Privacy Policy
At Zoiko Supply Group Inc., data protection is not just a compliance requirement — it is a strategic imperative for sustaining trust across our global supply chain. Operating in the USA, UK, Canada, LATAM, Asia-Pacific, and the Caribbean, we apply the strictest privacy and security standards to personal, commercial, and trade data.
Compliance Framework
We comply with, and often exceed, the requirements of:
- United States — California Consumer Privacy Act (CCPA), Health Insurance Portability and Accountability Act (HIPAA, where relevant), Federal Trade Commission (FTC) data standards.
- United Kingdom & European Union — UK Data Protection Act 2018 and General Data Protection Regulation (GDPR).
- Canada — Personal Information Protection and Electronic Documents Act (PIPEDA), plus applicable provincial legislation.
- LATAM — Brazil's General Data Protection Law (LGPD), Mexico's Federal Law on the Protection of Personal Data, and other national frameworks.
- Asia-Pacific — Singapore's Personal Data Protection Act (PDPA), Australia's Privacy Act, and local equivalents across operating territories.
- Caribbean — Adherence to data protection laws in Jamaica, Trinidad & Tobago, and other jurisdictions in which we operate.
Principles We Follow
- Lawful, Fair & Transparent Processing — Data is collected with knowledge, consent, and legitimate business purpose.
- Supply Chain Data Protection — Commercial and customs records, trade documentation, and partner information are safeguarded with end-to-end encryption and secure transfer protocols.
- Accuracy & Integrity — We maintain up-to-date, reliable information to ensure operational efficiency and regulatory compliance.
- Limited Retention — Data is stored only as long as necessary for legal, regulatory, or business obligations, after which it is securely destroyed or anonymised.
- Cross-Border Security — International transfers are governed by Standard Contractual Clauses, adequacy decisions, and binding corporate rules.
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access and obtain a copy of your data.
- Rectify inaccuracies.
- Request deletion ("Right to be Forgotten").
- Restrict or object to processing.
- Request portability of your data.
- File a complaint with a national data protection authority.