Effective date: 13 July 2026
Version: 2.0
This Privacy Policy explains how Auditzo collects, uses, stores, shares, and protects personal and technical information when you visit our website, contact us, submit a website for analysis, purchase a report, request a manual service, or otherwise use Auditzo.
Auditzo is a product operated by Zestminds Technologies Private Limited, a company incorporated in India with Corporate Identification Number U62099PB2023PTC058281 and registered office at #E-45, Industrial Area, Phase 8, SAS Nagar, Punjab 160071, India.
In this Policy, “Auditzo,” “we,” “us,” and “our” refer to Zestminds Technologies Private Limited.
This Policy applies to:
A separate Data Processing Addendum, proposal, Statement of Work, or other written agreement may apply to a particular enterprise, law-firm, agency, or custom engagement.
This Policy should be read together with our Terms & Conditions, Refund & Cancellation Policy, and Cookie Policy.
We may collect information that you voluntarily provide when you contact us, submit a website, purchase a report, request support, or engage Auditzo for a service.
This may include:
Please do not submit passwords, complete payment-card details, government identification numbers, medical information, or other unnecessary sensitive information through general contact forms, automated scan forms, or ordinary email.
Where sensitive or confidential evidence is required for a custom engagement, we may agree on an appropriate method of collection, access, transfer, and retention before the information is provided.
When a website is submitted for analysis, Auditzo may process or generate technical information relating to the submitted website.
Depending on the selected service, this may include:
Scan artifacts may occasionally contain personal information or identifiers exposed by the submitted website, its third-party technologies, URLs, network requests, cookies, browser storage, page content, or user journey.
Customers requesting authenticated, restricted, or custom testing must have appropriate ownership, authority, or documented permission, as explained in our Terms & Conditions.
Auditzo uses this information to perform the requested analysis, generate and deliver reports, investigate scan failures, provide support, and complete any agreed manual or technical work.
Payments are processed through Razorpay.
Razorpay may collect and process billing and payment information necessary to complete a transaction under its own terms and privacy practices.
Auditzo does not intentionally store complete payment-card numbers, CVV codes, or complete banking credentials. Payment credentials are handled by Razorpay and relevant financial institutions.
Auditzo may receive and retain limited transaction information such as:
We use this information to process orders, confirm payments, deliver reports, prevent fraud, provide support, issue invoices, and handle refunds or payment disputes.
Our website, hosting infrastructure, application servers, security providers, and scanner systems may automatically process technical information when you access or use Auditzo.
This may include:
We use this information to operate and secure Auditzo, prevent abuse, troubleshoot failures, investigate incidents, maintain availability, and protect customers, submitted websites, and our systems.
Auditzo currently uses Plausible Analytics to understand aggregated website usage, such as page views, traffic sources, and general usage patterns.
Plausible is designed to provide privacy-focused analytics without placing analytics cookies or creating persistent cross-site visitor profiles.
We use this aggregated information to understand which pages are useful, improve website navigation, and measure the general performance of Auditzo content and services.
Auditzo does not use Plausible Analytics for targeted advertising or cross-site behavioural advertising.
Plausible Analytics does not require analytics cookies.
Auditzo may nevertheless use strictly necessary cookies, browser storage, or similar technologies for functions such as:
Third-party services involved in security, infrastructure, or payments may also use technologies necessary to provide their services.
Further information, including the technologies currently observed on Auditzo, will be maintained in our Cookie Policy.
We may use information to:
We do not use customer contact, order, or report information for cross-site advertising.
The legal basis applicable to a particular activity depends on your location, your relationship with Auditzo, and the service requested.
Where required by applicable law, we may process information because:
Where we rely on consent, you may withdraw that consent for future processing, subject to applicable law and any processing that has already lawfully occurred.
Auditzo does not currently send customer names, email addresses, submitted website URLs, scan artifacts, HAR files, screenshots, report contents, or support communications to external artificial intelligence model providers such as OpenAI, Anthropic, or Google Gemini for report generation, analysis, or model training.
If this practice materially changes, we will update this Privacy Policy before or when the new processing begins, as required by applicable law.
Auditzo does not sell personal information and does not share customer information with third parties for cross-site behavioural advertising.
We may share limited information:
Service providers are permitted to process information only for the services they provide, subject to their agreements, applicable law, and their own legal obligations.
Auditzo currently uses service providers including:
Brevo may process recipient email addresses and delivery-related metadata to send order confirmations, report notices, service updates, support responses, and other transactional messages.
Cloudflare R2 is used to store generated report files and related information. Auditzo report objects stored in R2 are configured as private and are not intended to be made available through unrestricted public storage links.
Our providers may change as the Services develop. We will update this Policy where a change materially affects the way personal information is processed.
Auditzo operates internationally and may process information in more than one country.
GDPR-oriented website scans may be executed using scanner infrastructure located in Germany.
Website scans relating to other supported frameworks may be executed using scanner infrastructure located in the United States.
Generated reports and related files may be transferred to and stored in private Cloudflare R2 object storage. Application processing, transactional email delivery, payment processing, infrastructure operations, support, logging, and administration may involve other locations.
Authorized Auditzo personnel located in India may access customer, order, support, report, or technical information where reasonably necessary to operate the Services, resolve problems, provide support, or complete a manual engagement.
Using scanner infrastructure in Germany does not necessarily mean that all information relating to a scan remains exclusively in Germany.
Where cross-border processing is subject to specific legal requirements, the relevant arrangements may be addressed through our provider agreements, applicable contractual protections, or a separate Data Processing Addendum.
Enterprise, law-firm, or custom customers may contact us before an engagement to discuss specific regional-processing, confidentiality, security, or retention requirements.
We retain information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, support, security, payment administration, dispute handling, legal compliance, and legitimate business records.
Reports and related files are retained for a limited period depending on the selected service. The applicable availability or expiry date may be displayed on the report status page, report interface, order confirmation, or another service communication.
You should download any report or file you wish to retain before the displayed expiry date. Unless otherwise agreed in writing, Auditzo is not an indefinite archival, evidence-preservation, litigation-hold, or records-management service.
Scan artifacts, report files, and related technical records may be deleted after the applicable service period, subject to operational, backup, security, legal, or dispute-related requirements.
Order, payment, invoice, refund, and transaction records may be retained for longer where reasonably necessary for accounting, tax, fraud prevention, legal compliance, or dispute resolution.
Contact and support communications may be retained while an inquiry or engagement remains active and for a reasonable period afterwards.
Security, request, and error logs may be retained for a limited period necessary for troubleshooting, abuse prevention, incident investigation, and platform protection.
When information is deleted from active systems, limited copies may temporarily remain in backups or logs until those records are overwritten or expire through normal system processes.
You may request deletion by contacting [email protected]. We may retain information where continued retention is required or permitted by applicable law, necessary to complete an active service, protect security, resolve a dispute, or maintain required business records.
Auditzo uses reasonable technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, destruction, loss, or misuse.
Depending on the relevant system, these measures may include:
No website, transmission method, storage system, or security measure can guarantee absolute security.
If you believe that an Auditzo report, account, communication, or system has been accessed improperly, contact [email protected] promptly.
Depending on your location and the law applicable to the relevant processing, you may have rights to:
These rights are not absolute. A request may be limited where information must be retained for service delivery, security, fraud prevention, accounting, tax, legal compliance, dispute resolution, or the rights of another person.
To submit a request, contact [email protected].
We may request information reasonably necessary to verify your identity, locate the relevant records, confirm your authority, and protect information from unauthorized disclosure.
We will not discriminate against you for exercising a mandatory privacy right available under applicable law.
Auditzo currently uses customer contact information primarily for transactional and service-related communications, including:
We do not currently add customers automatically to a general promotional newsletter merely because they contacted us or purchased a service.
If Auditzo introduces optional marketing subscriptions, the signup should be voluntary and separate from the information required to provide a purchased service.
You may opt out of promotional communications using the unsubscribe method provided in the message. You may still receive essential transactional or service-related communications.
Auditzo analyzes website behaviour made available through a browser, network request, submitted evidence, or agreed test environment.
A submitted website may expose information relating to its visitors, customers, employees, vendors, or other individuals through URLs, page content, cookies, identifiers, browser storage, scripts, network requests, or other technical activity.
The customer requesting a scan or custom engagement is responsible for:
Where Auditzo processes information on a customer’s documented instructions for a custom engagement, additional data-processing terms may be agreed through a Data Processing Addendum or Statement of Work.
Auditzo is intended for website owners, businesses, professionals, agencies, technical teams, legal teams, and other persons legally able to request or purchase the Services.
Auditzo is not directed to children, and we do not knowingly solicit personal information from children through our paid services.
If you believe that a child has provided personal information to Auditzo without appropriate authorization, contact [email protected] so that we can review and, where appropriate, delete it.
Auditzo may contain links to third-party websites, legal resources, payment pages, service providers, or other external content.
This Privacy Policy does not govern the independent privacy practices of those third parties. Please review their applicable policies before providing information directly to them.
We may update this Policy to reflect changes to Auditzo’s services, infrastructure, providers, security practices, legal requirements, or data-handling activities.
The effective date and version number will be displayed at the top of the Policy.
We retain previous policy versions in our internal policy records. Where a change materially affects active customers or ongoing processing, we may provide additional notice where appropriate.
We will not use a policy update to retroactively make a materially different use of personal information without taking any additional steps required by applicable law.
For privacy questions, access or deletion requests, or concerns about Auditzo’s handling of information, contact:
Zestminds Technologies Private Limited