Privacy Policy & Data Protection Notice
Effective 2026-08-31 · Version 1.0
1. Introduction
Welcome to ZynReach.
Zyntra Digital, as the operator of the ZynReach platform, is committed to protecting the privacy of users and the personal data processed through the ZynReach website, its services, and its digital platform.
Data protection and privacy are a fundamental part of how ZynReach is designed and operated, and the company applies appropriate technical and organizational measures to protect data from unauthorized access, use, modification, disclosure, or loss.
ZynReach approaches privacy in accordance with the principles of: Transparency — Purpose Limitation — Data Minimization — Security — Accountability.
This Policy explains:
- What data we may collect.
- The sources of that data.
- How it is used.
- The legal bases for processing.
- When data is shared.
- The role of service providers.
- The rights of data subjects.
- How data is protected.
- How customer data is handled.
- The use of cookies.
- The use of artificial intelligence.
- Data retention and deletion.
- International transfers.
- How to contact us about privacy.
2. Data Controller / Responsible Party
For the purposes of this Policy, "ZynReach," "Zyntra Digital," "the Company," "we," and "us" refer to the entity that operates the ZynReach services.
The ZynReach website currently indicates that the platform is Powered by Zyntra Digital and that it operates from Egypt.
Contact details:
- Privacy: privacy@zynreach.com
- Legal: legal@zynreach.com
- General: info@zynreach.com
- Address: 63 C Al Ashgar Street, Al Haram, Giza Governorate 12556, Egypt.
3. Scope of This Policy
This Policy applies to data processed through:
This Policy does not apply to third-party services or websites that ZynReach does not control.
- The ZynReach website.
- User accounts.
- The ZynReach SaaS platform.
- Forms available on the website.
- Free trial requests.
- Demo requests.
- Sales inquiries.
- Customer service and support.
- Marketing communications.
- Integrations and APIs.
- Analytics services.
- Business Data services.
- CRM and marketing tools.
- Artificial intelligence features.
- Documents uploaded by users.
- Billing and subscription processes, depending on the service.
- Security and compliance operations.
- Any other digital services that expressly reference this Policy.
4. Data We Collect
ZynReach may collect various types of data depending on the nature of your use of the services.
Account data: when creating an account, we may collect:
- Name.
- Company name.
- Email address.
- Phone number.
- Job title.
- Country.
- Login credentials.
- Organization data.
- Account preferences.
- Language and time zone settings.
- Data of users associated with the organization.
5. Organization Data
When using Enterprise or Organization Management services, information such as the following may be processed:
ZynReach already provides Organization Management capabilities that include organizational identity, roles, branches, custom domains, and other organization settings.
- Organization name.
- Organizational structure.
- Branches.
- Departments.
- Roles.
- Permissions.
- Organization settings.
- Domains.
- User data.
- Security settings.
6. Customer Data Entered by Users
A user or customer may enter data within the platform, including:
This data may include personal information relating to other individuals.
- Customer data.
- Prospective customer (lead) data.
- Employee data.
- Supplier data.
- Contact data.
- Company data.
- Notes.
- Documents.
- Invoices.
- Transaction records.
- Project data.
- Support data.
- Marketing data.
- Communications data.
7. Customer Responsibility for Data It Enters
When a customer enters personal data relating to its employees, customers, suppliers, or other parties, the customer is responsible for ensuring that it:
- Has the right or legal basis necessary to process the data.
- Provides the required notices to the data subjects.
- Does not enter data it does not have the right to process.
- Complies with the laws applicable to its activity.
- Uses ZynReach in a manner consistent with the agreement and the DPA.
8. ZynReach as a Data Processor
When ZynReach processes personal data on behalf of the customer and in accordance with its instructions, ZynReach acts, depending on applicable law, as a Data Processor / Service Provider.
The customer is the party that determines the purposes and means of processing to the extent applicable to it under law.
In this case, the processing is governed by the applicable commercial agreement and the Data Processing Agreement (DPA).
ZynReach's currently published DPA states that the Company processes personal data on behalf of the customer and on the basis of its documented instructions, except as required by law.
9. ZynReach as a Data Controller
In other cases, such as the management of:
ZynReach may act as a Data Controller / Business.
In this case, it determines the purposes and means of processing data in accordance with applicable law.
- The website.
- Marketing.
- Prospective customers (leads).
- User accounts.
- Sales.
- Support.
- Security.
- Analytics.
- Business relationships.
10. Data Collected Automatically
When visiting the website or using the platform, technical information may be collected, such as:
This information is used for purposes including security, operating the service, improving performance, analytics, detecting misuse, and troubleshooting.
- IP address.
- Device type.
- Operating system.
- Browser type.
- Device or session identifiers.
- Pages visited.
- Date and time of visit.
- Duration of use.
- Referral source.
- Performance information.
- Error logs.
- Information about interaction with the service.
11. Usage Data
ZynReach may record information about how the services are used, such as:
This data may be linked to the user's or organization's account when necessary for legitimate purposes.
- Features used.
- Operations performed.
- Login times.
- Account settings.
- Search queries.
- Interaction with interfaces.
- Errors.
- System events.
12. Audit Logs
ZynReach uses audit logs to help organizations track activity within the platform.
Audit logs may include:
ZynReach notes that the platform records activities such as record changes, approvals, logins, and configuration changes within a searchable audit log.
These logs are handled in accordance with security, governance, legal, and applicable contractual requirements.
- User identity.
- The operation performed.
- The time of the operation.
- The affected resource.
- The changes made.
- Settings associated with the operation.
13. Business Data and Lead Generation
ZynReach provides capabilities related to company and contact discovery, building lead lists, and data enrichment.
As a result, certain company or contact data obtained from public sources, commercial sources, data providers, licensed databases, and technical or commercial sources available under their own terms may be processed.
This data may include:
- Name.
- Job title.
- Company name.
- Business email address.
- Business phone number.
- Company information.
- Industry.
- Location.
- Firmographic data.
- Technographic data.
- Business-related information.
14. Public Availability Does Not Mean "Non-Personal"
The fact that a piece of information is publicly available does not mean it is "non-personal."
Nor does its public availability mean that its use is not subject to applicable laws.
ZynReach treats personal data in accordance with its nature and the applicable law, not merely according to its source.
15. Third-Party Data Sources
When ZynReach obtains data from external sources or providers, it seeks to use sources and vendors that are appropriate under the applicable legal and contractual requirements.
Data received from service providers may be subject to terms of use, licensing restrictions, or legal requirements specific to the source.
16. Purposes of Data Processing
ZynReach may use personal data for the following purposes:
- Service provision: creating the account, operating the platform, authentication, executing operations, delivering features, managing the organization.
- Customer support: responding to inquiries, handling support requests, troubleshooting issues, communicating with the user.
- Sales: following up on demo requests, managing leads, scheduling demos, managing the business relationship.
- Marketing: sending marketing messages, delivering relevant content, measuring campaign effectiveness, subject to consent or opt-out requirements where required by law.
- Security: detecting attacks, preventing fraud, detecting misuse, protecting accounts, investigating incidents.
- Analytics: understanding service usage, improving products, improving user experience, measuring performance.
- Compliance: fulfilling legal obligations, responding to legitimate government requests, retaining required records.
17. Legal Basis for Processing
Depending on the nature of the processing and the applicable law, ZynReach may rely on one or more of the following legal bases:
ZynReach does not rely on a single legal basis for all types of processing.
- Performance of a contract.
- Taking steps prior to entering into a contract.
- Legitimate interest.
- Consent.
- Legal obligation.
- Protection of vital rights and interests, where applicable.
18. Legitimate Interests
When ZynReach relies on Legitimate Interests, it seeks to ensure that the processing is necessary for the specified purpose, does not exceed what is required, and does not unjustifiably override the individual's rights and interests in favor of the Company's interest.
Legitimate interests may include:
- Platform security.
- Fraud prevention.
- Service improvement.
- Product development.
- Managing business relationships.
- Protecting legal rights.
- Managing operations.
19. Consent
Where consent is legally required, ZynReach will seek to obtain it in a clear and specific manner.
Use of the service by itself should not be interpreted as consent to all types of marketing communications.
Users may withdraw their consent in cases where processing relies on consent.
20. Marketing Communications
ZynReach may send:
The ability to opt out of each type of communication varies according to its nature.
Messages necessary for operating the account or its security may not be opted out of when they are necessary to provide the service.
- Operational messages.
- Account-related notifications.
- Security messages.
- Service updates.
- Support messages.
- Marketing offers.
- Educational content.
21. Marketing Opt-Out
Users can unsubscribe from marketing communications through:
ZynReach must remain able to send messages necessary for the service, security, or contractual obligations.
- The unsubscribe link.
- Account settings, where available.
- Contacting ZynReach.
24. Data Sharing
ZynReach does not sell personal data merely to generate revenue from the sale of personal data.
Data may be shared, when necessary, with:
The current Compliance page describes the categories of sub-processors used for hosting, email, analytics, and customer support.
- Infrastructure providers.
- Email providers.
- Analytics providers.
- Customer support providers.
- Payment service providers.
- Security providers.
- Sub-processors.
- Professional advisors.
- Competent government authorities when disclosure is legally required.
25. Sub-processors
When ZynReach processes personal data on behalf of the customer, it may use Sub-processors to provide parts of the service.
This relationship is governed by the applicable DPA and legal and contractual requirements.
ZynReach maintains a list of sub-processors, and the current Compliance page indicates that the list is kept up to date, including the purpose and processing location of each.
26. Disclosure for Legal Reasons
ZynReach may disclose data if it is:
Disclosures are limited, as far as possible, to the information necessary for the legitimate legal purpose.
- Required by law.
- Required by a court order.
- Requested by a competent government authority.
- Necessary to protect legal rights.
- Necessary to investigate fraud or misuse.
- Necessary to protect the safety of users or the platform.
27. Business Transfers
In the event of:
Certain data may be transferred as part of the transaction, subject to applicable laws and data protection obligations.
Where the law requires notice to data subjects, the required steps will be taken.
- A merger.
- An acquisition.
- A restructuring.
- The sale of part of the business.
- A transfer of assets.
- An investment or reorganization.
28. Data Protection
ZynReach applies technical and organizational measures aimed at protecting data.
Depending on the service and environment, these include:
These controls are consistent with what is described on ZynReach's current Security page.
- Encryption in transit.
- Encryption at rest.
- Least Privilege.
- MFA.
- RBAC/ABAC.
- Audit Logging.
- System monitoring.
- Backups.
- Vulnerability management.
- Incident response.
29. No System Is Absolutely Secure
Despite the implementation of appropriate security controls, no system, network, or service can be guaranteed to be absolutely protected from all risks.
Accordingly, ZynReach does not provide an absolute guarantee that data will not be subject to any security incident under all circumstances.
Any specific security commitments are subject to the applicable commercial agreements, DPA, and SLA.
30. Data Retention
ZynReach retains data only for the period necessary to achieve the purpose for which it was collected, or for the period required by:
The retention period may vary depending on the type of data and its purpose.
- Law.
- Contract.
- Accounting requirements.
- Security requirements.
- Dispute resolution requirements.
- Fraud prevention requirements.
31. Data Deletion
When data is no longer needed, ZynReach seeks to delete it, anonymize it, or render it unidentifiable in accordance with applicable procedures and policies.
Some data may persist for a limited period in:
Deleting data from the user interface does not necessarily mean it is deleted from all backups immediately.
- Backups.
- Security logs.
- Audit logs.
- Systems subject to specific retention cycles.
32. Children's Data
ZynReach's services are not directed at children.
ZynReach does not intend to collect personal data from children without the required legal basis or consent.
If ZynReach becomes aware that it has unlawfully collected a child's data, it may take appropriate steps to delete it.
33. Sensitive Data
Users should not upload or enter sensitive personal data into ZynReach unless doing so is necessary for the service, the customer has an appropriate legal basis, it is permitted under the agreement, and appropriate controls have been implemented.
Sensitive data may include, depending on applicable law:
The customer must assess the suitability of using ZynReach for these categories before entering them.
- Health information.
- Biometric data.
- Sensitive financial data.
- Information relating to racial or ethnic origin, religion, or beliefs.
- Information relating to sex life.
- Data relating to children.
34. Artificial Intelligence and Data
ZynReach provides AI Assistants, AI Agents, AI Insights, and other artificial intelligence capabilities within the platform.
AI features may use data available within the scope of the service to perform the function requested by the user, depending on product and service settings.
Depending on the feature, ZynReach applies controls aimed at:
Some of ZynReach's AI Agent capabilities include human approval checkpoints and an audit trail of actions.
- Restricting access.
- Respecting permissions.
- Logging activities.
- Minimizing unnecessary data.
- Preventing unauthorized actions.
35. AI Data Input
Users should not enter personal or confidential data into AI tools unless they have the right to do so and the feature is designed to process such data.
The customer must review the product terms and feature-specific agreements before using AI tools to process sensitive or regulated data.
36. Automated Decisions
Outputs of ZynReach's artificial intelligence should not be interpreted as final legal, medical, financial, or employment decisions merely because they are produced by an automated system.
When a decision has a legal or significant effect on an individual, the entity using ZynReach must ensure there is human oversight and the required legal basis.
37. Data Subject Rights
Depending on applicable law, an individual may have rights relating to their personal data, including:
- Right of access — request to know what data is being processed and obtain a copy of it, where permitted by law.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of data in cases permitted by law.
- Right to restriction of processing — request restriction of data processing in specific cases.
- Right to object — object to certain types of processing.
- Right to withdraw consent — where processing relies on consent.
- Right to data portability — obtain data in a structured format, where this right applies.
- Rights relating to automated decisions — additional rights may apply where the law governs automated decision-making.
38. Data Subject Requests
Privacy requests may be submitted via: privacy@zynreach.com
ZynReach may request additional information to verify the identity of the requester before fulfilling the request, particularly if disclosure could reveal another person's personal data.
39. Identity Verification
ZynReach may take reasonable steps to verify the identity of a person submitting a request relating to personal data.
This is intended to prevent:
ZynReach will not request additional information beyond what is reasonable and necessary for verification.
- Unauthorized access.
- Identity theft.
- Disclosure of another person's data.
40. Customer Representatives
If a customer submits a request relating to the data of other individuals stored within its account, ZynReach may be required to refer the request to the customer as the party that controls that data.
In this case, ZynReach acts in accordance with the DPA, the customer's instructions, and applicable law.
41. Regulatory Requests
When ZynReach receives a legal request for data, it will, to the extent permitted by law, review it and determine the scope of the information requested.
It may refuse or challenge the request if it is:
Unless prohibited by law.
- Unlawful.
- Unclear.
- In excess of authority.
- Not compliant with legal requirements.
42. International Transfers
Data may be processed in a country different from the country in which the user resides.
ZynReach currently indicates that customer data is hosted by default in data centers within the United States, with regional options available for Enterprise plans as may be agreed.
Where there are legal restrictions on international transfer, ZynReach seeks to apply a lawful transfer mechanism and appropriate safeguards.
ZynReach's current DPA includes provisions specific to international transfers and appropriate safeguards.
43. Security and Privacy in Vendor Relationships
When using a third party to process personal data, ZynReach seeks to take appropriate measures depending on the nature of the service, such as:
- Contractual review.
- Data protection requirements.
- Purpose limitation.
- Access restriction.
- Security controls.
- Confidentiality obligations.
44. Payment Data
When purchasing paid services, payment data may be processed through specialized payment service providers.
Users should not send full payment card details by email or through forms not designated for payment.
Payment data is processed in accordance with the payment provider's arrangements and applicable laws and standards.
45. Communication and Support Data
When communicating with the ZynReach team, correspondence may be retained, such as:
This is for purposes including providing support, resolving issues, quality assurance, security, and relationship management.
- Email.
- Support messages.
- Ticket records.
- Account data.
- Issue details.
- Attached files.
46. Call Recording
If ZynReach records support or sales calls, it will do so in accordance with applicable law, and participants may be notified or their consent obtained where required.
Important: this section should not actually be activated unless ZynReach genuinely uses call recording, and does so in the manner described.
47. Analytics
ZynReach may use analytics tools to understand:
Some of this data may be processed by external Analytics providers.
The current Compliance page lists the Analytics provider among the Sub-processor categories, with a stated processing location in the United States.
- Website performance.
- Platform usage.
- User journeys.
- Errors.
- Conversions.
- Feature usage.
48. External Links
The ZynReach website may contain links to external websites or services.
ZynReach does not control:
Users should review the third party's privacy policy before providing personal information to it.
- Privacy policies.
- Data practices.
- Cookies.
- The content of external websites.
50. Data Breaches and Security Incidents
If ZynReach discovers a security incident affecting personal data, it will assess:
The customer, data subjects, or regulators may be notified where legally or contractually required.
- The nature of the incident.
- The type of data.
- The number of individuals affected.
- The level of risk.
- Legal requirements.
- Contractual obligations.
51. Not Every Technical Incident Is a Data Breach
Not every:
automatically constitutes a Personal Data Breach.
This is determined based on the facts, the risks, and applicable law.
- Alert.
- Failed Login.
- Vulnerability.
- Service Incident.
- Technical Error.
52. Retention of Compliance Records
ZynReach may retain records relating to:
This is for the period necessary for compliance, governance, and defense of legal rights.
- Consents.
- Data subject requests.
- Incidents.
- Disclosures.
- Audit activities.
- Legal requests.
53. Changes to This Privacy Policy
ZynReach may update this Policy from time to time due to:
The updated version is published on the website with the last updated date indicated.
- Product development.
- Addition of services.
- Technical changes.
- Legal changes.
- Changes in vendors.
- Changes in data processing practices.
54. Notice of Material Changes
If a change is material and significantly affects users' rights or the way their data is processed, ZynReach may take additional steps to provide notice in accordance with applicable law.
55. No Additional Contractual Rights Created
This Policy, by itself, does not create contractual obligations beyond those set out in:
In the event of a conflict, reference will be made to the applicable legal agreement and the governing law.
- Terms of Service.
- Master Service Agreement.
- DPA.
- Enterprise Agreement.
- SLA.
56. Protection of Intellectual Property and Confidential Information
This Privacy Policy does not grant the user any right to:
Confidential information must be protected in accordance with the applicable agreements.
- Source Code.
- Algorithms.
- Trade Secrets.
- Security Architecture.
- Internal Documentation.
57. Regulatory Compliance
ZynReach seeks to develop its privacy and security practices in a manner consistent with relevant legal requirements and regulatory frameworks.
The ZynReach website currently references:
This does not mean that use of ZynReach automatically makes the customer compliant with every requirement of any law or standard.
- GDPR — with respect to legal basis, data subject rights, and the DPA.
- CCPA — with respect to the rights and disclosures applicable to California residents.
- SOC 2 Type II — within the scope of the controls disclosed.
- ISO 27001 aligned — with respect to information security management practices.
58. GDPR
Where the GDPR applies to ZynReach's processing of personal data, the Company seeks to support the relevant rights and obligations in accordance with its role in the processing.
This may include:
ZynReach currently provides a DPA to Enterprise customers, and the Compliance page indicates that its GDPR framework includes documentation of the legal basis, data subject rights, and the availability of a DPA for European data.
- Lawful Basis.
- Data Subject Rights.
- Data Processing Agreement.
- International Transfers.
- Security Measures.
- Data Breach Procedures.
- Data Protection by Design.
59. CCPA / CPRA
Where California consumer privacy laws apply, ZynReach seeks to provide the rights and disclosures legally required.
Depending on the circumstances, these rights may include:
This section should not be interpreted as an acknowledgment that every user has every right under all circumstances; rights depend on applicable law and the user's status.
- Knowing what data is collected.
- Requesting access.
- Requesting deletion.
- Correcting data.
- Restricting certain types of use.
- Objecting to certain processing activities.
60. No Sale of Personal Data
ZynReach does not sell personal data merely to sell it to third parties.
In cases where ZynReach uses service providers to process data, the use is for specific operational or business purposes and in accordance with the contractual relationship and applicable law.
Any legal term such as "Sale" or "Sharing" must be interpreted in accordance with the definition set out in applicable law, not according to its general commercial meaning.
62. Rights of California Residents
Users covered by applicable California laws can submit privacy requests via: privacy@zynreach.com
ZynReach may request information to verify the request in accordance with legal requirements.
63. Rights of EU and EEA Residents
If the user is subject to the GDPR, they may exercise their rights via: privacy@zynreach.com
Where the appointment of a legal representative within the European Union is required, ZynReach must update this Policy with that representative's details before publishing this version as a final version directed specifically at the European Union.
64. Right to Lodge a Complaint
A data subject has the right, where permitted by law, to lodge a complaint with the competent data protection authority in the country or region in which they reside or in which the alleged infringement occurred.
Contacting ZynReach first does not prevent the exercise of this right.
65. No Legal Advice Provided
This Policy does not constitute legal advice for the user or customer.
Every organization must assess:
The customer must also obtain independent legal advice when necessary.
- The nature of its data.
- The location of its customers.
- Its industry sector.
- Regulatory requirements.
- The legal basis for processing.
66. Relationship with the Data Processing Agreement
When ZynReach processes personal data on behalf of the customer, the DPA is the primary document that sets out the rights and obligations of the parties with respect to the processing, to the extent provided by law and the agreement.
ZynReach currently maintains a published DPA that sets out the subject matter and scope of processing, sub-processors, security measures, data subject rights, and international transfers.
67. Relationship with the Security & Trust Policy
The Privacy Policy explains how personal data is collected, used, shared, and protected.
The Security & Trust Policy explains the security, technical, and organizational framework that ZynReach uses to protect the platform and data.
Neither document replaces the other.
68. Relationship with the Security & Compliance Documentation Request Policy
The Security & Compliance Documentation Request Policy sets out the terms and procedures for requesting restricted security and compliance documentation.
Publication of this Privacy Policy does not automatically grant any person the right to obtain confidential or restricted security documentation.
69. Privacy Requests
For all privacy requests, you may contact the Privacy Team at privacy@zynreach.com
The request should preferably include:
- Name.
- Email address.
- Company, where applicable.
- The nature of the request.
- A description of the data requested.
- Any information necessary for verification.
70. Legal Communications
For legal inquiries: legal@zynreach.com
For DPA requests: legal@zynreach.com
The currently published DPA indicates that a signed copy of the DPA may be requested by Enterprise customers via this email address.
71. Security
To report a security issue to ZynReach: security@zynreach.com
Passwords, API keys, or sensitive customer data should not be sent by email.
72. General Contact
ZynReach / Zyntra Digital
The website currently displays general contact information, phone numbers, and the corporate address in Egypt.
- Email: info@zynreach.com
- Privacy: privacy@
- Legal: legal@zynreach.com
- Security: security@zynreach.com
- Website: ZynReach.com
73. Effective Date
This Policy takes effect as of August 31, 2026.
It remains in effect until replaced by an updated version.
74. Document History
Summary of this document's details:
- Document Name — Privacy Policy & Data Protection Notice
- Company — Zyntra Digital / ZynReach
- Version — 1.0
- Effective Date — 31 August 2026
- Classification — Public Legal Policy
- Owner — Legal & Privacy
- Privacy Contact — privacy@zynreach.com
- Legal Contact — legal@zynreach.com
- Security Contact — security@zynreach.com
- Review Cycle — At least annually
- Status — Official
75. Legal Disclaimer
This Policy has been prepared to explain ZynReach's privacy and data protection practices in a transparent and organized manner.
This Policy does not constitute:
The rights and obligations of the parties are subject to applicable law and effective agreements.
- An absolute legal guarantee.
- Legal advice for the customer.
- A guarantee of the customer's compliance with laws.
- An amendment to an existing commercial agreement.
- A substitute for the DPA.
- A substitute for the Terms of Service.
- A guarantee that all processing activities are subject to a single law.
76. Short Consent Notice for Website Forms
It is recommended that a clear notice appear below the Book a Demo / Contact Sales / Free Trial forms, such as the following:
"By submitting this form, you acknowledge that ZynReach may process the information you provide to respond to your request, manage our business relationship, and provide relevant service communications, in accordance with our Privacy Policy. Marketing communications may be subject to separate consent and can be unsubscribed from at any time."
And in Arabic, for Arabic-language forms, a notice to the same effect:
"By submitting this form, you acknowledge that ZynReach may process the information you provide to respond to your request, manage our business relationship, and provide relevant service communications in accordance with our Privacy Policy. Marketing communications may be subject to separate consent and may be unsubscribed from at any time."
For privacy-related requests, contact us at privacy@zynreach.com.