Legal
Privacy
policy.
01Who we are
Zorqly, Inc. (“Zorqly”, “we”, “us”) provides IT services, software development and AI agentic systems. This policy explains what we do with personal data.
It covers two different situations, and the distinction matters:
- This website. Here we are the controller — we decide what is collected and why.
- Client engagements. When we build or operate systems for a client, that client is the controller and we act as a processor on their written instructions. What we may do with their data is set by the engagement contract and its data processing terms, not by this page.
Registered address: [confirm: registered office address].
02What we collect
From this website, only what you hand us:
| Data | Where it comes from | Why |
|---|---|---|
| Name, work email, company | The contact form | To answer your enquiry |
| Service interest and your message | The contact form | To understand what you need and scope it |
| IP address, user agent, request time | Automatic server logs at our host | Security, abuse prevention and diagnostics |
We do not run advertising trackers, analytics scripts or profiling on this site, and we do not buy contact lists.
We do not ask for special category data (health, biometrics, political or religious views) through this website. Please do not put it in the message box.
03Why we are allowed to use it
Under the GDPR and comparable regimes our lawful bases are:
- Legitimate interests — replying to a business enquiry you sent us, and keeping our site secure. You can object at any time.
- Performance of a contract — administering an engagement once you become a client.
- Legal obligation — tax, accounting and records we are required to keep.
- Consent — where we ask for it explicitly. You can withdraw it at any time without affecting what came before.
04AI agents and your data
This is the part most people want to read, so we will be direct about it.
- Enquiries sent through this website are not used to train any AI model, ours or a third party’s.
- In client engagements, every agent is given a scoped, least-privilege connection to specific systems. Scope is agreed in writing before anything is connected.
- Where an engagement involves a third-party model provider, that provider is named in the contract, is bound by a data processing agreement, and is configured so customer content is not used for model training where the provider offers that setting.
- Actions taken by agents are logged — what ran, on what input, and what changed — and those logs belong to the client.
- Actions that are irreversible or that exceed agreed thresholds require human approval by design.
If an agent we operate for you would touch personal data, that is scoped, documented and approved before go-live — not discovered afterwards.
05Who else sees it
We share personal data only with service providers who help us operate, each under contract and only for the purpose named:
| Provider | Purpose | Where |
|---|---|---|
| Vercel Inc. | Website hosting and request logs | United States / global edge |
| Google LLC | Serving the web fonts this site uses | Global |
| Email relay provider | Delivering contact-form enquiries to our inbox | United States |
We also disclose data where the law requires it, or to establish or defend legal claims. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
06International transfers
Our hosting and email providers operate in the United States and elsewhere, so data may be transferred outside your country. Where data leaves the UK or EEA, transfers rely on the European Commission’s Standard Contractual Clauses, the UK Addendum, or an adequacy decision, as applicable.
For client engagements, data residency is agreed in the contract. If you need processing kept in a specific jurisdiction, tell us during scoping — it is a design decision, not a switch we can flip afterwards.
07How long we keep it
| Record | Retention |
|---|---|
| Enquiry that does not become an engagement | 24 months from last contact, then deleted |
| Client records and correspondence | Term of the engagement, then 6 years for contractual and tax purposes |
| Server and security logs | Typically 30 days |
Where we act as a processor, retention follows the client’s instructions and their contract with us.
08Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, or withdraw consent.
Write to info@zorqly.com and we will respond within one month. We may ask you to confirm your identity first. You will not be charged, and asking will never affect how we treat you.
If you are unhappy with our response you can complain to your data protection authority — in the UK the Information Commissioner’s Office, in the EU your national supervisory authority, and [confirm: the supervisory authority for the company’s home jurisdiction].
09Security
We keep access to personal data on a need-to-know basis, protect accounts with multi-factor authentication, encrypt data in transit, and review access on a schedule. Our practices are described in more detail on our security page.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant regulator within the timeframes the law sets.
10Children
This site and our services are meant for businesses. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us data, write to us and we will delete it.
11Changes to this policy
If we change this policy we will update the date at the top of this page. Material changes affecting how we use data you already gave us will be notified directly where we hold a contact address for you.
This version is dated 9 September 2026.
12Contact us
Questions about this policy, or about a request under it: info@zorqly.com.
Postal address: [confirm: registered office address]. Data protection contact: [confirm: named DPO or responsible person, if one is appointed].