Legal

Privacy Policy

How CloudZenia collects, uses, and protects the personal data of our clients, partners, and website visitors.

Effective date: August 1, 2026

CloudZenia respects your privacy and is committed to protecting it. This policy explains what personal data we collect, why we collect it, and the choices you have.

1. Who we are

CloudZenia is an AWS Advanced Tier Services Partner. We deliver cloud migration, DevOps, managed services, cloud security, cost optimization, and Generative and Agentic AI engineering.

We operate through three entities, depending on where you’re based:

EntityRegistered addressActs as controller for
CloudZenia Inc.8 The Green, Dover, DE 19901, United StatesClients and visitors in the USA and Canada
CloudZenia (proprietorship, India)Unit 2315, 3rd Floor, B-Block, Ardente Office One, Hoodi Circle, Whitefield, Bengaluru 560048, IndiaClients and visitors in India and the rest of the world
CLOUDZENIA L.L.C-FZMeydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, UAEClients and visitors in the UAE and wider Middle East

Website: cloudzenia.com
Privacy contact: privacy@cloudzenia.com

2. What this policy covers

This policy applies to

Personal data about website visitors, prospects, clients, partners, suppliers, job applicants, and people who receive our communications.

This policy does not apply to

Personal data sitting inside a client’s own systems or AWS accounts, even when we’re accessing those systems to deliver a project. In that case, the client is the one in charge of that data (the “controller”), and we’re just processing it on their behalf, under their service agreement and Data Processing Agreement. If you’re a customer or employee of one of our clients and have questions about your data, that organisation is who you’ll want to reach out to, not us.

3. Data we collect

3.1 Information you give us

  • Contact details — name, job title, company, business email, phone number, country
  • Enquiry details — form submissions, proposal and RFP requests, meeting bookings, project requirements, support requests
  • Marketing details — newsletter sign-ups, event and webinar registrations, whitepaper downloads, communication preferences
  • Client and billing details — contract contacts, purchase orders, billing address, tax registration numbers, bank or payment references
  • Recruitment details — CV, cover letter, work history, education, certifications, references, and right-to-work information if you apply for a role
  • Correspondence — emails, meeting notes, call records, and support tickets

3.2 Information we collect automatically

  • IP address and rough location (city or country level)
  • Browser type and version, device type, operating system, language settings
  • Pages you viewed, time spent, navigation path, downloads, referring site
  • Cookies and similar identifiers (more on this in Section 8)

3.3 Information from other sources

  • Professional networking platforms like LinkedIn
  • Business directories, public company websites, and business intelligence providers
  • Referrals from AWS and other technology partners
  • Event organisers and sponsors

3.4 Data we do not want

Please do not send us sensitive personal data (health information, biometric data, government ID numbers, financial account credentials) through our website forms or general email. We do not need it, and we will delete it if we receive it.

4. Why we use your data

PurposeWhat this covers
Respond to enquiriesAnswering questions, sending proposals, scheduling calls
Deliver servicesRunning projects, providing support, managing the engagement
Billing and adminContracts, invoicing, payment, tax and accounting records
MarketingNewsletters, event invitations, insights and updates
Website improvementUnderstanding traffic and fixing what does not work
RecruitmentAssessing applications and managing hiring
SecurityPreventing fraud, abuse, and unauthorised access
Legal complianceMeeting tax, regulatory, and reporting obligations

We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not use it to train AI models.

  • Contract — to deliver services you or your organisation have engaged us for
  • Legitimate interests — running and growing our business, responding to enquiries, and keeping our systems secure. We balance these against your rights and freedoms.
  • Consent — marketing emails and non-essential cookies. You can withdraw consent at any time.
  • Legal obligation — tax, accounting, and regulatory requirements

5A. India (DPDP Act, 2023 and DPDP Rules, 2025)

Where the Digital Personal Data Protection Act, 2023 applies, CloudZenia acts as a Data Fiduciary. We process personal data with your consent, or for legitimate uses permitted under the Act. You may withdraw consent at any time by writing to privacy@cloudzenia.com, and withdrawing is as easy as giving consent.

Your rights as a Data Principal include access, correction, erasure, grievance redressal, and nominating another person to exercise your rights on your behalf. You also have a duty not to submit false information or file frivolous complaints.

Contact for DPDP queries and grievances: Ashwini Kumar, Founder — privacy@cloudzenia.com

If your grievance is not resolved, you may escalate to the Data Protection Board of India.

5B. United Arab Emirates

For our UAE entity, we process personal data in line with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and applicable free zone data protection rules.

6. Who we share data with

We do not sell or rent personal data. We share it only where necessary, with:

  • Cloud and hosting providers — primarily Amazon Web Services
  • Business tools — our CRM, email and marketing platform, analytics, ticketing, scheduling, and collaboration tools
  • AWS and technology partners — where needed to register an opportunity, apply for partner funding (MAP, migration credits, assessment funding), or jointly support your organisation. We share only what the programme requires.
  • Subcontractors and delivery partners — under confidentiality and data protection terms
  • Professional advisers — accountants, auditors, lawyers, insurers
  • Authorities — where required by law or valid legal process
  • A buyer or successor — if we are involved in a merger, acquisition, restructuring, or sale of assets. Your data stays protected under terms at least as strict as this policy.

All providers are bound by written contracts, act only on our instructions, and cannot use your data for their own purposes.

A current list of our main sub-processors is available on request from privacy@cloudzenia.com.

7. International transfers

We operate across India, the UAE, the UK, the United States, and other markets, so your data may be transferred to and stored in a country other than your own.

Where we transfer personal data out of the UK or the EEA, we rely on:

  • European Commission Standard Contractual Clauses
  • The UK International Data Transfer Addendum
  • Transfer risk assessments where required
  • Additional technical and contractual safeguards

You can request details of these safeguards by writing to us.

8. Cookies

Our website uses cookies and similar technologies to keep the site working, remember your preferences, and measure traffic.

  • Essential cookies are always active — the site cannot work without them.
  • Analytics and marketing cookies are used only with your consent, which you give through our cookie banner.

You can change or withdraw your choice at any time through the Cookie settings link in our website footer, or by clearing

9. How long we keep data

DataRetention
Enquiries that do not become projects24 months from last contact
Client and contract recordsDuration of the engagement, then 7 years for tax and legal purposes
Billing and accounting recordsAs required by Indian, US, and UAE tax law
Marketing contactsUntil you unsubscribe, then a suppression record only
Unsuccessful job applications12 months, unless you ask us to keep you on file
Website analyticsUp to 26 months
Security and access logs12 months

Once a retention period ends, we securely delete or anonymise the data.

10. How we protect your data

  • Encryption in transit (TLS) and at rest
  • Role-based access control and least-privilege access
  • Multi-factor authentication on all internal systems
  • Centralised logging, monitoring, and alerting
  • Vulnerability scanning and patch management
  • Confidentiality obligations and security training for all employees and contractors
  • A documented incident response process

No system is completely secure. If a breach occurs that is likely to put you at risk, we will notify the relevant authority and affected individuals within the timeframes required by law — within 72 hours where GDPR or the DPDP Rules apply.

11. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct data that is wrong or incomplete
  • Delete your data where the law allows
  • Restrict or object to certain processing
  • Port your data to another provider in a usable format
  • Withdraw consent at any time
  • Nominate someone to exercise your rights for you (India)
  • Opt out of the sale or sharing of personal data, and of targeted advertising (California and other US states — note we do not sell personal data)
  • Complain to a regulator

To exercise a right, email privacy@cloudzenia.com with the subject line “Data Subject Request”. We may ask you to verify your identity. We respond within 30 days, and will tell you if we need longer.

You can also complain to your local regulator — for example, the Information Commissioner’s Office (UK), your EU supervisory authority, or the Data Protection Board of India.

12. Marketing

Every marketing email has an unsubscribe link. You can also opt out by writing to privacy@cloudzenia.com. Opting out of marketing does not stop necessary service, contract, or security communications.

13. Children

Our website and services are for businesses and working professionals. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

Our website links to third-party sites, including our booking tool, review platforms, and social media pages. We are not responsible for their privacy practices. Please read their policies before sharing information with them.

15. Changes to this policy

We may update this policy as our business, technology, or legal obligations evolve. The current version, with its effective date, always lives on this page. If a change is significant, we’ll try to let you know directly.

16. Contact us

Privacy enquiries: privacy@cloudzenia.com

RegionEntityAddress
USACloudZenia Inc.8 The Green, Dover, DE 19901, United States
IndiaCloudZeniaUnit 2315, 3rd Floor, B-Block, Ardente Office One, Hoodi Circle, Whitefield, Bengaluru 560048
UAECLOUDZENIA L.L.C-FZMeydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai

Have a question about your data?

Our privacy team responds within 30 days.

CloudZenia

The enterprise control plane for autonomous cloud infrastructure. Build, scale, and secure your environment with full observability.

By subscribing you agree to our Privacy Policy