Privacy policy
How ZEEN Connect processes personal data.
1. Controller
The controller of the platform is ZEEN Connect. Company details, registered address, tax number and contact email should be completed in admin settings or before publishing the legal document.
2. Data we process
We process data entered during registration, profile setup, bookings, messages, workshops, payments, invoices, reviews and support. This may include name, email, phone number, billing address, booking data, communication between users, payment data and technical security data.
3. Purposes and legal bases
We process data to create and manage accounts, provide bookings, process payments, issue invoices, enable communication between clients and practitioners, provide user support, protect platform security, meet legal obligations and improve the service.
4. Payments and external providers
Payments are processed through Stripe. ZEEN Connect does not store full payment card details. We use Supabase for login, database and authentication. These providers may process data as processors or independent controllers for certain services.
5. Data retention
We keep data for as long as needed to provide the service, meet legal obligations, resolve disputes and maintain security. Accounting data is retained in accordance with applicable law.
6. User rights
You have the right to access, correct, delete, restrict processing, data portability, object and withdraw consent where processing is based on consent. Requests can be sent to the controller contact email.
7. Security
We use technical and organisational measures to protect data, including authentication, access controls and secure data transfer.
8. Contact
For questions about privacy, access to data, corrections or deletion, contact us at the controller contact email.
Sensitive wellbeing and health-related data
Bookings, notes, messages or reviews may reveal information about wellbeing, health, therapies, mental state or other sensitive circumstances. Share this only when needed for the booking or communication with the selected provider. The platform processes it to provide the service, maintain security, support users, meet legal duties and establish or defend claims, with appropriate legal bases and access limits.
Privacy rights in the EU, UK, US and other jurisdictions
EU/EEA and United Kingdom users have GDPR/UK GDPR rights including access, correction, deletion, restriction, portability and objection. Users in the United States, including California, may have additional local rights to notice, access, correction, deletion, limiting the use of sensitive information or opting out of certain processing. Requests are handled through the controller contact email.
Email notices and data minimisation
Email summaries follow data minimisation: the email contains only the number or type of new events and a link to the platform, not the content of private messages. Users can change the email summary preference in their account; essential transactional, security and legal notices may still be sent where needed.
Marketing emails and consent
For marketing emails we use only the contact email, language, user role, country for segmentation, explicit consent preference and, for imported contacts, the mailing-list data lawfully imported by the admin. Admins can send campaigns to all opted-in users, clients, providers or imported contacts and can limit them by country. Delivery events are logged for security, consent accountability and troubleshooting. Marketing emails do not contain private messages or sensitive booking data.
Zeen Video, Daily.co and webinar recording
We use Daily.co as a contracted technical provider for protected video services, workshops and webinars. When a participant joins, we provide Daily with a short-lived meeting token, an internal user identifier and a display name; Daily also processes the IP address and technical call data to establish the connection, secure the service and maintain call quality. Rooms are private and access is tied to a valid Zeen booking. Video, audio, screen sharing, chat and reactions are not recorded or persistently stored by default. Only for a paid Zeen Webinar may the host explicitly order recording, and every participant sees a clear notice before recording starts. The recording remains available to the provider through Zeen for no more than 7 days and is then permanently deleted. Daily states that it does not store video, audio or screen-share media unless recording is enabled, but may retain limited access and diagnostic logs under its privacy and security policies.
