Privacy Policy

Zeldoc AI Platform - Privacy Policy

Version 1.2 · August 2026

Note on legal references

This document contains references to specific articles and sections of EU and Danish legislation. Each reference is accompanied by a brief explanation in parentheses. Full text of the legislation can be found at eur-lex.europa.eu (EU legislation) and retsinformation.dk (Danish legislation).

1.Introduction

Zeldoc.ai ApS ("Zeldoc", "we") is the data controller for the processing of personal data in connection with the Zeldoc AI Platform ("the Platform"). This Privacy Policy describes how we collect, process, store and protect personal data in accordance with:

  • EU General Data Protection Regulation (GDPR) - Regulation (EU) 2016/679
  • The Danish Data Protection Act
  • EU AI Act - Regulation (EU) 2024/1689
  • Other Danish legislation

Zeldoc.ai ApS

CVR no.: 46329902
Address: Åboulevarden 69, 8000 Aarhus C, Denmark
Data controller: Zeldoc.ai ApS
DPO contact: [email protected]

Zeldoc does not store customer prompts, documents or generated outputs in the solution. This is a fundamental principle of the Platform and is the reason Zeldoc does not enter into separate Data Processing Agreements (DPA) with each customer.

2.Zeldoc's Core Feature: EU Data Sovereignty

2.1 Data locality in core products

All personal data processed through the Platform's core products is processed and stored exclusively on servers within the European Union. Our infrastructure is currently located in Denmark and Germany.

For ZControl and for inference via ZCore, ZDev and ZRouter with local/EU-hosted models:

  • No transfer of personal data to countries outside the EU/EEA
  • No dependence on US cloud providers for data processing
  • No access for US authorities under FISA, Section 702, Executive Order 12333 or similar schemes
  • No need for Standard Contractual Clauses (SCCs) or transfer impact assessments, as data does not cross EU borders, cf. Schrems II judgment (C-311/18)

This is a fundamental difference from AI platforms that are US-resident or dependent on US cloud infrastructure.

2.2 EXCEPTION: ZRouter and external frontier models

The only exception to the EU data sovereignty principle - and it is material

ZRouter is Zeldoc's model routing layer. ZRouter can route inference requests to two types of models:

  • Local/EU-hosted models - data stays in EU
  • External frontier models (e.g. Anthropic Claude, OpenAI GPT) - data leaves EU at inference

When ZRouter directs inference to external frontier models - whether directly via ZRouter or via the ZConnect add-on - the customer's prompts and inference data leave the EU data region and are transferred to the external model provider's infrastructure (e.g. USA).

2.3 Data sovereignty matrix

Product / ScenarioData in EU?Zero Data Retention?GDPR third-country transfer?
ZControl - aloneYesYesNo - not applicable
ZCore + local/EU modelsYesYesNo - not applicable
ZDev + local/EU modelsYesYesNo - not applicable
ZRouter + local/EU modelsYesYesNo - not applicable
ZRouter + external frontier modelsNo - data leaves EUNo - external provider policyYes - GDPR Art. 44-49
ZConnect (via ZRouter)No - data leaves EUNo - external provider policyYes - GDPR Art. 44-49

3.What Personal Data Do We Process?

3.1 Customer user data (Zeldoc as controller)

CategoryExamplesPurposeLegal basis
Identification dataName, email, phone, titleAccount creation, administrationContract (Art. 6(1)(b))
Access dataUsername, password (hashed), MFA secretsSecurity and access controlContract / Legitimate interest (Art. 6(1)(f))
Usage dataToken usage, API calls, timestampsBilling, capacity planningContract (Art. 6(1)(b))
Billing dataVAT no., address, payment detailsBilling, bookkeepingContract / Legal obligation (Art. 6(1)(c))

3.2 Customer data - prompts and outputs (Zeldoc does not store)

Prompts, documents and outputs that users submit or generate via the Platform may contain personal data. Zeldoc does not store this data in the solution. Zeldoc processes the customer's prompts and outputs only for the inference itself and deletes them immediately after. The customer is the data controller for the content of this data.

Important regarding external frontier models

When customer data (prompts that may contain personal data) is sent through ZRouter to external frontier models, this personal data is transferred to a third country. The customer is the data controller and must ensure a legal basis for this transfer, cf. GDPR Art. 44-49. Zeldoc is the processor for participating in the transfer, but responsibility for the transfer itself rests with the customer, cf. §6.

3.3 Automatically collected data

CategoryExamplesPurposeLegal basis
Technical dataIP address, browser type, OSSecurity, troubleshootingLegitimate interest (Art. 6(1)(f))
Usage dataLogin times, session durationSecurityLegitimate interest (Art. 6(1)(f))
CookiesSession cookies, functionality cookiesPlatform functionalityConsent / Necessary (Art. 6(1)(a)/(f))

Zeldoc does not use tracking cookies, marketing cookies or third-party analytics cookies, cf. the ePrivacy Directive and the Danish cookie regulation.

4.Purpose of Processing

Zeldoc processes personal data for the following purposes:

  • Service delivery - operation and maintenance of the Platform and Products
  • Administration - user management, access control, billing
  • Security - threat detection, incident response
  • Compliance - meeting legal requirements, including the Bookkeeping Act and GDPR Art. 32-34
  • Improvement - platform optimization and performance improvements (without using customer data for model training - see §7)
  • Support - customer support and troubleshooting

5.Roles: Controller vs. Processor

5.1 Zeldoc as data controller

Zeldoc is the data controller for the following data, cf. GDPR Art. 4(7):

  • Customer user and administration data (§3.1)
  • Technical and usage data (§3.3)
  • Billing data

5.2 Zeldoc as data processor

For customer data (prompts, documents, outputs, configurations) Zeldoc is the processor on behalf of the customer, who is the controller, cf. GDPR Art. 28. Zeldoc does not store customer data in the solution and processes it only to deliver the service, cf. this Privacy Policy.

5.3 Subprocessors

Zeldoc does not enter into separate sub-processor agreements with each customer, as Zeldoc does not store customer data in the solution. Zeldoc has a general sub-processor agreement that describes the categories of subprocessors Zeldoc uses to operate the Platform. The general sub-processor agreement can be read at zeldoc.ai/subprocessors.

External frontier model providers

External frontier model providers (e.g. Anthropic) are not subprocessors in the traditional sense. They are independent controllers or processors with their own legal basis and policies for the data they receive via ZRouter. See §6 for further description.

6.ZRouter and Third-Country Transfers

6.1 Data transfer to external model providers

When the customer uses ZRouter to route inference to external frontier models - directly or via ZConnect - prompts and inference data are transferred to external model providers outside the EU. The table below shows examples of external model providers and is not exhaustive:

External providerModelLocationTransfer basis
AnthropicClaude (family)USASCC + supplementary measures
GoogleGemini (family)USASCC + supplementary measures
OpenAIChatGPT (family)USASCC + supplementary measures

The table is indicative only and not exhaustive. The available portfolio of external model providers may change over time, and Zeldoc may add or remove providers at its discretion. The current and complete list is available in ZControl.

6.2 Legal basis for the transfer

The transfer to third countries via ZRouter/ZConnect is made using:

  • Standard Contractual Clauses (SCCs) - the European Commission's standard clauses for transfers to third countries, cf. GDPR Art. 46(2)(c)
  • Supplementary measures - encryption in transit (TLS 1.2+), data minimization, pseudonymization where possible
  • Transfer Impact Assessment - Zeldoc has assessed the risks of transfer to the relevant provider, cf. Schrems II (C-311/18) and EDPB Recommendations 01/2020

6.3 Customer responsibility for transfers

The customer is the data controller for the personal data sent through ZRouter to external frontier models. The customer must:

  • Ensure a legal basis for the processing itself (e.g. consent, contract, legitimate interest), cf. GDPR Art. 6
  • Ensure a legal basis for the transfer to third countries, cf. GDPR Art. 44-49
  • Inform data subjects about the transfer and the external recipient, cf. GDPR Art. 13/14
  • Conduct a transfer impact assessment for specific use cases if required
  • Refrain from sending special categories of personal data (health data, criminal offences, biometric data, etc.), cf. GDPR Art. 9, through external frontier models without separate assessment and explicit consent
  • Document the transfer in its own procedures and records of processing activities, cf. GDPR Art. 30

6.4 Zeldoc's measures for ZRouter external calls

Zeldoc ensures:

  • Access management via ZControl - ZRouter external calls can be restricted to specific users/roles
  • Ability to disable external frontier models per user, per role or per organization
  • Usage reporting separated from the core products
  • Encryption of data in transit (TLS 1.2+) between EU infrastructure and external provider

6.5 Zero Data Retention for external calls

Zeldoc cannot guarantee Zero Data Retention for external frontier model providers. The external provider's own data retention policies apply. The customer is encouraged to consult the external provider's privacy policy. The following is an example of such a policy and is not exhaustive:

Anthropic (example): https://www.anthropic.com/legal/privacy

6.6 Separation in ZControl

ZControl clearly shows:

  • Which models are local/EU-hosted vs. external frontier models
  • Whether a call has left the EU or not (data sovereignty indicator)

7.Use of Data for Model Training

7.1 Core products: no model training on customer data

Zeldoc does not use customer data (prompts, documents, outputs) to train, fine-tune or improve AI models in core products. Zeldoc does not store customer data. This is a critical difference from several US AI platforms.

7.2 Telemetry and platform improvement

Zeldoc collects aggregated, anonymized telemetry data (e.g. response times, error rates, general usage) to improve the Platform's performance and stability. This data does not contain customer data or personal data, cf. GDPR Art. 4(5) (anonymization).

7.3 Explicit consent

If Zeldoc wishes to use customer data for model improvement in the future, this will require explicit, separate and voluntary consent from the customer, as well as a separate agreement, cf. GDPR Art. 7.

7.4 External model providers

Zeldoc has no control over whether external frontier model providers (e.g. Anthropic) use the customer's prompts for model training. The customer should consult the external provider's policies. Where possible, Zeldoc will prefer providers that offer Zero Data Retention / no-training agreements.

8.Retention and Deletion

8.1 Retention periods

Data categoryRetention periodReasonLegislation
User accountsActive subscription period + 30 daysCustomer service, data exportGDPR Art. 5(1)(e)
Customer data (prompts/outputs)Not stored (Zero Data Retention)Zeldoc does not store customer dataGDPR Art. 5(1)(c) (data minimization)
Billing data5 yearsBookkeeping obligationBookkeeping Act § 10
Security logs90 daysSecurity managementGDPR Art. 32

8.2 Deletion on termination

On termination of the subscription:

  • Customer data (prompts/outputs) is not stored and therefore requires no deletion
  • User accounts are deleted after 30 days from termination
  • Billing data is retained in accordance with the Bookkeeping Act

Zeldoc deletes data in accordance with GDPR Art. 17 (right to erasure) and the Danish Data Protection Act § 4.

8.3 Customer's right to deletion

The customer may at any time request deletion of specific user data via ZControl. Zeldoc fulfills the request within 30 days, cf. GDPR Art. 17.

External frontier models

Zeldoc cannot delete data sent to external model providers via ZRouter. Deletion requests for data at external providers must be addressed directly to the provider by the customer. Zeldoc can assist with contact details.

9.Data Subject Rights

As Zeldoc is both a controller (for user data) and a processor (for customer data), different rights apply:

9.1 For user data (Zeldoc as controller)

Data subjects (users) have the following rights, cf. GDPR Art. 12-22:

RightGDPR articleHow
Right of accessArt. 15Request to [email protected]
Right to rectificationArt. 16Via ZControl or [email protected]
Right to erasure ("right to be forgotten")Art. 17Via ZControl or [email protected]
Restriction of processingArt. 18Request to [email protected]
Data portabilityArt. 20Export via ZControl (JSON/CSV)
Right to objectArt. 21Request to [email protected]
Right not to be subject to automated decisionsArt. 22N/A - the Platform does not make autonomous decisions with legal effect

Zeldoc responds to requests without undue delay and no later than 1 month after receipt, cf. GDPR Art. 12(3).

9.2 For customer data (customer as controller)

For customer data, the customer is the controller. Enquiries from data subjects about customer data (prompts, outputs, documents) should be addressed to the customer, not to Zeldoc. Zeldoc assists the customer in fulfilling such requests where technically possible, cf. GDPR Art. 28(3)(e).

External frontier models

For data sent to external model providers via ZRouter, the external provider's own process for data subject rights applies. Zeldoc cannot guarantee fulfillment of GDPR rights for data at external providers.

10.Security Measures

Zeldoc has implemented technical and organizational measures in accordance with GDPR Art. 32:

10.1 Technical measures

MeasureImplementation
Encryption in transitTLS 1.2+ for all data transfer - including to external model providers
Access controlRole-Based Access Control (RBAC) via ZControl
AuthenticationMulti-Factor Authentication (MFA) supported
Key managementHSM-based key management, rotation every 90 days
Network securityIsolated networks, firewall, IDS/IPS
Vulnerability scanningWeekly automated scanning + quarterly penetration testing

10.2 Organizational measures

MeasureImplementation
Access policyNeed-to-know, least-privilege
Security trainingAnnual training of all personnel with data access
Incident responseDocumented plan, tested annually
SubprocessorsGeneral sub-processor agreement, cf. §5.3

10.3 Personnel

Only authorized Zeldoc personnel with a business need have access to systems that may contain personal data. All access is logged. Zeldoc personnel are bound by confidentiality obligations, cf. GDPR Art. 28(3)(b) and the Danish Data Protection Act § 3.

11.Data Breach (Personal Data Breach)

11.1 Notification deadlines

Zeldoc informs the customer of a personal data breach that may affect customer data no later than 48 hours after discovery, so the customer can meet its obligation to notify the supervisory authority within 72 hours, cf. GDPR Art. 33.

11.2 Content of notification

The notification will contain, cf. GDPR Art. 33(3):

  • Description of the breach and the data affected
  • Likely consequences for data subjects
  • Zeldoc's and the customer's remedial measures
  • Contact details for further information

11.3 Documentation

Zeldoc documents all personal data breaches, including facts, consequences and remedial measures, cf. GDPR Art. 33(5).

12.EU AI Act

12.1 Risk classification

Zeldoc classifies the Platform's products in accordance with the EU AI Act (Regulation (EU) 2024/1689):

ProductRisk category (preliminary)Note
ZControlLimited riskAdministration tool, not an AI system in itself
ZCoreLimited riskAI assistant - may be high risk depending on use case
ZDevLimited riskDevelopment tool - may be high risk depending on use case
ZRouterLimited riskRouting infrastructure

12.2 Customer responsibility under the AI Act

The customer is responsible for classifying its specific use of the Platform in accordance with the AI Act. If the customer's use constitutes a high-risk AI system (e.g. AI systems for recruitment, credit assessment, biometric identification), cf. AI Act Art. 6 and Annex I/III, the customer must:

  • Conduct a conformity assessment, cf. AI Act Art. 43
  • Implement risk management, cf. AI Act Art. 9
  • Ensure transparency and information to users, cf. AI Act Art. 13
  • Establish human oversight, cf. AI Act Art. 14
  • Ensure accuracy, robustness and cybersecurity, cf. AI Act Art. 15
  • Maintain technical documentation, cf. AI Act Art. 11-12

12.3 Zeldoc's obligations under the AI Act

Zeldoc as provider of the Platform must, to the extent the Platform constitutes an AI system:

  • Document the Platform's technical characteristics and risks
  • Cooperate with the customer on AI Act compliance
  • Inform the customer of known risks and limitations of the Platform
  • Implement post-market monitoring, cf. AI Act Art. 72

12.4 Updates

Zeldoc continuously updates its AI Act classification and documentation as parts of the AI Act enter into force (2025-2027).

13.International Data Transfers - Overview

Product / ScenarioData leaves EU?Legal basisLegislation
ZControlNoNot applicableGDPR Art. 44 ff - not applicable
ZCore + local/EU modelsNoNot applicableGDPR Art. 44 ff - not applicable
ZDev + local/EU modelsNoNot applicableGDPR Art. 44 ff - not applicable
ZRouter + local/EU modelsNoNot applicableGDPR Art. 44 ff - not applicable
ZRouter + external frontier modelsYES ⚠️SCC + supplementary measuresGDPR Art. 46(2)(c), Schrems II
ZConnect (via ZRouter)YES ⚠️SCC + supplementary measuresGDPR Art. 46(2)(c), Schrems II

This is a key difference from platforms where US infrastructure is integrated into the core products and third-country transfer is unavoidable.

14.Children's Data

The Platform is not directed at children and does not knowingly collect personal data about children under 16, cf. the Danish Data Protection Act § 6 and GDPR Art. 8. If we become aware that we have collected data about a child under 16, we delete that data.

15.Cookies and Tracking

Zeldoc only uses necessary cookies for the Platform's functionality (session cookies, CSRF protection). Zeldoc does not use:

  • Marketing cookies
  • Third-party analytics cookies (e.g. Google Analytics)
  • Tracking pixels
  • Social media tracking

A cookie statement is available on the Platform's login page, cf. the Danish cookie regulation and the ePrivacy Directive Art. 5(3).

16.Changes to this Privacy Policy

Zeldoc may update this Privacy Policy due to legal requirements or changes in processing. Minor changes are published on the Platform. Material changes are notified to the customer in writing with 30 days' notice. The latest version is always available at zeldoc.ai/privacy.

17.Contact and Complaints

17.1 Contact Zeldoc

Zeldoc.ai ApS

Email (DPO): [email protected]
Address: Åboulevarden 69, 8000 Aarhus C, Denmark
CVR: 46329902

17.2 Complaint to the supervisory authority

If a data subject is dissatisfied with Zeldoc's processing of personal data, a complaint may be lodged with:

Datatilsynet (Danish Data Protection Authority)

Landemærket 13, 2nd floor
1119 Copenhagen K

Cf. GDPR Art. 77 (right to lodge a complaint with a supervisory authority).