Privacy Policy
1. Who we are
Zenith Intelligence is the sole proprietorship of Samuel Doorenbosch and builds AI systems for businesses: agents, automations and dashboards.
| Data controller | Zenith Intelligence |
| Dutch Chamber of Commerce (KvK) | 78550521 |
| samuel@zenithintelligence.ai | |
| Website | zenithintelligence.ai |
We do not have a Data Protection Officer (DPO); that obligation does not apply to us. For any privacy question, contact us at the e-mail address above.
2. What data we process
When you contact us. Name, company name, e-mail address, phone number, and the content of your message. You provide these yourself by e-mail, by phone, by booking a call, or during an intake or diagnostic conversation.
When you become a client. Company details, Chamber of Commerce number, contact person, billing and payment details (including IBAN for SEPA direct debit), and the correspondence about the engagement.
When you visit our website. Our website uses no cookies and no analytics. When the site loads, fonts and visual elements are loaded from external services (such as Google Fonts); your IP address is passed to those parties as a technical necessity.
What we do not do. We do not sell data, we do not profile you for advertising purposes, and we do not make automated decisions with legal effects about you.
3. Why we process this data
| Purpose | Legal basis (Article 6 GDPR) |
|---|---|
| Responding to your question or contact request | Legitimate interest (1(f)) or pre-contractual measures (1(b)) |
| Preparing and issuing a proposal | Pre-contractual measures (1(b)) |
| Performing an agreement and delivering the service | Performance of a contract (1(b)) |
| Invoicing and collecting payment | Performance of a contract (1(b)) and legal obligation (1(c)) |
| Keeping records for the Dutch tax authority | Legal obligation (1(c)) |
| Improving and securing the website | Legitimate interest (1(f)) |
4. How long we keep data
| Category | Retention period |
|---|---|
| Contact requests that do not lead to an engagement | 12 months after last contact |
| Proposals that are not accepted | 24 months |
| Client records and correspondence | 7 years after the agreement ends |
| Invoices and administration | 7 years (statutory Dutch tax retention obligation) |
After these periods we delete the data, unless a legal obligation requires us to keep it longer.
5. Who we share data with
We use service providers that process data on our behalf. A data processing agreement is in place with each of them. We never share more than necessary.
| Party | Purpose | Processing in |
|---|---|---|
| Google Workspace | E-mail, calendar, document storage | EEA / US |
| Calendly | Scheduling calls | US |
| Website hosting provider | Hosting of zenithintelligence.ai | EEA / US |
We may also share data with our bookkeeper or accountant, and with authorities where a legal obligation requires it.
6. Transfers outside the European Economic Area
Some of the parties above process data outside the EEA, mainly in the United States. Such transfers take place only on the basis of a valid mechanism under Chapter V GDPR: an adequacy decision of the European Commission (such as the EU-US Data Privacy Framework) or the European Commission's Standard Contractual Clauses (SCCs).
7. Cookies
Our website uses no cookies: no tracking, advertising or analytics cookies. No cookie banner is therefore required. Should this change in the future, we will update this policy.
8. Your rights
Under the GDPR you have the following rights:
- Access. Request which data we process about you.
- Rectification. Have inaccurate data corrected.
- Erasure. Have your data deleted, insofar as no retention obligation applies.
- Restriction. Have processing temporarily suspended.
- Portability. Receive your data in a common file format.
- Objection. Object to processing based on legitimate interest.
- Withdrawing consent. Where we process on the basis of consent, you can withdraw it at any time. This does not affect the lawfulness of earlier processing.
Send your request to samuel@zenithintelligence.ai. We respond within one month. To prevent abuse, we may ask you to identify yourself.
Does your request concern data we process on behalf of a client? Then we will refer you to that client, who is the data controller in that case, not us.
9. Security
We take appropriate technical and organisational measures to protect your data, including encryption in transit, need-to-know access, two-factor authentication on admin environments, and periodic backups. Our security policy and incident response procedure are documented internally.
Do you suspect a vulnerability or a data breach? Report it immediately via samuel@zenithintelligence.ai.
10. Complaints
If you disagree with how we handle your data, please contact us first. If we cannot resolve it together, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via autoriteitpersoonsgegevens.nl.
11. Changes
We may update this privacy policy when our services or regulations give reason to do so. The current version is always available at zenithintelligence.ai. The date at the top indicates when the policy was last changed.
