1. Data Fiduciary & Business Information
Under the provisions of India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the General Data Protection Regulation (GDPR), ZENSTRO operates as the Data Fiduciary (or Data Controller) in respect of the personal data collected through this website (https://zenstro.space).
Entity Name: ZENSTRO
Founder & Designated Data Protection / Grievance Officer: Shubham Pathak
Official Website: https://zenstro.space
Contact Channel: Via our Official Contact Form or official verified profiles.
2. Global & DPDP Act Compliance Framework
ZENSTRO provides software development, cloud infrastructure, AI automation, and consulting services to clients across India, the United States, the European Union, the United Kingdom, and globally. We adhere to key international privacy principles:
- Lawfulness, Fairness, and Transparency: We process data only with a legitimate legal basis and explicit purpose.
- Purpose Limitation: Personal data is processed exclusively for the stated purpose of responding to your inquiry or fulfilling a software engagement.
- Data Minimization: We request and process only the minimum necessary information required to evaluate and execute your technical requirements.
- Storage Limitation: We do not store personal data indefinitely; data is retained only as long as necessary for business communication and legal compliance.
3. Information We Collect (Data Minimization)
We do not collect sensitive personal data, financial account numbers, biometrics, government identifiers, or data relating to children. We collect only the following voluntary information when you submit our contact form:
- Full Name: To identify who we are communicating with.
- Business Email Address: To reply with technical project proposals, scoping documents, or responses.
- Company / Organization Name (Optional): To understand your business context.
- Technical Division / Scope of Interest: To route your inquiry to the appropriate engineering division (Web, Software, AI, Cloud, Security, or Consulting).
- Project Message: Context, requirements, and specifications provided voluntarily by you.
4. Lawful Basis for Processing
We process your personal data under the following recognized legal grounds:
- Explicit Consent (DPDP Section 6 / GDPR Article 6(1)(a)): When you fill out the contact form, you must check an affirmative consent box indicating agreement to this policy before your message is submitted.
- Pre-Contractual Steps (GDPR Article 6(1)(b)): Processing is necessary to take steps at your request prior to entering into a formal software development agreement or MVP scope document.
- Legitimate Interests: Maintaining the security and operational integrity of our website infrastructure against automated spam and denial-of-service attempts.
5. Purpose of Processing
The information collected from you is used strictly to:
- Review your technical inquiry and prepare a structured MVP scope document or quotation.
- Communicate directly regarding timelines, architecture, and technology capabilities.
- Coordinate project milestones and deliverables if an engagement proceeds.
Our Anti-Commercialization Guarantee: ZENSTRO will never sell, rent, monetize, or trade your personal data or project details to third-party data brokers, advertisers, or lead generation networks.
6. Third-Party Service Providers (Data Processors)
To ensure high availability, security, and reliable delivery, we utilize vetted technology providers who process data strictly under technical confidentiality standards:
| Provider |
Purpose |
Data Transferred |
| Formspree Inc. |
Encrypted transmission of contact form submissions to our inbox. |
Name, email, message text (encrypted in transit via TLS). |
| Cloudflare Inc. |
CDN caching, DNS routing, DDoS protection, and TLS encryption. |
Standard network metadata (IP address, user agent) for firewall verification. |
| GitHub API |
Displaying public open-source repository metrics on our Work page. |
No user data sent; purely client-side fetch of public repository data. |
7. Cookies & Zero-Ad-Surveillance Policy
ZENSTRO believes in a clean, privacy-respecting web:
- No Advertising Trackers: We do not deploy Meta/Facebook Pixels, Google Ads remarketing tags, TikTok pixels, or cross-site tracking scripts.
- Essential Storage Only: We use local storage purely to remember your dismissal of the site privacy notice banner and your reduced-motion preferences.
- Fonts: Google Fonts (Manrope and DM Mono) are loaded with preconnect attributes for typography rendering.
8. Data Retention & Security Standards
We implement rigorous organizational and technical safeguards:
- Encryption: All web traffic is strictly served over HTTPS with TLS 1.3 encryption.
- Access Control: Project inquiries are accessible solely to the Founder and authorized engineering leads.
- Time-Bound Retention: Inquiries that do not lead to an active engagement are securely deleted after 180 days. Client project records are maintained for the duration of the contractual warranty and tax compliance periods.
9. Your Rights as a Data Principal / Data Subject
Under the DPDP Act 2023 (India), GDPR (EU), and applicable global laws, you hold the following rights regarding your data:
- Right to Access: Request a summary of personal data held about you and processing activities undertaken.
- Right to Correction & Erasure: Request the correction of inaccurate data or the permanent deletion of your contact records.
- Right to Withdraw Consent: You may withdraw your consent for future communication at any time.
- Right to Grievance Redressal: Submit a complaint to our designated Grievance Officer regarding any privacy concern.
- Right to Nominate (DPDP Act): You have the right to nominate an individual to exercise your rights in the event of incapacity.
10. Grievance Officer & Redressal Procedure
In accordance with Section 6(5) and Section 13 of the Digital Personal Data Protection Act, 2023, the details of our designated Grievance Officer are set forth below:
Grievance Officer: Shubham Pathak (Founder & CEO)
Designation: Data Protection & Grievance Redressal Lead, ZENSTRO
Contact Mechanism: Submit a formal inquiry marked "Privacy Grievance" via our Contact Page.
Response Timeline: We acknowledge all legitimate grievance requests within 48 hours and provide formal resolution within 30 calendar days.
If you are located in India and are not satisfied with our grievance resolution, you hold the right to lodge a complaint with the Data Protection Board of India (DPBI). European visitors hold the right to contact their local supervisory Data Protection Authority (DPA).
11. Google API Services User Data Policy & Limited Use Disclosure
ZENSTRO integrates Google Sign-In (Google Identity Services) to enable streamlined authentication for clients, visitors, and verified administrators.
1. What Data We Request from Google
When you choose to authenticate with Google, ZENSTRO requests access only to standard, non-sensitive identity scopes (openid, profile, and email):
- Email Address: Used to uniquely identify your account, verify administrative privileges, and route inquiries.
- Full Name: Used to address you properly and personalize your studio experience.
- Profile Picture URL: Rendered in the website header to confirm your active authenticated session.
2. Purpose & Transparent Use of Google User Data
We process information obtained via Google Identity Services solely to:
- Authenticate your identity when accessing our website, client portal, or leadership console.
- Distinguish between client members and authorized studio leadership for role-based access control.
- Display your active authenticated status in the navigation header.
Mandatory Limited Use Statement:
ZENSTRO's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Privacy Protections, Sharing Restrictions & Revocation
- Zero Data Selling: We never sell, rent, monetize, or trade any Google user data to data brokers, advertisers, or third parties.
- No Advertising / Tracking: Google user data is never used for serving targeted advertisements or cross-site tracking.
- No AI Model Training: Information received through Google APIs is never used to train generalized artificial intelligence or machine learning models.
- No Sensitive Scopes: ZENSTRO does not request access to Gmail inboxes, Google Drive files, Calendar entries, or Contacts.
- Session Storage & Revocation: Your sign-in session is maintained locally on your device and can be cleared at any time by clicking the logout button in the site navigation bar, or by revoking access in your Google Account Permissions.