Privacy Notice
ZenShield · Enterprise Security Digital Platform
The short version: we don't use your data — we protect it. Your records stay in your workspace, are never sold or used for AI training, and are handled in line with GDPR and the Philippine Data Privacy Act (NPC).
Your data is yours
Every record your team creates on this platform — visitor logs, incidents, patrols, compliance assessments, designs — belongs to your organization. We do not sell it, share it with advertisers, or use it to train AI models. Ever.
Strict tenant isolation
Your workspace is isolated from every other organization on the platform at the application layer and the database layer. The one deliberate exception is the Community Blacklist, where an entry your managers explicitly submit is shared — after moderation, without revealing your organization's identity.
AI that stays inside
GAIA, the built-in assistant, answers only from your own records and the shared security knowledge library, under the asking user's own permissions. Conversations are logged for your administrators, budgeted, and never used to train models. When an external model provider is configured, only the minimum context needed to answer is sent, and blacklist photos never leave the platform.
Biometric data (face matching)
Face matching applies only to photos deliberately submitted with a Community Blacklist report. Each photo is analyzed once, on self-hosted infrastructure operated for this platform — never a third-party cloud — and stored as a numeric template (an embedding), not as facial geometry a person could be reconstructed from. Templates are used solely for advisory blacklist comparison, are never shared or used for training, and are deleted immediately when a report is rejected, withdrawn, or expires. Photo searches are not stored: the probe image is discarded after the comparison, and every search is recorded in the audit trail. All results are advisory — the platform never automatically denies anyone entry.
GDPR & NPC alignment
The platform is designed to operate in line with the EU General Data Protection Regulation (GDPR) and the Philippine Data Privacy Act of 2012 (RA 10173) under the National Privacy Commission (NPC): lawful basis for processing, purpose limitation, data minimization, retention limits with automatic purging, and security measures including encryption in transit, hashed credentials, role-based access, and full audit trails.
Your rights
Data subjects can request access, correction, or erasure of their personal data through your organization's administrator, who can export or delete records from the platform. Organizations can export their complete data set at any time and take it with them when they leave.
Retention
Operational records are retained per your organization's configured retention windows and then purged. Records that must be kept — open incidents, evidence attached to an active compliance program, or anything under legal hold — are never silently deleted.
Questions or data subject requests: contact your organization's administrator or privacy@zenshield.app.
This notice summarizes the platform's data practices; your organization's own privacy policy governs its use of the platform.