1. Who we are
ZAVTRO INFOTECH is the data controller for personal data processed through our website and customer portal. Our registered office is at Plot No 1052, Fakirabad, Kendrapara, Odisha, India.
For any privacy question, or to exercise a right described below, write to info@zavtro.com.
2. What we collect
We collect only what we need to deliver a service or answer an enquiry.
- Contact details you give us — name, email, phone, company and, if you choose to provide it, your GSTIN
- Billing information — address and payment metadata, never full card numbers
- Service data — domains, hosting accounts and project records tied to your account
- Technical data — IP address, browser and device type, captured in security logs
- Usage data — pages visited and features used, if you accept analytics cookies
3. How we use it
We use personal data to provide the services you have bought, to invoice you, to respond to support requests and to meet statutory record-keeping obligations.
We do not sell personal data, and we do not use customer data to train third-party models.
4. Legal basis
We process data to perform our contract with you, to comply with legal obligations, and where you have given consent — for example marketing email, which you can withdraw at any time.
5. Sharing and processors
We share data only with processors needed to run the service: payment gateways, email delivery providers, cloud infrastructure and analytics, each under a data processing agreement.
- Payment gateways — PhonePe, Razorpay, Cashfree, Stripe
- Email delivery — Brevo and Amazon SES
- Infrastructure — AWS and Cloudflare
- Analytics — Google Analytics and Microsoft Clarity, only with consent
6. Where data is stored
Customer data is stored in the Mumbai (ap-south-1) region by default so it stays in India. Alternative regions are available on request for customers with different residency requirements.
7. How long we keep it
Account and billing records are retained for eight years to meet Indian tax and company law requirements. Support tickets are kept for three years. Security logs are kept for twelve months.
8. Your rights
You can ask us to do any of the following, and we will respond within 30 days.
- Access a copy of the personal data we hold about you
- Correct anything inaccurate
- Delete data we no longer have a legal basis to keep
- Export your data in a portable format
- Withdraw consent for marketing or analytics
9. Security
We use encryption in transit and at rest, role-based access control, mandatory two-factor authentication for staff with production access, and logged administrative actions.
10. Changes to this policy
Material changes are announced by email to account holders at least 14 days before taking effect. The date at the top of this page always reflects the current version.