Legal

Privacy Policy

This policy explains what personal data Zinn Digital® collects, why, the legal bases we rely on, who we share it with, and the rights you have over it.

Who we are

Last updated: 21 July 2026.

Zinn Digital® Ltd (Company No. 16385785), 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("Zinn Digital", "we", "us" or "our") is the data controller for the personal data described in this policy, unless we are acting as a processor on your behalf as explained below.

We take privacy seriously and only process the data we need to run our hosting and SEO platform, bill for it, support you, keep it secure, and meet our legal obligations. This policy covers our websites, dashboards and APIs; our Cookie Policy covers cookies and similar technologies in detail.

1. The data we collect

The personal data we hold falls into a few clear groups.

Account data

The details you give us when you register and use the platform: your name, email address, organisation, login credentials and multi-factor settings, and the roles and team members you set up. Authentication is handled through our identity provider.

Billing data

What we need to charge you and issue invoices: billing name and address, country, tax identifiers, the plan you bought, and a payment mandate. Card payments are handled by our payment providers — we never receive or store your full card number or security code.

Usage and analytics data

How you interact with our own websites and dashboards: pages viewed, features used, device and browser information, and IP address. On our marketing site this is measured with PostHog only if you consent, and configured not to receive personal data or your search terms.

Support and communications

The content of tickets, emails and messages you send us, so we can help you and keep a record of what was agreed.

Customer site data (as processor)

The websites and applications you host with us may themselves contain personal data about your own users and customers. We process that data only to operate the hosting on your behalf — see section 4.

2. How we use your data

We use personal data to:

  • Provide, operate, secure and improve the platform and its features.
  • Create and administer your account and authenticate you.
  • Take payment, issue invoices, and meet tax and accounting obligations.
  • Provide support and respond to your requests.
  • Send you service messages — renewals, security notices, and important changes — and, where you have opted in, product and marketing updates you can unsubscribe from at any time.
  • Monitor for abuse, fraud and security threats, and enforce our terms.
  • Understand how our own websites are used so we can make them better, using analytics only where you have consented.
  • Comply with the law and respond to valid legal requests.

3. Our lawful bases

Under the UK GDPR and the EU GDPR, we rely on one or more of these lawful bases whenever we process your personal data:

  • Contract — to provide the service you have signed up for and to bill for it.
  • Legitimate interests — to secure the platform, prevent abuse and fraud, and run and improve our business, balanced against your rights and freedoms.
  • Legal obligation — to keep tax, accounting and other records the law requires.
  • Consent — for optional analytics cookies and for marketing where consent is required; you can withdraw consent at any time without affecting processing already carried out.

4. When we act as a processor

When we host your website or application, it may contain personal data about your own visitors, users or customers. For that data you are the controller and we are your processor: we handle it only on your documented instructions and only to provide the hosting service — we do not use it for our own purposes.

We keep that data logically separated between tenants, apply least-privilege access controls, and help you meet your own obligations, including responding to the data-subject requests and security-incident duties that fall on you as the controller. If you need a separate data-processing agreement, contact us.

5. Sharing and sub-processors

We do not sell your personal data. We share it only with service providers that help us run the platform, each under a contract that limits them to our instructions, and each sitting behind an adapter so it can be replaced. These include:

  • Payment providers, to take payment and prevent fraud.
  • Infrastructure and cloud providers that host the platform and its data.
  • A transactional email provider, to send account and service messages.
  • A product-analytics provider (PostHog), used on our own sites only with your consent.
  • Domain registries and DNS, CDN and security providers, where your plan uses them.
  • Professional advisers and authorities, where we are legally required to disclose data.

We choose sub-processors that offer appropriate security and privacy protections, and we keep the categories above current. We may also disclose data if required by law, to enforce our terms, or to protect the rights, safety and property of Zinn Digital®, our customers or the public.

6. International transfers

We are based in the United Kingdom and prefer to keep data in the UK and the European Economic Area where we can — our website analytics, for example, use an EU region. Some of our providers may process data in other countries.

Where personal data is transferred outside the UK or EEA, we rely on a lawful transfer mechanism — an adequacy decision, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses — together with additional safeguards where needed, so your data keeps an equivalent level of protection.

7. How long we keep data

We keep personal data only as long as we need it for the purposes in this policy. Account data is kept while your account is active. After you close it, we keep what we must to meet legal, tax and accounting duties and to resolve disputes, then delete or anonymise the rest.

Billing and invoice records are retained for the period tax law requires. Website content and backups follow the retention window described in your plan. Analytics data is retained for a limited period and holds no direct identifiers.

8. Your rights

Subject to the conditions in data-protection law, you have the right to:

  • Access the personal data we hold about you and get a copy.
  • Correct data that is inaccurate or incomplete.
  • Erase your data where there is no overriding reason for us to keep it.
  • Restrict or object to our processing, including profiling and direct marketing.
  • Receive your data in a portable, machine-readable format, and have it sent to another provider where technically feasible.
  • Withdraw consent at any time, where we rely on consent, without penalty.

To exercise any of these rights, contact us using the details below; we will respond within the time limit the law sets. Exercising your rights is free and carries no penalty. If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA, though we would welcome the chance to put things right first.

9. Cookies and analytics

Our websites use a small number of first-party cookies for preferences (such as your locale, currency and theme) and, only if you consent, one analytics cookie for PostHog. We do not run third-party advertising or cross-site tracking cookies. Our separate Cookie Policy lists every cookie by name, what it does and how long it lasts, and explains how to change your choice at any time.

10. How we protect data

Security is built into the platform. We do not claim any particular compliance certificate here, but we maintain strong technical and organisational measures and can describe our practices to buyers on request.

  • Encryption of data in transit with TLS across our services.
  • Per-tenant isolation so one customer's environment cannot reach another's.
  • Least-privilege access to systems, with secrets held in a dedicated secrets manager rather than in code.
  • An auditable trail of privileged and administrative actions.
  • Continuous monitoring, malware scanning and a defined process for handling security incidents.

11. Children

The service is intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy as our platform, providers or legal obligations change. When we make a material change we will update the date at the top of this page and, where appropriate, tell you by email or in the dashboard. Please review it from time to time.

13. How to contact us

The data controller is Zinn Digital® Ltd (Company No. 16385785), 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

For any privacy question, or to exercise your rights, reach us through our contact page at zinndigital.com/contact, or email office@zinndigital.com for formal data-protection requests. We will route your request to the person responsible for data protection.

Frequently asked questions

Who is responsible for my data?

Zinn Digital® Ltd (Company No. 16385785), 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom is the data controller for your account, billing and website-visitor data. When we host a site for you, we act as a processor for the personal data inside that site — you remain the controller for it.

Do you sell my personal data?

No. We never sell your personal data or your visitors' data, and we do not share it for third-party advertising. We share it only with the sub-processors that help us run the service, and only as much as they need.

What are my rights?

Under the UK GDPR and, where it applies, the EU GDPR, you can ask to access, correct, erase, restrict or object to our use of your personal data, ask for a portable copy, and withdraw consent at any time. Contact us and we will respond within the statutory time limit. You can also complain to the UK Information Commissioner's Office at ico.org.uk.

Where is my data stored and processed?

We host and process data in data centres chosen for the service and, for our website analytics, in PostHog's EU cloud region. Where data moves outside the UK or EEA, we rely on the legal safeguards described in this policy, such as adequacy decisions and standard contractual clauses.

How long do you keep my data?

We keep account and billing records for as long as you have an account and afterwards only as long as the law requires — for example, to meet tax and accounting obligations. Website content and backups are kept for the retention window described in your plan and then deleted.