Last updated: 5 July 2026
Zryos treats client confidentiality as a foundational engineering principle — not a legal afterthought. We handle source code, architecture diagrams, business logic, customer data, and strategic plans with the same rigour we apply to security engineering. This policy applies to all Zryos employees, contractors, and subcontractors.
Before any engagement begins, we sign a mutual Non-Disclosure Agreement (NDA) with the client. This protects both parties and establishes the framework for information sharing. Our standard NDA covers:
We classify all client information into three tiers and apply handling rules accordingly:
Any subcontractor engaged on a client project is bound by a written agreement that flows down these confidentiality obligations. Subcontractors do not receive Restricted information unless explicitly approved by the client. We remain fully responsible for subcontractor compliance.
If we become aware of any unauthorised disclosure or access to client confidential information, we will: (a) notify the client within 24 hours, (b) contain the breach immediately, (c) conduct a full investigation and provide a written report within 7 days, and (d) implement corrective measures to prevent recurrence. This is in addition to any obligations under GDPR Article 33.
Upon termination of an engagement or upon written request, we will return or destroy all client confidential materials within 14 days. This includes source code, documentation, data files, and copies on backup media (subject to backup rotation cycles — typically 30 days). A certificate of destruction is available on request.
We may reference the client's name and a general description of the work in our portfolio or case studies only with the client's written consent. We will never publish source code, architecture details, or sensitive project information without explicit approval. Clients may revoke consent at any time.
All Zryos team members receive confidentiality and data protection training at onboarding and annually thereafter. Training covers GDPR, data classification, secure handling, breach response, and the consequences of unauthorised disclosure. Completion is tracked and mandatory.
If required by law, court order, or regulatory authority, we may disclose client confidential information to the extent legally required. Where legally permissible, we will notify the client before disclosure and cooperate in seeking a protective order to limit the scope of disclosure.
This Confidentiality Policy complements our Privacy Policy (which covers personal data under GDPR) and our Terms & Conditions (which govern the overall service relationship). In case of conflict regarding personal data, the Privacy Policy prevails. For all other confidentiality matters, this policy prevails.
Questions about confidentiality? Email legal@zryos.com or write to: Zryos Ltd, Confidentiality Enquiries, Austin · Lisbon · Singapore. We respond within one business day.