LOADING DATA
Privacy and data protection

Zensli Privacy Policy

This policy explains how PKG AB processes personal data in connection with the Zensli service, how data is protected, and how responsibilities are divided between Zensli and its Customers.

PKG AB Sweden Customer-controlled privacy We do not sell personal data

1 Introduction

This Privacy Policy explains how PKG AB processes personal data in connection with providing and operating the Zensli service, including Customer account, communication, billing, security, and service usage data.

Zensli can also be configured by Customers to collect, analyse, identify, segment, and activate data relating to visitors of the Customer’s websites or applications. In those circumstances, the Customer determines the purposes and configuration of the processing and normally acts as Data Controller, business, or equivalent responsible entity under applicable privacy law. PKG AB normally processes such data on the Customer’s behalf as Data Processor, service provider, or equivalent provider.

Customers are responsible for configuring and using Zensli in accordance with the privacy, electronic communications, consumer privacy, and other laws applicable to their organisation, users, purposes, and jurisdictions.

We do not sell your personal data

PKG AB does not sell Customer account, communication, billing, or service usage data to advertisers or data brokers.

2 Who We Are

PKG AB, Reg. No. SE559008922201, is a Swedish company that provides the Zensli service.

Zensli helps organisations collect and analyse website activity, create visitor profiles, identify visitors where configured, generate analytical insights, and activate customer intelligence in connected systems.

For personal data related to Customer accounts, billing, communication, security, and use of the Zensli platform, PKG AB acts as Data Controller or in an equivalent role under applicable privacy law.

When Zensli processes website visitor or application user data on behalf of a Customer, the Customer normally determines the purposes and means of that processing and acts as Data Controller, business, or equivalent responsible entity under applicable law. PKG AB normally acts as Data Processor, service provider, or equivalent provider acting on the Customer’s instructions.

The Customer determines which Zensli features are enabled, what data is collected, whether and how visitors are identified, applicable privacy and tracking settings, how long data is retained, which integrations are used, and how collected information and analytical results are used.

Processing performed by PKG AB on behalf of a Customer is governed by the Zensli Data Processing Agreement and the Customer’s documented instructions.

3 Personal Data We Collect and Use

When PKG AB acts as Data Controller or determines the purposes of processing, we may collect and process the following categories of personal data:

Account Data Name, email address, job title, contact details, organisation, billing details, account roles, and related information provided when creating or managing a Zensli account. This information is used to provide, administer, and secure the service.
Communication Data Name, email address, organisation, message content, and other information provided when contacting us for support, sales, feedback, or another request. This data is used to respond to requests and manage the Customer relationship.
Account Usage and Security Data Login times, features used, configuration changes, administrative actions, security events, IP addresses, and technical information related to use of the Zensli platform. This data supports operation, security, auditing, troubleshooting, and service improvement.
Billing and Transaction Data Subscription, invoice, payment status, company, and transaction information required to administer subscriptions, accounting, and legal obligations.
Customer-controlled visitor data

Zensli may also process website visitor and application user data on behalf of Customers. The categories of data processed depend on the Customer’s configuration, purposes, integrations, and documented instructions.

4 Customer-Controlled Processing

Zensli provides configurable analytics, identification, profiling, security, integration, and activation capabilities. The availability of a feature does not mean that the feature is appropriate or lawful for every Customer, visitor, purpose, or jurisdiction.

Customers determine how Zensli is configured for their websites and applications. Depending on the Customer’s configuration, information processed through Zensli may include:

  • Website and application activity: Page views, visits, events, interactions, clicks, downloads, form activity, referrers, URLs, paths, titles, and similar usage information.
  • Technical information: IP addresses, browser and device information, operating system, screen information, network and ASN information, language settings, and similar technical signals.
  • Identifiers and device signals: Cookies, local storage identifiers, browser or device signals, fingerprints, pseudonymous visitor identifiers, or similar technologies where enabled or used by the Customer.
  • Submitted and identified information: Information submitted through forms or otherwise provided by users, including email addresses, telephone numbers, customer IDs, external IDs, or other identifiers configured by the Customer.
  • Profiles and analytical information: Visitor profiles, segments, engagement scores, churn-risk indicators, classifications, behavioural signals, and other analytical results generated from Customer-controlled data.
  • Connected-system data: Information received from or transmitted to CRM, marketing automation, analytics, data platforms, or other systems connected by the Customer.
Customer configuration and responsibility

The Customer is responsible for determining which features and data-processing activities are appropriate for its purposes and for configuring Zensli accordingly. This includes determining any required legal basis, consent or notice requirements, opt-out mechanisms, retention periods, identification settings, and other privacy controls required under applicable law.

Customers are responsible for providing appropriate privacy notices and, where required, obtaining consent, recognising applicable privacy preference signals, or providing mechanisms through which individuals can exercise applicable privacy choices.

Zensli may provide technical capabilities that assist Customers in implementing their chosen privacy approach, but PKG AB does not determine the Customer’s legal basis or decide which optional tracking, identification, profiling, analytics, or activation features the Customer should use.

6 Your Rights and Privacy Choices

Depending on where you live, the applicable law, the nature of the processing, and the role of the organisation processing your information, you may have some or all of the following rights:

Access to your personal data.
Correction of inaccurate or incomplete data.
Erasure or deletion where the applicable conditions are met.
Restriction of processing where applicable.
Data portability where applicable.
Objection to certain processing.
Withdrawal of consent where consent is the legal basis.
Information about categories, sources, purposes, uses, and disclosures of personal information where provided by applicable law.
Opt-out from certain sale, sharing, targeted advertising, or similar processing where provided by applicable law.
The right not to receive unlawful discriminatory treatment for exercising applicable privacy rights.
The right to lodge a complaint with a competent supervisory or privacy authority.

To exercise a right concerning personal data controlled directly by PKG AB, please contact us.

If your request concerns data collected through a website or application operated by a Zensli Customer, you should normally contact that Customer directly. The Customer determines the relevant processing and is generally responsible for responding to privacy requests concerning that data.

PKG AB assists Customers with valid privacy requests concerning data processed through Zensli in accordance with the Data Processing Agreement and applicable law.

Supervisory and privacy authorities

Sweden: Integritetsskyddsmyndigheten (IMY)
EU/EEA: Your competent national data-protection supervisory authority
United Kingdom: Information Commissioner’s Office (ICO)
United States: Applicable state or federal privacy regulator or authority

7 Children’s Privacy

Zensli Customer accounts and business services are not intended for children under 16.

PKG AB does not knowingly collect Customer account data directly from children. If such information is identified, it will be handled as required by applicable law.

Customers are responsible for determining whether their websites, applications, audiences, or use of Zensli involve children or minors and for configuring and using the service in accordance with applicable age, consent, and children’s privacy requirements.

8 Who We Share Personal Data With

Personal data for which PKG AB is responsible may be disclosed to trusted providers where reasonably necessary to operate, secure, support, or administer the Zensli service or meet legal obligations.

Service Providers and Subprocessors Providers that support hosting, infrastructure, email delivery, monitoring, security, customer support, or other service operations. Providers are subject to appropriate contractual, confidentiality, and data-protection obligations where required.
Billing and Accounting Providers Providers that support subscription administration, payment processing, invoicing, accounting, and related legal obligations.
Authorities and Legal Recipients Public authorities, courts, advisers, or other recipients where disclosure is required by law or necessary to establish, exercise, or defend legal claims.
No sale of personal data by PKG AB

PKG AB does not sell or rent Customer personal data to advertisers or data brokers.

Customers may configure Zensli to transmit data to CRM, marketing automation, analytics, data platforms, or other systems and recipients selected by the Customer. Such Customer-directed transfers are controlled by the Customer.

The Customer is responsible for determining whether its collection, use, disclosure, or transfer of information constitutes a sale, sharing, targeted advertising, disclosure, or another regulated activity under the laws applicable to the Customer.

9 International Transfers

Where PKG AB transfers personal data outside the EU or EEA in connection with processing for which PKG AB is responsible, an appropriate transfer mechanism is used where required, such as an adequacy decision, Standard Contractual Clauses, or another mechanism recognised under applicable Data Protection Legislation.

Additional safeguards may be applied based on the destination, recipient, type of data, and risks associated with the transfer.

Customers may also configure Zensli to transfer data to third-party systems or services selected by the Customer. The Customer is responsible for assessing and configuring those destinations and transfers in accordance with the laws applicable to the Customer.

10 Retention of Personal Data

For personal data for which PKG AB determines the purposes of processing, data is retained only for as long as reasonably necessary for the relevant purpose, including providing and securing the service, resolving disputes, and meeting legal, accounting, and reporting obligations.

Customer account data is normally retained while the account remains active. Following termination, data is deleted or anonymised according to the applicable agreement and retention policy, normally within 30 days unless a longer period is required by law.

For website visitor, application user, analytics, identification, profile, interaction, and similar data processed on behalf of a Customer, the Customer determines the applicable retention settings and instructions, subject to the applicable agreement and technical capabilities of the service.

Customers are responsible for selecting retention periods appropriate to their purposes and applicable legal requirements.

11 How We Protect Personal Data

PKG AB implements technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction, taking into account the nature of the processing and associated risks.

Access Control

Access is restricted according to role, responsibility, and operational need.

Encryption

HTTPS protects data in transit, with appropriate encryption controls applied to stored data where implemented.

Monitoring

Relevant system and application activity is logged and monitored to support incident detection, investigation, security, and auditing.

Backup and Recovery

Backup, redundancy, and recovery procedures support the availability and resilience of the service.

Additional information is available in the Zensli Data Processing Agreement .

12 Automated Decision-Making and Profiling

PKG AB does not use Customer account, communication, or billing data to make decisions about individuals that produce legal or similarly significant effects solely through automated processing.

Customer-controlled analytics and profiling

Zensli may provide Customers with functionality for visitor identification, profiling, segmentation, engagement scoring, churn-risk analysis, classifications, automation, and similar analytical activities.

The Customer determines whether these features are enabled, how they are configured, which data is used, and how their outputs are applied.

The Customer is responsible for determining whether its use constitutes profiling, automated decision-making, targeted advertising, or another regulated activity and for implementing any notices, choices, safeguards, legal bases, or other measures required by applicable law.

13 Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the Zensli service, legal requirements, security practices, data-processing activities, or the functionality available to Customers.

Material changes may be communicated through the Zensli platform, by email, or by another appropriate method.

The version published on this page is the current version of the Privacy Policy.

14 Contact Us

Contact PKG AB if you have questions about this Privacy Policy, want to exercise a privacy right concerning data controlled directly by PKG AB, or need information about how PKG AB handles personal data.

If your request concerns information collected by a Zensli Customer through that Customer’s website, application, or connected systems, please contact the Customer directly where possible. PKG AB may assist the Customer where required under the applicable Data Processing Agreement.

A1 Appendix 1 – Technical and Organisational Measures

PKG AB applies technical and organisational measures intended to protect personal data and maintain the confidentiality, integrity, availability, and resilience of the Zensli service.

  • Access Control: Access to personal data and production systems is restricted to authorised personnel according to operational need.
  • Authentication and Authorisation: Authentication and authorisation mechanisms are used to verify users and control access to systems and functionality.
  • Encryption: Data is protected in transit using HTTPS, with appropriate encryption controls applied to stored data where implemented.
  • Customer Data Separation: Technical and application controls are used to separate Customer accounts and Customer-controlled data and to restrict access according to the relevant Customer and authorised users.
  • Monitoring and Logging: Relevant system and application activities are monitored and logged to support security, detection, investigation, troubleshooting, and auditing.
  • Incident Response: Procedures are maintained for identifying, handling, investigating, and documenting security incidents.
  • Availability and Redundancy: Infrastructure, backup, redundancy, and recovery mechanisms are used as appropriate to support continued availability and resilience.
  • Personnel Confidentiality: Personnel authorised to handle personal data are subject to appropriate confidentiality obligations.
  • Customer Configuration: Zensli provides configurable functionality that enables Customers to determine how certain visitor data, identification features, integrations, analytical functions, and retention settings are used within their implementation.

For additional details, refer to the Zensli Data Processing Agreement .

Agreement and applicable terms

Use of the Zensli service is also governed by the applicable subscription agreement, Terms of Service, Data Processing Agreement, and any additional terms agreed between PKG AB and the Customer.

Customer responsibility

Privacy and data-protection requirements vary by jurisdiction, purpose, technology, and context. Customers are responsible for evaluating their own legal requirements and configuring and using Zensli accordingly. The availability of a Zensli feature does not constitute a determination by PKG AB that the feature may be used without consent, notice, opt-out, or another legal requirement.