Legal
Privacy Policy
We take privacy seriously. This policy explains exactly what data we collect, why we collect it, how we protect it, and what rights you have over it.
Data controller
Zerqano LLC
Standards
GDPR · CCPA · UK GDPR
Version
2.0.0
Review cycle
Annual minimum
1. Introduction & scope
Zerqano LLC (“Zerqano,” “we,” “us,” or “our”) operates the platform available at zerqano.com and associated subdomains, APIs, mobile applications, and services (collectively, the “Service”).
This Privacy Policy applies to all visitors, registered users, account administrators, and the organisations (“Customers”) that purchase or trial the Service. It describes our practices regarding the collection, use, storage, disclosure, and protection of personal data, and explains the rights available to data subjects under applicable law.
By accessing or using the Service you acknowledge that you have read and understood this Policy. If you are using the Service on behalf of an organisation, you represent that you have the authority to bind that organisation to this Policy.
Where Zerqano acts as a data processor on behalf of a Customer (e.g., processing files and documents uploaded by the Customer), the Customer's own privacy policy and our Data Processing Agreement govern that processing, and this Policy applies only to the extent Zerqano independently determines the purposes and means of processing.
2. Information we collect
We collect information in the following categories, limited to what is necessary for the purposes described in Section 4.
2.1 Account & identity data
- Full name, work email address, and profile information you provide during registration or account settings updates.
- Organisation name, role / job title, team size, and billing address.
- Authentication credentials stored as one-way cryptographic hashes. OAuth tokens from Google, Microsoft, or other SSO providers.
- Phone number and two-factor authentication (2FA) device metadata if you opt into MFA.
2.2 Customer-uploaded content ("Customer Data")
- Files, documents, receipts, invoices, purchase orders, and spreadsheets you upload or connect to the platform.
- Product catalogs, inventory records, sales orders, and supplier data ingested via CSV, API, or direct integration.
- Scanned receipts, photos, and OCR-extracted text processed through our document intelligence pipeline.
- Any personal data of third parties (e.g., customer names, supplier contacts) contained within Customer Data. The Customer is the data controller for such data.
2.3 Usage & telemetry data
- Pages and features accessed, click-paths, time-on-page, and session duration.
- Feature usage frequency (e.g., which AI modules are run, how often forecasts are generated).
- API request logs (endpoint, timestamp, HTTP status — not request body content).
- Error reports, crash logs, and performance metrics collected via Sentry and our internal logging infrastructure.
2.4 Device & browser data
- IP address (truncated to /24 after 90 days for analytics).
- Browser type and version, operating system, device type and screen resolution.
- Referring URL and UTM campaign parameters (anonymised after 30 days).
- Cookie and local-storage identifiers (see Section 10).
2.5 Communications data
- Emails, support tickets, and chat messages you send to us, including attachments.
- Survey responses, feedback form submissions, and NPS responses.
- Demo request form submissions and scheduling information.
3. Legal bases for processing (GDPR)
For individuals in the EEA, UK, or Switzerland, we rely on the following legal bases:
Contract performance (Art. 6(1)(b) GDPR)
Processing necessary to deliver the Service under our Terms — account management, billing, support, and running the AI pipeline on your Customer Data.
Legitimate interests (Art. 6(1)(f) GDPR)
Product analytics, security monitoring, fraud prevention, and service emails. We have conducted balancing tests confirming our interests do not override your rights.
Consent (Art. 6(1)(a) GDPR)
Marketing emails and non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
Legal obligation (Art. 6(1)(c) GDPR)
Retaining transaction records for tax, accounting, and regulatory compliance obligations.
4. How we use your data
We use personal data to:
- Create and manage your account, authenticate your identity, and deliver the features you have subscribed to.
- Process Customer Data through our AI pipeline (ingestion, forecasting, inventory, pricing, procurement, cross-sell) and return results to you.
- Generate reports, insights, and recommendations within the platform.
- Send transactional emails: account confirmations, password resets, pipeline-complete notifications, and invoice receipts.
- Provide customer support and respond to enquiries.
- Detect and prevent fraud, abuse, security breaches, and unauthorised access.
- Monitor and improve performance and reliability (debugging, load-testing, capacity planning).
- Conduct aggregate, anonymised product analytics to understand feature usage and prioritise roadmap decisions.
- Send marketing communications and product updates if you have opted in (or as an existing customer under soft opt-in).
- Comply with legal obligations, including tax record-keeping and responding to lawful regulatory requests.
We do not sell, rent, or broker personal data to third parties for their own marketing purposes.
6. International data transfers
Some of our subprocessors are located in the United States. Transfers from the EEA, UK, or Switzerland are governed by one or more of the following:
- EU Standard Contractual Clauses (SCCs) — 2021 Module 2 (controller-to-processor) incorporated into DPAs with all relevant subprocessors.
- UK International Data Transfer Agreement (IDTA) — for transfers from the UK to non-adequate third countries.
- Adequacy decisions — where applicable between EEA/UK countries.
You may request a copy of the safeguards we have put in place by contacting us at the address in Section 15.
7. Data retention
| Data category | Retention period | Basis |
|---|---|---|
| Account profile data | 90 days after account deletion | Contract / support window |
| Customer Data (uploaded files, extracted data) | 90 days after subscription end | Contract performance |
| AI pipeline outputs (forecasts, recommendations) | 24 months from generation | Legitimate interest |
| Billing & invoice records | 7 years | Legal obligation (tax law) |
| Security / access logs | 12 months rolling | Legitimate interest (security) |
| Error / crash logs (Sentry) | 90 days | Legitimate interest (debugging) |
| Marketing analytics | 24 months | Consent / legitimate interest |
| Support ticket conversations | 3 years | Legitimate interest (quality) |
When retention periods expire, data is securely deleted or anonymised per our deletion procedures. You may request earlier deletion under Section 8.
8. Your rights
8.1 Rights under GDPR (EEA & UK)
Right of access (Art. 15)
Receive a copy of the personal data we hold about you.
Right to rectification (Art. 16)
Correct inaccurate or incomplete data.
Right to erasure (Art. 17)
Request deletion of your data, subject to legal obligations.
Right to restriction (Art. 18)
Restrict processing in certain circumstances.
Right to portability (Art. 20)
Receive your data in a machine-readable format.
Right to object (Art. 21)
Object to processing based on legitimate interests, including profiling.
Right to withdraw consent
Withdraw consent for marketing or optional cookies at any time.
Right to lodge a complaint
File a complaint with your national supervisory authority (e.g., ICO in the UK).
8.2 Rights under CCPA / CPRA (California)
- Right to know — what categories of personal information we collect, the purposes, and with whom we share it.
- Right to delete — request deletion of personal information, subject to exceptions.
- Right to opt-out of sale/sharing — we do not sell or share personal information for cross-context behavioural advertising.
- Right to correct — correct inaccurate personal information.
- Right to limit use of sensitive personal information — collected only for the limited purposes described above.
- Right of non-discrimination — exercising your rights will not result in differential service or pricing.
To exercise California rights, submit a verifiable consumer request to the address in Section 15. We will respond within 45 days (extendable by a further 45 days with notice).
How to exercise your rights
Email privacy@zerqano.com with subject “Data Subject Request.” We verify your identity before processing and respond within 30 days (or as required by applicable law).
9. Children's privacy
The Service is directed to businesses and professionals. It is not intended for children under the age of 16 (or 13 in the United States under COPPA). We do not knowingly collect personal data from children under 16.
If you believe a child has provided personal data to us, please contact privacy@zerqano.com and we will promptly delete that information.
11. AI & automated decision-making
- Customer Data processing. When you upload files or data, our pipeline processes that data to generate recommendations. We act as a data processor for Customer Data.
- LLM providers. Some features send portions of Customer Data to OpenAI or Groq for language model inference. Data is processed under our API agreements and is not used to train their models (per current service agreements).
- No fully automated decisions with legal effects. Our AI outputs (forecasts, price recommendations, reorder suggestions) are advisory. No decisions with legal or similarly significant effects on individuals are made solely by automated means.
- Model training. We may use anonymised, aggregated Customer Data to improve our internal ML models. We will never use identifiable personal data for model training without explicit consent.
12. Security
We implement technical and organisational security measures proportionate to the risks of processing:
- TLS 1.2+ encryption in transit for all data exchanged with the Service.
- AES-256 encryption at rest for database volumes and file storage.
- Row-Level Security (RLS) policies on all database tables ensuring strict multi-tenant isolation.
- Bcrypt / Argon2 one-way password hashing — we cannot recover your password.
- Continuous security monitoring via Sentry and server-level intrusion detection.
- Automated dependency vulnerability scanning in our CI/CD pipeline.
- Strict Content-Security-Policy headers and OWASP-guided secure coding practices.
- Regular access reviews ensuring principle of least privilege.
For full technical details, see our Security & Data Protection page.
In the event of a personal data breach posing risk to your rights, we will notify affected users and relevant supervisory authorities within 72 hours (as required by GDPR).
13. Third-party links
The Service may contain links to third-party websites, integrations, or resources. This Policy does not apply to those third-party sites. We encourage you to review their privacy policies before sharing any personal data.
14. Policy changes
We may update this Privacy Policy from time to time. For material changes, we will:
- Update the “Last updated” date at the top of this page.
- Send a notification email to all registered users at least 14 days before changes take effect.
- Display a prominent notice in the platform dashboard.
Continued use of the Service after the effective date constitutes acceptance. If you disagree, you may close your account before changes take effect.
15. Contact & DPO
Email: privacy@zerqano.com
Subject line: “Data Subject Request” or “Privacy Enquiry”
Company: Zerqano LLC
Registered address: 2152 North Tripp Avenue, Chicago, IL 60639
Response time: Within 5 business days, completed within 30 days (or as required by law).
If located in the EEA or UK and not satisfied with our response, you have the right to lodge a complaint with your local data protection authority:
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- EU: Your national supervisory authority — edpb.europa.eu
- California: California Privacy Protection Agency — cppa.ca.gov
Document information
Document: Zerqano Privacy Policy
Version: 2.0.0
Effective: [EFFECTIVE DATE — UPON LLC FORMATION]
Data controller: Zerqano LLC
Registered address: 2152 North Tripp Avenue, Chicago, IL 60639
Language: English (governing)
Privacy contacts
Privacy & DPO: privacy@zerqano.com
General legal: legal@zerqano.com
Security reports: security@zerqano.com
Related documents
This document was last reviewed on 2026-06-30. Zerqano reviews its Privacy Policy at least annually and upon any material change to data processing activities, applicable law, or the Service. If you are located in the EEA or UK and have an unresolved complaint, you may contact your local supervisory authority. Historic versions are available on request from privacy@zerqano.com. Where a conflict exists between this English-language version and any translation, this English version prevails.