Legal
Privacy Policy
Last updated: 14 July 2026
This Privacy Policy explains how ZIZKA AI S.L. ("ZIZKA AI", "we", "us") processes personal data when you use ZizkaDB at db.zizka.ai, our managed cloud service, documentation, and related websites. It is written to comply with the EU General Data Protection Regulation (GDPR) and applicable Spanish data protection law.
1. Data controller
ZIZKA AI S.L.
Málaga, Spain
CIF B26956078
Email: privacy@zizka.ai
For data protection enquiries or to exercise your rights, contact us at the address above. You may also contact founder@zizka.ai.
2. Scope of this policy
This policy applies to:
- Managed cloud — accounts, API keys, dashboards, and billing at db.zizka.ai
- Website and marketing — pages, forms, demo requests, and optional newsletter subscriptions
- Support and sales contact — email and contact forms
Self-hosted ZizkaDB (OSS): If you run ZizkaDB on your own infrastructure, you are the data controller for data stored in your instance. We do not access your self-hosted database unless you voluntarily share logs or contact support. Open-source downloads and local Docker usage on your machine are outside our control as controller.
3. Personal data we process
Depending on how you use ZizkaDB, we may process:
- Account data — email address, name (if provided), tenant and user identifiers, authentication tokens
- Billing data — subscription plan, payment status; card details are processed by our payment provider (we do not store full card numbers)
- Operational / agent data — events, agent names, session metadata, and payloads you log via the API or SDK (this may include personal data if you choose to log it)
- Technical data — IP address, browser type, device information, API request logs, error reports
- Communications — messages you send via contact or enterprise forms
- Cookie / local storage data — consent preferences and session identifiers (see Section 9)
- Optional telemetry — anonymous SDK install metrics (SDK type, version, OS, and coarse country derived from IP at ping time; we do not store raw IP in telemetry tables) if not disabled (
ZIZKADB_TELEMETRY=false) - Optional product updates — if you choose to subscribe on the dashboard, we store your email solely to send release and security notices; you may unsubscribe at any time
4. Purposes and legal bases (GDPR Art. 6)
- Provide the service (account, API, dashboard, support) — performance of a contract (Art. 6(1)(b))
- Billing and fraud prevention — performance of a contract and legitimate interests (Art. 6(1)(b), (f))
- Security, abuse prevention, and service reliability — legitimate interests (Art. 6(1)(f))
- Product improvement and aggregated analytics — legitimate interests, where not overridden by your rights (Art. 6(1)(f))
- Marketing communications (e.g. product updates you subscribe to) — consent (Art. 6(1)(a)); you may withdraw at any time
- Legal obligations — e.g. tax and accounting records (Art. 6(1)(c))
Where we rely on legitimate interests, we balance our interests against your rights. You may object to processing based on legitimate interests (see Section 8).
5. Agent and event data
ZizkaDB stores operational data about AI agents (events, causal links, embeddings for search, baselines). You control what is logged. Do not log special category data (health, biometrics, etc.) unless you have a lawful basis and appropriate safeguards. If you log personal data about third parties (e.g. end users of your agents), you are responsible for providing notice and obtaining any required consents.
6. Processors and sub-processors
We use carefully selected service providers who process data on our instructions under data processing agreements where required by GDPR:
- Cloud infrastructure — hosting in the EU where practicable
- Stripe — payment processing
- Email provider — transactional email (e.g. login OTP, billing notices)
- OpenAI (optional) — embeddings for semantic search when you configure an API key
We share only the minimum data necessary for each service. Sub-processors are bound by contractual obligations consistent with GDPR. A detailed list is available on request at privacy@zizka.ai.
7. International transfers
We prefer EU/EEA processing. Where data is transferred outside the EU/EEA (for example, to a sub-processor in the United States), we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and supplementary measures where required.
8. Your rights under GDPR
If you are in the EU/EEA (or where GDPR applies), you have the right to:
- Access — obtain a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion ("right to be forgotten"), subject to legal retention
- Restriction — limit processing in certain circumstances
- Data portability — receive data in a structured, machine-readable format where applicable
- Object — object to processing based on legitimate interests or direct marketing
- Withdraw consent — where processing is based on consent, without affecting prior lawful processing
To exercise these rights, email privacy@zizka.ai. We respond within one month, extendable where permitted by law. You may also lodge a complaint with the Spanish supervisory authority: Agencia Española de Protección de Datos (AEPD).
Managed cloud users can export or delete account-related data via dashboard settings where available, or by contacting us.
9. Cookies and similar technologies
We use cookies and local storage for:
- Strictly necessary — authentication, security, load balancing (no consent required)
- Preferences — cookie consent choice stored locally
- Analytics / improvement — only where you accept optional cookies via our banner
You can accept or decline non-essential cookies via the site banner. Declining does not block access to the service. You may clear cookies in your browser at any time.
10. Retention
- Account data — while your account is active, then deleted or anonymised within a reasonable period after closure (subject to legal holds)
- Agent events — according to your plan and settings; see retention documentation
- Billing records — as required by tax and commercial law (typically up to 6–10 years in Spain)
- Security logs — limited period for incident investigation (typically up to 90 days unless needed for legal claims)
11. Security
We implement appropriate technical and organisational measures including encryption in transit (TLS), access controls, tenant isolation, and regular backups for managed cloud. No method of transmission or storage is 100% secure; report suspected incidents to founder@zizka.ai. See also our security overview.
12. Children
ZizkaDB is a B2B developer product and is not directed at children under 16. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data and we will delete it.
13. Changes to this policy
We may update this policy to reflect legal, technical, or business changes. We will post the revised version on this page with an updated date. Material changes affecting managed cloud customers may be communicated by email or in-dashboard notice where appropriate.
14. Other ZIZKA AI products
This policy covers ZizkaDB and db.zizka.ai. Other products from ZIZKA AI S.L. (for example zizka.ai) may have separate or supplementary privacy information.
15. Contact
Data protection enquiries: privacy@zizka.ai
General contact: founder@zizka.ai
Enterprise: contact form