This Privacy Policy explains how ZELOFUN LIMITED ("we", "us", "our"), a company registered in England and Wales with its registered office at 146 New Cavendish Street, Westminster, London, United Kingdom, W1W 6YQ, collects, uses, stores, shares, and protects personal data when you visit https://zelofun.diy, contact us, engage our facial recognition app development services, use software or platforms we build or maintain, or otherwise interact with us. We are committed to processing personal data lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) as incorporated into UK law by the Data Protection Act 2018, and with applicable guidance from the Information Commissioner's Office (ICO).
This policy applies to personal data we process as a data controller in connection with our own business operations, marketing, website administration, recruitment, and client relationship management. Where we develop facial recognition software, biometric authentication systems, or identity verification platforms on behalf of clients, we may also act as a data processor. In those circumstances, the client's privacy notice and data processing agreement govern the processing we carry out on their instructions, and this policy should be read alongside those documents.
Facial recognition and biometric processing involve heightened privacy risks because they relate to special category personal data and may affect fundamental rights and freedoms. We take these risks seriously and design our services and internal practices to embed privacy by design and by default, consistent with ICO expectations for biometric technologies.
The data controller responsible for personal data described in this Privacy Policy is:
If you have questions about this policy, wish to exercise your data protection rights, or need to report a concern, please contact us using the details above. We will respond within one calendar month unless the request is complex or numerous, in which case we may extend by up to two further months and will inform you of the extension and reasons.
Depending on how you interact with us, we may process the following categories of personal data:
This includes your name, job title, employer, postal address, email address, telephone number, and similar identifiers you provide when completing contact forms, requesting quotations, signing contracts, or communicating with our team.
When you visit our website, we may collect IP address, browser type and version, operating system, device identifiers, referral URLs, pages viewed, time and date of access, and interaction data collected through cookies and similar technologies as described in our Cookie Policy.
If you engage our services, we process information about your organisation, project requirements, technical specifications, integration environments, and correspondence relating to facial recognition app development, biometric system design, or related consultancy.
We may process billing contact details, purchase order references, invoice records, and payment status. Payment card details are typically processed directly by our payment service providers and are not stored by us in full.
If you apply for employment or contract roles with us, we process application materials, CVs, interview notes, references, and eligibility information as permitted by law.
Biometric data is personal data resulting from specific technical processing relating to physical, physiological, or behavioural characteristics that enables or confirms the unique identification of a natural person. Under UK GDPR Article 9, biometric data processed for the purpose of uniquely identifying an individual constitutes special category personal data and requires an additional lawful basis beyond ordinary processing grounds.
As a facial recognition app development company, our work frequently involves technologies that capture, analyse, compare, or store facial images, facial geometry, facial templates, depth maps, liveness detection signals, and derived biometric identifiers. We may process such data in the following contexts:
We do not sell biometric data. We do not use biometric data for purposes incompatible with those disclosed at collection. Where we process special category data, we document our condition for processing under Article 9(2), which may include explicit consent, necessity for employment or social security law, substantial public interest with appropriate safeguards, or explicit consent in line with ICO guidance on biometrics in the workplace and public-facing systems.
Facial recognition technology compares facial features from an image or video stream against reference data to verify identity or identify individuals. Our processing activities may include:
Each stage involves personal data processing decisions that must be justified, documented in records of processing activities, and communicated to data subjects. We support clients in conducting data protection impact assessments (DPIAs) where facial recognition is likely to result in high risk to individuals, such as large-scale public deployment, systematic monitoring, or processing of children's biometric data.
We process personal data only where we have a valid lawful basis under UK GDPR Article 6, and where special category data is involved, an additional condition under Article 9. The table below summarises typical bases; specific processing will be described in collection notices and contracts.
Processing necessary to perform a contract with you or to take steps at your request before entering a contract, including scoping facial recognition projects, delivering software, providing support, and invoicing.
Processing necessary for our legitimate interests in operating and improving our business, securing our systems, preventing fraud, and marketing our services to business contacts, balanced against your rights. We conduct legitimate interest assessments where appropriate.
Where required, we obtain freely given, specific, informed, and unambiguous consent, such as for non-essential cookies, certain marketing communications, or biometric enrolment in demonstration environments. Consent may be withdrawn at any time without affecting the lawfulness of processing before withdrawal.
Processing necessary to comply with laws applicable in England and Wales, including tax, accounting, and regulatory obligations.
For biometric processing, we rely on explicit consent or another Article 9 condition permitted by the Data Protection Act 2018 Schedule 1, documented in our compliance records and client-facing materials.
We collect personal data through multiple channels:
We use personal data for the following purposes:
Our website uses cookies and similar technologies as detailed in our Cookie Policy. Cookies may collect technical and usage data. Where cookies are non-essential, we request consent through our cookie banner in line with the Privacy and Electronic Communications Regulations (PECR) and UK GDPR. You may manage preferences through the banner or browser settings. Essential cookies necessary for website operation may be used without consent.
We may share personal data with:
Hosting providers, cloud infrastructure, email platforms, CRM systems, analytics providers, payment processors, and specialised biometric or AI tooling vendors who process data on our instructions under Article 28 data processing agreements.
Solicitors, accountants, insurers, and auditors bound by confidentiality obligations.
Where necessary to deliver contracted services, with appropriate contractual protections.
Where required by law, court order, or legitimate requests from authorities in England and Wales.
In connection with merger, acquisition, or asset sale, subject to continuity of protection.
We require processors to implement appropriate technical and organisational measures and process personal data only on documented instructions.
We primarily store and process data within the United Kingdom and European Economic Area. Where personal data is transferred outside the UK to countries without an adequacy decision, we implement appropriate safeguards such as the UK International Data Transfer Agreement, UK Addendum to EU Standard Contractual Clauses, or binding corporate rules, and conduct transfer risk assessments where required. Details of specific transfers are available on request.
We retain personal data only for as long as necessary for the purposes collected, including legal, accounting, and reporting requirements. Retention periods vary by data category:
When retention periods expire, we securely delete or anonymise data.
We implement technical and organisational measures appropriate to the risk, including encryption in transit and at rest where appropriate, access controls, multi-factor authentication, secure development practices, vulnerability management, staff training, and incident response procedures. Biometric templates and facial images receive enhanced protection including restricted access, segregation of environments, and audit logging. No method of transmission or storage is completely secure; we cannot guarantee absolute security but continuously work to maintain high standards aligned with ICO security guidance.
Facial recognition systems may involve automated processing that produces legal or similarly significant effects, such as automated identity verification decisions. Where we deploy such processing as controller, we provide meaningful information about the logic involved, significance, and envisaged consequences, and ensure suitable human review, challenge mechanisms, and accuracy safeguards where required by UK GDPR Article 22. Clients implementing our software remain responsible for lawful deployment and transparency to their end users.
Subject to conditions and exemptions, you have the following rights:
To exercise rights, contact helpdesk@zelofun.diy. We may need to verify identity. You also have the right to lodge a complaint with the ICO at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, or via ico.org.uk.
Our services and website are directed at businesses and professionals. We do not knowingly collect personal data from children under eighteen without appropriate parental authority and lawful basis. Facial recognition solutions involving minors require heightened safeguards; clients must ensure compliance with applicable child data protection rules before deployment.
Where processing is likely to result in high risk, particularly systematic use of biometric data or facial recognition in public contexts, we conduct or support DPIAs documenting processing operations, necessity, proportionality, risks, and mitigation measures. DPIA outcomes inform technical design, retention limits, and transparency materials.
We maintain records of processing activities as required by UK GDPR Article 30, including purposes, categories of data subjects and personal data, recipients, transfers, retention, and security measures. Our Data Protection Officer contact point is reachable at helpdesk@zelofun.diy. We cooperate with supervisory authority requests and demonstrate accountability through policies, training, and periodic reviews.
Our website may contain links to third-party sites. We are not responsible for their privacy practices. Review their policies before providing personal data.
We may update this policy to reflect legal, technical, or business changes. The "Last updated" date at the top indicates the latest revision. Material changes will be communicated via website notice or direct communication where appropriate. Continued use after changes constitutes acknowledgement of the updated policy where lawful.
For privacy enquiries, data subject requests, or biometric processing questions, contact:
This Privacy Policy is governed by the laws of England and Wales. Courts in England and Wales have exclusive jurisdiction over disputes relating to this policy, subject to your statutory rights.
Our approach to transparency ensures that individuals understand when facial recognition technologies process their biometric identifiers. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
We align retention schedules for facial templates with the minimum necessary period for authentication or verification purposes. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
Staff with access to special category biometric data receive role-based permissions and annual data protection training. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
Vendor due diligence includes assessment of subprocessors handling facial image data or embedding generation services. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
Incident response playbooks address potential personal data breaches involving biometric information without undue delay. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
Privacy notices for client deployments are reviewed to ensure Article 13 and 14 UK GDPR transparency requirements are met. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
We document legitimate interest assessments for business contact marketing and website analytics where applicable. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
Technical measures for biometric data include hashing of templates, secure key management, and environment segregation. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
Our approach to transparency ensures that individuals understand when facial recognition technologies process their biometric identifiers. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
We align retention schedules for facial templates with the minimum necessary period for authentication or verification purposes. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
Staff with access to special category biometric data receive role-based permissions and annual data protection training. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
Vendor due diligence includes assessment of subprocessors handling facial image data or embedding generation services. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
Incident response playbooks address potential personal data breaches involving biometric information without undue delay. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.
Privacy notices for client deployments are reviewed to ensure Article 13 and 14 UK GDPR transparency requirements are met. ZELOFUN LIMITED maintains documented procedures aligned with UK GDPR, the Data Protection Act 2018, and guidance published by the Information Commissioner's Office (ICO) regarding biometric data, facial recognition technologies, and lawful processing of special category personal data. Our Westminster-based team applies these standards across all facial recognition app development, identity verification platform deployments, and custom biometric solution engagements. Where processing involves facial geometry, facial templates, or derived biometric identifiers, we assess necessity, proportionality, and transparency obligations before any collection occurs. Clients and end users receive clear information about purposes, retention periods, and rights. We review our practices periodically and update internal policies when legislation, ICO codes of practice, or industry standards evolve. Contact us at helpdesk@zelofun.diy or +44 7853 281824 for questions about how these principles apply to your specific project or use of our services via https://zelofun.diy.