Back
Legal
Privacy Policy and Data Security
This Privacy Policy describes how 3-101-946648 SOCIEDAD ANÓNIMA collects, uses, and protects your personal information, in accordance with Law No. 8968 on the Protection of Individuals Regarding the Processing of Their Personal Data of the Republic of Costa Rica.
Last updated: July 24, 2026
Privacy Policy
Terms and Conditions
1. Data Protection Principles
We are committed to respecting the fundamental principles of Costa Rican regulations:
Informed Consent: We only process data after your express authorization.
Data Quality: Information will be accurate, current, and truthful.
Security: We implement technical and organizational measures to prevent loss or unauthorized access.
Confidentiality: Personnel with access to your data are bound by professional secrecy.
2. Information We Collect
A. Information Provided by the User
Identification: Full name, ID number (individual or corporate), email address, and phone number.
Financial Data: Information about assets, income, expenses, debts, and investment goals necessary for financial analysis.
Credentials: Usernames and encrypted passwords for platform access.
B. Automatically Collected Information
Technical Data: IP address, browser type, operating system, and access times.
Cookies and Tracking: We use cookies to improve user experience and analyze platform performance.
3. Purpose of Data Processing
Your personal data will be used strictly for:
Providing financial advice through our technology platform.
Personalizing your user experience and improving our analysis tools.
Processing transactions and managing your account.
Complying with legal obligations for money laundering prevention (Law 7786 and amendments).
Sending administrative or promotional communications, unless you have opted out.
4. Information Security
Security is our priority. We implement protocols similar to international standards (ISO/IEC 27001 or equivalent):
Encryption: Sensitive data is transmitted using secure protocols (SSL/TLS).
Access Control: We restrict access to personal information only to employees and contractors who need to know it.
Monitoring: We conduct periodic audits of our systems to detect potential vulnerabilities.
5. Data Transfer to Third Parties
3-101-946648 S.A. does not sell, rent, or commercialize your personal data. We will only share information with third parties in the following cases:
Service Providers: Companies that help us operate the platform (cloud hosting, payment processing), who act as Data Processors under strict confidentiality contracts.
Legal Compliance: When required by a competent judicial or administrative authority in Costa Rica.
International Transfer: If we use servers outside Costa Rica, we ensure that the destination country offers adequate protection levels according to the criteria of the Data Protection Agency (PRODHAB).
6. Google and Gmail Data
If you choose to connect a Gmail or Google Workspace mailbox, Zenloth requests read-only Gmail access and basic Google account identity information only for the email import feature.
Data accessed: Google account email address, provider account identifier, OAuth access and refresh tokens, Gmail message identifiers, sender, subject, received date, and the body/content of bank notification emails that match our supported sender rules.
Data created from Gmail: parsed transaction details such as amount, currency, transaction date, merchant/payee, reference number, source message identifier, import status, and related transaction records.
Data use: we use this data to verify your mailbox, read bank notification emails, import and categorize transactions, prevent duplicate imports, show sync status, reconnect your mailbox, troubleshoot the email import feature, and protect the service.
Data we do not change: Zenloth does not send, modify, archive, delete, label, or permanently delete messages in your Gmail account.
Data protection: OAuth tokens and provider credentials are stored encrypted at rest, and Google data is transmitted using secure protocols.
Data sharing: we do not sell, rent, or transfer Google user data to advertising platforms, data brokers, information resellers, or parties that use it for credit-worthiness, lending, retargeting, personalized advertising, or interest-based advertising.
Service providers: Google user data may be processed by infrastructure and service providers only as needed to operate, secure, maintain, or improve the user-facing Zenloth features described in this policy, subject to confidentiality and security obligations.
AI/ML restrictions: Zenloth does not use raw or derived Google Workspace API data to develop, improve, or train generalized or non-personalized AI/ML models. We do not transfer raw or derived Gmail data to third-party AI/ML services for those services to train their models.
Limited Use statement: Zenloth's use and transfer of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Retention and deletion: Zenloth processes matching message bodies transiently and stores only a content-free source marker for deduplication after parsing; raw Gmail bodies are not retained in the ingestion record. Disconnecting a mailbox requests revocation of the Google OAuth grant, removes the stored connection credentials, stops future Gmail access, and deletes source identifiers, per-message metadata, and intermediate import candidates from Zenloth. If you choose to keep imported transactions, the resulting transaction records remain available for your budgets and reports; you can instead choose to delete those transactions during mailbox deletion.
Account deletion: deleting your account purges user-owned profile, financial, Gmail-derived, mailbox-credential, and AI conversation records. Privacy-minimized product-health telemetry, aggregate statistics, limited records required for security, billing, or legal obligations, and a non-identifying deletion record may remain. Solely to prevent repeated one-time trial abuse, Zenloth also retains a non-reversible, environment-specific cryptographic marker derived from the normalized email address. The marker contains neither the email address nor a user, Google, or provider account identifier and is deleted no later than 24 months after account deletion.
7. Your Rights (ARCO)
In accordance with Law No. 8968, you have the following rights:
Access: Right to know what data we have about you.
Rectification: Right to update inaccurate or incomplete data.
Cancellation/Deletion: Right to have your data deleted when no longer necessary for the purpose collected.
Opposition: Right to object to the processing of your data for specific purposes.
To exercise these rights, you may send a signed request to: NACHO@ZENLOTH.TECH. We will respond within a maximum of 5 business days.
8. Right of Withdrawal and Cancellation
In the context of digitally contracted financial services, you have the right to cancel the service in accordance with our Terms and Conditions and current consumer protection regulations in Costa Rica.
9. Informed Consent
By clicking "Accept" or continuing to use our platform, you declare that:
You have been informed of the existence of a personal database owned by 3-101-946648 S.A.
You understand the mandatory or optional nature of your responses and the consequences of refusing to provide data.
You authorize the processing of your data for the purposes described herein.
10. Contact
For any questions about this policy or the handling of your data, contact us:
Company Name: 3-101-946648 SOCIEDAD ANÓNIMA
Email: NACHO@ZENLOTH.TECH
Address: San José, Mata Redonda, from Canal Siete, 200m west and 150m south.