Confidentiality Policy — Zryos | NDA, Data Handling & Security
/ LEGAL

Confidentiality
Policy.

Last updated: 5 July 2026

1. Our commitment

Zryos treats client confidentiality as a foundational engineering principle — not a legal afterthought. We handle source code, architecture diagrams, business logic, customer data, and strategic plans with the same rigour we apply to security engineering. This policy applies to all Zryos employees, contractors, and subcontractors.

2. Mutual NDAs

Before any engagement begins, we sign a mutual Non-Disclosure Agreement (NDA) with the client. This protects both parties and establishes the framework for information sharing. Our standard NDA covers:

  • Definition of confidential information (broadly scoped)
  • Permitted use (solely for delivering the agreed services)
  • Exclusions (information already public, independently developed, or rightfully received from a third party)
  • Duration of obligations (3 years post-engagement, unless otherwise agreed)
  • Return or destruction of materials upon request

3. Information classification

We classify all client information into three tiers and apply handling rules accordingly:

  • Restricted — Production source code, API keys, credentials, customer PII, financial data, trade secrets. Access: named individuals only, logged, encrypted at rest and in transit. Never shared outside the engagement team.
  • Confidential — Architecture diagrams, project plans, internal documentation, business requirements. Access: engagement team and authorised client personnel. Shared only under NDA.
  • Internal — General project status, non-sensitive technical discussions. Access: Zryos team members on the engagement. May be discussed internally for knowledge sharing without identifying the client.

4. Access controls

  • Need-to-know basis — Only team members directly involved in an engagement have access to client materials.
  • Role-based access — Permissions are scoped to each person's role (developer, reviewer, DevOps). No blanket access.
  • Audit trail — Access to Restricted information is logged. Logs are retained for 12 months.
  • Offboarding — When a team member leaves an engagement or Zryos, access is revoked within 24 hours. All client materials on personal devices are deleted.

5. Data handling & storage

  • Encryption — TLS 1.2+ in transit, AES-256 at rest. Client data is never stored on unencrypted media.
  • Isolation — Each client's data is stored in isolated environments (separate repositories, databases, or namespaces). No cross-client data leakage.
  • No personal devices — Client source code and Restricted materials are not copied to personal laptops or drives. Work is conducted on company-managed machines or client-provided environments.
  • Cloud hosting — When we host client infrastructure, it runs in GDPR-compliant cloud regions selected by the client.

6. Subcontractors

Any subcontractor engaged on a client project is bound by a written agreement that flows down these confidentiality obligations. Subcontractors do not receive Restricted information unless explicitly approved by the client. We remain fully responsible for subcontractor compliance.

7. Breach notification

If we become aware of any unauthorised disclosure or access to client confidential information, we will: (a) notify the client within 24 hours, (b) contain the breach immediately, (c) conduct a full investigation and provide a written report within 7 days, and (d) implement corrective measures to prevent recurrence. This is in addition to any obligations under GDPR Article 33.

8. Return & destruction

Upon termination of an engagement or upon written request, we will return or destroy all client confidential materials within 14 days. This includes source code, documentation, data files, and copies on backup media (subject to backup rotation cycles — typically 30 days). A certificate of destruction is available on request.

9. Portfolio & references

We may reference the client's name and a general description of the work in our portfolio or case studies only with the client's written consent. We will never publish source code, architecture details, or sensitive project information without explicit approval. Clients may revoke consent at any time.

10. Employee training

All Zryos team members receive confidentiality and data protection training at onboarding and annually thereafter. Training covers GDPR, data classification, secure handling, breach response, and the consequences of unauthorised disclosure. Completion is tracked and mandatory.

11. Legal disclosure

If required by law, court order, or regulatory authority, we may disclose client confidential information to the extent legally required. Where legally permissible, we will notify the client before disclosure and cooperate in seeking a protective order to limit the scope of disclosure.

12. Relationship to other policies

This Confidentiality Policy complements our Privacy Policy (which covers personal data under GDPR) and our Terms & Conditions (which govern the overall service relationship). In case of conflict regarding personal data, the Privacy Policy prevails. For all other confidentiality matters, this policy prevails.

13. Contact

Questions about confidentiality? Email legal@zryos.com or write to: Zryos Ltd, Confidentiality Enquiries, Austin · Lisbon · Singapore. We respond within one business day.