Privacy Policy
This policy describes how ZERQIVO processes users' personal data and the data contained in the documents uploaded to the platform.
1. Data controller
The data controller is Twist & Ride di Fabrizio Pisano, sole proprietorship, registered at Via Mar Ligure 5, 07026 Olbia (SS), Italy, VAT number 03023770906.
To exercise your rights under the GDPR, or for any question about the processing of your data, contact us through the contact form at zerqivo.com/enterprise#contact. The Zerqivo team will reply by email.
2. Data we process
Account data: e-mail address, name, the company you belong to and the role assigned to you within the workspace.
Uploaded documents: invoices and transaction documents uploaded by the user, together with the data they contain (parties involved, amounts, taxes, dates).
Service-generated data: audit outcomes, extracted evidence, applied rules and the activity log.
Technical data: application logs required for security, abuse prevention and error diagnostics.
3. Purposes and legal basis
Data is processed to deliver the requested service (performance of a contract), to keep the platform secure and prevent abuse (legitimate interest) and to comply with legal obligations.
Uploaded documents are never used for marketing purposes.
4. Artificial intelligence analysis
The content of uploaded documents is sent to an AI model provider solely to extract the data required for the audit. Tax conclusions are produced by deterministic rules configured within the platform.
Model calls are made server-side; no provider credential is ever exposed to the browser.
5. Retention
Documents, audits and activity logs are retained for as long as the account and workspace remain active, unless the user requests otherwise or a statutory retention obligation applies.
Deleting an account results in the deletion or anonymisation of the associated data, within the technical time required.
6. Recipients and providers
Data may be processed by technical providers acting as data processors: hosting and application infrastructure, managed database and storage, and the AI model provider.
An up-to-date list of providers can be requested through the contacts listed in section 1.
7. Security
Access to the workspace requires authentication. Data is isolated per tenant through database-level access policies, documents are stored in private storage accessible only through signed links, and application responses apply security headers and a Content Security Policy.
8. Your rights
You may request access, rectification, erasure, restriction, portability and objection to processing, as well as withdrawal of consent where applicable.
Requests should be sent to the contacts listed in section 1. You also have the right to lodge a complaint with the competent supervisory authority.
9. Changes
This policy may be updated. Material changes will be communicated to registered users through the service or by e-mail.