NIS2 — transposed Oct 2024 DORA — enforced Jan 2025 EU AI ACT — Art.50 transparency 2 Aug 2026 CRA — reporting obligations from Sep 2026 ISO 42001 — certification live GDPR — ongoing enforcement NIS2 — transposed Oct 2024 DORA — enforced Jan 2025 EU AI ACT — Art.50 transparency 2 Aug 2026 CRA — reporting obligations from Sep 2026 ISO 42001 — certification live GDPR — ongoing enforcement
Home/Privacy policy

Privacy policy

Zulon Audits OÜ, registry code 17480429, registered at Narva mnt 5, 10117 Tallinn, Estonia, is the controller for the personal data described here. This policy covers visitors to this website and our contacts at client, prospective client and supplier organisations. It does not cover personal data held inside a client's own systems that we see while carrying out an audit or assessment — there we act as a processor on that client's documented instructions, under the data processing agreement signed with them.

We collect business contact details, whatever you choose to tell us in an enquiry or a booked call, engagement and billing records, and technical data such as IP address and pages viewed. We use it to answer enquiries and deliver engagements, either to perform a contract or to take steps at your request before one; to meet our accounting and tax obligations under Estonian law; and to keep the website available and secure, which is our legitimate interest. Analytics and email updates rest on your consent, which you can withdraw at any time and which is explained in our Cookie policy. We do not seek the special categories of data listed in Article 9 GDPR. We keep data only as long as the purpose requires, except where the law fixes the period — accounting records must be preserved for seven years from the end of the financial year under § 12 of the Estonian Accounting Act.

We do not sell personal data and we do not share it for anyone else's marketing. It reaches only the service providers who host this site and run our email, CRM and scheduling systems, each engaged under a written contract meeting Article 28 GDPR, together with our professional advisers and, where the law requires disclosure, public authorities. We keep processing within the European Economic Area; where data does reach a country without an adequacy decision, we transfer it under the European Commission's Standard Contractual Clauses. We apply access controls, encryption in transit and supplier due diligence appropriate to the risk, as Article 32 requires.

You can ask us for a copy of your data, have it corrected or deleted, restrict or object to how we use it, or receive it in a portable format — the rights set out in Articles 15 to 21 GDPR. Objection to direct marketing is absolute, and withdrawing consent is as easy as giving it. Use the contact form on this site and we will reply within one month. You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn), or to the supervisory authority in the EU or EEA country where you live or work.