Zaivit trust centre

Trust should be
inspectable.

This page separates current website behaviour, engagement practices, and independent assurance. It avoids implying certifications or controls that have not been verified.

WEBSITE TRACKINGCookieless by default
FORM TRANSMISSIONNone
CERTIFICATIONS CLAIMEDNone
LAST REVIEWED

CURRENT WEBSITE STATE

The public site is private by default.

The current site is static. It uses no advertising pixels, no externally hosted fonts, no account systems, and no server-side enquiry forms. The product brief is generated entirely in the browser and leaves the device only when a visitor deliberately copies or downloads it.

Two measurement tools are in scope, and they are not governed the same way. Cloudflare Web Analytics records page views and performance without setting a cookie, without reading device storage, and without collecting personal data. Because it identifies nobody, there is nothing to consent to and nothing to opt out of. Google Analytics sets cookies, so it does not run at all until a visitor accepts it, and declining costs the visitor nothing. Both are described in full under the privacy notice.

Before contact collection is enabledA verified legal entity, contact channel, retention policy, processor list, and lawful basis must be published here.

DELIVERY SECURITY

Controls are scoped, assigned, and evidenced.

For each engagement, the applicable delivery plan should identify owners, tools, evidence, exceptions, and review points for:

  • Architecture and trust-boundary review
  • Repository, branch, and review protection
  • Secret and environment configuration management
  • Dependency and vulnerability checks
  • Functional, accessibility, and performance validation
  • Logging, monitoring, deployment, and rollback readiness
  • Decision records, exceptions, and residual-risk acceptance

These are engagement practices, not claims that every control applies to every product or that Zaivit currently holds a security certification.

DATA HANDLING PRINCIPLES

Use the minimum access necessary.

01

Purpose bound

Access is linked to defined work and removed when no longer required.

02

Client controlled

Client-managed repositories, environments, and identity are preferred where practical.

03

Explicit retention

Copies, logs, artifacts, and deletion responsibilities are agreed before processing.

04

Portable evidence

Relevant delivery records and operating knowledge are prepared for client ownership.

ASSURANCE BOUNDARIES

Readiness is not certification.

Zaivit can translate relevant requirements from frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and WCAG into technical controls and delivery evidence when they are within the agreed scope. Independent assessors issue certifications and audit opinions. Qualified legal counsel determines legal compliance.

PROCUREMENT CHECKLIST

Important terms should be explicit—not assumed.

Before an engagement begins, the parties should confirm legal identity, scope, ownership, confidentiality, access, data handling, subprocessors, retention, service expectations, incident contacts, insurance, and exit responsibilities. The applicable terms depend on the work and must be agreed in signed documents.

Download the evaluation checklist

PRIVACY NOTICE

What is measured, and what you can refuse.

Zaivit does not receive the selections entered in the brief builder. The brief is assembled in the browser and is never transmitted, whatever you decide below.

Cloudflare Web Analytics — no cookie, no choice required

When it is active, Cloudflare Web Analytics records page views, referring pages, approximate country, and page-performance timings. It sets no cookie, reads nothing from your device, and produces no identifier that follows you between sites or sessions. Zaivit sees aggregate counts only. The lawful basis is legitimate interest in knowing which pages of its own site are useful, which is why there is nothing here to opt out of — there is no personal data to withhold.

Google Analytics — cookies, and only if you accept

Google Analytics is loaded only after an explicit acceptance. Until then, and permanently if you decline, no Google script is requested and no Google cookie is set. There is no pre-consent signal of any kind. Accepting sets these cookies:

Cookies set by Google Analytics after acceptance
NamePurposeDuration
_gaDistinguishes one browser from another so repeat visits are not counted as new ones.2 years
_ga_<id>Holds the session state for this specific property.2 years

Where Google Analytics is active it is configured with IP anonymisation on and Google advertising signals off, so the data is not used to build advertising audiences.

Your choice, and how to change it

Your decision is kept in your browser's local storage under zaivit-consent. That entry exists only to remember the answer so you are not asked repeatedly; it is not a cookie, is never sent to a server, and is removed when you clear the choice. If your browser blocks storage, the choice cannot be remembered and Google Analytics stays off.

Clearing your choice stops Google Analytics from loading on the next page load. A tag already running in the current tab stops when the page is reloaded. Deleting cookies already set is done in your browser's own settings.

Who processes what

Cloudflare, Inc. hosts the site and provides Web Analytics. Google LLC provides Google Analytics, and only for visitors who accept it. Both operate global networks, so this processing may occur outside India.

Hosting

The site is hosted on Cloudflare Pages. To serve and protect it, Cloudflare processes request metadata such as IP address, user agent, and requested URL under its own terms. Zaivit runs no server of its own and receives no identifiable visitor logs.

Getting in touch

Two channels reach Zaivit: the email address and the WhatsApp number published on this site. Neither is a form on this site, and nothing you type into the brief builder is part of either.

Write by email and Zaivit receives your address and whatever you choose to include, and uses it only to respond. It is kept only for as long as the enquiry and any resulting engagement require.

Message the WhatsApp number and the message is carried by WhatsApp, operated by Meta Platforms, under Meta's own terms rather than Zaivit's. Zaivit receives your phone number, your WhatsApp profile name, and what you send. What Meta itself retains about that exchange is outside Zaivit's control and not something Zaivit can undertake to delete. If you would rather not involve a Meta service, email reaches the same people and is the better channel for anything sensitive.

To ask what is held, to request correction or deletion, or to raise a grievance, write to the published email address.

ACCESSIBILITY

Accessibility is part of release readiness.

The site uses semantic landmarks, keyboard-operable controls, visible focus, labelled form fields, responsive layouts, and reduced-motion support. It has been checked at 375, 768, 1024, and 1440 pixel widths. This is not an independent WCAG conformance audit.

WEBSITE TERMS

Information, not a contractual offer.

Website descriptions, sample artifacts, engagement horizons, and framework references are informational. Commercial scope, responsibilities, fees, service levels, intellectual-property terms, warranties, and data-processing terms must be agreed in signed engagement documents. Sample artifacts may be reused for evaluation but must not be presented as customer evidence.