Privacy Policy — Zenithy
← Back to Zenithy
Legal

Privacy Policy

Last updated: [effective date] · Data controller: [legal entity name] (“Zenithy”, “we”, “us”).

Plain-language draft. This template is not legal advice. Please have it reviewed by a qualified privacy lawyer — and align it with your actual data flows and sub-processors — before publishing.

Contents

  1. Overview
  2. Who we are
  3. Information we collect
  4. How we use it
  5. Legal bases
  6. Data we process for you
  7. Sub-processors
  8. Cookies & analytics
  9. Data retention
  10. Security
  11. International transfers
  12. Your rights
  13. Children
  14. Changes
  15. Contact

1Overview

This Privacy Policy explains how Zenithy collects, uses and protects personal data when you visit our website, book a demo, or engage us to build and run your Meta-ads analytics system. It also explains how we handle the advertising data we process on your behalf.

2Who we are

Zenithy is operated by [legal entity name], [registered address]. For any privacy question, contact [[email protected]].

3Information we collect

a. Information you give us

When you contact us, book a demo, or become a client, we collect details such as your name, work email, company, role, and the content of your messages. If you become a client, we also process the business and access details needed to deliver the Service.

b. Information collected automatically

When you visit our website we may collect limited technical data such as IP address, browser type, pages viewed and referring URLs, via cookies or similar technologies (see Section 8).

c. Demo bookings

Demo calls are scheduled through our third-party scheduling provider (Cal.com). Information you enter to book (such as your name and email) is processed by that provider on our behalf, subject to their privacy terms.

4How we use your information

5Legal bases (GDPR)

Where the GDPR applies, we rely on: performance of a contract (to deliver the Service you request), legitimate interests (to run and improve our business and secure our systems), consent (for non-essential cookies and marketing, where required), and legal obligation (for example accounting and tax records).

6Data we process on your behalf

As part of the Service, we help sync your advertising data (which may include limited personal data contained in your ad accounts) from Meta into a database that you own or control. In relation to that data, you are the data controller and we act as your data processor: we process it only on your documented instructions, to build, operate and support your system, and we do not sell it or use it for our own purposes. A data processing agreement can be provided on request.

7Sub-processors

We use trusted third parties to provide the Service. Representative categories (confirm and complete for your actual stack):

ProviderPurpose
Meta PlatformsSource of your advertising data (Marketing API)
AirbyteAutomated data synchronisation
Railway / Google BigQueryDatabase & data warehousing (client-owned where applicable)
Hosting provider [e.g. Vercel]Application hosting
Cal.comDemo scheduling
Email / CRM [provider]Communications

8Cookies & analytics

Our website uses essential cookies to function and may use analytics cookies to understand usage. Where required, we ask for your consent before setting non-essential cookies, and you can manage preferences through your browser. [Add your cookie/consent tool details.]

9Data retention

We keep personal data only as long as necessary for the purposes described here, to provide the Service, and to meet legal, accounting or reporting requirements. Data processed on your behalf is retained according to your instructions and your infrastructure’s settings, and deleted on request where we control it.

10Security

We apply appropriate technical and organisational measures to protect personal data, including scoped, least-privilege access and, where possible, read-only access to your accounts. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address any incident.

11International transfers

Your information may be processed in countries other than your own. Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.

12Your rights

Depending on your location, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent. To exercise these rights, contact us at [[email protected]]. You also have the right to complain to your local data protection authority.

13Children

The Service is for businesses and is not directed at children under 18. We do not knowingly collect personal data from children.

14Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with a new “Last updated” date.

15Contact

For any privacy request or question, contact [[email protected]], [legal entity name & address]. See also our Terms & Conditions.