Last updated 12 August 2026
Data Controller: [Zoto Legal Entity Name], [Registered Address] ("ZOTO", "we"). EU Representative (GDPR Art. 27, where required): [Name and Address]. Grievance / Data Protection Officer: [Name]. Contact: hello@zoto.ie.
Items shown in grey brackets are being finalised with our legal advisors.
1. Scope
This Policy explains how ZOTO collects, uses, stores, shares, and protects personal data when you use the ZOTO app or website, including free and paid tiers (visa alerts, parcels, job referrals, discounts, accommodation, community hubs, rewards).
2. Data We Collect
Examples: Name, date of birth, nationality, profile photo
Source: User-provided
Examples: Email, phone number, home or shipping address
Source: User-provided
Examples: Visa type, appointment preferences, residence permit status
Source: User-provided (may be sensitive in some contexts)
Examples: Card token, billing address, transaction history
Source: Stripe (processor)
Examples: CV details, job preferences, referral history
Source: User-provided
Examples: GPS or IP-derived location
Source: Device, with consent
Examples: Posts, community hub selections, messages, event RSVPs
Source: User-generated
Examples: Device ID, IP address, interaction logs, cookies
Source: Automatic
Examples: Opt-ins for partner offers and referral codes
Source: User-provided
We do not intentionally collect special category data (e.g., religion, health, sexual orientation) unless voluntarily and explicitly provided by you (e.g., community hub self-selection reflecting cultural origin) — such disclosure is treated as explicit consent under GDPR Art. 9(2)(a).
3. How We Use Your Data
Legal basis (GDPR): Contract performance (Art. 6(1)(b))
Legal basis (GDPR): Contract performance / Consent
Legal basis (GDPR): Contract performance
Legal basis (GDPR): Contract performance
Legal basis (GDPR): Contract performance
Legal basis (GDPR): Consent (Art. 6(1)(a)) — opt out anytime
Legal basis (GDPR): Legitimate interest (Art. 6(1)(f))
Legal basis (GDPR): Legal obligation (Art. 6(1)(c))
Legal basis (GDPR): Legitimate interest / Consent for non-essential cookies
4. Consent
4.1 Where processing relies on consent (marketing, non-essential cookies, community-hub cultural data, location), ZOTO obtains clear, specific, informed and freely given consent via an unticked checkbox or explicit in-app action. Pre-ticked boxes and bundled consent are not used.
4.2 You may withdraw consent at any time via Profile → Edit profile → Privacy & data, or by emailing hello@zoto.ie, without affecting the lawfulness of prior processing.
4.3 Consent for minors is not sought; the Platform is restricted to users 18+.
4.4 Consent records (type of consent, policy version accepted, timestamp) are logged for audit purposes.
5. Sharing and Disclosure
5.1 We share data with:
- (a) Payment processors (Stripe) — transaction data only;
- (b) Partner Brands — limited data (e.g., name, redemption code) needed to fulfil a discount or referral, with your consent or where necessary for contract performance;
- (c) Logistics and courier partners — shipping data for parcel services;
- (d) Influencer and referral partners — anonymised or aggregated attribution data, not full personal profiles, unless you explicitly opt in;
- (e) Cloud infrastructure providers acting as processors under signed Data Processing Agreements;
- (f) Government or regulatory authorities where legally compelled — we will notify you unless legally prohibited.
5.2 We do not sell personal data to third parties for their own independent marketing purposes.
6. International Transfers
Personal data may be transferred across borders. Transfers from the EU/EEA to non-adequate jurisdictions rely on European Commission Standard Contractual Clauses or another valid Art. 46 GDPR mechanism, supplemented by a Transfer Impact Assessment where required.
7. Retention
Retention period: Duration of account + 3 years after deletion
Retention period: 7 years (statutory bookkeeping)
Retention period: Until withdrawn + 3 years (proof of consent)
Retention period: Duration of account, unless flagged for legal hold
Retention period: 3 years
8. Your Rights
Subject to applicable law (GDPR Arts. 15–22; DPDP Act Sections 11–14) you have the right to access your data, rectify inaccuracies, erase data, restrict or object to processing, port your data, withdraw consent, and lodge a complaint with a supervisory authority (in Ireland, the Data Protection Commission). Requests can be made in-app or via hello@zoto.ie and are actioned within 30 days.
9. Security
ZOTO implements encryption in transit (TLS 1.2+) and at rest, role-based access controls, regular security review, and incident response procedures. In the event of a personal data breach likely to result in risk to your rights, ZOTO will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and affected users without undue delay where high risk exists (Art. 34).
10. Children's Privacy
The Platform is not directed at individuals under 18. We do not knowingly collect data from minors; accounts found to belong to minors will be deleted.
11. Automated Decision-Making
ZOTO does not currently use fully automated decision-making producing legal effects. If introduced (e.g., algorithmic job matching), users will be informed and given the right to request human review (GDPR Art. 22).
12. Changes to this Policy
Material changes are communicated via email or in-app notice at least 15 days before taking effect, with an updated "Last updated" date and, where required, fresh consent.
13. Contact
Data protection queries: hello@zoto.ie. Grievance Officer: [Name and Address]. EU Representative: [Name and Address]. You may also complain to your local EU Data Protection Authority or, in India, the Data Protection Board.