This Privacy Policy describes how FORTITUDO VINCIT SRL (“ZED-ZEN”, “we”) collects, uses and protects your personal data across all our platforms (zed-zen.com, app.zed-zen.com, radio.zed-zen.com, pulse.zed-zen.com, meniu.zed-zen.com), in accordance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679).
1. Data controller
FORTITUDO VINCIT SRL CUI (Tax ID): 43990858 | Trade Reg. No.: J2021000522266 Registered office: București, Romania Legal representative: Mantello Alexandru Lucian DPO email: [email protected] Phone: +40 757 314 021
2. ZED-ZEN’s role in data processing
ZED-ZEN acts as:
- Data controller — for users’ authentication data (email, encrypted password), contact data (contact form, event registrations), technical data (browsing, IP, analytics) and billing data
- Processor — for Clients’ Business Data (recipes, prices, statistics, reviews, playlists, employee information, etc.), where the Client remains the Controller
3. Personal data collected
The categories of data collected vary depending on the platform used:
3.1 Data common to all platforms
- Identification and contact data — name, email, phone, job title, company
- Authentication data — email, encrypted password (bcrypt/argon2)
- Technical data — IP address, browser type, operating system, device type, screen resolution
- Browsing data — pages visited, session duration, traffic source (via Google Analytics 4)
- Cookie data — consent preferences, language, theme (details in the Cookie Policy)
3.2 Data specific to ZED-ZEN App
- Company data (name, CUI/tax ID, address, bank details)
- Business data (recipes, ingredients, costs, prices, suppliers, menus)
- Delivery data (orders, Bolt/Glovo/Wolt platform statistics)
- Reviews and replies (Google, TripAdvisor)
- Product photos (AI-generated)
3.3 Data specific to Radio by ZED-ZEN
- Location data (name, address, audio settings)
- Playlists and music preferences
- Advertising spots (text, TTS-generated audio)
- Playback and monitoring statistics
3.4 Data specific to Pulse by ZED-ZEN
- Waiter data (name, photo, assigned location)
- Customer reviews (rating, comment, timestamp)
- Scan data (visitor IP, user agent — anonymised)
- Performance statistics per waiter
3.5 Data specific to Meniu Digital
- Menu content (products, prices, descriptions, images)
- Order data (selected products, value)
- Menu visitor analytics (pages viewed, time spent)
4. Purpose and legal basis of processing
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the contracted SaaS services | Art. 6(1)(b) — performance of a contract |
| Responding to enquiries (contact form) | Art. 6(1)(b) — pre-contractual measures |
| Event registration | Art. 6(1)(b) — performance of a contract |
| Payment processing (Stripe) | Art. 6(1)(b) — performance of a contract |
| Sending service notifications and alerts | Art. 6(1)(f) — legitimate interest |
| Web traffic analysis (Google Analytics) | Art. 6(1)(a) — user consent |
| AI features (text, photo and TTS spot generation) | Art. 6(1)(b) — performance of a contract |
| Platform security and fraud prevention | Art. 6(1)(f) — legitimate interest |
| Operation of essential cookies | Art. 6(1)(f) — legitimate interest |
| Legal and tax compliance | Art. 6(1)(c) — legal obligation |
5. Data recipients (Sub-processors)
Personal data may be shared with the following service providers:
| Provider | Service | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | EU (AWS eu-west-1, eu-central-1) |
| Amazon Web Services (AWS) | Cloud infrastructure (via Supabase) | EU |
| Railway Corp. | Application hosting (Radio, Pulse) | USA (Google Cloud, SCC) |
| Stripe Inc. | Payment processing, invoicing | EU / USA (DPF) |
| OpenAI LLC | AI features (text generation, TTS spots, AI chat) | USA (SCC, max. 30 days retention) |
| Google LLC (Gemini AI) | AI features (content generation) | USA (DPF, data is NOT used for training) |
| Google LLC (Analytics) | Web traffic analysis (Google Analytics 4) | USA (DPF, SCC) |
| Resend Inc. | Sending transactional emails and alerts | USA (SCC) |
| Web3Forms | Contact form processing | USA |
| Cybot A/S (Cookiebot) | Cookie consent management | EU (Denmark) |
| Cloudflare Inc. | CDN, DDoS protection, DNS | Global (DPF, SCC) |
| Public authorities | When we are legally required | Romania / EU |
Important: We do not sell or transfer your personal data to third parties for marketing purposes. Data sent to AI services (OpenAI, Google Gemini) does not contain identifiable personal data — we send only business content (texts, product descriptions).
6. International data transfers
Data is stored predominantly in the EU (Supabase on AWS EU). Transfers to the USA are carried out on the basis of:
- EU-US Data Privacy Framework (DPF) — for certified providers (Google, Stripe, Cloudflare)
- Standard Contractual Clauses (SCC) — approved by the European Commission, for the other providers
- Supplementary measures — data encryption, data minimisation, transfer impact assessments (TIA)
7. Data retention period
- Account/authentication data — for the lifetime of the active account + 30 days after deletion
- Business Data — for the duration of the contract + a 90-day recovery period
- Contact form data — maximum 2 years from the last interaction
- Google Analytics data — 14 months (per the GA4 settings)
- Security logs — 12 months
- API data (OpenAI) — max. 30 days, not used for training
- Accounting/tax data — 10 years (legal obligation, Romanian legislation)
- Cookies — according to the durations in the Cookie Policy
- Aggregated/anonymised data — may be kept indefinitely (does not constitute personal data)
8. Your rights (under the GDPR)
You have the following rights regarding your personal data:
- Right of access (Art. 15) — to obtain a copy of the personal data processed
- Right to rectification (Art. 16) — to correct inaccurate or incomplete data
- Right to erasure (Art. 17) — “the right to be forgotten”
- Right to restriction (Art. 18) — to limit processing in certain situations
- Right to data portability (Art. 20) — to receive the data in a structured, commonly used and machine-readable format
- Right to object (Art. 21) — to object to processing based on legitimate interest
- Right not to be subject to automated decisions (Art. 22) — including profiling
- Right to withdraw consent — at any time, without affecting the lawfulness of prior processing
To exercise your rights, contact us at [email protected]. We will respond within 30 calendar days. Exercising your rights is free of charge.
9. Data security
We implement appropriate technical and organisational measures:
Technical measures
- Encrypted communications (HTTPS/TLS on all platforms)
- Passwords stored encrypted (bcrypt/argon2 — never stored in plain text)
- Data separation between clients (Row Level Security — Supabase)
- Automatic daily backups
- Continuous system monitoring
- Firewall and DDoS protection (Cloudflare)
Organisational measures
- Access restricted on a “need-to-know” basis
- Internal data security policies
- Periodic risk assessments
- Notification procedures in the event of a data breach
10. Data breach notification
In accordance with Art. 33 and 34 GDPR, in the event of a security breach:
- ANSPDCP will be notified within a maximum of 72 hours
- Affected individuals will be notified without undue delay
- Clients (B2B) will be notified within a maximum of 24 hours
11. Right to lodge a complaint
If you believe your rights have been infringed, you have the right to lodge a complaint with the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — the Romanian National Supervisory Authority for Personal Data Processing:
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București Phone: +40 318 059 211 Email: [email protected] Website: www.dataprotection.ro
12. Changes to this policy
We reserve the right to update this policy. For significant changes, we will notify users by email and/or an in-platform notice at least 30 days in advance. The current version will always be available on this page, with the date of the last update stated at the top.
13. Contact
FORTITUDO VINCIT SRL CUI (Tax ID): 43990858 | Trade Reg. No.: J2021000522266 Email: [email protected] Phone: +40 757 314 021 București, Romania Website: zed-zen.com