Zeldoc AI Platform - Privacy Policy
This document contains references to specific articles and sections of EU and Danish legislation. Each reference is accompanied by a brief explanation in parentheses. Full text of the legislation can be found at eur-lex.europa.eu (EU legislation) and retsinformation.dk (Danish legislation).
1.Introduction
Zeldoc.ai ApS ("Zeldoc", "we") is the data controller for the processing of personal data in connection with the Zeldoc AI Platform ("the Platform"). This Privacy Policy describes how we collect, process, store and protect personal data in accordance with:
- EU General Data Protection Regulation (GDPR) - Regulation (EU) 2016/679
- The Danish Data Protection Act
- EU AI Act - Regulation (EU) 2024/1689
- Other Danish legislation
Zeldoc.ai ApS
Zeldoc does not store customer prompts, documents or generated outputs in the solution. This is a fundamental principle of the Platform and is the reason Zeldoc does not enter into separate Data Processing Agreements (DPA) with each customer.
2.Zeldoc's Core Feature: EU Data Sovereignty
2.1 Data locality in core products
All personal data processed through the Platform's core products is processed and stored exclusively on servers within the European Union. Our infrastructure is currently located in Denmark and Germany.
For ZControl and for inference via ZCore, ZDev and ZRouter with local/EU-hosted models:
- No transfer of personal data to countries outside the EU/EEA
- No dependence on US cloud providers for data processing
- No access for US authorities under FISA, Section 702, Executive Order 12333 or similar schemes
- No need for Standard Contractual Clauses (SCCs) or transfer impact assessments, as data does not cross EU borders, cf. Schrems II judgment (C-311/18)
This is a fundamental difference from AI platforms that are US-resident or dependent on US cloud infrastructure.
2.2 EXCEPTION: ZRouter and external frontier models
ZRouter is Zeldoc's model routing layer. ZRouter can route inference requests to two types of models:
- Local/EU-hosted models - data stays in EU ✅
- External frontier models (e.g. Anthropic Claude, OpenAI GPT) - data leaves EU at inference ❌
When ZRouter directs inference to external frontier models - whether directly via ZRouter or via the ZConnect add-on - the customer's prompts and inference data leave the EU data region and are transferred to the external model provider's infrastructure (e.g. USA).
2.3 Data sovereignty matrix
| Product / Scenario | Data in EU? | Zero Data Retention? | GDPR third-country transfer? |
|---|---|---|---|
| ZControl - alone | Yes | Yes | No - not applicable |
| ZCore + local/EU models | Yes | Yes | No - not applicable |
| ZDev + local/EU models | Yes | Yes | No - not applicable |
| ZRouter + local/EU models | Yes | Yes | No - not applicable |
| ZRouter + external frontier models | No - data leaves EU | No - external provider policy | Yes - GDPR Art. 44-49 |
| ZConnect (via ZRouter) | No - data leaves EU | No - external provider policy | Yes - GDPR Art. 44-49 |
3.What Personal Data Do We Process?
3.1 Customer user data (Zeldoc as controller)
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Identification data | Name, email, phone, title | Account creation, administration | Contract (Art. 6(1)(b)) |
| Access data | Username, password (hashed), MFA secrets | Security and access control | Contract / Legitimate interest (Art. 6(1)(f)) |
| Usage data | Token usage, API calls, timestamps | Billing, capacity planning | Contract (Art. 6(1)(b)) |
| Billing data | VAT no., address, payment details | Billing, bookkeeping | Contract / Legal obligation (Art. 6(1)(c)) |
3.2 Customer data - prompts and outputs (Zeldoc does not store)
Prompts, documents and outputs that users submit or generate via the Platform may contain personal data. Zeldoc does not store this data in the solution. Zeldoc processes the customer's prompts and outputs only for the inference itself and deletes them immediately after. The customer is the data controller for the content of this data.
When customer data (prompts that may contain personal data) is sent through ZRouter to external frontier models, this personal data is transferred to a third country. The customer is the data controller and must ensure a legal basis for this transfer, cf. GDPR Art. 44-49. Zeldoc is the processor for participating in the transfer, but responsibility for the transfer itself rests with the customer, cf. §6.
3.3 Automatically collected data
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Technical data | IP address, browser type, OS | Security, troubleshooting | Legitimate interest (Art. 6(1)(f)) |
| Usage data | Login times, session duration | Security | Legitimate interest (Art. 6(1)(f)) |
| Cookies | Session cookies, functionality cookies | Platform functionality | Consent / Necessary (Art. 6(1)(a)/(f)) |
Zeldoc does not use tracking cookies, marketing cookies or third-party analytics cookies, cf. the ePrivacy Directive and the Danish cookie regulation.
4.Purpose of Processing
Zeldoc processes personal data for the following purposes:
- Service delivery - operation and maintenance of the Platform and Products
- Administration - user management, access control, billing
- Security - threat detection, incident response
- Compliance - meeting legal requirements, including the Bookkeeping Act and GDPR Art. 32-34
- Improvement - platform optimization and performance improvements (without using customer data for model training - see §7)
- Support - customer support and troubleshooting
5.Roles: Controller vs. Processor
5.1 Zeldoc as data controller
Zeldoc is the data controller for the following data, cf. GDPR Art. 4(7):
- Customer user and administration data (§3.1)
- Technical and usage data (§3.3)
- Billing data
5.2 Zeldoc as data processor
For customer data (prompts, documents, outputs, configurations) Zeldoc is the processor on behalf of the customer, who is the controller, cf. GDPR Art. 28. Zeldoc does not store customer data in the solution and processes it only to deliver the service, cf. this Privacy Policy.
5.3 Subprocessors
Zeldoc does not enter into separate sub-processor agreements with each customer, as Zeldoc does not store customer data in the solution. Zeldoc has a general sub-processor agreement that describes the categories of subprocessors Zeldoc uses to operate the Platform. The general sub-processor agreement can be read at zeldoc.ai/subprocessors.
External frontier model providers (e.g. Anthropic) are not subprocessors in the traditional sense. They are independent controllers or processors with their own legal basis and policies for the data they receive via ZRouter. See §6 for further description.
6.ZRouter and Third-Country Transfers
6.1 Data transfer to external model providers
When the customer uses ZRouter to route inference to external frontier models - directly or via ZConnect - prompts and inference data are transferred to external model providers outside the EU. The table below shows examples of external model providers and is not exhaustive:
| External provider | Model | Location | Transfer basis |
|---|---|---|---|
| Anthropic | Claude (family) | USA | SCC + supplementary measures |
| Gemini (family) | USA | SCC + supplementary measures | |
| OpenAI | ChatGPT (family) | USA | SCC + supplementary measures |
The table is indicative only and not exhaustive. The available portfolio of external model providers may change over time, and Zeldoc may add or remove providers at its discretion. The current and complete list is available in ZControl.
6.2 Legal basis for the transfer
The transfer to third countries via ZRouter/ZConnect is made using:
- Standard Contractual Clauses (SCCs) - the European Commission's standard clauses for transfers to third countries, cf. GDPR Art. 46(2)(c)
- Supplementary measures - encryption in transit (TLS 1.2+), data minimization, pseudonymization where possible
- Transfer Impact Assessment - Zeldoc has assessed the risks of transfer to the relevant provider, cf. Schrems II (C-311/18) and EDPB Recommendations 01/2020
6.3 Customer responsibility for transfers
The customer is the data controller for the personal data sent through ZRouter to external frontier models. The customer must:
- Ensure a legal basis for the processing itself (e.g. consent, contract, legitimate interest), cf. GDPR Art. 6
- Ensure a legal basis for the transfer to third countries, cf. GDPR Art. 44-49
- Inform data subjects about the transfer and the external recipient, cf. GDPR Art. 13/14
- Conduct a transfer impact assessment for specific use cases if required
- Refrain from sending special categories of personal data (health data, criminal offences, biometric data, etc.), cf. GDPR Art. 9, through external frontier models without separate assessment and explicit consent
- Document the transfer in its own procedures and records of processing activities, cf. GDPR Art. 30
6.4 Zeldoc's measures for ZRouter external calls
Zeldoc ensures:
- Access management via ZControl - ZRouter external calls can be restricted to specific users/roles
- Ability to disable external frontier models per user, per role or per organization
- Usage reporting separated from the core products
- Encryption of data in transit (TLS 1.2+) between EU infrastructure and external provider
6.5 Zero Data Retention for external calls
Zeldoc cannot guarantee Zero Data Retention for external frontier model providers. The external provider's own data retention policies apply. The customer is encouraged to consult the external provider's privacy policy. The following is an example of such a policy and is not exhaustive:
Anthropic (example): https://www.anthropic.com/legal/privacy
6.6 Separation in ZControl
ZControl clearly shows:
- Which models are local/EU-hosted vs. external frontier models
- Whether a call has left the EU or not (data sovereignty indicator)
7.Use of Data for Model Training
7.1 Core products: no model training on customer data
Zeldoc does not use customer data (prompts, documents, outputs) to train, fine-tune or improve AI models in core products. Zeldoc does not store customer data. This is a critical difference from several US AI platforms.
7.2 Telemetry and platform improvement
Zeldoc collects aggregated, anonymized telemetry data (e.g. response times, error rates, general usage) to improve the Platform's performance and stability. This data does not contain customer data or personal data, cf. GDPR Art. 4(5) (anonymization).
7.3 Explicit consent
If Zeldoc wishes to use customer data for model improvement in the future, this will require explicit, separate and voluntary consent from the customer, as well as a separate agreement, cf. GDPR Art. 7.
7.4 External model providers
Zeldoc has no control over whether external frontier model providers (e.g. Anthropic) use the customer's prompts for model training. The customer should consult the external provider's policies. Where possible, Zeldoc will prefer providers that offer Zero Data Retention / no-training agreements.
8.Retention and Deletion
8.1 Retention periods
| Data category | Retention period | Reason | Legislation |
|---|---|---|---|
| User accounts | Active subscription period + 30 days | Customer service, data export | GDPR Art. 5(1)(e) |
| Customer data (prompts/outputs) | Not stored (Zero Data Retention) | Zeldoc does not store customer data | GDPR Art. 5(1)(c) (data minimization) |
| Billing data | 5 years | Bookkeeping obligation | Bookkeeping Act § 10 |
| Security logs | 90 days | Security management | GDPR Art. 32 |
8.2 Deletion on termination
On termination of the subscription:
- Customer data (prompts/outputs) is not stored and therefore requires no deletion
- User accounts are deleted after 30 days from termination
- Billing data is retained in accordance with the Bookkeeping Act
Zeldoc deletes data in accordance with GDPR Art. 17 (right to erasure) and the Danish Data Protection Act § 4.
8.3 Customer's right to deletion
The customer may at any time request deletion of specific user data via ZControl. Zeldoc fulfills the request within 30 days, cf. GDPR Art. 17.
Zeldoc cannot delete data sent to external model providers via ZRouter. Deletion requests for data at external providers must be addressed directly to the provider by the customer. Zeldoc can assist with contact details.
9.Data Subject Rights
As Zeldoc is both a controller (for user data) and a processor (for customer data), different rights apply:
9.1 For user data (Zeldoc as controller)
Data subjects (users) have the following rights, cf. GDPR Art. 12-22:
| Right | GDPR article | How |
|---|---|---|
| Right of access | Art. 15 | Request to [email protected] |
| Right to rectification | Art. 16 | Via ZControl or [email protected] |
| Right to erasure ("right to be forgotten") | Art. 17 | Via ZControl or [email protected] |
| Restriction of processing | Art. 18 | Request to [email protected] |
| Data portability | Art. 20 | Export via ZControl (JSON/CSV) |
| Right to object | Art. 21 | Request to [email protected] |
| Right not to be subject to automated decisions | Art. 22 | N/A - the Platform does not make autonomous decisions with legal effect |
Zeldoc responds to requests without undue delay and no later than 1 month after receipt, cf. GDPR Art. 12(3).
9.2 For customer data (customer as controller)
For customer data, the customer is the controller. Enquiries from data subjects about customer data (prompts, outputs, documents) should be addressed to the customer, not to Zeldoc. Zeldoc assists the customer in fulfilling such requests where technically possible, cf. GDPR Art. 28(3)(e).
For data sent to external model providers via ZRouter, the external provider's own process for data subject rights applies. Zeldoc cannot guarantee fulfillment of GDPR rights for data at external providers.
10.Security Measures
Zeldoc has implemented technical and organizational measures in accordance with GDPR Art. 32:
10.1 Technical measures
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all data transfer - including to external model providers |
| Access control | Role-Based Access Control (RBAC) via ZControl |
| Authentication | Multi-Factor Authentication (MFA) supported |
| Key management | HSM-based key management, rotation every 90 days |
| Network security | Isolated networks, firewall, IDS/IPS |
| Vulnerability scanning | Weekly automated scanning + quarterly penetration testing |
10.2 Organizational measures
| Measure | Implementation |
|---|---|
| Access policy | Need-to-know, least-privilege |
| Security training | Annual training of all personnel with data access |
| Incident response | Documented plan, tested annually |
| Subprocessors | General sub-processor agreement, cf. §5.3 |
10.3 Personnel
Only authorized Zeldoc personnel with a business need have access to systems that may contain personal data. All access is logged. Zeldoc personnel are bound by confidentiality obligations, cf. GDPR Art. 28(3)(b) and the Danish Data Protection Act § 3.
11.Data Breach (Personal Data Breach)
11.1 Notification deadlines
Zeldoc informs the customer of a personal data breach that may affect customer data no later than 48 hours after discovery, so the customer can meet its obligation to notify the supervisory authority within 72 hours, cf. GDPR Art. 33.
11.2 Content of notification
The notification will contain, cf. GDPR Art. 33(3):
- Description of the breach and the data affected
- Likely consequences for data subjects
- Zeldoc's and the customer's remedial measures
- Contact details for further information
11.3 Documentation
Zeldoc documents all personal data breaches, including facts, consequences and remedial measures, cf. GDPR Art. 33(5).
12.EU AI Act
12.1 Risk classification
Zeldoc classifies the Platform's products in accordance with the EU AI Act (Regulation (EU) 2024/1689):
| Product | Risk category (preliminary) | Note |
|---|---|---|
| ZControl | Limited risk | Administration tool, not an AI system in itself |
| ZCore | Limited risk | AI assistant - may be high risk depending on use case |
| ZDev | Limited risk | Development tool - may be high risk depending on use case |
| ZRouter | Limited risk | Routing infrastructure |
12.2 Customer responsibility under the AI Act
The customer is responsible for classifying its specific use of the Platform in accordance with the AI Act. If the customer's use constitutes a high-risk AI system (e.g. AI systems for recruitment, credit assessment, biometric identification), cf. AI Act Art. 6 and Annex I/III, the customer must:
- Conduct a conformity assessment, cf. AI Act Art. 43
- Implement risk management, cf. AI Act Art. 9
- Ensure transparency and information to users, cf. AI Act Art. 13
- Establish human oversight, cf. AI Act Art. 14
- Ensure accuracy, robustness and cybersecurity, cf. AI Act Art. 15
- Maintain technical documentation, cf. AI Act Art. 11-12
12.3 Zeldoc's obligations under the AI Act
Zeldoc as provider of the Platform must, to the extent the Platform constitutes an AI system:
- Document the Platform's technical characteristics and risks
- Cooperate with the customer on AI Act compliance
- Inform the customer of known risks and limitations of the Platform
- Implement post-market monitoring, cf. AI Act Art. 72
12.4 Updates
Zeldoc continuously updates its AI Act classification and documentation as parts of the AI Act enter into force (2025-2027).
13.International Data Transfers - Overview
| Product / Scenario | Data leaves EU? | Legal basis | Legislation |
|---|---|---|---|
| ZControl | No | Not applicable | GDPR Art. 44 ff - not applicable |
| ZCore + local/EU models | No | Not applicable | GDPR Art. 44 ff - not applicable |
| ZDev + local/EU models | No | Not applicable | GDPR Art. 44 ff - not applicable |
| ZRouter + local/EU models | No | Not applicable | GDPR Art. 44 ff - not applicable |
| ZRouter + external frontier models | YES ⚠️ | SCC + supplementary measures | GDPR Art. 46(2)(c), Schrems II |
| ZConnect (via ZRouter) | YES ⚠️ | SCC + supplementary measures | GDPR Art. 46(2)(c), Schrems II |
This is a key difference from platforms where US infrastructure is integrated into the core products and third-country transfer is unavoidable.
14.Children's Data
The Platform is not directed at children and does not knowingly collect personal data about children under 16, cf. the Danish Data Protection Act § 6 and GDPR Art. 8. If we become aware that we have collected data about a child under 16, we delete that data.
15.Cookies and Tracking
Zeldoc only uses necessary cookies for the Platform's functionality (session cookies, CSRF protection). Zeldoc does not use:
- Marketing cookies
- Third-party analytics cookies (e.g. Google Analytics)
- Tracking pixels
- Social media tracking
A cookie statement is available on the Platform's login page, cf. the Danish cookie regulation and the ePrivacy Directive Art. 5(3).
16.Changes to this Privacy Policy
Zeldoc may update this Privacy Policy due to legal requirements or changes in processing. Minor changes are published on the Platform. Material changes are notified to the customer in writing with 30 days' notice. The latest version is always available at zeldoc.ai/privacy.
17.Contact and Complaints
17.1 Contact Zeldoc
Zeldoc.ai ApS
17.2 Complaint to the supervisory authority
If a data subject is dissatisfied with Zeldoc's processing of personal data, a complaint may be lodged with:
Datatilsynet (Danish Data Protection Authority)
Cf. GDPR Art. 77 (right to lodge a complaint with a supervisory authority).
Contact