Privacy Notice
This Privacy Notice ("Notice") explains how Zentix Soft LTD ("Zentix Soft", "we", "us", or "our") collects, uses, shares, and protects personal data when you visit zentixsoft.com (the "Site"), contact us, subscribe to communications, or otherwise interact with us. This Notice is intended to provide information required under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU General Data Protection Regulation (EU GDPR), applicable electronic communications and cookie rules, and applicable United States state privacy laws.
1. Data Controller
Zentix Soft LTD acts as the data controller for personal data collected through the Site and related business communications.
Company details:
- Legal name: ZENTIX SOFT LTD
- Company number: 15461480
- Registered office: 5 Brayford Square, London, United Kingdom, E1 0SG
- Privacy contact email: info@zentixsoft.com
Where another Zentix Soft entity is involved in a specific client engagement, the relevant agreement or project notice will identify that entity and its role.
2. Scope of This Notice
This Notice applies to personal data processed through the Site, contact and enquiry forms, business development communications, analytics, marketing technologies, and our customer relationship management systems.
It does not replace any privacy notice or data processing terms that may apply to services provided under a separate client agreement.
3. Personal Data We Collect
We may collect and process the following categories of personal data:
- Identity and contact data — name, work email address, telephone number, company, job title, country and any other contact details you provide.
- Enquiry and communication data — the content of messages, project requirements, meeting information, correspondence and records of our responses.
- Technical and device data — IP address, browser type and version, device type, operating system, language, time zone, approximate location, referral URL and technical identifiers.
- Usage and interaction data — pages visited, session duration, clicks, scrolling, navigation paths, form interactions and similar information about use of the Site.
- Marketing and preference data — consent choices, cookie preferences, subscription status, communication preferences and interaction with marketing content.
- Security and verification data — information used to detect bots, abuse, fraud, malicious activity and other threats to the Site.
- Business relationship data — CRM records, lead source, notes, proposals, meeting records and information relating to prospective or existing client relationships.
Please do not submit special-category or highly sensitive personal data through the Site unless it is strictly necessary and we have specifically requested it.
4. How We Collect Personal Data
We collect personal data:
- directly from you when you complete a form, contact us, book a call, subscribe to communications or otherwise communicate with us;
- automatically through cookies, pixels, tags, scripts, local storage, server logs and similar technologies, subject to your consent where required;
- from service providers and business tools that support our Site, analytics, security, marketing and CRM activities; and
- from publicly available professional sources or business contacts where permitted by law.
5. Purposes and Lawful Bases
We process personal data only where we have an appropriate legal basis. Depending on the context, we rely on the following:
| Purpose | Data involved | Lawful basis |
|---|---|---|
| Responding to enquiries and arranging calls | Identity, contact, enquiry and communication data | Steps taken at your request before entering into a contract; legitimate interests in responding to business enquiries |
| Providing services and managing client relationships | Contact, communication and business relationship data | Performance of a contract; legal obligations; legitimate interests |
| Operating, securing and troubleshooting the Site | Technical, device, security and log data | Legitimate interests in maintaining a secure and functional Site; legal obligations where applicable |
| Website analytics and experience improvement | Technical, usage and interaction data | Consent in the EEA, UK and other jurisdictions where required; otherwise legitimate interests where permitted |
| Advertising, conversion measurement and retargeting | Technical, usage, marketing and online identifier data | Consent where required; applicable opt-out rights under US state laws |
| Managing CRM records and business development | Contact, communication and business relationship data | Legitimate interests in managing prospective and existing business relationships; consent where required |
| Sending marketing communications | Contact and preference data | Consent or legitimate interests where permitted by applicable electronic marketing laws |
| Compliance, legal claims and corporate administration | Relevant records and communications | Legal obligations; legitimate interests in establishing, exercising or defending legal claims |
6. Cookies and Similar Technologies
Our Site uses cookies and similar technologies, including tags, pixels, scripts and local storage. CookieYes is used to display the consent banner, record and manage your choices, and support the activation or blocking of non-essential technologies.
We use Google Tag Manager and Google Consent Mode to communicate consent choices to relevant tags. Cookies and storage used for non-essential analytics and marketing are not activated until the required consent has been provided. Depending on the configuration of Consent Mode, limited cookieless technical and consent-status signals may be processed before consent for security, consent management and privacy-preserving measurement.
The main categories are:
- Strictly necessary cookies and technologies — required for security, consent management, network delivery, form protection and core Site functions. These cannot generally be switched off through the banner.
- Analytics cookies — used with your consent to understand Site traffic and how visitors interact with pages, including through Google Analytics 4 and Microsoft Clarity.
- Marketing cookies and pixels — used with your consent to measure campaigns, attribute conversions and support advertising, including through Meta Pixel.
- Preference technologies — used to remember choices such as language and cookie settings where applicable.
You may accept all, reject non-essential technologies, or choose individual categories in the CookieYes banner. You can change or withdraw your choices at any time through the Cookie Settings or Revisit Consent link in the Site footer. Withdrawal does not affect processing that occurred before withdrawal.
The current cookie list, including cookie names, providers, purposes and expiry periods, is available through the CookieYes settings panel and is updated through regular scans.
7. Third-Party Services and Recipients
We use the following service providers. The data actually processed depends on your interaction with the Site, your consent choices and the configuration of each service.
| Service and provider | Purpose | Typical data |
|---|---|---|
| Google Analytics 4 and Google Tag Manager Google Ireland Limited / Google LLC |
Analytics, tag management and consent signalling | IP address, device and browser data, page and event data, online identifiers and consent status |
| Microsoft Clarity Microsoft Ireland Operations Limited / Microsoft Corporation |
Heatmaps, session interaction analysis and Site improvement | Device and browser data, page interactions, clicks, scrolling and masked session recordings |
| Meta Pixel Meta Platforms Ireland Limited / Meta Platforms, Inc. |
Advertising measurement, conversion attribution and retargeting | Online identifiers, page visits, device and browser data, events and, where enabled, hashed matching identifiers |
| HubSpot CRM HubSpot Ireland Limited / HubSpot, Inc. |
Contact forms, CRM, lead management, communications and marketing workflows | Contact details, form submissions, communications, lead source, preferences and CRM notes |
| bunny.net BunnyWay d.o.o. |
Content delivery, hosting support, performance and security | IP address, request URL, country code, user agent, delivery and security logs |
| Cloudflare Turnstile Cloudflare, Inc. |
Bot detection, abuse prevention and form security | IP address, browser and device signals, challenge-related data, verification token and security data |
| CookieYes CookieYes Limited |
Cookie banner, consent records and preference management | Consent choices, timestamps, technical identifiers and limited device and browser data |
We may also disclose personal data to professional advisers, auditors, insurers, regulators, law-enforcement bodies, courts, potential purchasers or investors, and other recipients where necessary for legal, corporate or security purposes.
We require processors to use personal data only on documented instructions, protect it appropriately and comply with applicable data protection obligations.
8. International Data Transfers
Some service providers operate globally or may process personal data outside the United Kingdom or European Economic Area, including in the United States.
Where required, we rely on recognised transfer safeguards, including adequacy decisions or regulations, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, and participation in the EU-US Data Privacy Framework or UK Extension where applicable. We may also use supplementary technical and organisational measures.
You may contact us for further information about the safeguards relevant to your personal data. Certain contractual or security information may be redacted where necessary.
9. Data Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Notice, including legal, accounting, security and dispute-resolution requirements. Our general retention periods are:
| Data category | Retention period |
|---|---|
| Website enquiries and correspondence | Up to 24 months after the last meaningful communication, unless a longer period is needed for a prospective or actual contract |
| Prospective-client and CRM records | Up to 3 years after the last meaningful business interaction, unless a valid deletion or objection request applies earlier |
| Client and contractual records | For the duration of the relationship and generally up to 6 years afterwards, subject to applicable legal and contractual requirements |
| Marketing contacts | Until consent is withdrawn or an objection or opt-out is received; limited suppression data may be retained to respect the opt-out |
| Analytics and Site interaction data | Generally up to 14 months, unless a shorter period applies under the relevant service configuration |
| Cookie consent records | Up to 12 months after the relevant preference record, or longer where reasonably necessary to demonstrate compliance |
| Server, CDN and security logs | Generally up to 12 months, unless a longer period is required to investigate an incident, prevent abuse or establish legal claims |
When data is no longer required, we delete, anonymise or securely isolate it, subject to backup cycles and legal retention obligations.
10. Data Security
We implement appropriate technical and organisational measures designed to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures may include access controls, encryption in transit, secure hosting, logging, vulnerability management, staff confidentiality obligations and incident-response procedures.
No method of transmission or storage is completely secure. You should avoid sending confidential or sensitive information through open website forms unless specifically requested.
11. Your Rights in the EEA and United Kingdom
Depending on the circumstances and applicable law, you may have the right to:
- be informed about how your personal data is processed;
- request access to your personal data and a copy of it;
- request correction of inaccurate or incomplete data;
- request deletion of personal data in certain circumstances;
- request restriction of processing in certain circumstances;
- receive certain data in a structured, commonly used and machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests and object at any time to direct marketing;
- withdraw consent at any time where processing is based on consent; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to legal exceptions.
To exercise a right, email info@zentixsoft.com. We may request information reasonably necessary to verify your identity and authority. We normally respond within one month, subject to permitted extensions for complex or multiple requests.
12. United States State Privacy Rights
If you are a resident of a US state with an applicable comprehensive privacy law, and that law applies to Zentix Soft, you may have rights to request access, confirmation, correction, deletion or portability of personal data; opt out of sale, sharing, targeted advertising or certain profiling; limit certain uses of sensitive personal data; appeal a refusal; and use an authorised agent. You will not be discriminated against for exercising an applicable privacy right.
We do not sell personal data for monetary consideration. However, the use of advertising technologies such as Meta Pixel may be treated as sharing, targeted advertising or a sale under certain US state laws. Where applicable, you may opt out through Cookie Settings. We also recognise browser-based universal opt-out preference signals where required by applicable law.
Requests may be submitted to info@zentixsoft.com. We may need to verify your identity or an authorised agent's authority. Rights and response periods vary by state and are subject to statutory exceptions.
13. Marketing Communications
You may unsubscribe from marketing emails at any time using the unsubscribe link in the message or by contacting us. We may retain limited information on a suppression list to ensure that your opt-out is respected.
Withdrawing from marketing does not prevent us from sending service-related, administrative or legally required communications.
14. Children's Privacy
Our Site and services are intended for business users and are not directed to children. We do not knowingly collect personal data from anyone under 16 through the Site. If you believe a child has provided personal data, please contact us so that we can assess and, where appropriate, delete it.
15. Automated Decision-Making
We do not currently use personal data collected through the Site to make decisions based solely on automated processing that produce legal or similarly significant effects. We may use analytics, segmentation, lead scoring or marketing automation to support business development, but material decisions are not made solely by those tools.
16. Personal Data Breaches
We maintain procedures to assess and respond to personal data incidents. Where legally required, we will notify the Information Commissioner's Office, another competent supervisory authority and/or affected individuals within the applicable timeframe.
17. Complaints
Please contact us first at info@zentixsoft.com so that we can try to resolve your concern.
UK residents may lodge a complaint with the Information Commissioner's Office (ICO). EEA residents may lodge a complaint with the data protection authority in the country of their habitual residence, place of work or the alleged infringement. You may also have a right to seek a judicial remedy.
18. Changes to This Notice
We may update this Notice to reflect legal, technical or business changes. The revised version will be posted on this page with an updated date. Where required, we will provide additional notice or obtain renewed consent.
19. Contact Us
For privacy questions or requests, contact:
ZENTIX SOFT LTD
5 Brayford Square, London, United Kingdom, E1 0SG
Company number: 15461480