Legal
Privacy Policy
This policy explains what personal data Zeno Life Plan collects, why, the legal bases we rely on, and the rights you have. It should be read alongside our plain-language Privacy & Data Principles.
1. Data controller
Zeno Life Plan (“Zeno Life Plan”, “we”, “us”) is the controller of the personal data described in this policy, except where we act as a processor on behalf of an organisation that has deployed the platform to its people. The controller’s registered details and Data Protection contact are set out in section 15.
2. Data we collect
We collect: (a) account data such as name, work email and organisation; (b) Life Plan content you create — reflections, objectives and related entries; (c) usage data such as pages viewed and progress; and (d) technical data such as device type and, subject to consent, cookie identifiers. We practise data minimisation and collect only what the methodology requires.
3. Purposes of processing
We process personal data to: provide and secure the platform and your Life Plan; deliver the individual and enterprise programmes; produce anonymised, aggregated cohort insight for organisations; respond to enquiries; comply with legal obligations; and, with consent, send communications. We apply purpose limitation — we do not repurpose your data for unrelated uses.
4. Legal bases
Under the GDPR we rely on: contract (to provide the service you or your organisation signed up for); legitimate interests (to secure, maintain and improve the platform, balanced against your rights); consent (for non-essential cookies and marketing, which you can withdraw at any time); and legal obligation (to meet regulatory duties).
5. Controller and processor roles
Where an organisation deploys Zeno Life Plan, the content of an individual’s Life Plan is private to that individual and is never disclosed to the employer. The organisation receives only anonymised, aggregated, aggregated insight and cannot access personal plan content or identify individuals.
The specific data-protection roles depend on the processing activity and the contractual arrangement. For direct individual users, Zeno Life Plan generally acts as controller. In an employer-sponsored deployment, the organisation and Zeno Life Plan each act as controller or processor for different activities, as documented in the applicable Data Processing Agreement, enterprise contract, records of processing and subprocessor documentation. In all cases the individual is the data subject and retains the rights described in section 10; the employer never receives access to private Life Plan content.
6. Cookies
We use strictly necessary cookies to run the site and platform, and — only with your consent — functional and analytics cookies. See our Cookies Policy for the full list and controls. You can change or withdraw consent at any time.
7. Analytics
Subject to consent, we use privacy-respecting analytics to understand aggregate usage and improve the product. Analytics data is not used to build advertising profiles and is not sold. Where possible we use aggregated or pseudonymised measurement.
8. Retention
We keep personal data only as long as necessary for the purposes above or as required by law. Life Plan content is retained while your account is active and deleted on request or within a defined period after account closure. Aggregated, anonymised data that can no longer identify you may be retained for statistical purposes.
9. International transfers
We operate internationally and may process data outside your country. Where personal data is transferred out of the EEA or UK, we use appropriate safeguards — such as European Commission Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum — and assess the destination’s protections.
10. Your rights
Subject to law, you have the rights of access, rectification, erasure, restriction, objection, portability, and to withdraw consent. To exercise them, submit a request through our secure contact form. We will respond within the timeframes required by the GDPR (generally one month).
11. Security
We protect personal data with encryption in transit and at rest, role-based access on a need-to-know basis, logging, and regular review of our controls. No system is perfectly secure, but we design for privacy and hold ourselves to a high standard.
12. Children
The commercial platform is intended for adults in a workplace or individual context and is not directed at children. Any youth programmes are delivered separately, with schools and guardians, under specific safeguards and age-appropriate consent arrangements.
13. Complaints
If you have a concern, please contact us first so we can help. You also have the right to lodge a complaint with your local data protection supervisory authority.
14. Updates
We may update this policy to reflect changes in law or our practices. We will post the new version here with an updated effective date and, where appropriate, notify you.
15. Contact
For data-protection matters, submit a privacy request through our secure contact form; for general matters, use our contact form. We do not publish email addresses, to protect against spam and data harvesting. The registered company name, address and (where applicable) Data Protection Officer details will be inserted here before go-live.
This document uses realistic, plain legal language for a company operating internationally with attention to the EU GDPR. It is a strong production draft, not final legal advice. Before go-live, qualified GDPR counsel should review: controller and processor roles; lawful bases; international transfers; retention periods; children’s data; cookie consent; governing law; and company identity and registered address.