Enzo

Privacy Policy

Last updated: September 2, 2026

1. Who We Are

This Privacy Policy describes how Enzo Technology, Inc., a Delaware corporation (“we,” “us,” or “our”) collects, uses, and shares your personal information when you use the website and content we operate (the “Site”) and the Enzo platform we make available to authorized organizations (the “Platform”, and together with the Site, the “Service”).

Enzo is an AI-powered relationship intelligence platform for go-to-market teams. The Service is intended for use in a business and workplace context.

This Policy covers the following categories of personal information:

  • Customer Data — the personal information contained within the data described as “Customer Data” in our Terms of Service, which we process and manage on behalf of a customer organization, under its instruction, as part of providing the Platform.

  • User Data — personal information about the individuals a customer organization authorizes to use the Service.

  • Visitor Data — personal information about visitors to our Site.

Our role differs by category. For Customer Data, the customer organization is the data controller and Enzo acts as a processor or service provider, processing data solely to provide the Service pursuant to that organization’s instructions. For Visitor Data, and for User Data processed for our own business purposes — account administration, billing, service security, fraud prevention, legal compliance, and communications relating to our own services — Enzo acts as an independent controller or business.

We process Customer Data on behalf of and under the instruction of the customer organization, in accordance with our data processing agreement with them. Accordingly, this Privacy Policy does not describe the privacy practices of our customers. If your personal information appears in a customer organization’s systems and you want to know how that organization collects, uses, or retains it, or you wish to exercise your rights over it, please contact that organization directly. If such data is processed on behalf of one of our customers, we will forward your request to such customer for their further handling.

Customer responsibilities. A customer organization decides whether and how to use the Platform and which of its systems to connect. It is solely responsible for ensuring that the individuals using the Platform on its behalf, and the individuals whose personal information appears in the data it connects, have been given adequate notice and, where notice or consent is required by applicable law, have given it — including specifically in the context of an employment relationship. The customer organization is also responsible for handling data subject requests from those individuals.

For clarity, with respect to data privacy and data protection obligations (including compliance with applicable data protection laws), the data processing agreement exclusively controls and will prevail over this Policy in the event of any conflict.

For privacy-related questions, contact us at privacy@getenzo.io. For general questions, contact support@getenzo.io. Our mailing address is 1750 Franklin Street 7, San Francisco, California 94109.

2. What We Collect

CategoryExamplesWhy
Account informationSuch as name and work emailCreate and maintain your account
Organization dataSuch as company name, team membership, and roleProvide the Service to your organization
Business records and communicationsSuch as company and deal records; notes; meeting records; messages and correspondence; and the transcripts produced from short audio clips during voice capture, and analyses of themGenerate relationship insights and recommended actions
ContactsNames, email addresses, and other profile details recorded in your organization’s systemsBuild the contact graph used for relationship tracking
Usage and diagnostic dataSuch as Platform pages visited, features used, IP address, browser type, and error reportsImprove the Service and diagnose issues
Visitor DataPages viewed and interactions on our Site, collected without cookiesUnderstand which parts of the Site are useful
Information you provideYour name, email address, phone number, company, and role, when you sign up for our mailing list or otherwise communicate with usRespond to you and send what you asked for

Third-Party Data: Because Enzo processes the records held in your organization’s business systems, we handle data about the contacts, prospects, and counterparties named in them, in addition to data about users — the same Third-Party Data described in our Terms of Service. This means data about people who are not Enzo users may be stored in the Service. Your organization is the data controller for this information.

Sensitive data: Business records and correspondence may contain sensitive personal information, depending on what your organization’s communications contain. We process it solely to deliver the Service. We do not intentionally request highly sensitive identifiers such as Social Security numbers, and your organization can stop this processing at any time by revoking our access from within its own systems.

3. Google API Data

Enzo accesses your Google account only to sign you in. Enzo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not sell it.

4. AI Processing

We use third-party AI services to power core features:

CategoryData SentPurpose
Large language model providersBusiness records and communications, contact names, account context, and transcriptsGenerate insights, account context, and suggested actions
Embedding providersText content from Customer DataSemantic search and content similarity matching
Speech-to-text providerShort audio clipsTranscription

The specific providers we use are identified in the data processing agreement with your organization.

No automated decisions. AI-generated outputs are informational only and do not produce legal effects or similarly significant effects on you. No automated decisions are made about your access to the Service or eligibility for anything.

Opting out: Your organization can revoke our access to any connected system at any time from within that system’s own settings, which stops all AI processing of its data. This will disable core features.

5. Who We Share Data With

We disclose your personal information only to service providers who help us provide the Service or perform business functions on our behalf. All of them are located in the United States. They include our cloud infrastructure provider, for storage, compute, hosting, and speech-to-text; artificial intelligence providers, as described in Section 4; website analytics providers, for measuring use of our Site; and email distribution services, for sending materials you request and managing our mailing list. Neither our analytics providers nor our email distribution services receive Customer Data.

The specific providers that process Customer Data on our behalf are identified in the data processing agreement with your organization.

We may also disclose personal information when required by law, to protect our rights, or in connection with a merger, acquisition, or sale of all or a portion of our assets.

We do not sell your personal information. We do not share personal information for advertising purposes or cross-context behavioral advertising.

6. Cookies

We use only essential cookies — authentication and session tokens necessary for the Service to function. We do not use cookies for analytics, advertising, tracking, or retargeting, so no consent banner is required and there is nothing to opt out of. You can manage cookies through your browser settings; disabling essential cookies may prevent the Service from functioning.

7. Data Storage and Security

We implement reasonable security measures including encryption in transit (TLS) and at rest (AES-256), least-privilege access controls, and secure credential storage.

However, no method of electronic transmission or storage is 100% secure. We cannot guarantee the absolute security of your data.

If we become aware of a security breach affecting personal data, we will notify the affected customer organization without undue delay, and will assist that organization in notifying the individuals concerned where it is required to do so. Our notification will describe the nature of the breach, the types of data affected, the likely consequences, and the measures we have taken or propose to take in response.

8. Data Retention

We retain your data while your account is active and for a reasonable period afterward as described below:

  • Account and organization data: Retained while your account is active. Deleted from active systems within 90 days of account deletion.

  • Customer Data, including transcripts, AI-generated content, and related processing data: Retained while your organization's subscription is active. Deleted within 90 days of subscription termination or a deletion request. Audio is sent for transcription and not persistently stored.

  • AI execution logs: Prompts and outputs from AI processing are retained for up to 90 days for quality monitoring and debugging, then permanently deleted.

  • Support and business records: Retained for as long as reasonably necessary in order to maintain our relationship and provide you with our Services, and in order to comply with our legal and contractual obligations.

  • Website analytics: Retained in aggregate. Because it is collected without cookies, it is not linked to an identified individual.

9. Your Rights

Regardless of where you are located, you can email privacy@getenzo.io to:

  • Access your data: Request a copy while your account is active, or for up to 30 days after termination.

  • Delete your data: Request deletion of your account and all associated data, subject to the retention periods described in this Policy.

Your organization can also revoke our access to any connected system at any time from within that system's own settings, and can revoke our access to your Google sign-in through your Google account permissions.

For EEA, UK, and Swiss Residents

Under the GDPR, you also have the right to rectification, restriction of processing, data portability, objection to processing, and to lodge a complaint with your local data protection authority. Our legal bases for processing include performance of a contract, compliance with a legal obligation, legitimate interest in account management, security, and product improvement, and, where applicable, your consent. Where we process Customer Data as a processor, the customer organization is responsible for establishing a legal basis for that processing. Processing can be stopped at any time by revoking our access or by contacting us, without affecting the lawfulness of processing carried out before withdrawal.

For California Residents

Under the CCPA/CPRA, you have the right to know what personal information we collect, use, and disclose; to delete it; to correct it; to limit the use and disclosure of sensitive personal information; and not to be discriminated against for exercising these rights. We will respond within 45 days as required by law.

In the last 12 months we may have collected the following categories of personal information, as defined in the CCPA: identifiers; customer records information; commercial information; internet or other electronic network activity information; professional or employment-related information; audio, electronic, and visual information; and inferences. We collect these for the purposes described in Section 2 and disclose them to the categories of service provider described in Section 5.

We do not sell or share your personal information for cross-context behavioral advertising, so there is nothing to opt out of. We honor Global Privacy Control (GPC) browser signals as a valid opt-out request under the CCPA/CPRA.

10. Third-Party Links

The Service may contain links to third-party websites or services that are not owned or controlled by Enzo Technology, Inc. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. You acknowledge and agree that we are not responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with your use of or reliance on any such content, goods, or services available on or through any such websites or services.

11. International Transfers

As described in Section 5, all of our service providers are based in the United States, so if you access the Service from outside the United States, your data will be transferred to and processed here.

For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as a legal mechanism for international data transfers. We are also evaluating certification under the EU-US Data Privacy Framework.

12. Children’s Privacy

The Service is intended for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email before they take effect. Non-material changes (such as formatting or clarifications) may be made without advance notice. The “Last updated” date at the top of this page indicates when the current version was published, and an amended version is effective as of that date. Continued use of the Service after a revised policy is published constitutes acceptance.

14. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the State of California, United States, without regard to its conflict-of-laws principles, consistent with our Terms of Service.