Privacy Policy
Last updated: 2026-06-30
This Privacy Policy describes how Zodiac Labs GmbH (“Zodiac,” “we,” “us”) collects, uses, and protects personal data across all of our services: the website at zodiac.eco (the “Site”), our web application (the “App”), and our browser extension (the “Extension”) — together, the “Services.” It explains your rights under the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other applicable laws.
1. Data controller
The data controller responsible for processing your personal data is:
Zodiac Labs GmbH
Kolonnenstraße 8
10827 Berlin
Email: privacy@zodiac.eco
2. What data we collect
Information you provide
- Contact. When you contact us (e.g., to book a demo or ask a question), we process your email address and any information you choose to share.
- Account. When you create an account, we process the data required to register and operate it — including your email address and authentication identifiers. Authentication is handled by WorkOS (see Section 4).
- Newsletter. When you subscribe to our product updates, we process your email address and the confirmation of your subscription (double opt-in). Delivery and unsubscribe handling run through Resend (see Section 4). You can unsubscribe at any time with one click in every email; after unsubscribing we retain only what is needed to honor your opt-out.
Information collected automatically
- Server logs. Our hosting providers record the IP address of each request, the user agent, and the timestamp. These are retained for a maximum of 30 days for security and abuse prevention.
- Diagnostic and error data. When the App or Extension encounters an error, we collect technical diagnostic data through our error-monitoring provider (Sentry) to detect and fix problems. This may include your IP address, browser and device information, the actions leading up to the error, the URLs and pages visited, the data submitted in the request that triggered the error, and related technical context.
- Aggregated analytics. On the Site we use Plausible Analytics, a privacy-friendly analytics tool that does not use cookies and does not collect personally identifiable information. IP addresses are hashed with a daily-rotating salt and discarded.
- Local storage. The Extension stores configuration and operational data locally in your browser (for example, your connected accounts and routes). This data stays on your device and is not transmitted to us except as described in this policy.
3. Legal basis for processing (GDPR)
- Article 6(1)(b) GDPR (contract) — to register and operate your account, respond to your inquiries, and provide the Services you request.
- Article 6(1)(f) GDPR (legitimate interest) — to operate, secure, debug, and improve the Services through server logs, error monitoring, and aggregated analytics.
- Article 6(1)(a) GDPR (consent) — only where we ask for and obtain your specific consent.
4. Third-party processors
We rely on the following processors to operate the Services. Each processes personal data only on our instructions:
- WorkOS, Inc. — authentication and identity management; processes account and login data. (United States)
- Neon, Inc. — managed database hosting for the App; stores account and application data. (United States)
- Fly.io, Inc. — backend application hosting; processes request metadata and server logs to operate the App. (United States)
- Functional Software, Inc. (Sentry) — error and performance monitoring for the App and Extension; processes diagnostic data as described in Section 2. (United States)
- Vercel Inc. — hosting and CDN for the Site and App; processes server logs to deliver them. (United States)
- Cloudflare, Inc. — CDN, DNS, and DDoS/security protection; processes request metadata, including IP addresses, to deliver and secure the Services.
- Plausible Analytics — aggregated traffic analytics for the Site; does not process personal data.
- Resend, Inc. — newsletter delivery and subscription management; processes subscriber email addresses and delivery events. (United States)
We have data-processing agreements (DPAs) in place with each processor as required under Article 28 GDPR.
5. Blockchain interactions
The App and Extension help you prepare and submit transactions to public blockchains. When you use these features, wallet addresses and transaction data are transmitted to third-party RPC node providers and, where applicable, to the Safe Transaction Service in order to read onchain state and relay your transactions. These parties operate independently and we do not control how they process or retain this data. Information recorded on a public blockchain is, by design, public and permanent.
6. International transfers
Some of our processors are located outside the European Economic Area, including in the United States (WorkOS, Neon, Fly.io, Sentry, and Vercel). Where data is transferred outside the EEA, we rely on Standard Contractual Clauses approved by the European Commission and apply additional technical safeguards consistent with the Schrems II decision.
7. Cookies and local storage
The Site does not use any cookies that require consent under TDDDG §25 / ePrivacy Directive Article 5(3). Strictly necessary cookies may be set to operate the Services (for example, to keep you signed in); these do not track you across sites and do not require consent. The Extension uses local browser storage to function, as described in Section 2.
8. Your rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access the personal data we hold about you (Article 15).
- Rectify inaccurate data (Article 16).
- Erase your data, subject to legal limits (Article 17).
- Restrict processing (Article 18).
- Port your data to another controller (Article 20).
- Object to processing based on legitimate interest (Article 21).
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Article 7(3)).
- Lodge a complaint with a supervisory authority. The competent authority for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
To exercise any right, contact privacy@zodiac.eco.
9. California residents (CCPA/CPRA)
If you are a California resident, you have the following rights:
- The right to know what personal information we collect, use, and disclose.
- The right to delete personal information we have collected.
- The right to correct inaccurate personal information.
- The right to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as defined under the CCPA/CPRA.
- The right to non-discrimination for exercising your rights.
To exercise any of these rights, contact privacy@zodiac.eco.
10. Data retention
We retain personal data only as long as necessary for the purposes described above, or as required by applicable law. Server logs are retained for up to 30 days. Diagnostic and error data is retained for up to 90 days. Account data is retained for the life of your account and deleted within 90 days of account closure, subject to legal retention obligations; where you ask us to erase your data under Article 17 GDPR, we action the request without undue delay. Communications you initiate with us are retained for as long as needed to provide a response and for legitimate business records.
11. Children
The Services are not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will delete it.
12. Security
We use industry-standard technical and organizational measures to protect personal data, including TLS encryption in transit, access controls, and regular security review. For security vulnerabilities, contact security@zodiac.eco.
13. Changes to this policy
We may update this Privacy Policy. The current version is always available at this URL. Material changes will be communicated by updating the “Last updated” date at the top of this page.
14. Contact
Questions about this Privacy Policy or our data practices? privacy@zodiac.eco.