Operating Corporate Entities: Infimatrix Inc. (Delaware, USA) & Infimatrix Technologies Private Limited (India) collectively called as Infimatrix
This Privacy Policy describes how personal data and cloud infrastructure telemetry are collected, processed, and secured when you visit www.zero-x.cloud (the “Website”) or subscribe to our cloud-native security platform applications and automated threat detection components (the “Services”).
For the purposes of applicable Data Protection Laws—including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and all amendments and guidelines issued thereunder (collectively, the “DPDPA”), the General Data Protection Regulation (GDPR) (EU) 2016/679, and UAE Federal Decree-Law No. 45 of 2021—Zero-X Cloud acts strictly as a Data Processor / Sub-fiduciary processing personal data solely on behalf of, and under the documented instructions of, the customer, who remains the Data Controller / Data Fiduciary.
We reject bundled consent mechanics. We collect and process personal data under unbundled, purpose-linked grounds strictly to provide, secure, and maintain an enterprise security platform:
Account Activation Data: Upon voluntary portal registration, we collect your name, business email address, corporate telephone number, company name, and job title. This data is used exclusively to fulfill service requests, manage subscription accounts, and handle electronic billing.
Platform Security Logs: We automatically log Internet Protocol (IP) addresses, approximate geographic location, browser variants, operating systems, and functional session tokens over encrypted HTTPS channels to analyze traffic patterns, diagnose anomalies, and secure platform infrastructure.
We deploy cookies and similar tracking technologies to enhance user experiences and monitor platform metrics. Essential functional cookies are deployed automatically, while non-essential tracking cookies require your explicit consent:
Cookie Category | Served By | Operational Purpose | Regulatory Status |
|---|---|---|---|
Strictly Necessary | Infimatrix, Inc. | Persists user secure authentication states over HTTPS and preserves cookie consent choices. | Mandatory — Cannot be disabled. |
Performance & Analytics | Google Analytics | Captures anonymized traffic patterns and UI interaction flows to diagnose server bugs. | Optional — Requires user consent. |
Targeted Advertising | Google Ads Manager | Utilizes cross-site telemetry to manage commercial product relevance and limit ad re-appearance. | Optional — Requires user consent. |
Users may modify or completely withdraw their granular consent profiles at any time without retroactive penalty via our integrated Cookie Preference Manager located in the footer of the Website.
We explicitly exclude your website interactions, connected source code, cloud configurations, or volunteered registration data from being sold to data brokers or third-party marketing networks.
In strict compliance with our corporate governance baselines, neither Customer Data, vulnerability profiles, nor platform scan results will be ingested, transferred, or utilized by Infimatrix, its subcontractors, or any third party to train, fine-tune, optimize, benchmark, or otherwise develop or improve any artificial intelligence models, large language models (LLMs), or automated remediation algorithms without the Customer’s express, standalone, prior written consent.
We retain personal data strictly for the duration required to fulfill our active commercial service obligations and statutory compliance mandates:
Account and Contact Records: Form-fill data and business interaction profiles are retained for a period of three (3) years from the date of our last recorded interaction before secure erasure.
Platform Log Telemetry: Web interaction logs and infrastructure analytics telemetry are held for a maximum of twenty-six (26) months from collection before undergoing automated destruction or absolute anonymization.
Processing data collected through our platform involves integration with premier infrastructure providers. We engage third-party infrastructure hosting companies, database managers, and analytical service entities under strict Data Processor Agreements. All such sub-processors are contractually bound to confidentiality and security frameworks no less stringent than those imposed on Infimatrix. The primary dynamically updated authorized sub-processor index is maintained at www.infimatrix.com/legal#subprocessors.
Infimatrix employs administrative, physical, and technical safeguards aligned with international ISO/IEC 27001:2022 benchmarks to shield personal data from unauthorized access, loss, or alteration. While we enforce robust encryption protocols—including TLS 1.3 in transit and AES-256 at rest—no method of transmission over the internet or system of electronic storage is completely secure. Infimatrix cannot guarantee the absolute security of website data transmissions, and any submission of information through this website is at your own risk.
Children’s Privacy Protection: Zero-X Cloud is strictly an enterprise B2B infrastructure solution. In strict compliance with the DPDPA, we do not knowingly capture, store, or process the personal data of data principals under eighteen (18) years of age.
DPDPA Grievance Escalation: All data privacy complaints or summary review requests directed to our Grievance Officer will be formally acknowledged within forty-eight (48) hours of receipt. Infimatrix covenants to resolve such issues within thirty (30) days of receipt, or within the maximum statutory timeline prescribed under the DPDPA, whichever period is shorter. Unresolved issues may be escalated to the Data Protection Board of India (DPBI).
Grievance Operations Contact: Direct all statutory requests to our centralized privacy desk at privacy@zero-x.cloud
Infimatrix reserves the right to modify this Privacy Policy at any time to reflect changing technical profiles or regulatory revisions. Changes take effect immediately upon their publication to this URL. For active subscription clients whose contact information is maintained, we will provide at least thirty (30) days’ direct written notification via email prior to the effective date of any material changes to our processing practices.
10.1 Contractual Dispute Resolution. Any commercial or contractual controversy arising strictly out of the interpretation of this Privacy Policy shall be submitted to exclusive binding arbitration in Wilmington, Delaware, USA, conducted by the American Arbitration Association (AAA) under its Commercial Arbitration Rules using a single arbitrator. All claims must be brought in your individual capacity, explicitly waiving any right to a jury trial or class action proceeding.
10.2 Statutory Regulatory Exception. The forum selection in Clause 10.1 applies strictly to commercial contract actions between the parties. It shall not apply to, limit, or abrogate the absolute statutory right of data principals to file regulatory complaints, summary reviews, or data breach notices directly with the Data Protection Board of India (DPBI) under the DPDPA, a competent EU Supervisory Authority under the GDPR, or the UAE Data Office under the UAE PDPL within their respective territorial jurisdictions.