Skip to main content
Legal

Privacy Policy

Effective date: 13 July 2026

Version: 2.0

This Privacy Policy explains how Auditzo collects, uses, stores, shares, and protects personal and technical information when you visit our website, contact us, submit a website for analysis, purchase a report, request a manual service, or otherwise use Auditzo.

Auditzo is a product operated by Zestminds Technologies Private Limited, a company incorporated in India with Corporate Identification Number U62099PB2023PTC058281 and registered office at #E-45, Industrial Area, Phase 8, SAS Nagar, Punjab 160071, India.

In this Policy, “Auditzo,” “we,” “us,” and “our” refer to Zestminds Technologies Private Limited.

In plain English: Auditzo processes limited contact, order, website-scan, report, support, and technical information to provide its services. We do not sell personal information, use customer information for cross-site advertising, or send customer data and scan evidence to external AI model providers.

1. Scope of this Policy

This Policy applies to:

  • The Auditzo public website
  • Free and paid automated website scans
  • Automated technical reports
  • Manual Evidence Audits
  • Custom legal, enterprise, agency, or multi-domain engagements
  • Website Tracking Remediation
  • Post-Remediation Verification
  • Website Privacy Monitoring
  • Contact, support, payment, and report-delivery communications

A separate Data Processing Addendum, proposal, Statement of Work, or other written agreement may apply to a particular enterprise, law-firm, agency, or custom engagement.

This Policy should be read together with our Terms & Conditions, Refund & Cancellation Policy, and Cookie Policy.

2. Information You Provide

We may collect information that you voluntarily provide when you contact us, submit a website, purchase a report, request support, or engage Auditzo for a service.

This may include:

  • Your name
  • Your email address
  • Your company or organization name
  • Your role or professional relationship to a website
  • The website domain or URL submitted for analysis
  • The framework, service, plan, or audit scope selected
  • Your inquiry, instructions, support request, or message
  • Information included in proposals, order forms, or project communications
  • Files or evidence voluntarily provided for a manual or custom engagement

Please do not submit passwords, complete payment-card details, government identification numbers, medical information, or other unnecessary sensitive information through general contact forms, automated scan forms, or ordinary email.

Where sensitive or confidential evidence is required for a custom engagement, we may agree on an appropriate method of collection, access, transfer, and retention before the information is provided.

3. Website Scan and Report Information

When a website is submitted for analysis, Auditzo may process or generate technical information relating to the submitted website.

Depending on the selected service, this may include:

  • Website domains, URLs, paths, and page titles
  • Selected legal or technical review framework
  • Scan region, browser environment, timestamps, and scan identifiers
  • Cookies and cookie-related attributes
  • Local storage and session storage entries
  • Scripts, pixels, tags, and embedded technologies
  • Third-party domains and network requests
  • Request URLs, headers, parameters, or other observable network information
  • HAR files and network-event records
  • Screenshots and page observations
  • Consent-banner and consent-state observations
  • Automated classifications, technical indicators, and report findings
  • Generated HTML, PDF, JSON, and other report files
  • Manual-review notes and evidence references where included

Scan artifacts may occasionally contain personal information or identifiers exposed by the submitted website, its third-party technologies, URLs, network requests, cookies, browser storage, page content, or user journey.

Customers requesting authenticated, restricted, or custom testing must have appropriate ownership, authority, or documented permission, as explained in our Terms & Conditions.

Auditzo uses this information to perform the requested analysis, generate and deliver reports, investigate scan failures, provide support, and complete any agreed manual or technical work.

4. Payment and Order Information

Payments are processed through Razorpay.

Razorpay may collect and process billing and payment information necessary to complete a transaction under its own terms and privacy practices.

Auditzo does not intentionally store complete payment-card numbers, CVV codes, or complete banking credentials. Payment credentials are handled by Razorpay and relevant financial institutions.

Auditzo may receive and retain limited transaction information such as:

  • Customer name and email address
  • Billing information made available through the payment flow
  • Auditzo order or audit reference
  • Razorpay order or payment reference
  • Product or service purchased
  • Amount and currency
  • Payment status
  • Transaction and delivery timestamps
  • Refund, dispute, or payment-support records

We use this information to process orders, confirm payments, deliver reports, prevent fraud, provide support, issue invoices, and handle refunds or payment disputes.

5. Technical and Security Information

Our website, hosting infrastructure, application servers, security providers, and scanner systems may automatically process technical information when you access or use Auditzo.

This may include:

  • IP address
  • Browser type and user-agent information
  • Device and operating-system information
  • Request date and time
  • Pages or application routes requested
  • Referring page or source
  • Error, performance, and diagnostic information
  • Security, abuse-prevention, and rate-limit events
  • Authentication, report-access, or session-related information

We use this information to operate and secure Auditzo, prevent abuse, troubleshoot failures, investigate incidents, maintain availability, and protect customers, submitted websites, and our systems.

6. Plausible Analytics

Auditzo currently uses Plausible Analytics to understand aggregated website usage, such as page views, traffic sources, and general usage patterns.

Plausible is designed to provide privacy-focused analytics without placing analytics cookies or creating persistent cross-site visitor profiles.

We use this aggregated information to understand which pages are useful, improve website navigation, and measure the general performance of Auditzo content and services.

Auditzo does not use Plausible Analytics for targeted advertising or cross-site behavioural advertising.

7. Cookies and Similar Technologies

Plausible Analytics does not require analytics cookies.

Auditzo may nevertheless use strictly necessary cookies, browser storage, or similar technologies for functions such as:

  • Session management
  • Website and application security
  • Form protection and abuse prevention
  • Authentication or report access
  • Remembering essential service choices
  • Payment and checkout functionality

Third-party services involved in security, infrastructure, or payments may also use technologies necessary to provide their services.

Further information, including the technologies currently observed on Auditzo, will be maintained in our Cookie Policy.

8. How We Use Information

We may use information to:

  • Provide free and paid website scans
  • Generate, store, and deliver technical reports
  • Perform Manual Evidence Audits and custom engagements
  • Provide remediation, verification, or monitoring services
  • Process orders, payments, refunds, and invoices
  • Respond to contact, support, and service requests
  • Send transactional and service-related emails
  • Investigate failed scans, report errors, and technical incidents
  • Prevent fraud, misuse, unauthorized access, and security threats
  • Maintain, troubleshoot, and improve the Auditzo platform
  • Understand aggregated website usage through Plausible Analytics
  • Maintain appropriate business, tax, accounting, and transaction records
  • Comply with legal obligations and valid governmental requests
  • Establish, exercise, or defend legal rights

We do not use customer contact, order, or report information for cross-site advertising.

10. External AI Providers

Auditzo does not currently send customer names, email addresses, submitted website URLs, scan artifacts, HAR files, screenshots, report contents, or support communications to external artificial intelligence model providers such as OpenAI, Anthropic, or Google Gemini for report generation, analysis, or model training.

If this practice materially changes, we will update this Privacy Policy before or when the new processing begins, as required by applicable law.

11. How We Share Information

Auditzo does not sell personal information and does not share customer information with third parties for cross-site behavioural advertising.

We may share limited information:

  • With service providers that help us operate the website, process payments, deliver emails, provide infrastructure, store reports, prevent abuse, or support the Services
  • With professional advisers such as accountants, auditors, insurers, or legal advisers where reasonably necessary
  • Where required by law, regulation, court order, or a valid governmental request
  • Where reasonably necessary to protect Auditzo, customers, target websites, users, or third parties from fraud, abuse, security threats, or unlawful activity
  • In connection with a merger, acquisition, restructuring, financing, investment, or transfer of all or part of the Auditzo business
  • With your direction or consent

Service providers are permitted to process information only for the services they provide, subject to their agreements, applicable law, and their own legal obligations.

12. Service Providers

Auditzo currently uses service providers including:

  • Razorpay for payment processing and transaction support
  • Brevo for transactional and service-related email delivery
  • Plausible Analytics for aggregated, privacy-focused website analytics
  • Cloudflare for infrastructure, security, network services, and private object storage through Cloudflare R2
  • Hosting and server providers used to operate the Auditzo application and regional scanner infrastructure

Brevo may process recipient email addresses and delivery-related metadata to send order confirmations, report notices, service updates, support responses, and other transactional messages.

Cloudflare R2 is used to store generated report files and related information. Auditzo report objects stored in R2 are configured as private and are not intended to be made available through unrestricted public storage links.

Our providers may change as the Services develop. We will update this Policy where a change materially affects the way personal information is processed.

13. Regional and International Processing

Auditzo operates internationally and may process information in more than one country.

GDPR-oriented website scans may be executed using scanner infrastructure located in Germany.

Website scans relating to other supported frameworks may be executed using scanner infrastructure located in the United States.

Generated reports and related files may be transferred to and stored in private Cloudflare R2 object storage. Application processing, transactional email delivery, payment processing, infrastructure operations, support, logging, and administration may involve other locations.

Authorized Auditzo personnel located in India may access customer, order, support, report, or technical information where reasonably necessary to operate the Services, resolve problems, provide support, or complete a manual engagement.

Using scanner infrastructure in Germany does not necessarily mean that all information relating to a scan remains exclusively in Germany.

Where cross-border processing is subject to specific legal requirements, the relevant arrangements may be addressed through our provider agreements, applicable contractual protections, or a separate Data Processing Addendum.

Enterprise, law-firm, or custom customers may contact us before an engagement to discuss specific regional-processing, confidentiality, security, or retention requirements.

14. Data Retention and Deletion

We retain information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, support, security, payment administration, dispute handling, legal compliance, and legitimate business records.

Reports and related files are retained for a limited period depending on the selected service. The applicable availability or expiry date may be displayed on the report status page, report interface, order confirmation, or another service communication.

You should download any report or file you wish to retain before the displayed expiry date. Unless otherwise agreed in writing, Auditzo is not an indefinite archival, evidence-preservation, litigation-hold, or records-management service.

Scan artifacts, report files, and related technical records may be deleted after the applicable service period, subject to operational, backup, security, legal, or dispute-related requirements.

Order, payment, invoice, refund, and transaction records may be retained for longer where reasonably necessary for accounting, tax, fraud prevention, legal compliance, or dispute resolution.

Contact and support communications may be retained while an inquiry or engagement remains active and for a reasonable period afterwards.

Security, request, and error logs may be retained for a limited period necessary for troubleshooting, abuse prevention, incident investigation, and platform protection.

When information is deleted from active systems, limited copies may temporarily remain in backups or logs until those records are overwritten or expire through normal system processes.

You may request deletion by contacting [email protected]. We may retain information where continued retention is required or permitted by applicable law, necessary to complete an active service, protect security, resolve a dispute, or maintain required business records.

15. Data Security

Auditzo uses reasonable technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, destruction, loss, or misuse.

Depending on the relevant system, these measures may include:

  • Encrypted connections through HTTPS
  • Private object storage for generated report files
  • Controlled application routes for report access and downloads
  • Role-based or restricted administrative access
  • Authentication and access controls
  • Logging, monitoring, and abuse-prevention measures
  • Limited access by personnel who require information for their work
  • Operational backup, recovery, and incident-response practices

No website, transmission method, storage system, or security measure can guarantee absolute security.

If you believe that an Auditzo report, account, communication, or system has been accessed improperly, contact [email protected] promptly.

16. Your Privacy Rights

Depending on your location and the law applicable to the relevant processing, you may have rights to:

  • Request information about personal data we process
  • Request access to personal data associated with you
  • Request correction of inaccurate or incomplete information
  • Request deletion of eligible personal information
  • Object to or request restriction of certain processing
  • Request a portable copy of eligible information
  • Withdraw consent where processing is based on consent
  • Opt out of eligible marketing communications
  • Complain to an applicable data-protection or consumer authority
  • Use an authorized representative where permitted by law

These rights are not absolute. A request may be limited where information must be retained for service delivery, security, fraud prevention, accounting, tax, legal compliance, dispute resolution, or the rights of another person.

To submit a request, contact [email protected].

We may request information reasonably necessary to verify your identity, locate the relevant records, confirm your authority, and protect information from unauthorized disclosure.

We will not discriminate against you for exercising a mandatory privacy right available under applicable law.

17. Marketing and Service Communications

Auditzo currently uses customer contact information primarily for transactional and service-related communications, including:

  • Order and payment confirmations
  • Scan and report status updates
  • Report-delivery notices
  • Manual-audit or project communications
  • Refund and support responses
  • Important service, security, or policy notices

We do not currently add customers automatically to a general promotional newsletter merely because they contacted us or purchased a service.

If Auditzo introduces optional marketing subscriptions, the signup should be voluntary and separate from the information required to provide a purchased service.

You may opt out of promotional communications using the unsubscribe method provided in the message. You may still receive essential transactional or service-related communications.

18. Information Observed on Submitted Websites

Auditzo analyzes website behaviour made available through a browser, network request, submitted evidence, or agreed test environment.

A submitted website may expose information relating to its visitors, customers, employees, vendors, or other individuals through URLs, page content, cookies, identifiers, browser storage, scripts, network requests, or other technical activity.

The customer requesting a scan or custom engagement is responsible for:

  • Having an appropriate right or lawful basis for the requested testing
  • Limiting the scope to what is reasonably necessary
  • Avoiding unnecessary submission of sensitive personal information
  • Providing authorization for restricted or authenticated testing
  • Handling downloaded reports and evidence appropriately

Where Auditzo processes information on a customer’s documented instructions for a custom engagement, additional data-processing terms may be agreed through a Data Processing Addendum or Statement of Work.

19. Children’s Privacy

Auditzo is intended for website owners, businesses, professionals, agencies, technical teams, legal teams, and other persons legally able to request or purchase the Services.

Auditzo is not directed to children, and we do not knowingly solicit personal information from children through our paid services.

If you believe that a child has provided personal information to Auditzo without appropriate authorization, contact [email protected] so that we can review and, where appropriate, delete it.

21. Changes to this Privacy Policy

We may update this Policy to reflect changes to Auditzo’s services, infrastructure, providers, security practices, legal requirements, or data-handling activities.

The effective date and version number will be displayed at the top of the Policy.

We retain previous policy versions in our internal policy records. Where a change materially affects active customers or ongoing processing, we may provide additional notice where appropriate.

We will not use a policy update to retroactively make a materially different use of personal information without taking any additional steps required by applicable law.

22. Contact Information

For privacy questions, access or deletion requests, or concerns about Auditzo’s handling of information, contact:

Zestminds Technologies Private Limited
Auditzo
#E-45, Industrial Area, Phase 8
SAS Nagar, Punjab 160071
India
CIN: U62099PB2023PTC058281
Email: [email protected]