Privacy Policy
Zengnia builds business platforms that handle sensitive operational data every day, so privacy is not an afterthought for us — it is part of the product. This policy explains what we collect, why we collect it, who we share it with and the control you have over your information when you use the Zengnia website, the Zengnia analytics portal and the Zengnia mobile application distributed through Google Play and the App Store.
01. Who we are
Zengnia (“Zengnia”, “we”, “us” or “our”) is a technology company based in Wilmington, DE 19808, United States. We design and operate business, healthcare and e-learning platforms together with the companion analytics products referenced in this policy.
For the purposes of the EU/UK General Data Protection Regulation, Zengnia acts as the data controller for the account and usage data described below. Where we process business records on behalf of a customer organisation that licenses one of our platforms, Zengnia acts as a data processor and handles that data strictly under the customer's written instructions and service agreement.
02. Scope of this policy
This policy covers:
- The Zengnia website — our public pages and the contact, enquiry, demo request and career forms on them.
- The Zengnia analytics portal — the authenticated web dashboard used by owners and managers.
- The Zengnia mobile application — our Android and iOS app, which presents the same business and Google Analytics data as the web dashboard.
It does not cover third-party websites or services that we link to. Those services operate under their own privacy policies, and we encourage you to read them.
03. Information we collect
We collect only what is needed to run the service. The table below summarises each category and why it is collected.
| Category | What it includes | Why we need it |
|---|---|---|
| Account data | Name, username, email address, assigned role (owner or manager) and an optional profile picture. | To create and secure your account and to determine what you are permitted to see. |
| Authentication data | A hashed password and an API access token issued to your device after sign-in. | To keep you signed in securely and to protect the account from unauthorised access. |
| Business analytics data | Aggregated operational statistics pulled from the companion products connected to your account. | To render the dashboards, charts and key performance indicators that are the purpose of the app. |
| Website analytics | Google Analytics 4 metrics for the properties linked to your applications, such as sessions, users and traffic sources. | To show website performance alongside your business numbers. |
| Enquiry data | Name, email address, phone number, company type, job title, country and the content of your message. | To answer a contact, demo or “get started” request you submitted to us. |
| Technical & log data | IP address, device and operating system type, app version, timestamps and error diagnostics. | To keep the service available, debug faults and detect abuse. |
We do not sell your personal information, we do not share it with data brokers, and we do not use it to serve advertising or to build advertising profiles. The Zengnia mobile app contains no third-party advertising SDKs.
04. How we use your information
We process the information above in order to:
- Provide, operate and maintain the website, portal and mobile app.
- Authenticate you and apply the correct role-based permissions.
- Generate the analytics, reports and dashboards you request.
- Respond to enquiries, demo requests and support tickets.
- Monitor performance, investigate incidents and fix defects.
- Protect the service against fraud, abuse and security threats.
- Comply with legal, accounting and regulatory obligations.
We do not use your data for automated decision-making that produces legal or similarly significant effects on you.
05. Legal basis for processing
Where the GDPR or similar laws apply, we rely on the following legal bases:
- Contract — to deliver the service to you or to the organisation that granted you access.
- Legitimate interests — to secure our systems, prevent abuse and improve our products, balanced against your rights.
- Consent — where you voluntarily submit a form or opt in to updates. You can withdraw consent at any time.
- Legal obligation — where we must retain or disclose records under applicable law.
06. The Zengnia mobile application
The mobile app is a companion client for the Zengnia analytics portal. Accounts are provisioned by an administrator — the app has no public sign-up. After you sign in, the app stores an access token on the device so you are not asked for your password on every request.
Permissions the app may request
- Internet / network access — required to fetch your analytics from our servers.
- Notifications — optional, used only to alert you to account or reporting events. You can disable it in your device settings.
- Photos / camera — optional, and requested only at the moment you choose to set a profile picture.
The app does not collect precise location, contacts, SMS, call logs, calendar entries or health data, and it does not record audio or video in the background.
Data stored on your device
Your access token and lightweight display preferences are stored in the operating system's protected app storage. Signing out or uninstalling the app removes this local data from the device.
07. How we share information
We share personal information only in the limited circumstances listed here, and always under contractual confidentiality and security obligations:
- Service providers — hosting, email delivery, error monitoring and similar infrastructure vendors acting on our instructions.
- Google Analytics — where a customer connects a Google Analytics 4 property, we read reporting data from Google on that customer's behalf.
- App distribution platforms — Google Play and the Apple App Store, which provide us with aggregated install and crash statistics.
- Your organisation — account administrators can see the accounts and access levels within their own organisation.
- Legal and safety — where disclosure is required by law or court order, or is needed to protect the rights and safety of users and the public.
- Corporate transactions — in a merger, acquisition or asset sale, subject to this policy continuing to apply.
08. How we protect your data
Security controls are applied across the stack: traffic is encrypted in transit with TLS, passwords are stored only as salted hashes, API access is token-based and scoped to a role, and administrative access to production systems is restricted to named personnel on a least-privilege basis. We log access, monitor for anomalies and patch our dependencies on a regular cycle.
No system can be guaranteed to be perfectly secure. If a breach affects your personal data, we will notify you and the relevant supervisory authority as required by applicable law.
09. Data retention
We keep personal data only as long as it serves the purpose it was collected for. Account data is retained while the account is active and for up to 90 days after it is closed, so it can be restored if the closure was a mistake. Enquiry and demo request records are kept for up to 24 months. Technical logs are rotated within 12 months. Records we must keep for tax, accounting or legal reasons are retained for the period the relevant law prescribes, after which they are deleted or irreversibly anonymised.
10. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy of it.
- Correct information that is inaccurate or incomplete.
- Request deletion of your personal data.
- Restrict or object to certain processing.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, without affecting processing already carried out.
- Lodge a complaint with your local data protection authority.
California residents additionally have the right to know what personal information is collected, to request its deletion, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
To exercise any right, email support@zengnia.com. We respond within 30 days and may need to verify your identity before acting on the request.
11. Account and data deletion
You can ask us to delete your Zengnia account and the personal data associated with it at any time, whether you use the web portal or the mobile app.
- Submit our account deletion request form — the quickest route, and it works whether or not you can still sign in, or
- Email support@zengnia.com from the address registered to the account, with the subject “Account deletion request”, or
- Contact your organisation's Zengnia administrator, who can request removal on your behalf.
We confirm receipt within 5 business days and complete the deletion within 30 days. Account details, profile image and authentication tokens are erased. Aggregated business statistics that contain no personal identifiers, and records we are legally required to retain, may be kept as described in section 9. Uninstalling the app removes locally stored data from your device but does not by itself delete your server-side account.
12. Cookies and similar technologies
Our website uses strictly necessary cookies to keep your session active and to protect forms against cross-site request forgery. We also use analytics cookies to understand, in aggregate, which pages are useful. You can block or delete cookies in your browser settings, though the authenticated portal will not function without the essential ones. The mobile app does not use browser cookies.
13. International data transfers
Zengnia operates from the United States and works with vendors in several jurisdictions, so your information may be processed outside your country of residence. Where data is transferred out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses together with additional technical measures.
14. Children's privacy
The Zengnia website, portal and mobile app are business tools intended for professional use and are not directed to children. We do not knowingly collect personal information from anyone under 16 years of age. If you believe a child has provided us with personal data, contact support@zengnia.com and we will delete it promptly.
15. Changes to this policy
We may update this policy as our products and legal obligations evolve. The “last updated” date at the top of the page always reflects the current version. If a change materially affects how we handle your personal data, we will notify you by email or through an in-app notice before it takes effect. Continuing to use the service after that point means you accept the revised policy.
16. Contact us
Questions about this policy, or about how we handle your data, are welcome at any time.
- Email: support@zengnia.com
- Address: Zengnia, Wilmington, DE 19808, USA
- Related: Terms & Conditions
