Privacy Policy
How Jenz collects, uses, and protects your personal data, and the rights you have over it.
Effective July 1, 2026 · Last updated July 21, 2026This Privacy Policy explains how Jenz AS ("Jenz," "we," "our," or "us") collects, uses, discloses, and protects personal data in connection with the Jenz platform and services ("Service"). It applies to our website (meetjenz.com), the Jenz Slack app, and all related services.
Jenz AS is established in Norway and the General Data Protection Regulation (GDPR), as incorporated into Norwegian law via the EEA Agreement, governs our processing of personal data.
1. Who We Are (Data Controller)
Jenz AS
Kongens gate 7
4611 Kristiansand
Norway
Org.nr. 938 033 110
Contact: [email protected]
For questions about this policy or to exercise your rights, contact us at [email protected].
2. Who This Policy Applies To
This policy covers three categories of individuals:
- Visitors people who visit meetjenz.com without an account
- Customers individuals who register for or administer a Jenz account or Workspace
- Workspace Members employees or team members of a Customer who interact with Jenz via Slack
Note for Workspace Members: Your employer (the Customer) is the data controller for personal data processed through your Slack workspace. Jenz processes that data as a data processor on their behalf, under a Data Processing Agreement (DPA). For questions about your employer’s data practices, contact them directly.
3. What Personal Data We Collect
3.1 Data You Provide Directly
| Data | Who | When |
|---|---|---|
| Name, email address, company name | Customers | Account registration |
| Billing name and address | Customers | Subscription purchase |
| Payment method details | Customers | Processed via our payment processor; Jenz never stores card numbers |
| Communications with us | Anyone | Support tickets, emails |
3.2 Data Collected Automatically
| Data | Who | Purpose |
|---|---|---|
| IP address, browser type, device type | Visitors, Customers | Security, analytics |
| Pages visited, referring URL | Visitors | Analytics |
| Timestamps, feature usage | Customers, Members | Product improvement, billing |
| Error logs and crash reports | Customers, Members | Debugging, quality |
3.3 Data from Slack
When a Workspace installs Jenz:
- Slack user IDs and display names of Members who interact with the bot
- Message content that Members send to Jenz in Slack (the prompts and instructions)
- Channel IDs and team ID of the installing Workspace
- Bot access token for the Workspace (stored encrypted; used to send replies)
We do not read Slack channels proactively or access conversations that do not involve the Jenz bot.
3.4 Data from Third-Party Integrations
When you connect integrations (e.g., Shopify, Stripe, Gmail, Meta for Facebook and Instagram ads), we access data from those services only as instructed by Users. This may include business data, customer order records, and other data held in those systems. Jenz does not store this data beyond the immediate task execution window unless you explicitly configure persistent storage.
Where Jenz surfaces integration data (for example, a Shopify order or product) into a Slack conversation in response to a request, that content becomes part of the conversation history and is retained and deleted according to Section 6 and on store uninstall, rather than kept as a separate integration dataset.
Shopify scopes and Protected Customer Data: For Shopify, Jenz requests read-only access to products, orders, customers, and store content (read_products, read_orders, read_customers, read_content). We access this data live, only when needed to carry out a task you ask Jenz to perform, and do not copy it into a standing Jenz database. We handle Shopify Protected Customer Data in accordance with Shopify’s Protected Customer Data requirements, applying data minimization and purpose limitation.
Shopify app removal and data deletion: When you uninstall Jenz from your Shopify store, we revoke and delete the store’s access credentials. In line with Shopify’s requirements, Jenz honors Shopify’s mandatory privacy webhooks: a customer data request (customers/data_request), a customer redaction request (customers/redact), and a store redaction request (shop/redact, which Shopify sends 48 hours after uninstall), upon which we erase the store’s data held by Jenz. Because Jenz does not keep a customer-indexed copy of Shopify records, customer-specific requests are handled at the store level.
Meta (Facebook and Instagram ads): If you connect a Meta account, you authorize Jenz through Meta’s login with the ads_read and ads_management permissions. With those permissions we read your advertising account structure (ad accounts, campaigns, ad sets, ads, and creatives) and its performance data (such as spend, impressions, reach, clicks, click-through rate, cost per thousand impressions, and conversions), and, when you ask us to, we create, change, pause, or resume campaigns, ad sets, ads, and creatives in your own ad accounts. Meta requires more than the advertising permissions to be granted for these use cases, so your connection also includes basic profile information (public_profile), access to the business account that holds your ad accounts (business_management), and read access to the list and engagement data of Pages you manage (pages_show_list and pages_read_engagement). Jenz does not use the Pages permissions: we do not read your Pages, your Facebook or Instagram messages, or your Instagram content. Your Meta access token is held by our integration provider, Composio, rather than stored as a Meta credential in the Jenz database. Carrying out your instructions involves AI: the advertising data described above is sent to the large language models that power Jenz, which read it and produce the analysis, answers, and actions you asked for. Those AI model providers are listed on our sub-processors page (Section 7.1). Meta data is used only to carry out your instructions: it is not sold or shared for third-party advertising purposes (Section 7.5), and it is not used to train AI models unless you have explicitly opted in (Section 5). You can review and remove the apps connected to your Meta account at any time in Meta’s own account settings.
3.5 Data We Do Not Collect
We do not collect:
- Special categories of data under GDPR Article 9 (health, biometric, racial origin, etc.)
- Data about children under 18
- Payment card numbers (handled by our payment processor)
4. Legal Bases for Processing (GDPR Article 6)
| Processing activity | Legal basis |
|---|---|
| Providing the Service to Customers | Contract (Art. 6(1)(b)) |
| Processing Workspace Member data via Slack | Contract (Art. 6(1)(b)), as processor; Customer is the controller |
| Billing and invoicing | Contract + Legal obligation (Art. 6(1)(b) and (c)) |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Product analytics and improvement | Legitimate interests (Art. 6(1)(f)) |
| Sending product updates and marketing to Customers | Legitimate interests (Art. 6(1)(f)) / Consent for direct marketing |
| Compliance with Norwegian or EU law | Legal obligation (Art. 6(1)(c)) |
| Responding to support requests | Contract / Legitimate interests |
Legitimate interests balancing: Where we rely on legitimate interests, we have assessed that our interests are not overridden by your interests or fundamental rights. You may object to processing based on legitimate interests at any time (see Section 9).
5. How We Use Personal Data
We use personal data to:
- Create and manage accounts and Workspaces
- Deliver and operate the Service (agent execution, tool calls, Slack integration)
- Process payments and issue invoices
- Respond to support requests
- Send transactional communications (service notices, security alerts)
- Send product updates and, where permitted, marketing communications
- Monitor for security threats, abuse, and unauthorized access
- Comply with legal obligations (tax, accounting, law enforcement requests)
- Improve the Service through aggregated and anonymized analytics
AI model training: We do not use Customer Data or Workspace Member data to train AI models unless you have explicitly opted in. Prompts sent to the Jenz bot are forwarded to our LLM providers (see Section 7) solely to generate responses.
6. Data Retention
| Category | Retention period |
|---|---|
| Account and Customer data | Duration of Subscription + 90 days, then deleted |
| Workspace Member interaction data | 90 days rolling, unless Customer configures longer retention |
| Billing records and invoices | 5 years (Norwegian Bookkeeping Act, bokføringsloven) |
| Security and access logs | 12 months |
| Support communications | 3 years |
| Anonymized usage analytics | Indefinitely (no personal data) |
You may request early deletion of your personal data at any time (subject to legal retention requirements). See Section 9.
8. International Data Transfers
Jenz AS is based in Norway (EEA). Our primary database is hosted by Railway in Amsterdam, in the EU. Railway Corp. is a United States company. Some of our sub-processors are located in the United States, which does not have a blanket EU adequacy decision.
Data that passes through US-based sub-processors (such as AI inference, application hosting, integrations, and payments) is subject to appropriate safeguards:
- Standard Contractual Clauses (SCCs) adopted by the European Commission, incorporated into our sub-processor agreements
- Adequacy decisions where applicable
Prompt content sent to our AI inference provider is processed transiently and not retained for training (per our agreement). You may request a copy of our transfer safeguards by contacting [email protected].
9. Your Rights Under GDPR
If you are located in the EEA (including Norway), you have the following rights regarding your personal data:
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of personal data we hold about you |
| Rectification (Art. 16) | Correct inaccurate or incomplete personal data |
| Erasure (Art. 17) | Request deletion of your data ("right to be forgotten") |
| Restriction (Art. 18) | Ask us to restrict processing in certain circumstances |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format |
| Object (Art. 21) | Object to processing based on legitimate interests or direct marketing |
| Withdraw consent (Art. 7(3)) | Withdraw any consent given at any time, without affecting prior processing |
| Automated decisions (Art. 22) | Not be subject to solely automated decisions with significant legal effects |
To exercise your rights: Email [email protected] with your name, email, and the specific request. We will respond within 30 days. We may request identity verification before processing sensitive requests.
Workspace Members: Rights requests relating to data processed on behalf of your employer must be directed to your employer (the Customer/data controller). We will assist Customers in fulfilling such requests per our DPA.
10. Right to Lodge a Complaint
You have the right to lodge a complaint with the Norwegian data protection supervisory authority:
Datatilsynet
Postboks 458 Sentrum
0105 Oslo
Norway
www.datatilsynet.no
[email protected]
If you are located in another EEA country, you may also contact your local supervisory authority. We ask that you contact us first so we can address your concern directly.
12. Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Encryption of data at rest and in transit (TLS 1.2+)
- Per-tenant (Workspace) data isolation enforced at the database level
- Encrypted storage of Slack bot tokens and OAuth credentials
- Access controls and audit logging for internal systems
- Regular security reviews
In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals where required under GDPR Articles 33 to 34.
13. Children
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact us at [email protected] and we will delete it promptly.
14. Links to Third-Party Services
The Service integrates with and may link to third-party services (Shopify, Stripe, Gmail, etc.). This policy does not cover those services. Review their privacy policies separately.
15. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify Customers via email at least 30 days before the change takes effect. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated policy.