Privacy Policy

How Zambra handles personal data: what we store, where, why, who we share it with, and how to stop it.

Version of

1. Who processes the data

Zambra is operated by MB Verslo botas, company code 306997072, registered at Perkūnkiemio g. 19, LT-12120 Vilnius, Lietuva. You can reach us at privacy@zambra.io.

There are two roles here and the difference matters. For the account data of the user — name, email, sign-in — we are the data controller. For the data a user enters about their own clients, guests and suppliers, the user is the controller and we act as a processor on their instructions (Article 28 GDPR). The purpose and scope of that processing is set by them, not by us.

2. Whose data ends up in the service

Three groups of people appear in the product, and they arrive very differently:

  • The user — a wedding host, DJ, photographer, agency or their employee. They sign up themselves and enter the data themselves.
  • The user's client — the couple or company that booked the event. Their data is entered by the user in the course of their work.
  • The event guest — someone invited to another person’s celebration. A guest never gave us anything about themselves and never registered with us.

That last point deserves to be said plainly: a guest has no contract with us and usually does not know the service exists at all. Today the system mostly holds the number of guests at an event. If a user records a guest as a contact, that record follows the same rules as any other contact, and the user remains the controller — a guest’s request goes to them first. We will help carry it out.

3. What we store

Account and sign-in: name, email address, a hash of the password (we never store the password itself and cannot recover it), interface language, organisation membership and role, and session records — sign-in time, expiry and the browser string.

Working data entered by the user:

  • contacts: name, preferred language, contact channels — phone, email, messenger and social accounts, notes about the person;
  • events and dates: date and part of day, event type, venue and its time zone, guest count, free-form notes;
  • money: payment amounts with their currency, purpose and status — expected or received;
  • suppliers and venues, including the user’s private ratings of them;
  • an activity log — what changed and when, used to resolve disputes.

We do not collect or ask for special categories of data: health, religion, political views, biometrics. If a user types something of that kind into a free-form note, that remains their responsibility as controller.

4. Why we process it

To deliver the service itself: the calendar of booked dates, event records, contacts and settlements. To let the user into their account and keep everyone else out. To investigate faults and abuse. To answer enquiries.

We do not sell data, do not share it with advertising networks, and do not use the content of a user’s working data to train models.

5. Legal bases

  • Performance of a contract with the user — Article 6(1)(b) GDPR: without processing their data the service cannot work.
  • Legitimate interest — Article 6(1)(f): service security, protection against unauthorised access, the activity log.
  • For data about clients and guests, the basis is determined by the user as controller; we process it on their instructions.
  • Consent — where we collect it separately. Consent can be withdrawn at any time.

We store the language in which consent was given together with the consent itself. Consent given in Lithuanian has to be shown back in Lithuanian, otherwise it cannot be evidenced.

6. Where the data lives

Everything is stored in the European Union: a Hetzner Online GmbH server in Falkenstein, Deutschland. The database, the application files and the backups are all there. There are no copies outside the EU.

This is a requirement, not a preference: personal data of EU residents — including guests who never registered with us — stays in the EU.

DNS records are hosted by Cloudflare, but proxying traffic through their network is deliberately switched off: connections go straight to our server in Germany and are decrypted only there.

The single transfer outside the EU is described in section 8.

7. Voice notes

Dictation is a primary way to enter data in this product, so we describe what happens to a recording in detail.

Recordings are transcribed on our own server in the EU by our own speech service (a Whisper model). The audio is not sent to Google, Apple or any other external speech-recognition service, and it does not leave the EU.

The audio file exists only for the duration of the transcription and is deleted immediately afterwards — what remains in the database is the transcribed text, not the sound. We keep no archive of voice notes.

8. Text parsing by a model, and transfer outside the EEA

To turn a note into event fields — date, client, venue, amount — the text of the note is sent to Anthropic PBC (United States), the Claude model. This is the only case in which data leaves the service, and we name it here rather than burying it in a list of vendors.

  • What is sent: the text of the note exactly as the user typed or dictated it. It may contain names, phone numbers, venue names and amounts.
  • What is not sent: the audio recording, passwords, the contents of the database, other users’ data.
  • When: only on a user action — when they press “parse”. Nothing is sent in the background.
  • Why: to extract structure from free-form text. The result is shown to the user for review and written to the database only after they confirm it.

The transfer is made under our agreement with Anthropic, which incorporates the European Commission’s Standard Contractual Clauses (SCC) for transfers to third countries.

9. How long we keep it

  • Account and organisation data — for as long as the account exists, and up to 30 days after a deletion request.
  • Sign-in session — 30 days, after which it expires by itself.
  • Deleted records are first marked as deleted and stop being shown; on request they are purged for good.
  • Backups are kept for 14 days and then overwritten in rotation, so deleted data disappears from backups within 14 days at the latest.
  • Audio recordings are not kept at all — see section 7.

10. Your rights

Under the GDPR you may request access to your data, correction of inaccurate data, erasure, restriction of processing, portability in a machine-readable format, objection to processing based on legitimate interest, and withdrawal of consent previously given.

Send the request to privacy@zambra.io. We answer within 30 days at the latest. If the data was entered by a service provider who is the controller, we will forward the request to them and carry out the technical side.

If our answer does not satisfy you, you may complain to the supervisory authority — the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt) — or to the authority of your own EU country.

11. Cookies

We set one technical cookie: the session identifier, without which staying signed in is impossible. It holds a random token, not personal data, and only a hash of that token is stored in the database.

There is no analytics, no advertising pixels and no third-party trackers in the service.

12. Security

Passwords are stored as hashes. Connections are HTTPS only. The database is not exposed to the internet and is reachable only by the application. The server sits behind a firewall and installs security updates automatically. Backups run daily and fail loudly if they come out empty.

No protection is absolute. If an incident poses a risk to people’s rights and freedoms, we will notify the supervisory authority and the affected users within the deadlines set by the GDPR.

13. Changes

This policy will change as the product develops. The current version is dated 2026-08-12. We will notify users of material changes before they take effect.

14. Contact

MB Verslo botas, Perkūnkiemio g. 19, LT-12120 Vilnius, Lietuva. Email: privacy@zambra.io. No separate Data Protection Officer has been appointed: the scale of processing does not require one under Article 37 GDPR. Enquiries are read by the company directly.