Legal

Privacy notice

Version 1.0Effective 2 September 2026Last updated 14 August 2026

A note on scope. K-Lake, the Zegress software, runs on your own infrastructure. In normal operation we do not receive, store or process the documents you connect it to. This notice therefore covers the personal data we handle as a business — website visitors, enquiries, customer contacts and support tickets — not your document estate.

1. Who we are

Zegress.Ai Limited ("Zegress", "we", "us") is a company registered in England and Wales, with its registered office in Liverpool, United Kingdom. We are the controller of the personal data described in this notice.

For any question about this notice or how we handle personal data, contact [email protected].

2. What we collect

CategoryWhat it includes
Contact dataName, work email address, job title, organisation and country, when you contact us or request a proof-of-concept.
Enquiry contentWhat you tell us in an email, form or meeting, including the details of your environment and requirements.
Support dataTicket content, logs and configuration you choose to share when you raise a support request.
Portal account dataAccount identifier, work email and authentication records for the customer portal.
Website usagePages viewed, referring source, approximate location derived from IP address, and device and browser type.
Marketing preferencesWhether you have consented to receive updates, and whether you have withdrawn that consent.

We do not deliberately collect special category data. Please do not include it in an enquiry or a support ticket.

3. Why we use it, and our lawful basis

PurposeLawful basis
Responding to enquiries and running a proof-of-conceptLegitimate interests, and steps taken at your request before entering a contract
Providing the product, support and the customer portalPerformance of a contract
Security, fraud prevention and protecting our systemsLegitimate interests
Sending marketing updates to individualsConsent, which you may withdraw at any time
Analytics and improving this websiteConsent, given through the cookie banner
Meeting legal, accounting and regulatory obligationsLegal obligation

4. Who we share it with

We share personal data only where it is necessary, and only with:

  • Service providers who help us operate, such as our email, hosting, customer relationship management and support ticketing providers, acting on our instructions.
  • Microsoft, where you transact through the Azure Marketplace, in relation to that transaction and billing.
  • Professional advisers such as our accountants and lawyers, where required.
  • Authorities, where we are legally required to do so.

We do not sell personal data, and we do not share it for third-party advertising.

The current list of sub-processors relevant to the product is published in our trust centre.

5. International transfers

We are based in the United Kingdom. Where a service provider processes personal data outside the UK or European Economic Area, we rely on an adequacy decision where one exists, or on the UK International Data Transfer Agreement or Addendum together with appropriate safeguards.

6. How long we keep it

  • Enquiries that do not become customers: up to 24 months from last contact.
  • Customer contact and contract records: for the term of the contract and 6 years afterwards, to meet legal and accounting obligations.
  • Support tickets: up to 24 months after closure.
  • Marketing consent records: until consent is withdrawn, and then a record of the withdrawal itself.
  • Website analytics: up to 14 months.

7. Your rights

Under UK GDPR you have the right to request access to your personal data, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing carried out before withdrawal.

To exercise any of these, email [email protected]. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If you are not satisfied with our response you may complain to the Information Commissioner's Office at ico.org.uk, though we would appreciate the chance to resolve it first.

8. How we protect it

We apply access control on a least-privilege basis, encrypt data in transit, restrict administrative access to named individuals, and require multi-factor authentication on our business systems. Our security posture, certification status and documentation are published in the trust centre.

9. Changes to this notice

We will update this notice when our processing changes. Where a change is material we will say so on this page and, where we hold your contact details and it is appropriate, tell you directly. The version and effective date at the top of this page always reflect the current notice.