Legal
Privacy notice
A note on scope. K-Lake, the Zegress software, runs on your own infrastructure. In normal operation we do not receive, store or process the documents you connect it to. This notice therefore covers the personal data we handle as a business — website visitors, enquiries, customer contacts and support tickets — not your document estate.
1. Who we are
Zegress.Ai Limited ("Zegress", "we", "us") is a company registered in England and Wales, with its registered office in Liverpool, United Kingdom. We are the controller of the personal data described in this notice.
For any question about this notice or how we handle personal data, contact [email protected].
2. What we collect
| Category | What it includes |
|---|---|
| Contact data | Name, work email address, job title, organisation and country, when you contact us or request a proof-of-concept. |
| Enquiry content | What you tell us in an email, form or meeting, including the details of your environment and requirements. |
| Support data | Ticket content, logs and configuration you choose to share when you raise a support request. |
| Portal account data | Account identifier, work email and authentication records for the customer portal. |
| Website usage | Pages viewed, referring source, approximate location derived from IP address, and device and browser type. |
| Marketing preferences | Whether you have consented to receive updates, and whether you have withdrawn that consent. |
We do not deliberately collect special category data. Please do not include it in an enquiry or a support ticket.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries and running a proof-of-concept | Legitimate interests, and steps taken at your request before entering a contract |
| Providing the product, support and the customer portal | Performance of a contract |
| Security, fraud prevention and protecting our systems | Legitimate interests |
| Sending marketing updates to individuals | Consent, which you may withdraw at any time |
| Analytics and improving this website | Consent, given through the cookie banner |
| Meeting legal, accounting and regulatory obligations | Legal obligation |
4. Who we share it with
We share personal data only where it is necessary, and only with:
- Service providers who help us operate, such as our email, hosting, customer relationship management and support ticketing providers, acting on our instructions.
- Microsoft, where you transact through the Azure Marketplace, in relation to that transaction and billing.
- Professional advisers such as our accountants and lawyers, where required.
- Authorities, where we are legally required to do so.
We do not sell personal data, and we do not share it for third-party advertising.
The current list of sub-processors relevant to the product is published in our trust centre.
5. International transfers
We are based in the United Kingdom. Where a service provider processes personal data outside the UK or European Economic Area, we rely on an adequacy decision where one exists, or on the UK International Data Transfer Agreement or Addendum together with appropriate safeguards.
6. How long we keep it
- Enquiries that do not become customers: up to 24 months from last contact.
- Customer contact and contract records: for the term of the contract and 6 years afterwards, to meet legal and accounting obligations.
- Support tickets: up to 24 months after closure.
- Marketing consent records: until consent is withdrawn, and then a record of the withdrawal itself.
- Website analytics: up to 14 months.
7. Your rights
Under UK GDPR you have the right to request access to your personal data, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing carried out before withdrawal.
To exercise any of these, email [email protected]. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are not satisfied with our response you may complain to the Information Commissioner's Office at ico.org.uk, though we would appreciate the chance to resolve it first.
8. How we protect it
We apply access control on a least-privilege basis, encrypt data in transit, restrict administrative access to named individuals, and require multi-factor authentication on our business systems. Our security posture, certification status and documentation are published in the trust centre.
9. Changes to this notice
We will update this notice when our processing changes. Where a change is material we will say so on this page and, where we hold your contact details and it is appropriate, tell you directly. The version and effective date at the top of this page always reflect the current notice.