ZantIQ, Inc. ("ZantIQ," "we," "us," or "our") is committed to protecting the privacy and security of the data entrusted to us. This Privacy Policy explains what information we collect, how we use and protect it, with whom we share it, and your rights regarding it.
This policy applies to ZantIQ's contract intelligence platform, website (zantiq.ai), and related services ("Service"). It applies to business customers and their authorized users. If you are a ZantIQ employee or contractor, a separate internal privacy policy applies to your personal data.
Questions? Email us at [email protected].
We collect three categories of information when you use ZantIQ:
When you connect a third-party system (Salesforce, HubSpot, Jira, Zendesk, Slack, or others), ZantIQ reads data from those systems as authorized by you to perform contract monitoring, obligation extraction, and breach detection. The specific data accessed depends on the connector and permissions you grant.
| Purpose | Data Used |
|---|---|
| Providing and operating the Service — contract extraction, obligation monitoring, connector sync, breach alerting | Contract Data, Connector Data, Account Data |
| Billing and subscription management — processing payments, invoicing, managing renewals | Billing Data, Account Data |
| Communications — service alerts, security notices, product updates, onboarding | Email address, Account Data |
| Support — responding to questions, troubleshooting, investigating reported issues | Account Data, Usage Data, Communications |
| Safety and security — detecting abuse, fraud, unauthorized access, and policy violations | Usage Data, Technical Data, Account Data |
| Product improvement — analyzing aggregated, anonymized usage trends to improve features | Anonymized Usage Data only (no Contract Data) |
| Legal compliance — fulfilling legal obligations, responding to lawful requests | As required by applicable law |
We do not use Contract Data for product improvement, model training, or any purpose beyond delivering the Service to you. We do not sell personal data to third parties.
ZantIQ does not use Customer Data to train, fine-tune, or improve any AI model — ours or any third party's. Specifically:
ZantIQ currently uses Google Gemini 2.0 Flash (gemini-2.0-flash-001) for extraction and text-embedding-005 for semantic search embeddings. We may update model versions as improved versions become available; material changes will be disclosed in our product changelog.
ZantIQ employees or contractors may access Customer Data in limited circumstances: (a) with Customer's permission for support troubleshooting; (b) to investigate a security incident; or (c) as required by law. Access is logged, role-restricted, and subject to confidentiality obligations.
ZantIQ uses the following categories of subprocessors to deliver the Service. All subprocessors are bound by data processing agreements that require them to maintain appropriate security and process data only on ZantIQ's instructions.
| Subprocessor | Function | Location |
|---|---|---|
| Google Cloud Platform | Cloud infrastructure, databases, object storage, and AI processing (Vertex AI / Gemini) | United States (with EU option for Enterprise) |
| Stripe | Payment processing and subscription billing | United States |
| [Email provider — e.g., SendGrid / Postmark] | Transactional email delivery (alerts, invoices, notifications) | United States |
| [Analytics — e.g., PostHog / Plausible] | Privacy-preserving product analytics | [Location] |
| [Error tracking — e.g., Sentry] | Application error monitoring and debugging | United States |
| [Support — e.g., Intercom / Linear] | Customer support and ticket management | United States |
Subprocessor updates. We will post updates to this list at zantiq.ai/legal/subprocessors at least thirty (30) days before adding a new subprocessor that processes personal data. Enterprise customers subscribed to subprocessor notification updates may object to new subprocessors within that window.
We share data only in the following circumstances:
With Connectors you authorize (Salesforce, HubSpot, Jira, Zendesk, etc.): ZantIQ reads from and writes to those systems as necessary to provide the Service features you configure.
With the vetted subprocessors listed in Section 4, solely to perform their designated functions.
If required by applicable law, valid legal process (subpoena, court order, regulatory demand), or to protect ZantIQ's rights or the safety of our users. We will notify you to the extent legally permitted before complying with any such request and will limit disclosure to what is legally required.
In connection with a merger, acquisition, or sale of substantially all of ZantIQ's assets, your data may be transferred to the successor entity. We will provide notice and, where required by law, seek consent before completing any such transfer. See also Section 14.
For any other purpose with your explicit prior consent.
ZantIQ does not sell, rent, or broker personal data to data brokers, advertisers, or other third parties for their own commercial purposes.
ZantIQ is headquartered in the United States and processes data on Google Cloud Platform in U.S.-based data centers by default. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data is transferred to the United States.
We transfer data internationally under the following safeguards:
EU data residency. Enterprise customers may request EU data residency, which keeps Contract Data and processing within Google Cloud's European regions. Contact [email protected] to configure this option.
| Data Type | Retention Period |
|---|---|
| Account information | Duration of subscription + 90 days post-termination (to support account recovery) |
| Contract Data and Outputs | Duration of subscription; available for 30-day export window post-termination; deleted within 60 days of that window closing |
| Connector Data (read/synced) | Duration of subscription; purged within 60 days of connector disconnection or subscription termination |
| Billing records | 7 years (tax and financial compliance) |
| Usage and technical logs | 90 days (operational), then aggregated/anonymized |
| Support communications | 3 years |
| Legal hold | As required by applicable legal obligation |
Enterprise customers may configure custom retention periods for Contract Data. Data on legal hold is securely isolated and deleted as soon as the hold is lifted.
ZantIQ implements technical, administrative, and physical safeguards designed to protect your data:
No security measure is perfect. We encourage customers to use strong passwords, enable SSO/MFA where available, and promptly report any suspected security issues to [email protected].
Regardless of your location, you may:
To exercise any privacy right, email [email protected] with "Privacy Request" in the subject. We respond within 30 days (or as required by applicable law). We may ask you to verify your identity before processing the request.
When ZantIQ processes personal data contained in Customer's contracts (e.g., names or contact details of counterparties), ZantIQ acts as a data processor on behalf of Customer (the data controller). ZantIQ acts as a data controller with respect to Account data, billing data, and usage data it collects for its own operational purposes.
| Processing Activity | Lawful Basis |
|---|---|
| Providing the Service (contract extraction, alerting, sync) | Performance of contract (Art. 6(1)(b)) |
| Billing and payment processing | Performance of contract (Art. 6(1)(b)) |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Product analytics (aggregated, anonymized) | Legitimate interests (Art. 6(1)(f)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Marketing communications | Consent (Art. 6(1)(a)) or Legitimate interests (opt-out available) |
If you are located in the EEA, UK, or Switzerland, you have the right to: access your personal data; rectify inaccurate data; erase data ("right to be forgotten") subject to applicable exceptions; restrict or object to processing; data portability; and withdraw consent (where processing is consent-based). You also have the right to lodge a complaint with your local supervisory authority.
ZantIQ has designated a data protection point of contact reachable at [email protected]. [Note: formal DPO appointment required if ZantIQ meets Art. 37 thresholds — to be assessed by counsel.]
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA grants you additional rights.
In the past 12 months, ZantIQ has collected the following categories of personal information as defined by the CCPA: identifiers (name, email, IP address), commercial information (subscription and billing records), internet or other electronic network activity information (usage logs), and professional or employment-related information (company and job title provided at signup).
Collected directly from you, from connected third-party systems you authorize, and automatically through the Service. Used for the business purposes described in Section 2.
ZantIQ does not sell personal information. ZantIQ does not share personal information with third parties for cross-context behavioral advertising. You therefore have the right to know that we do not engage in these activities, and no opt-out is required.
California residents may request: (a) the categories and specific pieces of personal information ZantIQ has collected; (b) disclosure of data sharing practices; (c) deletion of personal information (subject to legal exceptions); and (d) correction of inaccurate personal information. ZantIQ will not discriminate against you for exercising these rights.
Submit California privacy requests to [email protected] with "California Privacy Request" in the subject. We respond within 45 days (with a possible 45-day extension for complex requests).
The Service is designed for business use and is not directed at individuals under the age of 18 (or the applicable age of digital consent in their jurisdiction). We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from a minor, contact us at [email protected] and we will delete it promptly.
| Category | Purpose | Can opt out? |
|---|---|---|
| Strictly necessary | Authentication, session management, CSRF protection, load balancing | No — required for the Service to function |
| Analytics | Aggregate usage metrics (page views, feature adoption); privacy-preserving; no cross-site tracking | Yes — via cookie preferences banner |
ZantIQ does not use third-party advertising cookies, tracking pixels, or fingerprinting technologies. We do not participate in cross-site behavioral advertising networks.
Use our cookie preferences banner (accessible via the "Cookie Settings" link in the site footer) to manage analytics cookies. You may also configure your browser to block or delete cookies; note that blocking strictly necessary cookies will impair the Service's functionality.
If ZantIQ is acquired by or merged with another company, or if substantially all of its assets are transferred, your personal data may be transferred as part of that transaction. In such an event, we will: (a) provide at least 30 days' prior notice to affected customers; (b) ensure the acquiring entity is bound by privacy obligations at least as protective as this policy; and (c) give you the opportunity to export and delete your data before the transfer if you object. Your data will not be used by the acquiring entity for purposes materially different from those described here without your consent.
For customers subject to GDPR (or equivalent data protection law), ZantIQ offers a Data Processing Agreement (DPA) that governs ZantIQ's processing of personal data on your behalf as a data processor. The DPA includes the EU Standard Contractual Clauses where applicable.
Our standard Data Processing Agreement is available at zantiq.ai/legal/dpa. To execute a signed copy, email [email protected] with subject "DPA Request — [Company Name]." Enterprise customers may negotiate custom DPA terms. The DPA is incorporated by reference into the Terms of Service upon execution.
We may update this Privacy Policy from time to time. We will provide at least 30 days' prior notice of material changes via email to the Account's primary contact and via a banner in the Service. We will maintain an archive of prior versions at zantiq.ai/legal/privacy-history.
Continued use of the Service after the effective date of a revised policy constitutes acceptance of the updated terms. If you object to a material change, you may terminate your subscription as described in the Terms of Service and export your data during the applicable export window.
For privacy inquiries, rights requests, or to request our DPA:
We respond to all privacy requests within 30 days.
If you are in the EU/UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
© 2026 ZantIQ, Inc. · Privacy Policy · Terms of Service · Cookie Settings