1 Introduction
This Privacy Policy explains how PKG AB processes personal data in connection with providing and operating the Zensli service, including Customer account, communication, billing, security, and service usage data.
Zensli can also be configured by Customers to collect, analyse, identify, segment, and activate data relating to visitors of the Customer’s websites or applications. In those circumstances, the Customer determines the purposes and configuration of the processing and normally acts as Data Controller, business, or equivalent responsible entity under applicable privacy law. PKG AB normally processes such data on the Customer’s behalf as Data Processor, service provider, or equivalent provider.
Customers are responsible for configuring and using Zensli in accordance with the privacy, electronic communications, consumer privacy, and other laws applicable to their organisation, users, purposes, and jurisdictions.
PKG AB does not sell Customer account, communication, billing, or service usage data to advertisers or data brokers.
2 Who We Are
PKG AB, Reg. No. SE559008922201, is a Swedish company that provides the Zensli service.
Zensli helps organisations collect and analyse website activity, create visitor profiles, identify visitors where configured, generate analytical insights, and activate customer intelligence in connected systems.
For personal data related to Customer accounts, billing, communication, security, and use of the Zensli platform, PKG AB acts as Data Controller or in an equivalent role under applicable privacy law.
When Zensli processes website visitor or application user data on behalf of a Customer, the Customer normally determines the purposes and means of that processing and acts as Data Controller, business, or equivalent responsible entity under applicable law. PKG AB normally acts as Data Processor, service provider, or equivalent provider acting on the Customer’s instructions.
The Customer determines which Zensli features are enabled, what data is collected, whether and how visitors are identified, applicable privacy and tracking settings, how long data is retained, which integrations are used, and how collected information and analytical results are used.
Processing performed by PKG AB on behalf of a Customer is governed by the Zensli Data Processing Agreement and the Customer’s documented instructions.
3 Personal Data We Collect and Use
When PKG AB acts as Data Controller or determines the purposes of processing, we may collect and process the following categories of personal data:
Zensli may also process website visitor and application user data on behalf of Customers. The categories of data processed depend on the Customer’s configuration, purposes, integrations, and documented instructions.
4 Customer-Controlled Processing
Zensli provides configurable analytics, identification, profiling, security, integration, and activation capabilities. The availability of a feature does not mean that the feature is appropriate or lawful for every Customer, visitor, purpose, or jurisdiction.
Customers determine how Zensli is configured for their websites and applications. Depending on the Customer’s configuration, information processed through Zensli may include:
- Website and application activity: Page views, visits, events, interactions, clicks, downloads, form activity, referrers, URLs, paths, titles, and similar usage information.
- Technical information: IP addresses, browser and device information, operating system, screen information, network and ASN information, language settings, and similar technical signals.
- Identifiers and device signals: Cookies, local storage identifiers, browser or device signals, fingerprints, pseudonymous visitor identifiers, or similar technologies where enabled or used by the Customer.
- Submitted and identified information: Information submitted through forms or otherwise provided by users, including email addresses, telephone numbers, customer IDs, external IDs, or other identifiers configured by the Customer.
- Profiles and analytical information: Visitor profiles, segments, engagement scores, churn-risk indicators, classifications, behavioural signals, and other analytical results generated from Customer-controlled data.
- Connected-system data: Information received from or transmitted to CRM, marketing automation, analytics, data platforms, or other systems connected by the Customer.
The Customer is responsible for determining which features and data-processing activities are appropriate for its purposes and for configuring Zensli accordingly. This includes determining any required legal basis, consent or notice requirements, opt-out mechanisms, retention periods, identification settings, and other privacy controls required under applicable law.
Customers are responsible for providing appropriate privacy notices and, where required, obtaining consent, recognising applicable privacy preference signals, or providing mechanisms through which individuals can exercise applicable privacy choices.
Zensli may provide technical capabilities that assist Customers in implementing their chosen privacy approach, but PKG AB does not determine the Customer’s legal basis or decide which optional tracking, identification, profiling, analytics, or activation features the Customer should use.
5 Legal Bases for Processing
Where PKG AB acts as Data Controller or otherwise determines the purposes of processing, we process personal data using one or more legal bases available under applicable law.
Where Zensli processes website visitor or application user data on behalf of a Customer, the Customer is responsible for determining the appropriate legal basis and for satisfying applicable consent, notice, opt-out, privacy preference signal, and other legal requirements.
6 Your Rights and Privacy Choices
Depending on where you live, the applicable law, the nature of the processing, and the role of the organisation processing your information, you may have some or all of the following rights:
To exercise a right concerning personal data controlled directly by PKG AB, please contact us.
If your request concerns data collected through a website or application operated by a Zensli Customer, you should normally contact that Customer directly. The Customer determines the relevant processing and is generally responsible for responding to privacy requests concerning that data.
PKG AB assists Customers with valid privacy requests concerning data processed through Zensli in accordance with the Data Processing Agreement and applicable law.
Supervisory and privacy authorities
7 Children’s Privacy
Zensli Customer accounts and business services are not intended for children under 16.
PKG AB does not knowingly collect Customer account data directly from children. If such information is identified, it will be handled as required by applicable law.
Customers are responsible for determining whether their websites, applications, audiences, or use of Zensli involve children or minors and for configuring and using the service in accordance with applicable age, consent, and children’s privacy requirements.
8 Who We Share Personal Data With
Personal data for which PKG AB is responsible may be disclosed to trusted providers where reasonably necessary to operate, secure, support, or administer the Zensli service or meet legal obligations.
PKG AB does not sell or rent Customer personal data to advertisers or data brokers.
Customers may configure Zensli to transmit data to CRM, marketing automation, analytics, data platforms, or other systems and recipients selected by the Customer. Such Customer-directed transfers are controlled by the Customer.
The Customer is responsible for determining whether its collection, use, disclosure, or transfer of information constitutes a sale, sharing, targeted advertising, disclosure, or another regulated activity under the laws applicable to the Customer.
9 International Transfers
Where PKG AB transfers personal data outside the EU or EEA in connection with processing for which PKG AB is responsible, an appropriate transfer mechanism is used where required, such as an adequacy decision, Standard Contractual Clauses, or another mechanism recognised under applicable Data Protection Legislation.
Additional safeguards may be applied based on the destination, recipient, type of data, and risks associated with the transfer.
Customers may also configure Zensli to transfer data to third-party systems or services selected by the Customer. The Customer is responsible for assessing and configuring those destinations and transfers in accordance with the laws applicable to the Customer.
10 Retention of Personal Data
For personal data for which PKG AB determines the purposes of processing, data is retained only for as long as reasonably necessary for the relevant purpose, including providing and securing the service, resolving disputes, and meeting legal, accounting, and reporting obligations.
Customer account data is normally retained while the account remains active. Following termination, data is deleted or anonymised according to the applicable agreement and retention policy, normally within 30 days unless a longer period is required by law.
For website visitor, application user, analytics, identification, profile, interaction, and similar data processed on behalf of a Customer, the Customer determines the applicable retention settings and instructions, subject to the applicable agreement and technical capabilities of the service.
Customers are responsible for selecting retention periods appropriate to their purposes and applicable legal requirements.
11 How We Protect Personal Data
PKG AB implements technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction, taking into account the nature of the processing and associated risks.
Access Control
Access is restricted according to role, responsibility, and operational need.
Encryption
HTTPS protects data in transit, with appropriate encryption controls applied to stored data where implemented.
Monitoring
Relevant system and application activity is logged and monitored to support incident detection, investigation, security, and auditing.
Backup and Recovery
Backup, redundancy, and recovery procedures support the availability and resilience of the service.
Additional information is available in the Zensli Data Processing Agreement .
12 Automated Decision-Making and Profiling
PKG AB does not use Customer account, communication, or billing data to make decisions about individuals that produce legal or similarly significant effects solely through automated processing.
Zensli may provide Customers with functionality for visitor identification, profiling, segmentation, engagement scoring, churn-risk analysis, classifications, automation, and similar analytical activities.
The Customer determines whether these features are enabled, how they are configured, which data is used, and how their outputs are applied.
The Customer is responsible for determining whether its use constitutes profiling, automated decision-making, targeted advertising, or another regulated activity and for implementing any notices, choices, safeguards, legal bases, or other measures required by applicable law.
13 Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in the Zensli service, legal requirements, security practices, data-processing activities, or the functionality available to Customers.
Material changes may be communicated through the Zensli platform, by email, or by another appropriate method.
The version published on this page is the current version of the Privacy Policy.
14 Contact Us
Contact PKG AB if you have questions about this Privacy Policy, want to exercise a privacy right concerning data controlled directly by PKG AB, or need information about how PKG AB handles personal data.
If your request concerns information collected by a Zensli Customer through that Customer’s website, application, or connected systems, please contact the Customer directly where possible. PKG AB may assist the Customer where required under the applicable Data Processing Agreement.
A1 Appendix 1 – Technical and Organisational Measures
PKG AB applies technical and organisational measures intended to protect personal data and maintain the confidentiality, integrity, availability, and resilience of the Zensli service.
- Access Control: Access to personal data and production systems is restricted to authorised personnel according to operational need.
- Authentication and Authorisation: Authentication and authorisation mechanisms are used to verify users and control access to systems and functionality.
- Encryption: Data is protected in transit using HTTPS, with appropriate encryption controls applied to stored data where implemented.
- Customer Data Separation: Technical and application controls are used to separate Customer accounts and Customer-controlled data and to restrict access according to the relevant Customer and authorised users.
- Monitoring and Logging: Relevant system and application activities are monitored and logged to support security, detection, investigation, troubleshooting, and auditing.
- Incident Response: Procedures are maintained for identifying, handling, investigating, and documenting security incidents.
- Availability and Redundancy: Infrastructure, backup, redundancy, and recovery mechanisms are used as appropriate to support continued availability and resilience.
- Personnel Confidentiality: Personnel authorised to handle personal data are subject to appropriate confidentiality obligations.
- Customer Configuration: Zensli provides configurable functionality that enables Customers to determine how certain visitor data, identification features, integrations, analytical functions, and retention settings are used within their implementation.
For additional details, refer to the Zensli Data Processing Agreement .
Use of the Zensli service is also governed by the applicable subscription agreement, Terms of Service, Data Processing Agreement, and any additional terms agreed between PKG AB and the Customer.
Privacy and data-protection requirements vary by jurisdiction, purpose, technology, and context. Customers are responsible for evaluating their own legal requirements and configuring and using Zensli accordingly. The availability of a Zensli feature does not constitute a determination by PKG AB that the feature may be used without consent, notice, opt-out, or another legal requirement.