Privacy Policy

Last updated 26 August 2026

We hold passport numbers and, sometimes, a tax identification number. This policy says exactly what we collect, why, how it is protected and what you can ask us to do with it.

1. The short version

To register a company we have to collect real identity information — full legal names, dates of birth, addresses and passport or ID numbers. ZAMTRIX Business Formations collects only what a filing actually needs, encrypts the sensitive parts, never sells any of it, and shares it only with the authorities and providers required to complete your order.

The rest of this policy sets out the detail. If anything is unclear, ask us before you send us anything.

2. Who is responsible

ZAMTRIX Business Formations is the data controller for the information described here — meaning we decide why and how it is used, and we are accountable for it.

For any privacy question, or to exercise a right described below, contact w.z.bizmail@gmail.com.

3. What we collect

  • Account details: your full name, username, email address, date of birth, nationality and phone number. Date of birth is collected because we cannot serve anyone under 18.
  • Company details: the name you want, what the business will do, its addresses, its management structure and any classification codes.
  • Owner details: for every owner and manager — full legal name, address, nationality, date of birth, ownership share, contact details, and identity document type, number, issuing country and expiry date, together with the picture of that document you upload.
  • Tax identifiers: your US Social Security Number or ITIN, only where you tell us you have one and it is needed for your EIN application.
  • Payment records: the amount, method, date and reference. If you pay by card, your card details are entered on our payment provider's own secure page — they never reach our servers, and we never see or store your card number. If you pay by transfer, we keep the receipt you upload and the sender name you give.
  • Correspondence: messages you send us, and a record of the emails we send you about your application.
  • Technical data: the minimum needed to keep you signed in and the site working securely.

We do not use advertising cookies, we do not track you across other websites, and we do not build marketing profiles.

4. Why we hold it, and on what basis

  • To perform our contract with you: preparing and filing your formation documents, applying for your EIN, arranging your registered agent and address, delivering your documents and supporting you afterwards. Without this information we cannot provide the service at all.
  • To meet legal obligations: accounting and tax records, and checks we are required to carry out before acting for someone.
  • For our legitimate interests: keeping the service secure, preventing fraud and abuse, keeping records of what was filed and when, and establishing or defending legal claims. We weigh these against your interests and use the least intrusive approach that works.
  • With your consent: where we ask for it explicitly, such as sending you something you opted into. You may withdraw consent at any time, which does not affect what was lawful beforehand.

5. How it is protected

  • Identity numbers — passports, national IDs, SSNs, ITINs and any EIN we obtain — are encrypted before storage using AES-256-GCM, and are shown masked by default even to our own staff.
  • Account passwords are stored only as salted bcrypt hashes. Nobody, including us, can read your password.
  • The site is served over HTTPS, and uploaded documents are never publicly addressable.
  • Your order page is reached through a private link unique to you. Treat it like a password — anyone holding the link can see that order's progress. Documents you upload to us are never served back out through it, so a leaked link cannot be used to obtain your passport scan.
  • Access to a full application is restricted to administrators of the service.

No system is perfectly secure. We take the measures above seriously, but we cannot guarantee absolute security, and you send information to us accepting that residual risk.

6. Who we share it with

Only where your order requires it:

  • the state or agency you are registering with, and the IRS for your EIN — this is the purpose of the exercise, and some of what is filed becomes public record;
  • the registered agent, business address and mail providers whose services you ordered;
  • our payment provider, to take and reconcile your payment;
  • a bank, where you have asked us to support an application to them;
  • our email provider, to deliver notifications to you;
  • professional advisers, or an authority, where we are legally required to disclose or need to establish or defend a legal claim.

We do not sell your information, we do not rent it, and we do not share it for anyone's advertising.

If our business is ever sold or merged, your information may transfer as part of it — and would remain subject to a policy no less protective than this one.

7. What becomes public

Registering a company is a public act. Depending on the state, the company name, its registered address, and sometimes the names of owners or managers appear on a public register that anyone can search.

Using our registered agent service and business address is what keeps your own address off that register. We will tell you what your chosen state publishes before you file. Once information is on a public register we cannot remove it, and this policy cannot protect it.

8. International transfers

This service is inherently international: you may be anywhere, the company is registered in the United States, and our team and providers are elsewhere again. Your information will therefore be transferred to and processed in countries other than your own, including the United States and Pakistan, whose data protection laws may differ from yours.

By using the service you acknowledge and consent to those transfers. Where we are required to put safeguards in place for such transfers, we do.

9. How long we keep it

For as long as we act for your company, and afterwards for as long as we must keep business records — generally seven years from the end of the relationship.

You may ask us to delete an identity document image once the filing it supported is complete, and we will, unless we are required to retain it. Records of what was filed, and of payments, are kept for the full retention period because we are obliged to keep them.

10. Your rights

Subject to the law that applies to you, you may ask us to:

  • give you a copy of the information we hold about you;
  • correct anything inaccurate or incomplete;
  • delete what we are not obliged to keep;
  • restrict or object to certain processing;
  • provide your information in a portable format;
  • withdraw consent where processing relies on it.

Email w.z.bizmail@gmail.com and we will respond within 30 days. We may need to verify your identity first — which, given what we hold, is a protection for you.

Depending on where you live you may also have the right to complain to a data protection authority. We would rather you came to us first so we can put it right.

11. Children

The service is not for anyone under 18. We do not knowingly collect information from children, and we refuse applications where an owner is under age. If you believe a child has given us information, tell us and we will delete it.

12. Cookies

We use only the cookies needed to keep you signed in and to keep the site functioning securely. There is no advertising, analytics profiling or cross-site tracking here, so there is no consent banner to click through — because there is nothing to consent to.

13. Changes to this policy

We may update this policy as the service changes. The date at the top shows when it was last revised. Where a change materially affects your rights we will tell you by email.

14. Contact

Any question about your information: w.z.bizmail@gmail.com.