GDPR Privacy Notice — ZAHN
Legal

GDPR Privacy Notice

ZAHN Management UK Ltd  ·  Effective 15 January 2026

This Notice explains how ZAHN Management UK Ltd collects, uses, stores, shares, and protects personal data in accordance with the UK GDPR and EU GDPR. It supplements our general Privacy Policy and applies specifically to personal data processed through the ZAHN app and associated services.

Download full notice (PDF)
1
Data controller information

ZAHN Management UK Ltd is the data controller responsible for the processing of your personal data.

ZAHN Management UK Ltd
3rd Floor, 1 Ashley Road, Altrincham, Cheshire, WA14 2DT, United Kingdom
Email: legal@zahnapp.com
ICO Registration Number: [ICO REGISTRATION NUMBER]

Data Protection Officer (DPO)

[Insert DPO status here — either confirm appointment or state that a DPO is not mandatory and name the privacy lead contact.]

EU Representative

ZAHN is a UK-based organisation. Where we offer services to individuals in the EU/EEA, we are assessing our obligations under Article 27 EU GDPR regarding the appointment of an EU representative. We will update this Notice when an EU representative is appointed. In the meantime, EU/EEA users may contact us directly at legal@zahnapp.com.

2
Categories of personal data we process

We may collect and process the following categories of personal data:

CategoryExamples
Identity DataName, profile photo, username
Contact DataEmail address, phone number
Location DataReal-time GPS location, background location, Saved Spots, check-in data
Device DataDevice model, operating system, app version, language settings
Account DataLogin credentials, feature preferences, account settings
Technical DataCrash logs, app performance metrics, usage diagnostics
Communications DataSupport messages, feedback, and enquiries submitted to us
3
Legal bases for processing Key section

We process personal data under the following lawful bases under UK GDPR Article 6:

Legal BasisWhen We Rely On It
Consent Art. 6(1)(a)Precise and background location data; push notifications; optional safety features
Performance of a contract Art. 6(1)(b)Creating and operating your ZAHN account; providing core app functionality
Legitimate interests Art. 6(1)(f)Platform security; fraud prevention; app performance monitoring; service improvement
Legal obligation Art. 6(1)(c)Compliance with applicable laws and regulatory requirements

Where processing is based on consent, you may withdraw it at any time through your device settings or in-app controls. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

4
Purposes of processing

We use personal data to:

  • Operate and maintain the ZAHN app and related services
  • Provide real-time, location-based safety features including live sharing, Ghosting, Saved Spots, and check-ins
  • Personalise user experience and app content
  • Send safety alerts, notifications, and service communications
  • Monitor system performance and detect technical issues
  • Prevent fraud, misuse, and unauthorised access
  • Comply with legal and regulatory obligations
5
Automated decision-making and profiling

ZAHN does not carry out fully automated decision-making that produces legal or similarly significant effects on users, as described in Article 22 UK GDPR.

We may carry out limited, non-significant profiling to improve service functionality — for example, analysing aggregated location patterns to improve Saved Spots suggestions. This profiling does not produce legal effects, does not result in any decision being made about individual users, and cannot be used to identify you personally. Contact us at legal@zahnapp.com if you have questions about how profiling affects you.

6
Recipients of personal data

We may share personal data with trusted third-party service providers who act as data processors on our behalf, including providers of:

  • Authentication and database services
  • Cloud hosting and infrastructure
  • Push notification delivery
  • Analytics and performance monitoring
  • Customer support tooling

All third-party processors are subject to contractual data protection obligations in accordance with Article 28 UK GDPR. We do not sell personal data and do not share it for advertising or marketing purposes.

7
International data transfers

Personal data may be transferred outside the UK, EU, or EEA, including to the United States, where some of our third-party service providers are based. Where such transfers occur, we rely on:

  • UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs)
  • Data Processing Agreements (DPAs) with all relevant processors
  • Vendor security assessments and ongoing due diligence

An up-to-date list of key processors is available on request by contacting legal@zahnapp.com.

8
Data retention

ZAHN retains personal data only for as long as necessary to fulfil the purposes for which it was collected, in accordance with Article 5(1)(e) UK GDPR.

8.1 Active accounts

Personal data is retained for the duration that a user maintains an active account in order to provide core app functionality, maintain account security, enable safety features, and respond to support enquiries.

8.2 Account deletion and post-deletion retention

Upon account deletion or a valid erasure request, personal data is deleted or anonymised without undue delay. Certain data may be retained for up to 30 days where necessary to:

  • Comply with legal or regulatory obligations
  • Prevent fraud or misuse
  • Establish, exercise, or defend legal claims
  • Maintain system integrity

After this period, data is securely deleted or irreversibly anonymised unless a longer retention period is required by law.

8.3 Anonymised and aggregated data

Anonymised or aggregated data that can no longer identify individuals may be retained indefinitely for analytics, research, app performance improvement, and safety trend analysis. Such data cannot be used to re-identify users.

9
Your GDPR rights Key section

You have the following rights under UK GDPR and EU GDPR. To exercise any of these rights, contact us at legal@zahnapp.com. We will respond within one month. Identity verification may be required.

RightWhat It Means
Right of access Art. 15Request a copy of the personal data we hold about you
Right to rectification Art. 16Request correction of inaccurate or incomplete data
Right to erasure Art. 17Request deletion of your data, subject to legal limitations
Right to restrict processing Art. 18Ask us to limit how we use your data in certain circumstances
Right to object Art. 21Object to processing based on legitimate interests
Right to data portability Art. 20Receive your data in a structured, machine-readable format
Right to withdraw consent Art. 7(3)Withdraw consent at any time without affecting prior processing
Right to lodge a complaintContact the ICO at ico.org.uk or 0303 123 1113
10
Data security

ZAHN implements appropriate technical and organisational measures to protect personal data in accordance with Article 32 UK GDPR.

Technical measures
  • TLS encryption for data in transit
  • Secure authentication and access controls
  • Role-based access control (least privilege)
  • Server-side validation and database security rules
  • Secure cloud infrastructure with monitoring and firewalls
Organisational measures
  • Internal access and confidentiality policies
  • Data minimisation practices
  • Regular system and dependency reviews
  • Vulnerability monitoring, testing, and timely security updates

No system is entirely secure. Users are responsible for protecting their login credentials and notifying us promptly of any suspected unauthorised access.

11
Children's data

ZAHN is not intended for children under the age of 13 in the United Kingdom, or below the applicable age of digital consent in other jurisdictions (up to 16 in certain EU member states). We do not knowingly collect or process personal data relating to children. If we become aware that personal data of a child has been collected without appropriate consent, we will take steps to delete it promptly and disable the associated account.

12
Personal data breaches

In the event of a personal data breach, ZAHN will assess the risk to individuals and, where required under Articles 33 and 34 UK GDPR, notify the Information Commissioner's Office (ICO) within 72 hours and affected individuals without undue delay. We maintain an internal breach register and incident response procedures to support this obligation.

13
Updates to this notice

We may update this GDPR Privacy Notice from time to time. Material changes will be communicated via the App or our website. The effective date at the top of this Notice will be updated accordingly.

14
Contact us

If you have any questions, concerns, or complaints regarding this Notice or our data protection practices, please get in touch:

ZAHN Management UK Ltd, 3rd Floor, 1 Ashley Road, Altrincham, Cheshire, WA14 2DT, United Kingdom
ICO Registration Number: [ICO REGISTRATION NUMBER]
You also have the right to complain to the ICO at any time: ico.org.uk  ·  0303 123 1113