Privacy Policy
How Zetect Private Limited collects, uses and protects personal data — on this website, and in the Zetect platform.
Contents
- Who we are
- Scope and our two roles
- Personal data we collect
- What we do not collect
- How we use personal data
- Legal bases for processing
- Customer data in the platform
- Sharing and sub-processors
- International transfers
- How we protect personal data
- How long we keep it
- Your rights
- Children
- Changes to this policy
- How to contact us
1. Who we are
Zetect Private Limited (“Zetect”, “we”, “us”) provides a converged identity platform bringing together Access Management, Identity Governance and Privileged Access. We are a company incorporated in India, with registered office at Unit 603–604, 6th Floor, Tower B, Bhutani Alphathum, Sector 29, Noida, Uttar Pradesh 201305, India.
This policy explains what we do with personal data. If anything here is unclear, write to enquiry@zetect.in and we will explain it in plain terms.
2. Scope and our two roles
We handle personal data in two distinct capacities, and your rights differ between them.
- As a controller (or “Data Fiduciary” under India's DPDP Act)
- When you visit zetect.in or documentation.zetect.in, send us an enquiry, or deal with us as a customer or supplier contact, we decide why and how your data is processed. Sections 3 to 6 describe this.
- As a processor (or “Data Processor”)
- When a customer deploys the Zetect platform, that customer decides what identity data goes into it. We process it on their documented instructions under a separate agreement. If you are an employee, contractor or user of an organisation that uses Zetect, your relationship is with that organisation — see section 7.
This policy does not cover third-party websites we link to, or a customer's own use of the platform.
3. Personal data we collect
3.1 Information you give us
When you submit the enquiry form on our contact page, we collect the reason for your enquiry, your name, work email address, and — if you choose to provide them — your company name and phone number, together with the message you write. If you email us directly, we receive whatever that email contains.
3.2 Information collected automatically
Our hosting provider records standard server logs when a page is requested, which include the requesting IP address, timestamp, the resource requested, and the user-agent string reported by your browser. When you submit the enquiry form, the originating IP address is included in the notification we receive, and is used to rate-limit automated abuse of the form.
3.3 Information from other sources
We may also receive personal data about you from third parties we work with. Where that happens, the categories of source are:
- website and hosting providers;
- customer relationship management and business communication platforms;
- marketing and analytics providers;
- event, webinar and registration platforms;
- recruitment providers and professional services firms, where you apply for a role or deal with us through an adviser; and
- other service providers supporting our legitimate business activities.
Data reaching us this way is typically business contact information — your name, employer, job title and work email — together with a record of how the contact arose, such as an event you registered for. We combine it with what you have given us directly only to respond to you and to keep our records accurate.
This is separate from the website itself, which runs no analytics and sets no cookies, as section 4 explains. Where a provider in the list above is used in a way that collects data through our own properties, we will say so in section 4 and update this policy first.
4. What we do not collect
We think it is worth being specific, because many privacy policies are vague on this point. As at the last-updated date above, this website:
- sets no cookies, and stores nothing in your browser's local or session storage;
- runs no analytics, advertising, session-recording or heat-mapping tools;
- loads no third-party scripts, fonts or embeds — typefaces are served from our own domain;
- contains no social media pixels or tracking beacons;
- does not build a profile of you, and does not sell or rent personal data to anyone.
Because we set no cookies, there is no cookie banner and nothing to consent to. If this ever changes, we will update this section and, where the law requires it, ask for your consent first.
This section describes our website. Marketing email, which you receive only if you ask for it, is handled separately and described in section 5.1.
5. How we use personal data
- To answer you. Replying to an enquiry, arranging a demo, or responding to a support or partnership question.
- To provide and administer the platform for customers, including provisioning, support and billing contacts.
- To keep the service secure — detecting and preventing abuse of the enquiry form, and investigating security incidents.
- To meet legal and regulatory obligations, including tax, accounting and lawful requests from authorities.
- To improve the website through aggregate, non-identifying measures of what is being read.
We use what you send through the enquiry form to reply to that enquiry, and we do not resell it.
5.1 Marketing communications
We send marketing email — product news, release notes, event invitations and occasional research — only to people who have asked to receive it, or where sending it is permitted by the law that applies to you. Submitting the enquiry form does not by itself subscribe you: if we invite you to opt in, it will be a separate, clearly labelled choice.
Every marketing message carries a one-click unsubscribe link, and we honour it promptly. You can also unsubscribe at any time by writing to enquiry@zetect.in. Withdrawing consent does not stop the operational messages you need — a reply to your enquiry, a service notice, a security advisory or anything relating to your subscription — because those are not marketing.
Marketing email is commonly sent through a specialist provider, and such messages usually record whether a message was delivered, opened or clicked. We use that only to judge whether what we send is worth sending and to stop emailing people who clearly do not want it. We do not use it to build a behavioural profile of you, and we do not sell it. Note that this is different from our website, which carries no tracking at all — see section 4.
6. Legal bases for processing
Where the EU or UK GDPR applies to our processing, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry | Steps taken at your request prior to entering a contract; our legitimate interest in answering people who contact us |
| Providing the platform to a customer | Performance of a contract |
| Security, abuse prevention and server logging | Our legitimate interest in keeping the service available and secure |
| Legal, tax and regulatory compliance | Compliance with a legal obligation |
| Marketing communications, where sent | Consent, or legitimate interest where permitted, with an opt-out in every message |
Under India's Digital Personal Data Protection Act 2023, we process personal data on the basis of your consent or for legitimate uses permitted by that Act, and we give notice of the purpose at the point of collection.
7. Customer data in the platform
The Zetect platform processes identity data belonging to our customers — accounts, entitlements, group memberships, authentication events and privileged session records. Our customer decides what data enters the platform and for how long it stays.
In that context we act only on the customer's documented instructions. We do not use customer data to train models, to build profiles, or for any purpose of our own beyond providing and securing the service. Where the platform is deployed on-premise or in an air-gapped network, that data may never reach us at all.
If you are an individual whose data sits in a customer's Zetect tenant and you want to exercise a right over it, please contact that organisation — they are the controller. If you contact us instead, we will refer you to them and assist them in responding.
8. Sharing and sub-processors
We do not sell personal data. We share it only in these situations:
- Service providers who host our website, deliver our email and support our operations, under contract and only for those purposes.
- Professional advisers — lawyers, auditors and accountants — where they need it to advise us.
- Authorities, where we are legally required to disclose, or to establish or defend legal claims.
- A successor entity, in the event of a merger, acquisition or reorganisation, subject to this policy.
We rely on a small number of established third-party providers to run our own operations. Rather than name them here — infrastructure and tooling change over time, and this policy should not go stale when they do — we describe them by function:
- Cloud infrastructure and hosting, which serve this website and run the function that handles enquiry submissions.
- Email delivery, which transmits enquiry notifications to us and any communications we send you.
- Business and productivity tools, such as email, document storage and customer relationship management, used to run the company.
We choose these providers deliberately, and security is the main criterion. We use established providers operating at a scale that lets them invest far more in physical security, network defence, patching and monitoring than we could alone, and we prefer those holding recognised independent certifications and audit reports for the services we use. We review that posture before onboarding a provider and periodically afterwards.
Every provider is engaged under a written contract that limits them to processing personal data on our documented instructions, binds them to confidentiality, requires appropriate technical and organisational security measures, and restricts onward transfer. Credentials and secrets used to reach these services are held in a managed secret store, never in application code or configuration. We give providers only the minimum data they need to perform their function.
We keep a current list of the sub-processors that handle personal data, naming each one, its role and where it operates. You can request it from enquiry@zetect.in, and customers receive it under their data processing addendum along with notice of material changes.
9. International transfers
We are based in India, and our providers may process or store data in regions outside the country where it was collected. Where that happens we put appropriate safeguards in place — such as Standard Contractual Clauses or an equivalent transfer mechanism — and we transfer only what is necessary for the provider to perform its function. The regions currently in use for each service are shown on the sub-processor list described in section 8, which we keep current as providers or regions change.
10. How we protect personal data
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access control on the principle of least privilege, credential storage in a managed secret store rather than in application code or configuration, and logging of administrative activity.
No system is perfectly secure, and we do not claim otherwise. If a personal data breach occurs, we will notify the affected parties and the relevant authority within the timeframes the applicable law requires.
11. How long we keep it
We keep personal data for as long as it is needed for the purpose it was collected for — and no longer. Once that purpose has been served, the data is deleted, or anonymised so that it can no longer be connected to you.
Rather than fix an arbitrary period for everything, we judge it against the purpose:
- Enquiries and correspondence are kept while we are dealing with your enquiry and for a reasonable period afterwards, in case the conversation resumes. Where an enquiry does not lead anywhere, it is cleared out in the ordinary course.
- Customer and supplier contact records are kept for the life of the relationship, and for a limited period after it ends so that we can handle anything arising from it.
- Server and security logs are kept only as long as they remain useful for diagnosing faults, preventing abuse and investigating security incidents, then discarded on a rolling basis.
- Marketing contacts are kept until you unsubscribe or ask us to remove you. We keep a minimal record of the withdrawal itself, so that we can honour it.
- Records we are obliged to keep — accounting, tax and statutory records — are kept for the period the applicable law requires, and deleted once it expires.
Where you ask us to delete data and we have no remaining purpose or legal obligation requiring us to keep it, we will delete it rather than wait for a retention period to run out. Backups are overwritten on their own cycle, so a deleted record may persist briefly in backup media before it is fully removed.
12. Your rights
Depending on where you live, you may have some or all of the following rights. We will not charge you for exercising them, and we will not treat you differently for doing so.
- Access — a copy of the personal data we hold about you.
- Correction — to have inaccurate or incomplete data put right.
- Erasure — to have data deleted where we no longer have grounds to keep it.
- Objection and restriction — to object to processing based on legitimate interests, or ask us to pause it.
- Portability — to receive certain data in a machine-readable form.
- Withdraw consent — at any time, where we relied on consent; this does not affect processing already carried out.
- Opt out of marketing — through the unsubscribe link in any marketing email, or by writing to us; we will stop, and this does not affect service messages you still need.
- Nominate — under the DPDP Act, to nominate another individual to exercise your rights in the event of death or incapacity.
- Complain — to your data protection authority, or in India to the Data Protection Board.
To exercise any of these, write to enquiry@zetect.in. We will respond within the period the applicable law allows, and may need to verify your identity first.
If you are in California, you additionally have the rights to know, delete, correct and opt out of “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined under the CCPA.
13. Children
Zetect is an enterprise product. Our website and platform are not directed at children, and we do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy as our practices, the product or the law change. The “last updated” date at the top always reflects the current version. Where a change materially affects your rights, we will take reasonable steps to tell you before it takes effect.
15. How to contact us
Zetect Private Limited
Unit 603–604, 6th Floor, Tower B, Bhutani Alphathum,
Sector 29, Noida, Uttar Pradesh 201305, India
Email: enquiry@zetect.in
Web: www.zetect.in
See also our Terms of Service, Website Terms & Conditions and Disclaimer.