PRIVACY POLICY
Who we are
Zygo Consulting LLC is a United States operations consultancy for founder-led health and wellness brands. This policy explains what we do with personal data, both on this website and in the work we do for clients.
Ben Johnson, Principal, is our appointed data protection lead and the accountable owner for privacy and security at the firm. You can reach him at ben@zygoconsulting.co.
Two different roles
We handle personal data in two distinct situations, and the rules differ.
1. As a controller, for our own business
This covers visitors to this website and the business contacts we correspond with. We decide what to collect and why, and this policy governs it.
2. As a service provider, for our clients
When we build reporting and operations systems for a client, any personal data involved belongs to that client. They decide what is collected and why; we process it only on their written instruction. If you are a customer of one of our clients and want to exercise a right over your data, contact that business directly. We will support them in answering you.
This website
This site sets no cookies, runs no analytics, and carries no advertising or tracking pixels. There is no contact form and nothing here asks you to submit personal information.
Two things still happen when you visit, and you should know about both:
- Hosting logs. Our host records standard server log data, including your IP address, browser type, the pages requested, and timestamps. This is used to serve the site and protect it from abuse. We do not use it to build a profile of you.
- Fonts. Typefaces load from Google Fonts, which means Google receives your IP address in order to serve them. We do not send Google anything else about you.
Business contacts
If you email us, book a call, or become a client contact, we hold the ordinary details: your name, email address, phone number where you give one, your company, and the correspondence itself. We use it to answer you, to deliver work, and to keep records of what we agreed.
We do not send marketing email to people who have not asked for it, and we do not buy or rent contact lists.
Client engagement data
Our analytics work needs order economics and inventory movement. It does not need to know who the buyer was, and we have built our systems around that.
We exclude customer personal information at the point of extraction. When we pull data from a commerce platform on a client's behalf, a field allowlist is applied at the moment of collection. Buyer names, street addresses, phone numbers, and email addresses are never written into our systems. They are not stored and later deleted; they are not stored.
Where an engagement genuinely requires personal data, it is requested narrowly, approved in writing, and handled under our internal Personal Data Protection Policy and Data Classification Policy. Client data is kept segregated per client. It is never combined across clients, never used for benchmarking that would reveal one client's figures to another, and never used to train models.
We do not sell your data
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not provide it to data brokers. We have never done any of these things and have no plans to.
We disclose personal data only to the client who owns it, to the infrastructure providers listed below who process it on our behalf, or where the law requires it.
Who processes data for us
We use a small number of United States providers under their standard data processing terms: managed web hosting and serverless compute, cloud storage and database services where an engagement calls for them, and standard business email and productivity software. We do not use offshore development or data-processing vendors. Clients are told about any new provider that would handle their data before it is introduced.
Where data lives
All of our personnel, hosting, and storage are in the United States. We do not transfer client personal data outside the United States.
How long we keep it
- Client data: for the length of the engagement, then deleted or returned within 30 days of termination. Credentials are revoked and deletion is confirmed to the client in writing.
- Business contacts: while the relationship is active, and for three years after we last hear from you.
- Hosting logs: on our host's standard retention schedule, which is short.
How we protect it
We run a documented security program: a written information security policy, a data classification policy, a personal data protection policy, a vulnerability management procedure, and an incident response plan, all reviewed on a set schedule. In practice that means TLS 1.2 or higher on every connection, AES-256 encryption at rest, full-disk encryption on every company device, multi-factor authentication on every account with access to client data, least-privilege access granted per engagement and revoked when it ends, and API tokens encrypted individually before they are written anywhere, including logs.
If we ever suffer a breach affecting your data, we notify the affected client and the affected platform within 24 hours of detecting it, and we support any notification the law requires.
Your rights
Depending on where you live, you may have the right to ask us for a copy of the personal data we hold about you, to correct it, to delete it, to limit how we use it, or to object to a particular use. You also have the right not to be treated differently for exercising any of them.
Email ben@zygoconsulting.co and we will acknowledge within 5 business days and respond within 30 days. We may need to verify your identity first, and we will only ask for what is necessary to do that.
If your request concerns data we hold for a client, we will tell you which business to contact and let them know you asked.
Children
Our services are for businesses. This site is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email us and we will delete it.
Changes to this policy
We review this policy at least once a year, and whenever our systems or obligations change materially. The effective date at the top always reflects the current version. Material changes will be noted here.
Contact
Zygo Consulting LLC
Ben Johnson, Principal and data protection lead
ben@zygoconsulting.co
Security issues, including suspected vulnerabilities in any system we operate, go to the same address. We acknowledge reports within 2 business days.