Privacy Policy
This policy explains how Zap Fire collects, uses, shares, and protects personal data when you visit our website, when we provide services to your organisation, and when you interact with us in any other capacity. We have written it in plain language and structured it so you can find the section you need quickly. Section 16 tells you how to contact our grievance officer if you have a question or a complaint.
This policy is governed by the laws of India and, in particular, by the Digital Personal Data Protection Act, 2023 (the “DPDPA”). Where we serve clients or process data in other jurisdictions, additional protections may apply, as explained in section 15.
1. About this policy and who it applies to
This policy applies to personal data that Zap Fire processes in the course of its business, whether collected through our website, in person at your premises, over the phone, by email, through our enterprise resource planning (ERP) and AMC dashboards, or through any other channel.
It applies to personal data about:
- Visitors to our website, www.zapfire.org
- Individuals at organisations that ask us for a quote or enquire about our services
- Individuals at organisations that engage us to design, install, commission, or maintain fire safety and electronic security systems
- Individuals whose data is captured by systems we install, configure, or service on behalf of our clients (for example, biometric or card access control systems and CCTV)
- Suppliers, sub-contractors, and OEM partners
- Job applicants and our own personnel
- Anyone else who provides personal data to us or interacts with us
This policy replaces our earlier privacy policy dated 28 December 2020. If you have a question about how an earlier version applied to data we held before this version came into effect, please contact our grievance officer (section 16).
2. Who we are and how to contact us
“Zap Fire,” “we,” “us,” and “our” refer to the entity that provides fire safety, fire detection, suppression, public address and voice alarm, and electronic security services under the Zap Fire brand. Our registered details are:
- Legal entity name: Zap Fire
- Registered address: M-104, Today Blossoms II, Near Artemis Hospital, Sector-51, Gurugram, Haryana 122003, India
- Office telephone: 0124 4931885
- Alternate telephone: +91 9717304877
- Email: info@zapfire.org
- Website: www.zapfire.org
- PAN: AAAFZ5370N
- GSTIN: 06AAAFZ5370N1ZP
For privacy matters specifically, please contact our grievance officer using the details in section 16.
3. Definitions
We use a few terms from the DPDPA throughout this policy. The short definitions below are intended as a plain-language guide. The legal definitions in the DPDPA take precedence.
- Personal data: any data about an individual who is identifiable by reference to that data.
- Data principal: the individual to whom personal data relates. If you are reading this and we hold data about you, you are a data principal.
- Data fiduciary: the person or organisation that determines the purpose and means of processing personal data. Zap Fire acts as a data fiduciary for the personal data described in this policy.
- Data processor: a person or organisation that processes personal data on behalf of a data fiduciary.
- Processing: any operation on personal data, including collecting, recording, storing, organising, using, sharing, transmitting, retaining, or erasing.
- Consent: free, specific, informed, unconditional, and unambiguous agreement to processing, given by clear affirmative action.
- Legitimate use: a purpose for which the DPDPA permits processing without a fresh consent, such as performance of a contract, compliance with a law, or response to a medical emergency.
- Child: any individual under 18 years of age.
4. What personal data we collect
The personal data we collect depends on how you interact with us. The table below sets out the main categories. We will only collect data we actually need for the purposes described in section 5.
| Category | Examples |
|---|---|
| Contact and identification data | name, designation, organisation, work email, work telephone, signature on visit and acceptance documents |
| Enquiry and project data | details of the building, site, or system you ask us about; preferred response times; project scope; budgets you share with us |
| Site survey data | drawings, floor plans, photographs, system inventory, hazard maps, and notes taken during site visits |
| AMC and service data | service logs, inspection results, photo evidence captured during AMC visits, fault reports, parts replaced, and acceptance records, all tracked on our ERP |
| Communication data | emails, letters, WhatsApp messages, call records, and meeting notes exchanged with you |
| Commercial data | purchase orders, invoices, payment records, GSTINs, and bank details where you share these for billing |
| Website and device data | IP address, browser type and version, operating system, referring and exit pages, time and date of visit, clickstream, and cookie identifiers |
| Recruitment data | CVs, cover letters, qualifications, references, interview notes, and right-to-work documents for job applicants |
| Personnel data | data we hold about our employees as part of normal HR operations (see section 12 for special handling) |
| Biometric and credential data | data captured by access control systems we install or service on behalf of our clients (see section 12) |
| CCTV footage and access logs | captured by client systems we install, configure, or service (see section 12) |
We collect this data in several ways. You provide some of it directly: when you fill in a form on our website, send us an enquiry, accept a quote, sign a service report, or attend a meeting with us. Some of it is generated as a by-product of providing our services, such as the inspection logs created during an AMC visit. Some is collected automatically by our website (cookies, server logs). Some comes from third parties: your consultant or main contractor, public records, business directories, or our OEM partners.
We do not generally collect sensitive personal data such as health or financial account information beyond what is necessary for billing. Where we do encounter such data in the course of service (for example, biometric templates managed by an access control system we install for a client), we apply the special handling described in section 12.
5. How we use your personal data
We process personal data for the following purposes. Each is matched to a legal basis in section 6.
- Responding to enquiries and providing quotes: preparing surveys, designs, and proposals when you ask us about our services.
- Performing contracts: designing, installing, commissioning, modifying, and maintaining fire and security systems under our contract with you.
- Operating our AMC service: scheduling, executing, and logging AMC visits, and making the service history available to you through our ERP and dashboards.
- Compliance and certifications: preparing and submitting documentation required for fire NOC, insurance audits, OEM warranty registrations, and statutory inspections.
- Customer service and account management: answering your questions, handling complaints, sending service reminders, and managing renewals.
- Billing and finance: issuing invoices, recording payments, managing receivables, and meeting tax and accounting obligations.
- Recruitment: evaluating job applications and managing the hiring process.
- Personnel management: managing employment relationships with our team.
- Website operation and security: running our website, analysing how it is used, protecting against fraud and abuse, and keeping the website and our systems secure.
- Improving our services: analysing service patterns, equipment performance, and customer feedback to improve our offerings.
- Marketing and communications: where you have asked to hear from us, sending newsletters, service updates, and information about new offerings. You can unsubscribe at any time.
- Legal claims and disputes: establishing, exercising, or defending legal claims, and complying with court orders and regulatory requests.
6. Legal basis under the DPDPA
Under the DPDPA, we may only process personal data with your consent or for a legitimate use recognised by the law. We rely on the bases set out below.
6.1 Consent
We rely on your consent where you actively provide personal data through our website forms or otherwise opt in, for example by subscribing to our newsletter or agreeing to receive marketing communications. When we ask for your consent, we will tell you what we plan to do with your data and how to withdraw consent. You can withdraw consent at any time using the contacts in section 16. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6.2 Legitimate uses
We also rely on the legitimate uses recognised by Section 7 of the DPDPA, including:
- Performance of, or steps to enter into, a contract with you or your organisation
- Compliance with judgments, decrees, orders, or any law in force in India
- Responding to a medical emergency involving a threat to the life or health of you or another individual
- Measures to provide medical treatment or health services during an epidemic, outbreak, or threat to public health
- Measures to provide safety or assistance during a disaster or breakdown of public order
- Employment-related purposes for our personnel
Where required by law, we will identify the specific legitimate use we are relying on if you ask.
7. How we share personal data
We do not sell personal data. We share it only with the parties listed below, and only to the extent necessary for the purpose described.
7.1 Our personnel and contractors
Zap Fire engineers, project managers, account managers, and authorised contractors process personal data on a need-to-know basis to provide our services. Contractors are bound by written confidentiality and data protection obligations equivalent to ours.
7.2 OEM partners
Some of the equipment we supply requires registration of installations with the original equipment manufacturer for warranty, certification, or licensing. Where this is the case, we share the minimum personal data necessary (typically the client organisation name and a primary contact) with the OEM partner. Our OEM partners include manufacturers of fire alarm panels, sprinkler equipment, voice alarm controllers, aspirating smoke detection products, access control hardware, and CCTV systems.
7.3 Sub-contractors and partner contractors
For sites outside Delhi NCR or for specialist tasks, we engage partner contractors. They receive only the data needed to perform their part of the work and are bound by written confidentiality and data protection obligations.
7.4 Service providers
We rely on third-party service providers for cloud hosting, email, website analytics, ERP, payment processing, accounting, and communications. Each is bound by a contract that restricts their use of personal data to the services they perform for us.
7.5 Consultants and main contractors
When you engage us via a fire safety consultant or a main contractor (for example, on a new construction project), we share project-related data with them as required for the project.
7.6 Government and regulators
We share data with fire departments, state authorities, statutory regulators, and tax authorities when required by law, for example in connection with fire NOC applications, GST returns, or inspections.
7.7 Insurance underwriters and auditors
Where your insurer or an external auditor inspects the systems we have installed or maintain, we share the records they need.
7.8 Legal advisors and law enforcement
We share data with our legal advisors when needed, and with law enforcement, courts, or regulators where we are required to do so by law or where we believe disclosure is necessary to protect rights, safety, or property.
7.9 In a corporate transaction
If we sell or transfer all or part of our business, personal data may be transferred to the buyer or successor entity. We will tell affected data principals before any such transfer takes place, to the extent required by law.
8. International transfers
Zap Fire operates from India and most of the personal data we process stays in India. Some processing happens outside India, typically because:
- A cloud service provider we use stores or processes data in data centres located outside India
- An OEM partner is headquartered outside India and requires installation data for warranty or licensing
- A multinational client has its global procurement, accounts payable, or compliance functions outside India
Where we transfer personal data outside India, we do so in line with the conditions set out in Section 16 of the DPDPA and any rules notified by the Central Government from time to time. We will not transfer personal data to a country, region, or entity to which a transfer has been restricted by the Central Government.
9. How long we keep personal data
We retain personal data only as long as we need it for the purpose for which it was collected, and to meet our legal, tax, accounting, and contractual obligations. After that, we either delete it or anonymise it so it can no longer be linked to an individual.
The retention periods below are indicative. They may be extended where law requires or where a dispute, regulatory matter, or contractual obligation makes it necessary.
| Category | Indicative retention |
|---|---|
| Website enquiry data (where no contract follows) | 12 months from the date of enquiry |
| Cookies | as set out in section 13 |
| Quotes, proposals, and pre-contract correspondence | 24 months from the date of the quote, or until contract conclusion if longer |
| Project and AMC records (including drawings, BOQs, commissioning reports, inspection logs) | the duration of the contract, plus 8 years after the end of the contract or the last service event, whichever is later |
| Invoicing and tax records | 8 years, in line with the Income-tax Act and applicable GST rules |
| Recruitment data (unsuccessful candidates) | 12 months from the close of the recruitment exercise |
| Personnel data | the duration of employment, plus the period required by labour and tax law |
| CCTV footage on client sites | as configured by the client; Zap Fire retains only short-term access during service |
| Biometric and credential data on client access control systems | as configured by the client; Zap Fire does not maintain its own copy beyond what is needed for the specific service activity |
| Email and call records | 36 months, unless tied to a longer retention category above |
10. How we protect personal data
We take reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, and destruction. Our security measures include the following, applied proportionately to the sensitivity of the data and the risks involved.
10.1 Technical measures
- Encryption of data in transit on our website and in transactional emails where supported
- Access control on our ERP and shared drives, with role-based permissions
- Multi-factor authentication on administrative accounts
- Regular backups of business-critical data
- Anti-malware controls and patch management on our systems
- Logging and monitoring of access to systems that hold personal data
10.2 Organisational measures
- Written confidentiality obligations for all personnel and contractors
- Need-to-know access to project and client files
- Joiner, mover, and leaver procedures so access matches role
- Training for staff on data protection and information security
- Vendor due diligence and written data protection clauses in contracts with processors
- Incident response procedures for suspected or actual data breaches
10.3 Physical measures
- Locked storage for paper records at our office
- Restricted access to areas where servers and active records are held
- Secure handling and disposal of records and physical media at the end of their retention period
No system is completely secure. We continue to review and improve our measures. If you become aware of a security issue with our website or any data we hold, please contact our grievance officer.
11. Your rights as a data principal
The DPDPA gives you the following rights. You can exercise them by contacting our grievance officer (section 16). We will respond as soon as practicable, and in any case within the timeframes set by law.
11.1 Right to information about processing
You can ask us to confirm whether we are processing your personal data, and to give you a summary of the personal data we process and the processing activities involved.
11.2 Right to correction and erasure
You can ask us to correct inaccurate or misleading personal data, complete incomplete personal data, update personal data, and erase personal data that is no longer necessary for the purpose for which it was collected, subject to legal exceptions.
11.3 Right of grievance redressal
You can complain to our grievance officer about how we process your personal data. We will respond within the timelines set by law. If you remain dissatisfied, you can approach the Data Protection Board of India established under the DPDPA.
11.4 Right to nominate
You can nominate another individual to exercise your rights under the DPDPA in the event of your death or incapacity. We will provide a nomination form on request.
11.5 Right to withdraw consent
Where we rely on your consent, you can withdraw it at any time. Withdrawal does not affect processing already carried out, and we may still rely on other legal bases (such as legal obligation) to continue some processing.
11.6 Right to object to marketing
You can ask us not to send you marketing communications at any time, by emailing info@zapfire.org with “Unsubscribe” in the subject line or by using the unsubscribe link in any marketing email.
11.7 How to verify your identity
To protect your personal data, we may ask you to verify your identity before we act on a request. We will only use the verification information for that purpose.
12. Special handling of sensitive data and client systems
Some of the data we encounter in our work needs special treatment beyond the general controls in section 10.
12.1 Biometric and credential data on access control systems
When we install, configure, or service biometric or card-based access control systems for a client, the client is the data fiduciary for the personal data captured by those systems. We act as a data processor in that context, under the client’s instructions. We do not enrol, copy, export, or retain biometric templates, card numbers, or credential data for any purpose other than performing the specific service the client has engaged us for.
Where we maintain configuration backups for AMC purposes, we encrypt them and treat them as confidential client data. We delete them when no longer required for service.
12.2 CCTV footage and access logs on client systems
We may access CCTV footage and access control logs on client systems during commissioning, fault diagnosis, or AMC. The client owns and controls this footage; we access it only with the client’s authority and only for service purposes. We do not retain copies.
12.3 Drawings, floor plans, and security-sensitive site information
Floor plans, riser drawings, hazard maps, system inventories, and other documents we receive or create describe the security and safety arrangements of your site. We treat all such documents as confidential. They are stored on access-controlled systems, shared only with personnel and contractors who need them, and not used for marketing or any purpose unrelated to the contract.
12.4 Personnel data
HR data about our team is processed under separate internal policies that align with this policy and with applicable labour and tax law. Personnel can refer to those internal policies and contact HR for details.
12.5 Children
Our services are not directed at children. We do not knowingly collect personal data from a child (anyone under 18) without verifiable consent from a parent or lawful guardian. If we learn that we have collected personal data from a child without such consent, we will delete it. If you believe a child has provided personal data to us, please contact our grievance officer so we can take appropriate action.
Where the law requires verifiable consent of a parent or lawful guardian, we will obtain it before processing. We will not undertake processing that is likely to cause any detrimental effect on the well-being of a child, and we will not engage in tracking, behavioural monitoring of children, or targeted advertising directed at children.
13. Cookies and website tracking
Our website uses cookies and similar technologies to operate the site and analyse how it is used. A cookie is a small text file that a website places on your device. We use the categories below.
| Category | Purpose | Typical retention |
|---|---|---|
| Strictly necessary | Enabling core website functionality (page navigation, forms, security). The site will not work properly without these. | Session or up to 12 months |
| Performance and analytics | Helping us understand how visitors use the site (pages visited, time on page) so we can improve it. We use a standard analytics provider (such as Google Analytics). | Up to 24 months |
| Functional | Remembering your preferences (such as region or language) to give you a more consistent experience. | Up to 12 months |
| Marketing (if and when used) | Measuring the effectiveness of any campaigns we run, and tailoring messages on platforms where we advertise. We will only use marketing cookies with your prior consent through our cookie banner. | Up to 13 months |
You can manage cookies through the settings in your browser. You can also block third-party cookies and clear cookies that are already stored. Blocking strictly necessary cookies may affect how the site works for you. Where we use marketing cookies, we will obtain your consent through a cookie banner before placing them.
Our website may include links to third-party websites or social media platforms (such as Facebook, Twitter, Google, and Instagram). Once you click on a link to a third-party site, this policy no longer applies. We are not responsible for the privacy practices of those sites and encourage you to read their privacy notices.
14. Data breach notification
If we become aware of a personal data breach that is likely to result in harm to data principals, we will:
- Take immediate steps to contain the breach and limit its effect
- Notify the Data Protection Board of India in the manner and within the timeframe set out in the DPDPA and any rules made under it
- Notify affected data principals where required, with information about the nature of the breach, the data involved, the likely consequences, and the steps we are taking
- Investigate the root cause and put measures in place to prevent recurrence
We maintain an incident log and review it regularly.
15. Multinational clients and other jurisdictions
Some of our clients operate across multiple jurisdictions. Where personal data we process is also subject to a foreign data protection law, we will treat that data in accordance with the higher of the two standards, to the extent practicable.
15.1 European Economic Area and the United Kingdom
If you are based in the European Economic Area or the United Kingdom and the General Data Protection Regulation or UK GDPR applies to your personal data, you have additional rights under those laws, including the right to lodge a complaint with your national data protection authority. The rights described in section 11 broadly map to the corresponding GDPR and UK GDPR rights of access, rectification, erasure, restriction of processing, objection, and data portability. Where the GDPR or UK GDPR applies, we will identify the legal basis for processing in the equivalent terms.
15.2 Other jurisdictions
Where another data protection law applies, please contact us through section 16 and we will explain how we handle requests under that law.
16. Grievance officer and how to complain
If you have a question about this policy, or a complaint about how we have handled your personal data, please contact our grievance officer. We will acknowledge your communication and respond within the timeframe set by the DPDPA and applicable rules.
- Name: Amit Tyagi
- Designation: Grievance Officer
- Address: Zap Fire, M-104, Today Blossoms II, Near Artemis Hospital, Sector-51, Gurugram, Haryana 122018, India
- Email: info@zapfire.org (please mark the subject line “Privacy: Attention Grievance Officer”)
- Telephone: 0124 4931885
If you are not satisfied with our response, you may approach the Data Protection Board of India established under the DPDPA. Information about the Board, and how to refer a matter to it, will be published by the Ministry of Electronics and Information Technology.
17. Changes to this policy
We may update this policy from time to time to reflect changes in our services, the law, or our practices. When we do, we will update the effective date at the top of this policy. If the changes are material, we will draw them to your attention through a notice on our website or, where appropriate, by direct communication. We encourage you to check this page periodically to stay informed about how we protect personal data.
This policy is provided in English. If you would like a translation into Hindi or another language, please contact us.