Privacy Policy

Zinie is committed to protecting your privacy and handling personal data responsibly, transparently and securely. By accessing or using Zinie, creating an account, communicating with Zinie, submitting information, requesting a solution or otherwise using the Services, you acknowledge that you have read and understood this Privacy Policy. Where consent is required by applicable law, we will request it separately through a clear affirmative action. Your access to this Privacy Policy alone will not be treated as consent for any processing that legally requires specific consent. If you do not agree with this Privacy Policy, you should not provide personal data to us or use the Services.

Effective Date: 25/07/2027 · Last Updated: 25/07/2027. This Privacy Policy explains how Zestl Software Private Limited (“Zestl”, “Company”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data when you access or use Zinie.

About Zinie

Zinie is an AI-powered platform and service operated by Zestl Software Private Limited.

Zinie enables individuals, businesses and organisations to describe business requirements and have applications, workflows, automations, AI agents, integrations and other intelligent systems designed, built, configured, hosted, operated and improved through a combination of artificial intelligence, software systems and, where applicable, human expert review.

For the purposes of this Privacy Policy:

  • “Zinie” means the Zinie website, applications, messaging interfaces, workspaces, software, APIs, artificial intelligence capabilities, Generated Systems, cloud services and related services provided by us.
  • “Platform” means the technology environment through which Zinie is made available.
  • “Services” means the services, features, builds, integrations, deployments, hosting, maintenance, support and other functionality provided through Zinie.
  • “Customer” means the individual, company, organisation or other legal entity using the Services.
  • “Authorised User” means an employee, representative, contractor or other person authorised by a Customer to access Zinie.
  • “Generated System” means an application, workflow, automation, AI agent, dashboard, integration or other solution designed, generated, configured or delivered through Zinie.
  • “Customer Content” means information, instructions, business data, documents, prompts, files, communications and other material submitted to or processed through Zinie.
  • “Personal Data” means any data about an individual who is identifiable by or in relation to that data.
  • “Data Principal” means the individual to whom the Personal Data relates.

Capitalised terms not defined in this Privacy Policy will have the meanings given to them in the Zinie Terms of Service.

Scope of this Privacy Policy

This Privacy Policy applies to Personal Data collected or processed when you:

  • visit the Zinie website;
  • create or use a Zinie account or workspace;
  • communicate with Zinie through email, WhatsApp, chat or another supported channel;
  • submit a business requirement, idea or request;
  • use a Generated System;
  • interact with our customer support or experts;
  • register for an event, demonstration or trial;
  • respond to a survey or provide feedback;
  • apply for employment with us;
  • subscribe to our communications; or
  • otherwise interact with Zinie or the Company.

This Privacy Policy does not apply to third-party websites, platforms, software or services that have their own privacy policies and are not controlled by us.

Our role in processing personal data

Depending on the circumstances, we may process Personal Data in different capacities.

Data processed for our own purposes

We act as a Data Fiduciary or equivalent controller when we determine why and how Personal Data is processed, including when we process data for:

  • account administration;
  • customer communication;
  • billing;
  • security;
  • service analytics;
  • marketing;
  • legal compliance; and
  • improving Zinie.

Customer data processed on your behalf

Where a Customer uses Zinie or a Generated System to collect, store or process Personal Data relating to its employees, customers, vendors or other individuals, the Customer will ordinarily determine the purpose of that processing. In such cases:

  • the Customer acts as the Data Fiduciary or controller; and
  • Zestl acts as a Data Processor or service provider processing the data on the Customer’s documented instructions.

The Customer is responsible for:

  • having a lawful basis for processing that Personal Data;
  • providing required privacy notices;
  • obtaining required consents;
  • ensuring the accuracy and lawfulness of the data;
  • managing requests from Data Principals;
  • defining appropriate retention periods; and
  • ensuring that its use of Zinie complies with applicable law.

Our processing of such data may also be governed by a separate data processing agreement or Commercial Agreement.

Personal data we collect

The Personal Data we collect depends on how you interact with Zinie and which Services you use.

Account and identity information

We may collect:

  • name;
  • business or organisation name;
  • job title;
  • department or business function;
  • username;
  • account identifier;
  • profile information;
  • email address;
  • telephone or mobile number;
  • postal or business address; and
  • authentication and login information.

Business and professional information

We may collect:

  • employer or organisation details;
  • professional role;
  • business requirements;
  • operational processes;
  • use cases;
  • project information;
  • team information;
  • organisational structure; and
  • preferences relating to the Services.

Customer Content

When you describe a problem, request a build, upload documents or use a Generated System, we may process:

  • prompts and instructions;
  • written, audio or voice-note communications;
  • uploaded documents and files;
  • spreadsheets and databases;
  • workflow and process information;
  • business records;
  • reports;
  • communications;
  • images;
  • form submissions;
  • transaction or operational data;
  • feedback;
  • testing data; and
  • information processed through integrations.

Customer Content may contain Personal Data relating to you or other individuals. You must not provide Personal Data relating to another person unless you are legally authorised to do so.

Communications

We may collect information you provide when communicating with us through:

  • email;
  • telephone;
  • WhatsApp or other messaging services;
  • support requests;
  • chat;
  • meetings;
  • demonstrations;
  • surveys;
  • social media; and
  • other communication channels.

This may include the content of messages, attachments, call or meeting details and communication metadata. Where legally permitted, meetings or support interactions may be recorded for documentation, training, quality assurance or security purposes. We will provide notice where required.

Billing and transaction information

Where you purchase a Service, we may collect:

  • billing name;
  • billing address;
  • tax registration details;
  • invoice information;
  • subscription information;
  • payment status;
  • transaction identifiers; and
  • limited payment-related information.

Complete card, bank or payment credentials may be collected and processed directly by an authorised payment service provider rather than stored by us.

Device and technical information

When you access Zinie, we may automatically collect:

  • Internet Protocol address;
  • browser type and version;
  • device type;
  • operating system;
  • device identifiers;
  • language settings;
  • time zone;
  • referring website;
  • pages or features accessed;
  • date and time of access;
  • session information;
  • log data;
  • error and diagnostic information; and
  • network and security information.

Usage information

We may collect information about how Zinie is used, including:

  • features used;
  • requests submitted;
  • actions performed;
  • workspace activity;
  • build and deployment activity;
  • integration activity;
  • user feedback;
  • response times;
  • token or compute usage;
  • errors;
  • system events; and
  • interactions with Generated Systems.

Information from third parties

We may receive information from:

  • your employer or organisation;
  • an authorised Zinie customer or workspace administrator;
  • sales representatives or referral partners;
  • third-party integrations authorised by you;
  • authentication providers;
  • payment processors;
  • publicly available sources;
  • professional networking platforms;
  • analytics providers; and
  • service providers assisting us in operating Zinie.

Information you should not provide unless necessary

You should avoid submitting highly sensitive or regulated information unless:

  • it is necessary for the agreed use case;
  • you are authorised to provide it;
  • the relevant processing has been approved by us; and
  • appropriate contractual, security and compliance safeguards have been established.

This may include:

  • passwords or authentication credentials;
  • complete payment-card information;
  • government-issued identification numbers;
  • medical or health information;
  • biometric information;
  • information concerning children;
  • financial account credentials;
  • criminal records;
  • precise location information;
  • information revealing an individual’s race, religion, sexual orientation or political affiliation; and
  • information subject to sector-specific confidentiality requirements.

Do not include passwords, API secrets, private keys or production credentials in general prompts, chat messages or documents. Where credentials are required for an integration, they must be shared through an approved secure mechanism.

How we use personal data

We may process Personal Data for the following purposes.

Providing Zinie and the Services

We use Personal Data to:

  • create and manage accounts and workspaces;
  • understand business requirements;
  • communicate with users;
  • research and design proposed solutions;
  • generate and configure applications, workflows, agents and integrations;
  • provide expert review;
  • deploy, host and operate Generated Systems;
  • process instructions and requests;
  • provide support;
  • administer subscriptions;
  • maintain service history; and
  • deliver agreed professional services.

AI-assisted processing

We may use artificial intelligence systems to:

  • understand and classify requests;
  • interpret requirements;
  • extract information from Customer Content;
  • recommend workflows or solution designs;
  • generate text, configurations, code or system components;
  • identify patterns;
  • assist with testing and troubleshooting;
  • create summaries and reports; and
  • operate AI-enabled features within Generated Systems.

AI-assisted processing may involve third-party model or infrastructure providers acting as our subprocessors. We apply contractual and technical controls intended to limit such providers’ use of Customer Content to delivering the relevant service to us.

Unless expressly agreed with the Customer or permitted under a separately disclosed programme, Customer Content submitted to private Zinie workspaces will not be used to train general-purpose AI models for unrelated customers.

We may use aggregated or de-identified information to evaluate and improve Zinie, provided that such information does not identify you or disclose Customer confidential information.

Improving and developing Zinie

We may use information to:

  • understand how the Services are used;
  • measure performance;
  • identify errors;
  • improve user experience;
  • develop new capabilities;
  • evaluate AI-system quality;
  • improve safety and reliability;
  • perform research;
  • prepare aggregated analytics; and
  • improve our operational processes.

Where appropriate, we use aggregated, masked or de-identified data for these purposes.

Security and misuse prevention

We may process information to:

  • authenticate users;
  • detect unauthorised access;
  • prevent fraud and abuse;
  • enforce access controls;
  • monitor system integrity;
  • investigate suspicious activity;
  • identify malware or cyberattacks;
  • maintain audit logs;
  • protect customers and third parties; and
  • enforce our Terms of Service.

Billing and administration

We may use Personal Data to:

  • process subscriptions and payments;
  • issue invoices;
  • maintain accounting records;
  • calculate applicable taxes;
  • manage renewals;
  • communicate about outstanding amounts; and
  • administer Commercial Agreements.

Communications

We may use contact information to send:

  • account notices;
  • security alerts;
  • clarification requests;
  • project and build updates;
  • service announcements;
  • support responses;
  • invoices;
  • deployment notifications;
  • changes to the Services;
  • legal or policy notices; and
  • other administrative communications.

These communications may be necessary for providing the Services and may not always be subject to an opt-out.

Marketing

Where permitted by law, we may use your contact information to send information about:

  • Zinie features;
  • new Services;
  • demonstrations;
  • events;
  • newsletters;
  • customer stories; and
  • relevant offers.

You may unsubscribe from marketing communications using the unsubscribe option provided or by contacting us. Opting out of marketing will not prevent us from sending essential service-related communications.

Legal and regulatory compliance

We may process information to:

  • comply with applicable law;
  • respond to lawful requests from public authorities;
  • establish, exercise or defend legal claims;
  • conduct audits;
  • enforce agreements;
  • maintain legally required records;
  • prevent unlawful activity; and
  • protect the rights, safety and property of the Company, our customers and others.

Basis for processing personal data

Depending on the applicable law and circumstances, we process Personal Data based on one or more of the following:

  • your consent;
  • processing necessary to provide a Service requested by you;
  • performance of a contract with you or your organisation;
  • compliance with a legal obligation;
  • processing for certain legitimate uses recognised by applicable law;
  • protection of the rights, safety or property of individuals or organisations;
  • prevention and investigation of fraud or security incidents; and
  • our legitimate business interests, where recognised and where those interests do not override your rights.

Where processing is based on consent, you may withdraw that consent using the method provided at the time of collection or by contacting us.

Withdrawal of consent will not affect processing already lawfully undertaken before the withdrawal.

Withdrawal may prevent us from continuing to provide a Service where the relevant Personal Data is necessary for that Service.

Cookies and similar technologies

Zinie may use cookies and similar technologies, including local storage, pixels, tags and software development kits.

These technologies may be used to:

  • maintain user sessions;
  • remember settings;
  • authenticate users;
  • provide security;
  • understand Platform usage;
  • analyse performance;
  • diagnose errors;
  • improve functionality; and
  • support marketing where permitted.

Cookies may include:

  • Essential cookies — required for authentication, security, account access and core Platform functionality.
  • Preference cookies — remember settings such as language, display and user preferences.
  • Analytics cookies — help us understand usage, performance and areas for improvement.
  • Marketing cookies — where used and legally permitted, help measure campaigns and provide relevant communications.

You may be able to manage non-essential cookies through the cookie controls displayed on the Website or through your browser settings. Disabling certain cookies may affect the functionality of Zinie.

How we share personal data

We do not sell Personal Data. We may disclose Personal Data in the following circumstances.

Service providers and subprocessors

We may share information with trusted service providers that help us provide and operate Zinie, including providers of:

  • cloud hosting;
  • data storage;
  • artificial intelligence models;
  • application monitoring;
  • cybersecurity;
  • customer support;
  • email and messaging;
  • analytics;
  • authentication;
  • payment processing;
  • professional services; and
  • infrastructure.

These providers are permitted to process Personal Data only for the contracted services and are subject to appropriate confidentiality, security and data-protection obligations.

Human experts and authorised personnel

Customer Content may be accessed by authorised employees, contractors or experts where reasonably necessary to:

  • understand a requirement;
  • review a Generated System;
  • provide support;
  • troubleshoot an issue;
  • perform testing;
  • improve service quality;
  • respond to a security incident; or
  • fulfil a contractual obligation.

Access is limited based on role and business need.

Third-party integrations

Where you instruct Zinie to connect with a third-party system, we may send or receive information through that integration. The third party’s processing of Personal Data is governed by its own terms and privacy policy. You are responsible for ensuring that you are authorised to connect the relevant system and transfer the relevant data.

Your organisation and workspace administrators

If you use Zinie through an organisation, the organisation’s administrators may be able to:

  • access and manage your account;
  • control workspace permissions;
  • view usage information;
  • manage Customer Content;
  • configure integrations;
  • export data; and
  • suspend or remove your access.

Your use of an organisation-managed account is subject to that organisation’s policies.

Professional advisers

We may disclose information to lawyers, auditors, accountants, insurers, consultants and other professional advisers where reasonably necessary for legitimate business, legal, taxation, audit or compliance purposes.

Legal requirements and protection of rights

We may disclose information where we reasonably believe disclosure is necessary to:

  • comply with applicable law;
  • respond to a court order, legal process or lawful governmental request;
  • investigate fraud, misuse or security incidents;
  • protect an individual from harm;
  • enforce our agreements; or
  • protect the rights, property or safety of the Company, our customers, users or third parties.

Where legally permitted and appropriate, we may notify you before disclosing information in response to a legal request.

Business transfers

Personal Data may be disclosed or transferred as part of:

  • a merger;
  • acquisition;
  • financing;
  • restructuring;
  • sale of assets;
  • demerger;
  • insolvency process; or
  • transfer of all or part of our business.

Any recipient will be required to process the information consistently with this Privacy Policy or provide appropriate notice of material changes.

With your direction or consent

We may share Personal Data where you instruct us to do so or provide valid consent.

International data transfers

Zinie may use infrastructure, artificial intelligence providers and other service providers located in India and other countries. As a result, Personal Data may be processed outside the country in which it was collected.

Where required, we use appropriate contractual, technical and organisational safeguards for cross-border transfers.

We will not transfer Personal Data to a country or territory where such transfer is restricted under applicable Indian law.

Customers with specific data-location or residency requirements should communicate those requirements before using the relevant Service. Additional commercial or technical conditions may apply.

Data retention

We retain Personal Data only for as long as reasonably necessary for:

  • providing the Services;
  • maintaining active accounts;
  • completing builds and integrations;
  • supporting Generated Systems;
  • satisfying contractual obligations;
  • providing data export;
  • maintaining security and audit records;
  • preventing fraud and abuse;
  • resolving disputes;
  • enforcing agreements; and
  • complying with applicable law.

Retention periods may vary based on:

  • the category of information;
  • the purpose of processing;
  • Customer instructions;
  • the duration of the commercial relationship;
  • legal or regulatory requirements;
  • security requirements; and
  • applicable limitation periods.

Following account closure or termination, Customer Content may remain available for a limited offboarding or retrieval period specified in the Commercial Agreement or applicable service plan.

After the relevant retention period, information will be deleted, anonymised or securely isolated, unless continued retention is required by law.

Backup copies may remain for a limited period until they are overwritten through normal backup cycles. Access to such backups will remain restricted.

Security

We use reasonable administrative, organisational and technical safeguards designed to protect Personal Data against:

  • unauthorised access;
  • accidental loss;
  • unlawful disclosure;
  • alteration;
  • misuse;
  • destruction; and
  • unauthorised processing.

These safeguards may include:

  • access controls;
  • role-based permissions;
  • authentication controls;
  • encryption where appropriate;
  • network and application security;
  • audit logging;
  • vulnerability management;
  • secure software-development practices;
  • monitoring;
  • backup and recovery processes;
  • confidentiality obligations;
  • vendor assessments; and
  • incident-response procedures.

However, no online service, data transmission or storage system can be guaranteed to be completely secure.

You are responsible for maintaining the security of your account, devices, credentials, integrations and Authorised Users.

You must promptly notify us if you suspect unauthorised access, loss of credentials or a security incident involving Zinie.

Personal data breaches

Where we become aware of a Personal Data breach, we will assess and respond to it in accordance with applicable law and our incident-response procedures.

Where legally required, we will notify:

  • affected Customers;
  • affected Data Principals;
  • the Data Protection Board of India; and
  • any other competent authority.

Where we process Personal Data on behalf of a Customer, we will provide reasonable information and cooperation to assist that Customer in meeting its breach-notification obligations.

Your rights

Subject to applicable law, you may have the right to:

  • obtain information about the Personal Data being processed;
  • request access to your Personal Data;
  • request correction, completion or updating of inaccurate or incomplete Personal Data;
  • request erasure of Personal Data that is no longer required;
  • withdraw consent where processing is based on consent;
  • raise a grievance;
  • nominate another individual to exercise your rights in the event of death or incapacity; and
  • complain to the competent data-protection authority.

To exercise a right, contact us using the details in the Contact Us section.

We may need to verify your identity before acting on a request.

We may refuse or limit a request where permitted by law, including where information must be retained for legal compliance, security, fraud prevention, contractual enforcement or the establishment, exercise or defence of legal claims.

Where Zinie processes Personal Data solely on behalf of a Customer, we may direct your request to that Customer or assist the Customer in responding.

Your responsibilities as a data principal

When exercising your rights or providing information to us, you must:

  • provide authentic information;
  • not impersonate another person;
  • not suppress material information;
  • not register a false or frivolous grievance;
  • provide information reasonably required to verify your identity; and
  • comply with applicable law.

Children’s data

Zinie is intended for business users and is not directed to individuals under 18 years of age.

We do not knowingly permit a child to independently create a Zinie account.

Customers must not use Zinie to process Personal Data relating to children unless:

  • the use has been expressly approved by us;
  • the Customer has a lawful basis for doing so;
  • verifiable consent or authorisation has been obtained where required; and
  • appropriate contractual and technical safeguards have been implemented.

If you believe that a child’s Personal Data has been provided to us without proper authorisation, contact us so that we can take appropriate action.

Automated processing and AI outputs

Zinie may use automated processing to understand requests, classify information, generate Outputs and operate Generated Systems.

Zinie may also assist Customers in analysing business data and recommending actions.

Unless expressly agreed and legally permitted, Zinie should not be used as the sole decision-maker for decisions that materially affect an individual’s:

  • employment;
  • access to essential services;
  • credit;
  • insurance;
  • healthcare;
  • legal rights;
  • safety; or
  • similarly significant interests.

Customers are responsible for implementing appropriate human review, testing, validation, notices and safeguards for automated or AI-assisted decisions.

De-identified and aggregated information

We may create aggregated, statistical or de-identified information from Personal Data.

We may use such information to:

  • analyse Platform usage;
  • measure performance;
  • improve the Services;
  • conduct research;
  • develop features;
  • improve AI quality and safety;
  • create benchmarks; and
  • prepare business insights.

We will take reasonable steps intended to ensure that such information does not directly identify an individual or reveal Customer confidential information.

We will not attempt to re-identify properly de-identified information except where necessary to evaluate the effectiveness of de-identification or where permitted by law.

Third-party links and services

Zinie may contain links to or integrations with third-party websites and services.

We do not control and are not responsible for the privacy, security or data-processing practices of those third parties.

You should review the privacy policy and terms of each third-party service before providing information or enabling an integration.

The inclusion of a link or integration does not mean that we endorse or assume responsibility for the third party.

Social media

You may interact with Zinie through social media platforms.

Information posted publicly or shared through a social media platform may be visible to other users and may be collected or used by the relevant platform or third parties.

We are not responsible for the privacy practices of social media providers or for information you choose to make publicly available.

Testimonials and customer stories

We will not publish your name, logo, testimonial, Generated System details or Customer story for marketing purposes without appropriate authorisation.

Where you authorise publication, you may withdraw permission for future use by contacting us. Withdrawal will not require us to recall materials already lawfully published or distributed, but we will stop new uses within a reasonable period.

Employment applicants

If you apply for employment with the Company, we may process:

  • your name and contact details;
  • résumé or curriculum vitae;
  • employment history;
  • educational qualifications;
  • professional references;
  • interview information;
  • compensation expectations; and
  • information required for background or eligibility checks.

We use this information to evaluate applications, communicate with candidates, maintain recruitment records and comply with legal obligations.

Applicant information may be retained for future opportunities where permitted or with appropriate consent.

Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to Zinie;
  • changes in our processing activities;
  • new technologies;
  • legal or regulatory requirements;
  • security practices; or
  • operational changes.

The updated Privacy Policy will be posted through the Platform with a revised “Last Updated” date.

Where a change materially affects your rights or how we use Personal Data, we will provide reasonable notice through email, the Platform or another appropriate communication channel.

Where required, we will obtain fresh consent before applying a materially different processing purpose.

Grievance redressal

You may contact our Grievance Officer or Data Protection Officer if you:

  • have a question about this Privacy Policy;
  • wish to exercise a privacy right;
  • believe your Personal Data is inaccurate;
  • wish to withdraw consent;
  • have a concern about our processing;
  • believe a security incident has occurred; or
  • wish to make a complaint.

We will acknowledge and address grievances within the period required by applicable law.

If you are dissatisfied with our response, you may have the right to approach the Data Protection Board of India or another competent authority in accordance with applicable law.

Governing law

This Privacy Policy is governed by the laws of India.

Any dispute relating to this Privacy Policy will be handled in accordance with the dispute-resolution provisions contained in the Zinie Terms of Service, subject to any rights or remedies available under applicable data-protection law.

Contact us

For questions, privacy requests, grievances or complaints, contact:

Zestl Software Private Limited

Zinie Privacy Team