Privacy Policy

Last updated: August 11, 2026

1. Introduction and Scope

Zenative, Inc. ("Zenative," "we," "us," or "our") builds AI agents that help companies automate customer interactions and business workflows. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with the zenative.ai website (the "Site") and our platform, applications, and related services (the "Services"). Zenative is a Delaware corporation with its principal place of business at 71 Stevenson Street, Suite 400, San Francisco, CA 94105, United States.

When this Policy applies — Zenative as a controller. This Policy applies where Zenative determines how and why personal information is processed (acting as a "controller" or "business"). This includes personal information about: visitors to our Site; prospective customers and people who contact us; individuals who register for, administer, or use customer accounts (such as names, work emails, and login details); and billing contacts.

When this Policy does not apply — Zenative as a processor. When customers submit data, documents, knowledge bases, prompts, or other content to the Services, or their end users interact with AI agents deployed by our customers ("Customer Content"), Zenative processes that information as a "processor" or "service provider" on the customer’s behalf and under the customer’s instructions, as set out in our Terms of Service and any applicable data processing addendum ("DPA"). The customer’s own privacy notice governs that processing. If you interact with an AI agent operated by one of our customers and have questions about how your information is handled, please contact that customer directly; where we receive requests concerning Customer Content, we will refer them to the relevant customer and provide reasonable assistance.

2. Information We Collect

We collect the following categories of personal information:

  • Contact and account information. Name, email address, phone number, company name and role, account credentials, and preferences, collected when you fill out a form, request a consultation, register for a trial, or create an account.
  • Billing information. Billing contact details, subscription plan, ZenCoin credit balances, and transaction history. Payment card and bank details are collected and processed directly by our payment processors (such as Stripe); we do not store full card numbers.
  • Usage and device information. IP address, browser type, device information, operating system, access times, pages viewed, referring URLs, and interactions with the Site and Services, collected automatically through logs and cookies.
  • Service interaction records. Support requests, correspondence with us, trial records, and administrative logs of platform activity (such as configuration changes and agent deployment events).
  • AI interaction logs (account level). Metadata about your account’s use of AI features, such as request volumes, feature usage, credit consumption, and error logs. The content your organization submits to the Services is Customer Content and is handled as described in Section 1 and Section 4.

We do not intentionally collect sensitive categories of personal information (such as health, biometric, or precise geolocation data) through the Site, and we ask that you not submit such information through our forms.

3. How We Use Information and Our Legal Bases

We use personal information for the purposes below. Where the EU or UK General Data Protection Regulation ("GDPR") applies, the corresponding legal basis is indicated.

Purpose
Providing the Site and Services
Examples
Verifying identity; completing form submissions, consultations, and registrations; operating accounts; processing payments and ZenCoin credits; providing support
GDPR legal basis
Performance of a contract; legitimate interests
Purpose
Customer support and communications
Examples
Providing AI-assisted and human support, automated replies, technical assistance, service notices
GDPR legal basis
Performance of a contract; legitimate interests
Purpose
Improving and securing the Site and Services
Examples
Analytics, debugging, monitoring, fraud and abuse prevention, quality assurance
GDPR legal basis
Legitimate interests; consent where required for cookies
Purpose
Marketing
Examples
Sending information about products, features, and events, with opt-out in every message
GDPR legal basis
Legitimate interests; consent where required
Purpose
Legal compliance
Examples
Complying with law, tax, and accounting obligations; responding to lawful requests; enforcing our terms
GDPR legal basis
Legal obligation; legitimate interests

4. AI, Customer Content, and Model Training

We do not use Customer Content to train or fine-tune artificial-intelligence or machine-learning models made available to other customers. We may create and use anonymized, de-identified, aggregated, or synthetic data derived from Customer Content — data that does not identify our customers or any individual — for platform improvement, quality assurance, benchmarking, and security. Where we de-identify data, we maintain and use it only in de-identified form and do not attempt to re-identify it, except as permitted by law to test the effectiveness of our de-identification processes.

Unless a customer selects a private cloud or on-premises deployment, Customer Content is hosted on Zenative-managed cloud infrastructure provided by Microsoft Azure or Amazon Web Services. Retention, export, and deletion of Customer Content are governed by our Terms of Service and applicable DPA, including a sixty (60) day post-termination export window.

5. How We Share Information

We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as follows:

  • Service providers and subprocessors. Vendors that host and support our infrastructure and operations, including Microsoft Azure and Amazon Web Services (cloud hosting), Stripe (payment processing), and providers of analytics, communications, and support tooling. They may process personal information only for the purposes for which we engage them.
  • Professional advisors. Lawyers, accountants, auditors, and insurers, where necessary.
  • Legal and safety. Where required by law or legal process, or where necessary to protect the rights, property, safety, or security of Zenative, our customers, or others.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of all or part of our business, subject to confidentiality protections.
  • With your direction or consent. Including integrations you or your organization choose to enable.

6. International Data Transfers

We are headquartered in the United States, and personal information we collect is processed in the United States and other countries where we or our service providers operate, which may not provide the same level of data protection as your home jurisdiction. Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to countries not recognized as providing an adequate level of protection, we rely on appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses (together with the UK International Data Transfer Addendum and Swiss adaptations, as applicable), which are incorporated into our DPA, along with supplementary technical and organizational measures. If Zenative certifies under the EU-U.S. Data Privacy Framework (or its UK or Swiss extensions) in the future, we may additionally rely on that framework for relevant transfers. You may request a copy of the relevant transfer safeguards by contacting us as set out below.

7. Data Retention

We retain personal information for as long as needed for the purposes described in this Policy: account and billing information for the life of the account and thereafter as required for tax, accounting, and legal purposes; site and usage logs for a limited operational period; and support correspondence for as long as relevant to the relationship. Customer Content is retained and deleted in accordance with our Terms of Service and applicable DPA, including deletion from production systems following the post-termination export window and purging from backups on our routine backup rotation cycle. When retention is no longer required, we delete or de-identify the information.

8. Security

We maintain industry-standard administrative, technical, and organizational safeguards designed to protect personal information, including encryption of data in transit, access controls, monitoring, and a security program aligned with recognized frameworks such as SOC 2. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; you are responsible for maintaining the confidentiality of your account credentials.

9. Your Privacy Rights

Subject to applicable law, you have the right to access, view, correct, download (data portability), or delete the personal data we hold about you, and to object to or request restriction of certain processing. Where processing is based on consent, you may withdraw consent at any time without affecting prior processing. You may opt out of marketing communications at any time via the unsubscribe link in each message or by contacting us.

If you are in the European Economic Area, the United Kingdom, or Switzerland, these rights arise under the GDPR and its UK and Swiss equivalents, and you also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office). We will respond to requests within the timeframes required by applicable law and may need to verify your identity before acting on a request. If we hold your information as a processor on behalf of a customer, we will refer your request to that customer and assist as required.

To exercise any of these rights, contact us at support@zenative.ai.

10. California Privacy Rights

This section applies to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"). In the preceding 12 months, we have collected the categories of personal information described in Section 2 (identifiers; commercial information; internet or other electronic network activity; professional or employment-related information; and inferences drawn for service operation), from the sources and for the purposes described in Sections 2 and 3, and disclosed them for business purposes to the categories of recipients described in Section 5.

We do not "sell" personal information and have not done so in the preceding 12 months, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined by the CCPA. We do not use or disclose sensitive personal information for purposes requiring a right to limit. California residents have the right to: know and access the personal information we collect; correct inaccurate personal information; delete personal information; and not receive discriminatory treatment for exercising these rights. You may exercise these rights by emailing support@zenative.ai; authorized agents may submit requests on your behalf with proof of authorization. We will verify requests using information associated with your account or interaction with us.

11. Cookies and Analytics

We use cookies and similar technologies to operate the Site, remember preferences, and understand how the Site and Services are used. These include: (a) essential cookies required for login, security, and core functionality; and (b) analytics cookies that help us measure and improve the Site and Services. We do not use advertising or retargeting cookies. You can control cookies through your browser settings, and where required by law we request consent before setting non-essential cookies. Disabling cookies may affect the availability and functionality of the Site.

12. Children’s Privacy

The Site and Services are intended for business users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us personal information, please contact us and we will delete it.

13. Third-Party Sites and Services

The Site and Services may contain links to, or interoperate with, third-party websites and services, including integrations your organization chooses to enable. This Policy does not apply to those third parties, and we encourage you to review their privacy policies.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version at zenative.ai/privacy and revise the "Last updated" date above; material changes may also be communicated by email or in-product notice. Your continued use of the Site or Services after an update constitutes acceptance of the revised Policy to the extent permitted by law.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, or wish to exercise your rights, contact us at:

Zenative, Inc. Attn: Privacy 71 Stevenson Street, Suite 400 San Francisco, CA 94105, United States Email: support@zenative.ai

Discover what Zenative can do for you

Start Now