Privacy and data protection

Zensli Privacy Policy

This policy explains which personal data Zensli collects, why it is processed, how it is protected, and which rights are available to you.

PKG AB Sweden GDPR We do not sell personal data

1 Introduction

This Privacy Policy explains what information, including personal data, we collect from you as a Zensli Customer, how we use it, the legal grounds for processing, whether it is shared, and the rights and choices available to you.

This Policy applies to personal data processed by PKG AB in connection with providing and operating the Zensli service.

We do not sell your personal data

Zensli does not sell Customer account, communication, or usage data to third parties.

2 Who We Are

PKG AB, Reg. No. SE559008922201, is a Swedish company that provides the Zensli service.

Zensli helps organisations collect and analyse website activity, create visitor profiles, and activate customer intelligence in connected systems.

For personal data related to Customer accounts, billing, communication, and use of the Zensli platform, PKG AB acts as the Data Controller.

When Zensli processes website visitor or application user data on behalf of a Customer, the Customer normally acts as Data Controller and PKG AB acts as Data Processor under the Zensli Data Processing Agreement .

3 Personal Data We Collect and Use

We collect and process the following categories of personal data when acting as Data Controller:

Account Data Name, email address, job title, contact details, organisation, billing details, account roles, and related information provided when creating or managing a Zensli account. This information is used to provide, administer, and secure the service.
Communication Data Name, email address, organisation, message content, and other information provided when contacting us for support, sales, feedback, or another request. This data is used to respond and manage the relationship.
Account Usage Data Login times, features used, configuration changes, administrative actions, security events, and technical information related to use of the Zensli platform. This data supports operation, security, auditing, troubleshooting, and service improvement.
Billing and Transaction Data Subscription, invoice, payment status, company, and transaction information required to administer subscriptions, accounting, and legal obligations.
Customer-controlled visitor data

Zensli may also process website visitor and application user data on behalf of Customers. This processing is governed by the Data Processing Agreement and the Customer’s configuration and documented instructions.

5 Your Rights

Depending on the applicable law and circumstances, you may have the following rights:

Access to your personal data.
Correction of inaccurate or incomplete data.
Erasure where the applicable conditions are met.
Restriction of processing.
Data portability where applicable.
Objection to certain processing.
Withdrawal of consent at any time where consent is the legal basis.
The right to lodge a complaint with a competent supervisory authority.

To exercise a right concerning personal data controlled directly by PKG AB, please contact us.

For website visitor or application user data processed by Zensli on behalf of one of our Customers, the request should normally be directed to that Customer. We assist Customers with valid requests in accordance with the Data Processing Agreement.

Supervisory authorities

Sweden: Integritetsskyddsmyndigheten (IMY)
EU/EEA: Your competent national data-protection supervisory authority
United Kingdom: Information Commissioner’s Office (ICO)

6 Children’s Privacy

Zensli Customer accounts and business services are not intended for children under 16.

PKG AB does not knowingly collect Customer account data directly from children. If such information is identified, it will be handled and deleted as required by applicable law.

7 Who We Share Personal Data With

Personal data may be shared with trusted providers only where necessary to operate, secure, support, or administer the Zensli service.

Service Providers and Subprocessors Providers that support hosting, infrastructure, email delivery, monitoring, security, customer support, or other service operations. Providers are subject to appropriate confidentiality and data-protection obligations.
Billing and Accounting Providers Providers that support subscription administration, payment processing, invoicing, accounting, and related legal obligations.
Authorities and Legal Recipients Public authorities, courts, advisers, or other recipients where disclosure is required by law or necessary to establish, exercise, or defend legal claims.
No sale of personal data

PKG AB does not sell or rent Customer personal data to advertisers or data brokers.

8 International Transfers

Where personal data is transferred outside the EU or EEA, PKG AB uses a lawful transfer mechanism where required, such as an adequacy decision, Standard Contractual Clauses, or another mechanism recognised under applicable Data Protection Legislation.

Additional safeguards may be applied based on the destination, recipient, type of data, and risks associated with the transfer.

9 Retention of Personal Data

We retain personal data only for as long as necessary for the purpose for which it was collected, including providing the service, maintaining account security, resolving disputes, and complying with legal, accounting, and reporting obligations.

Customer account data is normally retained while the account remains active. Following termination, data is deleted or anonymised according to the applicable agreement and retention policy, normally within 30 days unless a longer period is required by law.

Data processed by Zensli on behalf of Customers is retained in accordance with the Customer’s configuration, instructions, contract, and the Data Processing Agreement.

10 How We Protect Personal Data

PKG AB implements technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction.

Access Control

Access is restricted according to role, responsibility, and operational need.

Encryption

HTTPS protects data in transit, with encryption controls applied to stored data.

Monitoring

Relevant system and application activity is logged and monitored to support incident detection and investigation.

Backup and Recovery

Backups, redundancy, and recovery procedures support the availability and resilience of the service.

Additional information is available in the Zensli Data Processing Agreement .

11 Automated Decision-Making and Profiling

PKG AB does not use Customer account, communication, or billing data to make decisions that produce legal or similarly significant effects solely through automated processing.

Zensli analytics features

The Zensli service may calculate engagement scores, churn-risk indicators, segments, classifications, or other analytical signals using data controlled by a Customer. The Customer determines how such insights are used and remains responsible for any resulting decisions or actions.

12 Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the Zensli service, legal requirements, security practices, or data-processing activities.

Material changes may be communicated through the Zensli platform, by email, or by another appropriate method.

The version published on this page is the current version of the Privacy Policy.

13 Contact Us

Contact PKG AB if you have questions about this Privacy Policy, want to exercise a privacy right, or need information about how personal data is handled.

A1 Appendix 1 – Technical and Organisational Measures

PKG AB applies measures intended to protect personal data and maintain the confidentiality, integrity, and availability of the Zensli service.

  • Access Control: Access to personal data and production systems is restricted to authorised personnel.
  • Authentication and Authorisation: Access mechanisms are used to verify users and control permissions.
  • Encryption: Data is encrypted in transit using HTTPS, with encryption controls applied to stored data.
  • Monitoring and Logging: System and application activities are monitored and logged to support detection, investigation, and auditing.
  • Incident Response: Procedures are maintained for handling and documenting security incidents.
  • Availability and Redundancy: Redundant infrastructure, backups, and recovery mechanisms support continued availability.
  • Personnel Confidentiality: Personnel authorised to handle personal data are subject to appropriate confidentiality obligations.

For additional details, refer to the Zensli Data Processing Agreement .

Agreement and applicable terms

Use of the Zensli service is also governed by the applicable subscription agreement, Terms of Service, and Data Processing Agreement.