Privacy Policy – Zentre (Website & SaaS)

English convenience translation. The legally authoritative version is the German “Datenschutzerklärung”; in case of discrepancies, the German version prevails.

Last updated: 4 Sep 2026

1. Controller

EZTO TECHNOLOGIES GmbH, Am Brand 41, 55116 Mainz, Germany

Data protection contact: dpo@zentre.ai | Legally relevant notices: legal@zentre.ai

Zentre is operated in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

Orientation: As a website visitor, Sections 3–4 and 7 concern you most; as a Zentre platform user, additionally Sections 5–10. Your rights are set out in Section 12.

2. Allocation of roles (Website/Business vs. SaaS)

3. Purposes, data categories, and legal bases (Website & Business)

The provision of contract and billing data is required for the conclusion of the contract; without it, the contract cannot be concluded and performed. Otherwise, the provision of personal data is voluntary.

4. Website: Cookies & consent

4.1 Online presences on social networks

We maintain online presences on social networks to communicate with users and provide information about our services. When you visit our profiles, the respective provider processes personal data (e.g. IP address, device information, interactions) under its own responsibility, potentially also outside the EU/EEA.

Legal basis: Art. 6 (1) (f) GDPR (external presentation and communication with users); for page statistics, joint controllership with the respective network exists (Art. 26 GDPR) as governed by the agreement provided by the network.

LinkedIn. We operate a company page on LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland). If you are logged in to LinkedIn, LinkedIn may attribute your visit to your account. For data processed as part of “Page Insights,” we and LinkedIn are joint controllers under Art. 26 GDPR. Privacy policy: linkedin.com/legal/privacy-policy · Opt-out: linkedin.com/psettings/guest-controls/retargeting-opt-out

Facebook. We operate a page on Facebook (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, “Meta”). For Page Insights data, we and Meta are joint controllers under Art. 26 GDPR; the arrangement is available at facebook.com/legal/controller_addendum. Privacy policy: facebook.com/privacy/policy

Instagram. We operate a business profile on Instagram (Meta Platforms Ireland Limited). Page Insights information: facebook.com/legal/terms/information_about_page_insights_data · Privacy policy: privacycenter.instagram.com/policy

Transfers to the USA may occur for Meta and LinkedIn services; they are based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where applicable, the EU-US Data Privacy Framework.

4.2 Meta Pixel (Facebook Pixel)

We use the Meta Pixel on our website, an analytics and marketing tool of Meta Platforms Ireland Limited (“Meta”). The Meta Pixel allows us to measure the effectiveness of our ads on Facebook and Instagram and to build audiences for advertising (retargeting/custom audiences).

Legal basis: exclusively your consent under Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG, given via our consent management (Usercentrics). Without consent, the pixel is not loaded. You may withdraw your consent at any time with effect for the future via the cookie settings.

Cookies: “_fbp” (browser identifier, stored up to 90 days) and “_fbc” (click identifier, stored up to 2 years).

Joint controllership: For the collection and transmission of event data to Meta, we and Meta are joint controllers under Art. 26 GDPR (arrangement: facebook.com/legal/controller_addendum); Meta is solely responsible for the subsequent processing.

Third-country transfer: personal data may be transferred to the USA; Meta relies on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and the EU-US Data Privacy Framework. More information: facebook.com/privacy/policy · Ad settings: facebook.com/settings?tab=ads

4.3 Xing Ads & Xing tag

We run advertisements on the professional network Xing and use a conversion-tracking tag (“Xing tag”) of New Work SE, Am Strandkai 1, 20457 Hamburg, Germany (“Xing”) on our website. The Xing tag allows us to measure the effectiveness of our Xing advertising campaigns (conversion measurement) and to build audiences for advertising. The data processed includes pages visited, configured events (e.g., registration), IP address, user agent, and cookie/click identifiers. Campaign reports (clicks, impressions, conversions) are provided by Xing platform-side in aggregated form.

Legal basis: exclusively your consent under Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG, given via our consent management (Usercentrics). Without consent, the tag is not loaded. You may withdraw your consent at any time with effect for the future via the cookie settings.

Place of processing: processing by New Work SE takes place within the EU/EEA (Germany); according to the provider, no third-country transfer takes place. More information: privacy.xing.com

4.4 Contentsquare / Hotjar (session analysis)

We use analysis tools from Contentsquare (Contentsquare SAS, 7 Rue de Madrid, 75008 Paris, France; including the Hotjar product line) on our website to understand and improve how our website is used — in particular heatmaps, scroll and click analysis, and session recordings. Input fields are excluded from recording (input masking); the tool is not active on legal-text pages (e.g., imprint, privacy policy, terms).

Legal basis: exclusively your consent under Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG, given via our consent management (Usercentrics). Without consent, the tool is not loaded. You may withdraw your consent at any time with effect for the future via the cookie settings.

Place of processing: processing takes place within the EU/EEA in accordance with the data processing agreement concluded with the provider (Art. 28 GDPR).

5. SaaS (Zentre): Data categories and principles

6. Hosting & data location

Standard: Hosting with Scaleway (Scaleway SAS, France) in the EU region Paris (fr-par), to the extent technically provided for in the respective service/plan. Productive data storage takes place within the EU/EEA.

Enterprise / Private Cloud: Differing EU hosting, on-prem, or private-cloud options are possible where agreed.

Content Delivery Network (Bunny CDN): We use the content delivery network of BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia (“Bunny”) for fast and secure delivery of our website and platform content. When content is retrieved, Bunny processes technically necessary connection data (in particular IP address, user agent, requested URL, timestamp). Delivery is restricted to EU/EEA locations. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in performant, secure delivery). A data processing agreement (Art. 28 GDPR) is in place with Bunny. More information: bunny.net/privacy.

7. Recipients / service providers

Payment processing (Stripe): We use Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin, Ireland, for billing and payment processing. Data processed: invoicing and payment data (e.g. name, email, billing address, payment token, transaction data). Legal basis: Art. 6(1)(b) GDPR (contract performance) and (c) GDPR (commercial/tax law obligations). Transfers to Stripe Inc. (USA) may occur, based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and the EU-US Data Privacy Framework. More information: stripe.com/privacy.

8. Remote access / access from third countries

In individual cases, engineering and support services may also be provided by vetted employees of EZTO TECHNOLOGIES GmbH outside the EU/EEA (remote access; under EDPB Guidelines 05/2021 this is not a third-country transfer). External service providers outside the EU/EEA are currently not engaged for this; any engagement would take place only under the DPA procedures (Section 12, Annex 3). Access to customer data takes place only on a case-by-case basis and to the extent necessary, on a need-to-know basis, time-limited, approved, and logged. There is no third-country access to content in Section 203 mode; this is prevented by technical access controls. Where a third-country transfer is necessary (including remote access), it takes place under appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g., EU Standard Contractual Clauses) and – where necessary – supplementary measures (e.g., encryption, access restrictions).

9. Third-country transfers

In the standard setup (EU hosting with Scaleway/Paris, EU routing via Cortecs, and Linkup in the EU where applicable), no third-country transfers regularly take place. Where transfers outside the EU/EEA are necessary (e.g., in the case of remote access in a support scenario), they take place under appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g., adequacy decision, EU Standard Contractual Clauses/SCC). Supplementary measures (e.g., encryption, access restrictions) are taken into account where necessary.

10. Retention period / deletion

11. Data security

EZTO implements appropriate technical and organizational measures to protect personal data (Art. 32 GDPR), in particular access controls, transport encryption (TLS 1.2 or higher), encryption of data/artifacts at rest (AES-256 (at minimum)), tenant separation, and security monitoring, commensurate with the respective risk. EZTO operates an ISO/IEC 27001-aligned ISMS; certification is underway; EZTO publishes the current status in the Trust Center.

12. Data subject rights

Data subject rights under the GDPR, in particular access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21) to processing based on legitimate interests. Withdrawal of consent at any time with effect for the future (Art. 7 (3)). There is a right to lodge a complaint with a data protection supervisory authority, in particular the authority competent for EZTO (the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, LfDI RLP).

EZTO does not carry out automated individual decision-making, including profiling, producing legal effects within the meaning of Art. 22 GDPR.

12.1 Withdrawal of consent and erasure of your data

You may withdraw any consent to data processing at any time with effect for the future (Art. 7(3) GDPR). Consent to cookies and analytics can be adjusted or withdrawn at any time via the cookie settings on our website.

To withdraw consent or to request erasure under Art. 17 GDPR, email dpo@zentre.ai.

For users of the Zentre platform (SaaS): the controller for content in your workspace (e.g. your account and stored chat histories) is your organization. Please contact your internal workspace administrator to request deletion of your account or stored chat histories. If you contact EZTO directly, we will — where permissible — forward your request to the controller (cf. Section 10 DPA). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

13. Contact