EN | FR ← Zen Solutions

Privacy & Data Agreement

Last updated: August 7, 2026

Zen Solutions (“we”), operated by Zen Solutions, provides an all-in-one automation and online-presence platform for businesses (booking, payments, accounting, AI agents, etc.). This policy explains what data we process, why, and your rights. Questions: zen-ai.net/consultation.

Our core promise. Your business data and your company’s features are never accessed or used without your consent — including for support. When you ask us for help, or explicitly authorize it, a Zen Solutions team member may look at or act within your account solely to assist you with that request. Outside of that consent, we do not view, share, sell, or use your data or your customers’ data.

1. Who can have an account

2. Data we process

Business owners (our clients)

The business’s end customers

3. Optional connected services

These are connected by you, only if you want the feature, and can be disconnected at any time. Credentials are encrypted and never shown back to your browser.

  • Your mailbox (email feature) — you connect a mailbox (Gmail, Outlook or any IMAP provider) using an app password you generate. We read and send email through standard IMAP/SMTP to power your inbox and, if you enable it, AI auto-replies and tidying. We do not use Google’s Gmail API for this.
  • Google Calendar (optional sync) — if you connect Google, we use calendar.events only to create, update and cancel the appointment events booked through the platform.
  • Stripe (payments), Twilio (SMS / phone agent), Facebook (Ads / Messenger) — connected by you to enable those features.
Google “Limited Use” compliance. If you connect Google Calendar, Zen Solutions’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we only use Google data to provide the features you requested; we do not sell it; we do not use it for advertising; and no human reads it except with your consent, for security, to comply with the law, or in aggregated/anonymized form.

4. Providers (sub-processors)

We never sell your data or your customers’ data, and we do not use it to serve third-party ads.

5. AI & automation

The AI assistant and automations act within the scope you configure and the permissions of the person using them. The AI manager and front-of-house bots are capped to each user’s access level and cannot act outside it.

6. Retention and security

We keep data while the account is active, then for the period required by law. Secrets (tokens, keys, app passwords) are encrypted at rest (AES-256-GCM) and never exposed to the browser. Data is isolated per business. You can request deletion of your account and data at any time.

Database backups are encrypted (AES-256-GCM) before they leave our servers and stored in a private bucket at Cloudflare (R2) in North America — Cloudflare holds the file but cannot read it, because the key never leaves our control. Backups are deleted automatically after 30 days by a rule on the bucket itself, not by anyone remembering to do it.

7. Your rights

Under Quebec’s Law 25 and applicable laws, you can access, correct or delete your data, or withdraw consent (including disconnecting Google or a mailbox at any time from your dashboard). Write to zen-ai.net/consultation.

8. Where your data is stored, and outside Quebec

Our application and database run on managed cloud infrastructure (Railway) located in the United States — not in Canada. We say so plainly because, under Law 25, communicating personal information outside Quebec carries specific obligations, and because you are entitled to know where your customers' information physically sits before you trust us with it.

What protects it there: encryption in transit (TLS) on every connection; credentials, tokens and mailbox passwords encrypted at rest; access scoped per user and enforced server-side; and our provider's own contractual data-protection terms. We have assessed this transfer against the factors Law 25 requires — the sensitivity of the information, the purpose of its use, the protective measures around it, and the legal regime of the destination. If you need your data to remain in Canada, tell us before you sign: it is a hosting decision we can discuss, not something to discover later.

9. Privacy Officer & confidentiality incidents

The person responsible for the protection of personal information at Zen Solutions is Mathieu Payment, owner. Reach the Privacy Officer at privacy@zen-solutions.net for any question, access request, correction, deletion, or complaint about how information is handled.

We keep a confidentiality incident register, in which every incident involving personal information is recorded — including those that do not present a risk of serious injury — and retained for at least five years. If an incident presents a risk of serious injury, we notify the Commission d'accès à l'information and the people concerned promptly, and take reasonable measures to reduce the risk and prevent recurrence. We remain responsible for these obligations even where the information is held by a provider on our behalf.

10. Cookies, the advertising pixel & changes

Essential cookies (session, language preference) are set on every visit and cannot be turned off — without them the site cannot keep you signed in or remember which language you read in.

On our own marketing pages we also offer the Meta advertising pixel, and it is off until you say yes. Nothing is requested from Meta and no advertising cookie is written unless you accept the notice shown on your first visit. Refusing loads nothing at all, and a Global Privacy Control signal from your browser is honoured as a refusal without us asking. When you do accept, the pixel discloses your IP address, your browser and the pages you view on this site to Meta Platforms, in the United States, so we can measure and target our own advertising. It is never placed on a client's own site or storefront.

You can change your answer at any time: review your advertising-measurement choice.

We may update this policy; the date at the top shows the last revision, and material changes are communicated to account owners.

11. The mobile app (Android)

The Zen Solutions app is the same service in a phone-sized window: it signs you in to the account your employer or Zen Solutions created for you, and shows you your own work. It asks for a small number of phone permissions, each for one purpose only, and each refusable — the app keeps working without them, minus that feature.

Diagnostics. If the app crashes it sends us the error, the app version and the phone model, attached to your business and your login so we can find it. It carries no message content, no customer records and no location. You can also send the same report yourself from Settings → Support & diagnostics.

What the app does not do. No advertising identifier, no analytics profile, no third-party trackers, and nothing collected for advertising. We do not sell your data or your customers' data. The app collects nothing at all until you sign in.

Deleting your data. Signing out removes this phone from our notification list. To delete an account and its data, write to the Privacy Officer at privacy@zen-solutions.net — for an employee account, your employer can also remove it from the Employees tab, which deletes it along with its registered devices.

Zen Solutions — zen-ai.net/consultation