1. Data Controller Statement
Zeno OS is an enterprise-grade neural business operating system owned, engineered, and operated exclusively by JR Digital Hub LTD. As the data controller, JR Digital Hub LTD is committed to strict compliance with international privacy mandates, including GDPR, NDPR, and enterprise multi-tenant isolation protocols.
2. Information We Collect
Account Credentials & Workspaces
We process your email address, unique tenant workspace ID, and Supabase JSON Web Tokens (JWTs) to authenticate sessions and isolate multi-tenant execution pods.
Financial & Payment Data Integrity
Zeno OS stores transaction logs and metered token balances. Express Statement: All raw credit card details, debit card numbers, and PINs are processed directly by our PCI-DSS Level 1 compliant payment gateway partner, Paystack. Zeno OS stores zero raw payment card credentials on our servers.
Operational & Agent Telemetry
To enable Oracle (Lead Gen), COO (Task Kanban), and CFO (Bookkeeping OCR) workflows, we collect document uploads, system audit logs, and search parameters. Any workspace-configured SMTP credentials are encrypted at rest using AES-256-GCM cryptography prior to database insertion.
3. How We Process Data (AI & LLM Orchestration)
Prompt & Invoice Processing: Documents processed by the CFO Agent and prompts sent to Google Gemini Vision APIs or Qdrant vector databases are partitioned strictly by workspace ID via Postgres Row Level Security (RLS). Zero customer workspace data is submitted to public LLMs for foundation model training.
Web Scraping & Lead Extraction: Public business intelligence gathered by the Oracle Agent (via Google Dorks / Serper APIs) is processed solely for outbound lead discovery requested by your workspace and is retained exclusively within your isolated tenant data store.
4. Data Security & Workspace Retention Rights
Multi-tenant boundary enforcement is enforced strictly at the database layer via Supabase JWT claims and Postgres Row Level Security policies.
You maintain full control over your data. You may request complete deletion or export of your workspace telemetry, financial ledger entries, and lead records by contacting our Privacy Operations desk.