ZARMIND Privacy Policy
1. About This Policy
ZARMIND is an independent digital design studio operated by Abouzar Alipour in British Columbia, Canada. This policy explains what personal information ZARMIND collects, why and how it is used, when it may be shared, how it is protected, and the choices and rights individuals have. ZARMIND operates online without a public office; in-person meetings are arranged in advance at the client’s location or another agreed place.
2. Scope
This policy applies to information under ZARMIND’s control through the public website, Start a Project, accounts and the Client Portal, enquiries, projects, support and account help, messages, files, documents, meetings, approvals, hello@zarmindstudio.com, and services used to provide and protect these functions. Independent client or third-party services have their own policies.
3. Privacy Officer
Abouzar Alipour is responsible for privacy matters. Email: hello@zarmindstudio.com. Do not send passwords, payment information, access keys, identity documents, or confidential information by ordinary email. A secure method will be arranged if needed.
4. Information We May Collect
Enquiries: name, email, business, region, language, website, links, needs, goals, audience, project details, content, domain, hosting, timing, approximate budget, form answers, optional files, draft data, reference and history, and the accepted Policy version.
Accounts and Portal: name, email, verification, membership, permitted records, sign-in and recovery security data, language, time zone, preferences and important access history. Passwords are not stored or displayed in readable form.
Projects and Support: messages, actions, deadlines, files, documents, versions, content, feedback, approvals, meetings, support, change requests, handover, activity history and internal notes. Internal notes are not published unless specifically prepared and shared.
Contact and technical data: name, email, subject, message and optional attachments; and infrastructure data such as IP address, request time, route, browser or device type and errors for security and operation. Non-essential analytics, behavioural advertising and profiling are not approved.
5. Sources
Information usually comes from the individual and, in limited cases, from an account invitation, referral, valid manual source, link provided for review, or an authorized client. Anyone providing another person’s information must have an appropriate purpose and authority.
6. Purpose of Use
Information is used only as reasonably necessary for drafts, enquiry review, accounts, engagements and projects, communication, meetings, files, content, feedback, approvals, support, handover, account help, general contact, necessary notices, records, security, contractual, tax and legal obligations, and privacy requests. A new incompatible purpose requires appropriate consent or legal authority.
7. Consent
Purposes are explained before or at collection. Express consent is used for sensitive, unexpected or optional processing; implied consent only where the purpose is clear and reasonably expected. An enquiry is not marketing or newsletter consent. ZARMIND has no active automated marketing list. Withdrawal may prevent a dependent service but does not remove valid legal, contractual or security obligations.
8. Sharing and Transfer
ZARMIND does not sell or provide information for behavioural advertising. Information is shared only to the extent necessary with infrastructure, email, authentication, file, backup, security, form and operations providers; necessary advisers; competent authorities; a party investigating misuse; or a party to a potential business transfer, with appropriate protection. Actual providers and processing locations are reviewed before activation and added where necessary. Processing outside Canada may be subject to the laws of that jurisdiction and does not remove ZARMIND’s responsibility.
9. AI
Personal information, client files, messages and confidential content are not entered into public AI tools merely for convenience. Future use requires independent review of necessity, provider, retention, model training, transfers and confidentiality.
10. Retention
Information is kept only while needed for its purpose, service, essential records or valid obligations. Enquiry drafts remain for 30 days after activity and no longer than 90 days from creation. Information used for a decision directly affecting an individual is retained for at least one year. Applicable tax records are generally kept for six years from the relevant tax year. Account, project and support records remain while needed for engagement, approvals, handover, disputes or obligations. Closing, deactivation and deletion are different. Backup and log periods will be set after infrastructure selection.
11. Safeguards and Incidents
ZARMIND uses safeguards reasonable for sensitivity and risk, which may include access restriction, Owner two-factor authentication, separation of internal and published information, file protection, event records, backups and secure access transfer. No online system guarantees absolute security.
Potential incidents are investigated, contained and documented. ZARMIND assesses affected information, individuals and harm and takes reasonable mitigation steps. Where required by law or useful to reduce harm, affected individuals and authorities are notified using confirmed information and without unreasonable delay.
12. Rights and Complaints
Individuals may make written requests concerning existence, access, use, disclosure, correction, consent withdrawal, deactivation, deletion, copies and complaints. Identity and authority are verified proportionately. PIPA access and correction requests are generally answered within 30 days unless a lawful extension applies. Deletion is not an absolute right to immediate removal of every record; valid limitations are explained.
Contact ZARMIND first at hello@zarmindstudio.com. Unresolved concerns may be directed to the Office of the Information and Privacy Commissioner for British Columbia:
https://www.oipc.bc.ca/for-the-public/how-do-i-make-a-complaint/13. Children, External Services and Cookies
Services are not intentionally directed at children, and a project that genuinely involves children’s information requires a separate review. External services have their own independent policies, and this Policy covers only processing under ZARMIND’s control. Essential cookies or storage may be used for security, sessions, language and basic operation; analytics, advertising, profiling and non-essential cookies are not active before review, a Policy update and consent.
14. Changes
This Policy is reviewed when there is a material change to data, purpose, service, transfer, rights or law. A material change is published before new processing begins and, where necessary, is accompanied by notice and new consent. The date, version and accepted version remain identifiable.