Privacy Policy – Zentre (Website & SaaS)
nglish convenience translation. The legally authoritative version is the German “Datenschutzerklärung”; in case of discrepancies, the German version prevails.
Last updated: 15 Jul 2026
1. Controller
EZTO TECHNOLOGIES GmbH, Am Brand 41, 55116 Mainz, Germany
Data protection contact: dpo@zentre.ai | Legally relevant notices: legal@zentre.ai
Zentre is operated in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
2. Allocation of roles (Website/Business vs. SaaS)
- SaaS / Zentre (customer tenant): In providing Zentre, EZTO generally processes personal data as a processor (Art. 28 GDPR) on behalf of the customer (controller). Details are set out in the Data Processing Agreement (DPA).
- Support & security in the SaaS context: Where support, error analysis, security/abuse prevention, or incident handling require the processing of customer data within the customer tenant, such processing is carried out as processing on behalf of the controller under the DPA.
- Website & business operations: For website operation, marketing/communications, contract initiation/conclusion, and billing/payment processing, EZTO processes personal data as its own controller; this Privacy Policy applies to such processing.
- No BYOK: Zentre does not currently support “Bring Your Own Key” (BYOK).
3. Purposes, data categories, and legal bases (Website & Business)
- Website operation, provision of content, IT security: Art. 6 (1) (f) GDPR (legitimate interest).
- Contract initiation/performance, account administration, communication: Art. 6 (1) (b) GDPR.
- Billing, accounting, retention obligations: Art. 6 (1) (c) GDPR (legal obligation) and/or Art. 6 (1) (b) GDPR.
- Consent-based technologies (e.g., analytics): Art. 6 (1) (a) GDPR in conjunction with Section 25 TDDDG.
4. Website: Cookies & consent
- Consent management: Usercentrics (Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany). Processing of consent status to fulfil the accountability obligation (Art. 7(1), Art. 5(2) GDPR); legal basis Art. 6(1)(c) or (f) GDPR; consent records stored for up to 3 years.
- Plausible Analytics (Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia): data-minimizing, cookieless analytics with EU hosting, only after consent (opt-in, Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG); no permanent storage of personal raw data.
- Bot protection: Friendly Captcha (Friendly Captcha GmbH, Germany) on the signup and login pages. To protect against automated abuse, a cookieless computational puzzle is solved in the browser; technical connection data is processed in the course of this (including a one-way-hashed, truncated IP address and browser characteristics) on EU infrastructure. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of the service, Art. 32 GDPR); access to terminal equipment information is strictly necessary (Sec. 25(2) no. 2 TDDDG) — no consent is required. No cookies are set and no tracking takes place.
- Meta Pixel: only after consent (opt-in), see Section 4.2
- Necessary cookies: operation, security, abuse prevention (Section 25 (2) TDDDG)
4.1 Online presences on social networks
We maintain online presences on social networks to communicate with users and provide information about our services. When you visit our profiles, the respective provider processes personal data (e.g. IP address, device information, interactions) under its own responsibility, potentially also outside the EU/EEA.
- LinkedIn. We operate a company page on LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland). If you are logged in to LinkedIn, LinkedIn may attribute your visit to your account. For data processed as part of “Page Insights,” we and LinkedIn are joint controllers under Art. 26 GDPR. Privacy policy: linkedin.com/legal/privacy-policy · Opt-out: linkedin.com/psettings/guest-controls/retargeting-opt-out
- Facebook. We operate a page on Facebook (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, “Meta”). For Page Insights data, we and Meta are joint controllers under Art. 26 GDPR; the arrangement is available at facebook.com/legal/controller_addendum. Privacy policy: facebook.com/privacy/policy
- Instagram. We operate a business profile on Instagram (Meta Platforms Ireland Limited). Page Insights information: facebook.com/legal/terms/information_about_page_insights_data · Privacy policy: privacycenter.instagram.com/policy
Transfers to the USA may occur for Meta and LinkedIn services; they are based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where applicable, the EU-US Data Privacy Framework.
4.2 Meta Pixel (Facebook Pixel)
We use the Meta Pixel on our website, an analytics and marketing tool of Meta Platforms Ireland Limited (“Meta”). The Meta Pixel allows us to measure the effectiveness of our ads on Facebook and Instagram and to build audiences for advertising (retargeting/custom audiences).
- Legal basis: exclusively your consent under Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG, given via our consent management (Usercentrics). Without consent, the pixel is not loaded. You may withdraw your consent at any time with effect for the future via the cookie settings.
- Cookies: “_fbp” (browser identifier, stored up to 90 days) and “_fbc” (click identifier, stored up to 2 years).
- Joint controllership: For the collection and transmission of event data to Meta, we and Meta are joint controllers under Art. 26 GDPR (arrangement: facebook.com/legal/controller_addendum); Meta is solely responsible for the subsequent processing.
- Third-country transfer: personal data may be transferred to the USA; Meta relies on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and the EU-US Data Privacy Framework. More information: facebook.com/privacy/policy · Ad settings: facebook.com/settings?tab=ads
5. SaaS (Zentre): Data categories and principles
- Account/organization data (e.g., name, email, organization, roles/permissions)
- Usage, security, and billing metadata (e.g., timestamps, request IDs, usage/cost, security-relevant events, IP where necessary)
- Content data (prompts/uploads/outputs) for service provision, depending on use case and configuration
- Web search (where activated): When the web search function is used, search queries (which may contain personal data) are transmitted to the search provider Linkup (Linkup Technologies SAS, France) in order to retrieve current information from the public web. Linkup processes within the EU; a zero-data-retention option is available.
- Default: no general content logging of prompts/outputs; chat retention concerns the user/workspace history.
- Exceptions: Temporary processing/storage may be necessary where debug/logging options are activated, in support cases on instruction, or for security-relevant events (in each case according to necessity and the retention configuration).
- No training by EZTO: EZTO does not use content data to train its own AI models. Use for training purposes is also excluded vis-à-vis the integrated model providers – where contractually agreed and technically available (e.g., zero data retention).
- AI routing via Cortecs: Routing to AI models takes place by default via the EU-based AI gateway Cortecs (Cortecs GmbH, Vienna), which processes data within the EU and integrates the downstream model providers as its own subprocessors. Where content is forwarded to model providers, their processing is governed by the respective terms and the chosen configuration.
- EU AI Act & transparency: Users interact with AI systems; outputs are generated automatically by AI models and may be erroneous. For the transparency obligations under Art. 50 of Regulation (EU) 2024/1689 (AI Act), EZTO is the provider of the AI system made available in the service (recognizability of the AI interaction; machine-readable marking of AI-generated content in line with the state of the art). Our customers are deployers within the meaning of the AI Act and are responsible for the disclosure obligations under Art. 50(3) and (4) AI Act (see Section 8 of the Terms). Zentre supports customers in this as an orchestration and governance layer.
- Note: Support requests/tickets may contain personal data (e.g., name, email, screenshots, diagnostic data). Such data is processed only to the extent necessary to handle the support case and in accordance with the DPA.
6. Hosting & data location
Standard: Hosting with Scaleway (Scaleway SAS, France) in the EU region Paris (fr-par), to the extent technically provided for in the respective service/plan. Productive data storage takes place within the EU/EEA.
Enterprise / Private Cloud: Differing EU hosting, on-prem, or private-cloud options are possible where agreed.
Content Delivery Network (Bunny CDN): We use the content delivery network of BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia (“Bunny”) for fast and secure delivery of our website and platform content. When content is retrieved, Bunny processes technically necessary connection data (in particular IP address, user agent, requested URL, timestamp). Delivery is restricted to EU/EEA locations. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in performant, secure delivery). A data processing agreement (Art. 28 GDPR) is in place with Bunny. More information: bunny.net/privacy.
7. Recipients / service providers
- Service providers (subprocessors) may be engaged to provide the services, in particular for hosting/infrastructure (Scaleway, EU), content delivery/CDN (Bunny – BunnyWay d.o.o., Slovenia, EU), AI gateway/routing to model providers (Cortecs, EU), web search (Linkup, EU, where used), email/communications (Infomaniak Network SA, Switzerland — adequacy decision), payment processing (Stripe, see below), bot/abuse protection (Friendly Captcha GmbH, Germany, EU), and engineering/support services.
- The current list of subprocessors (including purpose and, where available, location/country) is published in the Trust Center at zentre.ai/trust-center.
- Changes are generally announced at least 14 days before they take effect, unless compelling security reasons require a faster change.
Payment processing (Stripe): We use Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin, Ireland, for billing and payment processing. Data processed: invoicing and payment data (e.g. name, email, billing address, payment token, transaction data). Legal basis: Art. 6(1)(b) GDPR (contract performance) and (c) GDPR (commercial/tax law obligations). Transfers to Stripe Inc. (USA) may occur, based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and the EU-US Data Privacy Framework. More information: stripe.com/privacy.
8. Remote access / access from third countries
In individual cases, engineering and support services may also be provided by vetted employees and service providers outside the EU/EEA (remote access). Access to customer data takes place only on a case-by-case basis and to the extent necessary, on a need-to-know basis, time-limited, approved, and logged. There is no third-country access to content in Section 203 mode; this is prevented by technical access controls. Where a third-country transfer is necessary (including remote access), it takes place under appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g., EU Standard Contractual Clauses) and – where necessary – supplementary measures (e.g., encryption, access restrictions).
9. Third-country transfers
In the standard setup (EU hosting with Scaleway/Paris, EU routing via Cortecs, and Linkup in the EU where applicable), no third-country transfers regularly take place. Where transfers outside the EU/EEA are necessary (e.g., upon active selection of non-EU models or remote access), they take place under appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g., adequacy decision, EU Standard Contractual Clauses/SCC). Supplementary measures (e.g., encryption, access restrictions) are taken into account where necessary.
10. Retention period / deletion
- Website & business data: storage according to purpose and statutory retention obligations (in particular contract/billing data, generally 6 years under Section 257 HGB or 8/10 years under Section 147 AO). Website server log files are generally deleted after 30 days at the latest, unless longer retention is required for security reasons.
- SaaS / Zentre:
- Chat/workspace content data: uniformly 90 days; differing arrangements only by separate agreement (e.g., Enterprise/Private Cloud). Please export any conversations you need in good time.
- Backups: technical deletion/overwrite cycles typically up to 90 days.
- Security data/logs: only as long as necessary for security, abuse prevention, and incident analysis; potentially longer in the event of legal claims or statutory obligations.
- Web search: no permanent storage of search queries by EZTO.
- After contract termination, customer data is returned and/or deleted in accordance with the DPA.
11. Data security
EZTO implements appropriate technical and organizational measures to protect personal data (Art. 32 GDPR), in particular access controls, transport encryption (TLS 1.2 or higher), encryption of data/artifacts at rest (AES-256 (at minimum)), tenant separation, and security monitoring, commensurate with the respective risk. EZTO operates an ISO/IEC 27001-aligned ISMS; certification is underway; EZTO publishes the current status in the Trust Center.
12. Data subject rights
Data subject rights under the GDPR, in particular access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21) to processing based on legitimate interests. Withdrawal of consent at any time with effect for the future (Art. 7 (3)). There is a right to lodge a complaint with a data protection supervisory authority, in particular the authority competent for EZTO (the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, LfDI RLP).
EZTO does not carry out automated individual decision-making, including profiling, producing legal effects within the meaning of Art. 22 GDPR.
12.1 Withdrawal of consent and erasure of your data
You may withdraw any consent to data processing at any time with effect for the future (Art. 7(3) GDPR). Consent to cookies and analytics can be adjusted or withdrawn at any time via the cookie settings on our website.
To withdraw consent or to request erasure under Art. 17 GDPR, email dpo@zentre.ai.
For users of the Zentre platform (SaaS): the controller for content in your workspace (e.g. your account and stored chat histories) is your organization. Please contact your internal workspace administrator to request deletion of your account or stored chat histories. If you contact EZTO directly, we will — where permissible — forward your request to the controller (cf. Section 10 DPA). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
13. Contact
- For data protection inquiries: dpo@zentre.ai
- For legally relevant notices: legal@zentre.ai