural person.
Customer DataPersonal Data a customer uploads to, or generates within, the Platform — contacts, leads, notes, tasks, events, message threads, and the scores computed against them.
Professional DataBusiness-contact records about individuals in their professional capacity, assembled from public and licensed sources. See Section 21.
ControllerThe party that determines the purposes and means of processing.
ProcessorThe party that processes Personal Data on a controller’s documented instructions.
Sub-processorA processor engaged by us to carry out processing on a customer’s behalf. See Section 12.1.
CustomerAn organisation that subscribes to the Platform.
UserAn individual who accesses the Platform under a customer’s subscription.
YouThe reader — a customer, a user, a website visitor, or an individual whose Professional Data we hold.

3. Who We Are and How to Contact Us

Controller identity and the routes to reach us.

Legal entityZscaling Pvt. Ltd.
Privacy enquiries and data-subject requests[email protected]
Security vulnerability disclosure[email protected] · zsprm.com/.well-known/security.txt
Data protection contactPrivacy and Data Protection Officer, care of [email protected]
Registered address[to be inserted]
EEA / UK Article 27 representative[to be appointed if required — see Annex A]
Response acknowledgementWithin 5 business days of receipt

If you require this Policy in an alternative format because of a disability — large print, plain text, or screen-reader-friendly HTML — contact us at [email protected] and we will provide one at no charge.

4. The Roles We Play

Whether we are controller or processor depends on the context.

  • As controller: When you create an account, visit our websites, contact support, or purchase a subscription, we determine why and how your Personal Data is processed. Sections 19 and 20 apply to you directly.
  • As processor: When a customer loads contacts into a campaign, we process that Customer Data only on the customer’s documented instructions, under the Data Processing Agreement in the Customer Terms of Service. Section 22 sets out what the customer must warrant.
  • As controller of Professional Data: For business-contact records we assemble from public and licensed sources, we are the controller. Section 21 explains this and how to opt out.

IMPORTANT — If a company contacted you using ZsPRM, we are its processor — not its controller.

We cannot unsubscribe you from another organisation’s campaign, and we cannot delete a record that organisation controls. Use the opt-out in the message you received, or contact that organisation directly. If you do not know who they are, write to [email protected] with a copy of the message and we will identify them within 30 days so that you can exercise your rights against them.

5. Information We Collect

Every category of Personal Data we process, at field level.

5.1 Information you provide directly

CategoryFields
Account and identityWork email address; first, middle and last name; dial code and direct telephone number; department; designation; username; hashed password. Registration requires a business email address; consumer email providers are refused at signup.
OrganisationCompany name; industry; operating region; headquarters state and country; company dial code and telephone number.
BillingLegal entity name; billing address; billing email address; tax identifiers such as GST, VAT or EIN. We do not collect or store payment card numbers — see Section 12.1.
PreferencesNotification settings for activity alerts, task notifications, campaign alerts and contact activity; marketing preferences; interface preferences.
CommunicationsThe subject and body of support requests, feedback and correspondence, together with your account email address so that we may reply.

5.2 Customer Data you upload or generate

Contacts imported by file upload; leads generated within a campaign; company and contact attributes such as employer, role, seniority, location, headcount band and revenue band; notes; tasks; calendar events; message threads from connected mailboxes; and the scores, stage history and audit trail the Platform computes against them. We act as processor for all of it.

5.3 Information from connected mailboxes and calendars

Where you authorise it: message headers, bodies, attachments metadata and threading identifiers from a connected mailbox; and event titles, times, attendees and locations from a connected calendar. Section 9 describes the scopes requested and how to revoke them.

5.4 Information collected automatically

CategoryFields
TechnicalIP address; browser type and version; device type; operating system and version; screen dimensions; language and locale; referring URL.
UsagePages and features accessed; timestamps and session duration; search terms entered within the Platform; export and import actions; workflow activity.
AuditField-level change history across campaigns, contacts, leads and billing, recording the actor, the timestamp, the prior value and the new value.
SecurityAuthentication attempts including failures; rate-limit events; session identifiers and rotation events; source addresses associated with suspected abuse.
DiagnosticError messages, stack traces and performance timings generated when something fails. These may incidentally contain identifiers present in the failing request.

5.5 Information collected by the mobile applications

  • Device identifiers: Operating system and version, device model, application version and build number.
  • Session state: An authentication token held in the device’s secure storage, so that you are not asked to sign in on every launch.
  • Not collected: The applications do not collect precise geolocation, contacts stored on the device, photographs, the microphone, or advertising identifiers, and contain no third-party advertising or attribution software development kit.

5.6 Professional Data

Business-contact and company records — name, employer, role and seniority, work email address, direct dial, public professional-network profile, company size, industry, headquarters location and publicly reported funding events — together with the intent and market signals scored against them. Section 21 applies.

5.7 Special categories of personal data

We do not intentionally collect special categories of personal data as defined by Article 9 of the GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation — nor criminal-offence data under Article 10, nor sensitive personal information as defined by the CCPA. Customers must not upload such data as Customer Data, and Section 22 makes that a contractual obligation. We do not use Personal Data to infer any of these characteristics, and the scoring described in Section 8 operates only on the business attributes listed in Section 5.6.

6. Sources of the Information We Collect

Where each category comes from, including data we do not obtain from you.

This Section is provided in satisfaction of Article 14 of the GDPR, which requires us to tell you where we obtained your Personal Data when we did not obtain it from you directly.

CategorySourceObtained from you?
Account, organisation, billing, preferences, communicationsYou, or a colleague administering your workspaceYes
Customer DataThe customer, by upload or by use of the PlatformNo — from the customer
Mailbox and calendar contentThe mail or calendar provider you authorisedYes, by authorisation
Technical, usage, audit, security, diagnosticCollected automatically from your deviceYes
Professional DataPublicly accessible web pages; public company filings; public professional-network profiles and posts; licensed third-party data providers; customer submissionsNo
Payment statusOur payment processor, in response to a transaction you initiatedNo
Enrichment attributesLicensed data providers, applied to records a customer already holdsNo

We do not acquire Personal Data from data brokers whose collection sources we cannot identify, and we do not build the Professional Data set from cookie tracking, third-party advertising pixels, device fingerprinting, or the content of connected mailboxes.

7. How We Use Your Information

Every purpose, the data it uses, and the legal basis for it.

The table below states, for each purpose, the categories of Personal Data involved and the legal basis relied upon for individuals in the European Economic Area and the United Kingdom. Section 11 explains the bases themselves.

PurposeData usedLegal basis
Create and authenticate accountsAccount and identity; securityContract
Provide the Platform and its featuresAccount; Customer Data; mailbox and calendar contentContract
Score and stage prospect recordsCustomer Data; Professional Data; intent and market signalsContract, on the customer’s instruction
Take payment and manage subscriptionsBilling; commercialContract and legal obligation
Provide support and investigate faultsAccount; usage; diagnostic; communicationsContract
Secure the Platform and prevent abuseSecurity; technical; usage; auditLegitimate interests
Improve and develop featuresUsage; diagnostic, in aggregateLegitimate interests
Send service and administrative messagesAccount; preferencesContract
Send marketing about our own productsAccount; preferencesConsent, or legitimate interests where permitted
Assemble and maintain Professional DataProfessional DataLegitimate interests
Comply with tax, accounting and legal obligationsBilling; account; auditLegal obligation
Establish, exercise or defend legal claimsAny category, as strictly necessaryLegitimate interests

We do not use Customer Data or connected-mailbox content for our own marketing, and we do not use it to build or enrich the Professional Data set.

8. Automated Evaluation and Scoring

How the Platform scores prospects, the logic involved, and the limits of what a score does.

The Platform moves each prospect record through nine sequential stages, S0 to S8, and computes four scores against it: ICP fit, Lead score, BANT and CHAMP. This Section provides meaningful information about the logic involved, as required by Articles 13(2)(f) and 15(1)(h) of the GDPR.

8.1 The stages

StagesWhat happens
S0 — Eliminate noiseInvalid domains, role-based addresses, competitors, existing customers and duplicates are removed.
S1 — Firmographic alignmentIndustry, headcount band, revenue band, geography and corporate structure are compared with the campaign’s definition.
S2 and S3 — VerificationEmail address, direct telephone number and professional-network profile are checked for validity and currency.
S4 — Ideal customer profileSurviving records are scored attribute by attribute against the campaign definition, producing an ICP fit score.
S5 — Intent scoringPublicly observable technographic, firmographic, behavioural, social-proof, security and growth signals are scored into a composite.
S6 — Market intelligence scoringNews, capital events, hiring velocity and partnership signals are scored per account and folded into the Lead score. BANT and CHAMP are computed at this stage.
S7 — Deal momentumConversation velocity, meeting density and stakeholder coverage are tracked.
S8 — ConversionConverted records are flagged as customers and may be exported to the customer’s own CRM on instruction.

8.2 What the scores mean

  • ICP fit: How closely a record matches the campaign’s stated ideal-customer definition, computed only from business attributes.
  • Lead score: A weighted composite of ICP fit, intent signals and recorded activity.
  • BANT: Budget, authority, need and timeline, each scored and combined.
  • CHAMP: Challenges, authority, money and prioritisation, each scored and combined.

8.3 Safeguards

  • Decomposability: Every score can be opened to show the attribute-by-attribute arithmetic behind it. There is no opaque model output.
  • No autonomous action: No score causes a message to be sent, a meeting to be booked, or a person to be contacted. A user must act.
  • Human intervention: You may request human review of any score affecting you, and we will provide it.
  • Correction: If a score rests on an inaccurate attribute, correcting the attribute under Section 19 causes the score to be recomputed.

OUR POSITION ON ARTICLE 22 — Scores rank prospects. They do not, by themselves, make a decision about you.

Scores order a call list; they do not produce legal effects concerning an individual or similarly significantly affect them, and no score acts without a person. We therefore do not consider this solely automated decision-making within the meaning of Article 22 of the GDPR. If you believe a score has been used to make a decision with legal effect on you, write to [email protected]. We will review it, provide human intervention, explain the outcome, and allow you to contest it.

9. Connected Mailboxes and Calendars

The most sensitive permission the Platform requests, described in full.

9.1 How a connection is made

No mailbox or calendar is connected until a user completes the provider’s own OAuth consent screen, or enters IMAP credentials, in Settings. One mail provider and one calendar provider may be active at a time. A connection is made per user, not per organisation, and does not grant other users access to that mailbox.

9.2 Permissions requested

ProviderAccess requestedWhy
Gmail / Google WorkspaceRead, compose, send and modify messages in the connected mailboxTo display threads against the correct lead and to send replies you compose
Google CalendarRead and write events on the connected calendarTo show meetings on the campaign calendar and to create invitations you schedule
Microsoft 365 / OutlookRead and send mail; read and write calendar eventsAs above
IMAP and SMTPMailbox credentials supplied by you, used to read and sendFor mailboxes not offered through OAuth
CalDAVCalendar credentials supplied by youFor calendars not offered through OAuth

9.3 How credentials and tokens are held

  • OAuth tokens: Stored encrypted and used only to perform the actions described above. Tokens are not shared between customers and are never exposed to client-side code.
  • IMAP and SMTP credentials: Stored encrypted at rest. Where a provider offers OAuth we recommend it in preference to storing a password.
  • Revocation: Disconnecting in Settings revokes the token immediately and stops synchronisation. You may also revoke access directly with the provider, which has the same effect.

9.4 What we do with the content

  • Association: Sent and received mail is matched to a lead by comparing email addresses. Matching is an address comparison, not an analysis of message content.
  • Sending: Messages you compose and calendar invitations you create are sent from your own authenticated mailbox, not from ours, and appear in your own Sent folder.
  • Retention after disconnection: Messages already logged remain part of the customer’s Customer Data until the customer deletes them or the retention period in Section 16 expires.

LIMITS WE PLACE ON MAILBOX CONTENT — We do not read your mail for advertising, and we do not train models on it.

Connected-mailbox content is used to render your inbox, associate conversations with the correct lead, and allow you to reply. It is not used to build or enrich the Professional Data set, not sold, not disclosed to other customers, not used for our own marketing, and not used to train shared machine-learning models.

10. Artificial Intelligence

Three defined uses, and the commitments attached to them.

  • Campaign planning: Reading a campaign’s funnel and proposing dated tasks for the coming quarter. Proposals are displayed for review and nothing is saved until a user confirms.
  • Signal summarisation: Rendering collected intent and market signals into plain-language summaries, so that a user need not read every source.
  • In-product assistant: Answering natural-language questions about the customer’s own workspace, scoped to data that user is already permitted to see.

10.1 Commitments

  • Generative, never autonomous: The Platform does not send an email, book a meeting or contact a prospect without a person expressly approving it.
  • No shared-model training: Customer Data and connected-mailbox content are not used to train shared or third-party models. Prompts and outputs remain within your tenant.
  • Scoped to permission: The assistant cannot surface data the requesting user could not already open directly.
  • Opt-out: Where a customer asks us to use its Customer Data to improve features specific to its own workspace, that is agreed in writing and may be withdrawn at any time by writing to [email protected].

11. Legal Bases for Processing

For individuals in the European Economic Area and the United Kingdom.

Legal basisApplied to
Performance of a contract — Art. 6(1)(b)Creating and operating your account, providing the Platform, taking payment and supporting you.
Legitimate interests — Art. 6(1)(f)Securing the Platform, preventing fraud and abuse, improving features, defending legal claims, and assembling Professional Data about individuals in their professional capacity.
Consent — Art. 6(1)(a)Marketing email where consent is required, non-essential cookies, and any connected mailbox or calendar. Withdrawal is available at any time and does not affect prior processing.
Legal obligation — Art. 6(1)(c)Tax, accounting and statutory record-keeping, and responding to lawful requests from authorities.

11.1 Legitimate-interests assessment

Where we rely on legitimate interests we have carried out a balancing assessment weighing those interests against your rights and freedoms, considering the nature of the data, the reasonable expectations of the individual, and the availability of an opt-out. For Professional Data the assessment records that the data concerns individuals acting in a business capacity, is limited to work-related attributes, excludes special categories, and is subject to the unconditional opt-out in Section 21. A summary is available on request from [email protected].

11.2 Whether provision is required

Providing account and billing data is necessary to enter into and perform our contract with you; without it we cannot provide the Platform. Providing marketing consent, and connecting a mailbox or calendar, are entirely optional and refusing them has no effect on your access to the Platform beyond the loss of the feature concerned.

12. How We Share Your Information

Recipients, their location, and the safeguard applied to each.

We do not sell Personal Data. We disclose it only as set out below. Every sub-processor is engaged under a written contract imposing confidentiality, security obligations and processing limited to our documented instructions, and is assessed for security and privacy practice before engagement.

12.1 Sub-processors

RecipientPurposeTransfer safeguard
RazorpayPayment processing. Receives an order identifier and receipt reference only. Card details are captured by the processor’s hosted checkout and never reach our systems.Contractual; processing within India
GoogleWhere a user connects Gmail or Google Calendar; and Google Analytics on our public website.Standard Contractual Clauses
MicrosoftWhere a user connects a Microsoft 365 mailbox or calendar.Standard Contractual Clauses
MatomoProduct and website analytics, self-hosted on infrastructure we control.None required — data remains within our environment
Email delivery providerTransmission of transactional and campaign email. Content is limited to what the sender composed.Standard Contractual Clauses
Cloud hosting providerApplication and database hosting in the region selected for the workspace.Regional residency; Standard Contractual Clauses where applicable

We maintain a current list of sub-processors and give at least 30 days’ notice before appointing a new one. A customer may object on reasonable data-protection grounds, in which case we will work in good faith to provide an alternative or permit termination of the affected service without penalty.

12.2 Other disclosures

  • To your own CRM: On your instruction, records are exported to Salesforce, HubSpot, Pipedrive, Zoho or another destination you select. Once exported, that copy is governed by your agreement with that provider and is outside our control.
  • Within your workspace: Colleagues you invite see the campaigns they own or are assigned to. Access is granted per campaign, not workspace-wide, and is revocable by an administrator.
  • Professional advisers: Auditors, lawyers, accountants and insurers, under duties of confidentiality, where necessary.
  • Legal compulsion: Where required by law, regulation or valid legal process, and to establish, exercise or defend legal claims. Where we are lawfully able to do so, we will notify the affected customer before disclosing Customer Data.
  • Corporate transaction: In connection with a merger, acquisition or sale of assets, with notice to you and no reduction in the protections in this Policy without your consent.

13. International Data Transfers

Where data is held and the safeguards applied.

Residency regionsUnited States · European Union · United Kingdom · Asia-Pacific. The region is fixed for a workspace on the Enterprise package and is selected at provisioning.
EEA and UK transfersTransfers outside the EEA or UK rely on Standard Contractual Clauses, or the UK International Data Transfer Addendum, together with supplementary technical measures including encryption in transit and at rest.
Transfer impact assessmentCarried out before engaging a sub-processor in a third country, considering the destination’s legal regime and the practical risk of government access.
Onward transfersSub-processors are contractually prohibited from transferring Personal Data onward except under equivalent safeguards.
Copy of safeguardsAvailable on request from [email protected].

14. Data Security

The technical and organisational measures we apply.

14.1 Technical measures

TenancyDatabase isolation per tenant by default; a dedicated private network is available on the Enterprise package.
EncryptionAES-256 at rest and TLS in transit. Connected-mailbox tokens and IMAP credentials are encrypted at rest under separately managed keys.
AuthenticationSession rotation on login to defeat fixation; modern password hashing with transparent upgrade on next sign-in; rate limiting per source address and per account; lockout after repeated failures; HttpOnly and SameSite session cookies. SAML and OIDC single sign-on and SCIM provisioning are available on the Enterprise package.
Access controlPer-campaign visibility for users. Internal administrative access is limited to personnel who require it for a defined task, is logged, and is reviewed periodically.
Audit loggingField-level change history recording actor, timestamp, prior value and new value across campaigns, contacts, leads and billing.
BackupsRegular backups with periodically tested restoration.

14.2 Organisational measures

  • Confidentiality: All personnel with access to Personal Data are bound by written confidentiality obligations that survive the end of their engagement.
  • Training: Personnel receive data-protection and security awareness training on joining and periodically thereafter.
  • Least privilege: Access is granted on the principle of least privilege and revoked promptly when a role changes or ends.
  • Secure development: Changes are reviewed before release, and dependencies are monitored for known vulnerabilities.
  • Vendor assessment: Sub-processors are assessed before engagement and reassessed periodically.

No system is perfectly secure, and we do not claim otherwise. Section 15 sets out what happens if something goes wrong.

15. Personal Data Breaches

What we do if Personal Data is compromised.

  • Detection and containment: On becoming aware of a suspected breach we investigate, contain it, and assess the risk to affected individuals.
  • Notification to authorities: Where the breach is likely to result in a risk to the rights and freedoms of individuals, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it.
  • Notification to you: Where the breach is likely to result in a high risk to you, we notify you directly and without undue delay, describing the nature of the breach, the likely consequences, the measures taken, and the steps you can take.
  • Notification to customers: Where the breach affects Customer Data, we notify the customer controller without undue delay so that it can meet its own obligations.
  • Record: We maintain an internal record of breaches, their effects and the remedial action taken, whether or not notification was required.

16. Data Retention

How long each category is kept, and what starts the clock.

CategoryRetention periodTrigger
Account dataLife of the account, then deleted or anonymisedAccount closure
Customer Data90 days after cancellation to permit export or reinstatement, then permanent deletion within a further 30 days. A certificate of deletion is available on request.Subscription cancellation
Connected-mailbox contentAs Customer Data, or immediately on customer deletionDisconnection does not itself delete logged messages
Billing and invoicesAs long as tax and accounting law requires, irrespective of account closureStatutory period from the transaction
Audit logsUp to seven yearsDate of the logged event
Security logsUp to 24 monthsDate of the event
Diagnostic and error logsUp to 90 daysDate generated
Professional DataUntil removal is requested, or until the record ceases to be accurate or usefulOpt-out request under Section 21
Suppression listIndefinitely, as a hashed email address onlyNecessary to prevent a removed record being re-created
Marketing preferencesA reasonable period following your last interactionLast opened message or last sign-in
Support correspondenceUp to 36 monthsClosure of the request
Cookie dataAs stated in Section 17Set at the time of collection

Where deletion is not immediately possible for technical reasons — for example within a backup taken before the request — we isolate the data from further processing and delete it when the backup cycles out.

17. Cookies and Similar Technologies

Precisely what runs, for how long, and how to refuse it.

Cookie or technologyProviderPurposeDuration
PHPSESSIDZscaling — first partyMaintains your session while you are signed inSession
authZscaling — first partyHolds an authentication token so you remain signed in. HttpOnly and SameSite, so it is not readable by scripts.Until sign-out or expiry
_pk_idMatomo — self-hostedDistinguishes returning visitors for analyticsUp to 13 months
_pk_sesMatomo — self-hostedGroups requests into a single analytics session30 minutes
_ga and _ga_*Google AnalyticsAggregate measurement of our public websiteUp to 24 months
Advertising cookiesNoneWe operate no third-party advertising pixel on the Platform—

17.1 Managing cookies

You may refuse or delete cookies through your browser settings and through the privacy controls your operating system provides. Strictly necessary cookies cannot be disabled because the Platform cannot authenticate you without them; refusing analytics cookies has no effect on your use of the Platform.

17.2 Global Privacy Control and Do Not Track

Where your browser transmits a Global Privacy Control signal, we treat it as a valid request to opt out of any sale or sharing of personal information. Because we neither sell nor share personal information as those terms are defined by the CCPA, the signal changes nothing in practice, but it is honoured. There is no consensus industry standard for Do Not Track headers and we do not currently respond to them separately.

18. Marketing Communications

What we send, on what basis, and how to stop it.

Message typeBasisCan you opt out?
Service and administrative — billing, security, outages, policy changesNecessary to perform the contractNo, while the account is open
Product updates and feature announcementsLegitimate interests, or consent where requiredYes
Marketing about our own productsConsent, or legitimate interests where permittedYes
Event invitations and webinarsConsentYes
Research and feedback requestsLegitimate interestsYes

18.1 How to opt out

  • Email: Use the unsubscribe link in any marketing message, or change your preferences in Settings. Unsubscribes take effect within 10 business days at the latest, and usually immediately.
  • In-product notifications: Disable activity alerts, task notifications, campaign alerts or contact activity individually in Settings.
  • Mobile push: Disable notifications for the application in your device settings.
  • Everything at once: Write to [email protected] asking to be removed from all marketing.

We do not use postal mail or SMS for marketing, and we do not sell or rent our marketing list to anyone.

19. Your Privacy Rights and Choices

What you may ask for, how to ask, and what happens next.

Subject to the law applicable to you, you have the following rights.

  • Access: A copy of the Personal Data we hold about you and an explanation of our processing.
  • Rectification: Correction of inaccurate or incomplete data.
  • Erasure: Deletion, subject to any legal obligation requiring us to retain a record.
  • Portability: Your workspace exported in a structured, commonly used, machine-readable format — contacts, campaigns, scores, signals, notes and activity history.
  • Objection: Objection to processing based on legitimate interests, including profiling. For direct marketing the right is absolute and we will stop.
  • Restriction: Restriction of processing while a dispute about accuracy or lawfulness is resolved.
  • Withdrawal of consent: Withdrawal at any time where processing rests on consent, including disconnecting a mailbox or calendar.
  • Human intervention: Review by a person of any automated scoring affecting you, together with the right to express your point of view and contest the outcome.

19.1 How to make a request

Where to send it[email protected]
What to includeYour name, the email address associated with the data, and what you are asking for. For Professional Data, the employer shown on the record.
VerificationWe verify identity proportionately to the sensitivity of the request — usually by confirming control of the email address concerned. For broad access or deletion requests we may ask for further evidence. We do not require an account to make a request.
Authorised agentsPermitted. We verify the agent’s written authority and the identity of the individual on whose behalf they act.
AcknowledgementWithin 5 business days.
ResponseWithin 30 days. Complex or numerous requests may be extended by a further 60 days, with reasons given before the first period expires.
CostFree. A reasonable fee may be charged only for manifestly unfounded or excessive requests, and we will tell you before charging anything.

19.2 If we refuse

Where an exemption applies we will tell you which one and why, rather than simply declining. You may ask us to reconsider by replying to our response, and a different person will review it. You may also complain to a supervisory authority at any time — you do not need to exhaust our internal process first.

19.3 Right to complain to a supervisory authority

If you are inYou may complain to
The European Economic AreaYour national data protection authority. The European Data Protection Board publishes the current list of members.
The United KingdomThe Information Commissioner’s Office.
IndiaThe Data Protection Board of India, established under the Digital Personal Data Protection Act 2023.
SingaporeThe Personal Data Protection Commission.
CaliforniaThe California Privacy Protection Agency or the Attorney General.

19.4 Data held by our customers

Where we act as processor, direct your request to the customer that controls the data. We will assist that customer in responding, as our Data Processing Agreement requires, and we will identify the customer to you if you do not know who they are.

20. Additional Disclosures for California Residents

Made under the California Consumer Privacy Act as amended by the CPRA.

This Section applies to California residents and supplements the rest of this Policy. Terms used here have the meanings given in the CCPA.

20.1 Categories collected, sources, purposes and disclosures

CCPA categoryCollectedSourceDisclosed for a business purpose to
Identifiers — name, email, telephone, IP addressYesYou; your organisation; public and licensed sourcesHosting, email delivery, payment processor
Commercial information — subscriptions, transactionsYesYouPayment processor
Internet or network activity — usage, interactionsYesCollected automaticallyAnalytics providers
Professional or employment information — employer, role, seniorityYesYou; public and licensed sourcesCustomers using enrichment features
Inferences — ICP, Lead, BANT and CHAMP scoresYesDerived by usThe customer whose campaign the record belongs to
Sensitive personal informationNo——
Biometric, geolocation, education, or protected classificationsNo——

20.2 Retention

We retain each category for the period stated in Section 16. We do not retain personal information for longer than reasonably necessary for the purpose for which it was collected.

20.3 Sale and sharing

We do not sell personal information and we do not share personal information for cross-context behavioural advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve months, and we do not knowingly sell or share the personal information of consumers under 16.

20.4 Your California rights

  • Right to know: The categories and specific pieces of personal information collected, the sources, the purposes, and the categories of recipients.
  • Right to delete: Deletion of personal information we collected from you, subject to statutory exceptions.
  • Right to correct: Correction of inaccurate personal information.
  • Right to opt out: Of sale or sharing. Because we do not sell or share, no opt-out mechanism is required; we honour any request and any Global Privacy Control signal nonetheless.
  • Right to limit: Use and disclosure of sensitive personal information. We do not collect sensitive personal information.
  • Right to non-discrimination: We will not deny service, charge a different price, or provide a different quality of service because you exercised a right. We operate no financial-incentive programme in exchange for personal information.

20.5 How to submit a request

Submit a request to [email protected], or through an authorised agent with written permission and verification of your identity. We will confirm receipt within 10 business days and respond within 45 calendar days, extendable once by a further 45 days with notice. Requests are free of charge.

21. Professional Data and How to Opt Out

For individuals who never registered and have found their work details in our dataset.

We assemble business-contact records — name, employer, role and seniority, work email address, direct dial and public professional profile — from publicly accessible web pages, public filings, public professional-network posts and licensed data providers. We rely on legitimate interests, on the basis that work-related contact information carries a lower expectation of privacy than information about private life. You are entitled to disagree and to require us to stop, without giving a reason.

This Section, together with Section 6, constitutes the notice required by Article 14 of the GDPR where we obtain Personal Data other than from the individual concerned.

How to opt outEmail [email protected] from any address with the subject line “Professional data opt-out”, stating the name and employer shown on the record.
What we doWe locate every matching record and remove it from the dataset, retaining a minimal suppression entry — your email address in hashed form — so that the record is not re-created when we next refresh from public sources.
TimescaleWithin 30 days, and usually sooner.
ConfirmationWe confirm in writing when removal is complete.
What we cannot doWe cannot recall copies a customer exported to its own systems before your request. We will identify which customers received the record so that you may approach them directly.
No detrimentOpting out has no consequence for you. We do not maintain any list of individuals who have objected other than the hashed suppression entry.

22. Customer Obligations

What a customer must warrant when it uploads data to the Platform.

Where we act as processor, the customer is the controller and bears the corresponding obligations. By uploading Customer Data a customer warrants that:

  • It has a lawful basis: For the collection and the processing it instructs us to perform, including any profiling or scoring.
  • It has given notice: To the individuals concerned, as its own transparency obligations require.
  • It will not upload special categories: Or criminal-offence data, or sensitive personal information as defined by the CCPA, or data relating to children.
  • It will honour rights: Responding to access, correction, deletion and objection requests from its own data subjects, with our assistance.
  • It will comply with marketing law: Including consent and opt-out requirements applicable to the recipients it contacts through the Platform.

These obligations are set out in full in the Data Processing Agreement forming part of the Customer Terms of Service. Breach may result in suspension or termination of the service.

23. Children’s Privacy

The Platform is not intended for children.

The Platform is a business tool sold to organisations and is not directed to, nor intended for, anyone under the age of 16, or the higher age of consent applicable in your jurisdiction. We do not knowingly collect Personal Data from children. Registration requires a business email address, which makes inadvertent collection unlikely. Customers are contractually prohibited from uploading data relating to children. If you believe we hold data relating to a child, write to [email protected] and we will delete it promptly and confirm that we have done so.

24. Governing Law and Dispute Resolution

The law that applies and the route to resolution.

IndiaGoverned by the laws of India, including the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023. The courts at Pune, Maharashtra have exclusive jurisdiction. Unresolved disputes are referred to arbitration under the Arbitration and Conciliation Act 1996, seated in Pune.
SingaporeGoverned by the laws of Singapore, including the Personal Data Protection Act 2012. Unresolved disputes are referred to arbitration or mediation in Singapore under SIAC or SMC rules.
First stepBefore either, write to [email protected]. Most complaints are resolved in a single exchange.
Your statutory rightsNothing in this Section limits any right you have to complain to a supervisory authority or to a remedy available to you under applicable data protection law.

25. Changes to This Policy

How we tell you when this document moves.

We update this Policy when our practices, the Platform or the law change. Material changes — those that expand the purposes of processing, add a category of recipient, or reduce your rights — are notified by email or by in-product notice at least 14 days before they take effect. Non-material changes take effect on posting.

The effective date at the front of this document identifies the version you are reading. Prior versions are retained and available on request. Continued use of the Platform after a change takes effect constitutes acceptance of the updated Policy; if you do not accept it, you may close your account and request deletion under Section 19.

26. How to Contact Us

Monitored addresses, not a form that goes nowhere.

Privacy enquiries and data-subject requests[email protected]
Security vulnerability disclosure[email protected]
Data protection contactPrivacy and Data Protection Officer, care of [email protected]
Legal entityZscaling Pvt. Ltd.
Registered address[to be inserted]
Effective21 August 2026 · supersedes Version 3.1, 21 August 2026

27. Cancellation and Refunds

Stated here for visibility; the Terms of Service govern.

These are commercial terms rather than data-protection terms. They are set out in full in Sections 6.4 and 7.3 of the Terms of Service, which prevail over this summary if the two ever differ.

  • Refund window: A refund is considered only if it is requested within 7 calendar days of the date the payment was taken. A request made after the seventh day is not considered, and no refund is due for the unused remainder of a paid term.
  • One-time setup fees are never refunded: Any one-time setup, onboarding, implementation, data-migration or training fee is non-refundable in every circumstance, including where a refund of subscription fees is granted.
  • Cancellation notice: To cancel, your notice must reach us at least 30 days before the next subscription period begins. If it arrives later than that, the next period renews and its fee is payable in full, and the cancellation takes effect at the end of that renewed period.
  • Where to write: [email protected] for cancellations and refund requests. [email protected] for anything concerning your personal data.

Cancelling a subscription does not by itself delete your data. Section 16 sets out how long each category is retained after cancellation, and Section 19 explains how to request deletion.

Annex A — Regulatory Mapping

Where each statutory disclosure requirement is satisfied.

This annex is provided to assist review. It forms part of the Policy for reference only and does not limit the sections to which it refers.

A.1 GDPR Article 13 — data collected from the data subject

RequirementSection
13(1)(a) Identity and contact details of the controller3
13(1)(b) Contact details of the data protection contact3
13(1)(c) Purposes and legal basis7, 11
13(1)(d) Legitimate interests pursued11.1
13(1)(e) Recipients or categories of recipients12
13(1)(f) Transfers to third countries and safeguards13
13(2)(a) Retention period or criteria16
13(2)(b) Rights of access, rectification, erasure, restriction, objection, portability19
13(2)(c) Right to withdraw consent19
13(2)(d) Right to lodge a complaint with a supervisory authority19.3
13(2)(e) Whether provision is statutory or contractual and the consequences11.2
13(2)(f) Automated decision-making, including profiling, and the logic involved8

A.2 GDPR Article 14 — data not obtained from the data subject

RequirementSection
14(1)(d) Categories of personal data concerned5.6
14(2)(b) Legitimate interests pursued11.1, 21
14(2)(f) Source of the personal data, including publicly accessible sources6, 21
Notice and unconditional opt-out route21

A.3 Other GDPR obligations

RequirementSection
Art. 28 Processor obligations and sub-processor engagement12.1, 22
Art. 32 Security of processing14
Art. 33 and 34 Breach notification to authority and data subject15
Art. 27 Representative in the EEA or UK3 — to be appointed if required
Art. 12 Transparency, modality and timescales for responses19.1

A.4 CCPA as amended by the CPRA

RequirementSection
Categories collected, sources, purposes, recipients20.1
Retention disclosure16, 20.2
Sale and sharing disclosure20.3
Consumer rights and how to exercise them20.4, 20.5
Authorised agent19.1, 20.5
Non-discrimination and financial incentives20.4
Sensitive personal information5.7, 20.1
Global Privacy Control17.2

A.5 Other regimes

RequirementSection
DPDP Act 2023 (India) — grievance route and Data Protection Board19.3, 24
PDPA 2012 (Singapore) — complaint route19.3, 24
Children23
Marketing and anti-spam18, 22
Zscaling Pvt. Ltd.

Privacy Policy

© 2026 Zscaling Pvt. Ltd. | Terms of Service | Privacy Policy