This Privacy Policy describes how Zentra LLC collects, uses, stores, and protects information in connection with our cloud-native project and portfolio management platform and website at zentratool.com.
By using Zentra, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the platform.
1 Who We Are
Zentra is a cloud-native project and portfolio management platform operated by Zentra LLC. We provide real-time task tracking, Gantt scheduling, cost management, executive dashboards, and role-based collaboration tools to enterprise customers.
For questions about this Privacy Policy or your personal data, please contact us at:
2 Information We Collect
We collect information in two ways: information you provide directly, and information collected automatically when you use the platform.
2.1 Information You Provide
- Name and email address, collected when you are invited to or register for the platform.
- Account and profile data, such as your role within your organization.
- Project and task content, including project names, descriptions, tasks, comments, file attachments, and any other content you create or upload within the platform.
- Communications with us, such as support requests or inquiries sent to our team.
2.2 Information Collected Automatically
- IP address, collected and stored in our audit log as part of the security audit trail for every data-modifying operation.
- Usage data, such as pages visited, features used, and interaction patterns, used to improve the platform.
- Device and browser information, collected via standard web technologies.
- Cookies and similar tracking technologies, as described in Section 6 below.
2.3 Information We Do Not Store
⚠️ Important: User names and email addresses are managed exclusively by Clerk, our third-party identity provider, and are not stored in the Zentra application database. The Zentra database stores only opaque user ID strings (not personally identifiable on their own) as references.
3 How We Use Your Information
We use the information we collect for the following purposes:
- To provide and operate the Zentra platform, including authenticating users, displaying project and task data, and enabling collaboration features.
- To maintain security and audit trails, including logging all data-modifying operations with actor ID, action type, resource, IP address, and timestamp.
- To communicate with you regarding your account, including transactional emails related to your use of the service.
- To improve and develop the platform, using aggregated and anonymized usage data to understand how features are used.
- To comply with legal obligations, including responding to lawful requests from authorities where required.
- To enforce our Terms of Service and protect the rights, property, and safety of Zentra, our customers, and others.
🔒 We do not use customer data to train machine learning models, run analytics for third parties, or share data with advertisers.
4 How We Share Your Information
We do not sell your personal data. We share information only in the following limited circumstances:
4.1 Sub-Processors
We use the following trusted third-party sub-processors to operate the platform. All sub-processors are bound by GDPR-compliant Data Processing Agreements and are prohibited from using your data for their own purposes:
| Sub-Processor |
Role |
Data Processed |
Certifications |
| Clerk |
Identity & Authentication |
User identities and sessions |
SOC 2 Type II GDPR |
| Supabase |
Database & File Storage |
All application data and files |
SOC 2 Type II GDPR |
| AWS (via Supabase) |
Cloud Infrastructure |
All application data and files |
SOC 2 II ISO 27001 GDPR HIPAA |
| Vercel |
Frontend & API Hosting |
Request/response data (no persistence) |
SOC 2 Type II ISO 27001 GDPR |
We will notify customers of any sub-processor changes at least 30 days in advance.
4.2 Legal Requirements
We may disclose your information if required to do so by law, court order, or governmental authority, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website prior to your data being transferred and becoming subject to a different privacy policy.
5 Data Storage, Residency & Retention
5.1 Where Your Data Is Stored
| Component | Provider | Default Region |
| Database | Supabase (AWS RDS) | us-east-1 (configurable) |
| File Storage | Supabase Storage (AWS S3) | Same region as database |
| Identity Data | Clerk (AWS) | US or EU (Enterprise plan) |
| Frontend / API | Vercel Edge Network | Global CDN |
For customers requiring EU data residency, we support Supabase EU regions (Frankfurt, eu-central-1) and Clerk EU data residency on Enterprise plans. These must be configured prior to provisioning.
5.2 How Long We Retain Your Data
- Account and project data is retained for the duration of your active subscription.
- Audit logs are retained indefinitely within your tenant's database.
- Database backups are retained for 7 days (Pro plan) or 30 days (Enterprise plan) with Point-in-Time Recovery (PITR).
- Upon termination of your subscription, you may request full deletion of your organization's data. Deletion cascades at the schema level, removing all associated records.
6 Cookies & Tracking Technologies
Our website and platform use cookies and similar technologies to operate core functionality, maintain your authenticated session, and understand how the platform is used.
6.1 Types of Cookies We Use
- Essential cookies: Required for the platform to function, including session authentication tokens managed by Clerk. These cannot be disabled without breaking core functionality.
- Analytics cookies: Used to collect aggregated, anonymized data about how users interact with the platform, helping us improve the product.
- Preference cookies: Used to remember user-specific settings such as column visibility, ordering, and display preferences within the platform.
6.2 Your Cookie Choices
You can control non-essential cookies through your browser settings or through our cookie consent banner. Disabling essential cookies will prevent you from logging in or using the platform.
7 Data Security
We implement a multi-layered security architecture to protect your data:
| Layer | Measure |
| Encryption in Transit | TLS 1.2+ enforced on all connections between client, API, and database |
| Encryption at Rest | AES-256 encryption for all database data and file storage (managed by Supabase / AWS) |
| Tenant Isolation | PostgreSQL Row-Level Security (RLS) enforced at the database layer — cross-tenant access is architecturally impossible |
| Authentication | All sessions managed by Clerk with JWT (RS256). MFA and SSO (SAML 2.0 / OIDC) supported |
| Access Control | Role-based access control at organization, project, and portfolio levels with least-privilege enforcement |
| Audit Logging | Immutable, append-only log of all data-modifying operations with actor, action, resource, IP, and timestamp |
| Secrets Management | All credentials injected at runtime as environment variables; never stored in code or version control |
While we take extensive measures to protect your data, no security system is impenetrable. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.
8 Your Rights
Depending on your location, you may have the following rights with respect to your personal data:
8.1 GDPR Rights (EEA / UK Users)
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data, subject to our retention obligations.
- Right to Restriction: Request that we restrict processing of your personal data in certain circumstances.
- Right to Data Portability: Request your data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing of your personal data for certain purposes.
To exercise any of these rights, contact us at customerservice@zentratool.com. We will respond within 30 days.
8.2 CCPA Rights (California Residents)
- Right to Know: Request information about the categories and specific pieces of personal data we have collected about you.
- Right to Delete: Request deletion of personal data we have collected, subject to certain exceptions.
- Right to Opt-Out: We do not sell personal data, so there is nothing to opt out of.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
8.3 All Users
Regardless of location, you may at any time request deletion of your account and associated data by contacting your organization's administrator or reaching out to us at customerservice@zentratool.com.
9 Data Ownership
🔒 All customer data — including projects, tasks, users, files, and comments — belongs exclusively to the customer organization.
Zentra's access to customer data is restricted by the same Row-Level Security policies that govern all tenant access. Zentra employees do not have application-level access to read or modify customer data.
Customer data is strictly scoped to the customer's organization ID and is inaccessible to other tenants. Zentra will not use your data for any purpose other than operating the service.
10 Data Portability & Export
You retain full control over your data and can export it at any time:
- Grid Excel Export: Export any project's task data to .xlsx format directly from the platform UI.
- REST API: All data is accessible via our REST API using your organization's credentials, enabling custom exports and integrations.
- Full Data Deletion: Organizations may request complete deletion of all data at any time by contacting customerservice@zentratool.com.
11 Children's Privacy
The Zentra platform is designed for enterprise use and is not directed at children under the age of 13 (or 16 in the EU). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at customerservice@zentratool.com and we will take steps to delete that information.
12 Third-Party Links
Our platform or website may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you visit.
13 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Update the "Last Updated" date at the top of this policy.
- Notify you via email to the address associated with your account.
- Display a prominent notice within the platform for material changes.
Your continued use of Zentra after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
14 Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: