Privacy policy

1. INTRODUCTION

**Non Zero Design LLP** (hereinafter referred to as "Non Zero", "we", "us", "our") is delighted that you have shown interest in our services and any services which are provided via https://www.nonzero.space/, together with any software, APIs, mobile website and mobile applications related, linked, or otherwise connected thereto (collectively, the "Platform"). Data protection is a high priority for Non Zero. The use of the Platform is generally possible without any indication of personal data; however, if a data subject wants to use certain services offered via our Platform (such as submitting an enquiry through our contact form), processing of personal data may become necessary. Where the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain consent from the data subject.

The processing of personal data, such as the name, email address, or contact number of a data subject, shall always be in line with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Digital Personal Data Protection Act, 2023 of India read with the Digital Personal Data Protection Rules, 2025 (together, the "DPDP Act"), and in accordance with the country-specific data protection regulations applicable to Non Zero. By means of this Privacy Policy, our enterprise would like to inform the general public of the nature, scope, and purpose of the personal data we collect, use, and process. Furthermore, data subjects are informed, through this Privacy Policy, of the rights to which they are entitled.

As the controller (and, for the purposes of the DPDP Act, the Data Fiduciary), Non Zero has implemented numerous technical and organisational measures to ensure the protection of personal data processed through this Platform. However, Internet-based data transmissions may, in principle, have security gaps, so absolute protection may not be guaranteed. For this reason, every data subject is free to transfer personal data to us via alternative means, for example, by telephone or post.

This Privacy Policy should be read together with our separate Cookie Policy, which describes in detail the cookies and similar technologies used on the Platform.

2. DEFINITIONS

This Privacy Policy is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). Our Privacy Policy should be legible and understandable for the general public, as well as our customers and business partners. To ensure this, we would like to first explain the terminology used. Where relevant, we have indicated the corresponding term under the DPDP Act. In this Privacy Policy, we use, among other things, the following terms:

1. Personal data Personal data means any information relating to an identified or identifiable natural person ("data subject", referred to as a "Data Principal" under the DPDP Act). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

2. Data subject / Data Principal Data subject is any identified or identifiable natural person whose personal data is processed by the controller responsible for the processing. Under the DPDP Act, such a person is referred to as a Data Principal.

3. Processing Processing is any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

4. Restriction of processing Restriction of processing is the marking of stored personal data with the aim of limiting their processing in the future.

5. Profiling Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.

6. Pseudonymisation Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

7. Controller / Data Fiduciary Controller, or controller responsible for the processing, is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Under the DPDP Act, this role corresponds to that of the Data Fiduciary.

8. Processor / Data Processor Processor is a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller. Under the DPDP Act, this role corresponds to that of the Data Processor.

9. Recipient Recipient is a natural or legal person, public authority, agency, or another body, to which the personal data are disclosed, whether a third party or not.

10. Third party Third party is a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

11. Consent Consent of the data subject is any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

12. Consent Manager Consent Manager means, under the DPDP Act, a person registered with the Data Protection Board of India who acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.

3. NAME AND ADDRESS OF THE CONTROLLER

The controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in the Member States of the European Union, the California Consumer Privacy Act (CCPA), and the Data Fiduciary for the purposes of the DPDP Act, is:

Non Zero Design LLP
Enam Sambhav, BKC WeWork Enam Sambhav, C-20, G Block Rd, G Block BKC, Bandra Kurla Complex, Bandra East, Mumbai, Maharashtra 400051, India
Email: help@nonzero.space

4. PERSONAL DATA WE COLLECT

We collect personal data in two ways: data that you provide to us directly, and data that is collected automatically when you access the Platform.

Data you provide to us.

When you complete and submit the contact or enquiry form made available on the Platform, we collect the following categories of personal data:-
Name

Email address
Contact number

All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.

Data collected automatically.


When a data subject, or an automated system, calls up the Platform, a series of general data and information is collected and stored in the server log files. This may include the browser type and version, the operating system, the referrer URL, the date and time of access, the Internet protocol (IP) address, and similar technical data, as well as data and information that may be used in the event of attacks on our information technology systems. When using this general data and information, Non Zero does not draw any conclusions about the data subject; rather, this information is processed for the purposes described in the section titled "Purposes and Use of the Data We Collect". The anonymised data of the server log files are stored separately from all personal data provided by a data subject.

5. PURPOSES AND USE OF THE DATA WE COLLECT

We use the personal data we collect for the following purposes:

To respond to enquiries submitted through our contact form and to reach out to you where there is a potential business prospect;
To deliver the content of our Platform correctly and to optimise it;
To ensure the long-term viability and security of our information technology systems and website technology;
For analytics and statistical purposes, to understand how visitors use the Platform and to improve its usability;
To comply with applicable legal obligations; and
To provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack.

We do not use the personal data you provide through the contact form for automated decision-making that produces legal or similarly significant effects concerning you.

6. COOKIES

The Platform of Non Zero uses cookies and similar technologies. Cookies are text files that are stored on a computer system via an Internet browser. Many cookies contain a so-called cookie ID, which is a unique identifier of the cookie. Through the use of cookies, Non Zero can provide the users of this Platform with more user-friendly services that would not be possible without the cookie setting, and can optimise the information and offers on the Platform with the user in mind.

The data subject may, at any time, prevent the setting of cookies through our Platform by means of a corresponding setting of the Internet browser used, and may thus permanently deny the setting of cookies. Furthermore, cookies that have already been set may be deleted at any time via an Internet browser or other software programs. If the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our Platform may be entirely usable. On first access to the Platform, you are also presented with a cookie consent banner that allows you to accept or decline non-essential cookies and to manage your preferences.

A detailed description of the specific cookies used on the Platform, including their name, provider, purpose, and duration, is set out in our separate Cookie Policy, which forms part of and should be read together with this Privacy Policy.

7. CONTACT POSSIBILITY VIA THE PLATFORM

The Platform of Non Zero contains information that enables quick electronic contact with our enterprise, as well as direct communication with us, which also includes a general email address. If a data subject contacts the controller by email or via a contact form, the personal data transmitted by the data subject are automatically stored. Such personal data, transmitted on a voluntary basis by a data subject to the controller, are stored for the purpose of processing the enquiry or contacting the data subject. Enquiries submitted through the contact form on the Platform are routed to and received at help@nonzero.space. There is no transfer of this personal data to third parties for their own independent purposes.

8. DISCLOSURE OF DATA AND NO SALE OF PERSONAL DATA

We do not sell your personal data, and we do not share your personal data with third parties for their own advertising or commercial purposes. We use analytics and performance tools such as Google Analytics 4 and Microsoft Clarity solely for our own understanding of how the Platform is used, and not for onward sale or disclosure to unrelated third parties.

We may disclose personal data to the service providers and processors described in the sections below, who process personal data on our behalf and under our instructions in order to operate, host, secure, and analyse the Platform. We may also disclose personal data where required to do so by law, regulation, or a lawful request from a competent authority, or where necessary to protect our rights, property, or safety, or that of our users or the public.

9. INTERNATIONAL DATA TRANSFERS AND GLOBAL AUDIENCE

Non Zero Design LLP is a limited liability partnership incorporated in India, with its registered office in Mumbai, Maharashtra. The Platform is, however, accessible to, and may be used by, visitors located anywhere in the world. If you access the Platform from outside India, please be aware that your information may be transferred to, stored in, and processed in India, as well as in other countries where our service providers operate, including the United States and the European Economic Area.

These countries may have data protection laws that are different from, and in some cases less protective than, the laws of your country of residence. Where we transfer personal data internationally, we take steps to ensure that appropriate safeguards are in place in accordance with applicable law, and that the recipients are bound to protect the personal data to a standard consistent with this Privacy Policy. By using the Platform or submitting personal data to us, you acknowledge and, where required by law, consent to such transfer, storage, and processing.

Nothing in this Privacy Policy shall be read as targeting, or as an offer of goods or services to, individuals in any jurisdiction where doing so would be unlawful for Non Zero.

10. RESTRICTED JURISDICTIONS, SANCTIONS, AND EXPORT CONTROL

The Platform is not directed to, and is not intended for use by, any person located in, ordinarily resident in, or organised under the laws of any country or territory that is subject to comprehensive economic sanctions or embargoes, including but not limited to the Democratic People's Republic of Korea (North Korea), Iran, Syria, Cuba, and the Crimea, Donetsk, and Luhansk regions. The Platform is likewise not available to any person who is designated on any applicable restricted-party or sanctions list, including the lists maintained by the Government of India, the United Nations Security Council, the European Union, and the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC).

By accessing or using the Platform, you represent and warrant that you are not located in any such country or territory, and that you are not a person with whom dealings are prohibited under applicable sanctions or export control laws. We reserve the right to restrict or deny access to the Platform, and to decline to process any enquiry, where we believe that doing so is necessary to comply with such laws.

The Platform and its underlying technology may be subject to export control and economic sanctions laws, including those of India, the European Union, and the United States. You agree that you will not use, export, re-export, or transfer, directly or indirectly, any part of the Platform or any related technical data in violation of such laws. This clause applies in addition to, and does not limit, any other provision of this Privacy Policy.

11. SECURITY

This Platform ensures that data is encrypted when in transit. Encryption methods such as SSL/TLS are utilised to protect data when it is transmitted to and from this Platform over a secure communications channel, and the Platform is served over HTTPS with HSTS enabled by default. This process involves converting information or data into a code in order to prevent unauthorised access.

At present, we do not collect payments or process any payment card information through the Platform. Should we introduce paid services or a marketplace in the future, we will implement appropriate payment security measures and will update this Privacy Policy accordingly before any such processing begins.

Whilst we do everything within our power to ensure that personal data is protected at all times, we cannot guarantee the absolute security and integrity of information that has been transmitted to our Platform, as no method of transmission over the Internet is completely secure.

12. ROUTINE ERASURE AND BLOCKING OF PERSONAL DATA

The controller shall process and store the personal data of the data subject only for the period necessary to achieve the purpose of storage, or as far as this is granted by the applicable legislator in laws or regulations to which the controller is subject.

If the storage purpose is no longer applicable, or if a storage period prescribed by a competent legislator expires, the personal data are routinely blocked or erased in accordance with legal requirements.

13. PERIOD FOR WHICH THE PERSONAL DATA WILL BE STORED

The criteria used to determine the period of storage of personal data is the respective statutory retention period. After expiration of that period, the corresponding data is routinely deleted, as long as it is no longer necessary for the fulfilment of, or the initiation of, a contract, or for the purpose of responding to and following up on your enquiry. Where you have submitted an enquiry that does not result in an ongoing business relationship, we retain the associated personal data only for as long as reasonably necessary to deal with the enquiry and any related follow-up, after which it is deleted or anonymised.

14. CHILDREN'S PRIVACY

The Platform is intended for use by adults and is not directed at children. We do not knowingly collect personal data from children. Under the DPDP Act, the processing of the personal data of a child (a person below the age of eighteen years) requires the verifiable consent of a parent or lawful guardian, and we do not knowingly undertake such processing. If you are a parent or guardian and believe that a child has provided us with personal data without appropriate consent, please contact us at help@nonzero.space, and we will take reasonable steps to delete such information.

15. RIGHTS OF THE DATA SUBJECT

Subject to applicable law, each data subject has the following rights. If you wish to exercise any of these rights, you may contact us at any time at help@nonzero.space.

1. Right of confirmation. You have the right to obtain from the controller confirmation as to whether or not personal data concerning you are being processed.

2. Right of access. You have the right to obtain from the controller free information about your personal data stored at any time, and a copy of this information, together with the details prescribed by applicable law, such as the purposes of the processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the personal data have been or will be disclosed.

3. Right to rectification. You have the right to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning you, and, taking into account the purposes of the processing, the right to have incomplete personal data completed.

4. Right to erasure (right to be forgotten). You have the right to obtain from the controller the erasure of personal data concerning you without undue delay where one of the grounds prescribed by applicable law applies, and where the processing is not necessary, for example, where the personal data is no longer necessary in relation to the purposes for which it was collected, where you withdraw consent and there is no other legal ground for the processing, or where the personal data has been unlawfully processed.

5. Right of restriction of processing. You have the right to obtain from the controller restriction of processing where the accuracy of the personal data is contested, where the processing is unlawful and you oppose erasure, where the controller no longer needs the data but you require it for the establishment, exercise, or defence of legal claims, or where you have objected to processing pending verification.

6. Right to data portability. You have the right to receive the personal data concerning you, which you have provided to the controller, in a structured, commonly used, and machine-readable format, and the right to transmit that data to another controller without hindrance, where the processing is based on consent or on a contract and is carried out by automated means, and where technically feasible.

7. Right to object. You have the right to object, on grounds relating to your particular situation, at any time, to the processing of personal data concerning you which is based on the legitimate interests of the controller. You also have the right to object at any time to the processing of your personal data for direct marketing purposes, following which we will no longer process your personal data for such purposes.

8. Rights in relation to automated decision-making and profiling. You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except in the circumstances permitted by applicable law and subject to suitable safeguards.

9. Right to withdraw consent. Where the processing of your personal data is based on consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

16. YOUR RIGHTS UNDER INDIA'S DIGITAL PERSONAL DATA PROTECTION ACT

If you are a Data Principal whose personal data is processed by Non Zero as a Data Fiduciary, you have the following rights under the DPDP Act, in addition to any rights set out elsewhere in this Privacy Policy:

Right to access information. The right to obtain a summary of the personal data being processed and the processing activities undertaken, and the identities of any other Data Fiduciaries and Data Processors with whom the personal data has been shared.

Right to correction and erasure. The right to correction, completion, updating, and erasure of your personal data.- **Right of grievance redressal.** The right to have readily available means of grievance redressal in respect of any act or omission regarding the performance of our obligations.

Right to nominate. The right to nominate another individual to exercise your rights in the event of your death or incapacity.- **Right to withdraw consent.** Where processing is based on your consent, the right to withdraw that consent as easily as it was given.

You may exercise these rights, or lodge a grievance, by contacting us at help@nonzero.space. If your grievance is not resolved to your satisfaction, you may have the right to lodge a complaint with the Data Protection Board of India in accordance with the DPDP Act. Please note that certain provisions of the DPDP Act and the DPDP Rules, 2025 are being brought into force in a phased manner, and we will continue to align our practices with those provisions as they take effect.

17. CCPA PROVISO

The California Code of Regulations defines a "resident" as: (1) every individual who is in the State of California for other than a temporary or transitory purpose; and (2) every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose. All other individuals are defined as "non-residents". If this definition of "resident" applies to you, certain rights and obligations apply regarding your personal information.

Your California Privacy Rights.

If you are a California resident, you have the following rights specifically under the California Consumer Privacy Act:

Right to Know. You have the right to know and see what data we have collected about you over the past 12 months, including: (1) the categories of personal information we have collected about you; (2) the categories of sources from which the personal information is collected; (3) the business or commercial purpose for collecting your personal information; (4) the categories of third parties with whom we have shared your personal information; and (5) the specific pieces of personal information we have collected about you.

Right to Delete. You have the right to request that we delete the personal information we have collected from you, and direct our service providers to do the same, subject to certain exceptions permitted by law.

Right to Non-Discrimination. You have the right not to receive discriminatory treatment for exercising any of your CCPA rights.

California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes, and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. As stated elsewhere in this Privacy Policy, we do not disclose your personal information to third parties for their own direct marketing purposes.

To exercise your rights under the California Consumer Privacy Act, please contact us by sending an email to help@nonzero.space. Please provide your full name and email address so that we may respond to your request as quickly as possible. You may be required to verify your identity before we fulfil your request. You can also designate an authorised agent to make a request on your behalf, in which case you must provide us with written authorisation for the agent to act on your behalf, and you will still need to verify your identity directly with us.

18. LEGAL BASIS FOR THE PROCESSING

Article 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose. Where the processing of personal data is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract, such as when responding to enquiries concerning our services, the processing is based on Article 6(1)(b) GDPR. Where we are subject to a legal obligation by which processing of personal data is required, such as for the fulfilment of tax or regulatory obligations, the processing is based on Article 6(1)(c) GDPR. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or of another natural person, in which case the processing is based on Article 6(1)(d) GDPR. Finally, processing operations may be based on Article 6(1)(f) GDPR where the processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Where the DPDP Act applies, we process personal data on the basis of your consent or for such legitimate uses as are permitted under that Act.

19. THE LEGITIMATE INTERESTS PURSUED BY THE CONTROLLER OR BY A THIRD PARTY

Where the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is to contact you, respond to your enquiries, pursue potential business prospects, operate and secure the Platform, and understand and improve how the Platform is used.

20. PROVISION OF PERSONAL DATA AS A STATUTORY OR CONTRACTUAL REQUIREMENT

We clarify that the provision of personal data may be partly required by law (for example, tax regulations) or may result from contractual provisions (for example, information about a contractual partner). Sometimes it may be necessary, in order to conclude a contract, that a data subject provides us with personal data which must subsequently be processed by us. The non-provision of the personal data may have the consequence that the enquiry cannot be dealt with, or that a contract with the data subject cannot be concluded. Before personal data is provided by the data subject, the data subject may contact us, and we will clarify whether the provision of the personal data is required by law or contract, or is necessary for the conclusion of a contract, whether there is an obligation to provide the personal data, and the consequences of non-provision.

21. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF GOOGLE TAG MANAGER

On this Platform, the controller has integrated Google Tag Manager, together with the associated Google site tag (gtag.js). Google Tag Manager is a tag management solution operated by Google that allows website operators to manage and deploy measurement tags and code snippets (such as those used by analytics tools) through a single interface, without editing the website code directly. Google Tag Manager itself is a cookie-less domain that facilitates the loading of other tags, which may in turn collect data.

Google Tag Manager triggers other tags that may themselves collect data. Google Tag Manager does not access this data. If a deactivation or an objection has been made at the level of the individual tags (for example, the analytics tags described below), it will be respected. The operator of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For further information regarding Google's data processing practices, please refer to Google's Privacy Policy at https://policies.google.com/privacy.

22. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF GOOGLE ANALYTICS 4

On this Platform, the controller has integrated the component Google Analytics 4 (GA4). Google Analytics is a web analytics service, that is, the collection, gathering, and analysis of data about the behaviour of visitors to websites. A web analysis service collects, among other things, data about the website from which a person has come (the so-called referrer), which sub-pages were visited, and how often and for what duration a sub-page was viewed. Web analytics are mainly used for the optimisation of a website and to carry out a cost-benefit analysis of the Platform. In Google Analytics 4, IP addresses are used only transiently and are not logged or stored by Google in a manner that identifies the individual; IP data is anonymised at collection.

The operator of the Google Analytics component within the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The purpose of the Google Analytics component is the analysis of the traffic on our Platform. Google uses the collected data and information to evaluate the use of our Platform, to compile online reports showing the activities on our Platform, and to provide other related services to us. Google Analytics places a cookie on the information technology system of the data subject. With the setting of the cookie, Google is enabled to analyse the use of our Platform. Personal data, such as the access time, the location from which the access was made, and the frequency of visits, may be transmitted to Google, and some of this data may be transferred to and stored by Google on servers located in the United States of America.

The data subject may prevent the setting of cookies through our Platform at any time by means of a corresponding adjustment of the web browser used, and may object to the collection and use of data generated by Google Analytics by downloading and installing the browser add-on available at https://tools.google.com/dlpage/gaoptout. Further information and the applicable data protection provisions of Google may be retrieved at https://policies.google.com/privacy and https://marketingplatform.google.com/about/analytics/terms/us/.

23. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF MICROSOFT CLARITY

On this Platform, the controller has integrated Microsoft Clarity ("Clarity"). Clarity is a free service provided by Microsoft that enables website owners to gain detailed insights into user behaviour through tools such as heat maps, session recordings, and aggregated performance metrics. Clarity captures anonymised interaction data, including mouse movements, clicks, scroll patterns, and page engagement, to help us analyse visitor behaviour and optimise our website's usability without directly processing personally identifiable information.

Clarity's tracking code, which is embedded on our Platform, operates via first-party cookies that facilitate session continuity and enable the aggregation of usage statistics. Importantly, no personal data is directly collected by Clarity unless explicitly configured to do so. Data gathered by Clarity is transmitted to and processed by Microsoft Ireland Operations Ltd. and stored securely on Microsoft's Azure platform. Any deactivation measures or user consent preferences implemented on our website, such as cookie opt-in or opt-out settings, are respected by Clarity.

For further details regarding the data processing practices, security measures, and your rights in relation to Clarity, please refer to Microsoft's Privacy Statement at https://privacy.microsoft.com/en-us/privacystatement and the Clarity privacy information available at https://clarity.microsoft.com/privacy.

24. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF GOOGLE SEARCH CONSOLE

The controller has integrated Google Search Console ("GSC"). GSC is a free service provided by Google that enables website owners to monitor, maintain, and troubleshoot their site's presence in Google Search results. GSC delivers aggregated performance metrics, such as search impressions, click data, average ranking positions, indexing status, and crawl error reports, that assist us in evaluating and enhancing our website's visibility and content strategy. GSC collects data directly from Google's search index without deploying additional tracking technologies (such as cookies) on our website; as a result, no personal data of our visitors is processed by us via GSC.

For further details regarding the privacy practices applicable to GSC, please consult Google's Privacy Policy at https://policies.google.com/privacy.

25. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF GOOGLE FONTS AND GOOGLE HOSTED LIBRARIES

On this Platform, the controller uses Google Fonts (including the Google Font API and Google-hosted web font loader) and Google Hosted Libraries to display fonts and to load common JavaScript libraries in a uniform manner. These services are provided by Google. When a page of our Platform is loaded, your browser may retrieve the relevant fonts or libraries from Google's servers in order to display the content correctly. For this technical purpose, your browser must connect to Google's servers, and in doing so, Google may become aware of your IP address and the fact that our Platform has been accessed through your device.

The use of Google Fonts and Google Hosted Libraries is in the interest of a consistent and appealing presentation of our Platform, and constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. The operator of these services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Further information can be found at https://developers.google.com/fonts/faq and in Google's Privacy Policy at https://policies.google.com/privacy.

26. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF GOOGLE ADS AND DOUBLECLICK

The Platform may include components associated with Google's advertising and measurement services, including DoubleClick (now part of Google Marketing Platform). These services use cookies and similar identifiers to help measure the performance of, and interaction with, online content, and, where applicable, to support advertising. Such cookies may allow Google to recognise your browser across websites. Where these components are used, non-essential cookies are only set after you have given your consent through our cookie consent banner, and you may withdraw that consent at any time through your cookie preferences.

For information about how Google uses data from sites that use its services, and about your choices, including the ability to opt out of personalised advertising, please see https://policies.google.com/technologies/partner-sites and Google's advertising settings at https://adssettings.google.com.

27. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF GOOGLE WORKSPACE

The controller uses Google Workspace (Google Apps for Business) as its email hosting and business productivity service, with email authentication mechanisms. When you contact us by email, or when an enquiry submitted through the contact form is delivered to our inbox, the content of your communication and the associated personal data (such as your name, email address, and contact number) are processed and stored within Google Workspace on our behalf, so that we can receive, review, and respond to your communication.

Google acts as our processor in respect of this service and processes the data in accordance with its data processing terms. The operator within the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Further information is available in Google's Privacy Policy at https://policies.google.com/privacy.

28. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF WEBFLOW

The Platform is built and hosted using Webflow, a website design, content management, and hosting platform operated by Webflow, Inc. Webflow provides the underlying infrastructure that enables us to design, publish, host, and serve the Platform, and it processes the data necessary to deliver the website to your browser, including technical connection data such as your IP address and standard server log information. Where a contact or enquiry form is submitted on the Platform, Webflow processes the form data in order to transmit it to us; such enquiries are routed to our email address at help@nonzero.space.

Webflow acts as our processor in respect of the hosting and form functionality of the Platform. Webflow's infrastructure is served through content delivery and hosting providers, and data may be processed on servers located in the United States. For further information regarding Webflow's data processing practices and security measures, please refer to Webflow's Privacy Policy at https://webflow.com/legal/privacy.

29. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF CLOUDFLARE

The controller uses Cloudflare, a content delivery network and security service operated by Cloudflare, Inc. Cloudflare sits between your browser and our hosting infrastructure in order to accelerate the delivery of content, to balance load, and to protect the Platform against malicious traffic, such as denial-of-service attacks. For these purposes, Cloudflare processes technical connection data, including your IP address, the pages requested, and information about your browser and device, and it may set technical cookies that are strictly necessary to identify trusted web traffic and to secure the Platform.

Cloudflare acts as our processor in respect of these services and processes data through its globally distributed network. For further information regarding Cloudflare's data processing practices, please refer to Cloudflare's Privacy Policy at https://www.cloudflare.com/privacypolicy/.

30. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF AMAZON WEB SERVICES

The Platform makes use of Amazon Web Services (AWS), including Amazon CloudFront (a content delivery network) and AWS Lambda (a serverless compute service), provided by Amazon Web Services, Inc. and its affiliates. Amazon CloudFront caches and delivers content from servers located close to the visitor in order to reduce latency and improve performance, and AWS Lambda executes back-end functions that support the operation of the Platform. In providing these services, AWS processes technical connection data, including your IP address and standard request and log data, which is necessary to route and deliver content and to operate the relevant functions. Some of this processing may take place on servers located in the United States.

AWS acts as our processor in respect of these services. For further information regarding AWS's data processing practices and security measures, please refer to the AWS Privacy Notice at https://aws.amazon.com/privacy/.

31. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF FASTLY

The Platform is delivered in part through Fastly, an edge cloud and content delivery network operated by Fastly, Inc., which is used by our hosting provider to serve and load-balance content efficiently. Fastly caches content at edge locations and routes requests to the appropriate server in order to improve the speed, reliability, and availability of the Platform. For these purposes, Fastly processes technical connection data, including your IP address and standard request and log information, which is necessary to deliver the requested content to your browser.

Fastly acts as a processor in respect of the delivery of the Platform. For further information regarding Fastly's data processing practices, please refer to Fastly's Privacy Policy at https://www.fastly.com/privacy/.

32. DATA PROTECTION PROVISIONS ABOUT THE APPLICATION AND USE OF JSDELIVR

The Platform loads certain JavaScript libraries and related resources from jsDelivr, a free, open-source content delivery network. When a page of our Platform is loaded, your browser may retrieve these resources directly from the jsDelivr network in order to display and operate the content correctly. For this technical purpose, your browser must establish a connection to the jsDelivr servers, and in doing so, the operator of the network may become aware of your IP address and the fact that our Platform has been accessed through your device. The use of jsDelivr is in the interest of the reliable and efficient delivery of our Platform and constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR.

Further information regarding jsDelivr and its handling of data is available at https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net.

33. DATA PROTECTION PROVISIONS ABOUT COOKIE CONSENT MANAGEMENT

The Platform uses a cookie consent management tool in order to obtain, record, and manage your consent to the use of non-essential cookies and similar technologies, and to enable you to review and change your preferences at any time. In order to function, the consent tool stores information about the choices you make (for example, whether you have accepted or declined particular categories of cookies) so that your preferences can be respected on subsequent visits. This processing is necessary to comply with our legal obligations relating to consent and to give effect to your choices.

Details of the specific cookies set by the consent management tool, together with all other cookies used on the Platform, are set out in our separate Cookie Policy.

34. GRIEVANCE REDRESSAL AND CONTACT

If you have any questions, concerns, or complaints regarding this Privacy Policy or the manner in which we process your personal data, or if you wish to exercise any of your rights, you may contact us at:

Non Zero Design LLP

Email (privacy and data protection queries): help@nonzero.space

We will endeavour to respond to your request within a reasonable time and in accordance with applicable law. If you are located in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection supervisory authority. If the DPDP Act applies to you and your grievance is not satisfactorily resolved, you may approach the Data Protection Board of India.

35. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time in order to reflect changes to our practices, the services and service providers we use, or applicable law. When we make changes, we will revise the "Last Updated" date at the top of this Privacy Policy, and, where the changes are significant, we may provide additional notice. We encourage you to review this Privacy Policy periodically to stay informed about how we process personal data.

36. GOVERNING LAW AND JURISDICTION

This Privacy Policy and any matter relating to the processing of personal data by Non Zero shall be governed by the laws of India. Subject to any mandatory rights that you may have under the data protection laws of your country of residence, the courts at New Delhi, India, shall have jurisdiction over any dispute arising out of or in connection with this Privacy Policy. Nothing in this clause limits any right you may have to bring a complaint before a competent data protection supervisory authority.