← All policiesLegal · UK · EU · India

Privacy Policy

How Zamit collects, uses and protects your personal data — aligned with the EU GDPR, UK GDPR & DPA 2018, and India's DPDP Act 2023.

Last updated 15 July 2026

Compliance at a glance

This policy has been reviewed for compliance with the UK Consumer Rights Act 2015 and related UK consumer-protection law, the EU & UK General Data Protection Regulation (GDPR) together with the UK Data Protection Act 2018, and India's Digital Personal Data Protection Act, 2023 (DPDP Act).

UK Consumer Rights Act 2015EU & UK GDPRIndia DPDP Act 2023
Manage cookies and tracking on this browser:Exercise your data rights

This Privacy Policy explains what personal data Zamit collects, how we use it, who we share it with, and the rights you have. It is written to conform with the EU General Data Protection Regulation (EU GDPR), the UK GDPR and Data Protection Act 2018, and India's Digital Personal Data Protection Act, 2023 (DPDP Act). The Information Commissioner's Office (ICO) is our lead supervisory authority in the UK; for India, the Data Protection Board of India is the supervisory body under the DPDP Act.

1. Data controller

Zamit (UK HQ: Venture X, Building 7, Chiswick Park, 566 Chiswick High Road, London W4 5YG) is the data controller for personal data collected through our Services. You can contact us about privacy at connect@zamit.one.

2. The data we collect

  • Identity and contact data: first name, last name, email, phone, country code, country, state and city.
  • Profile data: age band, education stage, qualification, languages, target sector, mobility preferences and stated goals.
  • Assessment data: answers, scores, CEFR bands, recordings (where applicable), and Zamit-generated roadmaps.
  • Technical data: device, browser, IP address, approximate location, cookies and similar identifiers.
  • Communications: messages you send to us, including support requests.

3. How we use your data and the legal bases / grounds

  • Contract / performance of service — to create your account, run your assessments, deliver your roadmap and provide paid services (GDPR Art. 6(1)(b); DPDP Act, performance of contract).
  • Legitimate interests / legitimate uses — to improve our products, prevent abuse, secure the platform and develop new features, balanced against your rights (GDPR Art. 6(1)(f); DPDP Act "legitimate uses" under Section 7 where applicable).
  • Consent — for optional cookies, marketing emails and other processing that requires it. Under the DPDP Act, consent is "free, specific, informed, unconditional and unambiguous" and can be withdrawn at any time.
  • Legal obligation — to meet accounting, tax, safeguarding and other legal duties in the UK, EU and India.

4. Sharing and Data Processors / Data Fiduciaries

We share personal data with vetted processors (under GDPR) and data processors acting on behalf of Zamit as the Data Fiduciary (under the DPDP Act) who help us run the Services (hosting, email, analytics, AI inference, payments). Where data is transferred outside the UK or EU/EEA, we rely on approved safeguards such as adequacy regulations, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, or the UK Addendum. Cross-border transfers from India are made only to jurisdictions permitted under the DPDP Act and applicable Government of India notifications. We do not sell your personal data.

5. Retention

We keep personal data only as long as we need it for the purposes above, or as required by law. Inactive diagnostic sessions are typically deleted within 24 months. Account and transaction records are kept for up to 7 years to meet UK, EU and Indian accounting and tax requirements. Where you withdraw consent or close your account, we erase or anonymise personal data without undue delay, subject to legal retention obligations. See our Data Deletion Policy for full details.

6. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, audit logging, principle-of-least-privilege for staff access, and regular review of our processors — consistent with Article 32 of the GDPR and the "reasonable security safeguards" obligation in Section 8(5) of the DPDP Act. No system is perfectly secure; please use a strong, unique password.

7. Your rights as a Data Subject / Data Principal

Under the EU/UK GDPR you have the rights of a "data subject"; under the DPDP Act you have equivalent rights as a "Data Principal":

  • Right to be informed (this notice).
  • Right of access to / a summary of your personal data.
  • Right to rectification of inaccurate or incomplete data.
  • Right to erasure / deletion ("right to be forgotten" under GDPR; right to erasure under Section 12 of the DPDP Act).
  • Right to restrict processing (GDPR).
  • Right to data portability (GDPR).
  • Right to object, including to direct marketing (GDPR).
  • Rights in relation to automated decision-making and profiling (GDPR).
  • Right to withdraw consent at any time (GDPR and DPDP Act).
  • Right to nominate another person to exercise your rights in the event of death or incapacity (DPDP Act, Section 14).
  • Right of grievance redressal and to approach the Data Protection Board of India (DPDP Act, Section 13 and Section 27).

To exercise any right, email connect@zamit.one. We respond within one calendar month under GDPR, and within the timelines prescribed under the DPDP Act. You also have the right to complain to the ICO (ico.org.uk), your EU lead supervisory authority, or the Data Protection Board of India.

8. Children

Where the Services are used by users under 18 we apply the ICO's Age-Appropriate Design Code and, in India, the DPDP Act requirements for processing of children's personal data — including verifiable parental consent for users under 18, data minimisation, high-privacy defaults, and a prohibition on behavioural tracking or targeted advertising directed at children.

9. Protection of personal data and platform content against scraping

Personal data on Zamit (including candidate profiles, employer and recruiter contact details, and information surfaced inside job postings or company pages) is made available only for the purposes of using the Services. We do not authorise — and you must not — and must not permit any third party or automated agent (bots, crawlers, scrapers, headless browsers, RPA tools, AI agents or LLM training pipelines) to:

  • scrape, crawl, harvest, index, mirror or systematically extract personal data, job postings, listings, company profiles, courses, assessments or any other content from the Services;
  • copy, re-post, syndicate, aggregate, resell or redistribute such content on another site, job board, dataset or app, including by "copy-by-reference", deep-linking, framing, inline-linking or any technique that re-presents Zamit content while obscuring Zamit as the source;
  • combine, enrich or cross-reference personal data obtained from Zamit with other datasets to re-identify, profile or contact individuals for purposes they have not consented to; or
  • use Zamit personal data or content to train, fine-tune, evaluate or benchmark any machine-learning or generative AI system.

Such activity is a breach of our Terms of Use and Acceptable Use Policy, infringes our database and intellectual-property rights (including under the UK Copyright and Rights in Databases Regulations 1997 and the EU Database Directive 96/9/EC), and is an unlawful processing of personal data under the EU/UK GDPR and India's DPDP Act 2023. We will enforce these protections through takedown notices, account suspension, regulatory complaints and legal action, including injunctive relief and damages.

10. Changes

We will update this notice as our processing changes. The "last updated" date at the bottom indicates when it was last revised.

This policy is maintained by Zamit and has been reviewed for compliance with the UK Consumer Rights Act 2015 and the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013, the EU General Data Protection Regulation (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, and India's Digital Personal Data Protection Act, 2023 (DPDP Act). Our supervisory authorities include the Information Commissioner's Office (ICO) in the UK, the relevant lead supervisory authority in the EU/EEA, and the Data Protection Board of India under the DPDP Act. This is not a certification. For any question contact connect@zamit.one.