Zeldoc AI Platform - Privacy Policy
This document contains references to specific articles and sections of EU and Danish legislation. Each reference is accompanied by a brief explanation in parentheses. Full text of the legislation can be found at eur-lex.europa.eu (EU legislation) and retsinformation.dk (Danish legislation).
1.Introduction
Zeldoc.ai ApS ("Zeldoc", "we") is the data controller for the processing of personal data in connection with the Zeldoc AI Platform ("the Platform"). This Privacy Policy describes how we collect, process, store and protect personal data in accordance with:
- EU General Data Protection Regulation (GDPR) - Regulation (EU) 2016/679
- The Danish Data Protection Act
- EU AI Act - Regulation (EU) 2024/1689
- Other Danish legislation
Zeldoc.ai ApS
For the processing of customer data, Zeldoc is the processor on behalf of the customer, cf. §5.2. The scope of storage and retention periods are described in Zeldoc's Data Processing Agreement (DPA), which forms an integral part of the Terms of Service, cf. §5.6.
2.Zeldoc's Core Feature: EU Data Sovereignty
2.1 Data locality in core products
Personal data processed through the Platform's core products is stored exclusively on servers within the European Union (currently in Germany), and AI inference on local/EU-hosted models is executed exclusively on servers within the European Union (currently in Denmark). Connections to the Platform pass through Cloudflare, which may terminate the encrypted connection (TLS) outside the EU, see the section on operational services below.
For ZControl and for inference via ZCore, ZDev and ZRouter with local/EU-hosted models:
- No transfer of customer data (prompts, documents, outputs) to countries outside the EU/EEA during core inference
- The Platform's core products can, in an alternative setup, be delivered entirely on EU hosting and EU-hosted models without US companies. The current delivery uses US companies for support functions, including Cloudflare for network and TLS termination
- No SCCs or transfer impact assessments required for core inference, as customer data does not cross EU borders there, cf. Schrems II judgment (C-311/18)
Certain operational services (e.g. CDN, DNS, CI/CD and operational alerting) are provided by subprocessors that may be US companies - see the named subprocessor list at zeldoc.ai/subprocessors. SCC 2021/914 and/or the EU-US Data Privacy Framework apply as transfer mechanisms for these providers. Customer data is not processed by the operational subprocessors beyond transit/TLS termination and operational/security data (cf. the subprocessor list); core inference is executed in the EU.
This is a fundamental difference from AI platforms that are domiciled in the USA or dependent on US cloud infrastructure.
2.2 EXCEPTION: ZRouter and external frontier models
ZRouter is Zeldoc's model routing layer. ZRouter can route inference requests to two types of models:
- Local/EU-hosted models - data stays in EU ✅
- External frontier models (e.g. Anthropic Claude, OpenAI GPT) - data leaves EU at inference ❌
When ZRouter directs inference to external frontier models - whether directly via ZRouter or via ZConnect - the customer's prompts and inference data leave the EU data region and are transferred to the external model provider's infrastructure (e.g. USA).
2.3 Data sovereignty matrix
| Product / Scenario | Data in EU? | Zero Data Retention? | GDPR third-country transfer? |
|---|---|---|---|
| ZControl - alone | Yes | Yes | No - not applicable |
| ZCore + local/EU models | Yes | Yes | No - not applicable |
| ZDev + local/EU models | Yes | Yes | No - not applicable |
| ZRouter + local/EU models | Yes | Yes | No - not applicable |
| ZRouter + external frontier models | No - data leaves EU | No - external provider policy | Yes - GDPR Art. 44-49 |
| ZConnect (via ZRouter) | No - data leaves EU | No - external provider policy | Yes - GDPR Art. 44-49 |
3.What Personal Data Do We Process?
3.1 Customer user data (Zeldoc as controller)
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Identification data | Name, email | Account creation, administration | Contract (Art. 6(1)(b)) |
| Access data | Username, password (hashed) | Security and access control | Contract / Legitimate interest (Art. 6(1)(f)) |
| Usage data | Token usage, API calls, timestamps | Billing, capacity planning | Contract (Art. 6(1)(b)) |
| Billing data | VAT no., address, payment details | Billing, bookkeeping | Contract / Legal obligation (Art. 6(1)(c)) |
3.2 Customer data - prompts and outputs (transient processing)
Prompts, documents and outputs that users submit or generate via the Platform may contain personal data. Zeldoc's AI infrastructure (ZCore/ZDev) processes this data solely transiently during the AI inference itself and does not store it. Any storage of content (chats, history, notes etc.) takes place in the application layer chosen by the Customer (e.g. OpenWebUI, development clients or partner apps), which is not covered by Zeldoc's Data Processing Agreement (DPA). The customer is the data controller for the content of this data, including the application layer used. The scope of Zeldoc's processing is stated in the DPA, cf. §5.2 and §5.6.
When customer data (prompts that may contain personal data) is sent through ZRouter to external frontier models, this personal data is transferred to a third country. The customer is the data controller and must ensure a legal basis for this transfer, cf. GDPR Art. 44-49. Zeldoc is the processor for participating in the transfer, but responsibility for the transfer itself rests with the customer, cf. §6.
3.3 Automatically collected data
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Technical data | IP address, browser type and operating system (user agent) | Access control and security. Linked to the individual login session | Legitimate interest, Art. 6(1)(f) |
| Login information | Login time, logout time, session expiry time | Security | Legitimate interest, Art. 6(1)(f) |
| Consumption data (API) | Per API key: model, number of tokens, number of calls, timestamp. Not prompts or responses | Billing and consumption reporting | Contract performance, Art. 6(1)(b) |
| Cookies | refresh_token (login), NEXT_LOCALE (language choice), DISPLAY_CURRENCY (currency choice) | Platform functionality | Necessary and functional cookies, exempt from consent under ePrivacy Art. 5(3) |
Zeldoc does not use tracking cookies, marketing cookies or third-party analytics cookies, cf. the ePrivacy Directive and the Danish cookie regulation. Visitor numbers on Zeldoc's public websites are measured without cookies using Plausible, cf. section 15.1.
4.Purpose of Processing
Zeldoc processes personal data for the following purposes:
- Service delivery - operation and maintenance of the Platform and Products
- Administration - user management, access control, billing
- Security - threat detection, incident response
- Compliance - meeting legal requirements, including the Bookkeeping Act and GDPR Art. 32-34
- Improvement - platform optimization and performance improvements (without using customer data for model training - see §7)
- Support - customer support and troubleshooting
5.Roles: Controller vs. Processor
5.1 Zeldoc as data controller
Zeldoc is the data controller for the following data, cf. GDPR Art. 4(7):
- Customer user and administration data (§3.1)
- Technical and usage data (§3.3)
- Billing data
5.2 Zeldoc as data processor
Zeldoc is the processor on behalf of the customer, who is the controller, cf. GDPR Art. 28. Processing includes transient processing such as transmission and AI inference. Zeldoc stores account/administration data as well as operational, security and technical data cf. the Data Processing Agreement (DPA), Appendix A.3(b); customer content in the application layer is not covered, cf. the DPA, Appendix A.3(c). Where the same operational, usage and security data is also used for Zeldoc's own purposes (billing, security and operating the Platform), Zeldoc is the controller for that processing, cf. §5.1.
5.3 Subprocessors
Zeldoc has a standard Data Processing Agreement with each customer, incorporated into the Terms of Service, and maintains a general written authorisation for subprocessors (Art. 28(2)). The current subprocessor list - name, purpose, location and transfer mechanism - is published at zeldoc.ai/subprocessors. Customers are notified of new subprocessors at least 30 days in advance and may object on reasonable grounds.
External frontier model providers (e.g. Anthropic) are not subprocessors in the traditional sense. They are independent controllers or processors with their own legal basis and policies for the data they receive via ZRouter. See §6 for further description. Their zero-retention status, where offered, is stated in the subprocessor list at zeldoc.ai/subprocessors.
5.4 Data retention
Zeldoc's AI infrastructure (ZCore/ZDev) does not store content (prompts, outputs, documents); such data is processed solely transiently during AI inference, and request/response storage is disabled. Any storage of content (chats, history, notes etc.) takes place in the application layer chosen by the Customer (e.g. OpenWebUI, development clients or partner apps), which is not part of Zeldoc's services and is not covered by the DPA, cf. §5.2. Operational and usage metadata per AI call (pseudonymised key/team ID, which can be linked to the Customer's organisation and therefore potentially to identifiable users) is retained for 2 years, as it forms the basis for invoicing and is used to substantiate invoices to the Customer; technical logs, including access logs, are retained for 90 days, while session and security records in the Platform's database (e.g. login sessions with IP address) have no automatic deletion period; login sessions are deleted with the user account. The Platform's databases, including account, administration and usage data, are backed up encrypted, and backups are retained for 1 month; content (prompts and outputs) is not backed up, as it is not stored.
5.5 International transfers
The Platform's core products run exclusively on infrastructure in the EU/EEA, cf. §2. When using frontier models via ZRouter/ZConnect, data is transferred to third countries; such transfers are made using Standard Contractual Clauses (SCCs) and supplementary measures, cf. §6.
5.6 Data Processing Agreement
The Data Processing Agreement (DPA) forms an integral part of the Terms of Service and is available at zeldoc.ai/dpa.
6.ZRouter and Third-Country Transfers
6.1 Data transfer to external model providers
When the customer uses ZRouter to route inference to external frontier models - directly or via ZConnect - prompts and inference data are transferred to external model providers outside the EU. The table below shows examples of external model providers and is not exhaustive:
| External provider | Model | Location | Transfer basis |
|---|---|---|---|
| Anthropic | Claude (family) | USA | SCC + supplementary measures |
| Gemini (family) | USA | SCC + supplementary measures | |
| OpenAI | ChatGPT (family) | USA | SCC + supplementary measures |
The table is indicative only and not exhaustive. The available portfolio of external model providers may change over time, and Zeldoc may add or remove providers at its discretion. The current and complete list is available in ZControl. External model inference is sent directly to the selected model provider or via OpenRouter; the subprocessor list states which providers are in use. Zeldoc cannot guarantee Zero Data Retention, and the selected model provider's own retention policy applies, cf. §6.5.
6.2 Legal basis for the transfer
The transfer to third countries via ZRouter/ZConnect is made using:
- Standard Contractual Clauses (SCCs) - the European Commission's standard clauses for transfers to third countries, cf. GDPR Art. 46(2)(c)
- Supplementary measures - encryption in transit (TLS 1.2+), data minimisation, pseudonymisation where possible
- Transfer Impact Assessment - Zeldoc has assessed the risks of transfer to the relevant provider, cf. Schrems II (C-311/18) and EDPB Recommendations 01/2020
6.3 Customer responsibility for transfers
The customer is the data controller for the personal data sent through ZRouter to external frontier models. The customer must:
- Ensure a legal basis for the processing itself (e.g. consent, contract, legitimate interest), cf. GDPR Art. 6
- Ensure a legal basis for the transfer to third countries, cf. GDPR Art. 44-49
- Inform data subjects about the transfer and the external recipient, cf. GDPR Art. 13/14
- Conduct a transfer impact assessment for specific use cases if required
- Refrain from submitting special categories of personal data or personal data relating to criminal convictions and offences through external frontier models unless the Customer has conducted a separate risk assessment and ensured a valid legal basis for the processing, cf. GDPR Art. 9 and 10
- Document the transfer in its own procedures and records of processing activities, cf. GDPR Art. 30
6.4 Zeldoc's measures for ZRouter external calls
Zeldoc ensures:
- Access management via ZControl - access to external frontier models can be restricted per API key
- Ability to remove external frontier models from an individual API key
- Operational and usage metadata per AI call (timestamp, model, token count, cost, pseudonymised key/team ID, status) is retained for 2 years, as it forms the basis for invoicing and is used to substantiate invoices to the Customer. The content of the calls (prompts, files, outputs) is not stored - request/response storage is disabled
- Encryption of data in transit (TLS 1.2+) between EU infrastructure and external provider
6.5 Zero Data Retention for external calls
Zeldoc cannot guarantee Zero Data Retention for external frontier model providers. The external provider's own data retention policies apply. The customer is encouraged to consult the external provider's privacy policy. The following is an example of such a policy and is not exhaustive:
Anthropic (example): https://www.anthropic.com/legal/privacy
7.Use of Data for Model Training
7.1 Core products: no model training on customer data
Zeldoc does not use customer data (prompts, documents, outputs) to train, fine-tune or improve AI models in core products, cf. the Data Processing Agreement (DPA) and this Privacy Policy. This is a critical difference from several US AI platforms.
7.2 Telemetry and platform improvement
Zeldoc collects operational telemetry (e.g. response times, error rates and usage per model) to operate and improve the Platform's performance and stability. The telemetry is not anonymised: it is linked to pseudonymised identifiers such as the API key's and team's name and ID, which can be linked to the Customer's organisation, and key and team names can contain personal names. The telemetry contains no prompts or outputs and is retained for 60 days.
7.3 Explicit consent
If Zeldoc wishes to use customer data for model improvement in the future, this will require explicit, separate and voluntary consent from the customer, as well as a separate agreement, cf. GDPR Art. 7.
7.4 External model providers
Zeldoc has no control over whether external frontier model providers (e.g. Anthropic) use the customer's prompts for model training. The customer should consult the external provider's policies. Where possible, Zeldoc will prefer providers that offer Zero Data Retention / no-training agreements.
8.Retention and Deletion
8.1 Retention periods
| Data category | Retention period | Reason | Legislation |
|---|---|---|---|
| User accounts | Active subscription period + 30 days | Customer service, data export | GDPR Art. 5(1)(e) |
| Content (prompts/outputs) | Content is not stored by Zeldoc — storage takes place in the application layer, which is not part of Zeldoc's services | Transient processing during AI inference | GDPR Art. 28 (processor), cf. DPA |
| Billing data | 5 years | Bookkeeping obligation | Bookkeeping Act § 10 |
| Technical logs (including access logs) | 90 days | Operations and security management | GDPR Art. 32 |
| Session and security records in the database (e.g. login sessions with IP address) | No automatic deletion period. Login sessions are deleted with the user account | Access control and security | GDPR Art. 32 |
| Operational telemetry (metrics) | 60 days | Operations and stability | GDPR Art. 6(1)(f) |
| Operational and usage metadata per AI call (timestamp, model, tokens, cost, pseudonymised key/team ID, status) | 2 years | Invoicing and substantiating invoices | GDPR Art. 28 (processor), cf. DPA |
| Encrypted backups of the Platform's databases (account, administration and usage data; content is not backed up) | 1 month | Recovery after incidents | GDPR Art. 32, cf. DPA Appendix C.4 |
8.2 Deletion on termination
On termination of the subscription:
- Content is not stored by Zeldoc — storage takes place in the application layer, which is not part of Zeldoc's services, and therefore requires no deletion at Zeldoc
- User accounts are deleted after 30 days from termination
- Billing data is retained in accordance with the Bookkeeping Act
Zeldoc deletes data in accordance with GDPR Art. 17 (right to erasure) and the Danish Data Protection Act § 4.
8.3 Customer's right to deletion
The customer may at any time request deletion of specific user data from Zeldoc (the organisation's administrators can also remove users themselves in ZControl). Zeldoc fulfills the request within 30 days, cf. GDPR Art. 17.
Zeldoc cannot delete data sent to external model providers via ZRouter. Deletion requests for data at external providers must be addressed directly to the provider by the customer. Zeldoc can assist with contact details.
9.Data Subject Rights
As Zeldoc is both a controller (for user data) and a processor (for customer data), different rights apply:
9.1 For user data (Zeldoc as controller)
Data subjects (users) have the following rights, cf. GDPR Art. 12-22:
| Right | GDPR article | How |
|---|---|---|
| Right of access | Art. 15 | Request to [email protected] |
| Right to rectification | Art. 16 | Request to [email protected] |
| Right to erasure ("right to be forgotten") | Art. 17 | Request to [email protected] |
| Restriction of processing | Art. 18 | Request to [email protected] |
| Data portability | Art. 20 | Request to [email protected] |
| Right to object | Art. 21 | Request to [email protected] |
| Right not to be subject to automated decisions | Art. 22 | N/A - the Platform does not make autonomous decisions with legal effect |
Zeldoc responds to requests without undue delay and no later than 1 month after receipt, cf. GDPR Art. 12(3).
9.2 For customer data (customer as controller)
For customer data, the customer is the controller. Enquiries from data subjects about customer data (prompts, outputs, documents) should be addressed to the customer, not to Zeldoc. Zeldoc assists the customer in fulfilling such requests where technically possible, cf. GDPR Art. 28(3)(e).
For data sent to external model providers via ZRouter, the external provider's own process for data subject rights applies. Zeldoc cannot guarantee fulfillment of GDPR rights for data at external providers.
10.Security Measures
Zeldoc has implemented technical and organisational measures in accordance with GDPR Art. 32:
10.1 Technical measures
| Measure | Implementation |
|---|---|
| Encryption in transit | Encrypted transport for all data transfer - TLS 1.2+ to the internet and external model providers, encrypted private networking internally |
| Access control | Role-Based Access Control (RBAC) via ZControl |
| Key management | Secrets such as API keys, database credentials and tokens are stored centrally in an access-controlled secret service and deployed automatically to the production environment, so they never appear in source code or container images. Access is restricted to authorised operations personnel. TLS certificates are renewed automatically. Keys are replaced upon suspected compromise following a documented procedure. |
| Network security | Isolated private networks with encrypted transport; firewalls and minimised public exposure |
| Provider certifications | Hosting providers certified to ISO/IEC 27001; ISAE 3402 Type 2 and BSI C5 Type 2 reports available |
10.2 Organisational measures
| Measure | Implementation |
|---|---|
| Access policy | Need-to-know, least-privilege |
| Security training | Annual training of all personnel with data access |
| Subprocessors | General written authorisation + named subprocessor list at zeldoc.ai/subprocessors, cf. §5.3 |
10.3 Personnel
Only authorized Zeldoc personnel with a business need have access to systems that may contain personal data. Access to systems is logged, and technical logs are retained for 90 days. Zeldoc personnel are bound by confidentiality obligations, cf. GDPR Art. 28(3)(b) and the Danish Data Protection Act § 3.
11.Breach of Personal Data Security (Personal Data Breach)
11.1 Notification deadlines
Zeldoc informs the customer of a breach of personal data security that may affect customer data no later than 48 hours after discovery, so the customer can meet its obligation to notify the supervisory authority within 72 hours, cf. GDPR Art. 33.
11.2 Content of notification
The notification will contain, cf. GDPR Art. 33(3):
- Description of the breach and the data affected
- Likely consequences for data subjects
- Zeldoc's and the customer's remedial measures
- Contact details for further information
11.3 Documentation
Zeldoc documents all breaches of personal data security, including facts, consequences and remedial measures, cf. GDPR Art. 33(5).
12.EU AI Act
12.1 Risk classification
Zeldoc classifies the Platform's products in accordance with the EU AI Act (Regulation (EU) 2024/1689):
| Product | Risk category (preliminary) | Note |
|---|---|---|
| ZControl | Not an AI system | Administration tool, not an AI system in itself |
| ZCore | Limited risk | AI assistant - may be high risk depending on use case |
| ZDev | Limited risk | Development tool - may be high risk depending on use case |
| ZRouter | Not an AI system in itself | Routing infrastructure; the models it routes to are their providers' AI systems |
12.2 Updates
Zeldoc continuously updates its AI Act classification and documentation as parts of the AI Act enter into force (2025-2027).
13.International Data Transfers - Overview
| Product / Scenario | Data leaves EU? | Legal basis | Legislation |
|---|---|---|---|
| ZControl | No | Not applicable | GDPR Art. 44 ff - not applicable |
| ZCore + local/EU models | No | Not applicable | GDPR Art. 44 ff - not applicable |
| ZDev + local/EU models | No | Not applicable | GDPR Art. 44 ff - not applicable |
| ZRouter + local/EU models | No | Not applicable | GDPR Art. 44 ff - not applicable |
| ZRouter + external frontier models | YES ⚠️ | SCC + supplementary measures | GDPR Art. 46(2)(c), Schrems II |
| ZConnect (via ZRouter) | YES ⚠️ | SCC + supplementary measures | GDPR Art. 46(2)(c), Schrems II |
Certain operational services (CDN, CI/CD etc.) are provided by subprocessors that may be US companies - SCC 2021/914 and/or the EU-US Data Privacy Framework apply, cf. zeldoc.ai/subprocessors. Customer data is not processed by the operational subprocessors beyond transit/TLS termination and operational/security data (cf. the subprocessor list); core inference is executed in the EU.
This is a key difference from platforms that are domiciled in the USA, or where US infrastructure is integrated into the core products and third-country transfer is unavoidable.
14.Children's Data
The Platform is not directed at children and does not knowingly collect personal data about children under 16, cf. the Danish Data Protection Act § 6 and GDPR Art. 8. If we become aware that we have collected data about a child under 16, we delete that data.
15.Cookies and Tracking
Zeldoc only uses necessary cookies for the Platform's functionality (session cookies, CSRF protection). Zeldoc does not use:
- Marketing cookies
- Third-party analytics cookies (e.g. Google Analytics). Visitor numbers are measured without cookies, cf. section 15.1 below
- Tracking pixels
- Social media tracking
15.1 Visitor statistics (Plausible)
Zeldoc's public websites - zeldoc.ai and docs.zeldoc.ai - use Plausible Analytics to measure visitor numbers. Plausible was chosen precisely because it requires no consent:
- No cookies and no use of the browser's local storage or cache. Nothing is stored on your device, so the exemption in ePrivacy Directive Art. 5(3) is not needed - the provision is never triggered
- No persistent identifier, and no profiling or tracking across websites or sessions
- Your IP address is not stored. It is used only as input to a one-way hash together with a salt that is rotated and deleted every 24 hours, solely so that a visitor can be counted once per day. Neither the IP address nor the user agent is retained in raw form
- Data does not leave the EU. Plausible Insights OÜ is established in Tartu, Estonia, and visitor data is processed and stored in the EU (Falkenstein, Germany). There is therefore no third-country transfer and no need for SCCs or a transfer impact assessment
Only aggregated information is collected: page URL, referring URL, browser, operating system, device type and country derived from the IP address. No personally identifiable information is collected, and the statistics cannot be linked to a user, a customer account or an API key. The processing is based on Zeldoc's legitimate interest in understanding the use of its own websites, cf. GDPR Art. 6(1)(f); the balancing test favours Zeldoc because the interference is minimal when no identifiers are stored.
Plausible acts as a data processor for visitor data and a data processing agreement is in place, cf. GDPR Art. 28. Plausible is listed on the subprocessor page under Zeldoc's own tools, as it does not process Customer Data on the Customer's behalf. Plausible's own data policy is publicly available at plausible.io/data-policy.
Zeldoc's websites do not load fonts, scripts or other resources from third-party CDNs. Fonts are served from Zeldoc's own domain so that your IP address is not disclosed to, for example, Google Fonts on page load.
16.Changes to this Privacy Policy
Zeldoc may update this Privacy Policy due to legal requirements or changes in processing. Minor changes are published on the Platform. Material changes are notified to the customer in writing with 30 days' notice. The latest version is always available at zeldoc.ai/privacy.
17.Contact and Complaints
17.1 Contact Zeldoc
Zeldoc.ai ApS
17.2 Complaint to the supervisory authority
If a data subject is dissatisfied with Zeldoc's processing of personal data, a complaint may be lodged with:
Datatilsynet (Danish Data Protection Authority)
Cf. GDPR Art. 77 (right to lodge a complaint with a supervisory authority).