Privacy Policy – Zentre (Website & SaaS)

nglish convenience translation. The legally authoritative version is the German “Datenschutzerklärung”; in case of discrepancies, the German version prevails.

Last updated: 15 Jul 2026

1. Controller

EZTO TECHNOLOGIES GmbH, Am Brand 41, 55116 Mainz, Germany

Data protection contact: dpo@zentre.ai | Legally relevant notices: legal@zentre.ai

Zentre is operated in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

2. Allocation of roles (Website/Business vs. SaaS)

3. Purposes, data categories, and legal bases (Website & Business)

4. Website: Cookies & consent

4.1 Online presences on social networks

We maintain online presences on social networks to communicate with users and provide information about our services. When you visit our profiles, the respective provider processes personal data (e.g. IP address, device information, interactions) under its own responsibility, potentially also outside the EU/EEA.

Transfers to the USA may occur for Meta and LinkedIn services; they are based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where applicable, the EU-US Data Privacy Framework.

4.2 Meta Pixel (Facebook Pixel)

We use the Meta Pixel on our website, an analytics and marketing tool of Meta Platforms Ireland Limited (“Meta”). The Meta Pixel allows us to measure the effectiveness of our ads on Facebook and Instagram and to build audiences for advertising (retargeting/custom audiences).

5. SaaS (Zentre): Data categories and principles

6. Hosting & data location

Standard: Hosting with Scaleway (Scaleway SAS, France) in the EU region Paris (fr-par), to the extent technically provided for in the respective service/plan. Productive data storage takes place within the EU/EEA.

Enterprise / Private Cloud: Differing EU hosting, on-prem, or private-cloud options are possible where agreed.

Content Delivery Network (Bunny CDN): We use the content delivery network of BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia (“Bunny”) for fast and secure delivery of our website and platform content. When content is retrieved, Bunny processes technically necessary connection data (in particular IP address, user agent, requested URL, timestamp). Delivery is restricted to EU/EEA locations. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in performant, secure delivery). A data processing agreement (Art. 28 GDPR) is in place with Bunny. More information: bunny.net/privacy.

7. Recipients / service providers

Payment processing (Stripe): We use Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin, Ireland, for billing and payment processing. Data processed: invoicing and payment data (e.g. name, email, billing address, payment token, transaction data). Legal basis: Art. 6(1)(b) GDPR (contract performance) and (c) GDPR (commercial/tax law obligations). Transfers to Stripe Inc. (USA) may occur, based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and the EU-US Data Privacy Framework. More information: stripe.com/privacy.

8. Remote access / access from third countries

In individual cases, engineering and support services may also be provided by vetted employees and service providers outside the EU/EEA (remote access). Access to customer data takes place only on a case-by-case basis and to the extent necessary, on a need-to-know basis, time-limited, approved, and logged. There is no third-country access to content in Section 203 mode; this is prevented by technical access controls. Where a third-country transfer is necessary (including remote access), it takes place under appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g., EU Standard Contractual Clauses) and – where necessary – supplementary measures (e.g., encryption, access restrictions).

9. Third-country transfers

In the standard setup (EU hosting with Scaleway/Paris, EU routing via Cortecs, and Linkup in the EU where applicable), no third-country transfers regularly take place. Where transfers outside the EU/EEA are necessary (e.g., upon active selection of non-EU models or remote access), they take place under appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g., adequacy decision, EU Standard Contractual Clauses/SCC). Supplementary measures (e.g., encryption, access restrictions) are taken into account where necessary.

10. Retention period / deletion

11. Data security

EZTO implements appropriate technical and organizational measures to protect personal data (Art. 32 GDPR), in particular access controls, transport encryption (TLS 1.2 or higher), encryption of data/artifacts at rest (AES-256 (at minimum)), tenant separation, and security monitoring, commensurate with the respective risk. EZTO operates an ISO/IEC 27001-aligned ISMS; certification is underway; EZTO publishes the current status in the Trust Center.

12. Data subject rights

Data subject rights under the GDPR, in particular access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21) to processing based on legitimate interests. Withdrawal of consent at any time with effect for the future (Art. 7 (3)). There is a right to lodge a complaint with a data protection supervisory authority, in particular the authority competent for EZTO (the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, LfDI RLP).

EZTO does not carry out automated individual decision-making, including profiling, producing legal effects within the meaning of Art. 22 GDPR.

12.1 Withdrawal of consent and erasure of your data

You may withdraw any consent to data processing at any time with effect for the future (Art. 7(3) GDPR). Consent to cookies and analytics can be adjusted or withdrawn at any time via the cookie settings on our website.

To withdraw consent or to request erasure under Art. 17 GDPR, email dpo@zentre.ai.

For users of the Zentre platform (SaaS): the controller for content in your workspace (e.g. your account and stored chat histories) is your organization. Please contact your internal workspace administrator to request deletion of your account or stored chat histories. If you contact EZTO directly, we will — where permissible — forward your request to the controller (cf. Section 10 DPA). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

13. Contact