Privacy Policy
Last updated: 28 July 2026
1. Introduction
Welcome to Zuzana AI ApS ("we", "us", "our"). We respect your privacy and are committed to protecting any personal data you share when you:
- browse our website https://zuzana.ai (the "Site"); or
- install and use our Chrome browser extension (the "Extension").
This notice explains what information we collect, why we collect it, and the choices you have.
2. Scope
This policy applies to individual Site visitors, Extension end-users, and our AI customer-support platform (the "Platform"), including the third-party services a business customer connects to it (see §8).
If you are a business customer under a separate service agreement, the Data Processing Agreement (DPA) that names our dedicated Data Protection Officer governs how we process personal data on your behalf as your processor. This notice still describes that processing, so that you and the people whose data passes through the Platform can see how it is handled.
3. Who is responsible for your data?
Controller:
Zuzana AI ApS
Vejlevangen 6, 2840 Holte, Denmark
CVR-nr. 45761398
Email: privacy@zuzana.ai
Data Protection Officer (DPO):
Line Madsen
Email: dpo@zuzana.ai
Tel.: +45 78 77 50 10
(Use this contact for all data-protection enquiries.)
4. What data do we collect?
| Category | Examples | Collected when |
|---|---|---|
| Basic identifiers | email (if you sign up for news), support messages | you fill a form |
| Usage data (Site) | IP address, device type, pages visited, cookies | you browse the Site |
| Extension diagnostics | install / uninstall timestamps, anonymised error logs, feature-use counters | the Extension runs |
| Optional sync data (Extension) | your personal presets or settings | you opt-in to sync |
No page-content scraping – The Extension runs entirely in your browser. It reads page content only to provide its functionality (e.g. highlight text, run AI prompts) and never transmits the full page or your browsing history to our servers. Where API calls are necessary (e.g. to generate AI output) we send only the minimal prompt you trigger, over encrypted channels.
5. Why we process your data & legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Operate and secure the Site | usage data | Art 6(1)(f) legitimate interests |
| Deliver Extension features | diagnostic + optional sync data | Art 6(1)(b) contract |
| Email newsletters | email address | Art 6(1)(a) consent |
| Respond to support requests | basic identifiers + message | Art 6(1)(b) contract |
| Improve and debug | aggregated diagnostics | Art 6(1)(f) legitimate interests |
You can withdraw consent or object to processing at any time (§10).
6. Cookies & local storage
We use:
- Essential cookies to keep you logged in and remember preferences.
- Analytics cookies (Matomo, first-party, IP-anonymised) to measure traffic — opt-in only.
The Extension stores settings and recent prompts in your browser's local storage. You may delete them at any time via the Extension's Reset option.
7. Sharing & international transfers
We never sell your personal data. We share it only with:
| Recipient | Role | Safeguards |
|---|---|---|
| Cloud hosting provider | runs our servers (EU region) | GDPR-compliant, encrypt-at-rest |
| Email delivery service | sends newsletters | EU or US with Standard Contractual Clauses |
| Error-tracking service | receives pseudonymised crash reports | EU data centre |
If data is transferred outside the EEA, we rely on EU Standard Contractual Clauses and supplementary safeguards such as encryption in transit.
8. Google user data (Google Business Profile integration)
Where a business customer connects their Google Business Profile to the Platform, we access data from their Google Account on their behalf so that their team can read and answer Google reviews inside the Platform. This section is our disclosure under the Google API Services User Data Policy, including the Limited Use requirements.
Scope we request: https://www.googleapis.com/auth/business.manage. This is the only scope Google publishes for the Business Profile APIs, so there is no narrower alternative that still allows reading reviews and publishing replies.
| Google user data | Why we access it |
|---|---|
| Business accounts and locations | so the customer can choose which location to connect |
| Reviews (star rating, comment, review ID, create and update time) | to import each review into the Platform as a conversation for the team to answer |
| Reviewer display name | to attribute the review to a contact record, so an agent can see who they are replying to |
| Replies we publish | to send the reply the customer approves back to Google and keep the thread in sync |
| OAuth access and refresh tokens | to keep the connection working between syncs without re-authorising each time |
Where Google marks a reviewer as anonymous, we do not create a contact record for them.
Limited use. We do not use Google user data for advertising. We do not sell it or transfer it to third parties, except as needed to provide the feature, to comply with law, or as part of a merger where this notice continues to apply. We do not use it to train generalised AI or machine-learning models. Where a reply is drafted by AI, the review text is sent to our AI provider for that single request under an agreement that forbids retention for training.
Human access. Our staff do not read Google user data except with the customer's explicit permission for support, where required by law, for a security investigation, or in aggregated and anonymised form.
How to disconnect. Disconnecting the integration in the Platform revokes our tokens with Google and removes them from our systems, which stops all further access. A customer can also revoke our access independently at any time from the Google Account permissions page at https://myaccount.google.com/permissions. Reviews already imported remain in the customer's support history and follow the retention schedule in §11 unless deletion is requested.
9. Security
We apply industry-standard safeguards:
- HTTPS/TLS 1.3 encryption
- Encrypted secrets management
- Least-privilege access and MFA
- Routine vulnerability scans & penetration tests
10. Your rights
Under GDPR (and equivalent UK/EU laws) you may:
- Access your data
- Rectify inaccurate data
- Erase data ("right to be forgotten")
- Restrict or object to processing
- Withdraw consent at any time
- Port data you provided
To exercise any right, email dpo@zuzana.ai or privacy@zuzana.ai. We respond within 30 days.
11. Retention
| Data | Retention period |
|---|---|
| Newsletter subscribers | until you unsubscribe |
| Support emails | 2 years after ticket closure |
| Site analytics | 12 months (aggregated thereafter) |
| Extension diagnostics | 30 days |
| Google Business Profile tokens | revoked and deleted when the integration is disconnected |
| Imported Google reviews and replies | for the life of the customer's account, then per their DPA |
Back-ups are purged on a rolling 35-day schedule.
12. Changes
We may update this notice. Material changes will be announced via a Site banner or Extension release notes 14 days before they take effect.
13. Contact
Questions? Email dpo@zuzana.ai or write to Zuzana AI ApS, Vejlevangen 6, 2840 Holte, Denmark.
© 2025 Zuzana AI ApS