ZenTalk AI Privacy Policy

Last updated: 06.10.2026

1. Controller and contact

The controller of personal data described below is Global Thiel, NIP: 781-177-53-36, REGON: 302-327-865. Privacy contact: biuro@zentalk.pl, tel. +48 698 631 107.

No separate Data Protection Officer has been appointed. GDPR requests should be sent to the email above.

2. Scope and roles

This Policy covers: (a) visitors to www.zentalk.pl, (b) Customers with a ZenTalk Dashboard account, (c) business contacts in B2B outreach, and (d) — where ZenTalk acts as a processor — End Users of the Widget on Customer sites.

For Widget End Users, the store/site owner (ZenTalk Customer) is generally the controller. ZenTalk processes that data on the Customer’s behalf (GDPR Art. 28) to provide the chat service. The Customer should inform End Users in their own privacy notice. The chat lead form requires consent and names ZenTalk (hosting) and the site operator.

3. What data we process

Depending on context we may process:

  • Customer account data: name, email, password (at the auth provider), company name, billing details,
  • payment data: Stripe IDs, subscription/payment status (card numbers are handled by Stripe — we do not store full PAN),
  • chat message content, language, page URL,
  • technical data: IP address, user-agent, session / visitorId in browser storage,
  • chat lead form data: name, email, phone, company (optional) and consent metadata,
  • conversation ratings and product-related events (e.g. add-to-cart clicks) for quality/analytics for the Customer,
  • contact-form data on zentalk.pl,
  • support tickets and attachments,
  • security and abuse-limit logs,
  • for store-link demos: publicly available shop content and demo account data.

4. Purposes and legal bases

Performance of the contract with the Customer — GDPR Art. 6(1)(b).

Consent — e.g. analytics/marketing cookies on zentalk.pl, lead-form consent — Art. 6(1)(a).

Legitimate interests — IT security, abuse prevention, internal stats, B2B direct marketing, claims — Art. 6(1)(f).

Legal obligations (accounting, tax) — Art. 6(1)(c).

5. Where data is stored

The Service runs in the cloud. Application data and databases are hosted with infrastructure providers in the EU/EEA or with appropriate transfer safeguards (see §§ 6–7).

Main providers: Vercel (app hosting), PostgreSQL / Supabase (database, auth, storage), Stripe (payments), OpenAI (language models and embeddings), Google (Tag Manager / Analytics on the marketing site — after cookie consent), transactional email provider (e.g. Resend or SMTP).

6. Recipients and subprocessors

Data may be shared with, as needed:

  • OpenAI, Inc. — chat answers and search embeddings,
  • Stripe, Inc. — payments,
  • Vercel Inc. — hosting,
  • Supabase / PostgreSQL provider — storage and authentication,
  • Google — analytics/tags on zentalk.pl (after cookie consent),
  • email provider — transactional mail,
  • the ZenTalk Customer — for End User data from their Widget,
  • public authorities where required by law.

7. Transfers outside the EEA

Some providers (including OpenAI, Stripe, Google, Vercel) may process data in the USA or other third countries. GDPR-compliant mechanisms are used (e.g. Standard Contractual Clauses, adequacy decisions / Data Privacy Framework, depending on the provider).

By using the Service, the Customer accepts that End User queries and knowledge-base snippets may be sent to the AI model to generate answers.

8. Retention

Account and billing data — for the life of the contract and as required by tax/accounting law.

Closed chat conversations — per Customer retention settings in the Dashboard (typically 30–730 days; system default around 90 days unless changed).

Chat leads — per Customer settings (default around 365 days).

Login and some security logs — usually up to 90 days; abuse events — usually up to 30 days.

Demo accounts/knowledge from a shop link — usually up to 30 days, then deleted or deactivated.

Cookie consents on zentalk.pl — in the browser per the cookie banner.

9. Cookies and analytics (zentalk.pl)

On the marketing site we use:

  • necessary cookies for site operation,
  • analytics/marketing tags (Google Tag Manager, Consent Mode v2) — only after consent,
  • consent preferences and campaign attribution (e.g. UTM) in localStorage / sessionStorage.

10. Customer-site Widget

The Widget uses browser storage (localStorage / sessionStorage) for visitor continuity and sends technical data (IP, user-agent) to ZenTalk servers. It does not show its own cookie banner — the Customer is responsible for End User notices and consents on their site.

We do not encourage submitting special-category (sensitive) data in chat.

11. Your rights

You have the right of access, rectification, erasure, restriction, portability, objection (including to direct marketing) and to withdraw consent where processing is consent-based, and to lodge a complaint with a supervisory authority (in Poland: UODO).

Requests: biuro@zentalk.pl, tel. +48 698 631 107. Widget End Users may also contact the store owner (controller); ZenTalk will forward or assist as processor.

12. Business outreach (GDPR Art. 14)

The controller processes business contact details of entrepreneurs and company representatives: company name, website and business email or phone. Sources: public websites, registers/directories, company profiles, or a referral.

Purpose: one-off contact about ZenTalk AI (including a free demo) and follow-up if the recipient replies. Legal basis: legitimate interest — direct marketing of own services (Art. 6(1)(f) GDPR).

Retention: until objection, no longer than 6 months after the last unanswered contact; if cooperation starts — under customer rules. After objection we keep the address only on a suppression list.

Recipients: email and hosting providers acting for the controller. Data is not sold or used for profiling.

Rights: access, rectification, erasure, restriction, objection (reply “no” or email biuro@zentalk.pl) and complaint to UODO.

13. ZenTalkBot and demos

When preparing a demo, the Administrator may fetch publicly available shop content via ZenTalkBot, subject to robots.txt and https://www.zentalk.pl/bot. Demo data is usually deleted or deactivated within 30 days unless the account is handed over on other terms.

14. Partner Programme

In the ZenTalk AI partner programme (section 17 of the Terms) the Administrator processes Partners’ data: name, email address, phone, company details (name, tax ID, address), bank account number and holder, partner panel login data (password stored only as a cryptographic hash), and the history of assigned Customers, commission and payouts. Legal bases: performance of the participation agreement (Art. 6(1)(b) GDPR), legal obligations including tax and accounting (Art. 6(1)(c)) and the legitimate interest in preventing abuse and pursuing claims (Art. 6(1)(f)). The bank account number is stored encrypted. Data is kept for the duration of participation and then for the period required by tax and accounting law and until claims become time-barred.

If a Customer signs up with a Partner’s code or link, the Administrator makes available to that Partner in the partner panel the Customer’s name, assignment date, subscription status, amounts paid and commission accrued — to settle commission, based on the legitimate interest of the Administrator and the Partner (Art. 6(1)(f) GDPR). The Partner must keep this information confidential. The Customer has the right to object to such processing.

15. Changes

This Policy may be updated when law, infrastructure or the Service changes. The current version is always published on the website with the last-updated date. Material changes may also be announced to Customers (email / Dashboard).