Privacy Policy
Effective 2026-05-20.
This Privacy Policy describes how Zyg-Squared LLC (“Zyg-Squared,” “we,” “us”) collects, uses, and discloses personal data when you visit zyg-squared.com or use applications we publish.
1. Who we are
Zyg-Squared LLC is a Texas limited liability company located in Texas, USA. For the purposes of EU and UK data protection law, we are the data controller of personal data we collect through this website and our applications, unless explicitly stated otherwise in an application-specific addendum.
2. Scope
This policy applies to:
- The website at zyg-squared.com and its subdomains we operate
- iOS and Android applications published by Zyg-Squared LLC on the Apple App Store and Google Play
- Email correspondence sent to addresses ending in
@zyg-squared.com
It does not apply to services operated by clients of Zyg-Squared LLC. When you interact with a client’s product, that client’s privacy policy governs.
3. What we collect
3.1 Information you provide
- Contact details — your email address and any information you choose to include when you write to us.
- Engagement details — project descriptions, business context, and other information you share while exploring or executing an engagement.
3.2 Information collected automatically
- Access logs — when you visit the website, our content delivery network (Amazon CloudFront) records the request URL, response status, response size, request time, your IP address, your user agent, and the referring URL. These logs are written to a private storage bucket and retained for 365 days, with archival to long-term storage after 90 days.
- No first-party analytics or tracking cookies are set by the website. We do not embed third-party trackers, ad networks, or session replay tools.
3.3 Information our applications collect
Each Zyg-Squared LLC application has its own data practices, documented in the Apple Privacy Nutrition Label, the Google Data Safety form, and the application-specific addendum referenced below. We do not silently collect categories of data beyond what those disclosures describe.
4. Why we use it
We use the information we collect for the following purposes, with the listed legal bases under EU/UK GDPR:
- Responding to you. When you email us or fill out a contact form, we use your information to reply and follow up. Legal basis: legitimate interest, or performance of a contract if we are evaluating an engagement.
- Providing requested services. Performing the work described in a signed statement of work or order form. Legal basis: performance of a contract.
- Operating the website and applications. Detecting abuse, diagnosing errors, ensuring availability, and meeting security obligations. Legal basis: legitimate interest in operating a secure service.
- Meeting legal obligations. Responding to lawful requests from authorities, retaining records for tax and audit. Legal basis: compliance with a legal obligation.
We do not sell personal data, do not use it for targeted advertising, and do not subject you to automated decision-making that produces legal effects.
5. Who we share it with
We share personal data only with parties that need it to support the purposes above, and only under written agreements that bind them to protect it. Categories of recipients:
- Infrastructure providers — primarily Amazon Web Services, which hosts our website, application backends, and email infrastructure under our account.
- Email providers — Amazon Simple Email Service for delivery and reception of email to our domain. Email content is forwarded to a personal mailbox we control for response.
- Source control and CI/CD — GitHub, for code we write on our own behalf. Client code is held in repositories the client controls unless otherwise agreed.
- Professional advisors — accountants, lawyers, and auditors, where disclosure is necessary for them to provide services to us.
- Authorities — if compelled by valid legal process and we cannot lawfully refuse or limit the disclosure.
6. International transfers
We are based in the United States and process personal data there. If you contact us from outside the U.S., your information will be transferred to and processed in the U.S. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for transfers from the EEA, UK, or Switzerland.
7. Retention
- Email correspondence: retained while the relationship is active and for up to seven years afterward, in line with U.S. tax record-keeping norms.
- Web access logs: 365 days from the date of the request.
- Application data: as specified in each application’s addendum.
- Records we are legally required to keep: for the period required by applicable law.
8. Your rights
8.1 If you are in the EEA, UK, or Switzerland (GDPR)
You have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have data erased in the circumstances set out in Article 17 GDPR
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent, where processing is based on consent
- Lodge a complaint with your supervisory authority
8.2 If you are a California resident (CCPA / CPRA)
You have the right to:
- Know what personal information we collect about you and how we use it
- Request deletion of personal information we hold
- Correct inaccurate personal information
- Opt out of the “sale” or “sharing” of personal information — we do not engage in either
- Limit the use of sensitive personal information — we do not collect categories that would trigger this right
- Be free from retaliation for exercising any of these rights
8.3 How to exercise your rights
Email support@zyg-squared.com with the subject “Data request” and describe what you’d like us to do. We respond within 30 days for GDPR requests and 45 days for CCPA requests (extendable by an additional 45 days where permitted, with notice). We may need to verify your identity before acting on a request affecting personal data.
9. Children’s privacy
The website and our applications are not directed to children under 13 (or the equivalent minimum age in the relevant jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us and we will delete it.
10. Cookies and similar technologies
The website at zyg-squared.com does not set cookies, does not use local storage, and does not embed third-party tracking scripts. Server-side access logs (described in section 3.2) are the only mechanism by which we collect data about visits.
Individual applications may use platform-provided storage (e.g. NSUserDefaults on iOS, SharedPreferences on
Android) to remember settings on your device. This is local to your
device and is disclosed in the application’s addendum.
11. Application-specific addenda
Each Zyg-Squared LLC application that handles personal data publishes an addendum disclosing the specific data it collects, third-party SDKs it embeds, and the legal bases that apply to it. The current set of published addenda will be linked here as applications are listed on the App Store and Google Play.
No applications are currently published. This section will be updated at the time of the first listing.
12. Changes to this policy
We will update this policy when our practices change. Material changes will be flagged at the top of this page and reflected in the effective date. The current version is always available at the canonical URL below.
13. Contact
Questions about this policy or how we handle your data:
- support@zyg-squared.com
- Postal
- Zyg-Squared LLC, Texas, USA
- Canonical URL
- https://zyg-squared.com/privacy/