LEGAL & DATA GOVERNANCE
Last Revised: September 17, 2026 // WebZentrasLab Compliance Framework
Corporate Registry & Identification
Entity Name: WebZentrasLab
Registered Address: 24145 Kreisauer Ring 94, Kiel, Germany
Contact Email: [email protected]
Contact Phone: +49 1718 4029165
Industry: Web & Technology Infrastructure
Activity: High-concurrency web platforms, network security protocols, fault-tolerant server systems
Privacy Policy & Data Processing (GDPR)
2.1 Data Controller
WebZentrasLab, registered at 24145 Kreisauer Ring 94, Kiel, Germany, acts as the Data Controller under Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR). All personal data processing activities are conducted in compliance with applicable EU data protection legislation.
2.2 Data Retention Schedule
Personal data submitted through our contact forms and consultation consoles is retained for the following periods:
- Project inquiry data: 24 months from last communication, or until project completion plus 6 years for tax compliance.
- Contractual data: Duration of the commercial relationship plus 10 years per German commercial law requirements (Handelsgesetzbuch §257).
- Cookie & telemetry data: Maximum 13 months from collection date.
- Marketing consent records: Retained indefinitely until withdrawal of consent.
2.3 Data Handling Lifecycle
All personal information is processed exclusively for client communication, project delivery, technical support, and statutory reporting obligations. We employ AES-256 encryption for data at rest and TLS 1.3 for data in transit. Our infrastructure is hosted exclusively within EU-based data centers to ensure data sovereignty compliance.
2.4 Third-Party Data Sharing
WebZentrasLab does not sell, rent, or distribute personal information to unauthorized third-party data brokers. Limited data sharing occurs only with essential service providers (payment processors, email delivery services) under Data Processing Agreements (DPAs) that meet GDPR Article 28 requirements.
2.5 Client Rights
Under GDPR, you have the following rights:
- Right of Access (Art. 15): Request a copy of all personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data, subject to legal retention obligations.
- Right to Restriction (Art. 18): Request limitation of processing activities.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
To exercise any of these rights, contact our Data Protection team at [email protected]. We will respond within 30 days of receipt.
Terms of Service
3.1 Scope of Services
All digital services, infrastructure builds, and engineering advisory provided by WebZentrasLab are governed by explicitly contracted Statements of Work (SOW) executed between the client and WebZentrasLab. Services include but are not limited to: high-concurrency web platform development, network security protocol implementation, fault-tolerant server system architecture, real-time streaming infrastructure, API gateway configuration, database cluster management, DDoS mitigation, CI/CD pipeline setup, and 24/7 monitoring SLA retainers.
3.2 Intellectual Property Transfer
Upon complete settlement of all agreed commercial invoices, WebZentrasLab assigns all worldwide intellectual property rights in client-specific software deliverables, design tokens, configuration files, and digital assets directly to the client. Pre-existing frameworks, libraries, and proprietary tools used in development remain the property of WebZentrasLab under perpetual non-exclusive licenses granted to the client.
3.3 Project Deliverables & Acceptance
Deliverables are presented for client acceptance review within the timelines specified in the project SOW. The client has a 14-business-day acceptance window following each milestone delivery. Silence beyond this period constitutes deemed acceptance unless the client provides written objection specifying material defects.
3.4 Limitation of Liability
WebZentrasLab's total aggregate liability under any engagement shall not exceed the total fees paid by the client under the applicable SOW. We shall not be liable for indirect, consequential, or incidental damages including but not limited to lost profits, data loss, or business interruption.
Refund & Reimbursement Policy
5.1 Project Refund Terms
Refund eligibility is evaluated on a milestone-by-milestone basis according to the following schedule:
- Pre-commencement cancellation: 100% refund of any advance payments if cancelled before work begins, minus administrative processing fee of 3%.
- Early-stage cancellation (within first 30% of project timeline): Refund of 75% of remaining unearned fees.
- Mid-project cancellation: Refund of 50% of remaining unearned fees. All completed work and intellectual property delivered to date remain with the client.
- Late-stage cancellation (beyond 70% of project timeline): No refund of fees. All completed deliverables and source code are transferred to the client.
5.2 SLA Retainer Refunds
Monthly SLA retainer subscriptions may be cancelled with 30 days' written notice. Refunds for the current billing period are provided on a pro-rata basis for unused calendar days, calculated from the date of written cancellation notice.
5.3 Refund Processing
Approved refunds are processed within 14 business days to the original payment method. Processing fees charged by third-party payment providers are non-refundable. To initiate a refund request, contact [email protected] with your project reference number.
Security Audits & Compliance
6.1 Infrastructure Security Audits
WebZentrasLab conducts quarterly internal security audits and annual third-party penetration testing across all client-facing infrastructure. Audit reports are available to enterprise clients upon request under mutual NDA.
6.2 Compliance Certifications
Our infrastructure and operational procedures comply with:
- GDPR (EU) 2016/679 - General Data Protection Regulation
- CCPA - California Consumer Privacy Act (for US-based clients)
- ISO/IEC 27001 - Information Security Management
- SOC 2 Type II - Trust Service Criteria for Security, Availability, and Confidentiality
6.3 Incident Response
In the event of a personal data breach, WebZentrasLab will notify the relevant supervisory authority within 72 hours of discovery and inform affected data subjects without undue delay when the breach is likely to result in high risk to their rights and freedoms, in accordance with GDPR Articles 33 and 34.