Privacy Policy
Effective 30 September 2026.
This policy explains how DigiAutomate, a trading name of ZEN AI GOVERNANCE UK LTD (company number 16827795, 128 City Road, London, EC1V 2NX, United Kingdom), handles personal data in WMS Serton. Contact us about privacy at info@digiautomate.com.
1. Two roles
Your account. For the details you give us to run your account, we decide how the data is used, so we are the controller.
Your projects. For the documents and information you put into projects (which can include names and contact details of people at your clients), you decide what goes in and why. We process it only to provide the Service, as your processor, under the Data Processing Agreement.
2. What we collect
- Account details: your email address, password (stored by Google's sign-in service, never in plain text), role and approval status.
- Project content: documents you upload, discovery facts, playbook reviews, questions you ask and their answers, and documents you generate.
- Activity records: what was done, by which account and when (for example "project created"), kept for security and support.
- Billing: if you pay by card, Stripe handles the card and tells us the subscription status; if you are invoiced, the billing contact and invoice details.
We do not use analytics, advertising or tracking cookies.
3. Why we use it (lawful basis)
- To provide the Service and your account: performance of our contract with you.
- To keep the Service secure, prevent misuse and fix faults: our legitimate interests.
- To keep financial records: legal obligation.
We do not sell personal data, and we do not use your project content to train AI models.
4. AI processing
AI features run on a private model on a workstation we operate in the United Kingdom. Your documents are not sent to a third-party AI provider such as OpenAI or Google Gemini. Material marked as belonging to one client is kept out of shared libraries and other projects.
5. Where data is stored and who processes it
One row per provider. Locations were checked against our live configuration on 30 September 2026.
| Provider | Role | Data | Location |
|---|---|---|---|
| Google LLC (Firebase and Google Cloud) | Sub-processor | Firestore database: account records, projects, discovery facts, playbook reviews, questions and answers, generated documents | United States (nam5 US multi-region; fixed when the project was created) |
| Google LLC (Firebase and Google Cloud) | Sub-processor | Cloud Storage: uploaded documents. App Hosting: the application servers that handle every request | United States (us-central1, Iowa) |
| Google LLC (Firebase Authentication) | Sub-processor | Account sign-in: email address, password (stored hashed), sign-in IP address and browser details | United States (Firebase Authentication runs only in US data centres) |
| Supabase Inc. | Sub-processor | Evaluator database (Postgres): session records and evaluation workspace records | Ireland, EU (AWS eu-west-1) |
| DigiAutomate (our own infrastructure) | Processor (not a third party) | AI processing: document text and questions are read by a private model to propose facts, answer questions and draft documents. Nothing is sent to a third-party AI provider | United Kingdom (a private workstation we operate) |
| Stripe | Sub-processor, only if you pay by card | Card payments and subscription status. We never see or store card numbers | Not active yet. If card payment is switched on: Stripe data centres, including the United States, under Stripe’s data processing terms |
International transfers. Your project data and sign-in details are stored in the United States, and session records in Ireland (EU), so data is transferred outside the UK. We make these transfers only under an appropriate safeguard: for UK data, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (or the UK Extension to the EU–US Data Privacy Framework where the provider is certified); for EEA data, the EU Standard Contractual Clauses (or the EU–US Data Privacy Framework). Details are in the Data Processing Agreement, and you can ask us for a copy of the safeguard at info@digiautomate.com.
6. How long we keep it
We keep account and project data while your account is active. When your subscription ends you can ask for an export within 30 days; after that we delete your project content and account, except records we must keep by law (such as invoices, kept for 6 years). Activity records are kept for up to 12 months.
7. Your rights
You can ask to see, correct, export or delete your personal data, or object to how we use it, by emailing info@digiautomate.com. For personal data inside a customer's projects, we pass the request to that customer, who decides. You can also complain to the Information Commissioner's Office (ico.org.uk).
8. Security
Data travels over encrypted connections (HTTPS) and is encrypted at rest by our hosting providers. Each project has its own members and editors, and access is checked on every request. Tell us at once if you suspect a security problem.
9. Changes
We will post changes here and tell account holders by email before a significant change takes effect.