Privacy & data

How Zylaro handles your data.

Five plain-English points on what we collect when you submit the enquiry form, the legal grounds we rely on, how long we keep it, who can see it and how to ask for a copy, correction or deletion.

Done-for-you AI growth loops for UK service businesses — reception, booking, reminders and follow-up, wired into a live ROI dashboard. GDPR and PECR compliant, monitored monthly.

01 — What we collect

The enquiry form writes one row to Postgres.

When you submit the Zylaro enquiry form, the fields below are written as one row to a Postgres database so a real human can run the 20-minute fit-check with you. Nothing else is collected by the form — no third-party trackers, no advertising pixels, no device fingerprinting.

If you arrived via a tagged marketing link, we also store the matching UTM parameters so we can attribute the enquiry to the right campaign. UTM fields are stored as separate nullable columns and are only written if the URL actually carried them.

  • name

    so we know what to call you.

  • business

    so we know which company the fit-check is for.

  • email

    so we can reply with the booking link.

  • phone

    so we can call you if a faster channel matters.

  • vertical

    so the right call script is queued for you.

  • monthlyEnquiries

    so we can scope setup honestly on the call.

  • consent (boolean)

    the PECR opt-in, stored in the same row.

  • source

    set to "/enquire" so we can tell where the row came from.

  • createdAt

    a UTC timestamp; the start of the retention clock.

02 — Lawful basis

Two consent grounds, both recorded with the row.

Zylaro only processes your enquiry data because you have given consent to it. We do not rely on legitimate interest for the enquiry stage, and we do not profile or score you.

  • UK GDPR Article 6(1)(a) — consent

    The consent checkbox on the enquiry form is the legal basis for processing your personal data. Without it, we cannot run the fit-check — the submit button is gated on consent being true.

  • PECR — Privacy and Electronic Communications Regulations

    If we email or text you back about this enquiry (or any service messages tied to it), we rely on your PECR opt-in captured by the same checkbox. The opt-in is freely given, specific, informed and unambiguous, and is stored alongside the row as the consent boolean plus the createdAt timestamp as the audit trail.

03 — How long we keep it

Enquiry row: 12 months from last contact. PECR audit: longer.

We do not keep enquiry data forever. The clock runs from "last contact" — your last reply, the last call, or the booking confirmation, whichever is latest — not from "last system event".

  • Enquiry row

    Retained for 12 months from the last contact between you and Zylaro, then deleted (or earlier if you ask us to).

  • PECR consent evidence

    Kept for the life of the relationship plus 1 year — so we can evidence opt-in if challenged. The consent boolean, the createdAt timestamp and the page source (/enquire) are the audit trail.

  • Data we do not keep

    No recording of the enquiry form itself (only the verified row), no browser fingerprint, no advertising ID, no third-party analytics IDs.

04 — Who can see it

Two named humans in the UK. Three processors. No resale.

Personal data captured by the enquiry form is visible inside Zylaro at named-role scope only. The full list is intentionally short.

  • Zylaro founder

    the named founder of Zylaro — reads every row to run fit-checks.

  • On-call engineer

    the named engineer who operates the platform — reads rows only when needed to debug or to delete a row on request.

  • Hosting / database processor

    the underlying PostgreSQL host (a managed Postgres service) and the Zylaro application code that runs on it. Bound by our processor contract and access controls.

  • Stripe (in scope)

    name only — Stripe processes payment data if and when you go on to become a paying customer; your enquiry row is never shared with Stripe.

  • Not shared with

    no third-party marketing list, no data brokers, no analytics resale, no advertising networks. Zylaro does not enrich or score enquiry data.

05 — Your rights

Ask for a copy, a correction, an export or a deletion.

Under the UK GDPR you have the rights set out below. Zylaro honours every one of them, free of charge, on the same channel you used to give consent — one email address, one person, no ticket system.

  • Right of access

    ask for a plain-text copy of your enquiry row — name, business, email, phone, vertical, monthly enquiries, consent, source, createdAt.

  • Right to rectification

    ask us to correct anything that is wrong on your row.

  • Right to erasure ("right to be forgotten")

    ask us to delete your row — we will, and confirm in writing within 30 days.

  • Right to data portability

    ask for your row exported as JSON or CSV so you can hand it to another provider.

  • Right to withdraw consent

    withdraw your PECR opt-in at any time and we will stop contacting you about the enquiry — your row stays until the retention clock above deletes it, or until you ask for erasure.

  • Right to complain to the ICO

    if you would rather raise the matter with the UK Information Commissioner's Office (ico.org.uk), you can — though we would rather hear from you first.

Exercise your rights

One email address — every right routed through it.

Send a copy / correction / export / deletion / withdrawal request to the address below. We reply within 30 days (UK GDPR standard) and never charge for a request — not even the export.

zylaro@polsia.app

Last updated 10 August 2026 · Zylaro is the data controller for enquiry-form data captured on this site.