Legal

Privacy Policy

Last updated: August 6, 2026 · Effective: August 10, 2026 · Version 2.0

English version prevails. In case of any discrepancy between this version and any translation, the English version governs.

1. Introduction

1.1 This Privacy Policy explains how ZeroCorp Pte. Ltd. ("ZeroCorp", "we", "us") collects, uses, discloses, stores, and protects personal data in connection with our website, platform, and services.

1.2 We are committed to protecting your privacy and comply with the data protection laws applicable to our operations, including:

the Personal Data Protection Act 2012 of Singapore ("PDPA") — our primary legal framework, as ZeroCorp is registered in Singapore;

the EU General Data Protection Regulation ("GDPR") — where we process personal data of individuals in the European Economic Area (EEA) or the UK; and

the Indonesian Personal Data Protection Law (UU No. 27 Tahun 2022) — where we process personal data of individuals in Indonesia.

1.3 If you are located in the EEA or the UK, the GDPR-specific provisions in Sections 9–11 apply to you.

2. Who We Are; Controller and DPO

2.1 Entity. ZeroCorp Pte. Ltd., Republic of Singapore (ACRA registration in progress).

2.2 Roles. With respect to Control-Plane Data (account, authentication, and billing data), ZeroCorp acts as a data controller. With respect to business data processed in your dedicated VPS (Data-Plane), ZeroCorp acts as a data intermediary / processor on your instructions; you are the controller of that data.

2.3 Data Protection Officer (DPO). ZeroCorp has appointed a Data Protection Officer as required by the PDPA and its regulations. Contact the DPO at: dpo@zerocorp.live (or legal@zerocorp.live).

3. Data We Collect

3.1 Categories of personal data:

Account data — information you provide when registering or purchasing (e.g., name, email address, company name, industry, country).

Billing data — payment information processed by Paddle (payment method, billing address, transaction records). Paddle is the payment processor; ZeroCorp does not store full card details.

Technical / usage data — collected automatically when you interact with our site or platform (IP address, browser type, device information, pages visited, usage logs).

Communication data — information you send us through support or other channels (support tickets, emails, chat logs).

Business data (Data-Plane) — data processed on your behalf by your AI Agents in your dedicated VPS (your customer lists, business documents, emails, reports, AI-generated content).

3.2 Data we do NOT collect: (a) full payment card numbers (handled by Paddle under PCI DSS); (b) special categories of personal data (e.g., health, biometrics, racial or ethnic origin) unless you deliberately provide them as part of your business data; (c) data of children under 16 (see Section 12).

4. Purposes of Processing and Legal Bases

4.1 Purposes. We use personal data to:

1. Provide, operate, maintain, and improve the Service;

2. Process subscriptions, payments, and refunds (via Paddle);

3. Enable your AI Agents to operate on your behalf;

4. Authenticate users and secure the platform;

5. Communicate important updates, notices, and changes to legal documents;

6. Provide customer support;

7. Detect, prevent, and investigate fraud, abuse, or security incidents;

8. Comply with legal and regulatory obligations (including tax and accounting obligations).

4.2 Legal bases.

Under the PDPA (Singapore): we rely on consent (express or deemed), and where applicable the legitimate interests exceptions under the PDPA, for the purposes above. Where consent is required, we obtain it at the point of collection or use.

Under the GDPR (EEA/UK): our legal bases under Article 6 are:

Providing the Service and account management — Art. 6(1)(b), performance of a contract;

Billing, payment, refunds — Art. 6(1)(b), performance of a contract;

Security, fraud prevention — Art. 6(1)(f), legitimate interests;

Legal and regulatory compliance — Art. 6(1)(c), legal obligation;

Marketing communications (where applicable) — Art. 6(1)(a), consent;

Business data processed in your VPS — Art. 6(1)(b) / processed on your behalf as a processor (Art. 28).

5. Consent and Withdrawal

5.1 Where we rely on consent, you may withdraw consent at any time by contacting legal@zerocorp.live or through your account settings.

5.2 Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal, and does not affect processing based on other legal bases (for example, contract performance or legal obligation).

5.3 If you withdraw consent necessary for the provision of the Service, we may not be able to continue providing certain services, and we will inform you of the consequences.

6. Data Storage and Security

6.1 Architecture. ZeroCorp uses a split data model:

Control-plane (account, authentication, billing data) is processed by ZeroCorp centrally.

Data-plane (your business data) is stored in your dedicated, isolated VPS, separate from all other clients.

6.2 Security measures. We implement appropriate technical and organizational measures to protect personal data, including: encryption at rest and in transit; access controls and least-privilege principles; network isolation between client environments; monitoring for unauthorized access; and secure disposal of data. These measures align with the PDPA Protection Obligation (s. 24) and GDPR Article 32.

6.3 No liability transfer. While we apply these measures, no method of transmission or storage is completely secure. You are responsible for safeguarding your account credentials and for securing access to your own VPS environment.

7. Data Retention

7.1 Retention principles. We retain personal data only for as long as necessary for the purposes for which it was collected, in accordance with the PDPA Retention Limitation (s. 25) and GDPR Article 5(1)(e).

7.2 Account data (Subscriptions). Retained while your account is active and for thirty (30) days after termination, after which it is deleted or anonymized, unless longer retention is required by law (for example, tax or accounting records, which are retained for the periods required by applicable law).

7.3 Account data (EAP). Because the EAP grants a three-year service term, account data is retained for the duration of the EAP Term (as necessary to provide the Service) plus thirty (30) days, unless you terminate earlier or request deletion.

7.4 Business data in your VPS. Retained while your service is active and for thirty (30) days after termination, after which your VPS and its data are securely decommissioned. You may request immediate deletion at any time.

7.5 Backups. Backups are retained for fourteen (14) days.

7.6 Logs and technical data. Retained for security and operational purposes for a period not exceeding twelve (12) months, unless a longer period is required by law.

8. Disclosure and International Transfers

8.1 Third-party processors. We share personal data only with service providers necessary to operate the Service:

Paddle — payment processing and merchant-of-record services;

Hostinger — VPS hosting and infrastructure;

Self-hosted PostgreSQL — account data storage (control-plane only);

Google Workspace — optional business productivity tools (per client setup);

DeepSeek, OpenAI, Anthropic — AI model providers for agent intelligence.

Where these providers process personal data on our behalf, they do so under data processing agreements consistent with this Privacy Policy.

8.2 No sale of data. We do not sell, rent, or trade personal data. "Sale" of personal data is expressly prohibited under these terms.

8.3 Legal disclosures. We may disclose personal data where required by law, regulation, legal process, or governmental request, or where necessary to protect our rights, safety, or property, or the rights, safety, or property of others.

8.4 PDPA transfers. Where personal data is transferred outside Singapore, we ensure the recipient provides a standard of protection comparable to the PDPA, in accordance with the PDPA Transfer Limitation (s. 26).

8.5 GDPR transfers. Singapore does not currently have an EU adequacy decision. Where personal data of individuals in the EEA/UK is transferred outside the EEA/UK (including to Singapore), we rely on appropriate safeguards, including EU/UK Standard Contractual Clauses (SCCs) and supplementary measures, or other valid transfer mechanisms under GDPR Articles 44–49. You may request a copy of the relevant safeguards by contacting the DPO.

9. Your Rights (PDPA)

If you are in Singapore (or otherwise under the PDPA), subject to exceptions under the PDPA, you have the right to:

1. Access — request access to the personal data we hold about you and information about how it has been used or disclosed (PDPA s. 21);

2. Correction — request correction of inaccurate or incomplete personal data (PDPA s. 22);

3. Withdraw consent — withdraw consent for any processing for which we rely on consent.

We will respond to PDPA requests within thirty (30) days of receipt, or within any extended period permitted by the PDPA, and will notify you if an extension applies.

10. Your Rights (GDPR)

If you are in the EEA or the UK, you have the right to:

1. Access — obtain confirmation and a copy of your personal data (Art. 15);

2. Rectification — correct inaccurate or incomplete data (Art. 16);

3. Erasure — request deletion of your data ("right to be forgotten") (Art. 17);

4. Restriction — restrict processing in certain circumstances (Art. 18);

5. Portability — receive your data in a structured, machine-readable format and transmit it to another controller (Art. 20);

6. Object — object to processing based on legitimate interests or direct marketing (Art. 21);

7. Not be subject to automated decision-making — including profiling, that produces legal or similarly significant effects, subject to exceptions (Art. 22).

We will respond to GDPR requests within one (1) month, extendable by up to two further months for complex or numerous requests.

11. How to Exercise Your Rights; Complaints

11.1 To exercise any of the rights above, contact the DPO at dpo@zerocorp.live or legal@zerocorp.live. To verify your identity, we may ask for information reasonably necessary to confirm who you are. We may charge a reasonable fee for manifestly unfounded or excessive requests.

11.2 We aim to resolve all requests promptly. If you are dissatisfied with our response, you may:

Singapore: lodge a complaint with the Personal Data Protection Commission (PDPC) at pdpc.gov.sg;

EEA/UK: lodge a complaint with your local supervisory authority (e.g., the Information Commissioner's Office in the UK, or your national data protection authority).

12. Children

The Service is not directed at children, and we do not knowingly collect personal data from children under 16 (or the applicable minimum age in your jurisdiction). If you believe a child has provided us personal data, contact us and we will delete it.

13. Cookies and Similar Technologies

13.1 We use essential cookies for authentication and platform functionality, which cannot be disabled. With your consent, we also use analytics cookies to improve the Service.

13.2 Our cookie consent component allows you to accept or reject non-essential cookies on your first visit, and to change preferences at any time through your browser settings or the cookie preferences component.

14. AI and Automated Processing

14.1 AI Agents operate on your behalf and may process data you direct them to process. AI model providers (e.g., DeepSeek, OpenAI, Anthropic) receive only the data necessary to generate outputs on your instruction.

14.2 We do not use your business data or AI-generated content to train public AI models. Where a model provider trains on inputs, we rely on processing agreements that exclude training on your data, or we use non-training configurations.

14.3 AI-generated content may be imperfect (see ToS Section 10.2). ZeroCorp does not make decisions about you based solely on automated processing that produces legal or similarly significant effects.

15. Changes to This Policy

15.1 We may update this Privacy Policy as our services evolve or as legal requirements change. Material changes will be notified by email or through the platform before they take effect, where reasonably practicable.

15.2 Continued use of the Service after changes take effect constitutes acceptance of the updated Policy. The "Last updated" date at the top of this Policy reflects the latest revision.

16. Contact

DPO / Data protection inquiries: dpo@zerocorp.live

General legal inquiries: legal@zerocorp.live

Support: thoseplay@gmail.com

🍪 We use cookies

We use essential cookies to make our site work. With your consent, we also use analytics cookies to improve your experience.