Skip to main content
ZNYX AI
Privacy

Privacy Policy

How Zitrino handles personal data across the self-hosted ZNYX runtime and the hosted console. The runtime runs in your infrastructure; the hosted console operates on account and operational metadata.

1. Overview

This Privacy Policy explains how Zitrino ("Zitrino", "we", "us") handles personal data in connection with ZNYX, our AI security platform. ZNYX is split into two components with very different data boundaries: an open-source runtime (the AI firewall) that you self-host, and an optional hosted control plane (the "console") that we operate.

Because of this split, the way data is handled depends heavily on how you deploy ZNYX. This policy describes both. Where you have signed a commercial agreement or Data Processing Agreement (DPA) with us, that agreement governs if it conflicts with this page.

2. Our role: controller and processor

For our own business and website data (for example, account registration, billing, and marketing enquiries), Zitrino acts as a data controller.

For customer content processed through the hosted console on behalf of a customer, Zitrino acts as a data processor, and the customer is the controller. When you self-host the runtime, Zitrino does not act as a processor of the prompts and responses evaluated in your environment - that data never reaches us.

3. Information we collect

Depending on how you use ZNYX, we may collect:

  • Account data: name, work email, password hash, and organization membership.
  • Organization metadata: organization name, projects, environments, plan, and configuration.
  • Operational trace metadata: trace identifiers, policy decisions, detector summaries, latency, and project scope. The Growth operating model is metadata-first by default and does not store full prompt or response bodies unless you explicitly enable it.
  • Billing records: plan, usage counts, and invoicing details processed via our payment provider.
  • Support communications: messages, attachments, and contact details you send us.
  • Website data: cookies, device/browser information, and aggregate analytics for the marketing site.

4. How we use information

  • To provide, operate, secure, and improve the hosted console and website.
  • To authenticate users and enforce plan limits and access controls.
  • To provide support, respond to enquiries, and send service communications.
  • To process billing and meet legal, tax, and accounting obligations.
  • To detect, investigate, and prevent abuse, fraud, and security incidents.

5. Legal bases for processing (GDPR)

Where the GDPR or similar laws apply, we rely on the following legal bases: performance of a contract (to provide the service you signed up for), legitimate interests (to secure and improve our products), legal obligation (for tax and compliance records), and consent (for optional marketing and certain cookies, which you can withdraw at any time).

6. Runtime content boundary

The open-source runtime evaluates prompts, model outputs, and tool payloads inside your own infrastructure. That content is not transmitted to Zitrino for enforcement to work. You are responsible for the policies, retention rules, logging, and access controls you configure in your environment.

7. Cookies and analytics

Our marketing website uses strictly necessary cookies and, where permitted, limited analytics to understand aggregate usage. The hosted console uses cookies required for authentication and session management. You can control non-essential cookies through your browser or any consent controls we provide.

8. Data sharing and subprocessors

We do not sell personal data. We share data only with service providers (subprocessors) that help us run the hosted service - for example, cloud hosting, payment processing, and email delivery - under contractual confidentiality and data-protection terms. A current list of subprocessors for the hosted console is available on request and in the executed DPA.

9. International transfers

We operate across the UK, US, and India and may process data in those regions. Where personal data is transferred across borders, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms required by applicable law. Specific regional hosting commitments are addressed in commercial agreements where required.

10. Data retention

Retention depends on the deployment model and your agreement. Self-hosted customers control retention entirely within their own infrastructure. Hosted-console data is retained according to product defaults, your configuration, and contractual commitments, after which it is deleted or returned in line with the applicable agreement. We retain billing and legal records for as long as required by law.

11. Security

We design the hosted service around enterprise security controls including encryption in transit, access controls, audit logging, and least-privilege operations. No method of transmission or storage is completely secure, and external certifications or attestations are issued separately when available - none are implied by this page.

12. Your rights

Subject to applicable law, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing or withdraw consent. To exercise these rights, contact us using the details below. If we process data as a processor on behalf of a customer, we will route your request to the relevant controller.

13. Data subject and erasure requests

For the hosted console, we support data subject access and erasure workflows. Requests are verified and actioned within the timeframes required by applicable law. Self-hosted deployments handle such requests within the customer environment.

14. Children's data

ZNYX is a business product not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

15. Changes to this policy

We may update this policy from time to time. Material changes will be reflected on this page with an updated effective date. Continued use of the service after changes take effect constitutes acceptance of the updated policy.

16. Contact

For privacy questions or to exercise your rights, contact [email protected]. You can also reach us at:

USA
16192 Coastal Highway, Lewes, Delaware 19958
+1 (302) 291-4545

India · Coimbatore
GRG Gen Nxt Foundation Incubator,, Phase-2, 1708, Avinashi Road, Civil Aerodrome Post,, Coimbatore, Tamilnadu 641014
+91 93848 09905

Secure every prompt, agent, and tool call, in your boundary.

Pull the open-source runtime, drop it into your stack, and start enforcing policy in minutes, free, forever. Add the hosted control plane when you want centralized policies, evidence, traces, and team workflows.