Privacy Policy — Plain-Language Summary
Last updated: 2026-07-14
Important: This is a simplified, non-binding summary provided for convenience. The complete Spanish Privacy Policy is the official version. This summary does not replace it or limit your rights under the GDPR, Spanish law, or other applicable law.
Who handles your data
Zaroz Cloud is responsible for deciding how account, billing, website, security, and business-operation data is used. Contact [email protected] with privacy questions or requests.
When a customer stores personal data inside its hosted workloads, that customer usually decides why the data is used and Zaroz processes it on the customer’s instructions. In that situation, requests should normally go to the customer first.
Data Zaroz collects
Zaroz may collect:
- account, identity, organization, and contact details;
- purchases, invoices, payment status, tax details, and limited payment information;
- IP addresses, device and browser information, logins, API activity, server and network logs, usage, configuration, and security events;
- support tickets, emails, feedback, conversations, and files you provide;
- website visits, referrals, language and cookie choices, and consent-based analytics; and
- fraud, abuse, identity-verification, sanctions, and legal-compliance information.
Data may come from you, your organization, the Services and website, payment and security providers, public sources, abuse reporters, or authorities.
Why Zaroz uses it
Zaroz uses personal data to create accounts, provide and support Services, process payments, issue invoices, secure accounts and infrastructure, diagnose problems, improve reliability, send essential notices, prevent fraud and abuse, resolve disputes, and meet legal obligations.
Under the GDPR, this processing is generally based on performing a contract, taking requested steps before a contract, complying with the law, Zaroz’s legitimate interests in operating and protecting its Services, or consent. Optional analytics and marketing use consent where required. You may object when processing relies on legitimate interests.
Cookies
Zaroz uses necessary cookies for authentication, security, and essential features; preference cookies for language and consent choices; and optional analytics, including Google Analytics, after consent where required.
You can reject optional cookies in the banner. A permanent method for reopening cookie settings still needs to be added to the site. Zaroz does not use your data for third-party targeted advertising or sell it for money.
Who receives data
Data may be shared with providers that support payments, fraud prevention, infrastructure, hosting, networks, backups, monitoring, security, email, customer support, analytics, accounting, insurance, and professional advice. It may also be disclosed to courts, regulators, authorities, rights holders, or a business successor where legally required or reasonably necessary.
Providers acting as processors must follow Zaroz’s instructions and contractual safeguards. Some providers may process data outside the EEA. Where required, Zaroz uses recognized safeguards such as adequacy decisions or the European Commission’s Standard Contractual Clauses.
How long data is kept
Typical periods are:
- account data: while active and usually up to 90 days after closure;
- hosted customer content: according to the Service’s deletion process and backup rotation;
- invoices and tax records: seven years or the legally required period;
- support records: usually up to three years after resolution or closure;
- security, access, and network logs: generally up to 12 months; and
- abuse or fraud records: as long as reasonably needed to prevent repeat abuse or handle legal claims.
Data may be kept longer for an active dispute, investigation, legal duty, or restricted backup cycle.
Security
Zaroz uses measures such as encryption in transit, access controls, logging, network protections, backups, and vulnerability management. No system is completely secure. Customers remain responsible for securing credentials and systems under their control.
Your rights
Depending on applicable law, you may ask to access, correct, delete, restrict, or receive your data; object to processing; withdraw consent; and opt out of direct marketing. Contact [email protected] or dashboard support. Zaroz may verify your identity and normally responds within one month under the GDPR, with a possible two-month extension for complex or numerous requests.
You may complain to the Spanish Data Protection Agency (AEPD) or your local supervisory authority.
Other points
Accounts are for people aged 18 or over. Zaroz does not ordinarily make solely automated decisions with legal or similarly significant effects. Automated security signals may temporarily block suspicious activity for review.
Zaroz may update the policy and will provide reasonable notice of material changes where required.
Contact and official text
Privacy: [email protected]
Legal notices: [email protected]
The complete Spanish Privacy Policy is authoritative. If this summary differs from it, the Spanish policy prevails, except where mandatory law provides otherwise.