1 Our Role: Controller and Processor
Depending on the context, we act in different roles under data protection law:
- As a controller (or “business”), we determine how and why personal information is processed — for example, account registration data, billing information, website analytics, and marketing.
- As a processor (or “service provider”), we process personal information on behalf of our business customers when they upload or generate Customer Data through the Services. In that case, our customer is the controller, and our processing is governed by our agreement with them and this Policy. This Policy describes our practices as a controller; where we act as a processor, our customer’s privacy notice and instructions govern.
2 Information We Collect
We collect the following categories of personal information:
2.1 Information you provide
- Account and contact data: name, business email, company name, job title, username, and credentials.
- Billing data: billing contact, billing address, and limited payment metadata. Full payment card details are collected and processed by our payment processor (Stripe) — we do not store full card numbers.
- Communications: information you provide when you contact support, respond to surveys, or communicate with us.
2.2 Information collected automatically
- Usage data: features used, actions taken, pages viewed, timestamps, and interaction data.
- Device and log data: IP address, browser type, device identifiers, operating system, and referring URLs.
- Cookies and similar technologies: see Section 11.
2.3 Information from connected Third-Party Services
When you connect a Third-Party Service (such as TikTok Shop, Shopify, or others) to the Services, we receive data from those platforms as authorized by you — for example, store, catalog, order, performance, and account data. The data we receive depends on the integration and the permissions you grant. This may include personal information relating to your customers or contacts; where it does, you act as the controller and we process it on your behalf.
2.4 Customer Data
You and your Authorized Users may submit content and data into the Services. To the extent Customer Data contains personal information, we process it as a processor on your behalf.
3 How We Use Personal Information
We use personal information to:
- Provide, operate, maintain, and secure the Services;
- Create and administer Accounts and authenticate users;
- Process payments and manage Subscriptions (via Stripe);
- Enable and operate integrations with Third-Party Services;
- Provide AI Features and generate Output;
- Develop and improve the Services, including training, fine-tuning, and improving our AI models and features (see Section 4);
- Provide customer support and respond to inquiries;
- Communicate with you about the Services, including service and security notices;
- Send marketing communications where permitted (you may opt out at any time);
- Detect, prevent, and address fraud, abuse, security, and technical issues;
- Comply with legal obligations and enforce our agreements.
4 AI and Machine Learning
The Services use artificial intelligence and machine learning. We may use Customer Data and usage data to operate the AI Features and to train, fine-tune, evaluate, and improve our models and Services.
When we use data for model-improvement purposes:
- We apply measures designed to protect it, including aggregation and de-identification where reasonably practicable;
- Where we process personal information of our business customers’ end users as a processor, we do so in accordance with our agreement with the customer, and only as permitted by the customer’s instructions and applicable law;
- We do not use this data to make decisions producing legal or similarly significant effects about individuals without a lawful basis and appropriate safeguards.
Where you are our direct customer, you may request to opt your Customer Data out of model-improvement use by contacting us at hello@joinzenith.ai. Opting out may limit the availability or quality of certain features.
AI-generated Output may be inaccurate and should be reviewed before use. See our Terms of Service for details.
5 Legal Bases for Processing (GDPR/UK GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Services you or your organization have requested.
- Legitimate interests — to operate, secure, and improve the Services, and for direct marketing to business contacts, balanced against your rights.
- Consent — where required, such as for certain marketing; you may withdraw consent at any time.
- Legal obligation — to comply with applicable laws.
Where we act as a processor, the controller (our customer) is responsible for establishing a lawful basis for processing.
6 How We Share Personal Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share personal information only as described below:
- Service providers / sub-processors: vendors who help us operate the Services — for example, cloud hosting and infrastructure, payment processing (Stripe), email delivery, and customer-support tooling. These parties are bound by contractual obligations to protect the data and use it only as instructed. A current list of our sub-processors is available on request at hello@joinzenith.ai.
- Third-Party Services you connect: when you enable an integration, data flows to and from that service as you authorize.
- Legal and safety: where required by law, legal process, or to protect the rights, safety, and security of Zenith AI, our users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
- With your direction or consent: where you otherwise instruct us to share information.
7 International Data Transfers
We operate across the United States and Canada and may process personal information in these and other countries. Where we transfer personal information across borders — including from the European Economic Area, the UK, or Switzerland to countries that may not provide an equivalent level of protection — we implement appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement/Addendum, and additional measures as required. You may request more information about these safeguards using the contact details in Section 15.
8 Data Retention
We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. When personal information is no longer needed, we will delete or de-identify it. Where we act as a processor, we retain and delete Customer Data in accordance with our agreement with the relevant customer. Specific retention periods depend on the type of data and the purpose for which it is held.
9 Your Privacy Rights
Your rights depend on where you are located. We honor the rights granted to you under applicable law.
9.1 GDPR / UK GDPR (EEA and UK)
You may have the right to: access your personal information; correct inaccurate data; request erasure; restrict or object to processing; data portability; and withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.
9.2 CCPA / CPRA (California)
California residents have the right to: know the categories and specific pieces of personal information collected; know whether information is sold or shared; access and delete personal information; correct inaccurate information; and limit the use of sensitive personal information. As noted in Section 6, we do not sell or share personal information. We will not discriminate against you for exercising these rights.
9.3 PIPEDA and Canadian provincial laws
Individuals in Canada have the right to access and correct their personal information and to withdraw consent, subject to legal and contractual restrictions.
9.4 How to exercise your rights
To exercise any right, contact us at hello@joinzenith.ai. We will verify your request and respond within the timeframes required by applicable law. You may use an authorized agent where permitted. If your request concerns data we process on behalf of a business customer (as a processor), we will refer your request to that customer or act on their instructions.
10 Security
We implement administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for securing access to your Account.
11 Cookies and Tracking Technologies
We use only essential (strictly necessary) cookies and similar technologies required to operate the Services, authenticate users, maintain sessions, and keep the Services secure. We do not use advertising cookies, and we do not use cookies for cross-context behavioral advertising. Because these cookies are necessary for the Services to function, they cannot be disabled through a consent banner, though you can manage cookies through your browser settings (which may affect functionality). If we introduce analytics or other non-essential cookies in the future, we will update this Policy and provide any required controls.
12 Children’s Privacy
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from individuals under the age of 18. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
13 Third-Party Links and Services
The Services may contain links to, or integrate with, third-party websites and services that we do not control. This Policy does not apply to those third parties. We encourage you to review their privacy policies.
14 Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Services or by other appropriate means and update the “Last updated” date above. Your continued use of the Services after the changes take effect constitutes acceptance.
15 Contact Us
Zenith AI is jointly operated by Les Zinzons LLC (United States) and Cumuless Search Technologies Inc. (Canada).
For privacy questions or to exercise your rights:
If you are in the EEA or UK and have unresolved concerns, you have the right to complain to your local data protection authority.
Zenith AI