How information is handled
A technical discussion with a defined purpose
Zylox AI’s registered company controls the corporate website and the enquiries it receives about consultancy or software. The identity and registered address below identify that controller. Send only the context necessary to explain the decision or change being considered.
Sources and categories
Hosting through Cloudflare involves request information such as the page path, browser, IP address and time. Professional correspondence can add a sender’s name, reply contact and technical description. This site’s fonts are local assets; no advertising pixels, account service or additional analytics script appears in the published code.
Lawful bases for the work
The legitimate interests in maintaining a safe public site and handling relevant approaches fall under Article 6(1)(f), subject to individual rights. Requested precontractual measures may use Article 6(1)(b). Applicable legal record obligations use Article 6(1)(c). Any use based on consent requires a clear, separate explanation and a way to withdraw that consent.
Responsibility for engagement data
An engagement where Zylox AI acts as a processor needs documented customer instructions. Its arrangements must address permitted information, access, technical providers, protection and disposal or return at completion. An enquiry about architecture should not include passwords or unrestricted access details.
Retention and international transfers
A correspondence record is held for its enquiry or relationship purpose and any defensible legal requirement. Once that basis for retention ends, deletion or anonymisation is appropriate. Global providers can involve international transfers, which require applicable adequacy provisions or approved contractual safeguards.
How a person can act
Send an access, correction, restriction or deletion of data request to the registered office, identifying the exchange involved. Objection and portability rights apply when their legal tests are met. Only reasonable identity verification should be requested. The normal response period is one month, with any permitted extension explained.
A concern or incident
The response to a data breach must consider containment, consequences and legal notification. Reporting to the ICO within the applicable 72-hour window and informing people follow the relevant risk thresholds. A complaint can also be taken to the ICO independently. The website addresses professional buyers and is not a children’s service.