1. About This Policy
Zest Web Solutions (“Zest”, “we”, “us”, or “our”) is committed to respecting your privacy and protecting personal data collected through our website at zestwebsolutions.com (the “Website”), through our technical discovery interactions, consultation forms, project workflows, and direct communications.
This Privacy Policy outlines how we collect, process, maintain, disclose, and safeguard personal information in accordance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 (“DPDPA 2023”), the Digital Personal Data Protection Rules, 2025, and applicable privacy regulations in the jurisdictions where our international clients and website visitors reside (including the European Union General Data Protection Regulation (“GDPR”) and UK GDPR where lawfully applicable).
2. Data Fiduciary / Controller Identity
For the purposes of applicable data protection legislation, the Data Fiduciary (or Data Controller) is:
Zest Web Solutions
Operating Location: Ahmedabad, Gujarat, India
Privacy Officer / Legal Contact: info@zestwebsolutions.com
3. Categories of Information We May Collect
We collect only the personal information reasonably necessary to conduct our business, respond to inquiries, evaluate project requirements, deliver contracted digital engineering services, and maintain website security. Not all of the following data categories are collected from every visitor:
- Contact & Identification Data: Full name, professional email address, telephone number, business name, and job title when voluntarily submitted via contact forms, discovery booking widgets, or email inquiries;
- Business & Project Data: Store URL, website URL, platform requirements (e.g., Shopify, WordPress), technical stack specifications, project scope briefs, budget ranges, and RFP documents;
- Technical & Connection Data: Internet Protocol (IP) address, operating system, browser type and version, device category, screen resolution, referral source, and timestamps;
- Usage & Interaction Data: Pages visited, navigation paths, dwell time, scroll depth, resource downloads (e.g., whitepapers, framework guides), and button click events;
- Credentials & Access Data: Where contracted for technical development, temporary collaborator invitations, staging logins, or API credentials provided securely by clients under NDA.
4. How We Collect Personal Data
We collect personal information through several lawful channels:
- Direct Interactions: When you fill out contact forms, book a discovery consultation via our scheduling widget, request an SEO audit, download engineering playbooks, or correspond with our team via email, chat, or phone;
- Contractual Engagements: When entering into an Agency Partnership agreement, signing a Statement of Work, or providing technical brief documentation;
- Automated Technologies: As you navigate through our Website, automated logging mechanisms, performance analytics scripts, and essential cookies collect technical metadata about your equipment and browsing patterns.
5. Purposes for Which We Process Data
We process personal information solely for legitimate, transparent commercial purposes, including:
- Evaluating project requirements, providing quotations, and conducting technical discovery sessions;
- Executing contracted engineering, theme development, technical SEO, and white-label development services;
- Managing client accounts, billing, invoicing, milestone approvals, and administrative communications;
- Operating, monitoring, securing, and optimizing the performance and Core Web Vitals of our Website;
- Analyzing website usage trends, user journeys, and engagement to improve our technical resources and documentation;
- Sending transactional notices, contract updates, or relevant technical industry updates where legally permitted and consented to;
- Enforcing our legal agreements, Terms & Conditions, and defending against legal claims or security breaches;
- Complying with statutory accounting, tax, regulatory, and law enforcement requirements under applicable Indian law.
6. Lawful Grounds for Processing
Under the DPDPA 2023, DPDPA Rules 2025, and relevant global data protection laws, we process personal data under one or more of the following lawful bases:
- Consent: Where you have provided clear, affirmative consent for a specified purpose (e.g., submitting an inquiry form or opting in to receive our technical engineering dispatch);
- Performance of a Contract: Where processing is necessary to take steps at your request prior to entering into a contract or to perform our obligations under an executed SOW or partnership agreement;
- Legitimate Uses / Legitimate Interests: Where processing is necessary for specified legitimate business uses recognized under applicable law, such as fraud prevention, cybersecurity, responding to voluntary inquiries, and internal management;
- Legal Compliance: Where processing is required to comply with statutory obligations under Indian or applicable foreign law.
7. Technologies and Analytics Deployed
To ensure high performance, security, and accurate measurement, our Website utilizes standard, industry-grade third-party technologies:
- Google Tag Manager & Google Analytics 4 (GA4): We utilize GA4 to analyze aggregated, anonymized visitor behavior, traffic sources, and page performance. IP anonymization features are utilized where available;
- Microsoft Clarity & Behavioral Insights: May be utilized to generate heatmaps and session metrics to diagnose UI friction and optimize user experience;
- Calendly / Consultation Scheduling: Embedded or popup widgets to allow prospective clients and agency partners to schedule technical discovery calls;
- Hosting & Content Delivery Network (CDN): Server infrastructure and edge CDN networks (e.g., Cloudflare, Vercel) maintain access logs containing IP addresses and request headers for security, caching, and DDoS mitigation.
8. Cookies and Similar Technologies
Cookies are small text files placed on your device by websites that you visit. Our website uses cookies and similar storage technologies categorized as follows:
- Strictly Necessary Technologies: Required for the essential operation of the Website, load balancing, security validation, and session management;
- Performance & Analytics Cookies: Allow us to recognize and count the number of visitors and see how visitors move around the site when using it;
- Functionality & Preference Cookies: Used to recognize repeat visits and retain basic preferences.
You can manage, restrict, or disable cookies through your browser settings at any time. Please note that disabling certain cookies may affect the visual presentation or interactive functionality of the Website.
9. Data Sharing and Disclosures
Zest Web Solutions does not sell, rent, or trade your personal data to third parties for commercial marketing purposes. We share personal data only with trusted third parties under strict confidentiality and security safeguards:
- Technical Service Providers: Cloud hosting infrastructure, edge network providers, database management services, and email delivery platforms;
- Analytics & Productivity Tools: Analytics processors, project management platforms (e.g., Jira, ClickUp, Slack), and consultation scheduling software;
- Professional Advisers: Legal counsel, chartered accountants, auditors, and financial advisers bound by professional confidentiality obligations;
- Legal & Regulatory Authorities: Where disclosure is strictly required by law, court order, governmental inquiry, or to protect the vital interests, rights, and property of Zest, our clients, or the public.
10. International Data Transfers
Zest operates from Ahmedabad, Gujarat, India. If you access our Website or engage our services from outside India (such as Australia, the UK, the European Economic Area, the UAE, South Africa, Singapore, or the US), your personal data will be processed in and transferred to India and other countries where our third-party infrastructure providers maintain servers.
We ensure that all cross-border data transfers comply with applicable data protection requirements under DPDPA 2023, DPDPA Rules 2025, and relevant international data transfer frameworks, utilizing standard contractual clauses, technical encryption, and contractual data processing agreements with our service providers.
11. Data Retention
We do not retain personal data longer than is reasonably necessary to fulfill the purposes for which it was collected, including:
- Fulfilling our contractual obligations and maintaining project records under active agreements;
- Complying with statutory accounting, tax, and commercial record-keeping obligations under Indian law (typically up to seven (7) to eight (8) years for financial records);
- Maintaining evidence for legal defense, dispute resolution, and contract enforcement;
- General web inquiry records and technical logs are reviewed periodically and securely purged or anonymized when no longer required.
12. Technical and Organizational Security Measures
We implement commercially reasonable administrative, technical, and physical safeguards designed to protect personal data against accidental, unauthorized, or unlawful access, alteration, disclosure, or destruction. These measures include encrypted SSL/TLS data transmission, role-based access restrictions, firewall protections, two-factor authentication on technical systems, and confidentiality agreements with our in-house engineering staff.
While we maintain rigorous security protocols, no method of transmission over the internet or electronic storage system is completely secure. We cannot guarantee absolute security against all possible unauthorized breaches.
13. User Rights and Choices
Depending on your location and subject to applicable statutory exemptions under the DPDPA 2023, DPDPA Rules 2025, or other applicable privacy legislation, you may have the following rights regarding your personal data:
- Right to Access: The right to request confirmation of whether we process your personal data and to obtain a summary of data processed;
- Right to Correction & Deletion (Erasure): The right to request correction of inaccurate or misleading personal data, completion of incomplete data, or deletion/erasure of personal data that is no longer necessary for the purpose for which it was collected;
- Right to Withdrawal of Consent: The right to withdraw consent previously granted for processing at any time, without affecting the lawfulness of processing conducted prior to withdrawal;
- Right to Grievance Redressal: The right to readily available means of grievance redressal regarding data handling and resolution of privacy complaints;
- Right to Nominate: (Under DPDPA 2023) The right to nominate an individual who, in the event of death or incapacity, may exercise data rights on your behalf;
- Right to Object & Restriction: (Where GDPR applies) The right to object to processing based on legitimate interests, direct marketing, or request restriction of processing under specified legal grounds;
- Right to Data Portability: (Where applicable by law) The right to receive your personal data in a structured, commonly used, and machine-readable format.
14. Exercising Your Data Rights
To exercise any of your statutory data rights, please submit a written request to our Privacy Officer at info@zestwebsolutions.com. We will verify your identity before processing your request and respond within the timeframe mandated by applicable law (or within thirty (30) days where no specific statutory timeline applies).
15. Grievance Redressal Mechanism
In accordance with the Digital Personal Data Protection Act, 2023 and the DPDPA Rules, 2025, Zest Web Solutions maintains a dedicated grievance redressal procedure. If you have any concern, complaint, or grievance regarding our processing of your personal data:
Grievance Officer: Privacy & Compliance Lead
Entity: Zest Web Solutions, Ahmedabad, Gujarat, India
Email: info@zestwebsolutions.com
Response Commitment: We aim to acknowledge grievances within forty-eight (48) hours and resolve them within the prescribed statutory period.
16. International Data Subjects (EU, UK, US, AU, UAE, ZA, SGT)
Where you are located in the European Union, United Kingdom, Australia, United Arab Emirates, South Africa, Singapore, or the United States, we process your information in compliance with the principles of transparency, purpose limitation, data minimization, accuracy, and storage limitation. Where applicable law provides you the right to lodge a complaint with your local data protection supervisory authority, you may also do so.
17. Children’s Privacy
Our Website and services are designed exclusively for business enterprises, agency partners, and professional audiences. We do not knowingly solicit, collect, or process personal data from individuals under eighteen (18) years of age. If we become aware that we have inadvertently collected personal data of a minor without verifiable parental or guardian consent, we will promptly take steps to delete such data from our servers.
18. Third-Party Links and External Services
Our Website contains links to external websites, third-party case study platforms (e.g., Clutch.co), and social media profiles (LinkedIn, X/Twitter, Facebook, Instagram). We do not control and are not responsible for the privacy practices, cookie policies, or content of third-party platforms. We encourage you to review the privacy policies of any third-party websites you visit.
19. Updates to This Privacy Policy
We may update or revise this Privacy Policy periodically to reflect changes in our data processing practices, service offerings, or statutory legal requirements. Any modifications will be posted on this page with an updated “Last Updated” date. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal information.
20. Contact Information and Privacy Officer
If you have questions, comments, or requests regarding this Privacy Policy or our data handling practices, please reach out to:
Zest Web Solutions
Operating Location: Ahmedabad, Gujarat, India
Official Privacy & Data Protection Email: info@zestwebsolutions.com
General Inquiries: Contact Us