This Privacy Policy explains how Zargina Artificial Intelligence Services LLC ("Zargina", the "Company", "we", "us" or "our") collects, uses, discloses, transfers, retains and protects personal data in connection with the Banzena platform available at banzena.com (the "Platform" or "Banzena"), a hosted, multi-tenant e-commerce service that enables merchants to build and operate their own online stores using an AI store builder, hosting, included custom domains with SSL, checkout, and order, customer and store management tools. It applies to merchants and prospective merchants who register for or use the Platform ("Merchant", "you"), to visitors of our marketing website, and, in a limited capacity described below, to the shoppers and customers who interact with stores that Merchants operate using Banzena.
We have written this Policy to be read alongside our Terms of Service and our Cookie Policy, which together govern your use of the Platform. A central concept of this Policy is the distinction between two categories of personal data: (a) data relating to Merchants, their accounts and their use of the Platform, for which the Company acts as the controller; and (b) data relating to a Merchant's own store customers, for which the Merchant is the controller and the Company acts only as a processor following that Merchant's instructions. Understanding this distinction is important, because it determines who is responsible for the data, which privacy notice applies, and to whom an individual should direct a privacy request. We are committed to handling personal data fairly, lawfully and transparently, and to designing the Platform with privacy and security in mind. If you do not agree with this Policy, please do not access or use the Platform. For any privacy, data-protection or related questions, you can reach us at support@banzena.com.
1. Introduction and Scope
This Privacy Policy describes our practices regarding personal data that we collect, generate, or otherwise process through the Banzena Platform, our marketing website, our communications with you, and related services, features and tools (collectively, the "Services"). It is intended to satisfy our transparency obligations under applicable data-protection and privacy laws, including, where relevant, the EU General Data Protection Regulation ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"). Nothing in this Policy is intended to grant rights beyond those available under the laws applicable to you, and where a mandatory provision of applicable law conflicts with this Policy, that mandatory provision prevails to the extent of the conflict.
This Policy applies to personal data processed by the Company in its capacity as controller, principally data relating to Merchants, their authorised users, prospective Merchants, and website visitors. It also explains, at a high level, the personal data we process as a processor on behalf of Merchants in respect of their store customers. It does not replace any separate privacy notice that an individual Merchant publishes to its own customers, and it does not govern the independent data-processing activities of Merchants, payment processors, or other third parties who determine their own purposes for processing personal data, and over whose practices the Company has no control and assumes no responsibility.
By creating an account, accessing or using the Services, you acknowledge that you have read and understood this Policy. Where we rely on your consent for a specific processing activity, we will ask for it separately, and you may withdraw that consent at any time as described in Section 11. Capitalised terms used but not defined in this Policy have the meaning given to them in our Terms of Service, which this Policy supplements and into which it is incorporated by reference.
2. Our Roles: Controller and Processor
Data-protection law distinguishes between a "controller", who determines the purposes and means of processing personal data, and a "processor", who processes personal data on behalf of and under the instructions of a controller. The Company acts in different roles depending on the type of data concerned, and it is important to understand which role applies, because the role determines who is accountable for a given processing activity and to whom an individual should address a request.
Controller of Platform and account data. With respect to personal data about Merchants, prospective Merchants, the individuals who administer or use a Merchant account, and visitors to our marketing website, including registration and billing identifiers, account configuration, support communications, and technical, usage and device data generated through use of the Platform, the Company is the controller. This Policy is our controller-facing privacy notice for that data.
Processor of Merchant-customer data. With respect to personal data relating to a Merchant's own store customers, such as the names, contact details, shipping and billing information, order history and similar data that shoppers provide when interacting with or purchasing from a store built on Banzena, the Merchant is the controller and the Company acts solely as a processor. We process that data on the Merchant's behalf and on the Merchant's documented instructions, in order to host the store, operate checkout, deliver hosting, security and email functionality, store orders, and provide the administrative dashboard. We do not use Merchant-customer personal data for our own independent purposes, and we do not sell it. The handling of Merchant-customer data is also addressed in Section 12 and is governed by the data-processing terms incorporated into our Terms of Service.
Where the Company and a Merchant each determine their own purposes for the same data, or where a payment processor or other party acts as an independent controller for its own purposes, each party is responsible for its own processing under applicable law, and no joint-controller or agency relationship is created between the Company and any Merchant except as expressly agreed in writing.
3. Definitions
The following defined terms are used throughout this Policy:
- "Personal Data" means any information relating to an identified or identifiable natural person, such as a name, email address, online identifier, IP address, or other data that can be used, alone or in combination, to identify an individual. References to "personal data" and "personal information" are treated as equivalent for the purposes of this Policy.
- "Processing" means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, transmission, restriction, erasure or destruction.
- "Controller" means the entity that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
- "Processor" means an entity that Processes Personal Data on behalf of, and under the instructions of, a Controller.
- "Data Subject" means the identified or identifiable individual to whom Personal Data relates.
- "Merchant" means a person or entity that registers for and uses the Platform to build and operate one or more online stores, together with that Merchant's authorised users.
- "Merchant-Customer" means a shopper, customer or visitor who interacts with or purchases from a store operated by a Merchant using the Platform.
- "Sub-Processor" means a third party engaged by the Company to Process Personal Data in connection with the Services, such as our infrastructure and payment providers.
- "Services" means the Banzena Platform, our marketing website, and related features, tools and communications described in this Policy.
- "Aggregated or De-Identified Data" means data that has been aggregated, anonymised or otherwise processed so that it no longer identifies, and cannot reasonably be used to identify, an individual, and that is therefore not treated as Personal Data under this Policy.
4. Information We Collect
We collect Personal Data that you provide to us directly, data that is generated automatically when you use the Services, and, in limited cases, data we receive from third parties such as our payment processor. The categories of data we collect include the following.
- Account and registration data: the information you provide when you create or maintain a Merchant account, such as your name, business or store name, email address, login credentials (stored in hashed or otherwise protected form), store settings, and the contact details of authorised users.
- Store content and configuration: the content, settings and materials you create, upload or configure when building and running your store, including product information, catalogue and pricing data, store design and template selections, AI store-builder inputs and outputs, and other content you choose to publish.
- Payment and billing identifiers: because we charge a platform fee of one percent of each confirmed sale and facilitate card payments through Stripe, we process payment-related identifiers such as transaction references, amounts, payout and settlement information, and limited card metadata (for example, card type, the last four digits, and expiry where provided by Stripe). We do not collect or store full card numbers; full card details are collected and processed directly by Stripe under its own terms.
- Technical, usage and device data: information generated automatically through your use of the Services, including IP address, device and browser type, operating system, language settings, log files, access times, pages and features used, referring URLs, and similar diagnostic and analytics data.
- Support and communications data: the content of messages, requests, and correspondence you send to us, including support tickets sent to support@banzena.com, and records of our responses.
- Cookies and similar technologies: data collected through cookies, pixels, local storage and similar technologies on our marketing website and the Platform, as further described in Section 6 and in our Cookie Policy.
- Merchant-Customer data (as processor): when shoppers interact with or purchase from a Merchant's store, we process on the Merchant's behalf data such as customer names, email and contact details, shipping and billing addresses, order and transaction history, and related communications. We process this data only as a Processor, as described in Sections 2 and 12.
You are responsible for ensuring that any Personal Data you provide to us is accurate and that you have the necessary rights, consents or other lawful basis to provide it, including where you supply Personal Data relating to your authorised users or other third parties. Where required by law, you must inform those individuals of the Processing described in this Policy.
5. How and Why We Use Information, and Our Legal Bases
We use Personal Data for the purposes set out below. Where the GDPR, UK GDPR or similar laws apply, we rely on one or more of the following legal bases: performance of a contract with you; our legitimate interests, provided these are not overridden by your interests or fundamental rights; your consent, where we ask for it; and compliance with a legal obligation.
- To provide, operate and maintain the Services, including creating and administering your account, building and hosting your store, provisioning included custom domains and SSL, operating checkout, and providing the administrative dashboard. Legal basis: performance of our contract with you.
- To process payments and charge our platform fee, including facilitating card payments through Stripe and calculating, invoicing and collecting the one percent platform fee on confirmed sales. Legal basis: performance of our contract with you and compliance with legal obligations such as tax and accounting requirements.
- To communicate with you, including sending service, transactional, security and administrative messages, responding to support requests, and notifying you of changes to the Services or our policies. Legal basis: performance of our contract and our legitimate interest in operating and supporting the Services.
- To secure, monitor and improve the Services, including detecting, preventing and investigating fraud, abuse, bot activity and security incidents, debugging, analysing usage, and developing and improving features, including AI features. Legal basis: our legitimate interests in maintaining a secure, reliable and improving Platform, and, where applicable, compliance with legal obligations.
- To send marketing communications about our products and offerings, where permitted. Where required by law, we send such communications only with your consent or on the basis of an existing relationship, and you may opt out at any time. Legal basis: consent or our legitimate interest in promoting the Services.
- To comply with law and protect rights, including responding to lawful requests from public authorities, enforcing our Terms of Service, and protecting the rights, property and safety of the Company, Merchants, Merchant-Customers and others. Legal basis: compliance with a legal obligation and our legitimate interests.
We may create and use Aggregated or De-Identified Data derived from Personal Data for any lawful purpose, including to operate, analyse, improve, develop, benchmark and market the Services and to train and improve our AI features. Where we de-identify data, we will maintain it in de-identified form and will not attempt to re-identify it except as permitted by law. Aggregated or De-Identified Data is not subject to the rights described in Section 11.
Where we process Merchant-Customer data, we do so as a Processor for the purposes and on the instructions of the relevant Merchant, and the Merchant is responsible for establishing its own legal basis for that processing.
6. Cookies and Similar Technologies
We and our service providers use cookies, pixels, local storage and similar technologies to operate and secure the Services, remember your preferences, authenticate sessions, measure and analyse usage, and, where applicable and permitted, support marketing. Some of these technologies are strictly necessary for the Services to function, while others are optional and used only where the law permits or where you have given consent.
Detailed information about the specific technologies we use, their purposes and durations, and how you can manage or withdraw your preferences is set out in our Cookie Policy, which forms part of this Privacy Policy. You can also control cookies through your browser settings, although disabling certain cookies may affect the availability or functionality of parts of the Services. Because there is no common industry standard for recognising or honouring "Do Not Track" or similar browser signals, our Services may not respond to them, except to the extent we are required to recognise a recognised opt-out preference signal under applicable law. Stores operated by Merchants may use their own cookies and similar technologies, for which the relevant Merchant is responsible.
7. Automated Processing and AI Features
The Platform includes an AI store builder and other automated and AI-assisted features that process inputs you provide in order to generate store designs, content suggestions and related outputs, and that may process technical and usage data to operate, secure, personalise and improve the Services. These features are tools intended to assist you, and you remain responsible for reviewing, approving and using their outputs. We do not use automated processing to make decisions that produce legal or similarly significant effects concerning you without a lawful basis and, where required, appropriate safeguards.
Where we use Personal Data or content to develop or improve our AI features, we do so in accordance with this Policy and applicable law, and, in respect of Merchant-Customer data, only as permitted by our data-processing terms and the relevant Merchant's instructions. Outputs generated by AI features may be inaccurate or incomplete and should not be relied upon as professional, legal, financial or other specialised advice. To the extent permitted by applicable law, you are responsible for ensuring that your use of AI-generated outputs complies with all laws applicable to your store and your customers.
8. Disclosure of Information and Sub-Processors
We do not sell Personal Data. We disclose Personal Data only as described in this Policy, including to the categories of recipients set out below, and we require our Sub-Processors to protect Personal Data and to use it only for the purposes for which it is disclosed.
- Infrastructure and security provider: Cloudflare provides hosting, content delivery, security and bot-protection, and transactional email delivery for the Platform. In that capacity, Cloudflare processes Personal Data, including technical, usage and email-delivery data, as our Sub-Processor.
- Payment processor: Stripe processes card payments and related transactions. Stripe collects and processes full card details directly and acts as an independent controller for its own payment-processing, fraud-prevention and regulatory purposes, in addition to processing certain transaction data on our behalf.
- Other service providers: we may engage additional vendors who perform functions on our behalf, such as analytics, error monitoring, customer support tooling, and professional advisers, who Process Personal Data as Sub-Processors under appropriate contractual protections.
- Legal, safety and compliance disclosures: we may disclose Personal Data where we reasonably believe it is necessary to comply with applicable law or a lawful request, to enforce our Terms of Service, to detect, prevent or address fraud, security or technical issues, or to protect the rights, property or safety of the Company, Merchants, Merchant-Customers or the public.
- Business transfers: if the Company is involved in a merger, acquisition, financing, reorganisation, or sale or transfer of all or part of its assets, Personal Data may be transferred as part of that transaction, subject to the continued protection of this Policy or a successor policy with materially equivalent protections.
Where we disclose Merchant-Customer data, we do so as a Processor in accordance with the relevant Merchant's instructions and our data-processing terms. A list or description of our current Sub-Processors is available on request via support@banzena.com.
9. International Data Transfers and Safeguards
The Company and its Sub-Processors, including Cloudflare and Stripe, operate global infrastructure, and Personal Data may be transferred to, stored in, or accessed from countries other than the country in which you are located. Some of these countries may have data-protection laws that differ from those of your jurisdiction.
Where we transfer Personal Data internationally in a manner regulated by the GDPR, UK GDPR or similar laws, we implement appropriate safeguards to protect that data, which may include relying on adequacy decisions, entering into Standard Contractual Clauses (or the UK International Data Transfer Agreement or Addendum), and applying supplementary technical and organisational measures. You may request further information about the safeguards we use for a specific transfer by contacting us at support@banzena.com.
10. Data Retention
We retain Personal Data for as long as it is necessary to fulfil the purposes for which it was collected, including to provide the Services, maintain your account, operate your store, and comply with our legal, accounting, tax and reporting obligations, resolve disputes, and enforce our agreements. Retention periods vary depending on the type of data and the purpose for which it is processed, and may extend beyond the termination of your account where retention is required or permitted by law or is necessary to protect our legal interests.
When Personal Data is no longer required for these purposes, we will delete it or anonymise it so that it can no longer be associated with you, unless a longer retention period is required or permitted by law. With respect to Merchant-Customer data that we process as a Processor, we retain and delete that data in accordance with the relevant Merchant's instructions and our data-processing terms, subject to any retention required by applicable law.
11. Security Measures and Breach Notification
We implement and maintain technical and organisational measures designed to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, alteration, disclosure or access. These measures include encryption of data in transit, access controls and authentication, network and application security provided through our infrastructure provider, the use of established payment infrastructure that means we do not store full card numbers, and monitoring designed to detect and respond to security incidents.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for the security of the devices you use to access the Services, and you agree to notify us promptly at support@banzena.com if you suspect any unauthorised access to or use of your account. To the maximum extent permitted by applicable law, the Company is not responsible for any unauthorised access to, alteration of, or loss of Personal Data that results from circumstances beyond our reasonable control, including your own acts or omissions.
In the event of a personal-data breach affecting Personal Data for which we are the controller, we will assess the incident and, where required by applicable law, notify the relevant supervisory authority and affected individuals without undue delay and in accordance with the timeframes prescribed by law. Where we act as a Processor for Merchant-Customer data, we will notify the relevant Merchant of a personal-data breach affecting that data in accordance with our data-processing terms, so that the Merchant, as controller, can fulfil its own notification obligations.
12. Your Privacy Rights
Depending on your location and the applicable law, you may have some or all of the following rights in relation to Personal Data for which the Company is the controller. We will respond to requests in accordance with applicable law and may need to verify your identity before acting on a request. We may decline or limit a request to the extent permitted by law, including where it is manifestly unfounded or excessive, or where complying would adversely affect the rights and freedoms of others.
- Access: the right to obtain confirmation of whether we Process your Personal Data and to obtain a copy of that data.
- Rectification: the right to have inaccurate Personal Data corrected and incomplete data completed.
- Erasure: the right to request deletion of your Personal Data in certain circumstances.
- Restriction: the right to request that we restrict the Processing of your Personal Data in certain circumstances.
- Portability: the right to receive certain Personal Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller.
- Objection: the right to object to Processing based on our legitimate interests, and to object at any time to Processing for direct-marketing purposes.
- Withdraw consent: where we rely on your consent, the right to withdraw it at any time, without affecting the lawfulness of Processing carried out before withdrawal.
- Complain to a supervisory authority: the right to lodge a complaint with your local data-protection or supervisory authority.
For residents of California and other jurisdictions with comparable laws, you may have the right to know the categories and specific pieces of personal information we have collected, the right to delete and to correct your personal information, and the right to opt out of the "sale" or "sharing" of personal information and to be free from discrimination for exercising your rights. The Company does not sell your Personal Data, and we do not "share" it for cross-context behavioural advertising in the sense those terms are used under the CCPA/CPRA. You may exercise your rights, or use an authorised agent to do so, by contacting us at support@banzena.com.
If your request concerns Personal Data that relates to your activity as a Merchant-Customer of a particular store, the relevant Merchant is the controller of that data, and we will, where appropriate, direct your request to that Merchant or assist the Merchant in responding.
13. Merchant-Customer Data and Merchant Responsibilities
When you operate a store using Banzena, you are the controller of the Personal Data of your store customers, and the Company acts as your Processor with respect to that data. As controller, you are responsible for ensuring that your collection and use of Merchant-Customer Personal Data complies with all applicable data-protection and consumer-protection laws.
- Lawful basis and transparency: you are responsible for establishing a valid legal basis for processing Merchant-Customer data and for providing your customers with a clear and accurate privacy notice describing your own data practices.
- Consents and preferences: you are responsible for obtaining and honouring any consents required for your processing and marketing activities, including consents for cookies and similar technologies used on your store.
- Data-subject requests: you are responsible for responding to privacy requests from your store customers, and we will provide reasonable assistance, as required by our data-processing terms, to help you do so.
- Instructions and compliance: you must give us only lawful instructions regarding Merchant-Customer data, and you must not use the Services to process special categories of data or data of minors except where lawful and properly safeguarded.
Our Processing of Merchant-Customer data on your behalf is governed by the data-processing terms incorporated into our Terms of Service, which set out the subject matter, duration, nature and purpose of the Processing, the types of Personal Data and categories of Data Subjects, and the obligations and rights of each party. To the extent permitted by applicable law, you agree to indemnify, defend and hold harmless the Company and its affiliates, and their respective officers, directors, employees and agents, from and against any claims, demands, losses, liabilities, damages, fines, penalties, costs and expenses (including reasonable legal fees) arising out of or relating to your breach of this Section 13, your instructions, your privacy notices, or your processing of Merchant-Customer Personal Data.
14. Children's Privacy
The Services are intended for use by businesses and adults and are not directed to children. We do not knowingly collect Personal Data directly from children under the age of 13, or under the applicable minimum age in your jurisdiction (which may be 16 in parts of the European Economic Area), for our own purposes as a controller.
If you believe that a child has provided us with Personal Data in a context where the Company is the controller, please contact us at support@banzena.com and we will take appropriate steps to delete that information. Where children's data may be present in a Merchant's store, the relevant Merchant is responsible, as controller, for complying with all applicable laws relating to the processing of children's data.
15. Third-Party Links and Services
The Services, our marketing website, and stores operated by Merchants may contain links to, or integrations with, third-party websites, products and services that are not operated or controlled by the Company, including the websites and services of our payment processor and other providers. This Policy does not apply to those third parties.
We are not responsible for the privacy practices or content of third-party websites or services, and we encourage you to review the privacy notices of any third party before providing your Personal Data to them. The inclusion of a link or integration does not imply our endorsement of the relevant third party.
16. Intellectual Property and Ownership
The "Banzena" name, the Banzena logo and marks, this Privacy Policy and its text, the Platform and its software, source code, designs, store templates, AI features, databases, and all related intellectual property are owned exclusively by Zargina Artificial Intelligence Services LLC and are protected by copyright, trademark, trade-secret, database and other applicable laws. Nothing in this Policy transfers to you, or grants you any licence to, any right, title or interest in or to the Company's intellectual property, except for the limited right to access and use the Services in accordance with our Terms of Service.
You may not copy, reproduce, modify, distribute, publish, frame, scrape, or create derivative works from this Policy, the Platform, or any of the Company's marks or content, except as expressly permitted in writing by the Company or as permitted by mandatory applicable law. All rights not expressly granted are reserved by Zargina Artificial Intelligence Services LLC. To the extent that Aggregated or De-Identified Data, analytics, models, improvements, or other materials are generated by the Company in connection with the Services, such materials and all intellectual property rights in them are and remain the exclusive property of the Company.
17. Disclaimers and Limitation of Liability
While we take the protection of Personal Data seriously and apply the measures described in this Policy, the Services are provided on an "as is" and "as available" basis with respect to privacy and data-handling functionality, and, to the maximum extent permitted by applicable law, the Company makes no warranty, express or implied, that the Services or our security measures will be uninterrupted, error-free, or immune from unauthorised access, loss, misuse or alteration of data. This Section does not limit or exclude any right or remedy that cannot be limited or excluded under applicable mandatory data-protection law, including any non-waivable right to compensation a Data Subject may have under the GDPR, UK GDPR or similar laws.
To the maximum extent permitted by applicable law, and except in respect of liability that cannot be limited or excluded by law, the Company and its affiliates, and their respective officers, directors, employees, agents and Sub-Processors, shall not be liable for any indirect, incidental, special, consequential, exemplary or punitive damages, or for any loss of profits, revenue, goodwill, data or business, arising out of or in connection with this Policy or our Processing of Personal Data, whether based in contract, tort (including negligence), strict liability or otherwise, even if advised of the possibility of such damages. To the maximum extent permitted by applicable law, the aggregate liability of the Company arising out of or relating to this Policy is subject to, and shall not exceed, the limitations and caps on liability set out in our Terms of Service.
Nothing in this Policy excludes or limits liability for fraud or fraudulent misrepresentation, for death or personal injury caused by negligence, or for any other liability that cannot lawfully be excluded or limited. Where applicable law does not allow the exclusion or limitation of certain warranties or liabilities, the relevant exclusions and limitations apply only to the extent permitted by that law.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. When we make changes, we will revise the policy and, where appropriate, update the effective date or otherwise indicate when the policy was last revised.
If we make material changes, we will provide notice through the Services or by other reasonable means before the changes take effect, where required by applicable law. Your continued use of the Services after the updated Policy becomes effective constitutes your acknowledgement of the updated Policy, to the extent permitted by law.
19. General Provisions
This Privacy Policy, together with our Terms of Service, Cookie Policy and any data-processing terms incorporated by reference, constitutes the entire understanding between you and the Company regarding the Processing of Personal Data, and supersedes any prior privacy statements on the same subject matter. If any provision of this Policy is found to be invalid, unlawful or unenforceable, that provision will be severed or limited to the minimum extent necessary, and the remaining provisions will continue in full force and effect.
Our failure to enforce any provision of this Policy is not a waiver of that provision or of any other provision, and no waiver is effective unless made in writing. You may not assign or transfer your rights or obligations under this Policy without our prior written consent, while the Company may assign this Policy, in whole or in part, to an affiliate or in connection with a merger, acquisition, reorganisation, financing, or sale or transfer of assets. This Policy is binding on and enures to the benefit of the parties and their permitted successors and assigns. Headings are for convenience only and do not affect interpretation.
20. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), gives you specific rights regarding your personal information. This section supplements the rest of this Privacy Policy and applies only to the extent the CCPA governs our Processing of your personal information. The Company has not "sold" or "shared" personal information, as those terms are defined under the CCPA, in the preceding twelve months.
Categories of personal information we collect. In operating the platform we collect: identifiers (such as name, email address, account username and IP address); commercial information (such as your store, plan and transaction records); internet or other electronic network activity (such as usage and device information); and other information you choose to provide. We collect these categories for the business purposes described in this Policy and disclose them to the service providers and sub-processors named in this Policy. Payment card details are handled by our payment processor; the Company does not store full card numbers.
Do not sell or share; sensitive information. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not collect or use "sensitive personal information" (as defined by the CCPA) for the purpose of inferring characteristics about you, and we limit any use of such information to the purposes permitted under the CCPA. Because we do not sell or share personal information, we do not offer financial incentives in exchange for it.
- The right to know the categories and specific pieces of personal information we have collected, used and disclosed about you;
- The right to request deletion of your personal information, subject to legal exceptions;
- The right to correct inaccurate personal information;
- The right to opt out of the sale or sharing of personal information (noting that we do not sell or share);
- The right to limit the use and disclosure of sensitive personal information; and
- The right not to receive discriminatory or retaliatory treatment for exercising any of these rights.
To exercise your California rights, contact us at support@banzena.com. You may use an authorised agent to submit a request on your behalf, provided the agent can demonstrate authority to act for you and we can verify your identity. California's "Shine the Light" law permits California residents to request information about disclosures of personal information to third parties for those third parties' direct-marketing purposes; we do not disclose personal information to third parties for their own direct marketing.
21. Exercising Your Rights: Verification, Timeframes and Preference Signals
When you submit a rights request, we will take reasonable steps to verify your identity before acting on it, which may require you to confirm information already associated with your Account. We will not disclose personal information in response to a request we cannot reasonably verify.
We aim to respond to verified rights requests within the timeframes required by applicable law - generally within one (1) month under the GDPR and UK GDPR (extendable by up to two further months for complex or numerous requests, with notice), and within forty-five (45) days under the CCPA (extendable once by a further forty-five days, with notice). If we are unable to act on your request, we will explain why, subject to legal restrictions.
Some browsers and extensions transmit "Do Not Track" or Global Privacy Control signals. Because no common industry standard for Do Not Track has been finalised, our platform does not respond to Do Not Track signals; however, where required by law, we treat a recognised Global Privacy Control signal as a valid request to opt out of any sale or sharing of personal information. You also have the right to lodge a complaint with your local data-protection or privacy supervisory authority, although we encourage you to contact us first at support@banzena.com so that we can address your concerns.
22. How to Contact Us, Exercise Your Rights, and Governing Law
If you have any questions, concerns or requests regarding this Privacy Policy or our handling of Personal Data, or if you wish to exercise any of your privacy rights, you can contact us at support@banzena.com. This address also serves as the contact point for legal, privacy and intellectual-property matters relating to the Platform.
Where you contact us to exercise a right, please provide enough information for us to verify your identity and to locate the relevant Personal Data. If your request relates to data for which a Merchant is the controller, we will, where appropriate, refer you to the relevant Merchant or assist that Merchant in responding. To the extent any governing law, jurisdiction or competent courts must be determined in connection with this Policy, they shall be those of the Emirate of Abu Dhabi, United Arab Emirates, without prejudice to any mandatory data-protection rights you may have, or any complaint you may bring before a supervisory authority, under the laws of your own country of residence.
© 2026 Zargina Artificial Intelligence Services LLC. All rights reserved. Banzena, the Banzena logo and related marks are trademarks of Zargina Artificial Intelligence Services LLC. The Banzena platform and its software, designs and content are protected by copyright, trademark, trade-secret and other laws.
Banzena is a product of Zargina Artificial Intelligence Services LLC (zargina.com). Questions about this document? Email support@banzena.com.