ServicesWorkPartnersAboutBlog Contact Start a project

Legal

Privacy policy.

This website sets no cookies of its own, runs no analytics and loads nothing from another domain — with one exception, a map at the bottom of the contact page, and it loads only if you scroll to it. That is the short version, and you can verify all of it in your browser's network tab.


What this website collects

Nothing.

There is no analytics tag, no tag manager, no advertising pixel, no session recorder, no chat widget, and no font or video loaded from another domain. This site sets no cookies of its own, which is also why you were not shown a cookie banner — there is nothing of ours to consent to.

There is no contact form either. The links on the contact page open your own email client, so what you send goes directly to us and never passes through this website.

You do not have to take our word for any of this. Open developer tools, reload the page, and look at the requests and the cookie store.

One embedded map

There is a Google map at the bottom of the contact page. It is the only thing on this site loaded from another company, and it is the only thing that can set a cookie you did not get from us.

It is written so that it does as little as possible. The map is not in the page when the page arrives — it is added only once you scroll far enough down the contact page to see it, so a visitor who reads the address and leaves never contacts Google at all. No other page on this site embeds anything. We send no referrer with it, so Google is not told which page you came from, and we pass it a coordinate rather than your location.

Once it does load, it is Google's product on Google's terms: it may set cookies and it will know your IP address, the same as visiting Google Maps directly. That is governed by Google's privacy policy, not this one. If you would rather not load it, do not scroll to it — or use the "Get directions" link, which is an ordinary link and loads nothing until you click it.

What the server records

Standard web server logs, kept short, used only to keep the site working.

Like any web server, ours writes an access log: the IP address a request came from, the time, the page requested, the response status, the referring page and the browser's user-agent string. This is how a broken link or an attack gets noticed at all.

These logs are not linked to any identity, are not used for profiling or advertising, are not shared, and are rotated on a short cycle. Under the DPDP Act an IP address can be personal data in some circumstances, which is why they are mentioned here rather than treated as invisible.

What we collect when you contact us

Whatever you choose to put in your email, used to answer you and to run the engagement if one follows.

When you email us, call, or meet us, we hold what you send: your name, your work email and phone number, your company, and whatever you tell us about the problem you want solved. We use it to reply, to scope the work, and — if you become a client — to deliver and invoice.

We do not sell it. We do not share it with advertisers or data brokers. We do not add you to a marketing list because you enquired once; if we ever start a mailing list you will be asked first, and unsubscribing will be one click.

Client data during an engagement

Governed by the signed agreement, not by this page, and normally under a separate NDA and data processing agreement.

When we build a system for you, we usually need access to your data — documents, transcripts, records, sometimes production databases. That relationship is set out in the engagement contract, which takes precedence over this policy in every case of conflict.

What is consistent across engagements: we take the minimum access that does the job, we prefer redacted or synthetic data for development where that is workable, we return or destroy client data on request at the end, and we do not reuse one client's data to build anything for another. We do not train models on client data outside the engagement it belongs to.

Where you are bound by sector rules — RBI storage directions, for instance — the architecture is designed around them from the first conversation rather than adjusted afterwards. There is more on how we approach Indian data residency.

Where data is stored, and who else sees it

Business email and project tooling sit with established providers; anything with a residency requirement stays in India.

Correspondence lives in our business email. Project material lives in version control and project tooling. These are ordinary commercial services, and using them means those providers process data on our behalf under their own terms.

Where a client's requirement is that data stays inside India, we hold and process it inside India, and we tell you which components would otherwise cross a border. Where an engagement calls a model API that runs outside India, that is identified and agreed before it is built, never discovered at deployment.

How long we keep things

Enquiries that do not become projects: kept while a conversation is realistically live, then deleted. Client records: kept for the life of the engagement and afterwards only as long as tax, accounting and contractual obligations require. Server logs: rotated on a short cycle.

If you want something deleted sooner, ask. If a legal obligation prevents us, we will tell you which one.

Your rights

Access, correction, deletion, and a route to complain — write to privacy@zenmagix.com.

Under India's Digital Personal Data Protection Act 2023 you may ask what personal data of yours we hold, ask us to correct it if it is wrong, ask us to erase it, and nominate someone to exercise these rights if you cannot. If you are in the EU or UK, we will handle a GDPR request on the same terms rather than argue about which law applies.

Write to privacy@zenmagix.com. We will acknowledge within a few working days and tell you what we hold or what we have done. If we cannot do what you asked, you get the reason.

Grievances

If you are not satisfied with how we handled a data request, escalate it to the same address marked for the attention of the Grievance Officer, at Zenmagix Techsolution Private Limited, B-204, Kanakia Wall Street, Andheri - Kurla Road, Chakala, Andheri East, Mumbai, Maharashtra, 400093, India. If we still have not resolved it, the DPDP Act provides a route to the Data Protection Board of India.

Children

This is a business-to-business site and nothing on it is directed at children. We do not knowingly collect data about anyone under 18. If you believe we have, write to us and we will delete it.

Changes

If this policy changes materially, the date at the top changes with it. There is no mailing list to notify, which is a consequence of not having collected anyone's address for that purpose.

Related: Terms and conditions, Disclaimer, Refund policy.