Information

Privacy Policy

Last updated: 25 August 2026

This Privacy Policy explains how Zentor AI ("Zentor", "we", "us", "our") collects, uses, shares and protects personal data.

It applies to our website (zentorhq.com and related subdomains), our web application, our demo environment, our marketing and sales communications, and any other service that links to this policy.

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and other applicable data protection law.

1. Who we are

Controller: Zentor AIWebsite: zentorhq.com Privacy contact: privacy@zentorhq.com

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Privacy enquiries are handled by the contact above.

2. The two roles we play

This is the most important thing to understand about how Zentor handles data.

a) As a controller. For data about our website visitors, prospects, account holders and their users, and people who contact us, we decide why and how the data is processed. Sections 3 to 11 of this policy describe that processing.

b) As a processor. When you connect your online store to Zentor, we access your store data in order to generate forecasts and inventory recommendations. That store data may contain personal data relating to your customers and suppliers. For this data, you are the controller and we act only on your documented instructions. Section 12 describes this, and our Data Processing Agreement ("DPA") governs it.

3. Personal data we collect as a controller

3.1. Account and identity data

Name, business email address, phone number (optional), job title, company name, company registration and VAT number, country, account credentials (passwords are stored hashed, never in plain text), and account preferences.

3.2. Billing data

Billing name and address, VAT identification number, subscription plan, invoices, payment status and payment method metadata (for example card type and last four digits). Full card details are handled directly by our payment provider and are never stored on our systems.

3.3. Usage and technical data

IP address, browser type and version, device and operating system, language settings, referring URL, pages and screens viewed, features used, timestamps, session identifiers, error and diagnostic logs, and audit logs of security-relevant actions such as sign-ins and connection changes.

3.4. Communications data

Emails, in-app chat messages, support tickets, demo and onboarding call notes, and your marketing preferences.

3.5. Business contact data used for prospecting

We carry out business-to-business outreach. For that purpose we collect and process business contact information about people in their professional capacity — typically name, job title, company, business email address, public company website data, publicly accessible store information (such as catalogue size or number of out-of-stock products), and public professional profile information. This data is obtained from public sources, commercial data providers, business registries, and email verification services. See Section 6 for the legal basis and your right to object.

3.6. Store connection metadata

The store URL, platform type and version, API credentials or connection tokens you provide, connection status, and the technical configuration of the integration. Credentials are stored encrypted and used only to operate the integration.

3.7. Cookies and similar technologies

See Section 9.

We do not intentionally collect special categories of personal data (Article 9 GDPR), and you should not submit such data to us.

4. Where the data comes from

  • Directly from you, when you sign up, connect a store, contact us, book a demo, or subscribe.
  • Automatically, when you use our website or application.
  • From your connected store, through the integration you authorise.
  • From third parties, including commercial B2B data providers, email verification providers, public business registries, publicly accessible websites, and our payment provider.

5. Why we use personal data

PurposeData usedCreating and administering your accountAccount, identity, technicalProviding the Service, including forecasts and reportsAccount, store connection, usageAuthentication, fraud prevention and platform securityTechnical, audit logsBilling, invoicing, tax and accountingBilling, identitySupport, onboarding and troubleshootingCommunications, technical, accountImproving the Service, debugging, measuring performanceUsage, technicalProduct and service announcementsAccount, communicationsMarketing and B2B outreach to prospectsBusiness contact dataComplying with legal obligationsAs requiredEstablishing, exercising or defending legal claimsAs relevant

6. Legal bases

We rely on the following legal bases under Article 6(1) GDPR:

  • Performance of a contract (Art. 6(1)(b)) — creating and running your account, delivering the Service, processing payments, providing support, and sending service-related communications.
  • Legal obligation (Art. 6(1)(c)) — accounting, invoicing, tax and statutory record retention under applicable law.
  • Legitimate interests (Art. 6(1)(f)) — securing our platform, preventing abuse and fraud, improving and developing the Service, understanding how the Service is used, business-to-business marketing and prospecting to relevant professional contacts, and defending legal claims. Recital 47 GDPR expressly recognises direct marketing as a potential legitimate interest. We balance these interests against your rights and have concluded that our processing is proportionate and within reasonable expectations of business contacts in this sector. You can object to processing based on legitimate interests at any time — see Section 13.
  • Consent (Art. 6(1)(a)) — non-essential cookies and analytics, and marketing emails where consent is legally required. You may withdraw consent at any time; withdrawal does not affect processing carried out before withdrawal.

7. AI, forecasting and model improvement

7.1. Zentor uses machine learning to forecast demand and generate inventory recommendations. Our models operate primarily on commercial data — product identifiers such as EAN and SKU, stock levels, prices, sales quantities and dates. They do not require, and are not designed to use, the identity of your end customers.

7.2. We do not use identifiable customer data to train models for other customers. Where we improve our models using data derived from platform use, we do so on aggregated and de-identified datasets from which individual persons, stores and businesses cannot reasonably be re-identified.

7.3. Automated processing by Zentor produces suggestions and estimates. It does not produce decisions with legal or similarly significant effects on individuals within the meaning of Article 22 GDPR. Purchasing and stocking decisions are made by you.

8. Sharing your data

We do not sell personal data. We share it only with:

a) Service providers (processors) acting on our instructions under written contracts, including cloud hosting and infrastructure, content delivery and security, website hosting, email delivery, payment processing, analytics, error monitoring, CRM and sales engagement tools, and customer support tooling.

b) Professional advisers — accountants, auditors and lawyers, bound by professional confidentiality.

c) Authorities — where required by law, court order or a lawful request from a competent authority.

d) Business transfers — in connection with a merger, acquisition, reorganisation or sale of assets, subject to this policy continuing to apply or you being notified of any change.

An up-to-date list of our sub-processors is available on request at privacy@zentorhq.com. Where the list is published on our website, we will notify subscribed customers of material changes before a new sub-processor starts processing, allowing a reasonable period to object.

9. Cookies and similar technologies

We use:

  • Strictly necessary cookies — required for authentication, session management, load balancing and security. These cannot be disabled and do not require consent.
  • Preference cookies — remember settings such as your language choice.
  • Analytics cookies — help us understand how the site and product are used, so we can improve them.
  • Marketing cookies — used to measure campaign performance and, where applicable, to show relevant advertising.

Non-essential cookies are set only with your consent, collected through our cookie banner. You can change or withdraw your choices at any time via the cookie settings link in our website footer, or by clearing cookies in your browser. Blocking strictly necessary cookies may prevent parts of the Service from working.

10. International transfers

Our primary infrastructure is located in the European Union. Some service providers may process data outside the European Economic Area. Where that happens, we ensure an appropriate transfer mechanism is in place, such as an adequacy decision of the European Commission or the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organisational safeguards. You can request further information at privacy@zentorhq.com.

11. Retention

DataRetentionAccount dataFor the duration of the account, then deleted or anonymised within 30 daysStore data processed for the ServiceFor the duration of the subscription, then 30 days to allow export, then deleted or anonymisedInvoices and accounting recordsUp to 10 years, as required by applicable accounting and tax lawSupport and communicationsUp to 3 years after the last interactionTechnical and security logsTypically up to 12 monthsProspect and marketing contact dataUntil you object or unsubscribe, or up to 24 months without engagement, whichever is earlierCookie consent recordsUp to 12 months

Backups follow a rotating schedule and are overwritten in the ordinary course; data may persist in backups for a limited period after deletion from live systems. We may retain data longer where necessary to establish, exercise or defend legal claims.

12. Store data — where we act as your processor

12.1. When you connect a store, we access data such as products, identifiers (EAN, SKU), categories, prices, stock levels, stock movements, order lines and sales history. Depending on your store's configuration, some of this data may include personal data relating to your customers or supplier contacts.

12.2. For this data:

  • you are the controller and are responsible for having a valid legal basis and for informing your own customers;
  • we act as processor and process it only to provide the Service, on your documented instructions;
  • we do not use it for our own purposes, do not sell it, and do not disclose it except as instructed by you or required by law;
  • our staff access it only where necessary for support, security or maintenance, subject to confidentiality obligations and access controls;
  • we engage sub-processors under written terms no less protective than our own obligations;
  • we assist you, taking into account the nature of processing, with data subject requests, security, breach notification and impact assessments;
  • on termination we delete or return the data as described in Section 11 and in our Terms of Service.

12.3. Data minimisation. Zentor does not need end-customer identity data to function. We recommend that you configure the integration to share only the commercial fields required for forecasting.

12.4. Our DPA, incorporating the requirements of Article 28 GDPR, is available at privacy@zentorhq.com and forms part of your agreement with us.

13. Your rights

Where we act as controller, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten"), where applicable;
  • restrict processing in certain circumstances;
  • data portability — receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
  • object to processing based on legitimate interests, including profiling. Where you object to direct marketing, we will stop immediately and unconditionally;
  • withdraw consent at any time, where processing is based on consent;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see Section 7.3).

To exercise any right, write to privacy@zentorhq.com. We will respond within one month, extendable by two further months for complex requests, in which case we will inform you. We may need to verify your identity before acting. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.

If we act as processor for your store data, individuals should contact the store operator (our customer) directly; we will forward any request we receive to them.

Complaints. If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a data protection supervisory authority — in particular the authority in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement. A directory of European supervisory authorities is maintained by the European Data Protection Board at edpb.europa.eu.

We would appreciate the chance to address your concern first — please write to privacy@zentorhq.com before or alongside a complaint.

14. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest for sensitive fields such as store credentials, hashed passwords, role-based access control and least-privilege access, network protection and web application firewalling, logging and monitoring, regular backups, environment separation, dependency and vulnerability management, and confidentiality obligations for personnel.

No system is completely secure. If a personal data breach occurs that is likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and affected individuals and customers without undue delay where the breach is likely to result in a high risk.

To report a security concern, contact security@zentorhq.com.

15. Children

The Service is intended for business use by adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact privacy@zentorhq.com and we will delete it.

16. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the latest version. Where changes are material, we will notify account holders by email or in-product before they take effect. We encourage you to review this page periodically.

17. Contact

Zentor AI Website: zentorhq.com - info@zentorhq.com