GDPR Policy

Last updated: 9 July 2026

This policy sets out how Zest Assure meets its obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It explains the lawful bases on which we process personal data, the roles we take as controller and processor, the rights individuals hold and how we protect data that moves outside the UK. For a plain-language account of exactly what data we collect and why, read it alongside our Privacy Policy; for the technical and organisational controls that sit beneath it, see our Data Protection Policy.

Who we are

Zest Assure, a trading name of Juicy Media Ltd, is the controller of personal data collected through www.zestassure.com and the processor of the content our customers place in the platform. Juicy Media Ltd is registered in England & Wales under company number 05514688 and with the Information Commissioner's Office under registration number Z1589829. Our registered office is DiSH, Heron House, 47 Lloyd Street, Manchester, M2 5LN.

Questions about data protection, including anything you would raise with a Data Protection Officer, can be sent to hello@zestassure.com or posted to the registered office above. Juicy Media Ltd holds ISO 9001 and ISO 27001 certification, and the controls described in this policy sit within that certified management system.

Controller and processor roles

Our role under the UK GDPR depends on the data in question:

  • Controller. For the personal data we hold about our own prospects, customers' account contacts, suppliers and staff — and for data gathered through www.zestassure.com — we decide why and how the data is processed and act as controller.
  • Processor. For the personal data contained in the content our customers place in their compliance workspaces, the customer remains the controller. We process that data only on the customer's documented instructions and never for our own purposes.

Lawful bases for processing

We process personal data only where a lawful basis under Article 6 of the UK GDPR applies:

  • Performance of a contract — to provide, operate and maintain the platform, including authentication, collaboration and audit-ready exports; to send service emails; and to process subscription payments.
  • Legitimate interests — to secure the service, investigate misuse, maintain audit logs and respond to enquiries from people who are not yet customers, where those interests are not overridden by an individual's rights.
  • Legal obligation — to keep accounting records and to comply with security, tax and company law.
  • Consent — to set analytics cookies and measure and improve the website and platform. You can withdraw consent at any time through our cookie banner or by contacting us; see our Cookies Policy.

We do not use customer compliance content for advertising, and we do not send marketing emails without consent. The full picture of what we collect against each basis is set out in our Privacy Policy.

Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected and incomplete data completed;
  • have your data erased in certain circumstances;
  • restrict or object to particular processing, including any direct marketing;
  • receive the data you provided to us in a portable, machine-readable format;
  • withdraw consent at any time where consent is our lawful basis, without affecting processing that took place before withdrawal.

To exercise any of these rights, email hello@zestassure.com or write to our registered office. We will respond within one month. Where your data sits inside a customer's workspace we may need to refer your request to that organisation, as they act as controller for their own compliance content.

Sub-processors and international transfers

We never sell personal data. We share it only with sub-processors operating under a data processing agreement, or where the law requires disclosure. Some of those sub-processors — and the single sign-on and analytics providers we rely on — process data outside the UK. Where that happens, transfers are protected by an adequacy decision or by the International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses. The current list of sub-processors, their purposes and locations is published in our Privacy Policy.

Data breaches

We maintain a documented incident response procedure. Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it, and we will inform affected individuals — and, where we act as processor, the affected customer — whenever the law requires it. Our breach handling and wider security controls are described in our Data Protection Policy.

Complaints

If you are unhappy with how we have handled your personal data, please contact us first at hello@zestassure.com and give us the chance to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or by phone on 0303 123 1113.

Changes to this policy

We review this policy regularly and will update it when our practices, sub-processors or the law change. The date at the top of the page shows when it was last revised, and we will tell account holders about any material change by email or through the platform. This policy is governed by the laws of England & Wales.