Security · Data privacy
The safest datais the data younever collected.
How Zyposoft builds software that handles personal data: collect less, show each role only what it needs, change data before it leaves, keep it only as long as agreed, and be able to show who looked.
Six habits · 1
Ask for less in the first place.
Every field has to justify itself. Optional stays optional, and anything no longer used is removed.
Six habits · 2
Send back only what was asked for.
Each role, in each situation, gets the fields it needs and nothing extra in the response.
Six habits · 3
Change it before it leaves.
Masked, coded, given a pseudonym or rolled up into totals before it goes anywhere it does not need to be whole.
Six habits · 4
Keep it as long as agreed, then stop.
Retention is set per type of record and enforced, not hoped for. Deleting is recorded too.
Six habits · 5
Be careful what leaves the building.
What each connected system receives is agreed field by field, with no convenience extras, and reviewed when it changes.
Six habits · 6
Be able to show who looked.
Every access is recorded, including refused ones, and the records can be searched and exported.
Straight answers
What we do, and what we will not.
No hedging on the things that matter most. If AI features ever draw on your data beyond serving your own work, that is a separate conversation and a separate agreement.
- We do: Hold the minimum a workflow actually needs.
- We do: Keep sensitive data inside the environment you approved.
- We do: Let you set retention per type of record.
- We do: Record every access, including refused ones.
- We do: Tell you what a connected system receives, field by field.
- We will not: Sell or broker anyone's data.
- We will not: Train AI models on your data without a separate, explicit agreement.
- We will not: Copy live data into test systems for convenience.
- We will not: Add fields to an integration because they were easy.
- We will not: Keep records past the retention you set.
Where this page stops
The questions that belong in a contract, not on a website.
- Is this your privacy policy?No. This page is how the software handles personal data. The privacy policy, covering what Zyposoft itself collects, is a separate legal document linked in the footer.
- Which regulations does this satisfy?That depends on where you operate and what you process. Bring your obligations to us and we will go through them properly, in writing.
- Who controls the data?Normally you, with us processing on your behalf. The specifics belong in the contract, because they change several other answers.
- Someone asks who looked at their record.Access records can be searched and exported, so it is a report, not an investigation. Who may run it is your decision.
Getting it right
Mostly subtraction, done on purpose.
Fewer fields collected, fewer sent back, changed before they leave, and gone when you said they would be.
- Work out what is needed: Every field, Who needs it, What can go.
- Classify it: Sensitive, Identifying, Everyday.
- Decide what each role sees: Per role, Per situation, What is masked.
- Set retention, and mean it: Per record type, How deletion is proved, Legal holds.
- Go through the integrations: What each one sends, Field by field, Who signed it off.
- Check it, then keep checking: Who has access, Sample the records, Handle requests.
Talk to us
Collect less. Show less.
Bring us the data you hold and the obligations you have. We will tell you plainly what the software needs, what it does not, and how we would prove it.
This page is about engineering practice, not legal position. Which data is held, for how long, on what legal basis, in which jurisdiction and who controls it are settled in your contract and your own data-protection assessment.