Comprehensive Privacy Policy

Last updated: September 11, 2026

1. Introduction & Scope

Welcome to Zazapp ("we", "our", or "us"). We are deeply committed to protecting your personal data, respecting your privacy, and ensuring the highest standards of data security. This Comprehensive Privacy Policy explains in detail how we collect, use, process, and safeguard your information when you access and use our AI-powered omnichannel SaaS CRM, including all associated web applications, mobile interfaces, and API endpoints (collectively, the "Service"). By using Zazapp, you consent to the data practices described in this policy. If you do not agree with any part of this policy, you must immediately cease using the Service.

2. Data Controller & Data Protection Officer (DPO)

For the purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, Zazapp acts as the Data Processor for the data you collect from your end-customers, and as the Data Controller for your personal account data. We have appointed a dedicated Data Protection Officer (DPO) to oversee our compliance with global data protection frameworks. You can reach our DPO directly at hello@zazapp.io for any inquiries regarding your privacy rights or data security.

3. Categories of Personal Data Collected

To provide our comprehensive suite of CRM and AI automation services, we collect several categories of data:
  • Identity & Authentication Data: Information required to create and manage your account, including First Name, Last Name, Email Address, and authentication tokens derived from OAuth providers (Google Connect, Apple Connect, Facebook Connect).
  • Calendar & Scheduling Data: Through integrations with **Google Calendar** and **Microsoft Outlook**, we collect scheduling availability, event titles, participant emails, and meeting durations. This data is strictly utilized to enable autonomous appointment booking by our AI agents and is never sold or used for targeted advertising.
  • Omnichannel Messaging Data: Zazapp acts as a centralized inbox. We ingest, store, and process communications across multiple third-party modules, including **WhatsApp, Instagram, Facebook Messenger, Telegram, LinkedIn, TikTok, X (formerly Twitter), WeChat, Snapchat, Discord, and Twitch**. We also process emails via **IMAP/SMTP** integrations. This includes message content, timestamps, media attachments, and sender metadata.
  • Payment & Transaction Data: When you generate payment links via our integrations with **Stripe Connect, Mollie, or Mercado Pago**, we process transaction statuses, amounts, and billing identifiers. We do not store raw credit card numbers (PCI-DSS compliance is handled by our payment partners).
  • Technical & Telemetry Data: IP addresses, browser types, device identifiers, session logs, and AI token usage telemetry (e.g., tokens consumed by OpenAI, Google Gemini, or Anthropic Claude) required for billing and service optimization.

4. Legal Basis for Processing (GDPR Article 6)

We process your personal data based on one or more of the following legal grounds:
  • Contractual Necessity: Processing is necessary for the performance of our contract with you (e.g., providing the CRM service, routing messages, executing AI workflows).
  • Legitimate Interests: For our legitimate business interests, such as improving our platform, preventing fraud, and maintaining infrastructure security.
  • Consent: Where required by law, we rely on your explicit consent (e.g., connecting third-party OAuth apps like Microsoft Outlook or Google Workspace).
  • Legal Obligation: When processing is necessary to comply with applicable legal or regulatory requirements.
  • 5. Artificial Intelligence (AI) Processing & Safeguards

    Zazapp is fundamentally powered by advanced Artificial Intelligence. Our multi-agent systems (Sales Agent, Support Agent, Marketing Agent) require the processing of your data to function autonomously.
    • Automated Scanning & Profiling: Our AI engine continuously scans and analyzes incoming and outgoing messages across all connected platforms (WhatsApp, Microsoft Outlook emails, Instagram DMs, etc.) to understand context, extract intent, qualify leads, and trigger actions in the CRM pipeline.
    • Data Isolation & LLM Privacy: We employ strict multi-tenant data isolation. Your data is never mixed with other clients' data. Furthermore, under our enterprise agreements with LLM providers (e.g., OpenAI, Google), **your personal data and message history are explicitly excluded from being used to train public AI models**.
    • Human-in-the-Loop: While our AI operates autonomously, you retain full control to override AI actions, pause automated agents, and manually take over conversations at any time.

    6. Data Sharing & Sub-processors

    We do not sell your personal data. We may share data with trusted third-party sub-processors strictly necessary for providing our Service. These include:
  • Cloud Hosting Providers: (e.g., Hetzner, AWS) for secure data storage and infrastructure hosting.
  • AI Model Providers: (e.g., OpenAI, Google Gemini, Anthropic) accessed via enterprise APIs with zero-data-retention policies for model training.
  • Communication Gateways: (e.g., Evolution API, Meta Graph API) to route messages to WhatsApp, Facebook, and Instagram.
  • Payment Processors: Stripe, Mollie, and Mercado Pago for processing subscription fees and generated payment links. All sub-processors are bound by stringent Data Processing Agreements (DPAs) that mandate GDPR-compliant security measures.
  • 7. International Data Transfers

    Zazapp's primary infrastructure is hosted in the European Union (Hetzner). However, certain sub-processors or integrated platforms (e.g., Meta, Microsoft, Google) may process data in the United States or other global regions. In all cases involving the transfer of personal data outside the European Economic Area (EEA), we ensure adequate protection is in place by utilizing Standard Contractual Clauses (SCCs) approved by the European Commission, and supplementary encryption measures.

    8. Data Retention Policy

    We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy.
  • Standard Retention: CRM contacts, message histories, and calendar events are retained for a default period of **36 months** following the last recorded interaction, to maintain historical context for the AI agents.
  • Account Deletion: Upon your request to terminate your account, all associated personal data, including third-party API tokens (Microsoft Outlook, Google, Meta), message logs, and AI telemetry, will be permanently deleted or irreversibly anonymized within 30 days.
  • Legal Exceptions: We may retain specific transaction or billing records for longer periods if mandated by tax, legal, or accounting obligations.
  • 9. Data Security & Encryption

    Security is built into the core of Zazapp. We implement enterprise-grade technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.
  • Encryption in Transit: All communications between your browser, our servers, and third-party APIs are encrypted using TLS 1.2 or higher.
  • Encryption at Rest: Sensitive data, including OAuth tokens for Microsoft Outlook and Google Calendar, database backups, and payment configurations, are encrypted at rest using AES-256 encryption.
  • Access Controls: We enforce strict Role-Based Access Control (RBAC) internally and within your tenant space (Owner, Staff) to ensure data is only accessible to authorized personnel.
  • 10. Your Data Protection Rights (GDPR & CCPA/CPRA)

    Depending on your jurisdiction, you possess robust rights regarding your personal data:
  • Right to Access: You can request a complete export of the personal data we hold about you in a structured, machine-readable format.
  • Right to Rectification: You can correct inaccurate or incomplete data directly within your dashboard.
  • Right to Erasure (Right to be Forgotten): You can request the permanent deletion of your data.
  • Right to Restrict Processing: You can ask us to suspend the AI processing of your data.
  • Right to Object: You can object to data processing based on legitimate interests or direct marketing.
  • California Residents (CCPA/CPRA): You have the right to know what personal information is collected, the right to opt-out of the "sale" or "sharing" of your data (note: we do not sell data), and the right to non-discrimination for exercising your privacy rights. To exercise any of these rights, please contact us at hello@zazapp.io. Or use our Data Deletion Form.
  • 11. Changes to this Privacy Policy

    We reserve the right to update or modify this Comprehensive Privacy Policy at any time to reflect changes in our practices, technology, or legal obligations. We will notify you of any material changes by posting the updated policy on this page and, where appropriate, notifying you via email or a dashboard alert. Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the terms.

    12. Contact Information

    If you have any questions, concerns, or formal requests regarding this Privacy Policy, our data practices, or your dealings with the Zazapp platform, please contact our Data Protection Officer at:

    **Email:** hello@zazapp.io **Attention:** Legal & Privacy Department