Clear data protection

Privacy policy.

This notice explains what personal information Zytrivox processes, why it is needed, who controls it, how it is protected and the choices available to you.

Your workplace data stays private

Zytrivox personnel do not access or view the contents of customer workplace data. The platform processes that data automatically to provide the service, while access remains with the customer and its authorised users.

We do not sell personal information.
We do not use workplace data for advertising.
Access is role-based, limited and accountable.
Each customer workspace is logically separated.
Last updated22 July 2026
Applies inUnited Kingdom
OrganisationZytrivox Ltd
Company number16662494

1. Who we are

Zytrivox Ltd provides a building operations platform to property managers, managing agents and other organisations. Our registered office is 3rd Floor, 86–90 Paul Street, London, EC2A 4NE. Privacy enquiries can be sent to support@zytrivox.com.

2. Who manages your information

For workplace records, such as resident, visitor, parcel, key, maintenance, message and staff workflow data, the organisation operating your building is the controller. It decides why and how that information is used. Zytrivox provides the secure platform and acts as its processor, handling the information only to operate the service under the building operator's documented instructions.

If you are unsure which organisation operates your building, contact your building management team or ask us at support@zytrivox.com.

3. Information the platform processes

The platform processes information automatically so authorised workplace users can use the features selected by their building operator. This does not mean Zytrivox personnel can view it.

  • Authorised user details, including name, contact details, workplace role, resident reference and flat or unit identifier.
  • Operational entries created inside the workplace, including parcel, collection, visitor, key, ticket, access, leave, message and staff workflow entries.
  • Information voluntarily submitted by an authorised user, including notes, photographs, attachments and support messages.
  • Technical security events needed to protect sign-in, sessions, permissions and audit trails.

This information is supplied by you, your building operator or an authorised workplace user and is processed automatically to provide the requested service.

4. Why information is used

PurposeHow the platform supports it
Provide resident and building services.Runs the workplace features selected by the building operator.
Protect users and workplace records.Authenticates users, enforces permissions, records security events and prevents misuse.
Maintain reliable building operations.Processes authorised workflows, notifications, audit trails, backups and service recovery.
Meet legal and regulatory responsibilities.Supports the building operator's documented retention and compliance requirements.

The building operator is responsible for selecting and explaining the lawful basis for its use of workplace information. Zytrivox processes that information only to provide the platform under its instructions. We do not make solely automated decisions that produce legal or similarly significant effects about residents or staff.

5. Our no-access commitment

Zytrivox personnel will not access, read or browse the contents of customer workplace data. The software must process information automatically to perform the functions requested by the customer, but this does not give Zytrivox staff permission to view that information.

  • Workplace data is available only to the customer and users the customer authorises.
  • Each customer workspace is logically separated so another customer cannot access its records.
  • Support is provided without viewing customer content. Customers remain responsible for deciding what information they share voluntarily in a support request.
  • Authentication, permissions, session controls and audit records protect against unauthorised access.
  • The only exception is where Zytrivox is compelled to disclose specific information by a binding legal requirement. Where the law permits, the affected customer will be notified.

6. Sharing and service providers

We may share information with the customer and its authorised users; hosting, communications and other contracted providers needed to operate the service; professional advisers, insurers or auditors; and regulators, courts or law enforcement where disclosure is lawfully required. Providers must only use information for the contracted service and under appropriate safeguards. We do not sell personal information or share workplace content with advertisers.

7. International transfers

If information is made accessible to a separate organisation outside the UK and this is a restricted transfer, we use a mechanism recognised by UK law, such as UK adequacy regulations, an approved contractual safeguard or a lawful exception. Appropriate risk assessment and supplementary safeguards are used where required.

8. Retention and deletion

Workplace records are kept according to the building operator's instructions, configured retention rules and applicable legal requirements. Information is securely removed when it is no longer required. Deleted data may remain temporarily in protected backups until the relevant backup and recovery cycle expires.

9. Security is built into Zytrivox

Zytrivox is a secure building operations platform designed to protect workplace information at every stage. Security is maintained continuously and the platform receives regular security updates so safeguards remain current as technology and threats evolve.

  • Secure sign-in: authentication, session protection and multi-factor authentication capabilities help prevent unauthorised account access.
  • Strict permissions: role-based access ensures users see only the tools and information their workplace has authorised.
  • Separated workplaces: every customer workspace is logically isolated to prevent information crossing between organisations.
  • Protected records: security audit trails, controlled data handling and protected backups support confidentiality, integrity and recovery.
  • Continuous protection: service health and security events are monitored, with suspicious activity investigated and controlled.
  • Regular security updates: tested updates, security improvements and dependency fixes are deployed through a controlled release process.
  • Prepared response: documented incident and recovery procedures support prompt containment, investigation and restoration if an issue occurs.

Security controls are reviewed and improved as the platform develops. Suspected personal data breaches are assessed and handled promptly under applicable UK data protection requirements.

10. Cookies and session technology

The platform uses cookies or similar storage needed for sign-in, security, session continuity and user preferences. Zytrivox does not use customer workplace data to build advertising profiles. Any optional analytics or non-essential technology introduced in future will be described and handled with the choices required by law.

11. Your rights

Depending on the circumstances, you may have rights to be informed, access your information, correct it, erase it, restrict its use, object, receive portable data, withdraw consent and challenge qualifying automated decisions. Legal conditions and exemptions may apply.

For building or workplace records, contact your building operator first because it is the controller; Zytrivox will assist it with valid requests. You may also contact support@zytrivox.com for help or complain to the Information Commissioner's Office.

12. Changes and contact

We may update this notice when the service, law or our processing changes. Material changes will be communicated through an appropriate channel. The date at the top identifies the current version. Contact support@zytrivox.com for privacy questions or to ask for this notice in another accessible format.

13. Official guidance

This notice reflects ICO guidance on the right to be informed, controller and processor responsibilities, privacy by design and international transfers, together with the Data Protection Act 2018. Read the ICO right to be informed guidance, ICO controller and processor guidance, and GOV.UK data protection overview.