Privacy Policy
EFFECTIVE DATE
January 1, 2025
LAST UPDATED
January 30, 2026
JURISDICTION
Applies to our websites and digital services
✉️ Contact Privacy Team
Your Privacy, Simplified
How we share it: With service providers who help us operate. We do not sell your personal information.
Cookies: You control optional cookies via your preferences. Essential cookies ensure site functionality.
Your rights: Access, delete, correct, and opt-out rights available (where applicable by law).
Security: We implement appropriate safeguards and incident response practices to protect your data.
Our Accessibility Commitment
Acceptance: Using
this site means you
accept these terms
and agree to comply
with them.
Prohibited Conduct:
You may not misuse,
interfere with, or
compromise our site,
systems, or content.
1. Who We Are
Legal Name: Zoiko Foods Corp
2. Scope of This Policy
What This Covers
- Our corporate websites and web applications
- Online forms and inquiry submissions
- Newsletter subscriptions (if applicable)
- Business-to-business engagement platforms
What This Does Not Cover
- Third-party websites linked from our sites
- Partner platforms and external services
- Employment applications (covered by separate recruitment privacy notice)
- Employee data (covered by internal HR policies)
3. Information We Collect
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Identifiers | Name, email address, phone number (if provided) | Provided by you | Respond to inquiries; account/service delivery |
| Commercial/B2B | Company name, role, business contact information | Provided by you | B2B engagement and fulfillment |
| Technical Data | IP address, device type, browser, operating system | Collected automatically | Security, diagnostics, performance optimization |
| Usage Data | Pages viewed, clicks, session duration, referral source | Collected automatically | Analytics and service improvements |
| Cookies | Cookie IDs, preference flags, analytics identifiers | Device/browser | Remember settings; analytics (optional) |
4. How We Use Your Information
- Provide and operate our services: To deliver the functionality you request and maintain service quality
- Respond to inquiries and requests: To answer questions, provide support, and fulfill business communications
- Improve website performance and user experience: To analyze usage patterns, identify issues, and optimize our digital services
- Prevent fraud, abuse, and security incidents: To protect our systems, prevent unauthorized access, and maintain platform integrity
- Comply with legal obligations: To meet regulatory requirements, enforce our terms, and respond to lawful requests
- Business operations: For internal reporting, governance, auditing, and strategic planning
5. Legal Bases for Processing (GDPR)
| Purpose | Legal Basis | Plain English Explanation |
|---|---|---|
| Provide services / respond to inquiries | Contract / Steps at request of data subject | We use your data to do what you asked us to do |
| Security and fraud prevention | Legitimate interests | We protect our site, services, and users from harm |
| Compliance obligations | Legal obligation | We keep records required by law |
| Optional analytics cookies | Consent | You choose whether analytics cookies are enabled |
| Service improvements | Legitimate interests | We analyze usage to make our services better |
6. Cookies & Tracking Technologies
Cookie Categories
- Strictly Necessary: Essential for site functionality (cannot be disabled)
- Functional: Remember your preferences and settings
- Analytics: Help us understand site usage and performance (optional, requires consent)
- Marketing: Not currently used on our corporate sites
7. Data Sharing & Disclosure
Service Providers & Processors
- Cloud hosting and infrastructure providers
- Analytics and performance monitoring services
- Customer support and communication platforms
- Email delivery and marketing automation tools (if applicable)
Professional Advisers
- Legal counsel, auditors, and consultants where necessary for professional advice
Legal & Regulatory
- Government authorities, regulators, and law enforcement when required by law
- Courts and dispute resolution bodies in legal proceedings
Business Transfers
- In connection with mergers, acquisitions, or asset sales, with appropriate safeguards
8. International Data Transfers
Safeguards We Use
- Standard Contractual Clauses (SCCs): We use European Commission-approved SCCs when transferring data from the EEA
- Supplementary Measures: We implement additional technical and organizational safeguards as required
- Supplementary Measures: We implement additional technical and organizational safeguards as required
9. Data Retention
Retention Principles
- We keep data only as long as needed to provide services and fulfill legitimate business purposes
- We keep data only as long as needed to provide services and fulfill legitimate business purposes
- We maintain records necessary to resolve disputes or enforce our terms
- We securely delete or anonymize data when retention is no longer required
Typical Retention Periods
- Inquiry data: Retained for the duration of the business relationship or inquiry resolution, plus applicable statutory periods
- Technical logs: Typically retained for 12-24 months for security and diagnostic purposes
- Marketing consent: Until consent is withdrawn or contact becomes inactive
- Legal compliance records: Retained for periods required by applicable law (typically 6-7 years for business records)
10. Your Rights & Controls
GDPR Rights (EEA & UK)
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data (subject to legal limitations)
- Legal compliance records: Retained for periods required by applicable law (typically 6-7 years for business records)
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time
CCPA/CPRA Rights (California)
- Right to Know: Request disclosure of categories and specific pieces of personal information collected
- Right to Delete: Request deletion of your personal information (subject to exceptions)
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt-out of "sale" or "sharing" of personal information (not applicable as we don't sell data)
- Right to Limit: Limit use of sensitive personal information (if applicable)
- Right to Non-Discrimination: Exercise rights without receiving discriminatory treatment
Exercise Your Privacy Rights
You can submit a privacy request to access, correct, delete, or manage your personal data. We’ll verify your identity and respond within the timeframes required by law.
Verification & Processing
Depending on your location and applicable law, you may have the following rights regarding your personal information:
- GDPR: One month (extendable to three months for complex requests)
- CCPA: 45 days (extendable by 45 additional days if needed)
Authorized Agents (CCPA)
11. Security & Safeguards
Security Practices
- Access Controls: Role-based access and least privilege principles
- Encryption: Data encryption in transit (TLS) and at rest where appropriate
- Monitoring: Security monitoring, logging, and incident detection systems
- Vendor Management: Due diligence and contractual safeguards for service providers
- Incident Response: Procedures for identifying, responding to, and reporting security incidents
- Regular Reviews: Periodic security assessments and updates
12. Children's Privacy
We implement appropriate technical and organizational security measures to protect your personal information from
unauthorized access, disclosure, alteration, and destruction.
We implement appropriate technical and organizational security measures to protect your personal information from
unauthorized access, disclosure, alteration, and destruction.
13. Automated Decision-Making & Profiling
If this changes in the future, we will update this policy and provide clear information about the logic involved, the
significance, and your rights regarding such processing.
14. Policy Updates & Version Control
We do not use automated decision-making processes (including profiling) that produce legal effects or similarly
significant effects on individuals.
How We Communicate Changes
- Material Changes: We will notify you via email (if we have your contact information) or prominent notice on our website
- Minor Updates: Reflected in the "Last Updated" date at the top of this policy
- Continued Use: Your continued use of our services after updates constitutes acceptance of the revised policy
15. Contact, Complaints & Escalation
Privacy Contact Information
Postal Address
[City, State, Postal Code]
[Country]
CCPA Toll-Free Number (California Residents)
[To be provided if required]
Supervisory Authority (GDPR)
- UK: Information Commissioner's Office (ICO) - ico.org.uk
- EU Member States: Find your local authority at edpb.europa.eu