CloudZenia respects your privacy and is committed to protecting it. This policy explains what personal data we collect, why we collect it, and the choices you have.
1. Who we are
CloudZenia is an AWS Advanced Tier Services Partner. We deliver cloud migration, DevOps, managed services, cloud security, cost optimization, and Generative and Agentic AI engineering.
We operate through three entities, depending on where you’re based:
| Entity | Registered address | Acts as controller for |
|---|---|---|
| CloudZenia Inc. | 8 The Green, Dover, DE 19901, United States | Clients and visitors in the USA and Canada |
| CloudZenia (proprietorship, India) | Unit 2315, 3rd Floor, B-Block, Ardente Office One, Hoodi Circle, Whitefield, Bengaluru 560048, India | Clients and visitors in India and the rest of the world |
| CLOUDZENIA L.L.C-FZ | Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, UAE | Clients and visitors in the UAE and wider Middle East |
Website: cloudzenia.com
Privacy contact: privacy@cloudzenia.com
2. What this policy covers
This policy applies to
Personal data about website visitors, prospects, clients, partners, suppliers, job applicants, and people who receive our communications.
This policy does not apply to
Personal data sitting inside a client’s own systems or AWS accounts, even when we’re accessing those systems to deliver a project. In that case, the client is the one in charge of that data (the “controller”), and we’re just processing it on their behalf, under their service agreement and Data Processing Agreement. If you’re a customer or employee of one of our clients and have questions about your data, that organisation is who you’ll want to reach out to, not us.
3. Data we collect
3.1 Information you give us
- Contact details — name, job title, company, business email, phone number, country
- Enquiry details — form submissions, proposal and RFP requests, meeting bookings, project requirements, support requests
- Marketing details — newsletter sign-ups, event and webinar registrations, whitepaper downloads, communication preferences
- Client and billing details — contract contacts, purchase orders, billing address, tax registration numbers, bank or payment references
- Recruitment details — CV, cover letter, work history, education, certifications, references, and right-to-work information if you apply for a role
- Correspondence — emails, meeting notes, call records, and support tickets
3.2 Information we collect automatically
- IP address and rough location (city or country level)
- Browser type and version, device type, operating system, language settings
- Pages you viewed, time spent, navigation path, downloads, referring site
- Cookies and similar identifiers (more on this in Section 8)
3.3 Information from other sources
- Professional networking platforms like LinkedIn
- Business directories, public company websites, and business intelligence providers
- Referrals from AWS and other technology partners
- Event organisers and sponsors
3.4 Data we do not want
Please do not send us sensitive personal data (health information, biometric data, government ID numbers, financial account credentials) through our website forms or general email. We do not need it, and we will delete it if we receive it.
4. Why we use your data
| Purpose | What this covers |
|---|---|
| Respond to enquiries | Answering questions, sending proposals, scheduling calls |
| Deliver services | Running projects, providing support, managing the engagement |
| Billing and admin | Contracts, invoicing, payment, tax and accounting records |
| Marketing | Newsletters, event invitations, insights and updates |
| Website improvement | Understanding traffic and fixing what does not work |
| Recruitment | Assessing applications and managing hiring |
| Security | Preventing fraud, abuse, and unauthorised access |
| Legal compliance | Meeting tax, regulatory, and reporting obligations |
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not use it to train AI models.
5. Legal basis (UK and EU GDPR)
- Contract — to deliver services you or your organisation have engaged us for
- Legitimate interests — running and growing our business, responding to enquiries, and keeping our systems secure. We balance these against your rights and freedoms.
- Consent — marketing emails and non-essential cookies. You can withdraw consent at any time.
- Legal obligation — tax, accounting, and regulatory requirements
5A. India (DPDP Act, 2023 and DPDP Rules, 2025)
Where the Digital Personal Data Protection Act, 2023 applies, CloudZenia acts as a Data Fiduciary. We process personal data with your consent, or for legitimate uses permitted under the Act. You may withdraw consent at any time by writing to privacy@cloudzenia.com, and withdrawing is as easy as giving consent.
Your rights as a Data Principal include access, correction, erasure, grievance redressal, and nominating another person to exercise your rights on your behalf. You also have a duty not to submit false information or file frivolous complaints.
Contact for DPDP queries and grievances: Ashwini Kumar, Founder — privacy@cloudzenia.com
If your grievance is not resolved, you may escalate to the Data Protection Board of India.
5B. United Arab Emirates
For our UAE entity, we process personal data in line with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and applicable free zone data protection rules.
6. Who we share data with
We do not sell or rent personal data. We share it only where necessary, with:
- Cloud and hosting providers — primarily Amazon Web Services
- Business tools — our CRM, email and marketing platform, analytics, ticketing, scheduling, and collaboration tools
- AWS and technology partners — where needed to register an opportunity, apply for partner funding (MAP, migration credits, assessment funding), or jointly support your organisation. We share only what the programme requires.
- Subcontractors and delivery partners — under confidentiality and data protection terms
- Professional advisers — accountants, auditors, lawyers, insurers
- Authorities — where required by law or valid legal process
- A buyer or successor — if we are involved in a merger, acquisition, restructuring, or sale of assets. Your data stays protected under terms at least as strict as this policy.
All providers are bound by written contracts, act only on our instructions, and cannot use your data for their own purposes.
A current list of our main sub-processors is available on request from privacy@cloudzenia.com.
7. International transfers
We operate across India, the UAE, the UK, the United States, and other markets, so your data may be transferred to and stored in a country other than your own.
Where we transfer personal data out of the UK or the EEA, we rely on:
- European Commission Standard Contractual Clauses
- The UK International Data Transfer Addendum
- Transfer risk assessments where required
- Additional technical and contractual safeguards
You can request details of these safeguards by writing to us.
8. Cookies
Our website uses cookies and similar technologies to keep the site working, remember your preferences, and measure traffic.
- Essential cookies are always active — the site cannot work without them.
- Analytics and marketing cookies are used only with your consent, which you give through our cookie banner.
You can change or withdraw your choice at any time through the Cookie settings link in our website footer, or by clearing
9. How long we keep data
| Data | Retention |
|---|---|
| Enquiries that do not become projects | 24 months from last contact |
| Client and contract records | Duration of the engagement, then 7 years for tax and legal purposes |
| Billing and accounting records | As required by Indian, US, and UAE tax law |
| Marketing contacts | Until you unsubscribe, then a suppression record only |
| Unsuccessful job applications | 12 months, unless you ask us to keep you on file |
| Website analytics | Up to 26 months |
| Security and access logs | 12 months |
Once a retention period ends, we securely delete or anonymise the data.
10. How we protect your data
- Encryption in transit (TLS) and at rest
- Role-based access control and least-privilege access
- Multi-factor authentication on all internal systems
- Centralised logging, monitoring, and alerting
- Vulnerability scanning and patch management
- Confidentiality obligations and security training for all employees and contractors
- A documented incident response process
No system is completely secure. If a breach occurs that is likely to put you at risk, we will notify the relevant authority and affected individuals within the timeframes required by law — within 72 hours where GDPR or the DPDP Rules apply.
11. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct data that is wrong or incomplete
- Delete your data where the law allows
- Restrict or object to certain processing
- Port your data to another provider in a usable format
- Withdraw consent at any time
- Nominate someone to exercise your rights for you (India)
- Opt out of the sale or sharing of personal data, and of targeted advertising (California and other US states — note we do not sell personal data)
- Complain to a regulator
To exercise a right, email privacy@cloudzenia.com with the subject line “Data Subject Request”. We may ask you to verify your identity. We respond within 30 days, and will tell you if we need longer.
You can also complain to your local regulator — for example, the Information Commissioner’s Office (UK), your EU supervisory authority, or the Data Protection Board of India.
12. Marketing
Every marketing email has an unsubscribe link. You can also opt out by writing to privacy@cloudzenia.com. Opting out of marketing does not stop necessary service, contract, or security communications.
13. Children
Our website and services are for businesses and working professionals. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
14. Third-party links
Our website links to third-party sites, including our booking tool, review platforms, and social media pages. We are not responsible for their privacy practices. Please read their policies before sharing information with them.
15. Changes to this policy
We may update this policy as our business, technology, or legal obligations evolve. The current version, with its effective date, always lives on this page. If a change is significant, we’ll try to let you know directly.
16. Contact us
Privacy enquiries: privacy@cloudzenia.com
| Region | Entity | Address |
|---|---|---|
| USA | CloudZenia Inc. | 8 The Green, Dover, DE 19901, United States |
| India | CloudZenia | Unit 2315, 3rd Floor, B-Block, Ardente Office One, Hoodi Circle, Whitefield, Bengaluru 560048 |
| UAE | CLOUDZENIA L.L.C-FZ | Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai |


