Free5 minutesbeginner

Third-Party Data Sharing

Understand how Zenovay handles data sharing with third parties and sub-processors.

third-partydata-sharingsubprocessorsprivacycompliance
Last updated: January 15, 2025

Understand Zenovay's data sharing practices, sub-processors, and your control over third-party access.

Our Data Sharing Principles

What We Don't Do

Zenovay commits to:

PracticeOur Policy
Sell personal dataNever
Share for advertisingNever
Cross-site trackingNever
Data broker transfersNever
Unauthorized accessNever

What We Do

We share data only for:

  • Service delivery (hosting, processing)
  • Customer support (your request)
  • Legal compliance (when required)

Sub-Processors

Current Sub-Processors

ProviderPurposeData Center
CloudflareCDN, DDoS protectionGlobal
AWSData storageEU/US
HetznerEU data residencyGermany
PostmarkEmail notificationsUS
StripePayment processingUS

Sub-Processor Details

Cloudflare

  • Purpose: Script delivery, edge caching
  • Data: HTTP requests, IP addresses (transient)
  • DPA: Yes
  • Privacy: cloudflare.com/privacy

Amazon Web Services (AWS)

  • Purpose: Database hosting, file storage
  • Data: All analytics data
  • DPA: Yes
  • Region: eu-west-1 (Ireland) or us-east-1
  • Privacy: aws.amazon.com/privacy

Hetzner

  • Purpose: EU-only data residency option
  • Data: Analytics data (Enterprise EU)
  • DPA: Yes
  • Region: Germany only
  • Privacy: hetzner.com/privacy

Sub-Processor Updates

We notify customers of changes:

  • 30 days before new sub-processor
  • Email notification to account owners
  • Option to object (Enterprise)

Subscribe to updates:

  1. Go to SettingsNotifications
  2. Enable Sub-processor Updates

Data Access Control

Who Can Access Your Data

RoleAccess Level
Your teamFull (per permissions)
Zenovay supportOn request only
Sub-processorsTechnical only
Third partiesNever

Support Access

Zenovay support can only access your data when:

  • You explicitly request help
  • You grant temporary access
  • Investigation of security incident

Enable/disable support access:

  1. Go to SettingsSecurity
  2. Toggle Allow Support Access
  3. Set expiry if enabled

Audit Logs

View all data access:

  1. Go to SettingsAudit Log
  2. Filter by access type
  3. See who accessed what, when

Data Processing Agreement

DPA Contents

Our DPA covers:

  • Subject matter and duration
  • Nature and purpose of processing
  • Types of personal data
  • Data subject categories
  • Your rights as controller
  • Our obligations as processor
  • Sub-processor requirements
  • Security measures
  • Data breach procedures
  • Audit rights
  • Data return/deletion

Signing the DPA

  1. Go to SettingsLegal
  2. Click Data Processing Agreement
  3. Review terms
  4. Sign electronically
  5. Download signed copy

Standard Contractual Clauses

For international transfers, we use:

  • EU Standard Contractual Clauses (2021)
  • UK International Data Transfer Agreement
  • Swiss Standard Contractual Clauses

Included in our DPA.

No Data Selling

CCPA Compliance

Under CCPA "sale" definition:

  • We do not sell personal information
  • We do not share for cross-context advertising
  • We act as a service provider

Advertising Networks

We never share data with:

  • Google Ads
  • Facebook Ads
  • Any advertising network
  • Retargeting services
  • Data brokers

Customer Data Isolation

Multi-Tenant Architecture

Your data is isolated:

Zenovay Infrastructure
├── Customer A Data (encrypted, isolated)
├── Customer B Data (encrypted, isolated)
└── Customer C Data (encrypted, isolated)

Each customer's data:

  • Encrypted at rest
  • Encrypted in transit
  • Logically separated
  • Access controlled

No Cross-Customer Access

  • Customers cannot see each other's data
  • Analytics are not combined
  • No shared identifiers

Integration Data Sharing

When You Connect Integrations

If you connect third-party services:

IntegrationData SharedPurpose
SlackAlert messagesNotifications
ZapierEvent dataAutomation
WebhooksEvent payloadsCustom

You control what's shared:

  1. Go to SettingsIntegrations
  2. Select integration
  3. Configure data fields
  4. Enable/disable sharing

API Access

When you use our API:

  • You control data flow
  • Your responsibility after export
  • We log API access

Compliance Reports

SOC 2 Report

Available to Enterprise customers:

  • Type II certification
  • Annual renewal
  • Security controls verified

Request via SettingsSecurityCompliance.

GDPR Compliance

We maintain:

  • Records of processing
  • DPAs with sub-processors
  • Data breach procedures
  • Regular security audits

Transparency Report

Annual report includes:

  • Government requests received
  • Data disclosed (if any)
  • Sub-processor changes
  • Security incidents

Your Rights

Restrict Sharing

You can:

  • Disable support access
  • Use EU-only data residency
  • Disable integrations
  • Export and delete data

Data Portability

Export your data anytime:

  • JSON or CSV format
  • Full data export
  • Machine-readable

See Data Export.

Account Deletion

Delete all data:

  1. Go to SettingsAccount
  2. Click Delete Account
  3. All data permanently removed
  4. No backups retained

Privacy Policy Requirements

Your Disclosure

Include in your privacy policy:

## Third-Party Analytics

We use Zenovay for website analytics. Zenovay:
- Processes visitor data on our behalf
- Does not sell personal data
- Does not share with advertisers
- Uses sub-processors for hosting and delivery

For more information, see Zenovay's privacy policy
at [zenovay.com/privacy](https://zenovay.com/privacy).

Direct users to:

Questions and Contact

Privacy Questions

Contact our DPO:

Data Subject Requests

For visitor requests:

  • You handle as the controller
  • We assist as the processor
  • API available for erasure/export

Security Concerns

Report to:

Best Practices

Regular Review

  • Check sub-processor list quarterly
  • Review integration permissions
  • Audit team access
  • Update privacy policy

Documentation

Maintain records of:

  • DPA signing date
  • Sub-processor acknowledgments
  • Integration configurations
  • Access control settings

Communication

  • Inform users of analytics use
  • Respond to inquiries promptly
  • Update policies when changes occur

Next Steps

Was this article helpful?