Privacy Policy
How Zitrino handles personal data across the self-hosted ZNYX runtime and the hosted console. The runtime runs in your infrastructure; the hosted console operates on account and operational metadata.
1. Overview
This Privacy Policy explains how Zitrino ("Zitrino", "we", "us") handles personal data in connection with ZNYX, our AI security platform. ZNYX is split into two components with very different data boundaries: an open-source runtime (the AI firewall) that you self-host, and an optional hosted control plane (the "console") that we operate.
Because of this split, the way data is handled depends heavily on how you deploy ZNYX. This policy describes both. Where you have signed a commercial agreement or Data Processing Agreement (DPA) with us, that agreement governs if it conflicts with this page.
2. Our role: controller and processor
For our own business and website data (for example, account registration, billing, and marketing enquiries), Zitrino acts as a data controller.
For customer content processed through the hosted console on behalf of a customer, Zitrino acts as a data processor, and the customer is the controller. When you self-host the runtime, Zitrino does not act as a processor of the prompts and responses evaluated in your environment - that data never reaches us.
3. Information we collect
Depending on how you use ZNYX, we may collect:
- Account data: name, work email, password hash, and organization membership.
- Organization metadata: organization name, projects, environments, plan, and configuration.
- Operational trace metadata: trace identifiers, policy decisions, detector summaries, latency, and project scope. The Growth operating model is metadata-first by default and does not store full prompt or response bodies unless you explicitly enable it.
- Billing records: plan, usage counts, and invoicing details processed via our payment provider.
- Support communications: messages, attachments, and contact details you send us.
- Website data: cookies, device/browser information, and aggregate analytics for the marketing site.
4. How we use information
- To provide, operate, secure, and improve the hosted console and website.
- To authenticate users and enforce plan limits and access controls.
- To provide support, respond to enquiries, and send service communications.
- To process billing and meet legal, tax, and accounting obligations.
- To detect, investigate, and prevent abuse, fraud, and security incidents.
5. Legal bases for processing (GDPR)
Where the GDPR or similar laws apply, we rely on the following legal bases: performance of a contract (to provide the service you signed up for), legitimate interests (to secure and improve our products), legal obligation (for tax and compliance records), and consent (for optional marketing and certain cookies, which you can withdraw at any time).
6. Runtime content boundary
The open-source runtime evaluates prompts, model outputs, and tool payloads inside your own infrastructure. That content is not transmitted to Zitrino for enforcement to work. You are responsible for the policies, retention rules, logging, and access controls you configure in your environment.
7. Cookies and analytics
Our marketing website uses strictly necessary cookies and, where permitted, limited analytics to understand aggregate usage. The hosted console uses cookies required for authentication and session management. You can control non-essential cookies through your browser or any consent controls we provide.
8. Data sharing and subprocessors
We do not sell personal data. We share data only with service providers (subprocessors) that help us run the hosted service - for example, cloud hosting, payment processing, and email delivery - under contractual confidentiality and data-protection terms. A current list of subprocessors for the hosted console is available on request and in the executed DPA.
9. International transfers
We operate across the UK, US, and India and may process data in those regions. Where personal data is transferred across borders, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms required by applicable law. Specific regional hosting commitments are addressed in commercial agreements where required.
10. Data retention
Retention depends on the deployment model and your agreement. Self-hosted customers control retention entirely within their own infrastructure. Hosted-console data is retained according to product defaults, your configuration, and contractual commitments, after which it is deleted or returned in line with the applicable agreement. We retain billing and legal records for as long as required by law.
11. Security
We design the hosted service around enterprise security controls including encryption in transit, access controls, audit logging, and least-privilege operations. No method of transmission or storage is completely secure, and external certifications or attestations are issued separately when available - none are implied by this page.
12. Your rights
Subject to applicable law, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing or withdraw consent. To exercise these rights, contact us using the details below. If we process data as a processor on behalf of a customer, we will route your request to the relevant controller.
13. Data subject and erasure requests
For the hosted console, we support data subject access and erasure workflows. Requests are verified and actioned within the timeframes required by applicable law. Self-hosted deployments handle such requests within the customer environment.
14. Children's data
ZNYX is a business product not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
15. Changes to this policy
We may update this policy from time to time. Material changes will be reflected on this page with an updated effective date. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
16. Contact
For privacy questions or to exercise your rights, contact [email protected]. You can also reach us at:
USA
16192 Coastal Highway, Lewes, Delaware 19958
+1 (302) 291-4545
India · Coimbatore
GRG Gen Nxt Foundation Incubator,, Phase-2, 1708, Avinashi Road, Civil Aerodrome Post,, Coimbatore, Tamilnadu 641014
+91 93848 09905