Privacy Policy

How Zestine handles your data.

This Privacy Policy (“Policy”) governs how Zestine Technologies, Inc. (“Zestine,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information obtained from individuals and organizations that access or use our website at https://www.zestinetech.com/, our intelligent engineering platforms, software applications, APIs, and related services (collectively, the “Services”).

Effective · 2026 Governs · Zestine Services & Platforms Region · Global

Zestine is a U.S.-based technology company provides services for Engineering organizations. Our Services replace fragmented, manual workflows with intelligent, guided operational systems designed for precision and scale. By using our Services, you acknowledge and agree to the terms described in this Policy.

If you do not agree to this Policy, please discontinue use of our Services and contact us at support@zestinetech.com to request deletion of any previously collected data.

This Privacy Policy governs the processing of Personal Data by Zestine on behalf of the Authorised user / Organization in connection with the provision of the Zestine Products and Services, in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”), the UK GDPR (as incorporated into UK law by the European Union (Withdrawal) Act 2018), the California Consumer Privacy Act (“CCPA”) as amended by the CPRA, and all other applicable data protection laws (collectively, “Applicable Data Protection Law”).

For GDPR Clauses mentioned & referring in privacy policy document, please refer our Data Processing Agreement and respective Appendix A – processing details, Appendix B — Technical and Organisational Security Measures, Appendix C — Authorised Subprocessors and Appendix D — Standard Contractual Clauses (SCCs) for better understanding of the policy.

1Scope and Applicability

This Policy applies to:

This Policy does not apply to third-party products, services, or websites that may be linked from within the Services. We encourage you to review the privacy policies of those third parties independently.

2Data Governance and Compliance

Zestine Technologies, Inc. acts as the Data Controller for personal and technical information collected through our Services and is committed to maintaining data privacy and protection practices in alignment with applicable compliance standards, including GDPR, CCPA, and PIPEDA requirements where applicable.

Registered Name
Zestine Technologies, Inc.
Country of Incorporation
United States of America
Website
https://www.zestinetech.com/
Privacy Contact
support@zestinetech.com

3Personal & Technical Information We Collect

We collect limited personal, technical, operational, and usage information depending on how you interact with our Services / System, including:

GDPR Art. 5(1)(b): Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes (purpose limitation).
GDPR Art. 28(3)(a): The processor shall process personal data only on documented instructions from the controller.
GDPR Art. 28(3)(g): At the choice of the controller, delete or return all personal data to the controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage.

All account, authentication, and operational data are stored within secure cloud-based infrastructure protected through access controls, encryption, monitoring systems, and industry-standard security practices. Passwords are securely hashed and are never stored in plain-text format.

Multi-factor authentication (MFA) may not currently be available for all subscribed users. Users are responsible for maintaining the confidentiality of their account credentials. Password recovery and account assistance features are available where applicable.

GDPR Art. 28(3)(b): The processor shall ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Zestine may collect and process information for product activation, licensing validation, customer support, service delivery, operational monitoring, and platform security purposes. We do not sell or share personal information with third-party marketers.

Personal information and operational logs are retained only for as long as necessary to provide Services, comply with legal obligations, maintain security, resolve disputes, and enforce contractual agreements.

GDPR Art. 5(1)(e): Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (storage limitation).

4Artificial Intelligence usage in our interface

Zestine uses Ze AI, an AI-powered assistance system built on OpenAI technology. Ze AI may process user requests through OpenAI services in accordance with the applicable OpenAI Privacy Policy.

Ze AI is trained to assist engineering teams with product-related queries, technical guidance, operational support, and industry best practices related to Zestine products and services.

Users are strongly advised not to enter personal, confidential, sensitive, proprietary, or client-specific information through the AI chat interface.

All AI-generated responses are advisory in nature and are intended solely for informational and support purposes. Ze AI does not make fully automated technical, operational, or account-related decisions without meaningful human oversight.

Where AI-generated outputs may influence workflows, processes, or account-related activities, users may request human review or intervention by contacting support@zestinetech.com.

Ze AI processes only the information necessary to provide relevant technical assistance, product information, and operational guidance. Discussions or inputs unrelated to product support, technical usage, or operational assistance may be restricted, excluded, or not processed.

Screenshots, images, raw project files, engineering drawings, BIM models, proprietary datasets, and client-specific design information are not intentionally retained, curated, or used beyond the scope required to provide the requested response or support.

Zestine follows responsible and privacy-conscious AI practices. Any data processed through Ze AI is handled using anonymization or pseudonymization practices where applicable.

5Your Privacy Rights

GDPR Art. 33: The processor shall notify the controller without undue delay after becoming aware of a personal data breach. The controller must notify the supervisory authority within 72 hours of becoming aware.
GDPR Art. 34: Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the breach to the data subject without undue delay.

You may request access, correction, deletion, restriction, or portability of your personal information, subject to applicable laws and operational requirements. You may also withdraw consent or object to certain types of data processing, including marketing communications, at any time.

To exercise your privacy rights or request human review of significant AI-generated outputs, contact: support@zestinetech.com. Zestine will respond to verified requests within the timeframe required by applicable law.

6Cookies and Tracking Technologies

Zestine uses cookies and similar technologies to maintain platform functionality, improve user experience, analyze usage, and support platform performance. These may include necessary, functional, analytics, and consent-based marketing cookies.

We may use third-party analytics and monitoring services, including Google Analytics and Microsoft Clarity, to understand platform usage, diagnose technical issues, and improve our Services.

GDPR Arts. 44–49: Any transfer of personal data to a third country or international organisation may only take place if adequate protections are in place, including adequacy decisions, Standard Contractual Clauses (SCCs), or Binding Corporate Rules.

Users may manage or disable cookies through browser settings or our cookie consent preferences where applicable. Disabling certain cookies may affect some platform features or functionality.

7Updates to This Privacy Policy

Zestine may update this Privacy Policy periodically to reflect changes in our Services, operational practices, or legal requirements. Material updates may be communicated through our website, email notifications, or in-platform notices. Continued use of the Services after such updates constitutes acceptance of the revised Policy.

8Contact Us

Zestine shall notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a confirmed or reasonably suspected Personal Data Breach, to enable the Controller to meet the 72-hour notification deadline to the Supervisory Authority under GDPR Art. 33.

For questions, concerns, or privacy-related requests, please contact:

Email
support@zestinetech.com
Phone
+1 832 206 9137
Website
https://www.zestinetech.com/