Privacy Policy

Last Updated

Aug 7, 2025

Protecting your personal data is a top priority for us, Zentio GmbH. Below, we inform you about how we process your personal data when you visit our website www.zentio.io in accordance with the General Data Protection Regulation (GDPR).

1. Data Controller

Zentio GmbH
Grünberger Str. 86
10245 Berlin
Germany
Email: info@zentio.io

Privacy Contact

If you have any questions about data protection, feel free to contact our internal privacy contact person:
Christophe Kafrouni
Email: chris.kafrouni@zentio.io

2. General Information on Data Processing

2.1 Scope of Processing

We process personal data only to the extent necessary to provide and improve our website or respond to your inquiries.

2.2 Legal Bases

  • Consent: Art. 6(1)(a) GDPR

  • Contract performance / pre-contractual measures: Art. 6(1)(b) GDPR

  • Legal obligations: Art. 6(1)(c) GDPR

  • Legitimate interests: Art. 6(1)(f) GDPR

3. Access Data and Hosting

3.1 Server Log Files

When you visit our website, our hosting provider (IONOS SE, Germany) automatically collects the following data:

  • Browser type and version

  • Operating system used

  • Anonymized IP address

  • Date and time of server request

  • Referrer URL

  • Pages visited

This data is processed for ensuring a stable and secure website operation (Art. 6(1)(f) GDPR). The data is automatically deleted after 7 days.

3.2 Hosting

Our website is hosted by Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, Netherlands. Data is processed on servers provided by Amazon Web Services (AWS) located within the European Union (e.g., Frankfurt/Ireland). A data processing agreement (DPA) in accordance with Art. 28 GDPR has been concluded with Framer B.V. to ensure the protection of your data.

4. Web Analytics with PostHog

4.1 Use of PostHog

We use the service PostHog (PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA) to analyze user behavior on our website. All processing is performed on servers located in the EU. A data processing agreement (DPA) has been signed.

Collected data includes:

  • Anonymized IP address

  • Browser and device information

  • Interaction and page views

  • Timestamps and referrer URLs

4.2 Legal Basis and Consent

Data processing is based on your consent (Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG). When you first visit our website, a cookie banner appears where you can give or refuse your consent. Your choice is stored and can be changed at any time via the footer or the banner itself.

4.3 Retention Period

Anonymized analytics data is automatically deleted after 12 months.

5. Cookies

5.1 Necessary Cookies

These cookies are essential for the website to function properly and are automatically set. They do not contain any personal data and are used, for example, to store your cookie preferences.

5.2 Analytics Cookies

Analytics cookies are set only with your explicit consent (see section 4). They help us improve the usability and performance of our website.

6. Contact Form

6.1 Type and Purpose of Processing

If you contact us via the contact form, the following data is processed:

  • Name

  • Email address

  • Company (optional)

  • Your message

The data is processed for communication and potential business initiation.

6.2 Legal Basis

Processing is based on your consent (Art. 6(1)(a) GDPR) or, if it relates to entering into a contract, on Art. 6(1)(b) GDPR.

6.3 Retention

We delete this data once it is no longer needed for its intended purpose, no later than 2 years after receipt, unless legal retention requirements apply.

6.4 Storage in Supabase

Submitted data is stored in our EU-hosted database on Supabase (Supabase Inc.). A data processing agreement has been concluded in accordance with Art. 28 GDPR.

7. Your Rights

You have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR)

  • Right to rectification (Art. 16 GDPR)

  • Right to erasure (Art. 17 GDPR)

  • Right to restriction of processing (Art. 18 GDPR)

  • Right to data portability (Art. 20 GDPR)

  • Right to object (Art. 21 GDPR)

  • Right to withdraw consent at any time (Art. 7(3) GDPR)

  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)


8. No Automated Decision-Making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.


9. Data Security

We use SSL encryption to securely transmit your data. In addition, we implement appropriate technical and organizational measures to protect your data from unauthorized access, loss, or destruction.


10. Changes to This Privacy Policy

We reserve the right to update this privacy policy at any time. The version available at the time of your visit to our website applies.