Privacy Policy
Last updated: 6 August 2026
1. Who We Are
Zenitro is an AI business diagnostics platform operated by Ascendz Digital Limited ("we", "us", "our"), a business owned by Toni Martin. Zenitro allows businesses ("Subscribers") to build, publish and share AI-powered diagnostics, quizzes and assessments, which their own audiences ("respondents") complete to receive a personalised, AI-generated result.
Our platform is accessible at app.zenitro.co. For privacy enquiries, contact us at: clientsupport@ascendz.co
1.1 Our Role: Controller and Processor
Our role under data protection law depends on the data in question:
- For the personal data of our Subscribers (your account, login and billing data), we act as the data controller, and this Privacy Policy governs how we handle it.
- For the personal data of your respondents that flows through your diagnostics (their answers, including free-text responses, and any lead capture details such as name and email), the Subscriber is the data controller and Zenitro acts as a data processor, processing that data only on the Subscriber's documented instructions in order to provide the service.
As a Subscriber, you are responsible for having a lawful basis to collect your respondents' data and for providing them with your own privacy notice. Our processing of respondent data on your behalf is governed by our data processing terms, available on request.
2. Data We Collect
2.1 Account and Subscriber Data
When you register for Zenitro, we collect your organisation name and email address. Passwords are handled by our authentication provider and stored only in hashed form. We also store your chosen subscription plan and billing information processed via Stripe (we do not store full payment card details).
2.2 Diagnostic and Knowledge Base Content
Content you create to build your diagnostics (including questions, answer options, scoring logic, report templates, brand assets and any documents you upload to a diagnostic's knowledge base) is stored on our servers and used solely to power your diagnostics and the reports they generate.
2.3 Response Data
When a respondent completes one of your diagnostics, we store their answers (multiple-choice selections, ratings and any free-text they enter), the scores and result calculated from those answers, the AI-generated report produced for them, timestamps, the campaign or link source, and any lead capture information (such as name and email) collected by your diagnostic. Generated reports are stored as fixed snapshots associated with your account.
2.4 AI Provider API Keys
You may provide your own third-party AI provider API keys (Anthropic, OpenAI, Google, xAI). These are stored encrypted and used solely to make API calls that generate reports and assist authoring on your behalf.
2.5 Usage and Analytics Data
We collect aggregate usage data including response counts, result distributions, per-category averages and wallet usage to display analytics within your dashboard, to enforce plan limits and to improve the platform.
3. How We Use Your Data
- To provide and operate the Zenitro platform and generate the reports your diagnostics produce
- To process subscription payments and wallet top-ups via Stripe
- To send service emails (account registration, password reset, account notifications)
- To display analytics in your dashboard
- To enforce plan limits and prevent abuse
- To comply with legal obligations
We do not sell your data or your respondents' data to any third party. We do not use your data for advertising purposes.
4. Data Sharing and Third Parties
We share data only as necessary to deliver the service:
- Supabase: database, file storage, authentication and serverless functions (EU region where available)
- Vercel: hosting for the web application
- Stripe: payment processing. Stripe's privacy policy applies to payment data
- Resend: delivery of service and result emails. Where an email is sent (your account notifications, a respondent's "your result is ready" email, new lead alerts), the recipient's email address, their name where they gave one, and the content of that email pass through Resend. Resend keeps a record of sent messages for delivery troubleshooting
- AI Providers: to generate a respondent's report, the relevant diagnostic content and that respondent's answers are sent to an AI provider (Anthropic, OpenAI, Google or xAI). This applies both to Zenitro's managed AI models and to any AI provider key you supply yourself. Your use of those providers is governed by their respective terms
- OpenAI, for finding the right part of your knowledge base: when you upload a document, we send its text to OpenAI to be indexed, and we send a summary of a respondent's answers there too when their report is generated. This is how we find the passages relevant to what someone actually said, rather than sending your whole document to the AI every time. It happens whichever AI provider you have chosen for your reports, because this particular capability is OpenAI's. OpenAI does not use data sent through its API to train its models
- Anthropic, for reading uploaded documents: when you upload a PDF to a diagnostic's knowledge base, the whole document is sent to Anthropic to extract its text, even if you have chosen a different AI provider for reports. We ask you to confirm this before the file is sent. Word, PowerPoint, Markdown and plain-text files are read on our own servers and are not sent to any AI provider
We do not sell your personal data, and we do not share it with third parties for their own marketing or advertising purposes.
4.1 International Data Transfers
Some of the providers above are located outside the United Kingdom and the European Economic Area (EEA), in particular the AI providers (Anthropic, OpenAI, Google and xAI) and our email provider (Resend), which are based in the United States. This includes the indexing of your knowledge base described above. This means that when your diagnostics generate reports, the relevant content is transferred to and processed in the United States.
Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards as required by UK GDPR and EU GDPR, which may include the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), together with the data protection terms offered by each provider. You may request more information about the specific safeguards applied by contacting us at clientsupport@ascendz.co.
5. Data Retention
We retain your account data for as long as your subscription is active. Response data and the reports generated from it are retained as part of your account records for as long as your account remains active, so that results stay available to you and to the respondents you have shared them with.
On account termination, your data is deleted within 30 days unless a longer retention period is required by law. This runs as a scheduled daily job rather than on request, and it removes database records and uploaded files alike. We keep a record that a deletion happened, containing no personal data. You may also request deletion of specific data at any time (see Your Rights below).
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of your data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data
- Portability: receive your data in a machine-readable format
- Objection: object to certain processing activities
- Restriction: request we limit processing of your data
To exercise any of these rights, email clientsupport@ascendz.co. We will respond within 30 days.
7. Security
We implement industry-standard security measures including encrypted data transmission (TLS/HTTPS), hashed passwords via our managed authentication provider, token-based authentication, strict per-account data isolation enforced by database row-level security, and standard browser security headers (including HTTP Strict Transport Security and an enforced Content Security Policy). Your AI provider API keys are encrypted at rest using AES-256-GCM and are not readable from the application, only by the servers that make the calls. Links to individual results carry a random, expiring token rather than a permanent identifier, and no such link is issued when the account has chosen to hide individual results. We conduct regular security reviews.
No system is completely secure. In the event of a data breach affecting your personal data, we will notify you in accordance with applicable law.
8. Cookies
The Zenitro platform uses only essential functional session tokens, stored in your browser's local storage, to keep you signed in. We do not use tracking, analytics or advertising cookies, so no cookie consent banner is required. If this changes in future, we will update this policy and seek consent where the law requires it.
9. Children's Privacy
Zenitro is intended for business use only and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify Subscribers of material changes by email or via an in-platform notice. Continued use of the platform after changes take effect constitutes acceptance of the updated policy.
11. Contact
For any privacy-related questions or requests:
Ascendz Digital Limited / Toni Martin Email: clientsupport@ascendz.co Platform: app.zenitro.co