This structure reflects the current product, but it is not legal advice or a final notice. The operator must replace every bracketed placeholder, verify the actual infrastructure and business model, and obtain appropriate legal review.
1. Controller and contact
The data controller has not yet been entered. Before publication, replace the placeholders below with the person or legal entity that determines how Zenolu processes personal data.
Privacy questions and rights requests need a monitored contact channel. Do not publish this draft as a complete notice until that channel and the responsible entity are confirmed.
- [Full legal name or registered business name]
- [Complete postal address]
- [Privacy contact email address]
- [Data protection officer or representative, if legally required]
2. Information the product handles
The current application is designed around Supabase authentication and database storage. The exact production configuration and every enabled log or integration must still be audited.
Public creator profiles and published palettes are optional community features. Private account identifiers are designed to remain separate from the public profile.
- Account information: email address, authentication status, display name, account timestamps, and security-related authentication records.
- Workspace information: projects, design-system documents, saved versions, sharing snapshots, customer-review comments and display names, titles, and related timestamps.
- Community information: optional creator profile details, published palette snapshots, likes, and palette-use events.
- Technical information: account and share-review session cookies, language and theme preferences, local editor drafts, request metadata, and operational or security logs configured by the operator.
3. Purposes and legal bases
Zenolu needs information to create accounts, save and export design systems, provide sharing and community features, secure the service, and respond to requests.
The operator must map every purpose to an applicable legal basis before launch. Depending on the context, that may include performing a contract, legitimate interests, legal obligations, or consent. This draft does not choose those bases for the operator.
- [Confirm the legal basis for account creation and cloud project storage]
- [Document the balancing test for security, fraud prevention, and essential logs where required]
- [Identify any optional processing that needs consent and provide a withdrawal path]
- [Document legal retention duties that apply to the operator]
4. Service providers and international transfers
The repository currently integrates Supabase for authentication and database services. Production hosting, transactional email, monitoring, analytics, and support providers have not been confirmed in this draft.
Before launch, the operator must list the providers actually used, their roles and processing locations, and any safeguards for transfers outside the relevant jurisdiction.
- Supabase: verify the contracted entity, selected region, data processing agreement, sub-processors, and transfer safeguards.
- [Production hosting provider and region]
- [Transactional email or SMTP provider and region]
- [Monitoring, analytics, customer-support, or other processors—remove if none]
5. Retention, export, and deletion
The product includes a personal-data export and permanent account deletion. Database relationships are designed to remove account-owned projects, versions, shares, customer-review threads and comments, publications, likes, uses, and profiles when the identity is deleted.
Operational logs, email delivery records, provider backups, and legally required records may follow separate schedules. Those schedules are not yet specified and must be reconciled with the deletion promise.
- [Retention period for inactive accounts and workspace data]
- [Retention and access period for security and application logs]
- [Backup lifecycle and maximum time until deleted data expires from backups]
- [Any records retained for legal claims, tax, or compliance, including the applicable period]
6. Your choices and rights
Depending on where a person lives and which law applies, they may have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal data, and to complain to a supervisory authority.
Zenolu’s account area provides editing, export, and deletion controls, but the operator still needs a verified process for requests that cannot be completed in the product.
- Use Account settings to update supported personal details, download the available export, or start account deletion.
- Use [privacy contact email] for other requests after the address has been configured.
- [Name and link of the competent supervisory authority, if this must be identified]
- [Identity-verification and response procedure for data-subject requests]
7. Cookies and storage on your device
Zenolu currently uses storage needed for authentication, locale selection, appearance preferences, and local editor continuity. No advertising or behavioral analytics integration is present in the reviewed codebase.
The operator must repeat this audit against the deployed application. If optional analytics, marketing tools, or embedded third-party media are added, this section and any consent controls must be updated before those tools run.
- Authentication cookies keep a signed-in session and are refreshed by the application.
- A short-lived, HTTP-only cookie keeps access to one customer-review link after its password is accepted or, for a public link, after the reviewer starts commenting. Zenolu stores only the capability digest and does not ask a reviewer for an email address.
- A locale cookie remembers English or German selection.
- Browser storage remembers appearance preferences and may hold a local, unsynced editor draft.
- [Cookie names, lifetimes, providers, and security attributes verified from production]