Privacy Policy

What personal data the Zymiq client portal collects, why, who it is shared with — including the laboratories you send requests to — and the choices you have.

Version 2026-09-22 · Last updated 22 September 2026

1. Who is responsible

Zymiq Softwares Private Limited, of 76 Shiv Vatika, Lasudia Mori, Vijay Nagar, Indore, Madhya Pradesh 452010, India, is the controller of the personal data described here. You can reach us at info@zymiq.io.

Our Grievance Officer under the Digital Personal Data Protection Act, 2023 is Prateek Sharma, who can be reached at info@zymiq.io or on +91 85869 31454. If you are not satisfied with how we have handled a request or a complaint about your personal data, write to the Grievance Officer; if you remain dissatisfied, you may complain to the Data Protection Board of India.

2. What we collect

  • Account data — your name, work email, company, phone number, and a hash of your password. We never store your password itself.
  • Requests and enquiries — the project details, sample descriptions, standards, dates and notes you enter, and which laboratory you addressed them to.
  • Messages — what you and a laboratory write to each other about a request.
  • Results and reports — the reports a laboratory issues to you, and the progress of the work.
  • Technical data — IP address, browser and device type, and the pages you visit, recorded in server logs so that we can run and secure the service.
  • Analytics — if you consent to it. See § 8.
  • Visitor counts — one-way fingerprints of your connection, used only to avoid counting the same visitor twice in the same day or the same month. They cannot be traced back to you and are described in § 8.

3. Why we use it, and on what basis

  • To run your account and let you sign in — because we need to, to give you the service you asked for.
  • To pass your requests, messages and contact details to the laboratory you addressed — again, to perform the service; this is the point of the portal.
  • To show you your jobs and reports — same basis.
  • To send service emails (verification, password reset, a question from a laboratory, a report being ready) — same basis. These are not marketing and you cannot unsubscribe from all of them while you hold an account.
  • To keep the service secure, prevent abuse, and keep records we are required to keep — our legitimate interest, and in places a legal obligation.
  • To understand how the portal is used, through analytics — only with your consent, which you can withdraw at any time.

4. Who we share it with

The laboratory you send a request to. This is the substance of the service: your name, company, contact details, the request, your messages and your samples' details go to that laboratory, which becomes a controller of them in its own right and handles them under its own policy and its accreditation obligations. We do not share your details with laboratories you have not contacted.

Our service providers, who process data on our instructions:

  • Amazon Web Services — hosting, databases and file storage (US East, N. Virginia).
  • Amazon Simple Email Service — sending the service emails described above.
  • Google Analytics — usage measurement, only where you have consented.

We also share data where the law requires it, and we may transfer it as part of a sale or reorganisation of the business, in which case we will tell you.

We do not sell personal data.

5. Where your data goes

The portal and its databases run on Amazon Web Services in the United States (US East, N. Virginia), and Google Analytics also processes data there. If you are in India, this means your personal data is processed outside India; we tell you so here because the Digital Personal Data Protection Act, 2023 requires it. Where personal data protected by the laws of another country is transferred, we rely on the standard contractual clauses published by the European Commission, which form part of our agreements with both Amazon Web Services and Google.

6. How long we keep it

Account data is kept while your account is open, and for 90 days afterwards.

Requests, messages, results and reports are kept indefinitely. This is deliberate: they are the record of accredited testing, the issuing laboratory is required to be able to reproduce and defend its reports years later, and deleting our copy would not — and should not — delete the laboratory's. Closing your account does not delete them.

Analytics data is kept for 14 months — the longest retention Google Analytics offers on a standard property, so this is what the property is set to rather than a number chosen independently of it. Server logs are kept for 90 days.

The visitor fingerprints described in § 8 are deleted as soon as the period they count is over — after two days for the daily ones, and at the end of the calendar month for the monthly ones. The secret needed to make sense of each is destroyed on the same schedule. What remains is a count with nothing attached to it.

7. Your rights

Subject to the law that applies to you, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, object to or restrict some uses, ask for it in a portable form, and withdraw a consent you have given. Write to info@zymiq.io.

You can close your account yourself, from Account → Security. Closing it signs you out everywhere, releases your email address and removes your name, company and phone number from Zymiq; your requests, messages and reports are kept, for the reason given in § 6.

Two limits are worth stating plainly. We cannot delete a laboratory's records on its behalf — if you want data removed from a laboratory's own system, ask that laboratory. And we cannot delete records that we or the laboratory are required to keep, including the record of testing described in § 6.

You can also complain to your data protection authority. In India that is the Data Protection Board of India, established under the Digital Personal Data Protection Act, 2023; elsewhere it is the authority for the country you live in.

8. Cookies

We set two cookies that the portal cannot work without. They keep you signed in, they are not used to track you, and they are not shared with anyone. Because they are strictly necessary we do not ask permission for them, but we tell you they are here:

  • A short-lived session cookie holding your access token, so each page knows who you are.
  • A longer-lived, http-only refresh cookie, so you are not signed out every few minutes. It is readable only by our servers, never by scripts in your browser.

We also use Google Analytics to understand which parts of the portal are used and where people get stuck. Google Analytics sets its own cookies and is not strictly necessary, so we ask first: its script is not loaded at all unless you accept. If you decline, nothing analytics-related runs and no analytics cookie is set. You can change your mind at any time from the "Cookie choices" link at the foot of any page.

Your choice is remembered in your browser's local storage rather than in a cookie, and applies to that browser on that device.

Separately from Google Analytics, we keep a simple count of how many people use the public directory — how many read a page, opened a laboratory listing, searched, or sent an enquiry. This runs whether or not you accept cookies, and we think you should understand exactly why we consider that fair.

It stores nothing on your device. No cookie is set, nothing is written to your browser's storage, and nothing is read from it — so the rule that requires us to ask permission before placing things on your device is not engaged. To count people rather than page loads we take your IP address and browser identification, combine them with a secret random value of our own, and keep only the resulting fingerprint. Your IP address itself is never written down anywhere: it exists for the instant the fingerprint is calculated and is then gone, and the fingerprint cannot be reversed to recover it.

We do this twice over, because a daily count and a monthly count need different things. For the daily figures the secret is replaced every night and the old one destroyed, so your fingerprint tomorrow will not match your fingerprint today and we cannot follow you from one day to the next. For the monthly figures the secret necessarily lasts the calendar month — there is no way to count somebody once across a month without something that lasts that long — and it is destroyed, with the fingerprints, once the month is over.

The monthly fingerprint is also tied to the single page or laboratory listing it was recorded against. That is deliberate and it is the important part: the value we hold for you against one laboratory is an unrelated number to the value we hold for you against another, so we cannot tell that the same person looked at both. We never hold a single identifier that would show us what you browsed, in what order, or what you searched for. We cannot build a profile of you, and neither could anyone who obtained the data.

We do this on the basis of our legitimate interest in knowing how many people the directory reaches, which we cannot learn any other way: an analytics script is invisible to everyone who declines cookies, and most people decline. If you would rather not be counted at all, you can block requests to our domain with a content blocker, and nothing else on the site will stop working.

9. Security

Data is encrypted in transit. Passwords are stored hashed. Access to your requests and reports is scoped to your account at the database level, so another customer cannot read them even if the interface were wrong. No system is perfectly secure, and we do not claim otherwise.

10. Children

The portal is for business use and is not directed at children. We do not knowingly collect their data.

11. Changes

We may update this policy. The version and date at the top tell you which text is current, and we will give reasonable notice of a material change.

12. Contact

Privacy questions and rights requests: info@zymiq.io, or 76 Shiv Vatika, Lasudia Mori, Vijay Nagar, Indore, Madhya Pradesh 452010, India.