Legal

Privacy Policy

Last updated: 15 June 2026

This policy explains what personal data Zentria collects, why we collect it, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR).

1. Who we are

Zentria is a CRM service operated by:

Happy Cloud Studio Sp. z o.o.
Ul. Grzybowska 87
00-844 Warszawa, Poland
NIP: 5272786566
Email: zentriacrm@happycloudstudio.com

Happy Cloud Studio Sp. z o.o. is the data controller for personal data we collect about you as a Zentria user (your account, billing, support correspondence, and similar). For personal data that you upload into your workspace (your own customers, contacts, deals, and notes), we act as a data processor on your behalf and you remain the controller. The terms governing that relationship are set out in our Data Processing Agreement.

Privacy contact: Franco Toccu, reachable at zentriacrm@happycloudstudio.com.

2. Scope of this policy

This policy applies to:

It does not apply to third-party websites you reach through links from Zentria. Those have their own policies.

3. Information we collect

3.1 Account information

When you create an account: your name, email address, hashed password, language preference, and the role you hold in your workspace (Owner or Sales Rep). When an Owner invites a colleague, the same information is collected for that colleague.

3.2 Workspace content

The CRM data you choose to enter: your customers' contact details, deals, notes, tasks, attachments, and any tags or comments you write. We process this on your instructions as part of providing the service. You own it; we do not use it for any other purpose.

3.3 Usage and technical data

Standard server logs collected automatically: IP address, browser type, pages requested, and timestamps. We use this for security, abuse prevention, and to keep the service running. Logs are retained for up to 90 days.

3.4 Communications

If you write to us (support email, contact form, replies to product emails), we keep the message and our reply so we can follow up and improve the service.

3.5 Billing information

Once paid plans launch, billing details (company name, billing address, VAT number, invoice history) will be collected. Card and bank details are handled by our payment processor and never reach our servers.

3.6 Website analytics

On our public website (zentriacrm.com) we run our own privacy-first, cookieless analytics to understand how visitors find and use the site. We do not set cookies, we do not use local storage, and we do not create any cross-site or persistent identifier. We do not store your raw IP address or user-agent: they are used only momentarily to compute a daily-rotating, non-reversible visitor count, then discarded. We record only aggregate, non-identifying information such as the page visited, the referring website, an approximate location (country and region), a coarse device and browser type, and any campaign tag in the link you followed. There is no third-party advertising or analytics tracker. The authenticated app is never tracked this way.

3.7 Cookies

We use a small number of cookies, all strictly necessary to keep you signed in and to remember your language preference. See our Cookies notice for the full list.

4. Why we use your data, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Provide the Zentria service to you and your team Performance of a contract (Art. 6(1)(b))
Keep the service secure and prevent abuse Legitimate interest (Art. 6(1)(f))
Send transactional emails (signup confirmation, password reset, invoice, service notices) Performance of a contract (Art. 6(1)(b))
Issue invoices and keep tax records Legal obligation (Art. 6(1)(c)), Polish Accounting Act
Respond to your support requests Legitimate interest (Art. 6(1)(f))
Measure how our public website is used, with cookieless, anonymous analytics Legitimate interest (Art. 6(1)(f)); no cookie or device storage, so no Art. 5(3) ePrivacy consent is required
Send product news or offers (if and when we add this) Consent (Art. 6(1)(a)), opt-in only

We do not sell your data, we do not share it with advertisers, and we do not profile you or run automated decisions that produce legal effects.

5. How long we keep it

6. Who we share it with

We use a small number of trusted service providers (sub-processors) to operate Zentria. Each is bound by a written data processing agreement and processes data only on our instructions.

ProviderPurposeLocation of processing
Supabase Inc. Database, authentication, file storage Frankfurt, Germany (EU)
Cloudflare, Inc. Web hosting, CDN, application edge runtime, DDoS protection Global edge network, configured for EU data residency where supported
Brevo (Sendinblue SAS) Transactional email delivery (signup confirmation, password reset, account notices, website contact-form notifications) France, EU
Revolut Bank UAB Payment processing for paid subscriptions Lithuania, EU
Crisp IM SAS Live-chat customer support widget (website and in-app), including the chat messages and contact details you provide European Union (Netherlands and Germany)

We do not share your personal data with any third party for their own marketing purposes.

7. International data transfers

Your data is primarily processed within the European Economic Area (EEA). Some of our sub-processors are based in the United States (Cloudflare and Supabase as a corporate entity). For any transfer of personal data outside the EEA, we rely on the European Commission's Standard Contractual Clauses and, where appropriate, on adequacy decisions and supplementary technical measures, as required by Chapter V of the GDPR.

8. Your rights

Under the GDPR you have the following rights regarding your personal data:

To exercise any of these rights, email zentriacrm@happycloudstudio.com. We will respond within one month, as required by the GDPR. We may extend this by up to two further months for complex requests, in which case we will tell you within the first month.

If you are a contact in someone else's Zentria workspace (for example, our customer added your name to their CRM), the workspace owner is the controller of your personal data and is the right first point of contact. We will support them in handling your request, and you may also contact us directly if you prefer.

9. Security

We take security seriously. Measures we apply include:

No system is perfectly secure. If you believe an account has been compromised, contact us immediately.

10. Children

Zentria is a business tool. It is not intended for children. By creating an account you confirm you are at least 18 years old and acting on behalf of a business.

11. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date at the top. For material changes, we will notify you by email or through the app before they take effect.

12. Complaints

We hope you will come to us first so we can put things right. You also have the right to lodge a complaint with the Polish Data Protection Authority:

Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2
00-193 Warszawa, Poland
Web: uodo.gov.pl

If you reside in another EU country, you may also complain to the supervisory authority of your country of residence.

13. Contact

Questions about this policy or about how we handle your data:

Happy Cloud Studio Sp. z o.o.
Ul. Grzybowska 87, 00-844 Warszawa, Poland
Privacy contact: Franco Toccu
Email: zentriacrm@happycloudstudio.com