Last updated: 19 April 2026
Please note: This page is provided in good faith. For specific legal advice tailored to your situation, please consult a qualified solicitor.
This page provides a reference overview of Zempotis Ltd's legal and compliance posture. It is intended to assist clients and prospective clients in conducting due diligence. For documentation requests or compliance enquiries, please contact us at hello@zempotis.co.uk.
1. UK GDPR and Data Protection Act 2018
Zempotis Ltd is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 in all aspects of our data processing activities. Our approach includes:
- Processing personal data only for specified, explicit, and legitimate purposes
- Collecting only the minimum data necessary for those purposes (data minimisation)
- Keeping personal data accurate, up to date, and securely stored
- Retaining data only for as long as necessary, in accordance with our data retention schedule
- Implementing appropriate technical and organisational security measures
- Honouring data subject rights as required by law, including the rights of access, rectification, erasure, and objection
- Entering into Data Processing Agreements (DPAs) with sub-processors where required
Full details of our data processing practices are set out in our Privacy Policy.
2. ICO Registration
Our Information Commissioner's Office (ICO) registration status is: [to be confirmed].
This section will be updated once registration is in place. You can verify the registration status of any UK organisation via the ICO's public register at ico.org.uk.
3. Data Processors and Sub-Processors
We use the following third-party data processors and sub-processors in the delivery of our website and services. All processors operate under appropriate contractual safeguards.
| Provider | Role | Data processed | Location |
|---|---|---|---|
| Vercel | Website hosting and infrastructure | IP addresses, access logs, request metadata | USA (SCCs in place) |
| Resend | Transactional email delivery | Contact form data, recipient email address | USA (SCCs in place) |
| Google Analytics | Website analytics | Anonymised usage and session data | USA (SCCs in place) |
| [Chatbot provider] | AI chatbot functionality | Chatbot conversation data | [To be confirmed] |
A complete and current sub-processor list is available on request. Contact us at hello@zempotis.co.uk.
4. Data Retention Periods
We retain personal data in accordance with the following schedule. Brackets indicate values that are pending confirmation and will be updated once finalised.
| Data type | Retention period |
|---|---|
| Contact form enquiries (non-client) | [X months] from date of enquiry |
| Client records — financial | [7 years] in accordance with HMRC requirements |
| Client project records | [X years] from end of engagement |
| Website analytics data | [X months] as configured in Google Analytics |
| Server access logs | [X days] as retained by Vercel |
Retention periods may be extended where data is required to defend or pursue legal claims.
5. Data Breach Procedure
In the event of a personal data breach, Zempotis Ltd will follow the following procedure:
- Identify, contain, and assess the breach as quickly as reasonably practicable
- Assess the likely risk and impact on affected individuals' rights and freedoms
- Notify the ICO within 72 hours if the breach is likely to result in a risk to individuals' rights and freedoms, in accordance with UK GDPR Article 33
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms, in accordance with UK GDPR Article 34
- Document the breach, our assessment, and all remediation steps taken in our internal breach register
To report a suspected data security concern, contact us immediately at hello@zempotis.co.uk.
6. Due Diligence Documentation
The following documentation is available to clients and prospective clients on written request:
- Data Processing Agreement (DPA) — for engagements where Zempotis processes personal data on your behalf as a data processor
- Sub-processor list — a current, itemised list of all third-party providers we use in the delivery of our services
- Security overview — a summary of our technical and organisational security measures
To request any of these documents, please contact hello@zempotis.co.uk with the subject line “Due Diligence Request”. We aim to respond within [5] business days.
7. Business Continuity
We take reasonable measures to ensure the continued availability and resilience of our services. Our website infrastructure is provided by Vercel, which operates a globally distributed, high-availability platform with built-in redundancy.
In the event of a significant service disruption affecting clients, we will communicate with affected parties without undue delay, providing details of the issue and our remediation steps.
8. Professional Standards and Ethical AI Use
Zempotis designs, builds, and deploys AI-powered tools on behalf of clients. We are committed to the following principles in all AI implementations:
- Transparency: End users are informed — either via interface design or explicit disclosure — when they are interacting with an AI system rather than a human
- Accuracy: AI systems are trained, tested, and monitored for quality, relevance, and appropriateness to their intended use
- Human oversight: All AI deployments include defined escalation paths to human agents for situations the AI cannot or should not handle autonomously
- Data minimisation: AI systems are configured to collect only the data necessary for their intended function
- No harmful use: We do not build AI systems intended for deceptive, discriminatory, or unlawful purposes, and reserve the right to decline engagements that conflict with these principles
9. Compliance Enquiries and DPA Requests
For all compliance-related enquiries, data subject access requests, or to request a Data Processing Agreement, please contact:
- Company: Zempotis Ltd
- Email: hello@zempotis.co.uk
We aim to acknowledge all compliance enquiries within [2] business days and to respond fully within [5] business days.