LEGAL · EFFECTIVE SEPTEMBER 25, 2026
Privacy Policy
This Privacy Policy explains how Aleksandra Reznik, an individual based in Montenegro operating zenvor.chat (“we,” “us,” or “our”), processes personal data when you visit, create an account, use the dashboard, or communicate through a zenvor.chat widget.
1. Our roles
We are the controller of account, service administration, support, and billing records. For visitor messages and data that a zenvor.chat customer collects through its widget, that customer normally decides why and how the data is used. In that context, the customer is the controller and we process the data on its behalf to provide the service. Visitors should also review the privacy notice of the website where the widget appears.
2. Data we process
- Account data: name, email address, password hash, verification state, workspace role, and session records.
- Workspace data: workspace and project settings, team invitations, allowed domains, widget configuration, and installation status.
- Support-chat data: messages, attachments, timestamps, read state, and assigned team member.
- Visitor context: a pseudonymous visitor identifier, embedding website, current page, initial referrer, browser, operating system, device type, and any name, email, or custom attributes supplied by the customer or visitor.
- Billing data: customer, transaction, subscription, payment status, and receipt-related identifiers received from Paddle. Complete card details are handled by Paddle and are not stored by zenvor.chat.
- Technical and support data: security events, request timing, error details that exclude message contents, and information you send when contacting support.
3. Why we use data
We process personal data to:
- create accounts and provide the service under our contract;
- authenticate users and protect accounts, visitors, and infrastructure;
- deliver support messages, attachments, realtime updates, and service emails;
- administer trials, subscriptions, payments, cancellations, and refunds;
- answer support requests and diagnose failures;
- comply with tax, accounting, sanctions, fraud-prevention, and legal duties;
- improve reliability based on limited, content-free operational measurements;
- understand how visitors find and use zenvor.chat, with consent where cookies are involved.
Depending on the context, our legal bases are performance of a contract, compliance with law, our legitimate interests in operating and securing the service, consent where required, and the customer’s instructions when we act as its processor.
4. Cookies and browser storage
The dashboard uses strictly necessary session and security cookies for sign-in and request protection. The widget stores a random visitor token in the browser’s local storage so the same visitor can return to their conversation. We do not use advertising cookies or behavioral advertising.
With your consent, the website and the dashboard set PostHog analytics cookies on zenvor.chat to measure visits, page depth, traffic sources, and sign-up and setup steps. If you decline, we count visits without cookies. Analytics never receives message contents, attachments, visitor data, names, email addresses, or URL query strings, and the widget on customer websites never loads analytics. You can change your choice by clearing cookies for zenvor.chat.
5. Service providers and disclosures
We disclose data only as needed to operate the service:
- Hetzner hosts the application and PostgreSQL database in Germany;
- Amazon Web Services provides private S3 object storage for attachments in its Frankfurt, Germany region and scans new attachments for malware;
- Resend delivers account and transactional emails;
- PostHog (EU Cloud) receives website and dashboard usage events and a pseudonymous account identifier for product analytics;
- Paddle acts as Merchant of Record and processes checkout and billing data; when a renewal payment fails, Paddle (Retain) retries it and emails the billing contact a link to update the payment method;
- Telegram delivers alerts: a visitor name and a short message excerpt to a team member who connects Telegram alerts, once a message stays unread for 60 seconds; and a new account’s name and email to us, the service operator;
- professional advisers, authorities, or counterparties may receive limited data when required by law or necessary to establish, exercise, or defend legal claims.
We do not sell personal data. We do not share it for cross-context behavioral advertising.
6. International transfers
Our providers may process data in countries other than yours. Where required, we use recognized safeguards for international transfers, such as adequacy decisions or standard contractual clauses. Paddle processes payment data under its own privacy notice as Merchant of Record.
Telegram alerts are ordinary Telegram cloud messages, not Secret Chats. Telegram may process and retain delivered copies under its own privacy terms, including outside your country.
7. Retention
Account, workspace, message, and visitor records are kept while the workspace is active and are deleted when the workspace is permanently deleted, subject to limited legal and security retention. Confirmed attachments expire after 90 days. Session credentials have bounded lifetimes; dashboard sessions normally expire after 30 days. Backups and cleanup queues may retain encrypted or isolated residual copies until their normal rotation completes.
Billing, tax, accounting, fraud-prevention, and dispute records may be retained for the period required by applicable law or reasonably needed to resolve a claim. We delete or anonymize data when it is no longer needed for the stated purpose.
A team member can pause or disconnect Telegram alerts in Settings. Disconnecting removes the local binding and pending deliveries, but it does not remove messages already delivered to Telegram.
8. Security
We use access controls, encrypted transport, password hashing, private object storage, short-lived file links, tenant separation, and bounded credentials. New attachments are checked for malware, and a file with a detected threat is deleted. No service can guarantee absolute security. Please report a suspected security issue to support@zenvor.chat.
9. Your choices and rights
Depending on your location and our role, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; and complain to a data-protection authority. Withdrawing consent does not affect processing already performed.
Account owners can update information and permanently delete a workspace in Settings. For other requests, email support@zenvor.chat. If your data came from a widget on another company’s website, contact that company first; we will assist it with verified requests when we act as processor. We may verify identity before completing a request.
10. Children
zenvor.chat is not directed to children under 18, and we do not knowingly create accounts for them. Contact us if you believe a child provided personal data unlawfully.
11. Changes and contact
We may update this policy and will publish the revised effective date.
For privacy questions or requests, contact:
Aleksandra Reznik, Montenegro
support@zenvor.chat