Appendix
Privacy Policy
How Zheng Foundation LLC collects, uses, discloses, and safeguards your personal information.
Contents
- Introduction and Scope
- Information We Collect
- How We Use Your Information
- Legal Bases for Processing
- Disclosure of Your Information
- Data Retention
- Data Security
- Your Privacy Rights
- Cookies and Tracking
- Children's Privacy
- International Data Transfers
- Third-Party Services
- Do Not Track Signals
- Data Breach Notification
- Changes to This Policy
- Contact Us
1. Introduction and Scope
This Privacy Policy describes how Zheng Foundation LLC, a Utah limited liability company doing business as Zheng Foundation, collects, uses, stores, shares, and protects personal information obtained through our website located at www.zhengfoundation.hair, through any related digital properties, through our professional services, and through any other interactions you may have with our organization. This policy applies to all visitors, users, clients, prospective clients, vendors, and job applicants who interact with Zheng Foundation in any capacity.
Zheng Foundation is a computer systems design and related services firm specializing in enterprise systems architecture, cloud infrastructure engineering, systems integration, cybersecurity, and managed IT operations. Our principal office is located at 50 W Broadway, Suite 333, Salt Lake City, Utah 84101-2027, United States of America. Throughout this document, references to Zheng Foundation, we, us, and our refer to Zheng Foundation LLC and its affiliated operating entities. The website was developed and is maintained by the Zheng Foundation engineering team, who designed this site with data privacy as a foundational requirement.
By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any provision contained herein, you should discontinue use of our website and services immediately. We reserve the right to modify this policy at any time, and such modifications will be effective immediately upon posting to this page. Your continued use after changes constitutes your acceptance. We encourage you to review this policy periodically.
This Privacy Policy is designed to comply with applicable privacy laws in the jurisdictions where we operate, including but not limited to the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and applicable provisions of the General Data Protection Regulation to the extent they govern our processing activities. We are committed to the principles of transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality in all our data handling practices.
2. Information We Collect
2.1 Information You Provide Directly
We collect information that you voluntarily provide when you interact with our website, communicate with our team, or engage our services. This includes information submitted through our contact forms, email correspondence, phone calls, service inquiry forms, and client onboarding documentation. The categories of information we may collect include your full name, business email address, personal email address if provided, telephone number, job title, organization name, physical business address, billing address, payment information including bank account details and credit card data where applicable for service engagement, tax identification numbers, and any other information you choose to include in messages, project descriptions, or service requests submitted to us.
When you engage Zheng Foundation for professional services, we may also collect additional information necessary for the performance of our contractual obligations. This can include system access credentials provided under strict security protocols, network configuration data, infrastructure documentation, architectural diagrams, and other technical information related to your existing systems environment that you authorize us to review and optimize as part of the services we provide. We treat all client-provided technical information with the highest level of confidentiality and security.
2.2 Information Collected Automatically
When you visit our website, certain information is collected automatically through standard web technologies including your Internet Protocol address, browser type and version, operating system type and version, device type and manufacturer, screen resolution, referring and exit pages, date and time stamps of your visit, pages viewed and time spent on each page, clickstream data including the sequence of links and buttons you interact with, mouse movement patterns, scroll depth, and form interaction behavior. We use server logs, web beacons, tracking pixels, and similar technologies to collect this information. Server log data is typically retained for a period of thirty days before being archived and eventually purged, unless required for security investigations or legal compliance purposes.
2.3 Information from Third Parties
We may receive information about you from third-party sources to supplement our own records and to help us provide more relevant services. These sources may include business intelligence platforms, publicly available business registries, professional networking platforms, trade association directories, credit reporting agencies where applicable for business account verification, and referral partners who introduce you to our services. We treat all information received from third-party sources in accordance with this Privacy Policy and applicable law.
3. How We Use Your Information
We use the information we collect for specific business purposes that are necessary to provide our services, operate our business, and comply with legal obligations. Each category of use is described below.
We use your information to provide, maintain, and improve our services including the delivery of contracted computer systems design, architecture consulting, cloud infrastructure engineering, systems integration, cybersecurity assessment, and managed IT operations services. This includes using your contact information to communicate about project status, deliverables, milestones, and service-related notifications throughout the engagement lifecycle.
We use your information to respond to inquiries submitted through our website, by email, or by telephone. When you request information about our services, pricing, or availability, we process your contact details and the content of your inquiry to provide a responsive and personalized reply. We may follow up on inquiries that do not result in an immediate engagement to determine whether your needs have changed or whether additional information would be helpful to your evaluation process.
We use your information to process payments, manage billing and invoicing, maintain financial records, and fulfill our accounting obligations. This includes the use of payment information for transaction processing, invoice generation, payment reconciliation, collection activities where necessary, and financial reporting and auditing purposes required by applicable law and professional accounting standards.
We use your information to send marketing communications about our services, industry insights, technical white papers, event invitations, and company updates where you have provided consent or where otherwise permitted by applicable law. You may opt out of marketing communications at any time by using the unsubscribe link included in every marketing email or by contacting us directly at our published contact address.
We use your information to analyze website usage patterns, improve user experience, optimize website performance, conduct testing of content and layout variations, and develop aggregate statistical insights about our audience. We use your information to protect the security and integrity of our systems, networks, and data. This includes monitoring for unauthorized access attempts, investigating security incidents, detecting and preventing fraud, enforcing our Terms of Service, and complying with legal obligations including responding to lawful requests from law enforcement and regulatory authorities.
4. Legal Bases for Processing
For individuals located in jurisdictions that require a specified legal basis for the processing of personal data, we rely on the following legal grounds. Contractual Necessity means processing your information is necessary for the performance of a contract with you, such as delivering services you have engaged us to provide, or to take steps at your request prior to entering into a contract. Legitimate Interests means we process information where it is necessary for our legitimate business interests or those of a third party, provided those interests are not overridden by your data protection rights. Our legitimate interests include operating and improving our business, providing customer support, protecting against fraud and security threats, conducting business analytics, and marketing our services to existing and prospective clients in a business-to-business context. Consent means that where required by applicable law, we obtain your consent before processing your personal data for specific purposes, such as sending direct marketing communications. You have the right to withdraw consent at any time, though such withdrawal will not affect the lawfulness of processing performed prior to withdrawal. Legal Obligation means we process information where necessary to comply with applicable laws, regulations, court orders, government requests, or other legal processes. Vital Interests means that in rare circumstances, we may process information where necessary to protect your vital interests or those of another natural person.
5. Disclosure of Your Information
We do not sell your personal information. We do not rent, trade, or otherwise disclose your personal information to third parties for their independent commercial use. We may share your information only in the limited circumstances described below and always subject to appropriate confidentiality and data protection obligations.
We may share information with service providers and subcontractors who perform functions on our behalf. These include cloud hosting providers, payment processors, customer relationship management platform operators, email service providers, analytics services, professional advisors including legal counsel and accountants, auditors, and insurance providers. Each service provider is bound by contractual obligations that limit their use of your information to the specific purpose for which it was disclosed and require them to implement appropriate technical and organizational security measures commensurate with the sensitivity of the information they handle.
We may disclose information as required by law, regulation, legal process, or governmental request. This includes responding to subpoenas, court orders, search warrants, national security letters, or other lawful requests from public authorities. We will make reasonable efforts to notify you of such disclosure unless prohibited by law or where notification would compromise an ongoing investigation or pose a risk of harm. We may disclose information in connection with a corporate transaction, including a merger, acquisition, consolidation, restructuring, sale of all or a substantial portion of our assets, financing, or similar transaction. In such an event, we will require the acquiring entity to honor the commitments set forth in this Privacy Policy. We may disclose aggregated, de-identified, or anonymized information that cannot reasonably be used to identify you for any lawful purpose including industry analysis, benchmarking, and publication of technical insights.
6. Data Retention
We retain personal information for no longer than is necessary to fulfill the purposes for which it was collected, or as required by applicable law, regulation, or contractual obligation. The specific retention period for each category of information is determined by reference to the nature and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the information, whether those purposes can be achieved through alternative means, and applicable legal and regulatory requirements. Contact form submissions and inquiry correspondence are retained for a period of two years from the date of last communication, after which they are securely deleted unless a client relationship has been established. Client engagement records including contracts, project documentation, system architecture documents, and communications are retained for the duration of the client relationship plus seven years following termination of the engagement. Financial records including invoices, payment records, and accounting documentation are retained for a period of seven years in accordance with applicable tax laws and financial regulations. Website server logs and automatically collected technical data are retained for thirty days of rolling retention before being purged from active systems. Anonymized aggregate analytics data may be retained indefinitely for trend analysis and business planning.
7. Data Security
We implement and maintain comprehensive administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of your personal information. Our security program is aligned with industry standards and is regularly reviewed and updated to address evolving threats and vulnerabilities in the technology landscape.
Our technical safeguards include encryption of data in transit using TLS 1.3, encryption of data at rest using AES-256, multi-factor authentication for all administrative access, role-based access controls with the principle of least privilege, automated vulnerability scanning and penetration testing, intrusion detection and prevention systems, endpoint detection and response capabilities across all managed devices, security information and event management with real-time alerting, and regular third-party security assessments and audits of our infrastructure and applications.
Our administrative safeguards include a documented information security policy reviewed and updated annually, mandatory security awareness training for all personnel, background checks for employees and contractors with access to sensitive systems, formal incident response procedures with defined escalation paths and communication protocols, a vendor risk management program with security assessments for all third-party service providers, business continuity and disaster recovery plans tested at least annually, and data classification and handling procedures that define protection requirements based on information sensitivity levels. While we implement robust security measures, no method of electronic transmission or storage is perfectly secure, and we cannot guarantee absolute security. In the event of a data breach that affects your personal information, we will notify you and relevant authorities in accordance with applicable legal requirements and within the timeframes mandated by those requirements.
8. Your Privacy Rights
Depending on your jurisdiction of residence, you may have certain rights regarding your personal information. We honor all applicable privacy rights and will respond to verified requests in accordance with the timelines and requirements set forth by governing law. The rights described below may be subject to certain exceptions and limitations as provided by applicable statutes.
Right to Access and Data Portability: You have the right to request confirmation of whether we process your personal information and, if so, to obtain access to that information in a structured, commonly used, and machine-readable format. Right to Correction: You have the right to request correction of inaccurate or incomplete personal information that we hold about you. Right to Deletion: You have the right to request deletion of your personal information under certain circumstances. Right to Restrict Processing: You have the right to request restriction of the processing of your personal information in certain circumstances. Right to Opt Out of Sale or Sharing: Zheng Foundation does not sell personal information to third parties and has not done so in the preceding twelve months. We do not share personal information for cross-context behavioral advertising purposes. Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
To exercise any of these rights, please submit a verifiable request using the contact information provided in Section 16. We will acknowledge receipt of your request within ten business days and provide a substantive response within the time period required by applicable law, typically forty-five calendar days. We may extend the response period by an additional forty-five days when reasonably necessary, and we will notify you of any such extension. Before fulfilling your request, we will verify your identity by matching information you provide against our existing records.
9. Cookies and Tracking Technologies
Our website uses cookies, web beacons, tracking pixels, local storage, and similar technologies to enhance your browsing experience, analyze website traffic, and understand where our visitors originate. A cookie is a small text file that a website stores on your device through your web browser. Cookies may be session-based, meaning they expire when you close your browser, or persistent, meaning they remain on your device until they expire or are manually deleted. We use essential cookies that are strictly necessary for the operation of our website, enabling core functionality such as security, network management, and accessibility. Essential cookies do not require your consent under most privacy regulations. We also use analytics cookies that help us understand how visitors interact with our website by collecting and reporting information anonymously. These cookies allow us to measure page visits, traffic sources, time spent on pages, and user navigation patterns so we can improve our content and user experience. You may configure your browser settings to block, delete, or alert you about cookies. Please note that disabling essential cookies may affect the functionality of our website. We do not currently respond to browser-based Do Not Track signals in a standardized manner.
10. Children's Privacy
Our website and services are directed at business professionals and are not intended for use by individuals under the age of eighteen. We do not knowingly collect, solicit, maintain, or process personal information from children under the age of thirteen, or under the age of sixteen where applicable law sets a higher threshold. If we become aware that we have inadvertently collected personal information from a child without verified parental consent, we will take immediate steps to delete such information from our records.
11. International Data Transfers
Zheng Foundation is headquartered in the United States of America, and our primary data processing activities occur within the United States. If you are visiting our website or using our services from outside the United States, please be aware that your information will be transferred to, stored in, and processed within the United States, which may have data protection laws that differ from the laws of your country of residence. When we transfer personal information across international borders, we implement appropriate safeguards to ensure that your information receives an adequate level of protection as required by applicable data protection laws. These safeguards may include reliance on adequacy decisions issued by relevant regulatory authorities, execution of standard contractual clauses approved by applicable regulatory bodies, and assessment of the legal framework in the destination jurisdiction. By using our website or services, you acknowledge that your information will be subject to the laws of the United States, and you consent to the transfer of your information to the United States for processing in accordance with this Privacy Policy.
12. Third-Party Services and Links
Our website may contain links to third-party websites, services, and resources that are not owned, operated, or controlled by Zheng Foundation. These links are provided for your convenience and informational purposes only. We are not responsible for and make no representations regarding the privacy practices, content, security, or reliability of any third-party websites. We encourage you to review the privacy policies of every third-party website you visit before providing any personal information. When we engage third-party service providers to facilitate various aspects of our website and business operations, we conduct due diligence to assess their data protection practices and enter into written agreements that impose data protection obligations consistent with the commitments set forth in this Privacy Policy.
13. Do Not Track Signals
Certain web browsers and browser extensions offer a Do Not Track feature that sends a signal to websites requesting that they refrain from tracking the users browsing activities. At present, there is no consensus among industry participants, standards bodies, or regulatory authorities regarding the meaning of Do Not Track signals or how websites should respond to them. As a result, our website does not currently take action to respond to Do Not Track signals transmitted by web browsers. We continue to monitor developments in this area and will adjust our practices as industry standards and legal requirements evolve. In the meantime, you may manage your tracking preferences through the cookie controls described in Section 9 of this Privacy Policy.
14. Data Breach Notification
In the event of a security incident that results in unauthorized access to, disclosure of, or loss of personal information under our control, we will execute our incident response procedures to contain the incident, assess the scope and impact, and notify affected individuals and relevant regulatory authorities in accordance with applicable legal requirements and contractual obligations. Notifications will include a description of the incident, the categories and approximate number of individuals affected, the categories and approximate volume of personal information involved, the likely consequences of the breach, a description of the measures we have taken or will take to address the breach and mitigate its effects, and contact information for individuals to obtain additional information about the incident. We will provide notification without unreasonable delay and, where feasible, within the timeframes mandated by applicable law.
15. Changes to This Privacy Policy
We reserve the right to update, modify, or replace this Privacy Policy at any time and from time to time in our sole discretion. When we make material changes, we will post the updated policy on this page with a new Last Updated date and, where required by applicable law, we will provide additional notice such as a prominent notification on our website homepage or a direct email notification to individuals with whom we have an established relationship. Changes that are purely administrative, technical, or editorial in nature may be made without prior notice. We encourage you to review this Privacy Policy periodically to stay informed about our information practices and the choices available to you. Your continued use of our website or services following the posting of any changes to this Privacy Policy constitutes your acceptance of those changes.
16. Contact Us About Privacy
If you have questions, concerns, requests, or complaints regarding this Privacy Policy or our data handling practices, if you wish to exercise your privacy rights as described in Section 8, or if you believe that we have not adhered to the terms of this Privacy Policy, please contact us using the information below. We take all privacy inquiries seriously and will investigate and respond to your communication promptly and thoroughly.
Zheng Foundation LLC
Attn: Privacy Office
50 W Broadway, Suite 333
Salt Lake City, UT 84101-2027
United States of America
Email: serve@zhengfoundation.hair
Phone: +1 (806) 821-5199
Website: www.zhengfoundation.hair
The Zheng Foundation engineering team developed and maintains this website with data privacy and security as foundational design principles embedded throughout our technology platform.