Privacy Policy

Effective date: [DATE]  ·  Last updated: [DATE]

ZantIQ, Inc. ("ZantIQ," "we," "us," or "our") is committed to protecting the privacy and security of the data entrusted to us. This Privacy Policy explains what information we collect, how we use and protect it, with whom we share it, and your rights regarding it.

This policy applies to ZantIQ's contract intelligence platform, website (zantiq.ai), and related services ("Service"). It applies to business customers and their authorized users. If you are a ZantIQ employee or contractor, a separate internal privacy policy applies to your personal data.

Questions? Email us at [email protected].

Contents
  1. Information We Collect
  2. How We Use Your Information
  3. AI and Machine Learning Processing
  4. Subprocessors and Third-Party Service Providers
  5. Data Sharing and Disclosure
  6. International Data Transfers
  7. Data Retention
  8. Security
  9. Your Rights and Choices
  10. GDPR — EU/UK Customers
  11. California Privacy Rights (CCPA/CPRA)
  12. Children
  13. Cookies and Tracking
  14. Business Transfers
  15. Data Processing Agreement
  16. Changes to This Policy
  17. Contact Us

1. Information We Collect

We collect three categories of information when you use ZantIQ:

1.1 Information You Provide

1.2 Information from Connected Systems

When you connect a third-party system (Salesforce, HubSpot, Jira, Zendesk, Slack, or others), ZantIQ reads data from those systems as authorized by you to perform contract monitoring, obligation extraction, and breach detection. The specific data accessed depends on the connector and permissions you grant.

1.3 Information Collected Automatically

2. How We Use Your Information

PurposeData Used
Providing and operating the Service — contract extraction, obligation monitoring, connector sync, breach alerting Contract Data, Connector Data, Account Data
Billing and subscription management — processing payments, invoicing, managing renewals Billing Data, Account Data
Communications — service alerts, security notices, product updates, onboarding Email address, Account Data
Support — responding to questions, troubleshooting, investigating reported issues Account Data, Usage Data, Communications
Safety and security — detecting abuse, fraud, unauthorized access, and policy violations Usage Data, Technical Data, Account Data
Product improvement — analyzing aggregated, anonymized usage trends to improve features Anonymized Usage Data only (no Contract Data)
Legal compliance — fulfilling legal obligations, responding to lawful requests As required by applicable law

We do not use Contract Data for product improvement, model training, or any purpose beyond delivering the Service to you. We do not sell personal data to third parties.

3. AI and Machine Learning Processing

How AI processes your contract data ZantIQ uses Google Cloud's Vertex AI infrastructure and the Gemini family of AI models to extract structured obligations, identify terms, and generate Outputs from your Contract Data. This is the core of what the Service does, and by using ZantIQ you consent to this processing as a necessary part of service delivery.

3.1 What We Use AI For

3.2 No Training on Customer Data

ZantIQ does not use Customer Data to train, fine-tune, or improve any AI model — ours or any third party's. Specifically:

3.3 Model Versions

ZantIQ currently uses Google Gemini 2.0 Flash (gemini-2.0-flash-001) for extraction and text-embedding-005 for semantic search embeddings. We may update model versions as improved versions become available; material changes will be disclosed in our product changelog.

3.4 Human Review

ZantIQ employees or contractors may access Customer Data in limited circumstances: (a) with Customer's permission for support troubleshooting; (b) to investigate a security incident; or (c) as required by law. Access is logged, role-restricted, and subject to confidentiality obligations.

4. Subprocessors and Third-Party Service Providers

ZantIQ uses the following categories of subprocessors to deliver the Service. All subprocessors are bound by data processing agreements that require them to maintain appropriate security and process data only on ZantIQ's instructions.

SubprocessorFunctionLocation
Google Cloud PlatformCloud infrastructure, databases, object storage, and AI processing (Vertex AI / Gemini)United States (with EU option for Enterprise)
StripePayment processing and subscription billingUnited States
[Email provider — e.g., SendGrid / Postmark]Transactional email delivery (alerts, invoices, notifications)United States
[Analytics — e.g., PostHog / Plausible]Privacy-preserving product analytics[Location]
[Error tracking — e.g., Sentry]Application error monitoring and debuggingUnited States
[Support — e.g., Intercom / Linear]Customer support and ticket managementUnited States

Subprocessor updates. We will post updates to this list at zantiq.ai/legal/subprocessors at least thirty (30) days before adding a new subprocessor that processes personal data. Enterprise customers subscribed to subprocessor notification updates may object to new subprocessors within that window.

5. Data Sharing and Disclosure

We share data only in the following circumstances:

5.1 Service Delivery

With Connectors you authorize (Salesforce, HubSpot, Jira, Zendesk, etc.): ZantIQ reads from and writes to those systems as necessary to provide the Service features you configure.

5.2 Subprocessors

With the vetted subprocessors listed in Section 4, solely to perform their designated functions.

5.3 Legal Requirements

If required by applicable law, valid legal process (subpoena, court order, regulatory demand), or to protect ZantIQ's rights or the safety of our users. We will notify you to the extent legally permitted before complying with any such request and will limit disclosure to what is legally required.

5.4 Business Transfers

In connection with a merger, acquisition, or sale of substantially all of ZantIQ's assets, your data may be transferred to the successor entity. We will provide notice and, where required by law, seek consent before completing any such transfer. See also Section 14.

5.5 With Your Consent

For any other purpose with your explicit prior consent.

5.6 No Sale of Data

ZantIQ does not sell, rent, or broker personal data to data brokers, advertisers, or other third parties for their own commercial purposes.

6. International Data Transfers

ZantIQ is headquartered in the United States and processes data on Google Cloud Platform in U.S.-based data centers by default. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data is transferred to the United States.

We transfer data internationally under the following safeguards:

EU data residency. Enterprise customers may request EU data residency, which keeps Contract Data and processing within Google Cloud's European regions. Contact [email protected] to configure this option.

7. Data Retention

Data TypeRetention Period
Account informationDuration of subscription + 90 days post-termination (to support account recovery)
Contract Data and OutputsDuration of subscription; available for 30-day export window post-termination; deleted within 60 days of that window closing
Connector Data (read/synced)Duration of subscription; purged within 60 days of connector disconnection or subscription termination
Billing records7 years (tax and financial compliance)
Usage and technical logs90 days (operational), then aggregated/anonymized
Support communications3 years
Legal holdAs required by applicable legal obligation

Enterprise customers may configure custom retention periods for Contract Data. Data on legal hold is securely isolated and deleted as soon as the hold is lifted.

8. Security

ZantIQ implements technical, administrative, and physical safeguards designed to protect your data:

No security measure is perfect. We encourage customers to use strong passwords, enable SSO/MFA where available, and promptly report any suspected security issues to [email protected].

9. Your Rights and Choices

Regardless of your location, you may:

To exercise any privacy right, email [email protected] with "Privacy Request" in the subject. We respond within 30 days (or as required by applicable law). We may ask you to verify your identity before processing the request.

10. GDPR — EU/UK Customers

10.1 Controller vs. Processor

When ZantIQ processes personal data contained in Customer's contracts (e.g., names or contact details of counterparties), ZantIQ acts as a data processor on behalf of Customer (the data controller). ZantIQ acts as a data controller with respect to Account data, billing data, and usage data it collects for its own operational purposes.

10.2 Lawful Basis for Processing

Processing ActivityLawful Basis
Providing the Service (contract extraction, alerting, sync)Performance of contract (Art. 6(1)(b))
Billing and payment processingPerformance of contract (Art. 6(1)(b))
Security monitoring and fraud preventionLegitimate interests (Art. 6(1)(f))
Product analytics (aggregated, anonymized)Legitimate interests (Art. 6(1)(f))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))
Marketing communicationsConsent (Art. 6(1)(a)) or Legitimate interests (opt-out available)

10.3 GDPR Data Subject Rights

If you are located in the EEA, UK, or Switzerland, you have the right to: access your personal data; rectify inaccurate data; erase data ("right to be forgotten") subject to applicable exceptions; restrict or object to processing; data portability; and withdraw consent (where processing is consent-based). You also have the right to lodge a complaint with your local supervisory authority.

10.4 Data Protection Officer

ZantIQ has designated a data protection point of contact reachable at [email protected]. [Note: formal DPO appointment required if ZantIQ meets Art. 37 thresholds — to be assessed by counsel.]

11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA grants you additional rights.

11.1 Categories of Personal Information Collected

In the past 12 months, ZantIQ has collected the following categories of personal information as defined by the CCPA: identifiers (name, email, IP address), commercial information (subscription and billing records), internet or other electronic network activity information (usage logs), and professional or employment-related information (company and job title provided at signup).

11.2 Sources and Business Purposes

Collected directly from you, from connected third-party systems you authorize, and automatically through the Service. Used for the business purposes described in Section 2.

11.3 No Sale or Sharing of Personal Information

ZantIQ does not sell personal information. ZantIQ does not share personal information with third parties for cross-context behavioral advertising. You therefore have the right to know that we do not engage in these activities, and no opt-out is required.

11.4 California Rights

California residents may request: (a) the categories and specific pieces of personal information ZantIQ has collected; (b) disclosure of data sharing practices; (c) deletion of personal information (subject to legal exceptions); and (d) correction of inaccurate personal information. ZantIQ will not discriminate against you for exercising these rights.

Submit California privacy requests to [email protected] with "California Privacy Request" in the subject. We respond within 45 days (with a possible 45-day extension for complex requests).

12. Children

The Service is designed for business use and is not directed at individuals under the age of 18 (or the applicable age of digital consent in their jurisdiction). We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from a minor, contact us at [email protected] and we will delete it promptly.

13. Cookies and Tracking

13.1 Cookies We Use

CategoryPurposeCan opt out?
Strictly necessaryAuthentication, session management, CSRF protection, load balancingNo — required for the Service to function
AnalyticsAggregate usage metrics (page views, feature adoption); privacy-preserving; no cross-site trackingYes — via cookie preferences banner

ZantIQ does not use third-party advertising cookies, tracking pixels, or fingerprinting technologies. We do not participate in cross-site behavioral advertising networks.

13.2 Managing Cookies

Use our cookie preferences banner (accessible via the "Cookie Settings" link in the site footer) to manage analytics cookies. You may also configure your browser to block or delete cookies; note that blocking strictly necessary cookies will impair the Service's functionality.

14. Business Transfers

If ZantIQ is acquired by or merged with another company, or if substantially all of its assets are transferred, your personal data may be transferred as part of that transaction. In such an event, we will: (a) provide at least 30 days' prior notice to affected customers; (b) ensure the acquiring entity is bound by privacy obligations at least as protective as this policy; and (c) give you the opportunity to export and delete your data before the transfer if you object. Your data will not be used by the acquiring entity for purposes materially different from those described here without your consent.

15. Data Processing Agreement

For customers subject to GDPR (or equivalent data protection law), ZantIQ offers a Data Processing Agreement (DPA) that governs ZantIQ's processing of personal data on your behalf as a data processor. The DPA includes the EU Standard Contractual Clauses where applicable.

Our standard Data Processing Agreement is available at zantiq.ai/legal/dpa. To execute a signed copy, email [email protected] with subject "DPA Request — [Company Name]." Enterprise customers may negotiate custom DPA terms. The DPA is incorporated by reference into the Terms of Service upon execution.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will provide at least 30 days' prior notice of material changes via email to the Account's primary contact and via a banner in the Service. We will maintain an archive of prior versions at zantiq.ai/legal/privacy-history.

Continued use of the Service after the effective date of a revised policy constitutes acceptance of the updated terms. If you object to a material change, you may terminate your subscription as described in the Terms of Service and export your data during the applicable export window.

17. Contact Us

For privacy inquiries, rights requests, or to request our DPA:

We respond to all privacy requests within 30 days.

If you are in the EU/UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

© 2026 ZantIQ, Inc. · Privacy Policy · Terms of Service · Cookie Settings