DataProtection
How we look after your organisation's data under the GDPR.
1Built for European Data Protection
Zenchronity handles some of the most personal information an organisation holds about its people: who they are, when they are away and why. We designed the Service so that you can use it in line with the GDPR, and this page summarises how. The binding terms are in our Data Processing Agreement.
2Who Is Responsible for What
Your organisation is the controller of the data it puts into Zenchronity. You decide which people, leave types and integrations to use, and you are responsible for informing your employees.
Zenchronity is the processor. We process your data only to provide, secure and support the Service, on your instructions, under a Data Processing Agreement based on the European Commission's standard contractual clauses. It forms part of our Terms, so it applies from the day your organisation is set up, with no separate signature needed. A signed copy is available on request.
3Where Your Data Lives
Our servers and databases are in ISO/IEC 27001 certified data centres in the European Union. A small number of providers help us run the Service; they are listed in Annex IV of the Data Processing Agreement, with what each one does. Where a provider may process data outside the EU, the transfer is protected by the EU-US Data Privacy Framework or the Commission's standard contractual clauses.
We announce any change to our providers at least 30 days in advance, so you have time to raise a concern.
4How Your Data Is Protected
Data is encrypted in transit and at rest, and the details that identify people are encrypted again with a key specific to your organisation. Access is controlled by single sign-on, two-factor authentication and roles, each organisation's data is kept separate, and we take regular backups. Our Security page describes the measures in more detail.
5Sensitive Information
Some leave types, such as medical leave, can reveal information about health. You decide which leave types to use, and access to other people's leave is limited by role and reporting line. Leave comments and rest scores are never sent to our AI model provider, and burnout signals are calculated by fixed rules from annual leave, not by AI. See how Zen AI works.
6How Long We Keep Data
- Your organisation's data: For as long as your contract lasts.
- After the contract ends: Deleted within 30 days, after an export if you ask for one.
- Audit records: Deleted automatically after a few months.
- Zenchronity Calendar appointments: Deleted automatically 730 days after the appointment.
- Backups: Overwritten on a rolling basis.
7Your People's Rights
Employees exercise their data protection rights through their employer, as the controller. Your administrators can view, correct and export data and permanently delete users in the Service. If a request needs more than that, or if someone writes to us directly, we pass it to you and help you answer it.
8If Something Goes Wrong
If a personal data breach affects your data, we tell your administrators without undue delay and at the latest within 72 hours, with what we know, and we give you the information you need to notify your supervisory authority and, where required, the people affected. Current system status is on our status page.
9Documents
- Data Processing Agreement, including the list of sub-processors
- Privacy Policy
- Security
- How Zen AI works
- Cookie Policy
Questions from your DPO, legal or procurement team are welcome at privacy@zenchronity.com.