Privacy Policy
Last Updated
Aug 7, 2025
Protecting your personal data is a top priority for us, Zentio GmbH. Below, we inform you about how we process your personal data when you visit our website www.zentio.io in accordance with the General Data Protection Regulation (GDPR).
1. Data Controller
Zentio GmbH
Grünberger Str. 86
10245 Berlin
Germany
Email: info@zentio.io
Privacy Contact
If you have any questions about data protection, feel free to contact our internal privacy contact person:
Christophe Kafrouni
Email: chris.kafrouni@zentio.io
2. General Information on Data Processing
2.1 Scope of Processing
We process personal data only to the extent necessary to provide and improve our website or respond to your inquiries.
2.2 Legal Bases
Consent: Art. 6(1)(a) GDPR
Contract performance / pre-contractual measures: Art. 6(1)(b) GDPR
Legal obligations: Art. 6(1)(c) GDPR
Legitimate interests: Art. 6(1)(f) GDPR
3. Access Data and Hosting
3.1 Server Log Files
When you visit our website, our hosting provider (IONOS SE, Germany) automatically collects the following data:
Browser type and version
Operating system used
Anonymized IP address
Date and time of server request
Referrer URL
Pages visited
This data is processed for ensuring a stable and secure website operation (Art. 6(1)(f) GDPR). The data is automatically deleted after 7 days.
3.2 Hosting
Our website is hosted by Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, Netherlands. Data is processed on servers provided by Amazon Web Services (AWS) located within the European Union (e.g., Frankfurt/Ireland). A data processing agreement (DPA) in accordance with Art. 28 GDPR has been concluded with Framer B.V. to ensure the protection of your data.
4. Web Analytics with PostHog
4.1 Use of PostHog
We use the service PostHog (PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA) to analyze user behavior on our website. All processing is performed on servers located in the EU. A data processing agreement (DPA) has been signed.
Collected data includes:
Anonymized IP address
Browser and device information
Interaction and page views
Timestamps and referrer URLs
4.2 Legal Basis and Consent
Data processing is based on your consent (Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG). When you first visit our website, a cookie banner appears where you can give or refuse your consent. Your choice is stored and can be changed at any time via the footer or the banner itself.
4.3 Retention Period
Anonymized analytics data is automatically deleted after 12 months.
5. Cookies
5.1 Necessary Cookies
These cookies are essential for the website to function properly and are automatically set. They do not contain any personal data and are used, for example, to store your cookie preferences.
5.2 Analytics Cookies
Analytics cookies are set only with your explicit consent (see section 4). They help us improve the usability and performance of our website.
6. Contact Form
6.1 Type and Purpose of Processing
If you contact us via the contact form, the following data is processed:
Name
Email address
Company (optional)
Your message
The data is processed for communication and potential business initiation.
6.2 Legal Basis
Processing is based on your consent (Art. 6(1)(a) GDPR) or, if it relates to entering into a contract, on Art. 6(1)(b) GDPR.
6.3 Retention
We delete this data once it is no longer needed for its intended purpose, no later than 2 years after receipt, unless legal retention requirements apply.
6.4 Storage in Supabase
Submitted data is stored in our EU-hosted database on Supabase (Supabase Inc.). A data processing agreement has been concluded in accordance with Art. 28 GDPR.
7. Your Rights
You have the following rights under the GDPR:
Right of access (Art. 15 GDPR)
Right to rectification (Art. 16 GDPR)
Right to erasure (Art. 17 GDPR)
Right to restriction of processing (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
Right to object (Art. 21 GDPR)
Right to withdraw consent at any time (Art. 7(3) GDPR)
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
8. No Automated Decision-Making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
9. Data Security
We use SSL encryption to securely transmit your data. In addition, we implement appropriate technical and organizational measures to protect your data from unauthorized access, loss, or destruction.