Zinie is committed to protecting your privacy and handling personal data responsibly, transparently and securely. By accessing or using Zinie, creating an account, communicating with Zinie, submitting information, requesting a solution or otherwise using the Services, you acknowledge that you have read and understood this Privacy Policy. Where consent is required by applicable law, we will request it separately through a clear affirmative action. Your access to this Privacy Policy alone will not be treated as consent for any processing that legally requires specific consent. If you do not agree with this Privacy Policy, you should not provide personal data to us or use the Services.
Effective Date: 25/07/2027 · Last Updated: 25/07/2027. This Privacy Policy explains how Zestl Software Private Limited (“Zestl”, “Company”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data when you access or use Zinie.
Zinie is an AI-powered platform and service operated by Zestl Software Private Limited.
Zinie enables individuals, businesses and organisations to describe business requirements and have applications, workflows, automations, AI agents, integrations and other intelligent systems designed, built, configured, hosted, operated and improved through a combination of artificial intelligence, software systems and, where applicable, human expert review.
For the purposes of this Privacy Policy:
Capitalised terms not defined in this Privacy Policy will have the meanings given to them in the Zinie Terms of Service.
This Privacy Policy applies to Personal Data collected or processed when you:
This Privacy Policy does not apply to third-party websites, platforms, software or services that have their own privacy policies and are not controlled by us.
Depending on the circumstances, we may process Personal Data in different capacities.
Data processed for our own purposes
We act as a Data Fiduciary or equivalent controller when we determine why and how Personal Data is processed, including when we process data for:
Customer data processed on your behalf
Where a Customer uses Zinie or a Generated System to collect, store or process Personal Data relating to its employees, customers, vendors or other individuals, the Customer will ordinarily determine the purpose of that processing. In such cases:
The Customer is responsible for:
Our processing of such data may also be governed by a separate data processing agreement or Commercial Agreement.
The Personal Data we collect depends on how you interact with Zinie and which Services you use.
Account and identity information
We may collect:
Business and professional information
We may collect:
Customer Content
When you describe a problem, request a build, upload documents or use a Generated System, we may process:
Customer Content may contain Personal Data relating to you or other individuals. You must not provide Personal Data relating to another person unless you are legally authorised to do so.
Communications
We may collect information you provide when communicating with us through:
This may include the content of messages, attachments, call or meeting details and communication metadata. Where legally permitted, meetings or support interactions may be recorded for documentation, training, quality assurance or security purposes. We will provide notice where required.
Billing and transaction information
Where you purchase a Service, we may collect:
Complete card, bank or payment credentials may be collected and processed directly by an authorised payment service provider rather than stored by us.
Device and technical information
When you access Zinie, we may automatically collect:
Usage information
We may collect information about how Zinie is used, including:
Information from third parties
We may receive information from:
You should avoid submitting highly sensitive or regulated information unless:
This may include:
Do not include passwords, API secrets, private keys or production credentials in general prompts, chat messages or documents. Where credentials are required for an integration, they must be shared through an approved secure mechanism.
We may process Personal Data for the following purposes.
Providing Zinie and the Services
We use Personal Data to:
AI-assisted processing
We may use artificial intelligence systems to:
AI-assisted processing may involve third-party model or infrastructure providers acting as our subprocessors. We apply contractual and technical controls intended to limit such providers’ use of Customer Content to delivering the relevant service to us.
Unless expressly agreed with the Customer or permitted under a separately disclosed programme, Customer Content submitted to private Zinie workspaces will not be used to train general-purpose AI models for unrelated customers.
We may use aggregated or de-identified information to evaluate and improve Zinie, provided that such information does not identify you or disclose Customer confidential information.
Improving and developing Zinie
We may use information to:
Where appropriate, we use aggregated, masked or de-identified data for these purposes.
Security and misuse prevention
We may process information to:
Billing and administration
We may use Personal Data to:
Communications
We may use contact information to send:
These communications may be necessary for providing the Services and may not always be subject to an opt-out.
Marketing
Where permitted by law, we may use your contact information to send information about:
You may unsubscribe from marketing communications using the unsubscribe option provided or by contacting us. Opting out of marketing will not prevent us from sending essential service-related communications.
Legal and regulatory compliance
We may process information to:
Depending on the applicable law and circumstances, we process Personal Data based on one or more of the following:
Where processing is based on consent, you may withdraw that consent using the method provided at the time of collection or by contacting us.
Withdrawal of consent will not affect processing already lawfully undertaken before the withdrawal.
Withdrawal may prevent us from continuing to provide a Service where the relevant Personal Data is necessary for that Service.
Zinie may use cookies and similar technologies, including local storage, pixels, tags and software development kits.
These technologies may be used to:
Cookies may include:
You may be able to manage non-essential cookies through the cookie controls displayed on the Website or through your browser settings. Disabling certain cookies may affect the functionality of Zinie.
We do not sell Personal Data. We may disclose Personal Data in the following circumstances.
Service providers and subprocessors
We may share information with trusted service providers that help us provide and operate Zinie, including providers of:
These providers are permitted to process Personal Data only for the contracted services and are subject to appropriate confidentiality, security and data-protection obligations.
Human experts and authorised personnel
Customer Content may be accessed by authorised employees, contractors or experts where reasonably necessary to:
Access is limited based on role and business need.
Third-party integrations
Where you instruct Zinie to connect with a third-party system, we may send or receive information through that integration. The third party’s processing of Personal Data is governed by its own terms and privacy policy. You are responsible for ensuring that you are authorised to connect the relevant system and transfer the relevant data.
Your organisation and workspace administrators
If you use Zinie through an organisation, the organisation’s administrators may be able to:
Your use of an organisation-managed account is subject to that organisation’s policies.
Professional advisers
We may disclose information to lawyers, auditors, accountants, insurers, consultants and other professional advisers where reasonably necessary for legitimate business, legal, taxation, audit or compliance purposes.
Legal requirements and protection of rights
We may disclose information where we reasonably believe disclosure is necessary to:
Where legally permitted and appropriate, we may notify you before disclosing information in response to a legal request.
Business transfers
Personal Data may be disclosed or transferred as part of:
Any recipient will be required to process the information consistently with this Privacy Policy or provide appropriate notice of material changes.
With your direction or consent
We may share Personal Data where you instruct us to do so or provide valid consent.
Zinie may use infrastructure, artificial intelligence providers and other service providers located in India and other countries. As a result, Personal Data may be processed outside the country in which it was collected.
Where required, we use appropriate contractual, technical and organisational safeguards for cross-border transfers.
We will not transfer Personal Data to a country or territory where such transfer is restricted under applicable Indian law.
Customers with specific data-location or residency requirements should communicate those requirements before using the relevant Service. Additional commercial or technical conditions may apply.
We retain Personal Data only for as long as reasonably necessary for:
Retention periods may vary based on:
Following account closure or termination, Customer Content may remain available for a limited offboarding or retrieval period specified in the Commercial Agreement or applicable service plan.
After the relevant retention period, information will be deleted, anonymised or securely isolated, unless continued retention is required by law.
Backup copies may remain for a limited period until they are overwritten through normal backup cycles. Access to such backups will remain restricted.
We use reasonable administrative, organisational and technical safeguards designed to protect Personal Data against:
These safeguards may include:
However, no online service, data transmission or storage system can be guaranteed to be completely secure.
You are responsible for maintaining the security of your account, devices, credentials, integrations and Authorised Users.
You must promptly notify us if you suspect unauthorised access, loss of credentials or a security incident involving Zinie.
Where we become aware of a Personal Data breach, we will assess and respond to it in accordance with applicable law and our incident-response procedures.
Where legally required, we will notify:
Where we process Personal Data on behalf of a Customer, we will provide reasonable information and cooperation to assist that Customer in meeting its breach-notification obligations.
Subject to applicable law, you may have the right to:
To exercise a right, contact us using the details in the Contact Us section.
We may need to verify your identity before acting on a request.
We may refuse or limit a request where permitted by law, including where information must be retained for legal compliance, security, fraud prevention, contractual enforcement or the establishment, exercise or defence of legal claims.
Where Zinie processes Personal Data solely on behalf of a Customer, we may direct your request to that Customer or assist the Customer in responding.
When exercising your rights or providing information to us, you must:
Zinie is intended for business users and is not directed to individuals under 18 years of age.
We do not knowingly permit a child to independently create a Zinie account.
Customers must not use Zinie to process Personal Data relating to children unless:
If you believe that a child’s Personal Data has been provided to us without proper authorisation, contact us so that we can take appropriate action.
Zinie may use automated processing to understand requests, classify information, generate Outputs and operate Generated Systems.
Zinie may also assist Customers in analysing business data and recommending actions.
Unless expressly agreed and legally permitted, Zinie should not be used as the sole decision-maker for decisions that materially affect an individual’s:
Customers are responsible for implementing appropriate human review, testing, validation, notices and safeguards for automated or AI-assisted decisions.
We may create aggregated, statistical or de-identified information from Personal Data.
We may use such information to:
We will take reasonable steps intended to ensure that such information does not directly identify an individual or reveal Customer confidential information.
We will not attempt to re-identify properly de-identified information except where necessary to evaluate the effectiveness of de-identification or where permitted by law.
Zinie may contain links to or integrations with third-party websites and services.
We do not control and are not responsible for the privacy, security or data-processing practices of those third parties.
You should review the privacy policy and terms of each third-party service before providing information or enabling an integration.
The inclusion of a link or integration does not mean that we endorse or assume responsibility for the third party.
You may interact with Zinie through social media platforms.
Information posted publicly or shared through a social media platform may be visible to other users and may be collected or used by the relevant platform or third parties.
We are not responsible for the privacy practices of social media providers or for information you choose to make publicly available.
We will not publish your name, logo, testimonial, Generated System details or Customer story for marketing purposes without appropriate authorisation.
Where you authorise publication, you may withdraw permission for future use by contacting us. Withdrawal will not require us to recall materials already lawfully published or distributed, but we will stop new uses within a reasonable period.
If you apply for employment with the Company, we may process:
We use this information to evaluate applications, communicate with candidates, maintain recruitment records and comply with legal obligations.
Applicant information may be retained for future opportunities where permitted or with appropriate consent.
We may update this Privacy Policy to reflect:
The updated Privacy Policy will be posted through the Platform with a revised “Last Updated” date.
Where a change materially affects your rights or how we use Personal Data, we will provide reasonable notice through email, the Platform or another appropriate communication channel.
Where required, we will obtain fresh consent before applying a materially different processing purpose.
You may contact our Grievance Officer or Data Protection Officer if you:
We will acknowledge and address grievances within the period required by applicable law.
If you are dissatisfied with our response, you may have the right to approach the Data Protection Board of India or another competent authority in accordance with applicable law.
This Privacy Policy is governed by the laws of India.
Any dispute relating to this Privacy Policy will be handled in accordance with the dispute-resolution provisions contained in the Zinie Terms of Service, subject to any rights or remedies available under applicable data-protection law.
For questions, privacy requests, grievances or complaints, contact:
Zestl Software Private Limited
Zinie Privacy Team