Personal data

Privacy policy

How information submitted through the contact form is limited, protected and handled.

Last reviewed: August 2026

Scope of this website policy

This policy describes how zapinmnl.com handles information submitted through its contact form and the technical data needed to deliver and protect the website. Shopping accounts, checkout, comments, uploads and advertising profiles are not part of the website experience.

This policy applies to the website configuration described here. It will be updated whenever hosting, forms, connected services, audiences or processing purposes materially change.

Controller information pending confirmation

The website operator is responsible for personal data submitted through zapinmnl.com. Formal controller identity and registration details must be included before the website is used for binding sales or customer accounts.

Use the contact form only for a general enquiry. Do not submit payment credentials, passwords, identity documents, health information or confidential records through this channel.

Data not requested by the website

The contact form collects a name, email address, topic, message and privacy consent so the enquiry can be read and answered. It does not create an account, newsletter subscription, order or payment record.

If any of these functions is added, the policy, consent language, security controls and provider information must be updated before collection begins. A design element must not be treated as permission to start processing data.

Direct communications

An email link opens the visitor's chosen email service and sends information outside the website. Any message then received must be handled under the verified controller's procedures, including access control, retention, security and response to privacy requests.

Send only the minimum information needed for an initial enquiry. Do not attach identity documents, payment records, credentials, health information or other sensitive material unless the recipient and secure transfer method have been independently confirmed.

Technical delivery data

When the site is publicly hosted, infrastructure providers may process technical information needed to deliver pages, protect the service and investigate incidents. Depending on the final configuration, this may include an IP address, request time, requested path, device or browser information and security-event data.

The policy must name or describe the providers and roles, purposes, lawful bases, retention periods and any international transfers. Server and security logs should not be retained indefinitely by default.

Purposes and lawful bases

No final lawful-basis assessment has been completed for a public launch. Typical website purposes may include delivering requested pages, maintaining security, responding to enquiries and meeting legal obligations, but each purpose must be confirmed against the real processing activity.

Consent should be used only where the visitor receives a genuine choice and can withdraw it. Necessary security and delivery functions may rely on a different basis. The website operator is responsible for documenting the assessment.

Recipients, transfers and retention

Personal data should be accessible only to people and providers who need it for a defined purpose. Supplier contracts, confidentiality, security and instructions must be reviewed before any provider receives personal data through the public site.

Retention must be linked to purpose, legal obligations and documented review. The final schedule should distinguish short-lived technical logs, enquiry correspondence, contractual records and security evidence rather than assigning one period to everything.

Categories of data if site functions are activated

A future enquiry, event, download or support function could process identifiers and contact details, organisation and role information, the content of correspondence, communication preferences and technical records connected with the request. The final form should identify which fields are required and why before a visitor submits them.

Full order records, payment credentials and identity documents are outside the intended scope of an ordinary website enquiry. If a secure order-support or returns workflow is later introduced, it will need its own access rules, notices, contractual allocation of roles and documented handling procedures.

Data minimisation and accuracy

The owner should collect only personal data that is relevant and proportionate to a documented purpose. Optional information should be clearly distinguished from mandatory information, and a process should exist to remove duplicate, excessive or misdirected material.

People providing information should take reasonable steps to keep it accurate and avoid including details about others unless they are authorised and the disclosure is necessary. The organisation should provide a practical route to correct material inaccuracies and record corrections in connected systems where appropriate.

Children and sensitive information

The website presents fashion concepts and is not designed to solicit information from children. Messages that appear to come from a minor should be restricted and deleted where applicable law requires it.

General website channels should not be used for health information, biometric or genetic data, political or religious information, identity documents, financial credentials or other sensitive material. If a legitimate business process ever requires such information, it must use a specifically assessed and protected route.

Automated decisions and profiling

The website does not create advertising profiles or make decisions with legal or similarly significant effects. Security systems may still detect clearly abusive traffic to protect the service.

Any future use of profiling, lead scoring or automated decisions with legal or similarly significant effects would require a separate necessity, fairness and transparency review. The policy and visitor controls must be updated before that processing begins.

Security incidents and notification

The website operator should maintain a process for identifying, containing, recording and investigating suspected loss, misuse, unauthorised access or disclosure. Responsibilities should be agreed with hosting and other providers so that relevant facts can be escalated without avoidable delay.

If an incident affects personal data, the operator must assess the risk, preservation needs and any notification duties under the law that applies to the event. This policy should not promise a universal notification period without first confirming the jurisdiction, role and circumstances.

Cookies and connected services

The separate cookie policy describes browser storage and similar technologies for the current build. If analytics, embedded media, customer chat or other connected services are enabled, the privacy policy must also explain the personal data flows, providers, purposes and available choices.

Withdrawing consent for a non-essential technology should be as straightforward as granting it. Withdrawal does not make earlier lawful processing unlawful, but the site should stop the relevant future storage or access and explain how an existing identifier can be deleted where necessary.

Individual rights

Depending on applicable law and the processing involved, individuals may have rights to information, access, correction, erasure, restriction, portability, objection and review of certain automated decisions. Some rights are subject to conditions and exceptions.

The policy must provide a verified request channel, explain identity checks and name the competent supervisory authority. Requests should be logged and answered within the period required by applicable law.

Security, changes and review

Security measures should be proportionate to the data and risk and cover access, transfer, storage, incident response, backups and supplier management. No public page can guarantee absolute security.

This policy must be reviewed before the relevant feature is activated and whenever forms, analytics, embedded services, providers, locations or business processes change. Material changes should be communicated in a clear and accessible way.