<
🔏 Zero Knowledge · Your Privacy

Privacy Policy

Your privacy is not a compliance exercise. It is a design decision. ZazimFind is built on zero knowledge principles, so that keeping your data safe depends not on promises, but on how the system is built.

Version 2.1 Effective: 14 March 2026 ZazimFind Ltd · UK Company No. 17126690
Zero Knowledge Architecture. No User Data Stored.

ZazimFind processes your queries in memory during each request and discards all associated information immediately. We do not collect, store, or sell your personal data, search queries, or activity history. What you search stays with you. The sections below describe the minimal technical data that briefly passes through our infrastructure, and how we handle it.

Information We Collect

Because of our zero-knowledge architecture, we do not collect personal information about you or your queries. The table below explains what minimal technical data is handled and why:

Search Queries

Your queries are processed in-memory and discarded immediately upon returning results. They are never logged, stored, or associated with your identity.

Not Stored
Account Data

If you create an account, we hold your name, email address, and chosen password (hashed, never in plaintext). This is strictly for authentication.

Minimal
Technical Logs

Anonymised request metadata (HTTP method, status code, error type) retained for 1 year for infrastructure stability. No IP addresses are logged.

Anonymised Only
Cookies

Strictly necessary cookies for session authentication only. No tracking, advertising, or analytics cookies without your explicit consent.

Opt-in Only
Billing Data

Payment data is handled exclusively by our PCI-DSS certified payment processor. We receive only a transaction reference — no card details ever reach our servers.

Processor Only
Communications

Emails you send us for support are retained for 2 years for service quality, then permanently deleted.

Limited Retention

We do not sell personal data to third parties under any circumstances.


How We Use Data

Service provision: Account data is used solely to authenticate you and manage your subscription. We do not use it to personalise, profile, or analyse your behaviour.

Security & stability: Anonymised technical logs help us detect infrastructure anomalies, abuse, and security incidents without identifying individuals.

Communications: We use your email address to send account notices, security alerts, and (with your consent) product updates. You can unsubscribe from marketing communications at any time.

Legal compliance: We retain only the minimum data legally required. For example, billing transaction records for UK VAT and tax obligations.

We never use personal data beyond the purpose for which it was collected, consistent with GDPR Article 5(1)(b) purpose limitation.


Cookies & Tracking

We use strictly necessary cookies only by default, those required for authentication and session management. No tracking, advertising, profiling, or analytics cookies are set without your explicit consent. Third-party cookies (e.g., payment processors) operate under their own privacy policies.

On your first visit, our consent banner gives you a genuine choice. Declining does not affect your access to the service.


Data Sharing & Transfers

Service providers: We share minimal technical data with vetted vendors (cloud hosting, email delivery, payment processing) under strict data processing agreements that prohibit sub-processing and secondary use.

Legal requirements: We may disclose data when required by law or court order. We will notify affected users unless prohibited by law, and we challenge requests that are disproportionate or unlawful.

Business transfers: If ZazimFind Ltd is acquired or merges, users will receive 30 days' notice and the ability to delete their account before any data transfer occurs.

International transfers: Data from EU/UK users may be processed on servers outside the EEA/UK. We rely exclusively on EU Standard Contractual Clauses (SCCs) or adequacy decisions, satisfying GDPR Articles 44–46 and UK GDPR equivalents. No data is transferred to jurisdictions without appropriate safeguards.


Data Retention

We keep data only as long as necessary. Upon expiry or a valid deletion request, data is securely erased (AES-256 overwrite or equivalent) or irreversibly anonymised.

Data Category Retention Period Legal Basis
Search Queries Not retained, discarded on completion Zero-knowledge design
Account Data Duration of account + 90 days post-deletion Contract performance (GDPR Art. 6(1)(b))
Anonymised Technical Logs 12 months, then auto-deleted Legitimate interests (GDPR Art. 6(1)(f))
Support Correspondence 24 months from last contact, then anonymised Legitimate interests
Billing Records 7 years UK VAT Act 1994 / legal obligation
Cookie Consent Records 3 years Accountability obligation (GDPR Art. 5(2))
Incident Response Logs 3 years Legal obligation / legitimate interests

Your Privacy Rights

Under GDPR and UK DPA 2018, you have the following rights. We respond to verified requests within one calendar month (extendable by two months for complex requests, with notice). Exercising these rights is free of charge.

Access
Request a copy of all personal data we hold about you, including processing purposes and recipients.
Correction
Have inaccurate or incomplete personal data corrected without undue delay.
Erasure
Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
Restriction
Object to or restrict processing, including the right to stop marketing communications at any time.
Portability
Receive your data in a structured, machine-readable format for transfer to another provider.
Withdraw Consent
Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
Lodge Complaint
Complain to your local supervisory authority (ICO in UK; relevant EU DPA) if you believe your rights have been violated.
Know AI Decisions
Where an automated decision significantly affects you, request human review and an explanation of the logic.

California CCPA / CPRA

California residents have additional rights under the California Consumer Privacy Act (CCPA) as amended by CPRA. These rights include: the right to know what personal information is collected, used, or shared; the right to delete personal information (subject to exceptions); the right to correct inaccurate data; the right to limit use of sensitive personal information; and the right to opt out of sale or sharing of personal information.

We do not sell or share personal information for cross-context behavioural advertising. You will not be discriminated against for exercising any CCPA/CPRA rights. To submit a verifiable consumer request, contact us at the address below. We respond within 45 days, extendable by a further 45 days with notice.


Children's Data

Our services are not directed to children under 16 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from minors. If we discover that personal data from a child under 16 has been submitted, we will delete it promptly. If you believe a child has provided us personal information, contact our DPO immediately at privacy@zazimfind.co.uk.


Data Security

We protect the minimal data we hold with administrative, technical, and physical safeguards: AES-256 encryption at rest, TLS 1.3+ in transit, MFA for all administrative access, role-based access controls, continuous intrusion monitoring, and annual third-party penetration testing. Full details are on our Security & Privacy page.

No system is 100% secure. If you have concerns about the security of your account, contact us immediately at support@zazimfind.co.uk.


Breach Notification

In the event of a personal data breach that risks individuals' rights and freedoms, we will notify the applicable supervisory authority (ICO for UK; relevant EU DPA) within 72 hours of discovery, in accordance with GDPR Article 33. Where a breach is likely to result in high risk to individuals, we will notify affected users directly without undue delay.

For US residents (including California), we commit to notification within the timeframes required by state law, typically within 30–45 days, sooner where feasible. Every breach is documented, investigated, and subject to a post-incident review, with remediation actions shared transparently where appropriate.


Policy Updates

We may update this Privacy Policy to reflect changes in law, technology, or our practices. Material changes will be communicated via email or in-product notice at least 30 days before they take effect. The version number and effective date appear at the top of this page. A change log is maintained below for transparency.

Change Log:
v2.1 — 14 March 2026 · Current version. Strengthened zero-knowledge architecture disclosure; added CPRA rights; updated retention schedule.
v2.0 — 1 Jan 2026 · Initial public release aligned to UK DPA 2018 post-Brexit.


Contact & Complaints

To exercise your rights, ask questions, or submit a concern about our privacy practices, contact our Data Protection Officer:

🔐 Data Protection Officer

Email: privacy@zazimfind.co.uk

General support: support@zazimfind.co.uk

Post: Data Protection Officer, ZazimFind Ltd, United Kingdom (UK Company No. 17126690)