Privacy Policy

Effective Date: February 16, 2026 · Last Updated: September 24, 2026

This Privacy Policy explains how Zentrik Company (“Zentrik”, “we”, “us”) collects, uses, and shares personal data in connection with: (a) our websites (including zentrik.ai), (b) business communications with prospects and customers, and (c) limited account-related personal data processed to provide the Service (such as User name and email).

Customer content and workspace materials (“Workspace Data”) are governed primarily by our Terms and, where applicable, an executed Data Processing Addendum (“DPA”). For transparency on vendors that process Customer Personal Data, see our Sub-processors list at https://zentrik.ai/sub-processors.

1. Who We Are

Zentrik Company
490 Post St, Ste 500, PMB 2017
San Francisco, CA 94102, USA
Email: privacy@zentrik.ai

2. Personal Data We Collect

2.1 Data you provide

  • Contact information: name, email, phone number, company, role/title.
  • Account information: workspace invitation details, authentication identifiers (including SSO identifiers if used).
  • Billing and transaction information: billing contact details and invoicing details (payment processing may be handled by third parties depending on configuration).
  • Communications: messages, requests, and other information you provide in emails, forms, or support interactions.

2.2 Data collected automatically

  • Device and usage data: IP address, device type, browser type, pages viewed, approximate location derived from IP, and interaction data.
  • Cookies and similar technologies: used for site functionality and analytics as described in Section 7.

2.3 Data from third parties

  • If you use single sign-on, we may receive identity assertions from your identity provider.
  • If you schedule meetings with us using third-party tools, we may receive scheduling and contact details.
  • For business communications, we may collect professional contact details and context from your company’s website, publicly available professional profiles and publications, business introductions, and our prior correspondence with you. This can include your name, work email address, employer, role, publicly available professional information relevant to your role, company, or stated professional interests, and notes from our conversations with you.

2.4 Workspace and integration data

When you use product integrations, API access, MCP clients, or the Zentrik ChatGPT app, Zentrik may process the workspace content and metadata you choose to send or retrieve through those surfaces. This can include customer evidence, interview notes, support summaries, product records, findings, opportunities, ideas, source references, OAuth connection metadata, tool inputs, and tool outputs.

These flows are workspace-scoped. The Zentrik ChatGPT app reads from and writes to the authorized Zentrik workspace selected during OAuth; it does not require users to provide API keys, passwords, MFA codes, payment card data, government identifiers, or full chat transcripts.

3. How We Use Personal Data

We use personal data to:

  • Provide and operate our websites and services.
  • Set up accounts and authenticate Users.
  • Operate user-authorized integrations, API access, MCP clients, and ChatGPT app workflows.
  • Capture, retrieve, summarize, and connect workspace evidence and product records at the user’s request.
  • Communicate about demos, onboarding, support, and service notices.
  • Send relevant business communications about Zentrik, respond to your interest, and record your communication preferences and requests not to be contacted.
  • Process invoices and manage accounts.
  • Improve our websites and services, including analytics and performance troubleshooting.
  • Protect against fraud, abuse, and security incidents.
  • Comply with legal obligations.

4. Marketing Communications

We may contact business professionals about Zentrik, by email or on professional networks such as LinkedIn, when their work is relevant to our products. We use professional contact details and context from the sources described above to choose relevant recipients and tailor our messages. Where we obtain information from public or other third-party sources, we explain how we use it in or before our first communication where required by law. We obtain consent where required by applicable law.

You may object at any time to the use of your personal data for direct marketing. This right is absolute under the GDPR and UK GDPR. To stop future marketing communications, reply to a message, use the unsubscribe link where one is provided, or contact privacy@zentrik.ai. Your request applies to all of our marketing outreach to you, not only the channel where you made it. We keep a record of the request so that we do not contact you for marketing again. This does not stop necessary security, account, or service notices for services you use.

5. Legal Bases (EEA/UK)

Where applicable, we process personal data based on:

  • Contract or steps prior to entering a contract (for example, account setup and providing the Service).
  • Legitimate interests (for example, responding to inquiries, improving the Service, preventing abuse, ensuring security, and identifying and contacting relevant business professionals about Zentrik where permitted by law).
  • Consent (for example, optional product analytics).
  • Legal obligations (for example, tax and accounting).

6. Sharing and Disclosure

We share personal data with:

  • Service providers and Sub-processors that help us operate (hosting, monitoring, analytics and product telemetry, authentication, email delivery and business communications, integration infrastructure, and AI infrastructure as configured).
  • Professional advisors (legal, accounting) as needed.
  • Authorities when required by law.

We do not sell personal data for money. If certain analytics tools are considered “sharing” under some US state privacy laws, we provide opt-out mechanisms where required.

7. Cookies and Analytics

We use cookies and similar technologies for:

  • Essential website functionality.
  • Analytics and telemetry to understand usage and improve performance.

We use PostHog for browser analytics. On our public website we measure page views without cookies or any identifier stored on your device: each page view is recorded under a rotating, server-side hash that cannot be linked to you or across days, which is why the website does not ask for a choice. Inside the product, in regions where consent is required, the analytics SDK is identified only after an explicit choice. Elsewhere, privacy-safe analytics may be enabled by default. Browser analytics can include bounded usage events, device and browser information, and workspace identifiers. For an authenticated product User whose account has a saved display name, PostHog also receives the User's opaque account ID and display name so the person profile is recognizable. Unnamed product Users remain anonymous, and Ideas Portal and optional service telemetry do not create PostHog person profiles. We configure these events not to include email addresses, Workspace Data, transcripts, or other customer content. If optional analytics is rejected or later disabled, we stop identifying you: the analytics SDK is opted out, its stored identifiers are cleared, and no product event is sent. Page views on our public website continue under the same cookieless measurement described above, because they never identified you in the first place. A Global Privacy Control signal from your browser stops all of it, including those page views.

We use masked session recordings to improve the product. In Australia and New Zealand, recordings may start by default; elsewhere we ask before recording. Existing recording refusals and workspace restrictions still apply. You can turn recordings off while keeping usage analytics on through Privacy choices. We configure recordings to retain interface styling and fixed product labels while masking entered text, customer text, and content-bearing attributes. We block customer-content media and exclude console logs and network request details. Recordings are used to understand navigation and usability, not to collect Workspace Data. You can withdraw permission through Privacy choices.

Zentrik manages customer-specific restrictions on browser usage analytics, session recordings, and optional service usage analytics. Contact privacy@zentrik.ai for workspace requirements. Previously saved workspace opt-outs remain effective. These restrictions do not disable essential security records or the connected-source processing that your workspace authorizes to provide the service. A saved workspace restriction takes effect in other open product sessions within 30 seconds; it does not erase previously collected data.

To decide whether to ask for that choice, we derive your approximate country from your IP address on our own servers, using a locally stored database. Your IP address is not sent to a third party for this purpose. This product includes GeoLite2 data created by MaxMind, available from maxmind.com.

You can change this choice through Privacy choices in Zentrik or through your browser settings.

8. International Transfers

Zentrik operates from the United States and may process personal data in the United States and other locations where our service providers operate. Where required, we rely on appropriate safeguards such as standard contractual clauses or other lawful mechanisms.

9. Data Retention

We retain personal data for as long as necessary for the purposes described above, including:

  • For the duration of an account relationship and a reasonable period after.
  • As necessary to comply with legal, accounting, and security obligations.
  • For dispute resolution and enforcement of agreements.
  • Business contact details and correspondence while a business relationship with you is possible or ongoing.
  • A record of any request not to receive marketing communications, for as long as needed to keep honoring it.

10. Your Privacy Rights

Depending on your location, you may have rights to:

  • Access, correct, or delete personal data.
  • Object to or restrict processing.
  • Object at any time to the use of personal data for direct marketing.
  • Request a copy of your data (data portability).
  • Withdraw consent where processing is based on consent.
  • Opt out of certain processing (where applicable).

To exercise rights, contact privacy@zentrik.ai. We may verify your identity.

11. California and US State Privacy Disclosures

If you are a resident of California or certain other US states, you may have additional rights, including:

  • The right to know the categories of personal information collected and disclosed.
  • The right to request deletion of personal information (subject to exceptions).
  • The right to correct inaccurate personal information.
  • The right to opt out of certain disclosures or targeted advertising where applicable.
  • The right not to receive discriminatory treatment for exercising privacy rights.

We do not knowingly sell personal information in exchange for money.

12. Security

We use reasonable administrative, technical, and organizational measures to protect personal data. No system is 100% secure. For more detail, see https://zentrik.ai/security.

13. Changes

We may update this policy from time to time. We will update the “Last Updated” date and, if changes are material, provide additional notice where required.

14. Contact

For questions or requests, email privacy@zentrik.ai.

Company legal contact

Zentrik Company

490 Post St, Ste 500, PMB 2017

San Francisco, CA 94102, USA

Legal: legal@zentrik.ai | Privacy: privacy@zentrik.ai | Security: security@zentrik.ai