GDPR Compliance
Last Updated: May 23, 2026
Zoro Sales AI is fully committed to complying with the General Data Protection Regulation (GDPR) and ensuring the privacy and security of our European Union (EU) users and their customers' data. This page outlines our role and responsibilities regarding GDPR.
1. Our Role as a Data Processor
When you use Zoro Sales AI to manage leads, send outreach, or generate contracts, you act as the Data Controller, and Zoro Sales AI acts as the Data Processor. We only process personal data on your behalf and in accordance with your instructions.
2. Lawful Basis for Processing
We rely on the following lawful bases to process personal data:
- Contractual Necessity: To provide you with the services outlined in our Terms & Conditions.
- Legitimate Interests: To improve our platform, ensure security, and prevent fraud.
- Consent: When you opt-in to marketing communications or specific tracking cookies.
3. Data Subject Rights
Under the GDPR, individuals have specific rights regarding their personal data. Zoro Sales AI supports you in fulfilling these rights for your data subjects:
- Right of Access: You can export data related to any lead or contact from our platform.
- Right to Rectification: You can edit and update contact records directly in your dashboard.
- Right to Erasure (Right to be Forgotten): You can permanently delete contacts, which removes them from our databases.
- Right to Restrict Processing: You can pause campaigns and data processing for specific contacts.
4. Data Transfers Outside the EU
Zoro Sales AI uses secure cloud infrastructure. When personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as executing Standard Contractual Clauses (SCCs) with our sub-processors.
5. Security Measures
We employ technical and organizational measures to protect personal data, including encryption in transit and at rest, regular security audits, and strict access controls. Our databases are secured using row-level security (RLS) to ensure data isolation between workspaces.
6. Data Breach Notification
In the unlikely event of a personal data breach affecting your workspace, we will notify you without undue delay (and within 72 hours of becoming aware of it) so you can fulfill your obligations to regulatory authorities and data subjects.
7. Data Protection Officer (DPO)
If you have specific questions about our GDPR compliance or need to escalate a data protection request, you can contact our Data Protection Officer at: