ZI² Discover

Privacy Policy

Last updated: 2026-06-07. Effective: 2026-06-07.

This Privacy Policy explains how Zenith Intelligence Technologies, operating as ZI² Systems ("ZI²", "we", "us"), the operator of ZI² Discover (the "Service"), collects, uses, shares, retains, and protects personal data. It applies to visitors to discover.zi2.app, users of the dashboard, and consumers of the API.

1. Who we are

The controller of personal data described in this policy is:

Zenith Intelligence Technologies (ZI² Systems)
Founder and responsible person: Joseph-Israel Kadjo
Email: [email protected]

For privacy questions, data subject requests, and complaints, contact the data protection point of contact at the email address above. We act as the data protection officer for the Service; if your jurisdiction requires a formal Article 37 GDPR appointment we will provide named contact details on request.

2. The data we collect

2.1 Account data

Name, email address, password (stored as a bcrypt hash, never in plain text), workspace name, role, locale, and timezone.

2.2 Billing data

Billing address, tax identifier (where required), plan, invoice history, last four digits and brand of card. Full card numbers are not stored by ZI²; they are tokenized by Stripe, Paystack, or Flutterwave.

2.3 Site and content data

For each Verified Site you connect: the URL, verification proof, robots.txt and sitemap contents, HTML of pages we scan, rendered screenshots, schema markup, headers, Core Web Vitals measurements, and accessibility tree snapshots. This is the working material of the Service.

2.4 AI probe queries and responses

The queries we send to AI engines on your behalf, and the responses they return. This includes the text we extract from your content to phrase those queries.

2.5 Usage telemetry

IP address (truncated to /24 for IPv4 and /48 for IPv6 within 30 days), user-agent, dashboard pages visited, feature usage counters, API call counts, error logs, and per-tenant cost meters.

2.6 Communications

Support requests, feedback, and emails you send us, including any attachments.

3. Why we use it (purposes)

4. Legal bases (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under Article 6(1) GDPR:

5. Sub-processors and recipients

We share personal data only with sub-processors we have engaged in writing to operate the Service. The current list is below. We will update this list and notify customers of material changes via email or in-app at least 30 days in advance.

Our underlying hosting infrastructure is operated by ZI² on a dedicated server located in Germany (Server B). Backups remain within Germany. We do not sell personal data and do not share it with advertisers.

6. International transfers

When AI probe or payment data is transferred from the EEA, UK, or Switzerland to a country that has not received an adequacy decision (notably the United States for several sub-processors), we rely on the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914, supplemented by technical and organizational measures (TLS in transit, at-rest encryption at sub-processor side, minimization of payload). For US recipients certified under the EU-US Data Privacy Framework we additionally rely on that framework where applicable.

You may request a copy of the relevant transfer mechanism by emailing [email protected].

7. Retention

8. Your rights under GDPR

If GDPR applies to you, you have the right to:

9. How to exercise your rights (DSAR process)

Email [email protected] with the subject line "DSAR" and tell us which right you are exercising. We may need to verify your identity (typically by confirming control of the account email).

We respond within 30 days of a verified request. The first request in any 12-month period is free. We may charge a reasonable fee for additional copies or for requests that are manifestly unfounded or excessive.

10. Your rights under CCPA / CPRA

If you are a California resident, you have the right to know what personal information we collect, the right to delete it (subject to exceptions), the right to correct inaccurate information, and the right to opt out of the "sale" or "sharing" of personal information.

We do not sell personal information and we do not share it for cross-context behavioral advertising. We have no advertising cookies and no advertising sub-processors.

To exercise these rights, email [email protected] with "California request" in the subject line. We will not discriminate against you for exercising these rights.

11. Cookies and analytics

The marketing site uses only strictly necessary cookies by default. If we enable an analytics tool, it will be a privacy-respecting product (such as Plausible or self-hosted PostHog) loaded only after opt-in for EEA/UK visitors. We do not use Google Analytics, advertising pixels, or cross-site tracking. See the Cookie Policy for the per-cookie table.

12. Children

The Service is not directed to children. We do not knowingly collect personal data from anyone under 16 in the EEA or under 13 in the United States. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

13. Security

We apply technical and organizational measures appropriate to the risk, including TLS in transit, at-rest encryption, Postgres Row-Level Security for tenant isolation, bcrypt password hashing, ZI² Hybrid envelope encryption for sensitive credentials, daily backups, and audit logging. See the Security overview for the full description.

14. Automated decision-making

The Service does not make decisions about you that produce legal or similarly significant effects through purely automated processing. Scan findings and AI engine recommendations are presented to you; you remain in control of whether to apply a fix. Where the applier ships an automated change, the authority gate that allowed it was configured by you under section 7 of the Terms.

14a. Personal data of third parties on your sites

When we scan a Verified Site, we may incidentally process personal data about your visitors, customers, authors, or employees — for example, a name in a page byline, a contact email in a footer, a comment under a blog post. For that data, you are the controller and ZI² is your processor. We process it only to deliver the scanning, reporting, and fixing services you requested.

If you are subject to GDPR and need a Data Processing Agreement (DPA) under Article 28, our standard DPA is available on request to [email protected]. It includes the SCCs as a schedule. Enterprise customers can have a countersigned DPA on the order form.

14b. AI engine probes — additional disclosure

AI probes are the most novel data flow in the Service and we want to be explicit about them. When you launch a probe:

You can disable individual providers for your workspace at any time from the Probes settings; disabling a provider stops new outbound queries to it. Historical responses already stored remain in your scan history until you delete them or until the retention period in section 7 expires.

15. Changes to this policy

We will post any changes on this page and update the "Last updated" date. If a change is material we will notify you by email and in-app at least 30 days before it takes effect.

15a. Marketing communications

We send transactional emails (account, billing, scan completion, security notices) because they are necessary to provide the Service. We send product update and onboarding emails to active customers on the basis of legitimate interests; you can opt out via the link in each email or by emailing [email protected]. Opting out of marketing does not stop transactional emails.

We do not buy mailing lists, and we do not enroll non-customers in marketing automation without prior consent.

15b. Aggregated and de-identified data

We may produce aggregated or de-identified statistics from scan data — for example, the average number of structured-data issues per site in a benchmark category, or the share of pages that fail Core Web Vitals on a given month. These statistics do not identify you, your tenants, or any individual, and we may use them to publish research, train product models, or improve the Service. We do not republish identifiable per-site or per-tenant data without explicit permission.

16. Contact and complaints

For any privacy question, contact [email protected]. You may also lodge a complaint with your local supervisory authority. For users in Germany, that is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, datenschutz-berlin.de.

See also: Terms · Security · Acceptable Use · DMCA · Cookies