Privacy Policy
Version 1.0 · Effective date: to be set on launch
This Policy is written in English and the English version is the original and legally binding version. Translations, where provided in the app, are for convenience only and generated by DeepL machine translation. In the event of any inconsistency, the English version shall prevail. This Policy forms part of the Zensus legal framework alongside our Terms of Service, Health Data Agreement, Subscription Terms, Avatar Purchase Terms, Teams Community Guidelines, Marketing Preferences, and Data Retention Policy.
1. Who We Are
ZENSUS LTD ("we", "us", "our") is the data controller for personal data collected through the Zensus application ("the App") and website.
Registered address: Office 20089, 182–184 High Street North, East Ham, London, E6 2JA, United Kingdom
Privacy contact: support@zensus.co.uk
Data Protection Officer: Not yet formally appointed. We monitor this against the GDPR Article 37 threshold as our user base grows. Until a DPO is appointed, direct all privacy enquiries to the address above.
EU Representative (GDPR Art. 27): Not yet appointed — in progress. See Section 18 for how to reach us in the meantime.
No separate UK representative is required — ZENSUS LTD is itself the UK establishment.
2. What Personal Data We Collect
2.1 Account & Identity Data
Email address, display name, platform (iOS/Android), language preference, timezone, country code.
2.3 Payment & Financial Data
Subscription and avatar purchase status, payment provider customer ID, transaction history, and refund records. We do not store card numbers, CVV, or full payment details — these are handled directly by our payment processors. See our Subscription Terms and Avatar Purchase Terms.
2.4 Device & Technical Data
Device fingerprint, IP address (encrypted in audit logs), push notification tokens, user agent strings.
2.5 Content Contributions
Translation submissions for health content, votes on health content, user feedback, and Teams messages (see Section 9).
2.6 Authentication Data
OAuth provider links (Google, Apple ID), JWT token records, login events and account activity.
3. Legal Basis for Processing
| Processing Purpose | Legal Basis | Notes |
|---|---|---|
| Providing the app service | Art. 6(1)(b) — Contract | Core service delivery |
| Health data tracking | Art. 9(2)(a) — Explicit consent | See Health Data Agreement |
| Payment processing | Art. 6(1)(b) — Contract | Subscription and avatar billing |
| Financial record-keeping | Art. 6(1)(c) — Legal obligation | Tax law, 7 years |
| Security and fraud detection | Art. 6(1)(f) — Legitimate interests | Device fingerprinting, audit logs |
| Consent records | Art. 6(1)(c) — Legal obligation | Art. 7(1), indefinite |
| Marketing communications | Art. 6(1)(a) — Consent | Opt-in only, see Marketing Preferences |
| Teams data sharing (optional) | Art. 9(2)(a) — Explicit consent | Separate per-team consent |
4. How We Use Your Data
- Nutrition tracking and personalised analysis
- Body measurement and exercise trend tracking
- Subscription and avatar purchase management
- Push notification and email delivery
- Health content delivery and translation
- Security monitoring and fraud detection
- Customer support and legal compliance
- Gamification (achievements, streaks, quiz games)
- Teams matchmaking and leaderboards
We do not use your health data for advertising, profiling for third-party commercial purposes, or any purpose not listed above.
5. Data Retention
Full retention periods for every data category, and exactly what happens on account deletion, are set out in our Data Retention Policy. In summary: your app data (nutrition, exercise, measurements, Teams, avatars) is kept while your account is active and permanently deleted within 30 days of account deletion. Financial and consent records are retained longer where required by law (7 years and indefinitely, respectively) but are anonymised on deletion.
6. International Data Transfers
Our application servers and database are hosted in the United States (AWS us-east-1, via Fly.io and Supabase). Product analytics (PostHog) is hosted in the European Union. The transfer mechanism for each processor is set out below.
| Processor | Service | Country | Transfer Mechanism |
|---|---|---|---|
| Supabase | Database hosting | United States | EU–US Data Privacy Framework (DPF) / SCCs |
| Fly.io | Application hosting | United States | EU–US Data Privacy Framework (DPF) / SCCs |
| Stripe | Payment processing | United States | EU–US Data Privacy Framework (DPF) |
| Sentry | Error monitoring | United States | EU–US Data Privacy Framework (DPF) |
| Mailgun (Sinch) | Transactional email | United States | UK IDTA / EU SCCs, DPF certified |
| OneSignal | Push notifications | United States | EU–US Data Privacy Framework (DPF) |
| PostHog | Product analytics | European Union | EU-hosted — no transfer |
| Flutterwave | Payment processing | Nigeria/Kenya | Standard Contractual Clauses (SCCs) |
| Xendit | Payment processing | Philippines/Indonesia | Standard Contractual Clauses (SCCs) |
If the DPF is invalidated, affected US processors automatically fall back to Standard Contractual Clauses.
7. Your Rights as a Data Subject
| Right | How to Exercise It |
|---|---|
| Access | View your profile in-app; a full data export is available (Profile → Privacy → Download My Data) |
| Rectification | Edit your profile directly in the app |
| Erasure | Delete your account (30-day grace period applies) |
| Restriction | Contact us — not yet self-service in-app |
| Data portability | The data export above is provided in structured JSON |
| Object | Contact us to object to a specific processing activity |
| Withdraw consent | Delete your account, or contact us for non-health-data consents |
| Lodge a complaint | See below |
Lodging a complaint
- UK (our lead supervisory authority): Information Commissioner's Office (ICO) — ico.org.uk, 0303 123 1113
- EU: your local supervisory authority, or our EU representative once appointed (see Section 1)
- Nigeria: Nigeria Data Protection Commission (NDPC), under the Nigeria Data Protection Act 2023 (NDPA) — superseded the 2019 NDPR/NITDA regime
- Philippines: National Privacy Commission (NPC) — privacy.gov.ph
- California, USA: see Section 16
8. Health Data — Special Category Processing
We process health and biometric data on the basis of your explicit consent (GDPR Art. 9(2)(a)), given during registration via a separate consent screen — distinct from your acceptance of these Terms. Full detail on what is collected, how it is protected, who else can access it, and your rights over it is in our Health Data Agreement, which you are asked to accept before this data is processed.
9. Teams Feature — Group Data Sharing
Teams let groups of premium members share certain physical performance data and compete on leaderboards. Joining a Team requires a separate, explicit consent at the point of joining (Art. 9(2)(a)), and full detail on exactly what is shared is in our Teams Community Guidelines. In summary:
- Other Team members see your body measurements and circumferences, and your maximum running speed, as exact values
- Your cardiovascular metrics (VO2 max, resting heart rate, ApoB), food logs, and exercise sessions are never shared
- Nutrition is shown only as a group-level average — your individual intake is never visible to other members
- Team messages expire after 24 hours (retained longer only if reported for review)
- Leaving a Team immediately stops your data being visible to other members; your consent record is retained as legal proof of consent and withdrawal
10. Marketing Communications
Marketing emails (weekly nutrition report, general product updates) are sent only with your opt-in consent (Art. 6(1)(a)) and never pre-ticked. Full detail is in our Marketing Preferences notice. You can withdraw consent at any time via Profile → Notifications, with no effect on your account or app features.
11. Subscriptions and Payment Data
When you subscribe, we collect and process subscription and payment data to manage your account and comply with financial record-keeping obligations. Payment card data is processed directly by our payment processors (Stripe, Flutterwave, Xendit, Apple, Google, Samsung, Huawei, Xiaomi) — we do not store card numbers, CVV codes, or full payment details. Financial records are retained for 7 years to comply with tax and accounting law, even after account deletion; user-identifying fields are pseudonymised on deletion. For full billing, cancellation, and refund terms, see our Subscription Terms.
12. Avatars and Virtual Goods
Avatar purchases are one-time transactions, delivered instantly to your account. The same payment processors and data-handling rules as Section 11 apply. Full purchase, ownership, and refund terms are in our Avatar Purchase Terms.
Some avatars are associated with a Creator, who receives a revenue share on sales (see Section 13). Creators only receive aggregate sales and revenue figures for settlement purposes — they never receive your personal data, purchase history, or any way to identify you as an individual purchaser.
13. Sponsorship and Creator Programs
Zensus has infrastructure to support sponsored placements from brand partners and revenue-sharing arrangements with avatar creators.
- Sponsorship: as of the effective date of this Policy, no sponsor placements are live in the app. If this changes, we will update this Policy to describe what data, if any, is shared with sponsors before any placement goes live.
- Creators: one creator-designed avatar is live from launch, under our Creator/Influencer Agreement. As above, creators receive only aggregate sales figures, never individual user data.
15. Data Breach Notification
In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify you without undue delay. We are required to notify the UK Information Commissioner's Office (ICO) — our lead supervisory authority — within 72 hours of becoming aware of a qualifying breach. Where the breach affects EU residents, we will also notify the relevant EU supervisory authority via our Article 27 representative once appointed. If you believe your data has been compromised, contact support@zensus.co.uk.
16. California Privacy Rights (CCPA/CPRA)
These rights apply once certain revenue/user thresholds are met; they do not currently apply to us. If you are a California resident, you may still contact us with any privacy question and we will respond within 45 days. We do not sell personal information.
17. Children and Young People
Zensus requires users to be at least 16 years old. We do not knowingly collect data from anyone under 16. Users aged 16–17 are permitted to use Zensus; see Section 11 of our Health Data Agreement for the specific protections that apply to this age group.
18. Contact and How to Exercise Your Rights
Data Protection Officer: not yet appointed — see Section 1
Response time: within 30 days, as required by GDPR Art. 12
Postal address:
ZENSUS LTD
Office 20089, 182–184 High Street North
East Ham, London, E6 2JA
United Kingdom
19. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or an in-app notice. The "Effective date" above reflects the most recent revision. Continued use of the app after changes constitutes acceptance of the updated policy.