Privacy Policy
Last updated: January 2025 | Zora & Zenith Ltd | ICO Registration: [Pending] | GDPR Compliant
At Zora & Zenith Ltd ("the Agency", "we", "us", "our"), we are committed to protecting the privacy and personal data of all individuals who interact with our business. This Privacy Policy explains how we collect, use, store, and protect your personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Please read this policy carefully. By using our website or providing us with your personal information, you confirm you have read and understood this policy. If you have any questions, contact us at team@zorazenith.co.uk.
1. Who We Are (Data Controller)
Zora & Zenith Ltd is the Data Controller responsible for your personal data. As Data Controller, we determine the purposes and means of processing your personal data. Our contact details for all data protection matters are:
2. Data Collection Types of Data Collected
We may collect and process the following categories of personal data:
2.1 Information You Provide Directly
- Contact information: Full name, email address, telephone number, practice name and address.
- Enquiry information: Practice type, budget range, project description, and any other information you voluntarily include in your message.
- Communications: Records of correspondence, emails, and meeting notes during our engagement discussions.
- Contract information: Billing details, payment information (processed securely via third-party payment processors), and contractual communications.
2.2 Information Collected Automatically
- Technical data: IP address, browser type and version, operating system, referring URLs, and device identifiers.
- Usage data: Pages visited, time spent on pages, clicks, and navigation paths within our website.
- Cookie data: Information collected via cookies and similar tracking technologies (see Section 8 Cookies).
2.3 Information from Third Parties
We may receive information about you from third-party sources such as LinkedIn, Google, or other professional directories if you engage with our content on those platforms. We will only process such information where we have a lawful basis to do so.
3. Lawful Basis for Processing
We process your personal data only where we have a lawful basis to do so under UK GDPR. The lawful bases we rely upon are:
- Consent (Article 6(1)(a)): Where you have provided explicit consent to receive marketing communications, for example via our contact form's GDPR checkbox.
- Contractual necessity (Article 6(1)(b)): Where processing is necessary to perform a contract with you, or to take steps at your request before entering into a contract.
- Legal obligation (Article 6(1)(c)): Where processing is necessary for us to comply with a legal obligation, such as financial record-keeping.
- Legitimate interests (Article 6(1)(f)): Where processing is necessary for our legitimate business interests, such as improving our website, responding to unsolicited enquiries, and maintaining business security, provided these interests are not overridden by your rights.
4. Use of Data
We use the personal data we collect for the following purposes:
- To respond to your enquiries and schedule consultations.
- To provide the marketing, branding, and automation services you have engaged us for.
- To communicate with you about your project, service updates, and relevant developments.
- To send marketing and promotional communications where you have provided consent.
- To process payments and maintain accurate financial records.
- To improve our website, services, and user experience.
- To comply with our legal obligations and protect against fraudulent or unlawful activity.
- To conduct internal analytics and business intelligence to better understand our market.
We will never sell, rent, or trade your personal data to third parties for their own marketing purposes.
5. Data Sharing
We may share your personal data with carefully selected third parties only where necessary and under appropriate data processing agreements. These may include:
- Technology providers: CRM systems, email platforms, project management tools, and cloud storage providers used to operate our business.
- Payment processors: Secure, PCI-DSS compliant payment processors for handling billing transactions.
- Marketing platforms: Analytics tools such as Google Analytics to understand website performance (with appropriate consent).
- Legal and regulatory bodies: Where we are required to disclose information by law, court order, or regulatory authority.
All third-party processors are vetted for UK GDPR compliance. Where data is transferred outside the UK or European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs).
6. Data Storage
Your personal data is stored on secure, encrypted servers located within the United Kingdom or the European Economic Area. Where we use US-based service providers, we ensure appropriate data transfer mechanisms are in place. We implement technical and organisational security measures including encryption, access controls, and regular security reviews to protect your data against unauthorised access, loss, or disclosure.
7. Data Retention
We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. Our standard retention periods are:
- Enquiries and pre-contract communications: 12 months from the date of last contact if no contract is entered into.
- Client contract data and project files: 7 years from the end of the client engagement, in accordance with UK tax and financial record-keeping requirements.
- Marketing consent records: For the duration of the consent, plus 3 years after withdrawal to demonstrate compliance.
- Website analytics data: Up to 26 months (in accordance with Google Analytics default settings, adjustable upon request).
Once the relevant retention period expires, data is securely deleted or anonymised in accordance with our data disposal procedures.
8. Your Rights Under UK GDPR
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of Access (Article 15): You have the right to request a copy of the personal data we hold about you (a Subject Access Request).
- Right to Rectification (Article 16): You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to Erasure "Right to be Forgotten" (Article 17): You may request that we delete your personal data where there is no compelling reason for its continued processing. Note that this right is not absolute and may be subject to our legal obligations.
- Right to Restrict Processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances.
- Right to Data Portability (Article 20): Where processing is based on consent or contract, and is carried out by automated means, you have the right to receive your data in a structured, machine-readable format.
- Right to Object (Article 21): You have the right to object to processing based on legitimate interests or for direct marketing purposes.
- Rights Related to Automated Decision-Making (Article 22): You have the right not to be subject to decisions made solely by automated processing that have a significant effect on you.
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please contact us at team@zorazenith.co.uk with the subject line "Data Subject Request." We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data rights have been infringed.
9. Cookies
Our website uses cookies small text files placed on your device to improve your browsing experience and analyse website traffic. We use the following categories of cookies:
- Strictly necessary cookies: Essential for the website to function correctly. These cannot be disabled.
- Analytics cookies: Used to understand how visitors interact with our website (e.g., Google Analytics). These are only placed with your consent.
- Marketing cookies: Used to track visitors across websites and display relevant advertisements. These are only placed with your consent.
You can control cookie preferences through our cookie consent tool presented upon your first visit, or through your browser settings. Disabling certain cookies may affect website functionality. For more information about managing cookies, visit www.aboutcookies.org.
10. Marketing Communications
Where you have provided consent via our contact form, we may send you marketing communications about our services, industry insights, and relevant healthcare marketing content. You may withdraw your consent and unsubscribe at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at team@zorazenith.co.uk. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal.
11. Children's Data
Our services are directed exclusively at business professionals within the healthcare sector. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact us immediately so we can arrange for its deletion.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The updated version will be published on this page with a revised "Last Updated" date. We encourage you to review this policy periodically. Material changes will be communicated to active clients directly.
13. Contact Us
For all data protection enquiries, Subject Access Requests, or concerns about how we handle your personal data, please contact:
If you are not satisfied with our response, you have the right to escalate your complaint to the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint or call 0303 123 1113.