This is the first published version of this policy. Changes to it are made as described in section 16.
This is a translation provided for convenience. The Bulgarian text is authentic and prevails in the event of any discrepancy.
Who operates ZynTrail
| Legal name | Dedilayer Ltd. |
|---|---|
| Registered seat and address of management | Sofia, Bulgaria |
| Email for data protection matters | privacy@zyntrail.com |
| Service website | https://app.zyntrail.com |
These details are also published pursuant to Art. 4 of the Bulgarian Electronic Commerce Act (Закон за електронната търговия).
No Data Protection Officer has been designated. The reasoning is set out in section 12 — we state it rather than stay silent, because "no DPO" and "we never considered the question" look identical from the outside and are not the same thing. For any data protection matter, use the address above.
First, the thing that governs everything else: ZynTrail wears two hats
ZynTrail is a platform that companies use to serve their own customers. For some data we decide; for other data the customer company decides. In law these are two distinct roles, and conflating them is the most common defect in documents of this kind. So we separate them here, before anything else:
| Category of data | ZynTrail's role | Who is the controller |
|---|---|---|
| Customer company account and subscription data — contact person, email, billing, payments | Controller | ZynTrail |
| Identification, sign-in, sessions and security logs for the customer's users | Controller (limited scope — see 2.1) | ZynTrail |
| Everything the customer company enters into or receives through the platform — its own customers and contacts, tickets, messages, files, calls | Processor | The customer company |
| Working-time data of the customer's staff — shifts, leave, swaps, attendance, activity | Processor | The customer company |
Sections 3 – 13 concern the first two rows and constitute the notice required by Arts. 13 and 14 GDPR.
Section 14 concerns the last two rows. It is informational only. For that data ZynTrail is not the controller and this policy does not constitute a notice under Art. 13 or Art. 14 GDPR. That notice is owed by the relevant customer company.
2.1 Why the security log is our responsibility and not the customer's
Who signed in and when, from which address, which session was rejected, which administrator changed what — we create these records on our own decision, in order to protect the environment. The customer does not instruct us to keep them and cannot instruct us to stop without leaving us unable to protect the other tenants. So for these we are the controller, on the basis of Art. 6(1)(f) GDPR read with Recital 49, which expressly recognises network and information security as a legitimate interest.
The converse is equally true and less often admitted: shift, leave and attendance data is not ours. It is the customer company's HR data, even though it concerns people who hold accounts with us. For that data we are a processor.
2.2 How you came to see this policy if you work for one of our customers
Your account was created by your employer, not by you. That means we obtained your data indirectly for our own layer of processing, so the applicable notice is Art. 14, not Art. 13. We therefore do two things: we present this policy at your first sign-in and record the acknowledgement; and we require your employer, by contract, to have informed you. Either one alone would be thin.
What we process as controller
Contact person and administrators of the customer company: first and last name, work email, work telephone (where provided), job title and role in the system, interface language.
All users with an account: account identifier, role, department, sign-in records and active sessions, date and time of last sign-in, IP address in web server logs, session cookie identifiers, records of actions in the security log.
For billing: the customer company's name, EIK (Bulgarian company ID), VAT number, address and contact person; Stripe customer and subscription identifiers; payment history, amounts, dates and status. Payment card data never reaches our servers and we never see it — payment takes place on a page hosted by Stripe.
For usage metering: the number of language units (tokens) processed, per tenant and per period. We count volume, not content — request text is not stored for metering purposes.
Enquiries through the form on www.zyntrail.com: name, company, work email, telephone (where provided), the text of the message and the language of the page it was sent from.
This list is exhaustive for our role as controller. Data we process on a customer's instructions is described in section 14.
Purposes and legal bases
One basis per purpose. We do not list several possible bases so as to pick a convenient one later — that alone is a transparency failure.
| Purpose | Basis | Note |
|---|---|---|
| Creating and maintaining the account; providing the service | Art. 6(1)(b) — contract | The contracting party is the company. For the individual who represents it, the basis is (f), since that person is not personally a party |
| Invoicing and debt collection | Art. 6(1)(b) | |
| Accounting and tax reporting | Art. 6(1)(c) — legal obligation | Accountancy Act and Tax and Social Insurance Procedure Code |
| Sign-in, session management, detecting and preventing abuse | Art. 6(1)(f) | The interest is preventing unauthorised access and preserving the integrity of an environment shared by several independent tenants |
| Service communications — outages, changes, expiring subscription | Art. 6(1)(b) | This is not marketing and is not switched off by unsubscribing, because it is part of the service |
| Commercial communications to existing customers | Art. 6(1)(f) | Every message carries an opt-out. See also 4.1 |
| Replying to an enquiry sent through the website form — a demo, a trial, a question | Art. 6(1)(b) — steps taken at the enquirer's request before entering into a contract | Where the enquirer writes on behalf of a company, the basis for their own data is (f) |
| Establishing, exercising and defending legal claims | Art. 6(1)(f) |
We do not rely on consent for any purpose in this table. We say so expressly, because a consent-withdrawal paragraph in a document where consent is never used is a reliable sign of copied text.
Balancing test. Where the basis is legitimate interest, an assessment weighing that interest against your rights has been carried out and documented. We provide it on request at the address in section 1.
4.1 Right to object
Where we process on the basis of legitimate interest, you have the right under Art. 21 GDPR to object at any time. Where the objection concerns direct marketing we stop immediately and without assessment. In other cases we stop unless we demonstrate compelling legitimate grounds which override your interests.
Who we share data with
Recipients by category, with country and transfer basis, are set out in section 6. The named list of sub-processors — name, country, purpose, transfer mechanism and last-changed date — is provided on request at privacy@zyntrail.com, and to customer companies as Annex III to the Data Processing Agreement (Annex 1 to the Terms of Service).
It is a separate document deliberately: it changes more often than this policy, and embedding it here would mean one of the two silently going out of date.
Beyond sub-processors, data may be disclosed to: accountants and auditors (legal obligation); legal advisers and enforcement agents when defending claims; and competent authorities where required by law.
We do not sell personal data and we do not provide it to third parties for their marketing purposes.
Transfers outside the EU/EEA
The basis is stated per recipient, because they are not the same.
| Recipient | Country | Transfer basis |
|---|---|---|
| Platform hosting | An EU Member State — the specific one is named in the sub-processor list (section 5) | No transfer |
| Stripe (payments) | Ireland, with onward transfer to the USA | Adequacy decision (EU–US Data Privacy Framework); should it lapse, Standard Contractual Clauses under Implementing Decision (EU) 2021/914 |
| Google (Gmail, Drive) | Ireland, with onward transfer to the USA | As above |
| Meta (Messenger, Instagram, WhatsApp) | Ireland | The customer connects its own account; Meta is an independent controller for its platform |
| Telegram | United Arab Emirates | No adequacy decision. See 6.1 |
| OpenAI | Ireland, with onward transfer to the USA | Standard Contractual Clauses under the data processing agreement |
| Google Gemini | Ireland | As above. Paid tier only, under which submitted data is not used to train models |
| Telephony platform (ZynTrail Voice) | The Provider's own infrastructure, in the EU | Not a transfer and not a sub-processor — operated by the Provider itself |
| Number and SIP connectivity providers | Various, including the USA | Adequacy decision or Standard Contractual Clauses depending on the provider. Named individually in the sub-processor list (section 5) |
Stripe is not our sub-processor in the strict sense. For the payment transaction itself Stripe acts as an independent controller, because it has its own obligations under payment services and anti-money-laundering law which we cannot instruct away. We describe it that way rather than as a processor, because the latter would be untrue.
The same applies to Google and Meta as regards channels: there the customer company connects its own account and has its own relationship with those providers. We act under a grant it has given us.
6.1 Telegram
Telegram is operated by an entity established in the United Arab Emirates. There is no adequacy decision under Art. 45 GDPR for that country. The channel is disabled by default and is enabled only by an express decision of the customer company, which as controller assesses and documents the permissibility of the transfer for its own data.
How long we keep data
| Data | Period |
|---|---|
| Account and user profile data | For the term of the contract and 3 years after termination — the period under Art. 111 of the Obligations and Contracts Act for claims arising from periodic payments, which subscription fees are |
| Accounting documents and invoices | As required by the Accountancy Act and the Tax and Social Insurance Procedure Code. This overrides an erasure request |
| Security log and sign-in records | 12 months |
| Website form enquiries that did not lead to a contract | 12 months from the last correspondence on the enquiry |
| Data entered by the customer into the platform | On the customer's instructions. We do not set this period — see section 14 |
7.1 Backups — the honest answer
Erasure is executed against the live system. Backups are not edited record by record; that is technically impossible for an archive which must remain internally consistent and restorable.
Copies are overwritten on a rolling cycle: up to 7 days for the on-server copy and up to 30 days for the offsite copy. An erased record may therefore persist in a backup for at most 30 days after its erasure from the live system. During that period the copies are not opened or read, except in an actual disaster recovery event.
We say this rather than write "we erase immediately", because the latter would not be true of any system that keeps backups — including those that claim it.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection (Art. 21).
Response time: one month from receipt of the request. Where the request is complex or numerous, that period may be extended by a further two months; we will inform you of the extension and the reasons within the first month. This is the period under Art. 12(3) GDPR.
8.1 If you are a customer or counterparty of a company that uses ZynTrail
Then we process your data on that company's instructions, and it — not us — is the controller. Address your request to it.
If you nevertheless address it to us, we will:
- not respond on the merits, because we have no right to dispose of someone else's data;
- forward the request to the relevant controller without undue delay and no later than 5 business days;
- tell you that we have forwarded it and to whom — unless doing so would breach the confidentiality we owe our customer.
One limitation we owe you plainly. We cannot always establish which company you dealt with without searching across all tenants' data. Such a search is itself a processing operation for which we have no basis. So if you write to us, name the company you dealt with. Without it we cannot advance your request, however much we would like to.
8.2 Complaint to a supervisory authority
You have the right to lodge a complaint under Art. 77 GDPR:
Commission for Personal Data Protection (Комисия за защита на личните данни) 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria tel.: +359 2 915 3 518 · email: kzld@cpdp.bg · www.cpdp.bg
You may also complain to the supervisory authority of your habitual residence if that is in another Member State. Independently of any administrative complaint, you also have the right to an effective judicial remedy under Art. 79 GDPR.
Whether you must provide your data
To create an account we need the company's name and EIK, and the contact person's name and work email. Without them no contract can be concluded and the service cannot be provided. The remaining fields — telephone, job title, preferred language — are optional and leaving them blank has no consequences.
Automated decision-making
ZynTrail does not take decisions based solely on automated processing which produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.
AI features classify an enquiry, draft a reply and summarise a conversation. The customer company chooses how they work: manual — only when an agent asks; with approval — the assistant drafts, and an agent reviews and sends; automatic — the assistant sends the reply itself, but only during the hours the company has set. Automatic mode is switched on by the customer company, which can switch it off at any time. The assistant writes from the company's own documents and knowledge base. There is no feature that refuses service, sets a price or assesses a person without human involvement.
If that changes, we will change this section before the change, not after it.
AI features
- The provider is determined by the subscription plan, is not chosen by the customer company, and is named in section 6.
- Processing is carried out on the customer company's instructions; it remains the controller of the content.
- Submitted data is not used to train any model — neither ours nor the provider's. This is contracted with every provider we offer. A provider for which we cannot guarantee it is not offered.
- We meter usage in language units. Content is not stored for metering purposes.
- The customer company can disable AI features entirely from its settings.
- Where an AI feature communicates directly with a natural person, that person is informed that they are interacting with an automated system — an obligation under Art. 50 of Regulation (EU) 2024/1689.
Why no Data Protection Officer has been designated
Designation is mandatory under Art. 37(1) GDPR where the core activities require regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories.
The first limb — that processing personal data on customers' behalf is a core activity — is satisfied. The second, "large scale", is not, at the present number of tenants and volume of data, assessed against the criteria in Article 29 Working Party guidance (WP243), endorsed by the European Data Protection Board.
An officer has therefore not been designated, and a contact point for data protection matters is provided instead. The distinction is not cosmetic: an officer designated under Art. 37 must be notified to the Commission for Personal Data Protection and must be independent, and a person who simultaneously runs the company and builds the system cannot be independent of himself. Declaring ourselves a DPO would be closer to a breach than to diligence.
The assessment is documented, dated, and reviewed upon: a material increase in the number of tenants, the first tenant processing Art. 9 data, or a request from a supervisory authority.
Cookies
ZynTrail uses strictly necessary cookies only:
| Name | Purpose | Type | Duration |
|---|---|---|---|
zyntrail_token | Maintaining an authenticated session | First-party, HttpOnly | Until the browser is closed |
zyntrail_refresh | Renewing the session without re-entering a password | First-party, HttpOnly | Until the browser is closed |
XSRF-TOKEN | Protection against cross-site request forgery | First-party | Until the browser is closed |
No consent is required for these cookies — they fall within the exemption in Art. 261a of the Electronic Communications Act (Закон за електронните съобщения), being strictly necessary to provide a service explicitly requested by the user. Without them, signing in is impossible.
ZynTrail uses no analytics tools, no tracking pixels and no advertising cookies. None. There is therefore no consent banner on the site and there will not be one: a banner seeking consent for something that is not subject to consent misleads the user about their own rights.
Data the customer company enters into the platform
This section is informational. For the data described here, the controller is the customer company.
On its instructions we process: data about its customers and contacts (name, EIK, VAT number, responsible person, address, telephone, email, preferred language); the content of tickets and messages arriving by email, Messenger, Instagram, WhatsApp and web form; attachments; telephone call data including recordings; internal correspondence between the customer's staff; and shift, leave and attendance data.
Our relationship with the customer company is governed by a Data Processing Agreement (Annex 1 to the Terms of Service), concluded under Art. 28 GDPR.
14.1 Call recording
Where the customer company uses the telephony functionality, calls are recorded.
The controller of the recording is the customer company, not ZynTrail. It decides whether to record, for what purpose, for how long, and how it informs people. We provide the means.
What the law requires of it, and what our platform enables it to do:
- Notification before the recording begins, not after. The announcement must precede the first recorded second and state: that the call is being recorded, who the controller is, for what purpose, for how long, and where the full information can be found.
- Both parties are data subjects — the external participant and the customer's employee. Informing only one is not sufficient.
- For the employee, consent is not a valid basis, because of the imbalance inherent in an employment relationship. The customer should rely on legitimate interest with a documented assessment.
- Where the recording is stored depends on the call path, and the difference matters.
- Where the call runs through ZynTrail's own telephony platform, the recording is stored on the Provider's infrastructure. In that case the Provider holds the audio itself, as a processor acting on the customer company's instructions.
- Where a direct integration with an external telephony provider is used, the recording is stored with that provider, and ZynTrail's database holds only a reference to it.
In both cases ZynTrail holds the call metadata — direction, status, duration, operator, contact. The customer company can see which path is in use from its settings. The distinction is drawn because it determines who a request to delete a recording must be addressed to.
- The six-month traffic-data retention duty under Art. 251b of the Electronic Communications Act does not apply either to us or to our customers. It concerns undertakings providing public electronic communications services. We say so because it is a provision frequently cited in error in documents of this kind.
If you called a company that uses ZynTrail and have questions about the recording, address them to that company. See section 8.1.
Security
We apply the following categories of measures. We describe them at category level rather than by configuration: a published inventory of defences is a guide for whoever attacks them.
- Access to the platform is over HTTPS only, with automatically renewed certificates.
- The customer's credentials for external channels are stored encrypted.
- Attachments are delivered only via a signed temporary URL; the file directory is not publicly served.
- Separation between tenants is verified regularly; within a tenant, further limits apply by role and by department.
- Administrative actions on accounts are written to an audit log.
- Backups every 6 hours, with a performed and documented restore drill.
- Server access by cryptographic key only, with a firewall enabled and automatic security updates.
- The offsite backup is encrypted before it leaves the server (AES-256), with a passphrase the storage provider does not hold. Only ciphertext is stored there. Every file is read back immediately after encryption and before upload — an archive that cannot be opened is not a backup.
In the event of a personal data breach affecting data for which we are the controller, we notify the Commission for Personal Data Protection within 72 hours of becoming aware, and affected individuals where the breach is likely to result in a high risk to their rights. Where a breach affects a customer's data, we notify that customer within 24 hours of becoming aware, so that it can meet its own 72-hour deadline.
Changes to this policy
Every version carries a number, an effective date and a description of the changes. Material changes are notified to the customer company's contact address at least 30 days in advance. When a new version is adopted, the previous ones remain available on this site, unaltered.
Changes are not applied retroactively.
Version 1.0 · Effective 24 September 2026 · The Bulgarian text is authentic.