LAST UPDATED: 23.08.2026
This document is a draft based on common practice and on how the panel actually works. It is reviewed by the seller's lawyer before it takes effect.
This document explains which data is collected when you use the Zensyno SEO panel, why it is processed, on which legal basis, with whom it is shared, how long it is kept and how you exercise your rights.
The company is established in Montenegro. Because part of our users are resident in the European Union, this document is written to be compliant with the General Data Protection Regulation (GDPR).
1. DATA CONTROLLER
| Company name | Zensyno Digital Performance Agency D.O.O |
|---|---|
| Tax number | 03759172 |
| Registration number | 5 - 1314094 / 001 |
| Address | 50 Hercegovacka, Podgorica, Montenegro, 81000 |
| Phone | +90 850 241 90 38 |
| info@zensyno.com |
For the data relating to the account you open on the panel and to your usage records, the controller is the company named above.
2. CONTROLLER AND PROCESSOR ROLES
- When it comes to your account, your billing, your sign-in records and the security of the panel, we are the controller; we determine the purpose and the means of that data.
- When you enter data into the panel on behalf of your own customers (the domains you track, the people you report on, the contact details you upload) you are the controller and we are the processor acting on your instructions.
- In that second case the obligations between the parties are set out in a separate document: the Data Processing Addendum.
3. DATA COLLECTED
- Account data: name, e-mail address, an irreversible hash of the password, workspace name and user role.
- Invoice and payment records: plan name, amount, currency, payment status and the transaction reference returned by the payment provider.
- Business data you enter into the dashboard: the domains you track, keywords, projects, reports and documents.
- Data read from the accounts you connect: query, click, impression and traffic measurements for the Search Console and Analytics properties you authorise.
- Usage records: login time, IP address, browser information and records of actions taken in the dashboard.
- Support correspondence: the messages and attachments you send us by e-mail.
The card number, expiry date and security code never reach our server; that information is processed and stored only on the Paddle.com Market Limited side.
We do not collect special categories of personal data and we ask you not to enter such data into the panel.
4. PURPOSES OF PROCESSING AND LEGAL BASES
| Purpose | Legal basis |
|---|---|
| Opening your account, keeping your session, applying your permissions and providing the plan you purchased | Performance of the contract |
| Taking the payment, keeping the invoice record and renewing the subscription | Performance of the contract and legal obligation |
| Running ranking, keyword and link measurements and producing your reports | Performance of the contract |
| Connecting your Search Console and Analytics account and reading data from it | Your explicit consent (you can remove the connection at any time) |
| Preventing abuse and investigating error and security events | Legitimate interest |
| Sending mandatory service notices and support replies | Performance of the contract |
| Sending commercial messages | Your explicit consent |
| Keeping financial records for the period required by law | Legal obligation |
Where we rely on legitimate interest, we weigh our interest against your rights and share the outcome of that assessment on request.
5. SEARCH CONSOLE AND ANALYTICS CONNECTION
- You set up the connection yourself and grant access only for the properties you select.
- The access we receive is limited to reading measurement data; we make no changes on your site or in your account.
- You can remove the connection from your account screen at any time; once removed, no new data is read.
- Data read through the connection is visible only inside your own workspace.
6. PAYMENT DATA
Payments are taken by Paddle.com Market Limited as merchant of record. Your payment method, billing address and tax details are processed on the Paddle side. Only the amount, currency, status and transaction number of the payment come back to us.
7. SUBPROCESSORS AND RECIPIENTS
| Provider | Why it is used | Data transferred |
|---|---|---|
| Paddle.com Market Limited | Taking the payment, issuing the invoice, renewing the subscription and processing refunds. | Name, e-mail address, billing details, the payment method itself and transaction records. |
| Cloudflare | Hosting the panel, database and file storage, attack and abuse filtering. | All data entered into the panel together with technical records of requests (IP address, browser information). |
| DataForSEO | Running ranking, keyword and link measurements. | The domain, keyword, country and language to be measured. The account holder's identity details are not sent. |
| Sending notification and support e-mails, reading data from the Search Console and Analytics accounts you authorise, running the text generating features. | Recipient e-mail address and message content, measurement data of the properties you connect, the text submitted for generation. | |
| Sentry | Collecting fault records and fixing errors. | Error message, request address and technical context. Personal fields are masked before they are sent. |
Your data is not sold or transferred to third parties for marketing purposes. Upon a lawful request from a competent authority, data may be shared limited to the scope of that request.
The current list of subprocessors and the notice procedure applied when an addition is made to that list are explained in the Data Processing Addendum.
8. TRANSFERS TO THIRD COUNTRIES
Montenegro is not a member of the European Union and some of the providers we use are located outside the European Economic Area. Your data may therefore be transferred outside the European Economic Area.
- The transfer relies on the European Commission's standard contractual clauses or on an equivalent safeguard framework to which the provider is bound.
- The data transferred is limited to the minimum scope needed for the provider's function.
- You can request a copy of the safeguards we use at info@zensyno.com.
9. COOKIES
The cookies used in the panel are listed one by one in a separate document: the Cookie Policy. No third party tracking cookie for advertising or profiling is used.
10. RETENTION PERIODS
- Account and business data is kept for as long as your account is open.
- After the account is closed the data is kept for 90 days and then deleted.
- Payment and invoice records are kept in a separate record store for the period required by financial legislation.
- Login and action records are kept for a limited time for security review.
- Support correspondence is kept for a reasonable period after the request is closed.
11. YOUR RIGHTS
- To learn whether data about you is processed and to access the processed data.
- To request the correction of incorrect or incomplete data.
- To request the deletion of your data.
- To request that processing be restricted.
- To export your data in a structured and commonly used format and to move it to another controller.
- To object to processing based on legitimate interest.
- To withdraw your consent at any time; withdrawal does not make the processing carried out until then unlawful.
- To lodge a complaint with the supervisory authority.
You can send these requests from your registered e-mail address to info@zensyno.com. We answer within one month at the latest; if the request is complex and we need to extend that period, we tell you and explain why. We may ask for additional information to verify that the request comes from you.
We do not charge for your requests. The exception is the manifestly unfounded repetition of the same request.
12. AUTOMATED DECISION MAKING
No automated decision producing legal effects concerning you is taken and no profiling is carried out. The measurements and reports produced in the panel are analysis outputs based on the data you enter.
13. SECURITY
- Connections are carried encrypted and the dashboard is served only over HTTPS.
- Passwords are stored in an irreversible form.
- Permissions are applied by role; each user sees only the data of their own workspace.
- Secrets and keys are not kept in the code; they are stored in an encrypted settings store.
- Access and change records are kept.
If a breach affecting the security of personal data occurs, we notify the supervisory authority within the period prescribed by law and, where the risk is high, we inform you as well.
14. CHILDREN
The panel is a business tool and is not aimed at children. We do not knowingly collect data from children.
15. SUPERVISORY AUTHORITY AND COMPLAINTS
Please send your request to us first. If you find our answer insufficient, you may apply to the supervisory authority.
- For Montenegro the competent authority is the national body responsible for the protection of personal data.
- If you are resident in the European Union, you may also apply to the data protection authority of your country.
16. CHANGES
This document may be updated. The current version is published on this page and applies from the update date shown at the top of the page. For a material change we send a notice to your registered e-mail address.
17. CONTACT
You can send us your questions about data processing using the contact details above.