Privacy Policy

ZONDI Privacy Policy

Data Protection and Personal Information Handling
Version 1.1
Effective Date: August 6, 2026

1. Introduction

Zondi ("we," "our," or "us") is committed to protecting your privacy and ensuring you have a positive experience on our platform. This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information through our mobile application and website (collectively, the "Platform").

This Privacy Policy is designed to inform you about:

  • What personal data we collect
  • How we use and process your data
  • Your rights under data protection laws
  • How we protect your information
  • Our compliance with the General Data Protection Regulation (GDPR)

By accessing or using Zondi, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Platform.

2. Data Controller Information

The data controller responsible for processing your personal information is:

Organization NameZondi
Office AddressIx-Xatt Ta'Xbiex, House 12, Flat 6, MSD 1512 MSIDA, Malta
EU VAT IDMT30260412
Company RegistryC 105334
Data Protection OfficerSee Contact Information section below
Email for Data Inquirieshello@zondi.app

3. What Data We Collect

3.1 Data You Provide Directly

When you register and use Zondi, you voluntarily provide us with the following personal information:

  • Email Address: Required for account creation, password recovery, and communication
  • Full Name (First Name): Used for profile identification and communication
  • Age / Date of Birth: Required to verify that you are at least 18 years old
  • Gender: Optional field (Male / Female / Prefer not to say) for profile completion
  • Country of Origin and Home City: Used to display your background and help others understand your location context
  • Profile Photographs: 1–6 photographs uploaded by you for your profile (mandatory minimum 1)
  • Languages Spoken: List of languages you speak, displayed on your profile
  • About Me: Optional biography (up to 150 characters)
  • Next Destination: Optional information about where you plan to travel
  • Activity Status: Information about whether you are traveling solo, with a friend, or as part of a group
  • Geolocation Data: Your current geographical location is collected ONLY when you explicitly enable location services and consent to share it. You can withdraw this consent at any time through your device settings or in-app settings. Geolocation is essential for the "Travelers Nearby" feature and matching you with nearby users for activities.

3.2 Data Collected Automatically

  • IP Address: Automatically collected when you access the Platform for security and analytics purposes
  • Device Information: Information about the device you use (model, operating system, unique device identifiers)
  • Log Data: Server logs including access times, pages viewed, and actions taken within the app
  • Usage Data: Information about how you interact with features (e.g., activities you browse, requests you create)
  • Status Updates: Information you provide about your availability (e.g., "On My Way," "Arrived," "Running Late")

3.3 Data Provided in Communication

  • Chat Messages: All messages you send through the in-app chat system to other users
  • Meetup Card Information: Details you provide about proposed meetups (time, location, activity)
  • Ratings and Reviews: Star ratings and text feedback you provide after meetups
  • Photos Shared in Chats: Any additional photos you share during conversations
  • Support Communication: Messages you send to our support team when requesting assistance

3.4 Profile Verification Data

To enhance trust and safety, we collect:

  • Selfie Photo: A face photo you provide during profile verification
  • Verification Status: Whether your profile has been verified (linked to your profile photo)
  • Verification Badge: Your selfie is manually reviewed by the ZONDI Team against your profile photo

4. How We Collect Data

We collect your personal information through several methods:

4.1 Direct Collection

  • Registration and Profile Creation: You provide information when setting up your Zondi account
  • In-App Interactions: Data collected as you use features like creating requests, sending messages, and sharing your location
  • File Uploads: Photos and other media you deliberately upload to the Platform
  • Communication with Our Team: Information you share when contacting customer support

4.2 Automatic Collection

  • Cookies and Tracking Technologies: We use cookies and similar technologies to remember your preferences and improve user experience (see Section 10: Cookies and Tracking)
  • Analytics Tools: We collect usage data to understand how users interact with our Platform
  • Device Sensors: With your permission, we access your device's GPS to determine your location

4.3 Third-Party Sources

We may receive information about you from:

  • Service Providers: Such as payment processors and fraud detection services
  • Social Media: If you choose to link your account with social media platforms (optional)
  • Other Users: Information you appear in when other users tag you in photos or mention you in reviews

5. Legal Basis for Processing (GDPR Article 6)

Under GDPR Article 6, Zondi processes your personal information based on the following legal grounds:

5.1 Consent (GDPR Article 6(1)(a))

  • Geolocation Processing: We process your precise location data ONLY with your explicit prior consent. This is separate from general service access. You can withdraw geolocation consent at any time.
  • Marketing Communications: We only send promotional emails if you have opted in to receive them.
  • Optional Data Fields: Processing any optional information (About Me, Next Destination, etc.) is based on your voluntary provision of that data.
  • Cookies and Analytics: We rely on your consent (or legitimate interest under GDPR) for analytics and non-essential cookies.

5.2 Performance of Contract (GDPR Article 6(1)(b))

The following data is processed because it is necessary to provide the core service:

  • Email Address, Name, Age: Required to create and maintain your account
  • Profile Information: Necessary to enable other users to find and connect with you
  • Geolocation (when enabled): Essential for the "Travelers Nearby" matching feature
  • Chat Messages and Meetup Card Data: Necessary to facilitate communication and coordinate meetups

5.3 Legitimate Interest (GDPR Article 6(1)(f))

We process the following data to operate our Platform safely and improve service quality:

  • Device Information and Log Data: Used for security, fraud prevention, and platform stability
  • Usage Analytics: We analyze how users interact with features to improve user experience and fix bugs
  • Device and IP Information: Collected to prevent unauthorized access and detect suspicious activity

5.4 Legal Compliance (GDPR Article 6(1)(c))

  • We process data as required by applicable laws, including AML/KYC requirements in Malta and the EU.

5.5 Legitimate Purpose (GDPR Article 6(1)(d))

  • Identity Verification: Processing your selfie and profile photo to establish trust and prevent fraud.

No automatic decision-making or profiling beyond the Reliability Score (see Section 6) is performed on your data. The Reliability Score is calculated from your own actions and ratings received from other users, not from automated processing of personal characteristics.

6. How We Use Your Data

Zondi uses your personal information for the following specific purposes:

6.1 Core Service Delivery

  • Account Management: Creating and maintaining your account, managing your profile, and providing access to the Platform
  • Matching and Discovery: Using your location, age, activity preferences, and profile information to show you nearby travelers and activity opportunities
  • Communication: Facilitating messaging between users and enabling the Meetup Card coordination system
  • Activity Coordination: Processing the details of your meetup requests and confirmations
  • User Identification: Verifying your identity and ensuring you meet the 18+ age requirement

6.2 Safety and Trust

  • Reliability Scoring: Calculating your reputation score based on your meetup completion history and ratings from other users
  • Profile Verification: Manual review of your selfie against your profile photo by the ZONDI Team to issue a Verified badge
  • Fraud Detection: Identifying and preventing fraudulent, inappropriate, or harmful behavior
  • Report and Block Processing: Managing user reports about inappropriate behavior and maintaining block lists
  • Content Moderation: Reviewing user-generated content (photos, messages) for policy violations

6.3 Communication

  • Account Notifications: Sending you messages about your account status, registration confirmations, and important updates
  • Meetup Reminders: Notifying you when a scheduled meetup is approaching or when another user updates their status
  • Support Responses: Replying to your support requests and providing assistance
  • Legal Notices: Communicating about changes to our Privacy Policy or Terms of Use

6.4 Analytics and Improvement

  • Usage Analytics: Analyzing how you use the Platform to identify popular features and areas for improvement
  • Crash Reporting: Collecting error reports to fix bugs and improve stability
  • Feature Testing: Understanding how new features are used so we can optimize them
  • City Expansion Data: Using "Next Destination" information to inform decisions about where to launch Zondi next

6.5 Legal and Regulatory Compliance

  • Legal Obligations: Complying with court orders, law enforcement requests, and legal requirements
  • Regulatory Reporting: Meeting Malta and EU regulatory requirements, including GDPR
  • Terms Enforcement: Enforcing our Terms of Use and preventing abuse

6.6 Direct Marketing (if you opt in)

  • Promotional Communications: Sending emails about new features, special offers, or events (only if you have subscribed)
  • Social Media Marketing: Using aggregated, anonymized data for marketing purposes on Instagram, Facebook, and TikTok

7. Data Storage and Security

7.1 Where We Store Your Data

Zondi uses Supabase (Supabase Inc., based in San Francisco, USA) as our primary data hosting provider. Supabase provides:

  • Database Storage: PostgreSQL database hosting
  • File Storage: Cloud storage for photos and media
  • Authentication Services: Secure user authentication and session management
  • Real-time Services: Real-time chat and status update functionality

Supabase is a trusted, enterprise-grade cloud service provider that complies with GDPR and other data protection regulations. For more information, see https://supabase.com/privacy.

7.2 Data Security Measures

We implement industry-standard security controls to protect your personal information:

  • Encryption in Transit: All data transmitted between your device and Supabase is encrypted using TLS 1.2 or higher
  • Encryption at Rest: Sensitive data in the database is encrypted at rest using AES-256 encryption
  • Access Controls: Only authorized Zondi team members have access to personal data, protected by role-based access controls
  • Authentication: Your account is protected by password authentication. We do not store passwords in plaintext
  • Secure Code Development: Our development process includes regular security reviews and code audits
  • Regular Backups: Data is regularly backed up to prevent loss
  • Firewalls and Intrusion Detection: Supabase maintains firewalls and intrusion detection systems

7.3 Data Retention

We retain your personal information for as long as necessary to provide the service and fulfill the purposes outlined in this Privacy Policy:

  • Account Data: Retained while your account is active. After you delete your account, your account and its associated data are permanently deleted immediately, except for the limited categories described below
  • Backup Data: Deleted data may still exist in encrypted backups until those backups are naturally overwritten in the normal backup cycle
  • Legal Holds: If there is a legal dispute or investigation involving you, relevant data may be retained longer
  • Aggregated/Anonymized Data: We may retain anonymized data indefinitely for analytics and research purposes
  • Deleted Accounts: Your account, chat history, ratings, and reliability score are permanently deleted immediately. The only exception: if your account held First Wave or Lifetime Premium status, we keep a permanent, one-way hashed record of your email (and linked Google account, if any) solely to prevent that benefit from being re-claimed by re-registering. This hashed record cannot be reversed to reveal your email and contains no other information about you.
  • Support Tickets: We retain support communications for up to 2 years to improve customer service and address potential disputes

7.4 Data Backup and Recovery

Your data is backed up regularly to prevent loss due to technical failure. These backups are stored securely and are subject to the same access controls and encryption as live data.

7.5 Security Limitations

While we use industry-standard security practices, no system is completely secure. We cannot guarantee absolute security of your information. If a security breach occurs, we will notify affected users and relevant authorities as required by GDPR (within 72 hours of discovery).

8. Data Sharing

8.1 EXPLICIT NO THIRD-PARTY SHARING

Zondi is committed to protecting your privacy. We categorically DO NOT:

  • Sell your personal data to third parties
  • Share your personal data with advertisers or marketing companies
  • Lease, rent, or rent your contact information
  • Allow third parties to use your data for their own marketing purposes
  • Share your location data with anyone except as described below

This policy applies to all personal information, including email, name, location, and photos.

8.2 Data Shared Within the Platform (Between Users)

The following information is shared with other Zondi users as part of the core functionality:

  • Public Profile Information: Your name (first name only), age, country of origin, profile photos, languages, gender, and activity interests are visible to other users as part of discovery
  • Status Updates: When you create a meetup request or change your availability status, other users can see this information
  • Chat Messages: When you message another user, they receive and can see your messages
  • Meetup Card Details: Time, location, and activity information you include on a Meetup Card is visible to the user you matched with
  • Ratings and Reviews: Your star rating and written feedback about a meetup is publicly visible on the other user's profile (without revealing your identity unless you choose to)
  • Reliability Score: Your reputation score and number of completed meetups are visible to other users

Information NOT shared:

  • Your email address is not visible to other users
  • Your exact home address is never shared
  • Your full date of birth is not shared (only age/year)
  • Your precise geolocation coordinates are never visible to other users
  • Private messages and chat history are only visible to you and the recipient
  • Payment information (if applicable in future versions) is never shared

8.3 Data Shared with Service Providers

We may share limited personal information with carefully selected service providers who help us operate the Platform:

  • Supabase: Database, storage, and authentication services (see Section 7 for details)
  • Payment Processors: If you make a payment (in future versions), we share transaction details with the payment provider
  • Analytics Services: We use PostHog or Firebase for usage analytics. These services receive anonymized usage data
  • Email Services: We use Resend or similar email services to send you notifications. Only your email address is shared
  • Customer Support Tools: If we use a third-party support platform, we may share support ticket information
  • Cloud Backup Services: Regular backups may be stored with cloud providers

All service providers are contractually obligated to:

  • Process data only on our instructions
  • Maintain confidentiality and security
  • Not use your data for their own purposes
  • Comply with GDPR and other applicable laws
  • Ensure employees who access data are bound by confidentiality

8.4 Data Shared for Legal Reasons

We may disclose your personal information if legally required to do so:

  • Court Orders: In response to a subpoena, court order, or legal process
  • Law Enforcement: To comply with requests from law enforcement or government agencies
  • Safety Concerns: If we believe disclosure is necessary to prevent fraud, abuse, or other illegal activity
  • Legal Disputes: To defend our legal rights in litigation or disputes
  • Public Safety: If we believe it is necessary to protect the safety of our users or the public

When we receive a legal request for your data, we will:

  • Attempt to notify you unless legally prohibited
  • Provide only the minimum necessary information
  • Comply with all legal protections and requirements

8.5 Business Transfers

If Zondi is acquired, merged with another company, or sells its assets:

  • Your personal information may be transferred as part of that transaction
  • We will notify you of any such change and any choices you may have
  • The acquiring company must agree to maintain the protections in this Privacy Policy

8.6 Aggregated and Anonymized Data

We may use and share aggregated, anonymized data that cannot identify you personally. This data may be used for:

  • Marketing: "Zondi has 50,000 users in Malta" or "The most popular activity is Padel"
  • Research: Analyzing trends in travel and social connection
  • Public Reports: Publishing statistics about the app's usage and impact

This data cannot be used to identify you and is not subject to GDPR restrictions.

9. Your Rights Under GDPR

The General Data Protection Regulation grants you the following rights regarding your personal information:

9.1 Right of Access (GDPR Article 15)

You have the right to request a copy of all personal information we hold about you. We will provide this information in a structured, commonly used, and machine-readable format (a "Data Subject Access Request" or DSAR).

How to exercise this right:

  1. Send an email to hello@zondi.app with the subject "Data Access Request"
  2. Include your account email and sufficient identification information
  3. We will respond within 30 days with a complete copy of your data

The first request per year is free. Subsequent requests may incur a reasonable fee.

9.2 Right to Rectification (GDPR Article 16)

If any of your personal information is inaccurate or incomplete, you have the right to correct it.

How to exercise this right:

  • Profile Information: You can update most information yourself through the "Settings" or "Edit Profile" feature
  • Verification Status: If your Verified badge was incorrectly issued or denied, contact hello@zondi.app
  • Other Data: For information you cannot update yourself, contact hello@zondi.app with details of what needs correction

We will correct inaccurate information within 10 business days.

9.3 Right to Erasure (Right to be Forgotten) (GDPR Article 17)

You have the right to request deletion of your personal information, subject to certain exceptions.

How to exercise this right:

  1. In-App: Go to Settings → Account → Delete Account. This will delete your account and associated data
  2. Manual Request: Email hello@zondi.app with "Erasure Request" in the subject line

What happens when you delete your account:

  • Your profile is removed from the app immediately
  • Your personal data is permanently deleted immediately
  • Other users cannot see your profile or send you messages
  • Chat histories with your messages are anonymized
  • Your ratings and reviews may remain but will not be linked to your account
  • If your account held First Wave or Lifetime Premium status, we keep a permanent, one-way hashed record of your email (and linked Google account, if any) to prevent that benefit from being re-claimed by re-registering. See Section 7.3 for details.

Data we cannot delete:

  • Data needed for legal compliance (e.g., tax records, fraud investigation records)
  • Data that may still exist in encrypted backups until those backups are naturally overwritten in the normal backup cycle
  • Aggregated data that cannot identify you
  • Data needed to enforce our Terms of Use (e.g., records of users we have blocked)

9.4 Right to Restrict Processing (GDPR Article 18)

You have the right to ask us to restrict how we use your data while we investigate a dispute or verify accuracy.

When you request restriction:

  • We will limit processing to storage only
  • We will not use your data for any other purpose (with narrow exceptions for legal claims)
  • Processing resumes when the restriction is removed

How to exercise this right: Email hello@zondi.app with "Restrict Processing" in the subject line.

9.5 Right to Data Portability (GDPR Article 20)

You have the right to receive a copy of your personal data in a structured, machine-readable format and to transmit it to another service if you wish.

How to exercise this right:

  1. Send a "Data Portability Request" to hello@zondi.app
  2. We will provide your data in a CSV or JSON format within 30 days
  3. This includes account information, profile data, messages (text only, not media), and ratings

Note: Due to technical limitations, we cannot transfer your photos or complex relational data to another platform as part of an automated export. To request your photos, contact hello@zondi.app and we will help you.

9.6 Right to Object (GDPR Article 21)

You have the right to object to certain types of processing:

9.6.1 Object to Legitimate Interest Processing

If we process your data based on legitimate interest, you have the right to object. If you object, we must stop processing unless we demonstrate compelling legitimate reasons or it is necessary for legal claims.

How to exercise this right: Email hello@zondi.app with "Objection to Legitimate Interest Processing" in the subject line.

9.6.2 Object to Direct Marketing

You have the right to object to marketing emails at any time. Every marketing email includes an unsubscribe link that will immediately stop marketing communications.

How to exercise this right: Click the "Unsubscribe" link in any marketing email.

9.6.3 Object to Geolocation Processing

If you have consented to geolocation processing, you can withdraw that consent at any time.

How to exercise this right: Go to Settings → Privacy → Disable Location Sharing.

9.7 Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.

Our Reliability Score is NOT a decision that restricts your rights. However:

  • Your profile visibility may be reduced if your Reliability Score is low due to no-shows or negative ratings
  • You can always request an explanation of your score
  • You can request human review if you believe the score is unfair

9.8 How to Exercise Your Rights

To exercise any of these rights:

Option 1: In-App (Settings → Privacy & Data)

Some rights can be exercised directly through the app.

Option 2: Email Request

Send a written request to: hello@zondi.app

Your request should include:

  • Your full name and account email
  • The specific right you are exercising
  • Any relevant details (e.g., which data you want access to)
  • Your signature (for formal requests)

We will:

  • Respond within 30 days of receiving your request
  • Verify your identity before providing sensitive information
  • Inform you if we need additional time (up to 60 days for complex requests)
  • Explain any reason we cannot fulfill your request

9.9 Right to Lodge a Complaint

If you believe we have violated your data protection rights, you have the right to lodge a complaint with your local data protection authority:

  • EU Member States: Contact your national Data Protection Authority
  • Malta (Primary Jurisdiction): Office of the Data Protection Commissioner (Commissioner.it)
  • UK: Information Commissioner's Office (ico.org.uk)

You can file a complaint without first contacting us, but we welcome the opportunity to address your concerns.

10. Cookies and Tracking

10.1 Current Tracking Status

As of July 2026, Zondi does NOT currently use:

  • Cookies for tracking user behavior
  • Third-party analytics cookies
  • Retargeting or advertising pixels
  • Cross-site tracking technologies

10.2 Future Cookie Implementation

In future versions (V2+), Zondi may implement the following types of cookies:

Essential Cookies (Always On)

  • Session Management: Keeping you logged in while using the app
  • Security: Preventing fraud and protecting accounts
  • Functionality: Remembering your preferences and settings

These cookies are necessary for the app to function and cannot be disabled.

Analytics Cookies (Consent-Based)

If we implement analytics, we will:

  • Use privacy-respecting analytics tools (e.g., PostHog)
  • Obtain your explicit consent before deploying tracking cookies
  • Allow you to opt out at any time
  • Never sell analytics data to third parties

Preference Cookies (Optional)

  • Language and Interface: Remembering your language preference
  • Accessibility: Storing your accessibility settings

10.3 Local Storage and Device Storage

We use your device's local storage to:

  • Store authentication tokens (securely)
  • Cache user preferences and settings
  • Store draft messages (locally, not on our servers)
  • Remember your location permissions settings

This local data is stored on your device and is not transmitted to our servers except when you sync specific actions (e.g., sending a message).

10.4 Mobile Analytics

If Zondi collects analytics data from the mobile app, we use:

  • PostHog or Firebase Analytics (with GDPR-compliant configuration)
  • Event-based tracking (e.g., "User opened Activity Feed")
  • Aggregated statistics (no user-level tracking)
  • No personal data linked to analytics events

10.5 Your Cookie and Tracking Choices

How to manage cookies and tracking:

In the App:

  • Go to Settings → Privacy → Cookie Preferences
  • Adjust your preferences for each cookie type
  • Withdraw consent from analytics or preference tracking

On Your Device:

  • Disable cookies in your browser settings (for web version)
  • Disable app-level tracking through device settings
  • Opt out of personalized ads in your device's ad preferences

10.6 Do Not Track Signals

Some browsers include a "Do Not Track" signal. If you enable Do Not Track in your browser, we will respect that preference and will not use tracking technologies that identify you personally.

11. Data Retention

We retain personal information only as long as necessary to provide our service and fulfill the purposes outlined in this Privacy Policy. Here is our standard retention schedule:

11.1 Account and Profile Data

Type of DataRetention PeriodReason
Active Account DataWhile account existsNecessary to provide service
Profile Information (after deletion)ImmediatelyDeleted as part of account deletion
Backup CopiesUntil natural backup cycle overwriteDisaster recovery and system restoration
Legally Compelled RecordsAs required by lawLegal compliance (typically 3–7 years)
Tax Records7 yearsMalta tax authority requirements

11.2 Communication Data

Type of DataRetention PeriodReason
Chat MessagesWhile both parties' accounts activeAccess to conversation history
Chat History (deleted account)ImmediatelyDeleted as part of account deletion
Email Notifications3 monthsTo prove delivery and resolve issues
Support Tickets2 yearsCustomer service improvement and dispute resolution

11.3 Activity and Reputation Data

Type of DataRetention PeriodReason
Completed MeetupsWhile account active; deleted with the accountReputation system integrity
Ratings and ReviewsPermanentlyProtect community safety and inform other users
Reliability ScoreDeleted with the accountSee Section 7.3 for the narrow First Wave/Premium exception
User Reports1 yearIdentify patterns of abuse
Block/Report Records2 yearsPrevent repeat offenders

11.4 Security and Fraud Data

Type of DataRetention PeriodReason
Login Records and IP Logs90 daysDetect suspicious activity
Fraud Investigation Records3 yearsPrevent repeated fraud attempts
Device Fingerprints1 yearSecurity and abuse prevention
Verification Attempt Logs1 yearPhoto verification integrity

11.5 Analytics and Improvement Data

Type of DataRetention PeriodReason
Aggregated Usage DataIndefinitelyProduct improvement (cannot identify individuals)
Crash Reports6 monthsBug fixing and app stability
Feature Usage Analytics1 yearUnderstanding user behavior
Session Logs90 daysPerformance optimization

11.6 How We Delete Data

When the retention period expires:

  • Automatic Deletion: Most data is automatically deleted from live systems
  • Backup Deletion: Backup copies are overwritten during regular backup cycles
  • Secure Wiping: Sensitive data (e.g., passwords) is cryptographically destroyed
  • Archival: Some data may be archived for legal compliance but remains subject to access restrictions

11.7 Your Right to Request Earlier Deletion

You can request deletion of your data before the standard retention period expires:

  • Use the Delete Account feature in Settings for immediate account removal and immediate data deletion
  • Submit a formal Right to Erasure request (see Section 9.3)

We may retain data longer if:

  • Required by law (legal hold)
  • Necessary to resolve disputes or fraud
  • Needed to enforce our Terms of Use
  • It has been anonymized and cannot identify you

12. International Data Transfers

12.1 Where Your Data Is Stored

Zondi is registered in Malta (EU). However, your personal data may be transferred to and processed in countries outside the EU/EEA, including:

  • United States: Supabase's servers and services are located in the United States
  • Other Regions: If we expand to additional countries, data may be stored in those regions

12.2 Legal Framework for Transfers

Transfers of personal data outside the EU/EEA are only made where there is an adequate legal basis:

Standard Contractual Clauses (SCCs)

Supabase and other service providers have entered into Standard Contractual Clauses approved by the European Commission. These clauses ensure that your data receives the same level of protection outside the EU as it would within the EU.

Adequacy Decisions

In some cases, we may rely on the European Commission's adequacy decisions (e.g., UK Adequacy Decision).

Your Consent

Where required, we obtain your explicit consent before transferring data to countries without an adequacy decision.

12.3 Supabase and US Data Storage

Your data is stored on Supabase's servers located in the United States. Supabase:

  • Is SOC 2 Type II compliant
  • Implements contractual protections equivalent to GDPR
  • Provides encryption in transit and at rest
  • Is subject to US law and may be required to disclose data to US government agencies under certain circumstances

By using Zondi, you acknowledge that your data will be transferred to and processed in the United States in compliance with GDPR SCCs.

12.4 Your Rights Regarding International Transfers

You have the right to:

  • Request information about the legal basis for international transfers
  • Object to transfers if you believe they do not provide adequate protection
  • Request a copy of the Standard Contractual Clauses
  • Lodge a complaint with your data protection authority

If you object to international transfers, we may not be able to provide our service, as our infrastructure is US-based.

12.5 Data Localization Requirements

Future Expansion:

When Zondi expands to new countries (e.g., Czech Republic, Germany, Dubai), we will comply with local data localization requirements:

  • EU Countries: Data may be stored in EU-based servers
  • UAE: Data may be stored in accordance with UAE data protection laws
  • Other Jurisdictions: We will comply with applicable local requirements

12.6 Schrems II and Recent Developments

Following the Schrems II decision, we have implemented supplementary safeguards to protect data transferred to the US:

  • Encryption of sensitive data at the application level
  • Minimization of data transferred (only necessary data)
  • Regular assessment of US surveillance laws and their impact
  • Consideration of alternative storage options that may be more protective

We monitor developments in data protection law and will adapt our practices as required.

13. Children's Privacy

13.1 Age Restriction: 18+ Only

Zondi is restricted to users who are at least 18 years old. We do not knowingly collect or process personal information from individuals under 18.

13.2 Age Verification

During registration, you must confirm:

  • You are at least 18 years old
  • You have read and agree to our Terms of Use and Privacy Policy

We rely on user self-certification at registration and reserve the right to request identification to verify age.

13.3 What We Do If We Learn of Child Users

If we discover that someone under 18 has created an account:

  • We will immediately delete their account and all associated data
  • We will delete any photos or information they uploaded
  • We will not attempt to recover or archive this information
  • We will comply with COPPA (Children's Online Privacy Protection Act) if the child is in the US

13.4 Parental Consent

We do not collect parental consent, as we do not knowingly provide service to children. If a parent believes their child has created a Zondi account, they should contact hello@zondi.app immediately, and we will delete the account.

13.5 Child Safety in Communications

Our platform includes safeguards to prevent adult users from exploiting or grooming child users:

  • If a child is discovered on the platform, their account is immediately terminated
  • Users can report inappropriate behavior or solicitation through the Report function
  • We cooperate with law enforcement to investigate suspected child exploitation

If you have concerns about child safety on Zondi, please contact hello@zondi.app or local law enforcement.

14. Changes to Privacy Policy

14.1 Right to Update This Policy

Zondi may update this Privacy Policy as our service evolves, our business practices change, or new regulations are enacted. We are committed to informing you of any material changes.

14.2 What Constitutes a Material Change

Material changes include:

  • Changes to what data we collect
  • Changes to how we use your data
  • Changes to who we share data with
  • Changes to your rights
  • Changes to our retention practices
  • Changes to our data security practices

Non-material changes (clarifications, formatting, etc.) may be made without notice.

14.3 How We Notify You

For material changes, we will:

  • Update this page and mark changes with a new "Effective Date"
  • Send you an email notification (to your registered email address)
  • Display a notice in the app when you next log in
  • Request your affirmative consent if the changes significantly expand our data collection or use

14.4 Your Right to Reject Changes

If you do not agree with changes to this Privacy Policy:

  • You may delete your account (see Section 9.3)
  • Changes become effective after 30 days of notice
  • Continued use of the Platform after the effective date constitutes acceptance

14.5 Version History

VersionDateChanges
1.0July 7, 2026Initial Privacy Policy for Zondi
1.1August 6, 2026Clarified that account deletion is immediate and permanent; corrected verification-review and data-retention wording to match actual practice

14.6 Future Updates

We anticipate updating this policy as Zondi adds new features:

  • When we implement cookies/analytics (V2+)
  • When we add payment processing (V2+)
  • When we expand to new countries
  • When we introduce new data collection or processing practices

You can always find the latest version at https://zondi.app/privacy

15. Contact Information and Data Protection Officer

15.1 General Privacy Inquiries

For questions about this Privacy Policy or our data practices:

Email: hello@zondi.app

Website: https://zondi.app/privacy

Address: Ix-Xatt Ta'Xbiex, House 12, Flat 6, MSD 1512 MSIDA, Malta

Response Time: We aim to respond to all inquiries within 10 business days.

15.2 Data Protection Officer (DPO)

Zondi has appointed a Data Protection Officer to oversee our GDPR compliance. The DPO is available to:

  • Answer questions about data protection practices
  • Assist with the exercise of your data subject rights
  • Investigate complaints about our data processing
  • Serve as the point of contact for regulatory authorities

DPO Contact Information:

Email: hello@zondi.app

Address: Ix-Xatt Ta'Xbiex, House 12, Flat 6, MSD 1512 MSIDA, Malta

Response Time: We aim to respond to DPO inquiries within 5 business days.

15.3 Data Subject Access Requests (DSAR)

To request a copy of your personal data:

Email the following to hello@zondi.app:

Subject: "Data Subject Access Request (DSAR)"

Body: Include your registered email address and any details to help us identify your account

We will respond within 30 days with:

  • A complete copy of your personal data in a structured, machine-readable format
  • An explanation of how we process your data
  • Information about our data protection practices

First DSAR per calendar year: Free

Subsequent requests: May incur a reasonable administrative fee (typically €10–20)

15.4 Complaints and Escalation

If you are not satisfied with our response to a privacy concern:

Step 1: Contact Our Privacy Team

Send a detailed complaint to hello@zondi.app. Include:

  • Your account information
  • A description of the issue
  • What resolution you are seeking
  • Any supporting documentation

Step 2: Escalate to DPO

If unsatisfied with the privacy team's response, escalate to hello@zondi.app

Step 3: Regulatory Complaint

You have the right to lodge a complaint with your local data protection authority:

  • Malta: Office of the Data Protection Commissioner (Commissioner.it)
  • EU: Your national data protection authority
  • UK: Information Commissioner's Office (ico.org.uk)
  • Other: Contact the authority in the country where you live or where the issue occurred

15.5 Right to Legal Remedy

If you believe Zondi has violated your data protection rights and suffered damages, you have the right to seek compensation through:

  • Civil court proceedings (in Malta or your home country)
  • Regulatory authority complaints
  • Mediation or alternative dispute resolution

15.6 Changes to Contact Information

We may update our contact information as our business evolves. Please check this Privacy Policy for the most current contact details.


15.7 Acknowledgment

By using Zondi, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you have any questions or do not agree with our practices, please do not use the Platform.

END OF PRIVACY POLICY

This Privacy Policy is effective as of July 7, 2026.

For the latest version, visit https://zondi.app/privacy

© 2026 Zondi. All rights reserved.

Malta Company Registry C 105334 | EU VAT MT30260412

Questions? Contact hello@zondi.app