GDPR Compliance Statement
Last updated: August 24, 2026
Netsky LLC, doing business as Zenith Analysis (Zenith, we, us, or our), provides financial analysis, due-diligence, reporting, and data-room software to business customers. This statement summarizes how we address the General Data Protection Regulation (GDPR), UK GDPR, and related European data-protection requirements. It supplements our Privacy Policyand does not replace a customer's own compliance obligations.
1. Controller and processor roles
Zenith acts as a controller for personal data we use for our own business purposes, such as website operation, account administration, billing, security, support, and marketing. We act as a processor when a customer submits or connects personal data in accounting records, bank records, documents, data rooms, prompts, or other Customer Data and instructs us to process it through the Service.
When Zenith acts as processor, the customer remains the controller—or a processor acting for another controller—and determines the lawful basis, purposes, and means of processing. Our Data Processing Addendum governs that processing.
2. Legal bases when Zenith is controller
Depending on the context, we rely on:
- Contract: processing needed to create and administer an account, deliver requested services, handle payments, or take requested pre-contract steps.
- Legitimate interests: operating, securing, supporting, and improving a B2B service; preventing fraud; understanding product usage; communicating with business contacts; and establishing or defending legal claims. We consider and balance these interests against individual rights.
- Legal obligation: processing required for tax, accounting, sanctions, regulatory, or lawful-request obligations.
- Consent: processing based on a freely given choice, such as certain non-essential tracking or marketing where consent is required. Consent may be withdrawn at any time without affecting earlier lawful processing.
3. Processing principles
We seek to apply the GDPR principles of:
- lawfulness, fairness, and transparency;
- collection for specified, explicit, and legitimate purposes;
- data minimization and accuracy;
- retention only for as long as reasonably necessary;
- integrity, confidentiality, and risk-appropriate security; and
- accountability through contracts, records, policies, and review.
4. Individual rights
Subject to legal conditions and exceptions, individuals may have the right to:
- access personal data and receive information about its processing;
- correct inaccurate or incomplete personal data;
- request erasure or restriction of processing;
- object to processing based on legitimate interests or for direct marketing;
- receive certain data in a structured, commonly used, machine-readable format;
- withdraw consent where processing relies on consent; and
- lodge a complaint with the supervisory authority in their habitual residence, workplace, or the location of an alleged infringement.
To exercise a right concerning information Zenith controls, email GDPR@zenithanalysis.com. We may need to verify your identity. If the request concerns Customer Data that Zenith processes for a customer, contact that customer first. We will support the customer as required by our DPA.
5. Automated processing and AI
Some optional features use AI to extract information, classify data, generate analysis, or answer user questions. These features produce decision-support output for review by authorized business users. Zenith does not use solely automated processing to make decisions that produce legal or similarly significant effects about individuals on its own behalf. Customers are responsible for evaluating their use of output and providing human review where required.
6. Data protection by design and security
We use measures designed to protect personal data proportionate to risk, including access and permission controls, encrypted transport, encryption at rest where appropriate, protection of designated connection tokens, monitoring, backups, incident-response procedures, personnel confidentiality, and vendor review. We consider privacy and security when designing material new processing activities. No service can eliminate every security risk.
7. Personal data breaches
We maintain procedures to identify, investigate, contain, and remediate suspected incidents. When Zenith acts as processor, we notify the affected customer without undue delay after confirming a personal data breach and provide available information to support the customer's assessment and notification duties. When Zenith acts as controller, we notify authorities and individuals when required by applicable law.
8. Subprocessors
We use vetted providers for services such as hosting, storage, authentication, payments, accounting and bank connections, communications, monitoring, analytics, and optional AI features. We contractually require Subprocessors to protect Customer Personal Data as appropriate to their role and remain responsible for them as required by law. Our DPA includes a current list of principal providers and a process for material changes.
9. International transfers
Zenith is established in the United States, and personal data may be processed in the United States and other countries where we or our providers operate. Where a transfer from the EEA, UK, or Switzerland is not covered by an adequacy decision, we use an applicable transfer mechanism such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, supplemented by technical, contractual, or organizational measures where appropriate. Transfer details are in our DPA.
10. Retention and deletion
We retain personal data based on the purposes for which it was collected, contract terms, customer instructions, sensitivity, legal recordkeeping duties, limitation periods, security needs, and backup cycles. Customers can request export or deletion of Customer Data, subject to law and the Agreement. Our Privacy Policy gives more detail about retention criteria.
11. Data protection assessments and records
We maintain records and documentation appropriate to our role and provide reasonable information to help customers conduct data-protection impact assessments for their use of the Service. Customers remain responsible for determining whether an assessment, consultation, notice, or consent is required for their processing.
12. Contractual protections
Our DPA addresses documented instructions, confidentiality, security, Subprocessors, Data Subject assistance, breach cooperation, audits, return and deletion, U.S. state privacy terms, and international transfers. To request a countersigned DPA or discuss customer-specific requirements, contact us at GDPR@zenithanalysis.com.
13. Contact and complaints
Our privacy contact can be reached at GDPR@zenithanalysis.com. Zenith has not designated an EU or UK establishment through this statement. Where applicable law requires a representative or data protection officer for a particular processing activity, relevant contact details will be provided to affected customers and individuals.
You also have the right to contact your local data-protection authority. EEA authority details are available through the European Data Protection Board, and UK complaints may be directed to the Information Commissioner's Office.