ZyCloud Privacy Policy
Effective: 2026-05-08 Operator: Zyqual Ltd, a company incorporated in Jamaica. Contact: privacy@zyqual.com.
Plain English. We will tell you exactly what we collect, why, and what we do with it. If anything here is unclear, email us.
For the engineering posture behind this policy, see docs/07-PRIVACY_AND_DPA.md. For the subprocessor list, see SUBPROCESSORS.md.
1. Who is the controller of your data?
You are. ZyCloud is the data processor — we hold the data on your behalf and follow your instructions. For school accounts (Educator tier), the school is usually the controller; the teacher is the user.
Zyqual Ltd processes your data on your instructions, under the Jamaica Data Protection Act and the principles in this policy.
2. What we collect
| Category | What | Why |
|---|---|---|
| Identity | email, display name | so you can log in and we can address you |
| Account | password (hashed), tokens | to keep your account yours |
| Plan and billing | plan, last 4 of card via Stripe, billing country | to process subscriptions |
| Files | the files you upload | because that's the product |
| File metadata | filename, size, mime type, sha256 | to make the product work |
| Usage logs | IP, user-agent, action timestamps | to detect abuse, debug issues, and show you your activity |
| AI embeddings (Pro+) | vectors derived from file contents | to power AI search |
We do not collect anything we don't need.
3. How we use your data
- To provide ZyCloud. Storage, sharing, search, sync.
- To bill you. Via Stripe. Stripe holds your full card details, not us.
- To keep ZyCloud safe. Rate limits, abuse defence, fraud detection.
- To support you. When you email support, we look at your account.
- To send you transactional email. Receipts, password resets, share notifications, quota warnings. You cannot opt out of these — they are part of the service.
- To send you marketing email. Only if you opt in. Granular and revocable.
We do not sell your data. We do not share it with advertisers. We do not train AI models on your file contents.
4. Where your data lives
We use trusted third parties to operate ZyCloud. The full list with regions is at SUBPROCESSORS.md. Headlines:
- Object storage — currently AWS S3 (US-East). A 90-day Cloudflare R2 trial routes 10% of new uploads to R2's regional EU/US edges. We update this page if the trial promotes R2 to default.
- Database, application servers — US-East, dedicated hosts.
- Email — Resend (US).
- Payments — Stripe (US).
- AI embeddings (Pro+) — OpenAI (US). We send only the file contents needed to generate the embedding; OpenAI does not retain the content.
International transfers are governed by each subprocessor's standard contractual clauses or equivalent.
5. How long we keep your data
| Data | Retention |
|---|---|
| Your files | until you delete them, plus 30 days in trash |
| Account | until you delete it, plus 30 days grace |
| Audit logs (Free / Starter / Plus / Pro) | 13 months |
| Audit logs (Educator) | indefinitely or as you configure |
| AI embeddings | until the file is deleted |
| Backups | up to 35 days, encrypted |
| Support tickets | 24 months |
After deletion, we hard-delete from object storage with provider-side verification.
6. Your rights
Under the Jamaica Data Protection Act and equivalent regimes, you have the right to:
- Access your data — "Export my data" in account settings.
- Correct your data — settings page or email us.
- Delete your data — "Delete account" in settings, 30-day grace.
- Restrict processing — email privacy@zyqual.com.
- Object to legitimate-interests processing — email us.
- Port your data — same flow as access; standard formats.
- Withdraw consent for any optional processing — settings page.
- Complain to the Information Commissioner of Jamaica (3 Surbiton Road, Kingston 10).
We respond within 30 days. Free for the first request per year per person.
7. Security
See docs/06-SECURITY.md for the engineering detail. Headlines: TLS 1.3 only; AES-256 at rest; argon2id passwords; quarterly key rotation; ClamAV scanning; signed share links; full audit log.
If you find a vulnerability, email security@zyqual.com. We respond within 24h.
8. Cookies
We use a small number of strictly-necessary cookies for sign-in and CSRF protection. We do not use third-party advertising or tracking cookies on the marketing site or the app. Detail in COOKIE_POLICY.md.
9. Children
ZyCloud is a workplace tool for teachers. We do not offer student-facing accounts. If you are under 16 and using ZyCloud, please ask an adult to manage the account.
10. Changes to this policy
We will publish material changes 30 days before they take effect. For Educator-tier customers we email the change directly. The current version is always at cloud.zyqual.com/legal/privacy.
11. Contact
- Privacy: privacy@zyqual.com
- Security: security@zyqual.com
- General: info@zyqual.com
- Postal: <!-- TODO: confirm with Leon — Zyqual Ltd registered postal address. -->
Last updated: 2026-05-08 Owner: Leon Pennicooke Source: Adapted from ZyPortfolio Track 7 with ZyCloud-specific subprocessors.