Privacy policy
This policy explains what personal data Aethergrid SRLS handles when you visit talkzen.io or use the Talkzen platform, why we handle it, and what you can require of us. It is written to be read, not to be survived.
01Who is responsible for your data
The data controller is Aethergrid SRLS, a company registered in Italy under VAT number IT06439890655, which operates the Talkzen service and the talkzen.io website.
For anything in this policy — questions, complaints, or a request to exercise your rights — write to privacy@talkzen.io. We answer within 30 days, and usually much sooner.
Two different roles matter here, and confusing them causes most of the confusion about SaaS privacy. For your own account data — your name, your email, your billing — we are the controller. For the conversations your customers have with your Talkzen agent, you are the controller and we are only the processor: we handle that data on your instructions and for no purpose of our own.
02What we collect
We collect three kinds of data, and nothing beyond them:
| Category | What it contains | Where it comes from |
|---|---|---|
| Account data | Name, work email, company name, password hash, language preference, plan. | You, when you register. |
| Billing data | Billing address, VAT number, invoice history, last four digits and card brand. | You and our payment processor. We never see or store a full card number. |
| Usage data | Pages viewed, features used, conversation counts, error logs, IP address, browser and device type. | Automatically, as you use the site and the platform. |
When you write to us through the contact form we also keep your name, email, company, the message itself, and the IP address the message came from. The IP is kept only to make the form rate limit work and to investigate abuse.
We do not ask for and do not want special categories of data — health, beliefs, political opinions, biometrics. Please do not put them in a support ticket.
03Why we process it, and on what legal basis
Every processing operation needs a lawful basis under Article 6 GDPR. Ours are:
- To provide the service (contract, Art. 6(1)(b)). Creating your account, running your agents, delivering messages, invoicing you, answering your support requests. Without this data there is no service.
- To keep the service safe and working (legitimate interest, Art. 6(1)(f)). Rate limiting, fraud and abuse detection, error diagnosis, capacity planning, aggregate product analytics. We have weighed this against your interests and kept the data minimal and short-lived.
- To meet legal duties (Art. 6(1)(c)). Invoices and accounting records that Italian law requires us to retain.
- With your consent (Art. 6(1)(a)). Non-essential cookies, and marketing email. You can withdraw consent at any time, and withdrawing it is as easy as giving it.
We do not make decisions about you by automated means that produce legal effects, and we do not profile you for advertising.
04Data your customers send through the platform
When one of your customers messages your Talkzen agent, that conversation is your data, not ours. We store and process it solely to deliver the service you asked for.
Concretely, that means: we do not read your conversations except when you ask us to for support and grant access; we do not sell them; and we do not use them to train models that any other customer benefits from. Your content trains nothing outside your own account.
As the controller of that data, you are responsible for having a lawful basis to collect it and for telling your own customers what happens to it. A data processing agreement covering our side is available on request and is included by default in Enterprise contracts.
05Who else touches the data
We use a small number of sub-processors, each bound by a contract with GDPR-compliant terms:
- Hosting and infrastructure providers, in the European Union, that run our servers and databases.
- A payment processor that handles card details, so that we never receive them.
- A transactional email provider, for password resets, notifications and the contact form.
- The messaging platforms you choose to connect — WhatsApp, Meta, Telegram and the rest — which necessarily receive the messages you route through them, under their own terms.
The current list, with names and locations, is available at privacy@talkzen.io. We do not sell personal data to anyone, and we never have.
06Where the data is stored
Account data, billing data and conversation content are stored on servers located in the European Union.
Some sub-processors may process limited data outside the EEA. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision, and we keep the data involved to what the service genuinely needs.
07How long we keep it
| Data | Retention |
|---|---|
| Account data | While your account is open, then 30 days after closure. |
| Conversation content | While your account is open, or the shorter period you configure. Deleted within 30 days of account closure. |
| Invoices and accounting | Ten years, as article 2220 of the Italian Civil Code requires. |
| Server and security logs | 12 months. |
| Contact form messages | 24 months, or until you ask us to delete them. |
| Contact form IP addresses | One hour, for rate limiting only. |
When a period ends the data is deleted or irreversibly anonymised. Backups roll over on their own schedule and are fully cycled within 90 days.
08Sharing with third parties
Beyond the sub-processors listed above, we disclose personal data only when we are legally compelled by a valid order from a competent authority, when it is necessary to establish or defend a legal claim, or when a merger or acquisition transfers the business — in which case you would be told before anything changed, and the same protections would follow the data.
We do not share data with advertising networks or data brokers.
09How we protect it
Security is a set of practices, not a badge. Ours include:
- TLS 1.2 or better on every connection, with HTTP strictly redirected to HTTPS.
- Encryption at rest for databases and backups.
- Passwords stored only as salted hashes, never in a form we can reverse.
- Access to production limited to named staff who need it, with individual credentials and multi-factor authentication.
- Application databases and internal services bound to the local interface and unreachable from the public internet.
- Logged administrative access, and regular patching of the operating system and dependencies.
If a breach ever puts your rights at risk, we will notify the Garante per la protezione dei dati personali, the Italian supervisory authority, within 72 hours and tell you directly without undue delay.
10Your rights
Under the GDPR you can require us to:
- Give you access to the personal data we hold about you, and a copy of it.
- Correct anything inaccurate or incomplete.
- Delete your data, where we have no overriding obligation to keep it.
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
- Port your data to another provider in a structured, machine-readable format.
- Object to processing based on our legitimate interest, including any profiling.
- Withdraw consent at any time, without affecting what was lawful before you withdrew it.
Write to privacy@talkzen.io and we will act within 30 days. There is no charge unless a request is manifestly unfounded or repetitive.
If you think we have got it wrong, you can complain to the Garante per la protezione dei dati personali (www.garanteprivacy.it) or to the supervisory authority where you live. We would rather you told us first, but it is your right either way.
11Cookies
The site sets strictly necessary cookies and local storage entries to remember your language and your cookie choice. Analytics and marketing cookies are switched off until you turn them on, and you can change your mind from the link in the footer at any time.
The full list, with names and durations, is in the cookie policy.
12Children
Talkzen is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to privacy@talkzen.io and we will delete it.
13Changes to this policy
If we change this policy we will update the date at the top of the page. When a change materially affects your rights, we will tell account holders by email at least 30 days before it takes effect, so you have time to object or to leave.
Questions about any of this: privacy@talkzen.io, or the contact form.