Zolaymi LLC legal section
Privacy Policy
This Privacy Policy explains how Zolaymi LLC handles personal data when it operates its website, sells services, supports customers, and accesses client systems during WordPress and WooCommerce work.
Contents
- 1. Who we are and when this policy applies
- 2. Controller and processor roles
- 3. Information we may collect
- 4. Sources of information
- 5. Purposes and legal bases
- 6. Providers and third-party services
- 7. Sale, sharing and targeted advertising
- 8. International transfers and representatives
- 9. Privacy rights
- 10. Retention schedule
- 11. Credentials, client access and security
- 12. Contact
1. Who we are and when this policy applies
Zolaymi LLC is a Wyoming limited liability company that provides remote consulting, implementation, technical support and managed services for WordPress and WooCommerce businesses. In this Privacy Policy, "Zolaymi," "we," "us" and "our" mean Zolaymi LLC. "Website" means https://www.zolaymi.com and any related pages controlled by Zolaymi.
This policy applies when we act as a controller because we decide why and how personal data is processed. It also explains, at a high level, when we may act as a processor or service provider for a client.
Our services are intended for persons aged 18 or older. We do not knowingly collect personal data directly from children. A parent or guardian may contact [email protected] about suspected child data.
2. Controller and processor roles
We are a controller when we decide why and how to process information relating to website visitors, customers, prospective customers, account holders, newsletter subscribers, support contacts, review participants, contractor enquiries, legal contacts and compliance communications.
We may act as a processor, service provider or similar role when, under a client's instructions, we access or process personal data contained in WooCommerce stores, order records, customer accounts, abandoned carts, support tickets, transactional email systems, analytics systems, advertising systems, CRM or marketing platforms, shipping systems, review systems, APIs, webhooks, databases, backups and server logs.
Where we act as a processor for a business client, the Data Processing Agreement and the client's documented instructions govern that processing.
3. Information we may collect
Depending on how you interact with us and which services are purchased, we may process the following categories of information:
- Identity information, such as name, company name, role and account username.
- Contact information, such as email address, telephone number, WhatsApp details, billing address and country or region.
- Billing, transaction, invoice, tax-supporting and payment-status information.
- Account information, order references, subscriptions and service history.
- Project and contract information, including quotations, instructions, approvals, technical notes, deliverables and handover records.
- Support correspondence, attachments, issue descriptions, error messages, screenshots, access logs and ticket activity.
- Technical and device information, including IP address, browser, device, operating system, referrer, cookie identifiers, usage information, security logs and analytics data.
- Advertising attribution, cart and checkout information, review information, appointment information, client-system information and fraud-prevention information.
We do not intentionally request special-category data unless it is necessary for a lawful purpose and handled under appropriate safeguards. Customers should not send sensitive customer exports, passwords, API keys or payment-card data through ordinary forms or email.
4. Sources of information
Information may come from you, your employer or company, website interactions, WooCommerce, Stripe, PayPal, analytics and advertising providers, contact and support forms, scheduling systems, client systems, publicly available business information, fraud-prevention and security providers, and referrals.
If you provide information about another person, you must have the right to do so and must provide any notices or obtain any consents required by applicable law.
5. Purposes and legal bases
| Purpose | Typical legal basis | Notes |
|---|---|---|
| Providing services and deliverables | Contract or pre-contract steps | We use information needed to scope, perform, test and deliver WordPress and WooCommerce services. |
| Responding to enquiries | Legitimate interests or pre-contract steps | We respond to audit, support, sales and contact requests. |
| Processing payments | Contract and legal obligations | Stripe and PayPal process payment information under their own terms. We do not normally receive or store full card numbers. |
| Customer accounts and project management | Contract | Accounts help customers view orders, invoices and service history where enabled. |
| Support | Contract and legitimate interests | We handle issue reports, tickets, service questions and post-delivery support. |
| Security and fraud prevention | Legitimate interests and legal obligations | We protect the website, checkout, forms, client systems and our business. |
| Accounting and tax records | Legal obligations | Invoices, orders, payment records and tax-supporting records may be retained for statutory periods. |
| Direct marketing and newsletters | Consent or legitimate interests where legally permitted | You can unsubscribe or object to marketing at any time. |
| Abandoned-cart messages | Consent or another verified lawful basis | The lawful basis depends on jurisdiction, channel, consent and customer relationship. |
| Review requests | Contract-related legitimate interests or consent | The correct basis depends on jurisdiction, channel and review platform rules. |
| Analytics | Consent where required | Non-essential analytics should be blocked until consent in relevant jurisdictions. |
| Advertising and remarketing | Consent where required | Advertising cookies, pixels and similar technologies should be blocked until consent where legally required. |
| Legal claims | Legitimate interests and legal obligations | We may retain and use records to prevent, investigate or resolve disputes. |
| Service improvement | Legitimate interests | We use minimized or aggregated information where practical. |
6. Providers and third-party services
Current or expected providers may include WooCommerce, Stripe, PayPal, Kinsta Managed WordPress Hosting, Cloudflare, Cloudflare Turnstile, Google Workspace, Postmark, Google Analytics 4, Google Tag Manager, Google Ads, Meta Pixel, Meta Conversions API, Microsoft Clarity, Calendly, BlogVault, Complianz Premium for WordPress, Fluent Support, Brevo, Crisp, Twilio WhatsApp Business Platform and Prighter where representative services are required.
Some providers apply only when the relevant service, integration, cookie category, support channel, newsletter tool, live chat or WhatsApp workflow is enabled.
Third-party providers process information under their own terms and privacy notices. We do not control their independent processing, outages, pricing, policy changes or account decisions.
7. Sale, sharing and targeted advertising
Zolaymi does not sell personal data for money. Some U.S. state privacy laws may define certain advertising disclosures as "sharing," "sale" or "targeted advertising" even when no money is exchanged.
The following items must be assessed and implemented if legally required: "Do Not Sell or Share My Personal Information" link, targeted-advertising opt-out, Global Privacy Control handling, and authorized-agent request process. This policy does not state that the California Consumer Privacy Act or any specific U.S. state privacy law applies until threshold applicability has been assessed.
8. International transfers and representatives
Zolaymi is based in the United States. Information may be processed in the United States and other countries that may not provide the same level of data protection as your home jurisdiction.
Where legally required, appropriate transfer mechanisms may be used, including EU Standard Contractual Clauses, the UK International Data Transfer Addendum or IDTA, adequacy decisions, and Data Privacy Framework participation where valid and applicable.
EU representative assessment: complete an Article 27 GDPR assessment. If an EU representative is required, Zolaymi expects to appoint Prighter EU GDPR Representation and publish the entity and address from the signed mandate.
UK representative assessment: complete an Article 27 UK GDPR assessment. If a UK representative is required, Zolaymi expects to appoint Prighter UK GDPR Representation and publish Prighter Ltd details from the signed mandate.
These representative positions should be updated after the signed mandate details are available.
9. Privacy rights
Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction, objection, data portability, withdrawal of consent, marketing opt-out, complaint to a regulator, appeal of certain U.S. state privacy decisions where applicable, and opt-out of targeted advertising where applicable.
Send requests to [email protected]. We may need to verify your identity or authority before acting on a request. We will use the least intrusive verification method reasonably available and will not require unnecessary identification documents.
Withdrawing consent does not affect processing that occurred before withdrawal and does not prevent processing where another lawful basis applies.
10. Retention schedule
| Record type | Retention period |
|---|---|
| Unconverted sales enquiries | Up to 12 months after last meaningful contact. |
| Customer account information | While active and up to 24 months after closure, except records required longer. |
| Contracts, invoices, payment records, orders and tax-supporting records | Seven years. |
| Project files and deliverables | Up to three years after completion. |
| Support tickets | Up to 24 months after closure. |
| Legal claims and disputes | Until the applicable limitation period and dispute are resolved. |
| Marketing consent records | While consent is active and for a reasonable evidence period after withdrawal. |
| Newsletter information | Until unsubscribe, followed by minimal suppression information. |
| Security logs | Generally 90 days to 12 months depending on risk. |
| Backups | BlogVault independent off-site backups: 30 daily backups and 12 monthly backups, with automatic deletion after 12 months. |
| Analytics data controlled directly by Zolaymi | GA4 user and event retention: 2 months. Microsoft Clarity playback retention: 30 days. Clarity click data, heatmaps and saved sessions: 9 months. |
| Cookie data | According to the live cookie table and provider duration. |
| Client-system access | Only while required for the service. |
Information may be retained longer where required for tax, accounting, security, fraud prevention, dispute resolution or legal obligations.
11. Credentials, client access and security
Zolaymi recommends that clients create temporary, named, role-limited user accounts. Clients should not send permanent master passwords where avoidable. Credentials must not be transferred through ordinary unencrypted messages where safer methods are available.
We do not intentionally retain passwords after access is no longer required. Clients are responsible for revoking temporary access after completion. We may delete locally held access information after project completion. Access logs may remain in the client's own systems. Emergency or ongoing managed-service access may remain active only where agreed.
Reasonable safeguards may include access limitation, role-based permissions, strong authentication, encrypted connections, provider due diligence, secure backups where applicable, monitoring, access revocation, incident response and data minimization. No method of transmission or storage is perfectly secure, and we do not guarantee absolute security.
12. Contact
Zolaymi LLC can be contacted using the details below. Do not send passwords, API keys, payment-card information, full customer exports, or other sensitive information through ordinary email unless a secure transfer method has been agreed.
- General support: [email protected] (support at zolaymi dot com)
- Privacy and data-rights requests: [email protected] (contact at zolaymi dot com)
- Legal notices: [email protected] (legal at zolaymi dot com)
- Telephone: +1 602 661 9771
- Website: https://www.zolaymi.com
- Public business mailing address: 1309 Coffeen Avenue STE 1200, Sheridan, WY 82801, United States
Policy contact
Questions, legal notices, privacy requests and support requests should be sent to the correct Zolaymi contact address so they can be handled properly.
- General support: [email protected] (support at zolaymi dot com)
- Privacy and data-rights requests: [email protected] (contact at zolaymi dot com)
- Legal notices: [email protected] (legal at zolaymi dot com)
- Telephone: +1 602 661 9771
- Public business mailing address: 1309 Coffeen Avenue STE 1200, Sheridan, WY 82801, United States