ZeroGrantZEROGRANT

ZeroGrant Privacy Policy

Applies to zerogrant.io, the ZeroGrant API, SDKs, dashboard, sandbox, and documentation.

Data controller for this site and operational data: [CONTRACTING ENTITY] ("ZeroGrant", "we", "us")

Last updated:

1. Who this policy is for and how ZeroGrant is structured

1.1 ZeroGrant provides delegated-access infrastructure. Understanding this policy depends on one distinction:

  • Operational data - data we hold to run the business and the Service: your account, billing, security logs, telemetry, and website analytics. For this data, ZeroGrant is the controller, and this policy governs it.
  • Customer processing data - personal data our customers process through the Service by integrating it into their applications. For this data, our customer is the controller and ZeroGrant is the processor, acting on the customer's documented instructions under the Data Processing Addendum ("DPA"). This policy describes that role but the customer's own privacy notice governs that processing toward data subjects.

1.2 If you are an owner or end user whose data is processed by an application built on ZeroGrant, your relationship is primarily with that application, which is the controller. Contact that application for your rights over data it controls. We will support the controller in meeting your rights as required by the DPA and law.

2. What we collect and why (operational data, ZeroGrant as controller)

Account and identity

Name, work email, organisation, credentials. Purpose: to create and secure your account. Lawful basis: contract.

Billing

Billing contact, plan, transaction records (card data handled by our payment processor, not stored by us). Purpose: to charge for paid plans. Lawful basis: contract; legal obligation (tax/accounting).

API and security logs

API request metadata (timestamps, endpoints, status, intent and grant identifiers, IP, rate-limit and anomaly signals). Purpose: to operate, secure, debug, and prevent abuse of the Service. Lawful basis: legitimate interests (security and service integrity), and contract.

Service telemetry and diagnostics

SDK version, error traces, performance metrics. Purpose: reliability and improvement. Lawful basis: legitimate interests.

Website and product analytics

Pages, referrers, device/browser, cookie identifiers. Purpose: to understand and improve the site and product. Lawful basis: consent where required (see Cookies).

Support and communications

Messages you send us, support tickets. Purpose: to help you and keep records. Lawful basis: legitimate interests; contract.

2.1 What our logs are designed not to contain. The Service is architected so that operational logs record authority and operation metadata (that a scoped operation occurred, its identifiers, its result status) rather than the raw underlying personal data of owners. We do not receive Owner Root Authority private key material, and the Service is designed so we cannot decrypt owner-controlled resources by ourselves. Where a customer's configuration causes personal data to be transmitted to or through the Service, that data is processed as customer processing data under the DPA, not as our operational data.

3. Customer processing data (ZeroGrant as processor)

3.1 When you integrate ZeroGrant, personal data your application handles through the Service is processed by us only on your documented instructions, as your processor, under the DPA. This includes verifying live authority, performing the permitted operation within the protected boundary, and returning the permitted result to your application.

3.2 For this data:

  • you determine purposes and means and are the controller;
  • we do not use it for our own purposes, do not sell it, and do not process it except to provide the Service and as the DPA permits;
  • our subprocessors are listed at [SUBPROCESSOR URL] and are bound by equivalent obligations;
  • return and deletion on termination follow the DPA.

3.3 Owners and data subjects seeking to exercise rights over customer processing data should contact the relevant customer (controller). We will assist the controller as required.

4. How we share operational data

4.1 We share operational data with:

  • Subprocessors and vendors who host, secure, bill, support, and analyse the Service, under contract and only as needed (listed at [SUBPROCESSOR URL]);
  • Professional advisers (legal, accounting, audit) under confidentiality;
  • Authorities, where legally required, limited to what the law compels;
  • A successor, in a merger, acquisition, or asset sale, subject to this policy.

4.2 We do not sell operational data, and we do not use owner personal data for advertising.

5. International transfers

5.1 Where we transfer personal data outside the UK/EEA, we rely on an adequacy decision or appropriate safeguards, principally the [UK IDTA / EU Standard Contractual Clauses], plus supplementary measures where needed. Details and copies are available on request at [PRIVACY CONTACT].

6. Retention

6.1 We keep operational data only as long as needed for its purpose:

  • account data for the life of the account plus [PERIOD];
  • billing records for [STATUTORY PERIOD, e.g. 6-7 years] as tax law requires;
  • security logs for [PERIOD];
  • analytics for [PERIOD].

6.2 Customer processing data retention is governed by the DPA and your instructions.

7. Security

7.1 We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, least-privilege, logging, and monitoring. The Service's own architecture is designed to minimise what usable data exists to be compromised.

7.2 No system is perfectly secure, and we do not claim the Service is unhackable. We maintain incident procedures and will notify affected controllers and, where required, authorities and data subjects in line with law.

8. Your rights

8.1 Depending on where you are and your relationship to the data, you may have rights to access, rectify, erase, restrict, port, or object, and to withdraw consent.

8.2 For operational data we control, contact [PRIVACY CONTACT] and we will respond within the statutory period.

8.3 For data controlled by a customer application, contact that application; we will assist as processor.

8.4 You may complain to your supervisory authority. In the UK this is the Information Commissioner's Office. We ask for the chance to resolve it first.

9. Cookies

9.1 We use strictly necessary cookies to run the site and, with your consent where required, analytics and preference cookies. Manage these via our cookie banner or your browser. See the [Cookie Notice] for the full list.

10. Children

10.1 The Service is a business tool not directed to children, and we do not knowingly collect children's data as operational data. Where a customer application processes minors' data, the customer is responsible for the lawful basis and safeguards for that processing.

11. Changes and contact

11.1 We may update this policy and will post the new date and, for material changes, give reasonable notice.

11.2 Contact: [PRIVACY CONTACT EMAIL] - [POSTAL ADDRESS] - [UK/EU REPRESENTATIVE, if applicable].