Legal document
Privacy Policy
Last updated: July 2026 · Version 1.0
1. Data Controller
The data controller for personal data collected through zoprio.com and the Zoprio platform is:
Name: Petrut Romeo Paul
NIF (Tax ID): Y3944273V
Address: Carrer Del Barranc 5, 46016 Valencia, Spain
Contact email: support@zoprio.app
2. What Data We Collect and Why
We collect the minimum data necessary to provide the service. The following table details the data processed, its purpose, and the legal basis:
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Full name | Account holder identification | Art. 6.1.b — contract performance |
| Email address | Account access, service notifications, subscription communications | Art. 6.1.b — contract performance |
| Password (hashed) | Secure authentication | Art. 6.1.b — contract performance |
| Business name | Subdomain configuration and public page | Art. 6.1.b — contract performance |
| Timezone and language | Correct display of schedules and communications | Art. 6.1.b — contract performance |
| Logo and cover image | Personalisation of the business's public page | Art. 6.1.b — contract performance |
| Business physical address | Display location link in booking confirmation emails to clients | Art. 6.1.b — contract performance |
| IP address | Security, fraud prevention, and aggregated statistics | Art. 6.1.f — legitimate interest |
| Billing data (managed by Stripe) | Subscription payment processing | Art. 6.1.b — contract performance |
Zoprio does not sell personal data to third parties or use it for advertising or commercial profiling purposes.
3. End-Client Data
When a business uses Zoprio, it enters data about its own clients into the platform (name, email, phone, notes, booking history, date of birth, etc.).
Regarding this data:
- The business (Zoprio user) is the Data Controller and decides what data is collected and for what purpose.
- Zoprio acts as the Data Processor and only processes this data to provide the contracted service.
- Zoprio does not access this data except as required for the correct operation of the platform (sending automated emails, reminders, business reports, etc.).
- The business can export all their client data in CSV format from the dashboard at any time.
- When the account is deleted, all end-client data is permanently deleted from Zoprio's servers.
The business is responsible for informing their end-clients about the use of Zoprio to manage their bookings and data, and for having the appropriate legal basis for such processing.
5. Storage and Security
Data is stored on secure servers within the European Union. Security measures applied include:
- Password encryption using one-way hash algorithms (bcrypt)
- Encrypted communications via HTTPS/TLS on all connections
- JWT tokens with expiry for session authentication
- Restricted database access with secure credentials
- Automatic database backups
- Strict multi-tenancy: each business can only access its own data
In the event of a security breach affecting personal data, Zoprio will notify affected users and the Spanish Data Protection Agency (AEPD) within the timeframe established by the GDPR (72 hours from becoming aware of the incident).
6. Sharing Data with Third Parties
Zoprio uses the following service providers who may have access to data in the context of service delivery:
- Railway (railway.app) — backend server and PostgreSQL database hosting. EU infrastructure.
- Vercel (vercel.com) — frontend and public pages hosting.
- Resend (resend.com) — transactional email delivery service (booking confirmations, reminders, etc.).
- Cloudinary (cloudinary.com) — image storage and processing (business logos and cover images).
- Stripe (stripe.com) — payment processor for subscription billing. Stripe manages payment data independently under its own privacy policy.
- Google AI — the platform's AI assistant uses Google's models to process queries made to the assistant. Queries are sent anonymously and are not linked to identifying business data.
All providers have been selected for offering adequate data protection guarantees in compliance with the GDPR. We do not share data with third parties for advertising or marketing purposes.
7. International Data Transfers
Some of the providers mentioned above (Vercel, Resend, Cloudinary, Stripe, Google AI) may process data on servers outside the European Economic Area. In these cases, we ensure that transfers take place with appropriate safeguards, in particular through:
- Standard Contractual Clauses approved by the European Commission
- Provider adherence to the EU-US Data Privacy Framework (where applicable)
8. Data Retention
| Data type | Retention period |
|---|---|
| Business account data | Duration of the contract and up to 3 months after cancellation |
| End-client data | While the business has an active account; deleted when the account is deleted |
| Billing records | 5 years (legal tax obligation in Spain) |
| System logs (IPs) | Maximum 12 months |
| AI assistant conversations | While the business has an active account; deleted when the account is deleted |
9. Your Rights
Under the GDPR, you have the right to:
- Access: know what personal data we hold about you
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your data ("right to be forgotten")
- Restriction: request that we restrict processing of your data
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interest
You can exercise these rights by writing to support@zoprio.app. We will respond within a maximum of 30 days.
You may also lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es if you consider that your rights have not been duly addressed.
Self-service from the dashboard
Most rights can be exercised directly from the Zoprio dashboard:
- Rectification: edit your details in Settings → Business Information
- Portability: export all your client data as CSV from the Customers section
- Erasure: permanently delete your account from Settings → Delete Account
10. Changes to This Policy
Zoprio may update this Privacy Policy. When changes are significant, registered users will be notified by email at least 15 days in advance.
The date of the last update always appears at the top of this document.
11. Contact
For any questions regarding privacy or the processing of your data:
Email: support@zoprio.app
Postal address: Carrer Del Barranc 5, 46016 Valencia, Spain