ZEEUS - SbyDData & Privacy Policy
On this page

Mock Data Policy

Proposed effective date: July 11, 2026 · Last updated: July 11, 2026

This mock policy is provided for product demonstration and internal review. It is not final legal advice or an approved policy.

This mock Data Policy explains how ZEEUS - SbyD may collect, use, store, share, and protect personal data when people use the ESG questionnaire platform, the Yumi AI assistant, and related services.

1. Who is responsible for your data

ZEEUS - SbyD is the proposed data controller for the platform. Privacy questions and requests can be sent to privacy@zeeus.app. Technical support can be contacted at support@zeeus.app.

2. Data we may collect

  • Account and profile data, such as name, email address, optional username, profile image, and verification status.
  • Authentication and security data, including hashed passwords, reset and verification tokens, two-factor authentication data, passkey public credentials and device information, session tokens, IP addresses, user agents, and Google OAuth account data where enabled.
  • Organization data, including organization details, memberships, roles, invitations, and related timestamps.
  • Questionnaire and usage data, including ESG answers, selected options, multi-dimensional assessments, save timestamps, progress, and navigation state.
  • Yumi interaction data when AI features are enabled, including chat messages, questionnaire context sent to the model, tool requests, prompts, and model responses.
  • Audit and technical data, including important account and organization actions, exports, record identifiers, timestamps, IP addresses, user agents, errors, feature events, and rate-limit events.

3. Why we process data

  • To create and manage accounts, organizations, memberships, and invitations as part of providing the service.
  • To authenticate users, protect accounts, monitor security, and prevent misuse based on contractual necessity and legitimate interests.
  • To save questionnaire answers, calculate results, and generate reports requested by users.
  • To provide Yumi assistance where AI features are explicitly enabled and the user chooses to use them.
  • To maintain audit trails, comply with legal obligations, troubleshoot errors, and improve service reliability.

4. Yumi and automated assistance

Yumi uses AI models to suggest answers, explain fields, and help navigate the questionnaire. Relevant questionnaire context and prompts may be sent to OpenRouter when AI features are enabled.

  • Yumi's output is advisory and may be inaccurate.
  • Users can review, change, or reject suggested values.
  • No automated profiling is intended for advertising or marketing.
  • Questionnaire decisions remain under human control.

5. Service providers and data transfers

  • OpenRouter may process AI prompts and responses when Yumi is enabled.
  • Google may process authentication data when Google sign-in is configured and used.
  • The configured SMTP provider may process recipient and message data when email features are enabled.
  • Primary hosting is intended to be in the European Union. AI providers may process data in the United States or other countries, subject to appropriate transfer safeguards.

6. Internal access and legal disclosure

Authorized organization administrators may access member information, organization questionnaire answers, and organization audit records. ZEEUS - SbyD may disclose data where required by law or where necessary to protect legal rights, property, users, or the service.

7. Proposed retention periods

  • Account and authentication data: until account deletion, followed by up to 30 days for recovery and backups.
  • Session data: until session expiry, followed by up to 30 days for security purposes.
  • Organization data: until the last member leaves or the organization is deleted, followed by up to 90 days.
  • Expired invitation data: up to 30 days after expiry.
  • Questionnaire answers: until organization deletion, followed by up to 90 days.
  • AI interaction data: up to 30 days unless a resulting value is saved as a questionnaire answer.
  • Audit logs: up to seven years where required for compliance or accountability.
  • Technical logs: up to 90 days for monitoring and troubleshooting.

8. Security measures

  • Passwords are stored as hashes rather than readable passwords.
  • Sessions use expiring server-side tokens, and data in transit is intended to be protected with HTTPS/TLS.
  • Two-factor authentication and WebAuthn passkeys are available as additional account protections.
  • Organization access is role-based, and sensitive actions are recorded in audit trails.
  • AI, email, and test features are disabled by default and require explicit configuration.

9. Your rights and choices

  • Request access to, correction of, restriction of, or deletion of personal data, subject to applicable law.
  • Review and edit account details, organization memberships, and questionnaire answers available in the product.
  • Delete an account or, where authorized, an organization and its associated data.
  • Export questionnaire reports as PDF, CSV, or a data bundle.
  • Choose whether to use optional AI and email features where those choices are available.

10. Children's privacy

ZEEUS - SbyD is not intended for children under 16 and does not knowingly seek to collect their personal data.

11. Changes and contact

Material policy changes are intended to be communicated by email or an in-app notice. Questions, complaints, or rights requests can be sent to privacy@zeeus.app.