Skip to content
Legal

Privacy policy

What we collect, why, how long we keep it, and what you can ask us to do about it.

Effective 1 September 2026Last updated 1 September 2026Contact support@zitrino.com
Privacy policyTerms of service
The short version

We collect contact details you give us and aggregate site analytics. We do not sell data, do not run advertising trackers, and never use client content to train models. Client content stays in the client’s boundary and is governed by the data processing agreement, not by this page.

1. Who we are

Zitrino builds and operates enterprise AI products and delivers engineering services. For information you give us through this website, or through a commercial relationship with us, Zitrino is the data controller. For content processed inside a client deployment of our products, the client is the controller and Zitrino acts as a processor under a data processing agreement.

2. What we collect

We collect as little as we can and nothing we do not have a use for. There is no advertising network on this site and no cross-site tracking.

Contact detailsName, work email, organisation and role, when you submit an enquiry, subscribe or apply for a role.
Enquiry contentWhat you write in the message field, kept only as long as needed to respond and record the relationship.
Site analyticsAggregated page views and referrers, collected without cookies and without individual profiles.
Service telemetryFor managed deployments, operational metrics such as latency, error rates and cost. Not customer content.
Recruitment dataCV, application material and interview notes, where you apply for a role.

3. Client content is different

Content processed by our products inside a client environment, including prompts, documents, retrieved context and generated outputs, belongs to the client. We do not use it to train or improve our models or products, and we do not disclose it to model providers outside the routing policy the client configures.

Where a hosted model provider is used, we operate under zero-retention terms so that content is not stored or used for training by that provider. Clients can restrict routing to self-hosted or in-region models at any time.

4. Why we process it

We rely on the following lawful bases: performance of a contract, where you are a client or in the process of becoming one; legitimate interests, for responding to business enquiries, securing our services and improving our own operations; consent, for the newsletter, which you can withdraw in one click; and legal obligation, where retention or disclosure is required of us.

5. Who we share it with

We do not sell personal data and we do not share it for advertising. We use a small number of sub-processors for hosting, email delivery and applicant tracking, each under contract and listed in our trust centre. Clients are notified at least 30 days before any addition to the sub-processor list for services they use.

6. International transfers

Managed deployments run in the region the client selects. Where personal data moves outside its region of origin, we rely on Standard Contractual Clauses or an adequacy decision, and we apply supplementary technical measures including encryption and pseudonymisation. Sovereign and air-gapped deployments involve no cross-border transfer at all.

7. How long we keep it

Enquiry records are kept for 24 months from last contact. Client contractual records are kept for the term plus seven years, as required for tax and audit. Recruitment data is kept for 12 months unless you ask us to keep it longer for future roles. Operational telemetry is aggregated after 90 days. Client content follows the retention schedule in the applicable data processing agreement, and is deleted or returned on termination.

8. Your rights

Depending on where you are, you may have the right to access, correct, delete, restrict or port your personal data, to object to processing based on legitimate interests, and to withdraw consent. Write to support@zitrino.com and we will respond within 30 days. If your data is processed inside a client deployment, contact that organisation first, and we will support their response as processor.

9. Security

We hold ISO/IEC 27001 and SOC 2 Type II, encrypt data in transit and at rest, enforce least-privilege access with quarterly review, and test independently each year. Full detail, including our incident disclosure commitment, is published in the trust centre.

10. Changes and contact

We will post material changes to this page and, where the change affects an active client relationship, notify the named contact directly. For any privacy question, or to reach our data protection contact, write to support@zitrino.com.

This page is a plain-language policy for the Zitrino website and services. It is not legal advice, and where a signed data processing agreement exists with your organisation, that agreement takes precedence over anything written here.