Effective: 26 June 2026 · Read time: ~10 min
We believe privacy is a right, not a feature. This policy explains exactly what data we collect, why we collect it, and how you can control it. We follow India's DPDP Act 2023 as our primary framework and meet the requirements of GDPR, COPPA, and other applicable global laws.
zpsyche ("we," "us," "our") is the Data Fiduciary under India's DPDP Act 2023 and the Data Controller under the EU GDPR for personal data processed through zpsyche.com.
Contact for privacy matters: legal@zpsyche.com
For users in the EU, UK, or other GDPR-applicable jurisdictions, we process your data under the following legal bases:
Processing necessary to provide the personality test service you signed up for.
Country detection at signup (you may opt out by contacting us). Marketing emails (explicit opt-in only).
Fraud prevention, platform security, and anonymised analytics.
Retaining payment records for tax and accounting compliance.
We do not sell, rent, or trade your personal data. We share data only with the sub-processors listed below, each bound by data processing agreements:
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database & auth | All account & result data (encrypted at rest) |
| Payment processor | Payments | Email, order amount, transaction ID |
| PostHog | Analytics | Anonymised usage events (no PII by default) |
| ipapi.co | Country detection | IP address at signup only; country name stored, IP discarded |
| Email provider | Transactional email | Email address, OTP, receipts |
We may disclose data to law-enforcement authorities if required by a valid court order or applicable law. We will notify you unless prohibited from doing so.
We use minimal, privacy-respecting cookies:
We do not use third-party advertising cookies or behavioural tracking for ad targeting. We do not participate in any ad network.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access
Request a copy of the data we hold about you.
Rectification
Correct inaccurate or incomplete data.
Erasure
Request deletion of your personal data ("right to be forgotten").
Portability
Receive your data in a machine-readable format.
Restriction
Ask us to pause processing while a dispute is resolved.
Objection
Object to processing based on legitimate interests.
Withdraw Consent
Revoke previously given consent at any time.
Nomination (DPDP)
Nominate another person to exercise rights on your behalf in the event of death or incapacity (India only).
To exercise any right, email legal@zpsyche.com. We will respond within 30 days (or 72 hours for data-breach notifications).
Current policy:to create a zpsyche account and consent on your own behalf, you must be 18 or older — a single global floor, applied the same way in every country, not the jurisdiction-by-jurisdiction minimums below. A user under 18 may still use zpsyche with a parent or guardian’s self-attested consent — see Terms & Conditions §02 for exactly how that consent is given and what it means.
The table below is kept for transparency about what each jurisdiction’s own law technically permits for self-consent — it does not describe zpsyche’s own policy, which is the global floor and guardian-consent path described above regardless of jurisdiction.
Last reviewed: 26 June 2026. Laws change — always verify with official sources (linked below).
| Region / Law | Min. age to self-consent | Under that age |
|---|---|---|
🇪🇺 European Union GDPR — Art. 8 Member states may lower to 13 | 16 (min. 13)GDPR Article 8 ↗ | Parental consent required |
🇺🇸 United States COPPA Federal minimum | 13FTC COPPA Rule ↗ | Verifiable parental consent required |
🇺🇸 California, USA CCPA / CPRA Under 13: parent opt-in; 13–16: user opt-in | 13–16CA AG — CCPA ↗ | Opt-in consent required |
🇬🇧 United Kingdom UK GDPR / DPA 2018 Age Appropriate Design Code applies | 13ICO UK GDPR ↗ | Parental consent required |
🇨🇦 Canada PIPEDA / CPPA OPC guidance; CPPA reform pending | 13OPC — PIPEDA ↗ | Parental consent required |
🇦🇺 Australia Privacy Act 1988 / Online Safety Act Social media minimum is 16 (2024 legislation) | 15OAIC Privacy Act ↗ | Parental consent + age assurance required |
🇨🇳 China PIPL — Art. 31 Personal information of minors under 14 | 14PIPL (NPC) ↗ | Guardian consent required |
🇯🇵 Japan APPI (revised 2022) Based on civil code contractual capacity | 15PPC Japan ↗ | Parental consent required |
🇰🇷 South Korea PIPA — Art. 22 Legal representative consent required below 14 | 14PIPC Korea ↗ | Legal representative consent required |
🇧🇷 Brazil LGPD — Art. 14 Children defined as under 12; adolescents 12–18 with restrictions | 12LGPD (gov.br) ↗ | Parental / guardian consent required |
🇸🇬 Singapore PDPA 2012 PDPC advisory guidance | 13PDPC Singapore ↗ | Parental / guardian consent required |
🇮🇳 India DPDP Act 2023 — § 9 Highest threshold globally; parental consent must be verifiable | 18MeitY — DPDP Act ↗ | Verifiable parental / guardian consent required |
This table is for informational purposes only and does not constitute legal advice. Age thresholds may vary by service type and national implementation. Consult official sources for the latest requirements.
Your data may be processed outside your country of residence (e.g., on servers operated by Supabase). Where data is transferred internationally, we ensure appropriate safeguards are in place — including Standard Contractual Clauses (EU SCCs) where applicable — to ensure your data receives an equivalent level of protection.
We implement industry-standard technical and organisational measures to protect your data:
No method of transmission over the internet is 100% secure. In the event of a data breach that poses a risk to your rights, we will notify you and relevant authorities within 72 hours of becoming aware.
We may revise this Privacy Policy to reflect changes in law, technology, or our services. When we make material changes, we will update the "Effective" date at the top of this page and notify registered users via email at least 14 days before the changes take effect. Your continued use after that date constitutes acceptance of the revised policy.
For privacy enquiries, data requests, or to file a grievance under the DPDP Act 2023:
zpsyche — Privacy & Data Protection
Email (all privacy requests)
legal@zpsyche.comResponse time
Within 30 days for standard requests · 72 hours for breach notifications
Grievance Officer (DPDP Act)
Same contact above · Subject line: "DPDP Grievance"