Privacy policy.
What we collect, why we collect it, and the control you keep over it, written to GDPR standards and applied across every market we serve.
Last updated July 2026
1. Data controller
Zula.One is operated by ZulaOne OÜ, a company established and registered in Estonia (European Union), with its global operations centre in Maryland, United States, and regional offices across the European Union and the MENA region.
For EU and EEA users, ZulaOne OÜ acts as data controller. Regional offices in the EU and MENA process data under the same standard.
2. What we collect
Account and contact details, business and catalogue information, transaction and fulfilment records, device and usage data, and communications you send us.
Early access submissions collect your user type, your name or business, brand or organisation name, and your email address so we can notify you at launch. These submissions are routed to our early access team at crm@zula.one.
3. Why we use it
To operate your workspace, produce the intelligence and benchmarks you rely on, detect fraud and abuse, meet legal obligations, and notify you about the service and your early access benefits.
4. Legal bases
Performance of a contract, legitimate interests in operating and securing the network, consent where you opt in to partner sharing or marketing, and compliance with legal obligations.
6. AI and automated processing
We use your trade, catalogue and usage data to generate scores, benchmarks and recommendations, including the Commerce Intelligence Score, that help you understand your own business. This processing relies on our legitimate interest in providing the service, or your consent where required.
We do not use fully automated processing to make a decision that produces a legal or similarly significant effect on you without offering a path to human review. If you believe an automated output about your business is materially wrong, you can request a review at compliance@zula.one.
7. International transfers
Data may be processed in the EU, the United States and regional MENA locations. Transfers rely on adequacy decisions or standard contractual clauses with supplementary safeguards.
8. Retention and security
We keep records for as long as your account is active and for the periods required by tax, accounting and anti-fraud law, after which data is deleted or anonymised. Data is encrypted in transit and at rest, with role-based access control and regular access review.
9. Children's privacy
Zula.One is a business-to-business platform and is not directed at, or intended for use by, individuals under eighteen. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact compliance@zula.one and we will remove it.
10. Marketing communications
We send early access and product updates to the email address you provide, based on your consent or our legitimate interest in keeping registered businesses informed. Every marketing message includes a way to opt out, and opting out never affects your access to the service itself.
11. Data breach notification
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within the timeframe required by law and inform affected users without undue delay where the risk is high.
12. Your rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time. You may also lodge a complaint with your supervisory authority, including the Estonian Data Protection Inspectorate.
13. Changes to this policy
We may update this policy as our practices or the law change. Material changes will be communicated through the platform or by email before they take effect.
14. Contact
compliance@zula.one. ZulaOne OÜ, Estonia. Global operations centre: Maryland, United States.
