Last updated: 29.06.26
1. Who We Are
Zynoff UK Limited is the Data Controller for personal data collected directly by us.
Contact: support@zynoff.com
If you are a Subscriber, we act as a Data Processor for personal data you upload relating to your own customers.
2. What Data We Collect
We may collect:
- Account information (name, email, business details).
- Billing details.
- Usage data.
- Device and log information.
- Communications.
- Customer Data uploaded by Subscribers.
3. Lawful Basis for Processing
We process personal data under:
- Contract performance.
- Legitimate interests (service improvement, security).
- Legal obligations.
- Consent, where required.
4. How We Use Data
We use data to provide and maintain the Service, process payments, provide support, improve functionality, and comply with legal obligations.
5. Data Retention
We retain data for the duration of the subscription, for up to 12 months after termination, or longer if required by law.
6. International Transfers
Data may be processed outside the UK. Where this occurs, we implement appropriate safeguards including UK International Data Transfer Agreements and Standard Contractual Clauses.
7. Sub-Processors
We may use third-party providers for cloud hosting, payment processing, email delivery, and analytics. A current list is available upon request.
8. Security
We implement appropriate technical and organisational measures including encryption in transit (SSL/TLS), access controls, and secure hosting environments.
9. Data Subject Rights
You have the right to:
- Access your personal data.
- Correct inaccuracies.
- Request erasure.
- Restrict processing.
- Object to processing.
- Data portability.
- Lodge a complaint with the UK Information Commissioner’s Office (ICO).
ICO website: https://ico.org.uk
Requests may be sent to support@zynoff.com.
10. Data Breach Notification
In the event of a personal data breach affecting Subscriber data, we will notify the Subscriber without undue delay.
11. Cookies
We use cookies and similar technologies to maintain sessions, improve user experience, and analyse usage. A separate Cookie Notice is available.
Data Processing Terms (Embedded Summary)
Where the Subscriber uploads personal data relating to third parties:
- Subscriber is the Data Controller.
- Zynoff acts as Data Processor.
- We process data only on documented instructions.
- We implement appropriate security measures.
- We assist with data subject requests where reasonably possible.
- We delete or return data upon termination, subject to retention requirements.
Data Erasure Request
Individuals may request deletion of their personal data by emailing support@zynoff.com with the subject “Data Deletion Request”. We may require identity verification.
Deletion requests will be processed within one month unless extended under UK GDPR. Certain data may be retained where legally required.
Data Processing Agreement (DPA)
UK GDPR – Zynoff UK Limited
Last updated: 29.06.26
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Zynoff UK Limited (Company No. 15452602) (“Processor”) and the Subscriber (“Controller”).
1. Definitions
UK GDPR: UK General Data Protection Regulation.
Personal Data: as defined under UK GDPR.
Processing: any operation performed on Personal Data.
Data Subject: identified or identifiable individual.
Sub-Processor: third party engaged by Processor.
2. Roles of the Parties
Where the Subscriber uploads Personal Data relating to its own customers, staff, or contacts, the Subscriber acts as Data Controller and Zynoff acts as Data Processor. Zynoff shall process Personal Data only on documented instructions from the Subscriber.
3. Nature & Purpose of Processing
Zynoff processes Personal Data solely for providing the Service, hosting and storing Customer Data, technical support, and maintaining and securing the platform.
Categories of Data may include names, contact details, billing information, invoice data, and business-related transaction information.
Data Subjects may include Subscriber personnel, Subscriber customers, suppliers, and contractors.
4. Processor Obligations
Zynoff shall process data lawfully and only on documented instructions, ensure staff are subject to confidentiality obligations, implement appropriate technical and organisational security measures, not sell Personal Data, and not process data for its own marketing purposes.
5. Security Measures
Zynoff implements encryption in transit (TLS/SSL), access controls and authentication protections, role-based access limitation, secure cloud hosting environments, and regular security updates.
6. Sub-Processors
Zynoff may engage Sub-Processors for cloud hosting, email delivery, analytics, and payment processing. Zynoff shall ensure Sub-Processors are subject to data protection obligations and remain responsible for their compliance. A current list is available upon request.
7. International Transfers
If Personal Data is transferred outside the UK, Zynoff shall implement appropriate safeguards, including a UK International Data Transfer Agreement (IDTA) and Standard Contractual Clauses (SCCs).
8. Data Subject Rights
Zynoff shall, where reasonably possible, assist the Controller in responding to data subject requests and provide relevant data within a reasonable timeframe. The Subscriber remains responsible for responding to data subjects.
9. Data Breach Notification
If Zynoff becomes aware of a Personal Data Breach affecting Subscriber data, Zynoff shall notify the Subscriber without undue delay and provide available details necessary to meet regulatory obligations.
10. Deletion & Return of Data
Upon termination, Zynoff shall make data export available for 30 days. Thereafter, data shall be securely deleted unless required by law.
11. Audit Rights
Upon reasonable notice, the Subscriber may request information necessary to demonstrate compliance with this DPA. Zynoff may satisfy audit requirements through security documentation, certifications, or written confirmations.
12. Liability
Liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA forms part of the Terms and is automatically incorporated upon subscription.
Cookie Policy
Last updated: 29.06.26
1. What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help maintain secure sessions, improve user experience, and analyse usage.
2. Types of Cookies We Use
Essential Cookies are required for login authentication, session management, and security. These cannot be disabled.
Analytics Cookies are used to understand platform usage and improve functionality. These are optional and require consent.
Functional Cookies remember preferences and enhance user experience.
3. Third-Party Cookies
We may use third-party providers such as analytics services and payment processors. These providers may set cookies subject to their own policies.
4. Managing Cookies
You can accept or reject non-essential cookies via our banner, adjust browser settings, and withdraw consent at any time via account settings.
5. Contact
For cookie-related queries: support@zynoff.com.