01Who we are
Zonovva (“Zonovva”, “we”, “us”, “our”) — the parent brand of the Zonovva group, trading as Zonovva Pvt Ltd and registered as a micro enterprise under Udyam (UDYAM-MH-26-1073317), Pune, Maharashtra, India. Incorporation of Zonovva Private Limited is in progress. Until it completes, the operating entity is Zonovva, a Udyam-registered micro enterprise owned by Tejas Sakore. On incorporation these policies continue to apply to the incorporated company and this page will be updated with the CIN.
This policy covers zonovva.com and every website, subdomain and form operated by Zonovva and the Zonovva brands: Zonovva Creative Agency, Imaginex Web Solutions, TrustLoop, Zonovva Automation, Innovatia Gen Technologies and Zonovva Global Community (together, the “Zonovva brands”). This includes zonovva.com/creative/, zonovva.com/automation/, zonovva.com/community/, trustloop.zonovva.com, imaginexweb.com and tejassakore.com. Where a brand publishes a more specific policy, that policy applies in addition to this one.
02What we collect
Information you give us. When you submit an enquiry, application, community request or newsletter form we collect the name, email address, phone number, company name, website, area of interest and any message you provide.
Unfinished forms. If you begin filling an enquiry form, the details you have typed so far are sent to us periodically while you type and again if you leave without sending, together with the point at which you stopped. We do this so we can follow up an enquiry that did not make it through, and we treat that information exactly as a completed enquiry. If you later submit the form, the partial record is marked as completed. Ask us and we will delete it.
Visit analytics. When you visit, our own analytics record: the pages you view and the order you view them in; the site, search engine, advert or link that brought you here (including UTM tags and click identifiers such as gclid and fbclid); the buttons, links and sections you click; how far you scroll; how long you stay and how long you are active; videos you play; text you copy; whether the tab was hidden; your device type, operating system, browser and version; screen and window size; language; time zone; network connection type and speed; hardware details your browser exposes (processor cores, memory, graphics renderer, touch support, battery level where available); page-load performance timings; and any JavaScript errors you encounter.
IP address and approximate location. We record your IP address and derive from it your approximate location (city, region, country, postal area, time zone) and your internet service provider. This is done by querying a third-party IP-location service from your browser. Location from an IP address is approximate and is never street-level.
Identifiers. We set a first-party visitor identifier in a cookie and in your browser’s local storage so we can recognise a returning visitor and connect the pages of one session together. It does not contain your name. When you follow a link from one Zonovva website to another (for example from zonovva.com to imaginexweb.com or tejassakore.com) the identifier is carried in the link so your journey across the Zonovva network is recorded as one visit rather than several unrelated ones.
Device fingerprint. We compute a device hash from technical characteristics of your browser and device — how it renders a small hidden graphic, the graphics processor, screen size and colour depth, installed fonts, time zone, language, processor and memory class. The hash lets us recognise a returning device even when cookies are cleared and helps us detect fraud and bots. It is a one-way code that cannot be reversed into those details and is never combined with data from outside the Zonovva network.
Additional technical signals. Whether an ad blocker is active; the Global Privacy Control setting; colour-gamut and HDR support; pointer type; approximate storage quota; the number (never the names or content) of cameras, microphones and speakers your browser reports; window size and history length; JavaScript memory limits; and which browser capabilities (Bluetooth, USB, sharing, WebAuthn) are available. These describe the device class, not you.
Movement trails. While you are on a page we sample the position of your pointer and your scroll position a few times per second (as percentages of the page, not screen recordings) so we can build heat-maps of what people look at and where they hesitate.
Consent choice. We record the option you choose on the cookie notice.
We do not collect payment card details on our websites. Payments to any Zonovva brand are handled by invoice, bank transfer or a payment gateway that processes card data under its own security standards.
03How we use it
Enquiry details are used to respond to you, prepare a quotation or proposal, route your request to the right Zonovva brand and communicate about a potential or active engagement.
Visit analytics and location data are used to understand who visits our websites, which content is useful, where visitors come from, how the sites perform on different devices and networks, and to detect abuse. We use this to improve our websites, our ventures and our communication — and to know when someone is looking at our work so we can be ready to answer quickly.
All of this data — from every Zonovva website — is stored in one Google Sheet operated by Zonovva (Google Workspace, data hosted by Google) and will later be read by a private Zonovva analytics portal so the founder and team can see visitor trends, enquiries and unfinished forms across the whole network in one place. Access is limited to the founder and named team members.
We do not sell, rent or trade personal information. We do not use it to make automated decisions with legal or similarly significant effects on you. We only use this information to improve Zonovva and its brands.
04Lawful basis for processing
We process personal data on three bases. Contract — where the data is needed to quote for, deliver or support work you have engaged a Zonovva brand for. Legitimate interest — where we respond to an enquiry, measure and secure our websites, keep basic records of who we have worked with, and understand our audience; we have balanced these interests against your rights and offer an opt-out. Consent — where you have explicitly agreed, for example by ticking the box on a form, accepting marketing cookies or joining a mailing list. Consent can be withdrawn at any time without affecting processing already carried out.
For visitors in India this processing follows the Digital Personal Data Protection Act, 2023. For visitors in the European Economic Area and the United Kingdom it follows the GDPR and UK GDPR; our legitimate-interest analytics can be switched off from the cookie notice at any time.
We do not process special-category data (health, biometric, religious, caste or political information) and ask that you do not send it to us.
07How long we keep it
Enquiry data: up to twenty-four months from last contact, then deleted or anonymised unless an engagement follows.
Client and engagement records: for the duration of the engagement and afterwards for as long as Indian tax and record-keeping law requires (currently eight years for financial records).
Visit analytics and IP-derived location: raw event data for up to 26 months; aggregated statistics (which contain no identifiers) indefinitely.
Unfinished-form captures: 90 days, unless you contact us in that time.
Device hashes and movement trails: 26 months with the visit data they belong to.
Community membership data: for as long as you remain a member and 12 months after.
08Your rights
You can ask us what personal data we hold about you, ask us to correct it, ask us to delete it, object to or restrict processing, withdraw consent, or ask for a copy in a portable format. Email us and we will respond within thirty days. We may need to verify your identity first.
You can opt out of analytics and marketing at any time using the cookie notice (clear the site’s cookies to see it again) or by emailing us. Opting out stops the visitor identifier, device hash, movement trails and form captures on this device immediately. You can unsubscribe from any mailing using the link in the email or by replying.
If you are in India you may also nominate a person to exercise these rights on your behalf and may complain to the Data Protection Board of India. If you are in the EEA or UK you may complain to your local supervisory authority. We would appreciate the chance to resolve any concern directly first.
09Children
Our websites and services are intended for businesses and adults. We do not knowingly collect information from anyone under eighteen. If you believe a child has provided data to us, contact us and we will delete it.
10Client account access
Delivering websites, Google Business Profiles, analytics, social and advertising accounts often means being granted access to systems that belong to you. We ask for the lowest level of access that allows the work to be done, and we ask to be added as a user rather than being given your password.
Where a password cannot be avoided, it is stored in a password manager, never in email or chat, and we ask you to rotate it when the engagement ends. Access is removed at handover unless you have asked us to stay on for maintenance.
11Security
Accounts we control use unique passwords and two-factor authentication where the platform supports it. Devices are password-protected and encrypted. Access to client material and to visitor analytics is limited to the people who need it. Data sent from our websites travels over HTTPS.
No system is perfectly secure. If a breach affects your personal data we will tell you what happened, what data was involved and what we are doing about it, without undue delay and in line with applicable law.
12Marketing and portfolio use
Zonovva brands may show delivered work in portfolios, on social media and in proposals, including your business name, logo and screenshots of public-facing work. If you would rather we did not, tell us in writing and we will remove it — before or after publication, at no cost.
Confidential material, internal documents and anything covered by a signed NDA is never published.
13Meta, Google and other platform integrations
Zonovva brands operate business accounts, apps and integrations on Meta (Facebook, Instagram, WhatsApp Business), Google and other platforms. Where such an integration accesses data from your account (for example to manage a page or send WhatsApp messages you have opted into), we use only the permissions needed for the agreed work, keep the data no longer than needed, and delete it on request. You may withdraw access at any time through the platform’s settings.
Data deletion requests relating to any Zonovva app or integration may be sent to info@zonovva.com with the subject “Data deletion request”. We confirm completion within thirty days.
14External links
Our websites link to other websites (including Zonovva brand sites on other domains, partner sites and social platforms). Their privacy policies apply once you leave our pages.
15Changes to this policy
If this policy changes materially we will update the date at the top of this page and, for active clients and community members, notify you directly. On incorporation of Zonovva Private Limited the responsible entity in this policy will be updated accordingly; your rights will not be reduced.
16Contact
Questions about this policy: info@zonovva.com or +91 95522 38893 (call or WhatsApp). Postal address: Zonovva, Flat 102, Chandrabhaga, Nanded Fata, Lagad Colony, Lagad Industries Road, Pune, Maharashtra 411068, India.
Grievance officer for the purposes of Indian data-protection law: Tejas Sakore, Founder, reachable at founder@zonovva.com.
This document is written in plain English for a small Indian business group. It is reviewed as Zonovva grows and will be updated when Zonovva Private Limited is incorporated. It does not constitute legal advice to you.