Privacy Policy & Data Protection Notice

Effective 2026-08-31 · Version 1.0

1. Introduction

Welcome to ZynReach.

Zyntra Digital, as the operator of the ZynReach platform, is committed to protecting the privacy of users and the personal data processed through the ZynReach website, its services, and its digital platform.

Data protection and privacy are a fundamental part of how ZynReach is designed and operated, and the company applies appropriate technical and organizational measures to protect data from unauthorized access, use, modification, disclosure, or loss.

ZynReach approaches privacy in accordance with the principles of: Transparency — Purpose Limitation — Data Minimization — Security — Accountability.

This Policy explains:

  • What data we may collect.
  • The sources of that data.
  • How it is used.
  • The legal bases for processing.
  • When data is shared.
  • The role of service providers.
  • The rights of data subjects.
  • How data is protected.
  • How customer data is handled.
  • The use of cookies.
  • The use of artificial intelligence.
  • Data retention and deletion.
  • International transfers.
  • How to contact us about privacy.

2. Data Controller / Responsible Party

For the purposes of this Policy, "ZynReach," "Zyntra Digital," "the Company," "we," and "us" refer to the entity that operates the ZynReach services.

The ZynReach website currently indicates that the platform is Powered by Zyntra Digital and that it operates from Egypt.

Contact details:

  • Privacy: privacy@zynreach.com
  • Legal: legal@zynreach.com
  • General: info@zynreach.com
  • Address: 63 C Al Ashgar Street, Al Haram, Giza Governorate 12556, Egypt.

3. Scope of This Policy

This Policy applies to data processed through:

This Policy does not apply to third-party services or websites that ZynReach does not control.

  • The ZynReach website.
  • User accounts.
  • The ZynReach SaaS platform.
  • Forms available on the website.
  • Free trial requests.
  • Demo requests.
  • Sales inquiries.
  • Customer service and support.
  • Marketing communications.
  • Integrations and APIs.
  • Analytics services.
  • Business Data services.
  • CRM and marketing tools.
  • Artificial intelligence features.
  • Documents uploaded by users.
  • Billing and subscription processes, depending on the service.
  • Security and compliance operations.
  • Any other digital services that expressly reference this Policy.

4. Data We Collect

ZynReach may collect various types of data depending on the nature of your use of the services.

Account data: when creating an account, we may collect:

  • Name.
  • Company name.
  • Email address.
  • Phone number.
  • Job title.
  • Country.
  • Login credentials.
  • Organization data.
  • Account preferences.
  • Language and time zone settings.
  • Data of users associated with the organization.

5. Organization Data

When using Enterprise or Organization Management services, information such as the following may be processed:

ZynReach already provides Organization Management capabilities that include organizational identity, roles, branches, custom domains, and other organization settings.

  • Organization name.
  • Organizational structure.
  • Branches.
  • Departments.
  • Roles.
  • Permissions.
  • Organization settings.
  • Domains.
  • User data.
  • Security settings.

6. Customer Data Entered by Users

A user or customer may enter data within the platform, including:

This data may include personal information relating to other individuals.

  • Customer data.
  • Prospective customer (lead) data.
  • Employee data.
  • Supplier data.
  • Contact data.
  • Company data.
  • Notes.
  • Documents.
  • Invoices.
  • Transaction records.
  • Project data.
  • Support data.
  • Marketing data.
  • Communications data.

7. Customer Responsibility for Data It Enters

When a customer enters personal data relating to its employees, customers, suppliers, or other parties, the customer is responsible for ensuring that it:

  • Has the right or legal basis necessary to process the data.
  • Provides the required notices to the data subjects.
  • Does not enter data it does not have the right to process.
  • Complies with the laws applicable to its activity.
  • Uses ZynReach in a manner consistent with the agreement and the DPA.

8. ZynReach as a Data Processor

When ZynReach processes personal data on behalf of the customer and in accordance with its instructions, ZynReach acts, depending on applicable law, as a Data Processor / Service Provider.

The customer is the party that determines the purposes and means of processing to the extent applicable to it under law.

In this case, the processing is governed by the applicable commercial agreement and the Data Processing Agreement (DPA).

ZynReach's currently published DPA states that the Company processes personal data on behalf of the customer and on the basis of its documented instructions, except as required by law.

9. ZynReach as a Data Controller

In other cases, such as the management of:

ZynReach may act as a Data Controller / Business.

In this case, it determines the purposes and means of processing data in accordance with applicable law.

  • The website.
  • Marketing.
  • Prospective customers (leads).
  • User accounts.
  • Sales.
  • Support.
  • Security.
  • Analytics.
  • Business relationships.

10. Data Collected Automatically

When visiting the website or using the platform, technical information may be collected, such as:

This information is used for purposes including security, operating the service, improving performance, analytics, detecting misuse, and troubleshooting.

  • IP address.
  • Device type.
  • Operating system.
  • Browser type.
  • Device or session identifiers.
  • Pages visited.
  • Date and time of visit.
  • Duration of use.
  • Referral source.
  • Performance information.
  • Error logs.
  • Information about interaction with the service.

11. Usage Data

ZynReach may record information about how the services are used, such as:

This data may be linked to the user's or organization's account when necessary for legitimate purposes.

  • Features used.
  • Operations performed.
  • Login times.
  • Account settings.
  • Search queries.
  • Interaction with interfaces.
  • Errors.
  • System events.

12. Audit Logs

ZynReach uses audit logs to help organizations track activity within the platform.

Audit logs may include:

ZynReach notes that the platform records activities such as record changes, approvals, logins, and configuration changes within a searchable audit log.

These logs are handled in accordance with security, governance, legal, and applicable contractual requirements.

  • User identity.
  • The operation performed.
  • The time of the operation.
  • The affected resource.
  • The changes made.
  • Settings associated with the operation.

13. Business Data and Lead Generation

ZynReach provides capabilities related to company and contact discovery, building lead lists, and data enrichment.

As a result, certain company or contact data obtained from public sources, commercial sources, data providers, licensed databases, and technical or commercial sources available under their own terms may be processed.

This data may include:

  • Name.
  • Job title.
  • Company name.
  • Business email address.
  • Business phone number.
  • Company information.
  • Industry.
  • Location.
  • Firmographic data.
  • Technographic data.
  • Business-related information.

14. Public Availability Does Not Mean "Non-Personal"

The fact that a piece of information is publicly available does not mean it is "non-personal."

Nor does its public availability mean that its use is not subject to applicable laws.

ZynReach treats personal data in accordance with its nature and the applicable law, not merely according to its source.

15. Third-Party Data Sources

When ZynReach obtains data from external sources or providers, it seeks to use sources and vendors that are appropriate under the applicable legal and contractual requirements.

Data received from service providers may be subject to terms of use, licensing restrictions, or legal requirements specific to the source.

16. Purposes of Data Processing

ZynReach may use personal data for the following purposes:

  • Service provision: creating the account, operating the platform, authentication, executing operations, delivering features, managing the organization.
  • Customer support: responding to inquiries, handling support requests, troubleshooting issues, communicating with the user.
  • Sales: following up on demo requests, managing leads, scheduling demos, managing the business relationship.
  • Marketing: sending marketing messages, delivering relevant content, measuring campaign effectiveness, subject to consent or opt-out requirements where required by law.
  • Security: detecting attacks, preventing fraud, detecting misuse, protecting accounts, investigating incidents.
  • Analytics: understanding service usage, improving products, improving user experience, measuring performance.
  • Compliance: fulfilling legal obligations, responding to legitimate government requests, retaining required records.

18. Legitimate Interests

When ZynReach relies on Legitimate Interests, it seeks to ensure that the processing is necessary for the specified purpose, does not exceed what is required, and does not unjustifiably override the individual's rights and interests in favor of the Company's interest.

Legitimate interests may include:

  • Platform security.
  • Fraud prevention.
  • Service improvement.
  • Product development.
  • Managing business relationships.
  • Protecting legal rights.
  • Managing operations.

20. Marketing Communications

ZynReach may send:

The ability to opt out of each type of communication varies according to its nature.

Messages necessary for operating the account or its security may not be opted out of when they are necessary to provide the service.

  • Operational messages.
  • Account-related notifications.
  • Security messages.
  • Service updates.
  • Support messages.
  • Marketing offers.
  • Educational content.

21. Marketing Opt-Out

Users can unsubscribe from marketing communications through:

ZynReach must remain able to send messages necessary for the service, security, or contractual obligations.

  • The unsubscribe link.
  • Account settings, where available.
  • Contacting ZynReach.

22. Cookies

ZynReach may use cookies and similar technologies.

These may include:

  • Essential Cookies — necessary to operate the website or platform.
  • Security Cookies — help protect sessions and accounts.
  • Analytics Cookies — used to understand how the website is used.
  • Preference Cookies — used to remember user settings.
  • Marketing Cookies — may be used for marketing purposes or to measure campaigns where legally permitted.

24. Data Sharing

ZynReach does not sell personal data merely to generate revenue from the sale of personal data.

Data may be shared, when necessary, with:

The current Compliance page describes the categories of sub-processors used for hosting, email, analytics, and customer support.

  • Infrastructure providers.
  • Email providers.
  • Analytics providers.
  • Customer support providers.
  • Payment service providers.
  • Security providers.
  • Sub-processors.
  • Professional advisors.
  • Competent government authorities when disclosure is legally required.

25. Sub-processors

When ZynReach processes personal data on behalf of the customer, it may use Sub-processors to provide parts of the service.

This relationship is governed by the applicable DPA and legal and contractual requirements.

ZynReach maintains a list of sub-processors, and the current Compliance page indicates that the list is kept up to date, including the purpose and processing location of each.

27. Business Transfers

In the event of:

Certain data may be transferred as part of the transaction, subject to applicable laws and data protection obligations.

Where the law requires notice to data subjects, the required steps will be taken.

  • A merger.
  • An acquisition.
  • A restructuring.
  • The sale of part of the business.
  • A transfer of assets.
  • An investment or reorganization.

28. Data Protection

ZynReach applies technical and organizational measures aimed at protecting data.

Depending on the service and environment, these include:

These controls are consistent with what is described on ZynReach's current Security page.

  • Encryption in transit.
  • Encryption at rest.
  • Least Privilege.
  • MFA.
  • RBAC/ABAC.
  • Audit Logging.
  • System monitoring.
  • Backups.
  • Vulnerability management.
  • Incident response.

29. No System Is Absolutely Secure

Despite the implementation of appropriate security controls, no system, network, or service can be guaranteed to be absolutely protected from all risks.

Accordingly, ZynReach does not provide an absolute guarantee that data will not be subject to any security incident under all circumstances.

Any specific security commitments are subject to the applicable commercial agreements, DPA, and SLA.

30. Data Retention

ZynReach retains data only for the period necessary to achieve the purpose for which it was collected, or for the period required by:

The retention period may vary depending on the type of data and its purpose.

  • Law.
  • Contract.
  • Accounting requirements.
  • Security requirements.
  • Dispute resolution requirements.
  • Fraud prevention requirements.

31. Data Deletion

When data is no longer needed, ZynReach seeks to delete it, anonymize it, or render it unidentifiable in accordance with applicable procedures and policies.

Some data may persist for a limited period in:

Deleting data from the user interface does not necessarily mean it is deleted from all backups immediately.

  • Backups.
  • Security logs.
  • Audit logs.
  • Systems subject to specific retention cycles.

32. Children's Data

ZynReach's services are not directed at children.

ZynReach does not intend to collect personal data from children without the required legal basis or consent.

If ZynReach becomes aware that it has unlawfully collected a child's data, it may take appropriate steps to delete it.

33. Sensitive Data

Users should not upload or enter sensitive personal data into ZynReach unless doing so is necessary for the service, the customer has an appropriate legal basis, it is permitted under the agreement, and appropriate controls have been implemented.

Sensitive data may include, depending on applicable law:

The customer must assess the suitability of using ZynReach for these categories before entering them.

  • Health information.
  • Biometric data.
  • Sensitive financial data.
  • Information relating to racial or ethnic origin, religion, or beliefs.
  • Information relating to sex life.
  • Data relating to children.

34. Artificial Intelligence and Data

ZynReach provides AI Assistants, AI Agents, AI Insights, and other artificial intelligence capabilities within the platform.

AI features may use data available within the scope of the service to perform the function requested by the user, depending on product and service settings.

Depending on the feature, ZynReach applies controls aimed at:

Some of ZynReach's AI Agent capabilities include human approval checkpoints and an audit trail of actions.

  • Restricting access.
  • Respecting permissions.
  • Logging activities.
  • Minimizing unnecessary data.
  • Preventing unauthorized actions.

35. AI Data Input

Users should not enter personal or confidential data into AI tools unless they have the right to do so and the feature is designed to process such data.

The customer must review the product terms and feature-specific agreements before using AI tools to process sensitive or regulated data.

36. Automated Decisions

Outputs of ZynReach's artificial intelligence should not be interpreted as final legal, medical, financial, or employment decisions merely because they are produced by an automated system.

When a decision has a legal or significant effect on an individual, the entity using ZynReach must ensure there is human oversight and the required legal basis.

37. Data Subject Rights

Depending on applicable law, an individual may have rights relating to their personal data, including:

  • Right of access — request to know what data is being processed and obtain a copy of it, where permitted by law.
  • Right to rectification — request correction of inaccurate or incomplete data.
  • Right to erasure — request deletion of data in cases permitted by law.
  • Right to restriction of processing — request restriction of data processing in specific cases.
  • Right to object — object to certain types of processing.
  • Right to withdraw consent — where processing relies on consent.
  • Right to data portability — obtain data in a structured format, where this right applies.
  • Rights relating to automated decisions — additional rights may apply where the law governs automated decision-making.

38. Data Subject Requests

Privacy requests may be submitted via: privacy@zynreach.com

ZynReach may request additional information to verify the identity of the requester before fulfilling the request, particularly if disclosure could reveal another person's personal data.

39. Identity Verification

ZynReach may take reasonable steps to verify the identity of a person submitting a request relating to personal data.

This is intended to prevent:

ZynReach will not request additional information beyond what is reasonable and necessary for verification.

  • Unauthorized access.
  • Identity theft.
  • Disclosure of another person's data.

40. Customer Representatives

If a customer submits a request relating to the data of other individuals stored within its account, ZynReach may be required to refer the request to the customer as the party that controls that data.

In this case, ZynReach acts in accordance with the DPA, the customer's instructions, and applicable law.

41. Regulatory Requests

When ZynReach receives a legal request for data, it will, to the extent permitted by law, review it and determine the scope of the information requested.

It may refuse or challenge the request if it is:

Unless prohibited by law.

  • Unlawful.
  • Unclear.
  • In excess of authority.
  • Not compliant with legal requirements.

42. International Transfers

Data may be processed in a country different from the country in which the user resides.

ZynReach currently indicates that customer data is hosted by default in data centers within the United States, with regional options available for Enterprise plans as may be agreed.

Where there are legal restrictions on international transfer, ZynReach seeks to apply a lawful transfer mechanism and appropriate safeguards.

ZynReach's current DPA includes provisions specific to international transfers and appropriate safeguards.

43. Security and Privacy in Vendor Relationships

When using a third party to process personal data, ZynReach seeks to take appropriate measures depending on the nature of the service, such as:

  • Contractual review.
  • Data protection requirements.
  • Purpose limitation.
  • Access restriction.
  • Security controls.
  • Confidentiality obligations.

44. Payment Data

When purchasing paid services, payment data may be processed through specialized payment service providers.

Users should not send full payment card details by email or through forms not designated for payment.

Payment data is processed in accordance with the payment provider's arrangements and applicable laws and standards.

45. Communication and Support Data

When communicating with the ZynReach team, correspondence may be retained, such as:

This is for purposes including providing support, resolving issues, quality assurance, security, and relationship management.

  • Email.
  • Support messages.
  • Ticket records.
  • Account data.
  • Issue details.
  • Attached files.

46. Call Recording

If ZynReach records support or sales calls, it will do so in accordance with applicable law, and participants may be notified or their consent obtained where required.

Important: this section should not actually be activated unless ZynReach genuinely uses call recording, and does so in the manner described.

47. Analytics

ZynReach may use analytics tools to understand:

Some of this data may be processed by external Analytics providers.

The current Compliance page lists the Analytics provider among the Sub-processor categories, with a stated processing location in the United States.

  • Website performance.
  • Platform usage.
  • User journeys.
  • Errors.
  • Conversions.
  • Feature usage.

49. Security as a Shared Responsibility

Protecting data is not ZynReach's responsibility alone.

The customer and user bear responsibilities including:

  • Protecting login credentials.
  • Using strong passwords.
  • Enabling MFA.
  • Not sharing accounts.
  • Managing users.
  • Reviewing permissions.
  • Protecting devices.
  • Not sending unnecessary data.

50. Data Breaches and Security Incidents

If ZynReach discovers a security incident affecting personal data, it will assess:

The customer, data subjects, or regulators may be notified where legally or contractually required.

  • The nature of the incident.
  • The type of data.
  • The number of individuals affected.
  • The level of risk.
  • Legal requirements.
  • Contractual obligations.

51. Not Every Technical Incident Is a Data Breach

Not every:

automatically constitutes a Personal Data Breach.

This is determined based on the facts, the risks, and applicable law.

  • Alert.
  • Failed Login.
  • Vulnerability.
  • Service Incident.
  • Technical Error.

52. Retention of Compliance Records

ZynReach may retain records relating to:

This is for the period necessary for compliance, governance, and defense of legal rights.

  • Consents.
  • Data subject requests.
  • Incidents.
  • Disclosures.
  • Audit activities.
  • Legal requests.

53. Changes to This Privacy Policy

ZynReach may update this Policy from time to time due to:

The updated version is published on the website with the last updated date indicated.

  • Product development.
  • Addition of services.
  • Technical changes.
  • Legal changes.
  • Changes in vendors.
  • Changes in data processing practices.

54. Notice of Material Changes

If a change is material and significantly affects users' rights or the way their data is processed, ZynReach may take additional steps to provide notice in accordance with applicable law.

55. No Additional Contractual Rights Created

This Policy, by itself, does not create contractual obligations beyond those set out in:

In the event of a conflict, reference will be made to the applicable legal agreement and the governing law.

  • Terms of Service.
  • Master Service Agreement.
  • DPA.
  • Enterprise Agreement.
  • SLA.

56. Protection of Intellectual Property and Confidential Information

This Privacy Policy does not grant the user any right to:

Confidential information must be protected in accordance with the applicable agreements.

  • Source Code.
  • Algorithms.
  • Trade Secrets.
  • Security Architecture.
  • Internal Documentation.

57. Regulatory Compliance

ZynReach seeks to develop its privacy and security practices in a manner consistent with relevant legal requirements and regulatory frameworks.

The ZynReach website currently references:

This does not mean that use of ZynReach automatically makes the customer compliant with every requirement of any law or standard.

  • GDPR — with respect to legal basis, data subject rights, and the DPA.
  • CCPA — with respect to the rights and disclosures applicable to California residents.
  • SOC 2 Type II — within the scope of the controls disclosed.
  • ISO 27001 aligned — with respect to information security management practices.

58. GDPR

Where the GDPR applies to ZynReach's processing of personal data, the Company seeks to support the relevant rights and obligations in accordance with its role in the processing.

This may include:

ZynReach currently provides a DPA to Enterprise customers, and the Compliance page indicates that its GDPR framework includes documentation of the legal basis, data subject rights, and the availability of a DPA for European data.

  • Lawful Basis.
  • Data Subject Rights.
  • Data Processing Agreement.
  • International Transfers.
  • Security Measures.
  • Data Breach Procedures.
  • Data Protection by Design.

59. CCPA / CPRA

Where California consumer privacy laws apply, ZynReach seeks to provide the rights and disclosures legally required.

Depending on the circumstances, these rights may include:

This section should not be interpreted as an acknowledgment that every user has every right under all circumstances; rights depend on applicable law and the user's status.

  • Knowing what data is collected.
  • Requesting access.
  • Requesting deletion.
  • Correcting data.
  • Restricting certain types of use.
  • Objecting to certain processing activities.

60. No Sale of Personal Data

ZynReach does not sell personal data merely to sell it to third parties.

In cases where ZynReach uses service providers to process data, the use is for specific operational or business purposes and in accordance with the contractual relationship and applicable law.

Any legal term such as "Sale" or "Sharing" must be interpreted in accordance with the definition set out in applicable law, not according to its general commercial meaning.

61. Do Not Sell or Share

If ZynReach becomes subject to a legal obligation to provide a separate mechanism for Do Not Sell or Share My Personal Information,

the appropriate mechanism will be made available to the users covered by that law.

62. Rights of California Residents

Users covered by applicable California laws can submit privacy requests via: privacy@zynreach.com

ZynReach may request information to verify the request in accordance with legal requirements.

63. Rights of EU and EEA Residents

If the user is subject to the GDPR, they may exercise their rights via: privacy@zynreach.com

Where the appointment of a legal representative within the European Union is required, ZynReach must update this Policy with that representative's details before publishing this version as a final version directed specifically at the European Union.

64. Right to Lodge a Complaint

A data subject has the right, where permitted by law, to lodge a complaint with the competent data protection authority in the country or region in which they reside or in which the alleged infringement occurred.

Contacting ZynReach first does not prevent the exercise of this right.

66. Relationship with the Data Processing Agreement

When ZynReach processes personal data on behalf of the customer, the DPA is the primary document that sets out the rights and obligations of the parties with respect to the processing, to the extent provided by law and the agreement.

ZynReach currently maintains a published DPA that sets out the subject matter and scope of processing, sub-processors, security measures, data subject rights, and international transfers.

67. Relationship with the Security & Trust Policy

The Privacy Policy explains how personal data is collected, used, shared, and protected.

The Security & Trust Policy explains the security, technical, and organizational framework that ZynReach uses to protect the platform and data.

Neither document replaces the other.

68. Relationship with the Security & Compliance Documentation Request Policy

The Security & Compliance Documentation Request Policy sets out the terms and procedures for requesting restricted security and compliance documentation.

Publication of this Privacy Policy does not automatically grant any person the right to obtain confidential or restricted security documentation.

69. Privacy Requests

For all privacy requests, you may contact the Privacy Team at privacy@zynreach.com

The request should preferably include:

  • Name.
  • Email address.
  • Company, where applicable.
  • The nature of the request.
  • A description of the data requested.
  • Any information necessary for verification.

71. Security

To report a security issue to ZynReach: security@zynreach.com

Passwords, API keys, or sensitive customer data should not be sent by email.

72. General Contact

ZynReach / Zyntra Digital

The website currently displays general contact information, phone numbers, and the corporate address in Egypt.

  • Email: info@zynreach.com
  • Privacy: privacy@
  • Legal: legal@zynreach.com
  • Security: security@zynreach.com
  • Website: ZynReach.com

73. Effective Date

This Policy takes effect as of August 31, 2026.

It remains in effect until replaced by an updated version.

74. Document History

Summary of this document's details:

  • Document Name — Privacy Policy & Data Protection Notice
  • Company — Zyntra Digital / ZynReach
  • Version — 1.0
  • Effective Date — 31 August 2026
  • Classification — Public Legal Policy
  • Owner — Legal & Privacy
  • Privacy Contact — privacy@zynreach.com
  • Legal Contact — legal@zynreach.com
  • Security Contact — security@zynreach.com
  • Review Cycle — At least annually
  • Status — Official

For privacy-related requests, contact us at privacy@zynreach.com.