Privacy Policy
Last updated: June 19, 2026
Zonnetech (“we,” “us,” or “our”) is committed to protecting the privacy, security, and intellectual data of our clients, partners, and website visitors. This Privacy Policy governs our data collection, processing, and storage practices across our corporate website, communication channels, and technical development environments.
1. Information We Collect
We collect information across two main categories: data required to manage our business relationship, and technical telemetry data required to optimize our web infrastructure.
A. Personal and Corporate Identifiers
When you initiate contact, request a technical consultation, or enter into a development contract, we collect:
- Identity Data: Full name, corporate title, and company affiliation.
- Contact Data: Corporate email address, telephone number, physical business address, and messaging handles (e.g., Slack, WhatsApp, or LinkedIn).
- Project and Technical Specifications: Source code access (where authorized), UI blueprints, workflow descriptions, and system architecture diagrams shared during discovery phases.
B. Automated Technical Telemetry
When you interact with our website, our infrastructure logs standard network data via cookies and server logs:
- Device & Usage Data: IP addresses, browser specifications, operating system versions, referring URLs, access times, and clickstream behaviour across our site architecture.
2. Technical Data Architecture and System Isolation
As an engineering firm specializing in custom AI software, automated workflows, and data processing, we enforce strict boundaries regarding data separation:
- Client System Isolation: Any data, API tokens, server credentials, or databases made accessible to Zonnetech during a development cycle or case study analysis remain under the exclusive ownership and control of the client.
- Zero Proprietary Retention: We do not retain, copy, or scrape data processed through the custom software or AI tools we build for our clients unless explicitly required under a signed maintenance contract.
- AI Data Training Boundaries: We strictly adhere to compliant development protocols. The custom AI models, LLM fine-tuning pipelines, and automation tools we build for you are configured to prevent data leakage. Client data is never used to train our proprietary tools or shared with unauthorized foundational model providers.
3. Legal Grounds and Methods for Data Utilization
We process personal and operational data exclusively under the following legal frameworks:
- Performance of a Contract: To draft proposals, manage code deployment milestones, and deliver contracted engineering services.
- Legitimate Interests: To secure our network, prevent malicious traffic, optimize our web design layouts, and maintain clear communications regarding project timelines.
- Explicit Consent: For featuring client case studies, verified performance reviews, and logos on our public-facing platforms.
4. Information Sharing and Disclosure Restraints
Zonnetech enforces a zero-monetisation policy on data. We do not sell, lease, or trade corporate or personal information to third-party brokers or marketing networks. Information is only shared under the following conditions:
- Subcontractors and Infrastructure Providers: We may share project technical telemetry with verified cloud infrastructure providers (e.g., AWS, Google Cloud) or encrypted project management tools under strict Non-Disclosure Agreements (NDAs).
- Legal & Compliance Mandates: We will disclose data if required by a court order, enforceable government request, or to protect the legal rights, safety, and security of Zonnetech and our engineering partners.
5. Enterprise-Grade Security and Retention Protocols
Security is engineered directly into our daily operational workflows:
- Data Protection: We utilize industry-standard encryption protocols for data in transit (TLS 1.3) and at rest (AES-256). Code repositories and client secrets are stored within secure, access-controlled environments utilizing multi-factor authentication (MFA).
- Data Retention: We retain corporate identifiers and communication history for as long as necessary to fulfil our business contract, legal obligations, or resolve active disputes. Upon contract termination and request, all client-side technical assets are permanently purged from our active local development environments.
6. International Data Transfers
Because we build global digital products, the data we process may be transferred to and maintained on servers located outside your state, province, or country. We employ robust cross-border data protection mechanisms, including Standard Contractual Clauses (SCCs), to ensure your data is treated with the same level of security wherever it is located.
7. Your Statutory Rights
Depending on your operational jurisdiction (such as GDPR, CCPA, or regional data protection laws), you possess the following legal rights regarding your information:
- Right to Access & Portability: Request a comprehensive breakdown of all personal data we retain.
- Right to Rectification: Mandate the immediate correction of incomplete or inaccurate data.
- Right to Erasure (“Right to be Forgotten”): Request the permanent deletion of your data from our internal databases, subject to legal or contractual retention overrides.
- Right to Object/Restrict Processing: Limit how we process specific subsets of your operational data.
To exercise any of these rights, submit a formal request to our privacy team at privacy@zonnetech.com.
8. Updates to This Policy
We reserve the right to modify this Privacy Policy to reflect evolving technical frameworks, security standards, or international legal updates. Any changes will be published transparently on this page with an updated “Effective Date.”
9. Contact Information
For formal inquiries regarding our data handling methodologies, security compliance, or privacy standards, please contact our data supervisor:
Zonnetech — Privacy & Data Security Compliance
Email: privacy@zonnetech.com