← All policiesLegal · UK · EU · India

Data Deletion Policy

How you can request deletion of your account and personal data — and how Zamit erases data under the EU/UK GDPR and India's DPDP Act 2023.

Last updated 15 July 2026

Compliance at a glance

This policy has been reviewed for compliance with the UK Consumer Rights Act 2015 and related UK consumer-protection law, the EU & UK General Data Protection Regulation (GDPR) together with the UK Data Protection Act 2018, and India's Digital Personal Data Protection Act, 2023 (DPDP Act).

UK Consumer Rights Act 2015EU & UK GDPRIndia DPDP Act 2023
Manage cookies and tracking on this browser:Exercise your data rights

This Data Deletion Policy explains how Zamit handles requests to delete personal data, and how we automatically erase data when it is no longer required. It implements the right to erasure under Article 17 of the EU/UK GDPR ("right to be forgotten") and the right to erasure of personal data under Section 12(3) of India's Digital Personal Data Protection Act, 2023 (DPDP Act).

1. What you can request

  • Deletion of your Zamit account and login.
  • Erasure of your profile, assessment answers, scores, recordings and generated roadmaps.
  • Deletion of uploaded documents and CVs.
  • Removal of messages you have sent through the platform (subject to other participants' records).
  • Withdrawal of consent to optional processing such as marketing or analytics cookies.

2. How to request deletion

You can request deletion in any of the following ways:

  • From inside your account: Settings → Privacy → Delete my account (where available).
  • By email to connect@zamit.one with the subject line "Data deletion request".
  • By writing to our Grievance Officer / Data Protection contact at the same email address (acting as the contact point required under Section 8(9) of the DPDP Act).

We may ask you to verify your identity before acting on a request, to protect your account from unauthorised deletion.

3. Our response timelines

  • We acknowledge every deletion request within 7 days.
  • We complete verified deletions within 30 days — meeting the one-calendar-month timeline under EU/UK GDPR and the prescribed timelines under the DPDP Act.
  • If a request is complex or we need more time, we will tell you why and give an expected date.

4. What is deleted, and what is retained

On a verified deletion request we erase or irreversibly anonymise personal data held about you across our production systems. Some information may be retained for a limited period where we are legally required or permitted to do so, including:

  • Financial / tax records — invoices and payment records kept for up to 7 years under UK, EU and Indian accounting and tax law.
  • Fraud, safety and abuse logs — limited records to prevent re-registration of abusive accounts and to defend legal claims.
  • Aggregated / anonymised data — statistics that no longer identify you may be retained for research and product improvement.
  • Backups — encrypted backups are overwritten on a rolling schedule, typically within 35 days, after which the data is no longer recoverable.
  • Issued credentials — issued certificates and credentials may be retained in a tamper-evident verification record; we will remove personal identifiers on request where this does not break the integrity of the credential.

5. Automatic deletion

  • Inactive diagnostic sessions are deleted automatically within 24 months.
  • Accounts that remain unverified are deleted within 30 days.
  • Accounts inactive for 36 consecutive months may be deleted after we have given you reasonable advance notice.
  • Documents in your private vault are deleted when you delete them or close your account, whichever is earlier.

6. Third parties and data processors

When we delete your data, we instruct our data processors (hosting, email, analytics, AI inference, payments) to delete or anonymise the corresponding records in line with their contracted retention schedules. We do not sell personal data to third parties.

7. Withdrawal of consent

You can withdraw consent for optional processing at any time without affecting the lawfulness of processing carried out before withdrawal. Where consent was the only basis for processing, withdrawal triggers deletion of the affected data under Section 12(3) of the DPDP Act and Article 17 of the GDPR.

8. Children's data

A parent or legal guardian may request deletion of a child's data on the child's behalf. We will action verified requests promptly in line with the ICO Age-Appropriate Design Code and Section 9 of the DPDP Act.

9. Complaints

If you believe we have not met our deletion obligations, you may complain to the Information Commissioner's Office (ICO) at ico.org.uk, your EU/EEA lead supervisory authority, or the Data Protection Board of India under Section 27 of the DPDP Act.

This policy is maintained by Zamit and has been reviewed for compliance with the UK Consumer Rights Act 2015 and the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013, the EU General Data Protection Regulation (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, and India's Digital Personal Data Protection Act, 2023 (DPDP Act). Our supervisory authorities include the Information Commissioner's Office (ICO) in the UK, the relevant lead supervisory authority in the EU/EEA, and the Data Protection Board of India under the DPDP Act. This is not a certification. For any question contact connect@zamit.one.