Skip to content
Zefract

Legal · Privacy

Privacy Policy

We collect less than most agencies, we tell you exactly what we do with it, and we never sell it. This page is the long version, written so you can actually read it.

Effective
3 August 2026
Last updated
1 September 2026
Version
1.0
Applies to
zefract.com and all Zefract services
Registered office
T-8, Ace Parkway, Sector 150, Noida 201310, Uttar Pradesh, India
CIN
U62011UW2026PTC256771
PAN
AADCZ1261G
Contents

Zefract Tech Pvt Ltd builds products and grows them. Doing that means we handle personal data — yours if you visit this site or talk to us about work, and your customers’ if you hire us to run marketing or build software. Those are two different jobs with two different sets of rules, and this policy keeps them clearly apart.

Where the law uses a technical word, we use it and then explain it. Where a section only applies to some readers — people in the EU or UK, for example — we say so at the top of that section.

Section 01

Who we are

In plain English

Zefract is an Indian private limited company based in Delhi NCR. We’re the ones responsible for the data described in this policy, and here’s how to reach us.

Zefract Tech Pvt Ltd (“Zefract”, “we”, “us”, “our”) is a private limited company incorporated in India, operating as a product-and-growth studio: one team that designs, builds and markets digital products for founders and small-to-mid-sized businesses.

Legal name
Zefract Tech Pvt Ltd
CIN
U62011UW2026PTC256771
PAN
AADCZ1261G
Registered office
T-8, Ace Parkway, Sector 150, Noida 201310, Uttar Pradesh, India

Under India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, Zefract is a Data Fiduciary — the organisation that decides why and how personal data is used. You are a Data Principal — the person the data is about. Under the UK and EU GDPR the equivalent terms are controller and data subject. This policy uses both where it helps.

This policy covers www.zefract.com, our proposals and sales conversations, our client engagements, our hiring process, and our email and social channels. It does not cover third-party websites we link to.

Section 02

The two roles we play, and why it matters to you

In plain English

For our own website and sales, we decide what happens to data — so this policy governs. For data inside a client’s ad account, CRM or database, the client decides and we just follow instructions. If you’re a customer of one of our clients, their privacy policy is the one you want, not this one.

Most agency privacy policies blur this line. We’d rather draw it, because it determines who you go to when you want something done about your data.

SituationOur roleWho is accountable
You browse zefract.com, download something, or fill in the contact formData Fiduciary / controllerZefract. This policy applies in full.
You email us a brief, take a call, or receive a proposalData Fiduciary / controllerZefract.
You apply for a role with usData Fiduciary / controllerZefract.
You are a named contact at a client companyData Fiduciary / controllerZefract, for the business relationship.
You are a customer or lead of a Zefract client, and your data sits in their CRM, ad account, email list or database that we operateData ProcessorThe client. We act only on their written instructions. Contact them first — see §12.

If you contact us about data we hold as a processor, we will not act on it unilaterally. We will tell you who the responsible business is, or pass your request to them, within a reasonable time. That isn’t us dodging — it’s the correct handling, and doing otherwise would be a breach of our duty to the client.

Section 03

What we collect

In plain English

Contact details you give us, what you do on our website, and the working files of a live project. We don’t buy lists, we don’t scrape, and we don’t collect sensitive categories like health or biometric data.

Data you give us directly

  • Enquiry and brief data — name, work email, phone number, company, role, country, budget range, and whatever you write in the message field.
  • Meeting and call data — scheduling details, and notes we take. If we record a call, we ask first and you can say no. Recordings are never made covertly.
  • Client onboarding data — billing contact, registered address, GSTIN or VAT number, PAN or tax ID, bank details for refunds, and the named contacts on the account.
  • Credentials and access — where you grant us access to your Google Ads, Meta Business, Analytics, CMS, hosting or repository. See §9 for how we handle these.
  • Candidate data — CV, portfolio, work history, notice period, expected compensation, and interview notes.
  • Subscription data — the email address you give us for our newsletter or teardowns, and whether you opened or clicked.

Data we collect automatically when you use this site

  • IP address (which we truncate for analytics), approximate city-level location, device type, browser, operating system and screen size.
  • Pages viewed, referring URL, time on page, scroll depth, and which links and buttons you clicked.
  • Cookie and local storage identifiers, subject to your consent choices — see §5.
  • Server logs, including request timestamps and error traces, kept for security and debugging.

Data we get from third parties

  • Aggregate campaign and traffic reporting from Google, Microsoft, Meta and LinkedIn.
  • Publicly available business information — company website, LinkedIn company page, published funding or hiring news — used to research a prospect before a first call.
  • Payment confirmations from our payment processor. We never see or store your full card number.

What we deliberately do not collect

We do not collect special or sensitive category data — health, biometric, genetic, caste, religious belief, political opinion, sexual orientation or trade union membership — and we ask you not to send it. We do not buy contact lists, scrape personal email addresses, or use data brokers to enrich profiles of individuals. If a client’s project requires handling sensitive categories, that is scoped, contracted and secured separately before any work begins.

Section 04

Why we use it, and on what legal basis

In plain English

To reply to you, to do the work you hired us for, to get paid, to keep the site secure, and to send marketing you asked for. Each purpose has a lawful basis listed below, so you can check our reasoning rather than take our word for it.

Under the DPDP Act, our lawful ground is consent or one of the legitimate uses the Act permits. Under the UK and EU GDPR the available bases are broader; where you are in the UK, EEA or Switzerland, the GDPR column applies.

What we doData usedDPDP basisGDPR basis
Reply to your enquiry and prepare a proposalEnquiry, brief, meeting notesConsent — you gave it to us for exactly thisSteps prior to entering a contract
Deliver the work in your Statement of WorkClient, project and access dataLegitimate use — performance of a contractPerformance of a contract
Invoice you, collect payment, meet tax and audit dutiesBilling, tax and payment dataLegal obligationLegal obligation
Measure how the site performs and improve itAnalytics and usage dataConsent, via the cookie bannerConsent
Send you our newsletter or a teardown you asked forEmail address, engagement dataConsent, withdrawable any timeConsent, or soft opt-in for existing clients
Keep the site and our systems secure, prevent fraud and abuseIP, logs, device dataLegitimate use — security and prevention of fraudLegitimate interests
Assess a job applicationCandidate dataConsent, and steps prior to employmentSteps prior to a contract
Defend a legal claim, or comply with a lawful orderWhatever the matter requiresLegal obligation / enforcement of legal rightLegal obligation, legitimate interests

What we never do with it

We do not sell personal data. We do not rent, licence or trade it. We do not share your enquiry with other agencies as a referral. We do not use your project data to train third-party AI models — see §6. And we do not use automated decision-making that produces a legal or similarly significant effect on you.

Section 05

Cookies and tracking

In plain English

Necessary cookies load automatically because the site can’t work without them. Everything else — analytics, advertising pixels — stays off until you agree, and you can change your mind at any time from the link in the footer.

We use a consent banner on first visit. Non-essential cookies are set to “off” by default. We do not use pre-ticked boxes, and we do not treat continued scrolling as consent.

CategoryWhat it doesExamplesConsent needed
Strictly necessaryRouting, security, load balancing, remembering your cookie choiceSession cookie, consent recordNo — the site cannot function without these
AnalyticsCounts visits and shows us which pages help and which don’tGoogle Analytics 4, with IP anonymisationYes
Advertising & attributionTells us which ad or campaign led to an enquiryGoogle Ads tag, Meta Pixel, LinkedIn Insight TagYes

You can withdraw or change consent at any time through the Cookie settings link in our footer, and independently through your browser settings. Blocking analytics and advertising cookies will not stop you using any part of this site. We honour Global Privacy Control signals where your browser sends them.

Consent records — what you agreed to, when, and from which banner version — are kept as proof of consent for as long as the DPDP Rules require, and no longer.

Section 06

Who we share it with

In plain English

A short list of service providers who help us run the studio, each under contract. Nobody else, unless the law requires it or you ask us to.

We share personal data only in these circumstances:

  1. Service providers (sub-processors) who process data on our instructions under a written agreement with confidentiality and security terms.
  2. Professional advisers — our accountants, auditors and lawyers — where they need it to advise us.
  3. Authorities, where we are legally required to disclose. We will tell you unless we are legally barred from doing so.
  4. A buyer, if Zefract is acquired or merged. You will be told before your data moves and this policy will continue to apply until you are given a new one.

Current categories of service provider

PurposeProvider categoryWhere processed
Website hosting and CDNNetlifyGlobal edge; primary processing facilities in the United States
Email and documentsGoogle WorkspaceGlobal
CRM and proposalsGoogle Workspace / manual processesGlobal
AnalyticsGoogle Analytics 4Global
Advertising platformsGoogle, Meta, Microsoft, LinkedInGlobal
Email marketingNo dedicated ESP currentlyN/A
Payments and invoicingProvider to be determinedProvider-dependent
Project management and file storageGoogle Workspace/MicrosoftGlobal

A current and complete sub-processor list is available on request from privacy@zefract.com. Clients on an active engagement are notified before we add a sub-processor that will touch their data, and may object.

AI and machine learning tools

We use AI tools in parts of our work — research, drafting, code assistance and analysis. Where we do, we use business or enterprise tiers configured so that inputs are not used to train the provider’s models, and we do not paste client confidential material or personal data into consumer AI tools. Any AI-assisted output is reviewed by a person before it reaches you. If your organisation needs AI tooling excluded entirely from your engagement, say so and we will contract for that.

Section 07

Sending data outside India

In plain English

Some of our tools store data abroad. When that happens we make sure there’s a contract in place that keeps your protections travelling with the data.

Zefract operates from India and serves clients globally. Personal data may therefore be transferred to, stored in, or accessed from countries other than the one you are in — most commonly the United States, the European Union, Singapore and the United Arab Emirates, depending on where our service providers operate.

The DPDP Act permits transfer of personal data outside India except to territories the Central Government restricts by notification. We monitor those notifications and will stop or relocate a transfer if a destination becomes restricted.

Where data of individuals in the UK or EEA is transferred outside those areas, we rely on the UK International Data Transfer Addendum or the European Commission’s Standard Contractual Clauses, together with a transfer risk assessment where one is required. You can request a copy of the safeguards applied to a specific transfer.

Section 08

How long we keep it

In plain English

Only as long as the purpose lasts, plus whatever the tax and legal rules force us to keep. Then we delete it or strip the identifying parts out.

We do not keep personal data indefinitely “just in case”. Each category has a defined retention period:

DataKept forWhy
Enquiry that did not become a project24 months from last contactBuying cycles in our category are long; then deleted
Client contract, SOW and project records7 years after the engagement endsLimitation periods and contractual defence
Invoices, tax and accounting records8 yearsIndian tax and companies-law retention
Client working files and deliverables12 months after handover, then deleted unless you ask us to keep themTransition support
Platform credentials and access tokensRevoked within 5 working days of engagement endLeast-privilege principle
Newsletter subscriptionUntil you unsubscribe, plus a suppression recordThe suppression record exists so we don’t email you again by mistake
Unsuccessful candidate data12 months, with consent; otherwise 6 monthsFuture roles and equal-opportunity records
Website server logs90 daysSecurity and debugging
Cookie consent recordsAs required by the DPDP RulesProof of consent
Call recordings90 days unless the project needs them longerAccuracy of notes

When a period ends we delete the data or irreversibly anonymise it. Anonymised, aggregate statistics — such as “38% of enquiries came from organic search” — carry no personal data and may be kept indefinitely.

Section 09

How we protect it

In plain English

Encryption, multi-factor authentication, least-privilege access, and never asking you for a password. We use delegated access to your platforms, not shared logins.

We apply reasonable security safeguards proportionate to the data we hold, as required by Rule 6 of the DPDP Rules, 2025 and by Article 32 of the UK and EU GDPR:

  • Encryption in transit (TLS 1.2 or higher) and at rest with our infrastructure providers.
  • Multi-factor authentication on every account that touches client data, without exception.
  • Role-based access on a need-to-know basis, reviewed when someone joins, changes role or leaves.
  • A password manager for all shared secrets. Credentials are never sent over email, WhatsApp or Slack.
  • Access logs and activity monitoring, retained for at least one year in line with Rule 6.
  • Confidentiality obligations and security training for every employee and contractor.
  • Documented backup and recovery procedures for systems we host.

How we take access to your platforms

We ask for delegated access — a Google Ads manager account link, a Meta Business Manager partner request, a named Analytics user, a repository collaborator invite. We do not ask for your username and password, and you should be sceptical of any agency that does. Delegated access means you can see exactly what we can reach, and revoke it in one click without changing a single password.

No system is perfectly secure, and we will not pretend otherwise. What we will do is tell you quickly and honestly if something goes wrong — see §13.

Section 10

Your rights

In plain English

You can ask what we hold, correct it, delete it, take it elsewhere, withdraw consent, and complain. It’s free, and we aim to answer within 30 days.

If you are in India — your rights as a Data Principal

  • Access — a summary of the personal data we process about you, what we do with it, and who we’ve shared it with.
  • Correction and completion — to have inaccurate or incomplete data corrected, completed or updated.
  • Erasure — to have your data deleted, unless we are required by law to keep it.
  • Withdraw consent — as easily as you gave it. Withdrawal doesn’t undo processing that already happened lawfully.
  • Nominate — to name someone who can exercise these rights on your behalf if you die or become incapacitated.
  • Grievance redressal — to raise a complaint with our Grievance Officer and, if unresolved, with the Data Protection Board of India. See §14.

The DPDP Act also places duties on you: don’t impersonate someone else when making a request, don’t suppress material information, and don’t file a frivolous or false complaint. We mention it because the Act does.

If you are in the UK, EEA or Switzerland

You additionally have the right to restrict processing, to object to processing based on legitimate interests or direct marketing, to data portability in a machine-readable format, and not to be subject to solely automated decision-making with legal or similarly significant effects. You may complain to your national supervisory authority — in the UK, the Information Commissioner’s Office at ico.org.uk.

If you are in the UAE, Australia, Singapore or elsewhere

We extend the access, correction, deletion and objection rights above to everyone, regardless of location. Where your local law gives you more, your local law wins.

How to make a request

Email privacy@zefract.com with the words “Privacy request” in the subject line and tell us what you want. We will:

  1. Acknowledge within 3 working days.
  2. Verify your identity — proportionately. For a request tied to an email address we already hold, replying from that address is usually enough. We will not demand ID documents we don’t need.
  3. Respond substantively within 30 days. If a request is complex we may take up to 60 days, and we will tell you why before the first 30 are up.

There is no charge. If a request is manifestly unfounded or repetitive we may decline it, and we will explain our reasoning in writing so you can challenge it.

Section 11

Children’s data

In plain English

Our services are for businesses. We don’t knowingly collect data from anyone under 18, and we don’t run behavioural advertising aimed at children.

Zefract sells business-to-business services. This website is not directed at children, and we do not knowingly collect personal data from anyone under 18 years of age — the threshold set by the DPDP Act, which is higher than the age used in many other jurisdictions.

We do not track children, run behavioural advertising directed at them, or process children’s data for profiling. If we learn we have collected data from a child without verifiable consent from a parent or lawful guardian, we will delete it promptly. If you believe this has happened, contact privacy@zefract.com.

If a client engagement would require processing children’s data — an education or paediatric-care client, for example — we treat that as a separate scoping exercise with its own consent architecture, before any work starts.

Section 12

Data we handle on behalf of clients

In plain English

When we run your ads, email or CRM, your customers’ data stays yours. We follow your instructions, we don’t reuse the data, and we hand it all back and delete our copies when we’re done.

Running marketing and building software means touching data that belongs to our clients and their customers. For that data we are a Data Processor under the DPDP Act and a processor under the GDPR. Our commitments:

  • We act only on documented instructions from the client, set out in the Statement of Work or a data processing addendum.
  • We do not use client data for our own purposes. Not for benchmarking, not for lookalike audiences on another account, not for training models, not for prospecting.
  • We keep it separated. Client data lives in the client’s own accounts and workspaces wherever technically possible, not pooled in ours.
  • We flag unlawful instructions. If an instruction would breach data protection law — uploading a purchased list, for example — we say so in writing and decline.
  • We assist with rights requests. If one of your customers asks you to delete their data, we help you honour it inside the systems we operate.
  • We return and delete. At the end of an engagement we hand over what’s ours to hand over and delete our working copies, on the timeline in §8.

Clients who need a formal Data Processing Addendum — including GDPR Article 28 terms, our sub-processor list, Standard Contractual Clauses and a security schedule — can request one at privacy@zefract.com. We will sign one. We’d rather you asked.

If you are a customer of one of our clients and want your data accessed, corrected or deleted, please contact that business directly. They control it. If you’re not sure who to contact, write to us and we’ll point you in the right direction without disclosing anything we shouldn’t.

Section 13

If something goes wrong

In plain English

If there’s a breach affecting your data, we tell you — in plain language, quickly, with what happened and what to do about it. No burying it in a status page.

In the event of a personal data breach, we will:

  1. Contain the incident and assess what data and whose data is affected.
  2. Notify affected individuals without delay, in plain language: what happened, what data was involved, what the likely consequences are, what we have done, what you can do to protect yourself, and who to contact.
  3. Notify the Data Protection Board of India within the timelines set by the DPDP Rules, and follow up with the detailed report within the period the Rules allow.
  4. Notify affected clients without undue delay where the breach touches data we process for them, so they can meet their own obligations. Contractually, that means within 24 hours of becoming aware.
  5. Notify supervisory authorities in other jurisdictions — such as the ICO within 72 hours — where their law applies.
  6. Publish a post-incident summary of what we changed, where doing so does not create further risk.

We maintain an incident response procedure and access logs sufficient to investigate. Suspected security issues can be reported to security@zefract.com. We will acknowledge a good-faith report within 3 working days and will not pursue legal action against researchers who report responsibly and do not access or exfiltrate data beyond what is needed to demonstrate the issue.

Section 14

Grievance Officer and complaints

In plain English

A named human is responsible for privacy complaints here. If we don’t sort it out, you can escalate to the regulator — and here’s how.

As required by the DPDP Act and by the Information Technology (Intermediary Guidelines) framework, we publish the name and contact details of the person responsible for handling privacy grievances.

Grievance Officer
Devender
Designation
Director
Phone
+91 93114 41557
Address
T-8, Ace Parkway, Sector 150, Noida 201310, Uttar Pradesh, India
Response time
Acknowledged in 3 working days, resolved within 30 days

Escalating. If we don’t resolve your grievance to your satisfaction, you may complain to the Data Protection Board of India, which is constituted and accepting complaints. The Board expects you to have raised the matter with us first, so please give us the chance.

If you are in the UK or EEA, you may instead complain to your supervisory authority. Nothing in this policy removes that right.

Section 15

Changes to this policy

In plain English

We’ll update this page when the law or our tools change. Meaningful changes get emailed to clients and subscribers — not slipped in quietly.

We review this policy at least once a year and whenever we adopt a new tool, enter a new market, or the law changes materially. The “last updated” date at the top always reflects the current version.

For material changes — a new purpose, a new category of recipient, a shorter or longer retention period — we will give notice at least 14 days before the change takes effect, by email to clients and subscribers and by a notice on this page. Where a change requires fresh consent under the DPDP Act, we will ask for it rather than assume it.

Previous versions are archived and available on request, so you can see exactly what changed and when.

Section 16

Contact us

Questions about this policy, a rights request, or something you think we’ve got wrong:

Post
Zefract Tech Pvt Ltd, T-8, Ace Parkway, Sector 150, Noida 201310, Uttar Pradesh, India

We read everything sent to these addresses. A real person replies.

Chat with us