How we collect, process, and protect your personal information
At Z360.AI, we take the protection of your personal data seriously. This privacy policy informs you about which personal data we collect and process when you visit our website, register for our service, and use our platform as a customer (restaurant owner or operator). It also informs you about your rights under the General Data Protection Regulation (GDPR).
This policy concerns the processing of data of our customers, prospects, and website visitors, for which Z360.AI is the data controller. For the personal data of our customers' end customers (guests) that is processed via our platform in the course of WhatsApp chats and phone calls, the respective customer (restaurant) is the controller; in this respect Z360.AI acts solely as a processor under Art. 28 GDPR on the basis of the Data Processing Agreement (DPA).
The controller within the meaning of the GDPR is:
Z360.AI (owner: Alper Koyuncu)
Konrad-Adenauer-Str. 4
93077 Bad Abbach, Germany
Phone: +49 941 942 230 52
Email: info@z360.ai
For data protection inquiries, you can reach us at privacy@z360.ai.
Depending on your use, we process the following categories of personal data about you as a customer, prospect, or website visitor:
First and last name, salutation, and the username or identifier of your account used during registration.
Email address, telephone number, and the master data of the business you create on our platform – in particular restaurant name, address, telephone number, email address, and an optionally uploaded logo. This data is stored in our database in order to manage the account and provide the service.
Login credentials for your user account. Passwords are stored exclusively in encrypted or hashed form via our authentication service (Supabase Auth); we have no access to your password in plain text. We also process the role and permission assignments of your account.
To process paid use, we process billing-related data. The actual payment processing is carried out by our payment service provider Stripe (see the section "Payment Processing via Stripe"). Full payment data – such as credit card numbers or bank details for SEPA direct debits – is entered directly with Stripe and is not stored by us. In our database we only store the Stripe customer ID, the subscription ID, the billing or subscription status, and usage-based billing data (e.g., the volume of AI and telephony services used).
Information about how you use our platform and services, including usage-based consumption data (e.g., the number of voice calls and the volume of AI usage), which we evaluate for billing and to improve the service.
IP address, login data, browser type and version, time zone setting and location, operating system and platform, time of access, and protocol/log data generated when accessing our website and platform.
When you call our telephone number, you are assisted by an AI-powered voice agent. In this context we process your telephone number and the content of the conversation, including a recording and/or transcript, in order to handle your request. For details, see the section "Phone Calls with Our AI Voice Agent".
If you use our live remote support and start the remote assistance application (RustDesk) offered on our support page, we process the data required to establish the connection – in particular the device/client ID, the session password, your IP address, the device name, operating system information, and connection and log data. During an active session, the transmitted screen content as well as mouse and keyboard inputs are also processed. For details, see the section "Remote Support via Remote Assistance (RustDesk)".
We only process your personal data insofar as this is legally permitted. The main purposes and the respective legal basis under Art. 6 GDPR are:
Our customers' data – in particular account, contract, and business data – is stored in a database that we operate with the infrastructure provider Supabase Inc. Supabase processes this data exclusively on our behalf and on the basis of a data processing agreement.
Access to this data is restricted to those persons who need it to provide and administer the service (need-to-know principle). We take appropriate technical and organizational measures to protect the data against unauthorized access, loss, or alteration.
To process paid services, we use the payment service provider Stripe. The provider for customers in the European Economic Area is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
Depending on your selection, credit card, SEPA direct debit, and PayPal are available as payment methods. Payment data is entered directly in a secure environment provided by Stripe (Stripe Checkout). We do not receive or store full card or account details; Stripe only transmits to us a customer ID, a subscription ID, and the payment or billing status.
Stripe processes the personal data arising in the payment process as an independent controller in order to carry out the payment and to prevent fraud and abuse. The legal basis for transmitting the data required for payment to Stripe is the performance of the contract (Art. 6(1)(b) GDPR). Further information on data processing by Stripe can be found in Stripe's privacy policy at https://stripe.com/privacy.
When you call our business telephone number, your calls are answered and handled by an AI-powered voice agent. In doing so, we process your telephone number and the content of the conversation, including a recording and/or transcript. In this respect, Z360.AI is the controller within the meaning of the GDPR.
The purpose of the processing is to receive and handle your request, answer inquiries, initiate and perform contractual relationships, and ensure the quality of our customer service. The legal basis is the performance of pre-contractual or contractual measures (Art. 6(1)(b) GDPR) as well as our legitimate interest in efficient and high-quality telephone availability (Art. 6(1)(f) GDPR).
To operate the AI voice agent, we use the service provider ElevenLabs, Inc., USA, which performs the voice processing (speech recognition and speech synthesis) on our behalf as a processor. The telephone connection is established via the telephony provider Twilio Ireland Ltd., Ireland. Insofar as personal data is transferred to a third country (in particular the USA) in this context, we base such transfers on the EU Commission's Standard Contractual Clauses (Art. 46 GDPR).
We store the recordings and transcripts of your phone calls for a maximum of ninety (90) days and then delete them automatically and irreversibly, unless statutory retention obligations apply. The content of your conversations is not used to train or improve AI models.
On our support page, we offer you the option of downloading a free remote assistance application for Windows based on the open-source software RustDesk. This allows us to provide you with live assistance at your request: after your explicit approval, a support employee can temporarily see your screen and, with your consent, make inputs on your device.
When you start the application, the following data is processed in order to establish the connection: a randomly generated device/client ID, a session password, your IP address, the device name and operating system information, as well as connection and log data (e.g., time and duration of the session). During an active session, screen content as well as mouse and keyboard inputs are also transmitted; if you use the chat function, its content as well. Which information becomes visible depends on what is displayed on your screen during the session.
A remote assistance session is only established if you start the application yourself and actively share the displayed ID and password with us. You can see what is happening during the session at all times and can end the connection at any time by disconnecting the session or closing the application. Permanent or unattended access to your device is not possible; once the session has ended, no access remains. The application does not need to be installed and can simply be deleted after the session. We do not record the session.
The connection is established exclusively via a RustDesk server (ID and relay server) that we operate ourselves, and it is transmitted in encrypted form. This server is hosted by DigitalOcean, LLC in a data center in Frankfurt am Main, Germany; no data is transmitted to the public RustDesk servers. Insofar as a third-country connection (USA) cannot be ruled out in the context of hosting by DigitalOcean, we base the transfer on the EU Commission's Standard Contractual Clauses (Art. 46 GDPR).
The legal basis for the processing is the performance of the contract or the implementation of pre-contractual measures (Art. 6(1)(b) GDPR) as well as our legitimate interest in providing efficient and customer-friendly support (Art. 6(1)(f) GDPR). Connection and log data is stored only for as long as is necessary for the operation and security of the service and is then deleted.
On our website www.z360.ai we use the TikTok Pixel – exclusively after your explicit consent via our cookie banner ("Marketing" category). The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, together with TikTok Information Technologies UK Limited, Kaleidoscope, 6 Bell Yard, London, WC2A 2JR, United Kingdom (together "TikTok").
The TikTok Pixel allows us to measure the success of our ads on TikTok (conversion tracking), to show visitors of our website ads on TikTok again (retargeting) and to build audiences for our advertising. When the pixel is loaded, information such as your IP address, device and browser information, the page visited, the time of the visit and a pseudonymous identifier stored in a cookie ("_ttp") is transmitted to TikTok. In addition, we transmit certain interaction events without content, e.g. that a product or pricing page was viewed, a button such as "Book a demo" or "Register" was clicked, or a demo or registration form was successfully submitted; the data entered into the forms itself is not transmitted to TikTok. If you are logged in to TikTok at the same time, TikTok may associate this information with your TikTok account. When you submit the demo or registration form, we additionally transmit the e-mail address you entered and – for registrations – your phone number to TikTok in hashed form (so-called manual Advanced Matching). Hashing is performed with SHA-256 directly in your browser; the plain-text data is not transmitted to TikTok. TikTok uses the hash values solely to match them against the hash values of its own user accounts in order to improve the attribution of conversions to ads. Names, restaurant name or message contents are not transmitted to TikTok.
In addition to the transmission by the pixel in your browser, we also transmit the "form submitted" event for the demo and registration forms from our server to TikTok (TikTok Events API). This includes the same hashed contact data, your IP address, the browser identifier (user agent), the page address, an event ID and – where available – the TikTok click ID (ttclid) and the pixel identifier (_ttp). The event ID ensures that TikTok counts the browser and server events as a single event. The purpose is more reliable measurement, e.g. when the pixel is blocked by browser settings. This server-side transmission also takes place only if you have consented to the "Marketing" category.
The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Without your consent the pixel is not loaded and no data is transmitted to TikTok. You can withdraw your consent at any time with effect for the future via the "Cookie settings" link in the footer of our website; the pixel is then paused and the cookies it has set are deleted. The lawfulness of the processing carried out until withdrawal remains unaffected.
For the collection of data on our website and its transmission to TikTok we are jointly responsible with TikTok (Art. 26 GDPR); the joint controllership agreement forms part of the TikTok Business Products Terms (Joint Controller Addendum). TikTok is solely responsible for the subsequent processing. In this context, data may be transferred to countries outside the European Economic Area, in particular the USA and Singapore; TikTok bases these transfers on the EU Commission's Standard Contractual Clauses (Art. 46 GDPR). The cookies set by the pixel have a lifetime of up to 13 months. Further information can be found in TikTok's privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en and in our Cookie Policy.
To provide our service, we use carefully selected service providers that process personal data on our behalf. For the processing of your account, contract, and billing data these are in particular:
• Supabase Inc., USA – database and authentication services
• Vercel Inc., USA – hosting infrastructure
• Stripe Payments Europe, Limited, Ireland – payment processing (independent controller; see above)
• Twilio Ireland Ltd., Ireland – telephony for inbound calls
• ElevenLabs, Inc., USA – AI voice agent for phone calls
• ZeptoMail (Zoho Corporation), USA/India – sending of transactional and notification emails
• DigitalOcean, LLC, USA – hosting of our self-operated RustDesk server for remote support (server location: Frankfurt am Main, Germany)
A complete overview of the sub-processors that we use to process the end-customer or guest data of our customers can be found in the Data Processing Agreement (DPA).
Some of the service providers we use are located in or process data outside the European Union, in particular in the USA. Insofar as personal data is transferred to a third country in this context, we ensure an adequate level of data protection through appropriate safeguards – in particular the EU Commission's Standard Contractual Clauses under Art. 46 GDPR.
This also applies to the TikTok Pixel used on our website only after your consent; details can be found in the section "Advertising and Reach Measurement on Our Website: TikTok Pixel".
We store your personal data only for as long as is necessary for the purposes stated. Account and contract data is stored for the duration of the contractual relationship. After the contract ends, we delete or anonymize the data, insofar as no statutory retention obligations apply. Invoice- and accounting-relevant data is retained in accordance with the applicable tax- and commercial-law periods (generally up to ten years).
Recordings and transcripts of phone calls with our AI voice agent are stored for a maximum of ninety (90) days and are then deleted automatically and irreversibly (see the section "Phone Calls with Our AI Voice Agent").
We have put in place appropriate technical and organizational security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered, or disclosed. Access to your personal data is limited to those employees, agents, and contractors who have a business need to know.
We have put in place procedures to deal with any suspected personal data breach and will notify you and the competent supervisory authority of a breach where we are legally required to do so.
Subject to the legal requirements, you have the following rights in relation to your personal data:
If you have any questions about this privacy policy or our privacy practices, or if you wish to exercise your rights, please contact us: