[LEGAL]
This Privacy Policy explains how Zonder Solutions S.L. ("Vendian", "we", "us") collects, uses, shares, stores, and protects personal data when you use our website and our managed automation services.
We apply privacy-by-design principles and process personal data only for defined lawful purposes, with safeguards proportionate to risk and to the maximum extent required by applicable law.
Data controller for covered processing activities:
This Policy applies to personal data processed in connection with our website, scoping and onboarding, the operation of managed automation Modules within a client's connected systems, customer support, billing, and related professional services.
When we operate a Module on a client's behalf, we typically act as a processor for the personal data within that client's connected systems; the client's instructions and a data processing agreement also apply to that processing.
Our services use AI to help build and operate Modules, for example to classify data, generate drafts, summarize content, and support automated workflows.
AI-generated Outputs may contain errors or uncertainty. Sensitive actions run on a preview → confirm basis with a named human accountable, and clients remain responsible for appropriate review of outcomes.
We do not use identifiable client content for broad AI model training by default.
We may use de-identified and aggregated usage signals, telemetry, and performance metadata to improve service quality, security, and reliability, to the maximum extent permitted by applicable law.
We share personal data only where necessary to provide the services, protect legitimate interests, or comply with legal obligations.
We prioritize processing and storage in the EEA where operationally feasible.
When data must be transferred outside the EEA/UK, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent lawful mechanisms, with supplementary technical and organizational controls where appropriate.
Where data is no longer needed, we delete, anonymize, or securely isolate it according to our retention and deletion controls.
We maintain incident response processes to identify, contain, investigate, and remediate security events.
Where required by applicable law, we notify affected parties and competent authorities within legally mandated timeframes.
Depending on applicable law and your location, you may have rights including access, correction, deletion, portability, restriction, objection, and withdrawal of consent.
Where we process data on behalf of a client as processor, we will direct your request to that client (the controller) where appropriate and support them in responding.
To protect security and prevent unauthorized disclosure, we may verify requester identity before processing rights requests.
We respond within timeframes required by applicable law and may extend where legally permitted for complex requests, with notice to the requester.
We use a consent-first model for non-essential tracking. On first visit, analytics and performance tracking remain blocked until you choose "Accept all." If you choose "Accept none," non-essential tracking stays disabled. We do not run advertising or cross-context behavioral tracking.
You can change your choice anytime from the "Cookie settings" control in the footer. Blocking non-essential cookies may limit analytics-based improvements but does not disable core site functionality.
We do not sell personal data for money, and we do not use it for cross-context behavioral advertising.
Where applicable law defines certain disclosures as "sharing," you may exercise opt-out rights through available controls and by contacting [email protected].
Our services are intended for adults and business users. We do not knowingly collect personal data from individuals under 18 for use of the services.
If you believe underage data was provided in violation of this Policy, contact [email protected] for prompt review and removal where required.
We use automated systems to support routing, scoring, detection, and workflow automation as part of operating the Modules. These systems are designed to assist operations with named human accountability, not to replace legally required human judgment in sensitive contexts.
Where applicable law grants rights regarding automated decision-making, you may request review through [email protected].
Our website may contain links to third-party sites, and our Modules operate within clients' third-party systems. Those third parties' privacy practices are governed by their own policies and terms.
If you believe your data has been processed unlawfully, you may contact us first at [email protected] so we can investigate and resolve the issue.
You may also lodge a complaint with a competent data protection authority in your jurisdiction.
We may update this Policy to reflect legal, technical, or operational changes. Updated versions will show a revised effective date.
Where required by applicable law, we will provide additional notice or obtain consent before material changes take effect.
For privacy, data subject rights, legal notices, and compliance inquiries, contact [email protected].
Reference your organization and the email address you use with us to accelerate verification and response.