Privacy policy
What we collect, why, who we share it with, and the choices you have.
Last updated: 27 September 2026
Who we are
ZeroSpams is a service of ZeroSpams ("we", "us"), Port Saeed, Deira, Dubai, UAE, 678895. For anything about this policy or your data, email [email protected].
Our two roles
For zerospams.com and our own customers, we decide how data is used (we are the "controller"). This covers people who visit this website, send us an enquiry, or buy an installation.
For websites where we installed ZeroSpams, the website owner decides. The software runs on their servers, and we only see their data if they give us access to install or fix it. If you sent a form on another company's website that uses ZeroSpams, that company is responsible for your data. See visitors to our customers' sites.
What we collect
When you send our contact form
- What you type: name, email, and optionally phone, company, website address and your message.
- Technical details of the connection: IP address, the country we derive from it, browser and device type.
- Your browser's time zone and language, so we can reply at a suitable time and in a suitable language.
- To tell people from spam bots, a short summary of how the message was written: how long the typing took, how many corrections were made, how much was pasted, and how regular the typing rhythm was; and how the "slide to send" control was used (how many milliseconds the slide took and how the pointer moved). This is a handful of numbers, not a record of the keys you pressed; we never record what you type letter by letter.
- How you arrived: the site or search engine that sent you, campaign tags in the link, the first page you saw, the page you wrote from, and how many pages you viewed and for how long. If you're asked and don't allow browser storage, only the page you wrote from is included.
When a form submission is blocked as spam
The reason it was blocked, the IP address with its last part removed, the device type, the email address entered, the first 200 characters of the message and the summary of how it was written. We keep this for a short time to check that real people aren't being blocked.
When you become a customer
Business contact details, your website addresses, quotes, invoices and correspondence. While we install or fix something, we also hold the access details you give us, and delete them when the work ends. Card payments are handled by our payment provider; we don't see or store full card numbers.
Browser storage
This website uses no third-party cookies and no advertising or analytics trackers. It stores a few small items in your own browser:
| Name | What it holds | How long | When |
|---|---|---|---|
| zs_consent | Your answer to "Remember how you found us?" | Until you clear it | Always, to remember your choice |
| zs_first | The first page you visited, the site that sent you, campaign tags and whether you came from an ad | 90 days | Only if you allow it |
| zs_sess | Pages viewed and start time of this visit | Until you close the tab | Only if you allow it |
| zs_admin | Sign-in session cookie | Until you sign out or close the browser | Only for our staff in the admin area |
Nothing in zs_first or zs_sess leaves your browser unless you send the contact form. You can change your choice at any time with .
Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Replying to your enquiry and preparing a quote or free check | Steps you asked us to take before a contract (GDPR art. 6(1)(b)); for the UAE, processing needed to respond to your request |
| Blocking spam and abuse of our forms | Our legitimate interest in keeping our systems secure (GDPR art. 6(1)(f)) |
| Understanding where enquiries come from (source, first page, country) | Our legitimate interest in understanding our enquiries; browser storage only with your consent |
| Carrying out installations, invoicing and fixes | Performance of our contract (GDPR art. 6(1)(b)) |
| Keeping invoices and tax records | Legal obligation (GDPR art. 6(1)(c)), including UAE tax law |
Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), consent is the main legal basis. By sending the contact form after reading the notice beside it, you consent to the processing described there. You can withdraw that consent at any time by emailing us; this doesn't affect processing we have already carried out.
Who we share it with
We don't sell personal data and we don't use it for advertising. We share it only with service providers who help us run ZeroSpams, under contracts that require them to protect it:
- Mailgun (Sinch), to send emails.
- Our hosting provider, which stores our website and database.
- ipinfo.io, which receives an IP address and returns the country it belongs to.
- Our payment provider, for customers who pay by card.
- Professional advisers such as accountants and lawyers, when needed.
We may also disclose data when the law requires it, or to protect our rights, our customers or the public.
Where it is stored
Our database is hosted in the European Union. Some providers above may process data in other countries. When data leaves the UAE or the European Economic Area, we rely on the safeguards those laws require, such as the European Commission's standard contractual clauses.
How long we keep it
- Enquiries: 24 months after the last contact, unless you become a customer.
- Blocked spam records: 30 days.
- Customer records and invoices: for as long as UAE law requires (at least five years for tax records).
- Access details for customers' systems: until the work is finished.
- Browser storage: as shown in the table above.
Your rights
You can ask us to show you the data we hold about you, correct it, delete it, limit how we use it, send it to you in a portable format, or stop using it. You can object to processing based on our legitimate interests and withdraw consent at any time. Email [email protected]; we reply within 30 days and may ask you to confirm your identity.
If you're unhappy with our answer, you can complain to the UAE Data Office, or to the data protection authority where you live or work if you're in the EU or UK.
Visitors to our customers' websites
When ZeroSpams is installed on another company's website, it runs on that company's servers and sends email through that company's own accounts. The company decides what is collected and how long it is kept, and its own privacy policy applies. We don't receive that data. If we're given access to their systems to install or fix the software, we act only on their instructions, under a written data processing agreement.
To ask about that data, contact the website owner. If you contact us, we'll tell you who to contact.
Security
We use encrypted connections, restrict admin access to named staff with individual accounts, store passwords only in hashed form, and keep blocked-spam records with IP addresses partly hidden. No system is perfectly secure; if a breach affects your data, we'll tell you and the authorities when the law requires it.
Changes to this policy
We'll update the date at the top when this policy changes, and tell customers by email about significant changes.