Legal

Privacy policy

Effective: 11 October 2026

This policy explains what personal data Pyzen collects through pyzen.app and in our sales conversations, why we collect it, and what you can ask us to do with it.

It does not cover data we process for our clients inside the automations we build and run for them. That work is governed by our contract with each client and our data processing agreement. There, the client decides what happens to the data, and we act on their instructions.

1. Who we are

Pyzen ("we", "us") is run by its founder. The legal entity is being formed, and its name, address and company number will be added here. Until then, the founder is the controller of the personal data described here.

For anything in this policy, contact hello@pyzen.app. A person reads that inbox, not a bot.

2. The short version

  • We set no cookies. No advertising pixels. No cross-site tracking.
  • If we count visits, we use Plausible, which does not identify you.
  • If you book a call, send the form, or email us, we use what you give us to reply and to run the conversation. Nothing else.
  • We do not sell your data, and we do not use it to train AI models.
  • You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Email hello@pyzen.app.

3. What we collect and why

Each activity below lists what we collect, why, our legal basis under the EU and UK GDPR, and how long we keep it.

3.1 When you visit the site

Visit statistics (only when switched on)

  • What: aggregate visit statistics: page, referrer, country, device type, and browser. Plausible counts daily visitors using a hash of your IP address and user agent, combined with a salt that is deleted every 24 hours. It stores no IP address and no identifier that follows you.
  • Why: to see which pages are useful and improve them.
  • Legal basis: Legitimate interests (Art. 6(1)(f))
  • How long: aggregate statistics only, kept while the site runs.

Server logs at our host, Cloudflare, Inc. (Cloudflare Pages)

  • What: IP address, time, page requested, and user agent, in Cloudflare's request logs.
  • Why: security, preventing abuse, and keeping the site running.
  • Legal basis: Legitimate interests
  • How long: Per Cloudflare's own log retention. We don't keep a separate copy.

Cookies

  • We set no cookies. Cloudflare may set a strictly necessary security cookie if it has to check that a visitor isn't a bot. It isn't used for tracking or advertising.

3.2 When you book a free call

  • What: name, work email, company, the time you chose, and anything you write in the booking notes. Online booking runs on Cal.com. If the calendar isn't available, you book by email instead.
  • Why: to schedule and run the call.
  • Legal basis: Steps at your request before a contract (Art. 6(1)(b)) or legitimate interests
  • How long: 24 months after our last contact, unless you become a client.

3.3 When you send the contact form or email us

  • What: name, work email, company, role (if given), and your message. The contact form doesn't send anything itself. It opens your own email app with a message to hello@pyzen.app, and you choose whether to send it.
  • Why: to reply and continue the conversation.
  • Legal basis: Steps at your request before a contract, or legitimate interests
  • How long: 24 months after our last contact, unless you become a client.

3.4 During the free call and scoping

  • What: notes about your business process: steps, systems, volumes, and costs. We ask you not to share customer personal data at this stage, and we use sample or redacted documents where we can.
  • Why: to estimate effort, cost, and return, and to quote.
  • Legal basis: Steps at your request before a contract, or legitimate interests
  • How long: 24 months after our last contact, unless you become a client.

3.5 When we research companies we might work with

  • What: business contact data from public sources (company websites, LinkedIn, press, and public registries): name, job title, company, work email, and business phone.
  • Why: to find people in roles our service fits, and contact them about it.
  • Legal basis: Legitimate interests. In the EU/UK, email marketing rules apply as well; see section 5.
  • How long: 12 months if there is no reply. Deleted immediately if you object.

3.6 When you become a client

  • What: contact and billing details for your company's contacts.
  • Why: to deliver the contract, invoice, and keep accounting records.
  • Legal basis: Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
  • How long: For the contract, then as long as tax and accounting law requires (usually 6–7 years)

We do not ask for, and do not want, special-category data (health, biometrics, beliefs, and so on) through the site.

4. Who we share it with

We use a small number of service providers. They process data for us under contract and may not use it for their own purposes.

Provider What they do for us
Cloudflare, Inc. (Cloudflare Pages) Hosts the website and keeps its request logs
Plausible Insights OÜ (EU) Privacy-friendly visit statistics, when switched on
Cal.com, Inc. Booking calendar, when online booking is available
Our business email provider Business email and documents
Our CRM tool Keeps track of conversations with prospects and clients

Ask hello@pyzen.app and we'll name our current email and CRM providers.

We will disclose data if the law requires it, or to protect our rights in a dispute. If Pyzen is sold or merged, data may pass to the new owner under this policy.

We do not sell personal data, and we do not "share" it for cross-context behavioral advertising, as California law defines those terms.

5. Business outreach

Pyzen is a business-to-business service. Sometimes we contact people at companies whose operations we think we can help with.

  • We only use work contact details, and we only contact people in relevant roles.
  • Every message tells you who we are and how to stop hearing from us. One reply saying "no" is enough.
  • If you object, we delete your details. We keep only a minimal suppression record (your email address), so we never contact you again.
  • Where the law requires your consent before we email you, we get it first, or we don't email you.

6. International transfers

Our providers may process data outside your country, including in the United States. When we transfer personal data out of the EU, UK or Switzerland, we rely on an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified) or on standard contractual clauses (and the UK Addendum) with the provider.

7. Security

We keep personal data in a small number of business systems. Access uses strong, unique passwords and two-factor authentication, and is limited to people who need it. No system is perfectly secure. If a breach affects your data and the law requires it, we will tell you and the regulator.

8. Your rights

Depending on where you live, you can ask us to:

  • tell you what data we hold about you, and give you a copy
  • correct it
  • delete it
  • restrict or object to how we use it (including any outreach, at any time)
  • send it to you or another company in a portable format

Email hello@pyzen.app. We reply within one month. We may need to confirm your identity first. We won't charge you, and we won't treat you differently for asking.

If you are in the EU or UK and you are unhappy with our answer, you can complain to your data protection authority. In the UK, that is the Information Commissioner's Office (ico.org.uk).

If you live in a US state with a consumer privacy law, you can use the rights that law gives you through the same email address.

9. Children

The site is for businesses. It is not aimed at anyone under 16, and we do not knowingly collect their data.

10. Changes

If we change this policy, we will update it here and change the effective date at the top. If a change is significant, we will say so on the site.

11. Contact

Pyzen · hello@pyzen.app