Skip to content
Zorix Systems — software that powers your business

How we work

Delivery model

Zorix operates from three locations: the United Kingdom, Germany and Pakistan. We state that on the website rather than in the fourth meeting, because a distributed model that only appears during due diligence looks like something being hidden.

This page sets out the structure in the detail your procurement, security and legal teams will ask for.

Structure

Contracting and leadership

The contracting entity is the UK company — Software Systems Limited, 7 Bell Yard, London, England, WC2A 2JR, company number 14466340 — and all commercial terms, liability, insurance and data processing obligations sit with it. Invoicing is in sterling unless you request euros.

Technical leadership sits in the UK and Germany. Every engagement has a named solution architect and a named delivery lead in one of those two locations, and they are the people accountable for the technical outcome. They are not coordinators relaying messages: they design the system, review the code and answer to you for the result.

Engineering capacity sits across all three locations. Our Pakistan operation is a Zorix office with directly employed engineers on Zorix contracts, not a subcontracted or freelance arrangement. The same interview standard, code review process and security policy applies in every location.

Pods

How a delivery pod is composed

Work is delivered by dedicated pods rather than a shared resource pool. A typical pod for a £250,000 to £500,000 phase is a solution architect (part-time across two engagements), a delivery lead, four to six engineers, a QA engineer and a designer as required. The engineers on your system stay on your system for the duration of the phase.

Every person on the pod is named to you, with their location and role. You interview the architect and delivery lead before mobilisation if you want to, and you can reject a proposed team member without explanation.

Working pattern

Overlap, ceremonies and escalation

  • Minimum four hours of working-day overlap with UK business hours, every working day, contractually stated.
  • Stand-up, sprint planning, review and retrospective are held inside the overlap window and are open to your team.
  • Named UK or Germany contacts are reachable through UK business hours; out-of-hours cover is available under a managed run agreement.
  • Escalation step one: the delivery lead, response within one business day. Step two: the engagement director, response within one business day. Both are named in the contract.
  • Public holidays differ by location. The pod calendar is published at mobilisation and factored into the plan rather than discovered at a sprint review.

IP and access

Ownership, repositories and environments

All intellectual property, including source code, documentation and designs, assigns to you on payment for the relevant phase. Every engineer, in every location, is employed under contracts that vest work product in the company and are subject to confidentiality obligations that survive employment.

Repositories can sit in your GitHub, GitLab or Azure DevOps tenancy from the first commit, so you hold the code as a matter of fact rather than of contract. Environments can be hosted in your cloud subscription with our engineers holding scoped, time-limited access issued through your identity provider. Access is reviewed monthly and revoked within one business day of a person leaving the pod.

Cross-border data

Personal data and international transfers

The United Kingdom has not issued adequacy regulations for Pakistan. Where personal data is transferred there, an appropriate safeguard under Article 46 UK GDPR is required: in practice an International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a Transfer Risk Assessment. Zorix maintains both and will provide them for your review before contract.

Our default engineering practice is to avoid the transfer entirely. Production personal data stays in the UK or EU region; offshore engineers work against anonymised or synthetically generated datasets; and where production access is genuinely required for an incident, it is granted just-in-time to a named individual in an approved location, logged, and revoked on closure.

Data processing terms, sub-processor lists, retention periods and breach notification timelines are agreed in the data processing agreement before mobilisation. Our security and compliance position sets out certification and insurance status line by line.

Questions

Frequently asked

Who do we contract with?

The UK entity, under English law, with disputes heard in the courts of England and Wales. You have no contractual relationship with our German or Pakistan operations; they are our delivery capacity, and our obligations to you do not change depending on where an individual sits.

Can we require that all work happens in the UK or EU?

Yes. UK-only or UK and Germany-only delivery is available and is priced differently, because the cost structure is different. Some clients apply this to the whole engagement, others only to specific components such as production data handling.

How do you handle personal data crossing borders?

Transfers to Pakistan are made under an International Data Transfer Agreement or the UK Addendum to the EU SCCs, supported by a Transfer Risk Assessment which we maintain and will share. In most engagements we avoid the question by keeping production personal data inside the UK or EU and giving offshore engineers access only to anonymised or synthetic datasets.

Tell us what your systems are doing wrong.

Send the problem, not a brief. We will tell you whether it is a project we should be involved in.

Talk to us