How we protect your data and respect your privacy under GDPR and international standards. Last updated: March 22, 2026.
The data controller responsible for processing your personal data is:
ul. Konduktorska 18/7
00-775 Warszawa, Poland
KRS: 0001227482 | NIP: 5214156564 | REGON: 544179182
Email: [email protected]
You can contact us with any privacy questions, data requests, or concerns using the contact information above. We aim to respond to all inquiries within 30 days.
We have appointed a Data Protection Officer (DPO) to oversee our data protection practices and ensure compliance with GDPR requirements. The DPO is available to answer questions about our processing activities and to assist with your rights requests.
We collect personal data only when necessary to provide our services, improve your experience, and comply with legal obligations. Below are the types of data we collect:
When you submit our contact form on the website, we collect:
When you subscribe to our newsletter, we collect:
When you visit our website, we automatically collect:
Cookies and similar tracking technologies collect data about your browsing behavior. See Section 10: Cookie Policy for full details.
If you use ZestIQ Sales Agent on your ecommerce store, the product collects and processes:
This data is processed on behalf of your store (the data controller) to provide AI-powered customer service. You retain full control and responsibility for this data.
Under GDPR Article 6, we only process your data where we have a legal basis. Here's our basis for each type of data:
| Data Type | Legal Basis | Purpose |
|---|---|---|
| Contact Form | Legitimate Interest | Respond to your inquiries and provide customer support |
| Newsletter Signup | Consent | Send you marketing emails and product updates |
| Website Analytics | Legitimate Interest | Understand user behavior, improve site performance, ensure security |
| Essential Cookies | Legitimate Interest | Site functionality, security, and user session management |
| Marketing Cookies | Consent | Retargeting ads, email tracking, user engagement metrics |
| Sales Agent Data | Contract Performance | Deliver AI chatbot service to your store and provide analytics |
We use collected personal data only for the following purposes:
We do not sell, rent, or trade your personal data to third parties. However, we may share data with trusted partners who help us provide services, subject to strict data protection agreements:
All service providers are bound by Data Processing Agreements (DPAs) ensuring they process data only on our instruction and maintain equivalent security measures.
We may disclose personal data if required by law, court order, or government request. We will notify you of such requests unless legally prohibited.
If ZestIQ is acquired, merged, or sold, your data may be transferred as part of that transaction. We will provide notice of such changes and any choices you may have regarding your data.
Zero Data Selling Policy: We are fundamentally committed to NOT selling, trading, or disclosing your personal data to advertisers, brokers, or third-party marketers. Your privacy is not a commodity.
ZestIQ operates globally, and your data may be transferred to, stored in, or processed in countries outside the European Union. When we transfer data internationally, we ensure adequate safeguards:
For transfers to the United States, we rely on:
You have the right to know where your data is being transferred and the safeguards in place. You can request information about our data transfer mechanisms at any time by contacting our DPO.
We retain personal data only as long as necessary to fulfill the purposes for which it was collected. Once data is no longer needed, we securely delete or anonymize it.
| Data Type | Retention Period | Reason for Retention |
|---|---|---|
| Contact Form | 2 years | Respond to follow-ups; maintain customer records |
| Newsletter Subscriber | Until unsubscribe | Manage active subscriptions; reactivation opportunities |
| Website Analytics | 24 months | Track long-term trends; inform product decisions |
| Cookie Data | 13 months | Standard analytics retention; comply with GDPR |
| Server Logs | 90 days | Security, fraud prevention, and debugging |
| Sales Agent Conversations | 1 year | Model improvement, analytics, dispute resolution |
| Billing/Payment Records | 7 years | Legal and tax compliance requirements |
After the retention period, data is deleted or irreversibly anonymized. You can request earlier deletion at any time (subject to legal obligations).
Under GDPR Articles 12-22, you have the following rights regarding your personal data:
You have the right to request a copy of all personal data we hold about you, including:
How to exercise: Email [email protected] with subject "Data Access Request."
If your personal data is inaccurate or incomplete, you can request correction. We will update your data and notify relevant third parties (where applicable).
How to exercise: Email [email protected] with subject "Data Correction Request" and details of what needs to be updated.
You can request deletion of your personal data, except where we have a legal obligation to retain it (e.g., for tax/billing purposes). Upon your request, we will:
How to exercise: Email [email protected] with subject "Right to Erasure Request."
You can ask us to pause our use of your data while you dispute its accuracy, or while you exercise other rights. We will store your data but not actively process it.
How to exercise: Email [email protected] with subject "Data Processing Restriction Request."
You can request your data in a portable, machine-readable format (e.g., CSV) to transfer to another service. We will provide this within 30 days.
How to exercise: Email [email protected] with subject "Data Portability Request."
You can object to processing based on legitimate interest or direct marketing. Upon objection, we will:
How to exercise: Email [email protected] with subject "Data Processing Objection" or click "Unsubscribe" in any marketing email.
If you consented to marketing emails or cookies, you can withdraw that consent at any time. We will honor your withdrawal immediately.
How to exercise: Click "Unsubscribe" in marketing emails, adjust cookie settings, or email [email protected].
If you believe we are not complying with GDPR, you have the right to lodge a complaint with your local data protection authority:
Response Timeline: We will respond to all rights requests within 30 days of receipt. If your request is complex, we may extend this to 60 days (with notification). Requests are free, except for excessive or unfounded repeated requests.
Cookies and similar tracking technologies (pixels, local storage) help us deliver and improve our website. We use four categories of cookies:
Required for basic website functionality. These cannot be disabled without breaking site features.
Legal basis: Legitimate interest in site security and functionality.
Help us understand how visitors interact with our site so we can improve it.
Legal basis: Consent (we ask before setting these).
Allow third parties to show you personalized ads based on your browsing history.
Legal basis: Consent (we ask before setting these).
Enhance your experience by remembering preferences and enabling advanced features.
Legal basis: Legitimate interest in improving user experience.
When you first visit our site, we display a cookie consent banner. You can:
Our website and products are not directed at children under the age of 16. We do not knowingly collect personal data from individuals under 16 without verifiable parental consent.
If you are under 16: Do not submit personal information through our contact forms or newsletter signup. If you believe we have collected data from a child under 16 without consent, please contact us immediately.
Parental rights: Parents or guardians can request access to, or deletion of, their child's data by contacting [email protected] with proof of guardianship.
We implement technical and organizational measures to protect your data from unauthorized access, alteration, or loss:
However, no system is 100% secure. We encourage you to use strong passwords and report any security concerns to [email protected].
We may update this privacy policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Your continued use of our website after changes indicates your acceptance of the updated policy. If you do not agree with changes, you can request deletion of your data.