The responsible legal entity or entities, privacy contact, confirmed lawful bases, retention schedule, hosting and email providers, international-transfer safeguards, and relevant supervisory authority must be confirmed by Zerp Labs. This draft does not guess those details.
1. Introduction
This Privacy Policy explains how personal information is handled when you visit the Zerp Labs website, contact the team about a project or service, or request access to a case study. It should be read together with any additional privacy information shown at the point where information is collected.
2. Who we are
The website presents the services of Zerp Labs and describes its relationship with Zirius AS. The site also lists Zerp Labs India Pvt. Ltd. and Zirius AS office locations.
Business confirmation required: the legal entity or entities acting as controller for website visitors, contact enquiries, and case-study requests have not been confirmed. Those details, including the correct privacy contact, must be added before this policy is published as final.
3. Information we collect
Depending on how you use the website, we may collect:
- your full name;
- your business or company name;
- your work email address;
- a project summary and information you voluntarily enter in message fields;
- the case study you request or access; and
- technical request and security information, which may include an IP address, browser and device information, request headers, timestamps, referring page, and server or security logs where those records are generated.
Please do not include unnecessary sensitive personal information in free-text fields.
4. Contact enquiries
When you submit the Contact Us form, the name, work email address, and project summary you provide are used to assess and respond to your enquiry and to communicate with you about the project or service you requested. The information is not collected through that form for newsletter or promotional subscription purposes.
5. Case-study requests
When you request access to a case study, the form collects your company name and email address. These details are used to provide access to the requested case study and to operate and secure that request flow. They are not used to subscribe you to marketing through the current form.
6. How personal information is used
Personal information may be used to:
- respond to enquiries and communicate about requested projects or services;
- provide access to requested case-study information;
- operate, maintain, troubleshoot, and secure the website and forms;
- detect spam, fraud, misuse, or automated submissions;
- keep appropriate business records; and
- comply with legal obligations or establish, exercise, or defend legal claims where applicable.
7. Lawful basis for processing
Where the GDPR, UK GDPR, or similar law applies, the lawful basis depends on the purpose and circumstances. For a person-initiated business enquiry, processing may be necessary to take steps requested before entering a contract and/or may be based on legitimate business interests in responding to the enquiry, operating the service, and protecting the website. Any reliance on legitimate interests must be assessed against the individual's rights and interests.
Consent is used only where the activity genuinely requires consent. Reading this policy or submitting an ordinary business enquiry is not presented as consent to marketing.
Business confirmation required: the responsible business must document and approve the lawful basis used for each processing purpose before publication.
8. Contact Form 7
The website uses Contact Form 7 to operate the Contact Us and case-study forms. Submitted form fields are processed so the request can be delivered and handled. Whether submissions are also stored in the WordPress database, copied to a secondary mailbox, included in email logs, or sent to another integration depends on the site's administrative configuration.
Business confirmation required: confirm the To, From, Reply-To, Mail (2), Additional Settings, remote-IP mail-tags, storage, logging, webhook, CRM, and email-delivery configuration for forms 1601 and 1588.
9. Cloudflare Turnstile
The website uses Cloudflare Turnstile on its forms to distinguish legitimate visitors from automated traffic and reduce spam or abuse. Turnstile processes browser, device, network, and interaction signals needed for this security function. Cloudflare states that Turnstile does not access, store, or transmit form entries or other page inputs.
Cloudflare's processing is governed by its own terms and privacy policy. Whether Turnstile pre-clearance or a Cloudflare clearance cookie is enabled must be confirmed in the Cloudflare account.
10. Google Maps
The Contact Us page currently embeds Google Maps. Loading that page may connect your browser directly to Google, which can receive technical request information such as your IP address, browser details, and the page requesting the map. Google may use cookies or similar storage according to its configuration and your Google settings.
Google's handling of information is described in the Google Privacy Policy. The map implementation is not used by this website to request your device's precise location.
11. Google Fonts and icons
The website currently loads Plus Jakarta Sans, Noto Sans, Roboto, and Material Symbols from Google-hosted stylesheets. When these resources are requested, Google receives ordinary technical request information, which may include your IP address and browser information. Google's handling of that information is described in its privacy policy.
12. Hosting, CDN, and server logs
The website's hosting, web-server, network, and security infrastructure may create logs needed to deliver pages, diagnose faults, maintain security, and investigate misuse. The live website currently identifies LiteSpeed server software, but that does not identify the hosting provider or establish what logs are retained.
Business confirmation required: identify the hosting/CDN providers, confirm which technical logs are created, who can access them, and how long they are retained.
13. Cookies and similar technologies
A technical audit dated 11 September 2026 did not identify Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, Microsoft Clarity, or Hotjar on the public pages reviewed. The forms use Cloudflare Turnstile, and the Contact Us page embeds Google Maps; those services may use cookies or similar technologies depending on their configuration. No cookie-consent banner was present during the audit.
This description must be reviewed whenever scripts, embeds, analytics, advertising, or consent settings change. Any technology that is not strictly necessary must not be loaded before the required user choice where applicable law requires prior consent.
14. Third-party service providers
The website currently relies on providers that support form delivery, spam prevention, security, embedded maps, externally hosted fonts and icons, hosting, and email delivery. Providers should receive only the information needed to perform their service and should be subject to appropriate contractual and security requirements.
Business confirmation required: confirm the complete provider list, the purpose of each provider, and the applicable processing terms.
15. Who personal information may be shared with
Information may be shared with authorised staff or contractors who need it to respond to a request, with service providers that operate the website, forms, security, or email delivery, and with professional advisers, authorities, or other parties where disclosure is required by law or necessary to protect legal rights. Personal information is not sold through the current website forms.
16. International transfers
Because the website presents organisations and operations in India and Norway and uses international technology providers, personal information may be processed outside the country where it was submitted. The countries involved and the transfer safeguards that apply have not been fully verified.
Business confirmation required: confirm the actual data flows and, where required, the adequacy decision, contractual clauses, or other lawful transfer mechanism relied upon.
17. Data retention
Personal information should be kept only for as long as needed to handle the request, maintain appropriate business and security records, meet legal or accounting obligations, and resolve or defend claims. Different categories may require different retention periods.
Business confirmation required: approve and publish the actual retention periods or the criteria used to determine them, including any WordPress database records, mailboxes, backups, security logs, and third-party systems.
18. Data security
Reasonable technical and organisational measures should be used to protect personal information against unauthorised access, loss, alteration, or disclosure. Current technical measures visible on the website include HTTPS, spam-prevention controls, and Cloudflare Turnstile. No internet transmission or storage system can be guaranteed to be completely secure.
19. Your rights
Depending on the law that applies and the circumstances, you may have rights to:
- request access to your personal information;
- ask for inaccurate or incomplete information to be corrected;
- request deletion of personal information;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive or transfer certain information in a portable format where applicable; and
- withdraw consent at any time where processing genuinely relies on consent, without affecting processing already carried out lawfully.
These rights can be subject to legal conditions and exceptions. To make a request, use the contact details on the Contact Us page until a dedicated privacy contact has been confirmed. Identity may need to be verified before a request is completed.
20. Complaints
If you have a concern about how personal information is handled, please contact the business first so it can investigate. Where applicable, you may also have the right to complain to the data-protection supervisory authority responsible for your location or for the relevant controller.
Business confirmation required: identify the controller and the appropriate lead or local supervisory authority before publication.
21. Changes to this Privacy Policy
This policy may be updated when the website, services, providers, or legal requirements change. The revised version should be posted on this page and the last-updated date changed. Material changes should be brought to users' attention where appropriate.