Privacy Policy

Last updated: 28 July 2026

1. Introduction

Welcome to Zuzana AI ApS ("we", "us", "our"). We respect your privacy and are committed to protecting any personal data you share when you:

  • browse our website https://zuzana.ai (the "Site"); or
  • install and use our Chrome browser extension (the "Extension").

This notice explains what information we collect, why we collect it, and the choices you have.

2. Scope

This policy applies to individual Site visitors, Extension end-users, and our AI customer-support platform (the "Platform"), including the third-party services a business customer connects to it (see §8).

If you are a business customer under a separate service agreement, the Data Processing Agreement (DPA) that names our dedicated Data Protection Officer governs how we process personal data on your behalf as your processor. This notice still describes that processing, so that you and the people whose data passes through the Platform can see how it is handled.

3. Who is responsible for your data?

Controller:

Zuzana AI ApS
Vejlevangen 6, 2840 Holte, Denmark
CVR-nr. 45761398
Email: privacy@zuzana.ai

Data Protection Officer (DPO):

Line Madsen
Email: dpo@zuzana.ai
Tel.: +45 78 77 50 10
(Use this contact for all data-protection enquiries.)

4. What data do we collect?

Category Examples Collected when
Basic identifiers email (if you sign up for news), support messages you fill a form
Usage data (Site) IP address, device type, pages visited, cookies you browse the Site
Extension diagnostics install / uninstall timestamps, anonymised error logs, feature-use counters the Extension runs
Optional sync data (Extension) your personal presets or settings you opt-in to sync

No page-content scraping – The Extension runs entirely in your browser. It reads page content only to provide its functionality (e.g. highlight text, run AI prompts) and never transmits the full page or your browsing history to our servers. Where API calls are necessary (e.g. to generate AI output) we send only the minimal prompt you trigger, over encrypted channels.

5. Why we process your data & legal bases

Purpose Data Legal basis (GDPR)
Operate and secure the Site usage data Art 6(1)(f) legitimate interests
Deliver Extension features diagnostic + optional sync data Art 6(1)(b) contract
Email newsletters email address Art 6(1)(a) consent
Respond to support requests basic identifiers + message Art 6(1)(b) contract
Improve and debug aggregated diagnostics Art 6(1)(f) legitimate interests

You can withdraw consent or object to processing at any time (§10).

6. Cookies & local storage

We use:

  • Essential cookies to keep you logged in and remember preferences.
  • Analytics cookies (Matomo, first-party, IP-anonymised) to measure traffic — opt-in only.

The Extension stores settings and recent prompts in your browser's local storage. You may delete them at any time via the Extension's Reset option.

7. Sharing & international transfers

We never sell your personal data. We share it only with:

Recipient Role Safeguards
Cloud hosting provider runs our servers (EU region) GDPR-compliant, encrypt-at-rest
Email delivery service sends newsletters EU or US with Standard Contractual Clauses
Error-tracking service receives pseudonymised crash reports EU data centre

If data is transferred outside the EEA, we rely on EU Standard Contractual Clauses and supplementary safeguards such as encryption in transit.

8. Google user data (Google Business Profile integration)

Where a business customer connects their Google Business Profile to the Platform, we access data from their Google Account on their behalf so that their team can read and answer Google reviews inside the Platform. This section is our disclosure under the Google API Services User Data Policy, including the Limited Use requirements.

Scope we request: https://www.googleapis.com/auth/business.manage. This is the only scope Google publishes for the Business Profile APIs, so there is no narrower alternative that still allows reading reviews and publishing replies.

Google user data Why we access it
Business accounts and locations so the customer can choose which location to connect
Reviews (star rating, comment, review ID, create and update time) to import each review into the Platform as a conversation for the team to answer
Reviewer display name to attribute the review to a contact record, so an agent can see who they are replying to
Replies we publish to send the reply the customer approves back to Google and keep the thread in sync
OAuth access and refresh tokens to keep the connection working between syncs without re-authorising each time

Where Google marks a reviewer as anonymous, we do not create a contact record for them.

Limited use. We do not use Google user data for advertising. We do not sell it or transfer it to third parties, except as needed to provide the feature, to comply with law, or as part of a merger where this notice continues to apply. We do not use it to train generalised AI or machine-learning models. Where a reply is drafted by AI, the review text is sent to our AI provider for that single request under an agreement that forbids retention for training.

Human access. Our staff do not read Google user data except with the customer's explicit permission for support, where required by law, for a security investigation, or in aggregated and anonymised form.

How to disconnect. Disconnecting the integration in the Platform revokes our tokens with Google and removes them from our systems, which stops all further access. A customer can also revoke our access independently at any time from the Google Account permissions page at https://myaccount.google.com/permissions. Reviews already imported remain in the customer's support history and follow the retention schedule in §11 unless deletion is requested.

9. Security

We apply industry-standard safeguards:

  • HTTPS/TLS 1.3 encryption
  • Encrypted secrets management
  • Least-privilege access and MFA
  • Routine vulnerability scans & penetration tests

10. Your rights

Under GDPR (and equivalent UK/EU laws) you may:

  • Access your data
  • Rectify inaccurate data
  • Erase data ("right to be forgotten")
  • Restrict or object to processing
  • Withdraw consent at any time
  • Port data you provided

To exercise any right, email dpo@zuzana.ai or privacy@zuzana.ai. We respond within 30 days.

11. Retention

Data Retention period
Newsletter subscribers until you unsubscribe
Support emails 2 years after ticket closure
Site analytics 12 months (aggregated thereafter)
Extension diagnostics 30 days
Google Business Profile tokens revoked and deleted when the integration is disconnected
Imported Google reviews and replies for the life of the customer's account, then per their DPA

Back-ups are purged on a rolling 35-day schedule.

12. Changes

We may update this notice. Material changes will be announced via a Site banner or Extension release notes 14 days before they take effect.

13. Contact

Questions? Email dpo@zuzana.ai or write to Zuzana AI ApS, Vejlevangen 6, 2840 Holte, Denmark.


© 2025 Zuzana AI ApS