Home/Privacy Policy
Privacy Policy
How Smartintent AI Solutions Private Limited, trading as Zenius QA, collects, uses, shares and protects personal data — on this website, in our platform, and in the course of our services — and the rights you have under the GDPR, the UK GDPR, US state privacy laws including the California CCPA/CPRA, and India's Digital Personal Data Protection Act, 2023.
1. Who we are
The controller of personal data described in this policy is Smartintent AI Solutions Private Limited, a company incorporated in India, trading as Zenius QA ("Zenius", "we", "us"). Registered office: T-18, Plot No. 9B & 9C, Cross River Mall, Shahdara, Delhi 110032, India. US office: 221 Camille St, Leander, TX 78641, USA.
Our Data Protection Officer — who is also our Grievance Officer for the purposes of India's Digital Personal Data Protection Act, 2023 and Rules, 2025 — is Rahul, reachable at rahul@zenius.ai or by post at the Delhi address above.
2. What this policy covers
This policy applies to personal data we process as a controller: visitors to this website, people who contact us or request a coverage map, call or trial, users of the Zenius platform's self-serve accounts, and the business contacts of our customers, prospects, partners and suppliers.
When we deliver testing services or run the platform on a customer's systems, we process data on that customer's behalf as a processor. That processing — source code, test environments, test evidence such as videos and traces, and any personal data they may contain — is governed by our Data Processing Addendum and the customer's own privacy notice, not by this policy.
3. Data we collect
3.1 Data you give us
- Enquiries and requests — name, work email address, company, role, the product URL you ask us to map, your peak and release cadence, and anything you write in a message.
- Platform accounts — name, work email, company, authentication details, and the metadata of repositories you connect (names, branches, pull-request titles and acceptance criteria) so that the Zenius agent can generate and run tests.
- Contracting and billing — names and contact details of signatories and billing contacts, purchase orders, invoices and payment status. We do not store card numbers.
- Correspondence — emails, meeting notes, support messages and call summaries.
3.2 Data collected automatically
- Server logs kept by our hosting provider — IP address, browser type, pages requested, timestamps and referring page — used for security and to keep the site running.
- Analytics — only if analytics is enabled on this site and you accept it in the cookie banner: aggregated page views and events, with IP addresses truncated. See the Cookie Policy.
- Platform usage — actions taken in the platform, run results and error logs, used to operate and improve the service.
3.3 Data from other sources
When preparing a proposal or a coverage map we may look up publicly available business information about your company and role — for example your company website or professional profile — and receive your details from a colleague or partner who referred you.
We do not collect special categories of personal data (such as health, religion or biometric data) and do not ask you for them.
4. Why we use it and our legal bases
| Purpose | Data | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Responding to your enquiry, preparing a coverage map, proposal or pilot | Enquiries, correspondence, public business information | Steps at your request before entering a contract (Art. 6(1)(b)); our legitimate interest in responding to business enquiries (Art. 6(1)(f)) |
| Providing the platform and delivering services under contract | Platform accounts, repository metadata, usage, contracting data | Performance of a contract (Art. 6(1)(b)) |
| Billing, accounting and tax | Contracting and billing data | Legal obligation (Art. 6(1)(c)); performance of a contract |
| Keeping the website and platform secure, preventing abuse | Server logs, platform usage | Legitimate interest in security (Art. 6(1)(f)) |
| Understanding how the website is used | Analytics data | Your consent (Art. 6(1)(a)), given through the cookie banner and withdrawable at any time |
| Telling existing customers and people who asked about relevant services | Business contact details | Legitimate interest in business-to-business communication (Art. 6(1)(f)), with an opt-out in every message; consent where local law requires it |
| Establishing, exercising or defending legal claims; complying with law | Any of the above, as relevant | Legitimate interest (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
We do not use personal data for automated decision-making that produces legal or similarly significant effects, and we do not sell personal data.
5. Who we share it with
- Affiliates under common ownership, if any, where they help deliver an engagement or provide shared business functions, under the same obligations as us.
- Service providers acting on our instructions under contract: web hosting, email and productivity tools, cloud infrastructure for the platform and evidence storage, form processing and analytics (where enabled), accounting and e-signature tools. A current list of the providers that process customer data is available in the sub-processor notice.
- Professional advisers — lawyers, accountants, auditors and insurers — where necessary.
- Authorities and courts where required by law, or to protect our rights, our customers or the public.
- A buyer or successor in the event of a merger, acquisition or sale of assets, under confidentiality and on the same terms as this policy.
We do not sell personal data and we do not share it for cross-context behavioural advertising.
6. International transfers
We are based in India with an office in the United States, and our service providers operate in India, the United States and the European Union. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data will be transferred outside those territories. We protect such transfers with the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), the UK International Data Transfer Addendum, and supplementary measures including encryption in transit and at rest and access limited to named staff. You can ask for a copy of the relevant clauses by contacting the Data Protection Officer.
7. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not lead to a contract | 24 months from our last contact with you, then deleted |
| Customer, contracting and billing records | Duration of the relationship plus the period required by tax and company law (up to 8 years in India) |
| Platform accounts | Until you delete the account or 12 months of inactivity, then removed within 30 days |
| Test evidence processed for customers | 90 days by default under the DPA; configurable; deleted on request |
| Server logs | 12 months |
| Analytics (if enabled and accepted) | 14 months |
8. Security
We apply technical and organisational measures appropriate to the risk: multi-factor authentication and least-privilege, named access; encryption in transit (TLS 1.2+) and at rest; secrets kept in vaults rather than documents; peer review and dependency scanning for the platform; patching targets; logging of access to evidence; confidentiality obligations and security training for all staff; and a documented incident-response process. If a breach affects your personal data, we will notify you and any competent authority as required by law — within 72 hours for the GDPR and without delay under India's DPDP Rules. Details are on the Security & trust page.
9. Your rights — EEA, UK and Switzerland
You have the right to access the personal data we hold about you; to have it rectified if inaccurate; to have it erased in certain circumstances; to restrict processing; to receive the data you provided in a portable format (portability); to object to processing based on legitimate interests, including direct marketing at any time; and to withdraw consent where processing is based on consent, without affecting processing before the withdrawal. To exercise a right, email the Data Protection Officer at rahul@zenius.ai. We respond within one month, extendable by two months for complex requests, and may ask you to verify your identity. You may also lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, the authority of your member state.
10. Your rights — California and other US states
This section supplements the rest of the policy for residents of California and of other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others). Zenius is a business-to-business service; we process the personal information of individuals mainly in their professional capacity.
10.1 Categories of personal information (CCPA/CPRA)
| Category | Collected | Source | Purpose | Disclosed to | Sold or shared |
|---|---|---|---|---|---|
| Identifiers (name, email, IP address) | Yes | You; your device | Respond, provide services, security | Service providers, affiliates | No |
| Customer records (company, role, billing contact) | Yes | You; your employer | Contracting, billing | Service providers, advisers | No |
| Commercial information (services purchased) | Yes | Our records | Contracting, billing | Service providers, advisers | No |
| Internet activity (pages viewed) | Only with your consent | Your device | Analytics | Analytics provider (if enabled) | No |
| Professional information (job title, employer) | Yes | You; public sources | Respond, provide services | Service providers, affiliates | No |
| Sensitive personal information | No | — | — | — | No |
| Inferences | No | — | — | — | No |
In the preceding 12 months we have not sold or shared personal information as those terms are defined in the CCPA/CPRA, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. Retention periods are in section 7.
10.2 Your rights
Subject to legal exceptions, you may request to know and access the personal information we hold about you (including categories, sources, purposes and recipients); to delete it; to correct inaccurate information; to opt out of sale, sharing or targeted advertising (we do none); to limit the use of sensitive personal information (we collect none); to receive a portable copy; and not to be discriminated against for exercising these rights. Residents of Virginia, Colorado, Connecticut, Texas and similar states may appeal a refused request by replying to our decision; we answer appeals within the statutory period and tell you how to contact your attorney general if you remain dissatisfied.
To exercise a right, email rahul@zenius.ai with "Privacy request" in the subject, or write to either office listed in section 1. We verify requests by matching the details you provide to our records and may ask for additional information. An authorised agent may submit a request on your behalf with your signed permission; we may also ask you to confirm the request directly. We respond within 45 days, extendable by a further 45 days with notice. California residents may also request, once a year, information about disclosures to third parties for their direct marketing (Civil Code §1798.83); we make none.
11. Your rights — India (Digital Personal Data Protection Act, 2023)
If you are in India, we process your personal data as a Data Fiduciary under the DPDP Act, 2023 and the DPDP Rules, 2025 (notified 14 November 2025, with obligations phased in over the following 18 months). Where we rely on consent, our notice tells you what data we collect and why, and you may withdraw consent as easily as you gave it. You have the right to access a summary of your personal data and the processing activities; to correct, complete, update and erase your data; to grievance redressal; and to nominate a person to exercise your rights if you are unable to. We respond to requests within 90 days. Requests and grievances go to our Grievance Officer, Rahul, at rahul@zenius.ai or the Delhi address above. If you are not satisfied with our response, you may approach the Data Protection Board of India.
12. Your privacy choices
Do Not Sell or Share My Personal Information. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. If that ever changes, this section will carry a working opt-out and the footer link will lead here.
Global Privacy Control. We honour the GPC browser signal as a valid opt-out of analytics and of any sale or sharing.
Cookie choice. If analytics is enabled on this site, you can change your answer at any time: . See the Cookie Policy.
Marketing. Every message we send about our services includes an unsubscribe option; you can also email rahul@zenius.ai.
13. Children
This website and the platform are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18 (or under the age of digital consent where you live). If you believe a child has provided us with personal data, contact the Data Protection Officer and we will delete it.
14. Cookies and similar technologies
This site sets no cookies and loads no third-party resources by default. Fonts are served from our own servers. If analytics is enabled, one analytics cookie is set only after you accept it in the banner, and your choice is stored in your browser. Full details, including how to withdraw, are in the Cookie Policy.
15. Changes to this policy
We update this policy when our practices or the law change. The date at the top shows the latest version; material changes are announced on this page and, for customers, by email. Earlier versions are available from the Data Protection Officer.
16. How to contact us
Data Protection Officer and Grievance Officer: Rahul — rahul@zenius.ai
Smartintent AI Solutions Private Limited, T-18, Plot No. 9B & 9C, Cross River Mall, Shahdara, Delhi 110032, India
Zenius QA US office, 221 Camille St, Leander, TX 78641, USA
US phone: +1 512 524 6804