Privacy Policy

How Zen Automation collects, uses, and protects your data

Last Updated: January 1, 2024

1. Introduction

Zen Automation, LLC, a computer systems design and related services company, is committed to protecting the privacy of individuals who interact with our website at https://www.zenautomation.buzz and use our professional services. This Privacy Policy explains in detail how we collect, store, use, share, and safeguard your personal information when you visit our website, contact us, engage our systems design and automation services, or otherwise interact with Zen Automation.

We have designed this policy to comply with applicable data protection laws including the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR) where applicable, and other relevant United States federal and state privacy regulations. By accessing our website or using our services, you acknowledge that you have read and understood the practices described in this Privacy Policy. If you do not agree with any part of this policy, you should discontinue use of our website and services immediately.

Zen Automation acts as a data controller for the personal information we collect directly from you. For certain enterprise engagements where we process data on behalf of our clients, we act as a data processor and follow the data processing agreements established with those clients. This distinction is important because your rights and our obligations may vary depending on our role with respect to specific data processing activities.

2. Information We Collect

We collect several categories of information to provide and improve our computer systems design and automation services. The types of information we gather depend on how you interact with us and which services you use.

2.1 Personal Information You Provide Directly

When you contact us via email at care@zenautomation.buzz, call us at +1 (743) 649-6356, submit a contact form on our website, or engage our professional services, we may collect the following categories of personal information:

  • Contact Information: Your full name, email address, phone number, company name, job title, and mailing address including the information you provide to our office at 2758 E 3530 S, St George, Utah 84790-7964, United States.
  • Business Information: Details about your organization, its size, technical infrastructure, existing systems architecture, technology stack, business requirements, project scope, and objectives for which you seek our services.
  • Communications Data: The content of your messages to us, including emails, phone call records, meeting notes, project specifications, technical documentation, support tickets, and any attachments you share during the course of our engagement.
  • Financial Information: Billing details, payment method information, invoicing records, purchase orders, and transaction history related to the services you purchase from Zen Automation. Payment card information is processed exclusively through our PCI-compliant third-party payment processors and is never stored on our own systems.
  • Professional Data: Curriculum vitae, professional certifications, security clearances, and other credentials if you apply for a position with Zen Automation or seek to join our network of technology partners and contractors.

2.2 Information Collected Automatically

When you visit our website, certain information is collected automatically through standard web technologies. This information helps us understand how our website is used, improve its performance, and maintain security. The automatically collected data includes:

  • Technical Data: Your Internet Protocol (IP) address, browser type and version, operating system, device type, screen resolution, time zone setting, browser plug-in types and versions, and the capabilities of the device and software through which you access our website.
  • Usage Data: Information about how you interact with our website including the pages you visit, the time and date of your visit, time spent on each page, links you click, scroll depth, mouse movements, and the referring website or search engine that directed you to us.
  • Server Logs: Our web servers automatically record requests including the requesting IP address, timestamp, HTTP method, URL requested, HTTP status code, response size, and user agent string. These logs are essential for diagnosing technical issues and detecting security threats.
  • Analytics Information: Aggregated statistical data about website traffic patterns, user navigation paths, and conversion metrics. We use privacy-respecting analytics tools that anonymize IP addresses and do not track users across unrelated websites.

2.3 Information from Third Parties

In the course of business, we may receive information about you from third-party sources including technology partners, integration platforms you have authorized, publicly available business databases, professional networking platforms, and service providers that assist with identity verification, fraud prevention, and credit assessment for enterprise engagements. We treat all such data consistent with this Privacy Policy and the contractual obligations we have with those third parties.

3. How We Use Your Information

Zen Automation uses the collected information for legitimate business purposes directly related to the provision of our computer systems design, automation engineering, and related professional services. Each use falls under one of the lawful bases recognized by applicable data protection law: contractual necessity, legitimate interest, legal obligation, or consent.

3.1 Primary Business Purposes

  • Service Delivery: To provide, operate, maintain, and improve our systems design, automation engineering, cloud infrastructure, API integration, and cybersecurity consulting services. This includes project planning, technical architecture design, software development, quality assurance testing, deployment, monitoring, and ongoing support and maintenance of delivered systems.
  • Client Communication: To respond to your inquiries, send service-related announcements, provide project status updates, deliver technical documentation, schedule meetings, and manage the ongoing business relationship with you and your organization.
  • Contractual Performance: To fulfill our obligations under the agreements we have entered into with you, including processing payments, issuing invoices, managing project scope, enforcing terms of service, and exercising our rights under applicable contracts.
  • Business Operations: To manage internal business processes such as accounting, auditing, resource allocation, project portfolio management, financial reporting, compliance monitoring, and legal risk assessment.

3.2 Secondary and Ancillary Purposes

  • Website Improvement: To analyze how visitors use our website, identify technical issues, optimize page load performance, improve navigation structure, test new features, and enhance the overall user experience of our online presence.
  • Security and Fraud Prevention: To protect the security and integrity of our website, systems, networks, and data against unauthorized access, cyberattacks, malware, fraud, and other malicious activities. This includes real-time traffic monitoring, automated threat detection, incident response procedures, and forensic analysis when necessary.
  • Marketing Communications: With your explicit consent where required by law, we may send you information about new services, technology insights, case studies, white papers, event invitations, and other content we believe may be relevant to your interests. You may opt out of marketing communications at any time by following the unsubscribe instructions in each message or by contacting us directly.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and enforceable governmental requests, as well as to establish, exercise, or defend legal claims and protect the rights, property, and safety of Zen Automation, our clients, and the public.
  • Research and Development: To conduct internal research, develop new services and methodologies, improve existing offerings, train machine learning models on anonymized datasets, and advance the state of the art in computer systems design and automation engineering.

3.3 Lawful Basis for Processing

For individuals located in the European Economic Area (EEA), the United Kingdom, or other jurisdictions requiring a lawful basis for personal data processing, we rely on the following legal grounds: (a) processing necessary for the performance of a contract with you or to take pre-contractual steps at your request; (b) processing necessary for our legitimate business interests, provided those interests are not overridden by your data protection rights; (c) your consent, which you may withdraw at any time; and (d) compliance with legal obligations to which Zen Automation is subject.

4. Sharing and Disclosure of Information

Zen Automation does not sell, rent, or trade your personal information to third parties for their own marketing purposes. We share information only in the limited circumstances described below and always under appropriate contractual safeguards.

  • Service Providers and Subprocessors: We engage carefully selected third-party companies and individuals to perform functions on our behalf, including cloud hosting providers, payment processors, customer relationship management platforms, communication tools, analytics services, email delivery services, project management software, and security monitoring tools. These service providers are contractually bound to process data only on our documented instructions and to implement technical and organizational measures at least as protective as those described in this policy.
  • Professional Advisors: We may share information with our legal counsel, accountants, auditors, and other professional advisors who require access to such information to provide their services to Zen Automation and who are bound by statutory or contractual confidentiality obligations.
  • Business Transfers: In connection with a merger, acquisition, reorganization, sale of assets, bankruptcy, or similar corporate transaction, your information may be disclosed to prospective or actual acquirers, successors, or assigns as part of the due diligence process and transferred as a business asset. We will require the receiving party to continue honoring this Privacy Policy or to provide notice and choice before applying materially different privacy practices.
  • Legal Requirements: We may disclose information if we determine in good faith that disclosure is reasonably necessary to comply with any applicable law, regulation, legal process, or enforceable governmental request; to enforce our Terms of Service or other agreements; to detect, prevent, or address fraud, security, or technical issues; or to protect against harm to the rights, property, or safety of Zen Automation, our clients, employees, or the public as required or permitted by law.
  • With Your Consent: We may share your information for any other purpose with your prior explicit consent, including integration with third-party services you have authorized us to connect with your systems and environments.

5. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. The specific retention period depends on the nature of the information and the context in which it was collected.

  • Client Engagement Records: Information related to active client engagements is retained for the duration of the engagement plus a period of seven years after the engagement concludes, to comply with tax, accounting, and legal obligations and to defend against potential claims.
  • Communications: Email correspondence and other communications are retained for a period of four years from the date of the last communication, unless a longer period is required for legal or regulatory reasons.
  • Website Usage Data: Automatically collected analytics data is retained in identified form for up to twenty-six months and may be retained in aggregated, anonymized form indefinitely for research and analytical purposes.
  • Server Logs: Web server access logs are retained for a rolling period of ninety days for security and diagnostic purposes, after which they are automatically purged.
  • Marketing Data: Information used for marketing purposes is retained until you withdraw your consent or opt out of receiving marketing communications, after which it is removed from active marketing lists within thirty days.

When the applicable retention period expires, we either securely delete or fully anonymize the personal information so that it can no longer be associated with an identifiable individual. Deletion may be accomplished through secure erasure protocols, cryptographic shredding, or physical destruction of storage media, depending on the storage medium and the sensitivity of the data.

6. Security Measures

Zen Automation implements and maintains a comprehensive suite of administrative, technical, and physical security controls designed to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. As a computer systems design company, security engineering is a core competency and we apply the same rigorous standards to our own infrastructure that we recommend to our enterprise clients.

  • Encryption: All data transmitted between your browser and our servers is protected using Transport Layer Security (TLS) with strong cipher suites and perfect forward secrecy. Data at rest is encrypted using AES-256. Backups are encrypted with separate key material and stored in geographically distributed locations.
  • Access Control: We enforce the principle of least privilege across all systems. Access to personal information is restricted to authorized personnel on a need-to-know basis, authenticated through multi-factor authentication (MFA), and governed by role-based access control policies. All access events are logged and periodically reviewed.
  • Network Security: Our infrastructure is protected by next-generation firewalls, intrusion detection and prevention systems (IDS/IPS), DDoS mitigation services, web application firewalls (WAF), and continuous network traffic analysis for anomalous behavior patterns.
  • Application Security: We follow secure software development lifecycle (SDLC) practices including threat modeling, static and dynamic application security testing (SAST/DAST), regular penetration testing by independent third-party security firms, dependency vulnerability scanning, and secure code review for all systems that process personal data.
  • Organizational Measures: All employees and contractors receive mandatory data protection and security awareness training upon onboarding and annually thereafter. We maintain an incident response plan tested through regular tabletop exercises, and we carry cyber insurance covering data breach response and notification costs.
  • Physical Security: Our office at 2758 E 3530 S, St George, Utah 84790-7964 and all data center facilities where our infrastructure resides employ access control systems, video surveillance, environmental monitoring, and around-the-clock security personnel where applicable.

Despite these measures, no method of transmission over the Internet or electronic storage is one hundred percent secure. While we strive to protect your personal information using commercially reasonable means, we cannot guarantee its absolute security. In the event of a data breach that affects your personal information, we will notify you and applicable regulatory authorities without undue delay in accordance with legal requirements.

7. Your Privacy Rights

Depending on your jurisdiction of residence, you may have certain rights regarding the personal information we hold about you. Zen Automation is committed to honoring these rights in accordance with applicable law.

  • Right to Access: You may request a copy of the personal information we hold about you, along with details about how we process it, the categories of recipients, and the retention period. We will provide this information in a structured, commonly used, machine-readable format within the timeframes required by law, typically thirty to forty-five days depending on the jurisdiction.
  • Right to Rectification: If you believe the personal information we hold about you is inaccurate or incomplete, you have the right to request that we correct or update it. We will respond to such requests within a reasonable timeframe, usually within thirty days.
  • Right to Erasure: In certain circumstances, you may request that we delete your personal information. This right is not absolute and we may need to retain certain information where there is a compelling legitimate interest or legal obligation to do so, such as compliance with tax laws, defense of legal claims, or ongoing contractual obligations.
  • Right to Restrict Processing: You may request that we limit the processing of your personal information in specific situations, such as when you contest the accuracy of the data or object to our processing while your objection is being verified.
  • Right to Data Portability: Where processing is based on consent or a contract and carried out by automated means, you may request that we provide your personal information to you or directly to another controller in a portable, machine-readable format.
  • Right to Object: You may object to the processing of your personal information for direct marketing purposes at any time, and we will cease such processing immediately upon receiving your objection. You may also object to processing based on our legitimate interests, and we will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
  • Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights. This means we will not deny you services, charge different prices, or provide a different level of service because you chose to exercise your rights under applicable privacy law.

To exercise any of these rights, please contact us using the details provided in Section 13 (Contact Us) of this Privacy Policy. We may need to verify your identity before processing your request, which may involve asking you to confirm specific information we already hold. You may also designate an authorized agent to submit requests on your behalf, provided the agent presents written authorization from you and their own identity verification.

8. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and understand where our visitors come from. This section explains what cookies are, which types we use, and how you can control them.

8.1 What Are Cookies

Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work efficiently and to provide information to website operators. Cookies may be first-party cookies, set by the website you are visiting, or third-party cookies, set by a domain other than the one you are visiting. Cookies can be session cookies, which are deleted when you close your browser, or persistent cookies, which remain on your device for a set expiration period.

8.2 Types of Cookies We Use

  • Essential Cookies: These cookies are strictly necessary for the operation of our website. They enable core functionality such as security, network management, and accessibility. Without these cookies, the website cannot function properly. Our website does not require cookie consent for essential cookies as they are exempt under most privacy regulations.
  • Performance and Analytics Cookies: These cookies collect information about how visitors use our website, such as which pages are visited most often and whether users encounter error messages. The information collected is aggregated and anonymized. We use this data to improve how our website works and to measure the effectiveness of our content.
  • Functional Cookies: These cookies allow our website to remember choices you make, such as your preferred language or region, and provide enhanced, more personalized features. They may be set by us or by third-party providers whose services we have added to our pages.

8.3 Managing Cookies

Most web browsers allow you to control cookies through their settings preferences. You can typically configure your browser to block all cookies, accept only first-party cookies, or delete cookies when you close your browser. Please note that disabling certain types of cookies may impact the functionality of our website and degrade your user experience. To learn more about managing cookies, visit the help documentation of your specific browser: Google Chrome, Mozilla Firefox, Apple Safari, or Microsoft Edge.

9. International Data Transfers

Zen Automation is headquartered in the United States at 2758 E 3530 S, St George, Utah 84790-7964. Our primary data processing activities occur on infrastructure located within the United States. If you are located outside the United States and choose to provide information to us, your data will be transferred to, stored, and processed in the United States, which may have data protection laws that differ from those in your country of residence.

When we transfer personal information from the European Economic Area, the United Kingdom, or other jurisdictions with data transfer restrictions to the United States or other countries, we implement appropriate safeguards in accordance with applicable data protection law. These safeguards may include the use of European Commission-approved Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, binding corporate rules for intra-group transfers, and assessments of the laws and practices of the destination country. We also apply supplementary technical and organizational measures where necessary to ensure an equivalent level of protection for transferred data.

By using our website and services, you understand that your information may be transferred to our facilities and those third parties with whom we share it as described in this Privacy Policy.

10. Childrens Privacy

Our website and services are designed for businesses and professionals and are not intended for use by individuals under the age of eighteen. We do not knowingly collect, solicit, or process personal information from children under sixteen years of age. No part of our website, including its content and functionality, is directed to or structured to attract children.

If we become aware that a child under the relevant age threshold has provided us with personal information without verified parental consent, we will take immediate steps to delete such information from our systems. If you are a parent or guardian and you believe that your child has provided us with personal information, please contact us using the details in Section 13 so that we can take corrective action promptly.

11. Third-Party Services and Links

Our website may contain links to third-party websites, platforms, services, and resources that are not owned or controlled by Zen Automation. This Privacy Policy applies solely to information collected by Zen Automation through our own website and services. We are not responsible for the privacy practices, content, or security of third-party websites and services.

When you click on a link that directs you to a third-party website, we encourage you to review that websites privacy policy and terms of service before providing any personal information. The inclusion of a link on our website does not constitute an endorsement of the linked website or its privacy practices. You access third-party websites entirely at your own risk.

If you authorize us to integrate with third-party services such as cloud platforms, version control systems, continuous integration tools, monitoring services, or communication platforms as part of a client engagement, the handling of your data by those third parties is governed by their respective privacy policies and the terms of the specific integration agreements we maintain with them.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal obligations, or the services we offer. When we make material changes to this policy, we will post the updated version on this page and update the Last Updated date at the top of the page. For significant changes that substantially affect your rights or the way we handle your personal information, we will take additional steps to notify you, which may include sending an email to the address we have on file for you, posting a prominent notice on our website, or requesting your renewed consent where required by law.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our website and services after we post any modifications to this policy constitutes your acknowledgment of the changes and your consent to abide by the updated Privacy Policy. If you disagree with any change, you should discontinue use of our website and contact us to discuss the handling of your existing data.

13. Contact Us

If you have any questions, concerns, comments, or requests regarding this Privacy Policy or our privacy practices, please contact Zen Automation through any of the following channels. We are committed to addressing your inquiries promptly and thoroughly.

  • Email: care@zenautomation.buzz (for privacy-related inquiries, please include Privacy Concern in the subject line)
  • Phone: +1 (743) 649-6356 (available during business hours, Mountain Time, Monday through Friday)
  • Mail: Zen Automation, LLC, 2758 E 3530 S, St George, Utah 84790-7964, United States
  • Website: https://www.zenautomation.buzz

We will acknowledge receipt of your inquiry within five business days and aim to provide a substantive response within thirty days. If your concern relates to data protection and you are located in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to lodge a complaint with your local supervisory authority or data protection regulator, though we encourage you to contact us first so that we have an opportunity to address your concern directly.

For formal legal notices or service of process, please use the mailing address listed above and direct correspondence to the attention of the Legal Department. Any communication sent to Zen Automation should reference the appropriate matter or department to ensure prompt routing and handling.