Zinq
LEGAL / WEBSITE & APP PRIVACY POLICY

Privacy policy.

Current version: Version 0.5 - Sep 07 2026

Zinq Privacy Policy Package

Effective Date: September 3, 2026

Last Updated: September 7, 2026

Publication note: Parts I–VII are public-facing. Part VIII is an internal developer and compliance checklist and should not be published as part of the Privacy Policy.


PART I — GLOBAL PRIVACY POLICY

1. About This Privacy Policy

Zinq is a private-investment visualization, portfolio-management, document-analysis, and workflow platform operated by Pulsehound Ltd., an Israeli company (“Pulsehound,” “Zinq,” “we,” “us,” or “our”).

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit zinq.co, request information or support, create or use an account or workspace under the Free plan or another Zinq plan, upload or import information, connect Gmail or a cloud-storage account, use Zinq’s AI-assisted features, or otherwise interact with us.

Current publicly marketed Zinq plans may include Free, Investor Pro, Club / Fund, and Institutional plans. Each plan may have its own user, document-processing, integration, reporting, workspace, support, and other service limitations as described on zinq.co or in the applicable order, checkout, or workspace notice.

This Policy applies worldwide. Additional terms for the EEA, United Kingdom, California, New Jersey, and Israel appear below. Although technically available worldwide, current marketing is primarily directed to Israel and the United States unless a specific page, campaign, or agreement states otherwise.

2. Who We Are and How to Contact Us

Pulsehound Ltd.<br> 11 Menachem Begin Road<br> Ramat Gan<br> Israel

Privacy contact and Data Protection Officer:
Yair Udi, Chief Executive Officer
Email: privacy@zinq.co
Telephone: +972-74-820-458
Telephone hours: Sunday–Thursday, 9:00 a.m.–4:00 p.m. Israel time

You may use these details to submit a privacy request, complaint, request for international-transfer information, or appeal.

3. Our Roles

3.1 Pulsehound as controller

Pulsehound generally acts as controller for account registration, authentication, security, workspace administration, the public website, plan administration, communications, support, operational analytics, audit records, legal compliance, and business administration.

3.2 Pulsehound as processor or service provider

For customer-controlled workspace content, Pulsehound generally acts as processor, service provider, or contractor on the customer’s instructions. This includes uploaded documents, connected-mailbox content, imported cloud files, portfolio records, cap tables, AI extraction results, tasks, reports, advisor packages, and information concerning founders, investors, beneficial owners, signatories, contacts, and other non-users.

Where Pulsehound acts as processor, the customer determines the underlying purpose and lawful basis. We may refer privacy requests concerning customer-controlled content to that customer.

4. Information We Collect

4.1 Website, signup, and business-contact information

We may collect your name, work email, firm or fund, role, portfolio size, primary use case, telephone number, country, meeting details, communication content, and any additional information you provide.

4.2 Account and profile information

We may collect your name, email, password hash, profile image, organization or workspace, role, permissions, title, telephone number, country, timezone, verification status, suspension or deletion status, and last-login information.

Zinq may support Google, LinkedIn, or Microsoft sign-in. If you use social sign-in, we may collect and store provider account identifiers, verified email status, display name, profile image URL, and token/session records needed to authenticate the account and prevent account takeover. Google sign-in for authentication is separate from Gmail or Google Drive integrations and does not by itself grant Zinq access to Gmail messages, Drive files, or other restricted Google user data. LinkedIn sign-in uses LinkedIn OpenID Connect profile and email information for authentication. We do not store readable passwords; for password-based accounts we store password hashes and security tokens needed for account verification, recovery, and sessions.

4.3 Authentication, device, and security information

We may collect IP address, browser and device information, operating system, user agent, session and token records, login times, failed-login and lockout data, reset and verification records, request identifiers, audit events, and suspected misuse or unauthorized-access information.

The application may use an HTTP-only refresh cookie, browser memory for an access token, and local storage for the current workspace and interface preferences. Zinq may also record limited account-engagement signals, such as login/session timestamps and whether a session lasted more than approximately two minutes, to operate onboarding and customer-success communications.

4.4 Workspace and membership information

We may collect workspace name, slug, logo, plan, including Free, Investor Pro, Club / Fund, Institutional, or other plan status where applicable, currency, timezone, settings, owner, memberships, roles, permissions, invitations, acceptance details, and administrative actions.

Workspace administrators may invite, remove, or suspend users, change permissions, review relevant audit information, and export workspace information. If a user leaves an organization, content contributed to that organization’s workspace may remain with the organization.

4.5 Uploaded and imported documents

Zinq primarily supports PDFs and may support XML and other formats. We may collect the original file, filename, file type and size, uploader, source, hash, storage path, detected document type and date, OCR and extraction status, related portfolio records, and recycle-bin or deletion status.

Documents may contain names, signatures, addresses, emails, telephone numbers, tax or registration identifiers, banking instructions, beneficial ownership, investment amounts, shareholdings, employee or founder information, legal rights, and other confidential information.

You must not upload unnecessary medical records, biometric data, government-identification documents, information about children, or other highly sensitive information. You may upload such information only where strictly necessary for a permitted Zinq function and where you have a lawful right to do so.

4.6 Extracted and derived investment information

Zinq may extract, structure, calculate, or derive document classification, parties, entities, dates, securities, investment amounts, currencies, share counts, prices, valuation and conversion terms, rights, warrants, options, cap tables, ownership, valuations, distributions, performance metrics, warnings, confidence indicators, and user corrections.

Deleting a source document does not automatically delete metrics, portfolio records, transaction records, cap-table data, calculations, or other information previously extracted or committed from it. Those records must be deleted separately.

4.7 Gmail and company-update information

If you connect Gmail, Zinq may access messages available through the authorized Gmail read permissions. The initial scan may cover up to the preceding year, may include archived messages, and excludes spam and trash. Sent mail is not intentionally collected as a separate source. Zinq does not currently offer label or folder restrictions.

Zinq may access message and thread identifiers, sender and recipient addresses and names, subject, date, body, links, attachment metadata, and relevant attachments.

Zinq automatically examines messages to determine whether they are relevant company, investor, financing, or portfolio updates. Messages determined not to be relevant are read transiently for classification and are not intended to be stored as company updates. Operational logs may record errors or aggregate counts, but are not intended to retain complete irrelevant-message content.

For relevant messages, Zinq may store sender and recipient details, subject, date, text or HTML body, links, attachments, detected company, AI summary, extracted metrics and requests, category, matching information, confidence, and model details.

Email addresses may be used to generate workspace-specific Connections Hub information. Other workspace users should not see mailbox bodies through the Connections Hub, but may see derived names, professional email addresses, roles, affiliations, and relationship information.

The user chooses the ongoing synchronization frequency. A user may connect only a mailbox the user is authorized to use.

Disconnecting Gmail stops future access and synchronization and causes stored OAuth credentials to be revoked or deleted where supported. Previously imported portfolio updates and derived Connections Hub records remain until separately deleted. Deleting the original message in Gmail does not delete Zinq’s copy. Where no in-app deletion control is available, deletion may be requested at privacy@zinq.co.

4.8 Cloud-storage and virtual-data-room information

Zinq may support Box, Google Drive, OneDrive, and Dropbox. Some integrations may be limited by account plan, provider availability, workspace settings, or deployment configuration. Box is currently the primary functional bulk VDR importer.

Depending on the provider and user selection, Zinq may collect provider account details, file and folder names and identifiers, selected roots, file metadata, imported files, job status, skipped or forgotten status, duplicate-prevention records, and error information.

Zinq’s intended use is to read and download selected content. It does not intentionally create, modify, move, or delete content in the external service. Box may request root_readwrite because Box requires that permission to download files.

Zinq may retain identifiers and outcomes for skipped or forgotten files to prevent repeated import. Disconnecting a provider stops future access and should revoke or delete OAuth credentials. Imported documents remain until separately deleted.

4.9 Portfolio, company, fund, and transaction information

We may collect or create investment-vehicle, portfolio-company, target-entity, founder, equityholder, incorporation, registration, tax-identifier, sector, geography, website, professional-network, investment, transaction, security, financing-round, valuation, distribution, cap-table, investor, opportunity, scenario, report, advisor, ownership, and performance information.

Information relating to an individual investor, founder, employee, beneficial owner, advisor, trustee, or signatory may be personal information even where the surrounding record relates to a business.

4.10 Tasks, evidence, workflow, and notifications

We may collect task titles and descriptions, owners and assignees, due dates, statuses, comments, outputs, evidence, URLs, files, notifications, related records, and other user-entered information. Users should avoid unnecessary personal or confidential information in free-text fields.

4.11 Connections Hub and professional relationship information

Zinq may create workspace-specific person and relationship records from connected Gmail information, user entries, documents, company information, professional public sources, and enabled providers.

Records may include name, professional email, role, employer or company affiliation, LinkedIn or similar URL, source, connection, and graph metadata. These records are isolated by workspace.

Zinq does not use Connections Hub records to infer sensitive traits, creditworthiness, health, religion, ethnicity, political opinions, sexual orientation, or similar characteristics. Zinq does not contact non-users solely because they appear in customer content. Users may hide or delete Connections Hub records and may request correction at privacy@zinq.co.

4.12 Public and market enrichment

Yahoo Finance may be used for public market and benchmark information. StartupWiki, StartupHub, Growjo, Brave Search, or similar sources may be available only when enabled. Bright Data is not currently confirmed as an active provider.

Enrichment may include company identifiers, websites, professional URLs, prices, indices, stages, sectors, employee estimates, public descriptions, professional roles, source data, retrieval dates, and match-confidence information.

4.13 Support information

Support information may include account and workspace identity, subject, message, priority, status, communication history, technical details, screenshots, attachment metadata, and audit data.

Screenshots can reveal any information displayed on the captured screen. Do not include unnecessary passwords, banking data, government identifiers, medical information, or other sensitive information.

4.14 Analytics, cookies, and browser storage

The public website uses Google Analytics to understand traffic and improve Zinq. Google Analytics may collect browser and device type, approximate location, pages viewed, interactions, referral data, date and time, and cookie or similar identifiers.

The authenticated application uses operational logs and may use Sentry for error monitoring. We have not identified advertising pixels, targeted-advertising tools, or session replay in the application.

4.15 Logs and error information

We may collect HTTP method and path, status, latency, request ID, application events, warnings, errors, stack traces, routes, environment data, workspace or user context, security events, and information incidentally included in an error.

Sentry may receive errors, stack traces, route and environment information, and incidental user or customer context when enabled. We do not promise that all logs are free of personal information.

5. How We Use Information

We use information to:

  • register, authenticate, and administer users and workspaces;
  • store, organize, retrieve, extract, and display documents;
  • create and maintain portfolio, investment, transaction, security, valuation, and capitalization records;
  • calculate portfolio metrics;
  • operate Gmail, cloud-storage, enrichment, Connections Hub, reporting, workflow, and notification features;
  • operate account registration, onboarding, Free plan and paid plan availability, plan limits, billing, checkout, subscription administration, and service availability;
  • communicate invitations, product availability, onboarding messages, lifecycle/product follow-ups, service notices, and support responses;
  • secure Zinq, manage permissions, prevent abuse, and investigate incidents;
  • debug, monitor, and improve reliability;
  • comply with law, enforce agreements, and establish or defend claims; and
  • support a merger, financing, sale, reorganization, or similar transaction.

We do not use customer documents, emails, portfolio records, or AI outputs for generalized model training, prompt testing, model evaluation, fine-tuning, or general product improvement unless the customer gives separate express authorization.

Authorized personnel may access customer content only where reasonably necessary for support, security, debugging, legal compliance, or operation of the service, subject to appropriate confidentiality, access, and logging controls.

6. Legal Bases Where GDPR or UK GDPR Applies

PurposeLegal basis
Account creation, authentication, workspace operation, document and portfolio services, integrations, and supportContract or steps requested before contract
Security, fraud prevention, audit logs, reliability, corporate administration, and claimsLegitimate interests and, where applicable, legal obligation
Requested communications, onboarding, lifecycle/product follow-ups, and marketing communicationsConsent, pre-contractual steps, contract, or legitimate interests where permitted
Non-essential website analytics cookiesConsent where required
Essential service operationsContractual necessity and legitimate interests
Legal and regulatory complianceLegal obligation
Emergency protectionVital interests where applicable
Customer workspace contentCustomer instructions under the customer agreement and DPA
Public professional and company informationLegitimate interests, subject to minimization and rights

You are not generally legally required to provide information, but required fields are necessary to provide the relevant account, feature, or response.

7. Artificial Intelligence

Zinq may use internal extraction, classification, and normalization systems controlled by Pulsehound, and may use an external large-language-model provider for ZinqAI and document-processing features when enabled for the workspace or plan.

The current external LLM provider is OpenAI OpCo, LLC, a Delaware company. The current model or endpoint is GPT 4.1 or a similar OpenAI API model/endpoint. The model, endpoint, or equivalent OpenAI API capability may change to maintain service quality, availability, security, or accuracy.

External LLM processing location and data residency for the current Zinq configuration are United States / USA. All other service processing locations for the current Zinq configuration are United States / USA, except that Pulsehound administration, support, security, and legal personnel may operate from Israel.

Where external AI processing is enabled, the provider may receive complete content or excerpts from documents, emails, attachment text, names, emails, cap tables, financial information, extraction schemas, prompts, and instructions.

Zinq retains information uploaded or synced with Zinq to provide the Services. Zinq does not use customer documents, synced emails, portfolio records, extracted information, or AI outputs for any other purpose unless the customer gives separate express authorization or processing is required for security, debugging, legal compliance, or operation of the Services.

OpenAI states that data sent to the OpenAI API is not used to train or improve OpenAI models unless the customer expressly opts in. See Data controls in the OpenAI platform.

OpenAI applies its default API retention policy unless different account, project, or contractual controls apply. Zinq does not represent that Zero Data Retention or Modified Abuse Monitoring is enabled unless this is confirmed in a separate agreement or notice. See Data controls in the OpenAI platform, OpenAI data residency controls, and the OpenAI Privacy Policy.

Customer content is not used to train generalized Zinq or third-party models without separate express authorization.

AI output is advisory, may be incomplete or inaccurate, and must be reviewed by an authorized user. Zinq does not use AI to autonomously approve investments, execute transactions, extend credit, make employment or insurance decisions, or alter legal rights.

8. How We Disclose Information

We may disclose information to:

  • customers and authorized workspace users;
  • hosting, database, object-storage, queue, email, analytics, monitoring, OAuth, cloud-storage, enrichment, and AI providers;
  • legal, accounting, insurance, security, and other professional advisers;
  • authorities where legally required;
  • parties involved in protecting rights or investigating misuse; and
  • participants in a proposed or completed corporate transaction.

Major providers may include:

Provider or categoryPurpose
Google Cloud Platform / Google Cloud RunHosts application services and Google-managed infrastructure in United States regions
PostgreSQL providerApplication database in a United States region
Redis providerBullMQ queues and background jobs in a United States region where configured
Google Cloud StorageStores uploaded and imported files in a United States bucket or region
GitHub / GitHub ActionsSource control, build, testing, and deployment
SentryError and performance monitoring
ResendTransactional, onboarding, lifecycle/product, and support email when enabled
GoogleAnalytics, sign-in, Gmail, Drive, Google Cloud Storage, and other Google services in United States provider regions where applicable
LinkedInOptional social sign-in through LinkedIn OpenID Connect
MicrosoftSign-in, Mail, and OneDrive when enabled
BoxUser-authorized VDR/file import
DropboxUser-authorized file access when enabled
OpenAI OpCo, LLC, a Delaware companyExternal LLM processing through GPT 4.1 or a similar OpenAI API model/endpoint when enabled
Yahoo FinancePublic market and benchmark information
StartupWiki, StartupHub, Growjo, Brave Search, or similarOptional public/company enrichment
SiteGroundPublic website hosting
GoDaddyDomain registration and related services

Available providers vary by configuration and may change.

We may use and disclose genuinely de-identified or aggregate information where it cannot reasonably identify an individual, customer, fund, portfolio, or confidential transaction. We will not attempt to reidentify it except to test whether de-identification remains effective or as permitted by law.

9. No Sale or Targeted Advertising

Zinq does not sell personal information, exchange it for valuable consideration, share it for cross-context behavioral advertising, use it for targeted advertising based on activity across unrelated services, operate as a data broker, or use sensitive information to infer characteristics for advertising or marketing.

If these practices change, we will update this Policy and implement required choices before beginning them.

10. International Transfers

Pulsehound is located in Israel, and Pulsehound administration, support, security, and legal personnel may operate from Israel.

Zinq’s production application processing location is the United States. Google services used by Zinq, including Google Cloud Storage and any Google-hosted PostgreSQL/Cloud SQL configuration, operate in United States provider regions. External LLM processing with OpenAI uses United States / USA data residency and processing. Other subprocessors or service providers are configured for United States processing where region selection is available, subject to provider limitations, system data, legal requirements, customer/user location, and emergency security processing.

Where required, we use an adequacy decision, European Commission Standard Contractual Clauses, the UK transfer addendum or another approved UK mechanism, Israeli-law contractual assurances, an approved transfer framework, or another lawful mechanism.

You may request information concerning transfer safeguards at privacy@zinq.co.

11. Data Retention

Zinq retains information uploaded or synced with Zinq only as needed to provide, secure, support, maintain, and legally operate the Services, and not for unrelated purposes.

InformationGeneral retention rule
Prospect, signup inquiry, and unsuccessful account/request informationUntil consent is withdrawn or two years after last interaction, subject to a suppression record
Active account and workspace dataWhile active
Closed account dataOrdinarily up to 90 days, except required records and customer-owned contributions
Workspace data after deletionNo post-termination export window; user may export before confirming deletion, after which active content is destroyed subject to exceptions
Documents in recycle binUntil the user permanently clears the recycle bin
Permanently deleted original documentsRemoved promptly from active storage; may remain in backups up to 90 days
Extracted text, AI outputs, and committed portfolio dataWhile active or until separately deleted; source-document deletion does not delete them
Imported Gmail updates and attachmentsWhile active or until deleted through a control or request
Gmail OAuth credentialsRevoked or deleted promptly on disconnect
Disconnected Gmail metadataUp to 12 months for security, audit, and troubleshooting
Import histories and skipped/forgotten file recordsWhile needed, then ordinarily up to 12 months
Tasks, comments, evidence, reports, and notificationsWhile active, then deleted with the workspace subject to exceptions
Audit logsUp to seven years
Login and security logsUp to 24 months
Application and HTTP logsUp to 12 months
Sentry eventsProvider setting, not exceeding 12 months where configurable
Support tickets and screenshotsUp to three years after closure
Marketing, lifecycle-email, and suppression recordsAs long as needed to demonstrate consent, administer product communications, and honor opt-out
Privacy-request recordsUp to five years
Contracts, tax, invoice, and accounting recordsSeven years or longer where required
BackupsOrdinarily overwritten within 90 days, subject to legal hold, security, integrity, or disaster recovery

A customer contract may prescribe a different period for customer content.

12. Deletion and Account Closure

You may delete information using available controls or by contacting privacy@zinq.co. Only a workspace owner or authorized Zinq superadministrator may permanently delete a workspace.

There is no post-termination export period. Before confirming deletion, the user chooses whether to export available data. After confirmation, active customer content is destroyed subject to the recycle bin, separately stored derived records, backups, legal holds, fraud and security needs, legal obligations, and customer ownership of workspace contributions.

Deleting an individual account does not necessarily delete contributions to an organization’s workspace.

13. Security

We use reasonable administrative, technical, and organizational safeguards, including as applicable encryption in transit and at rest, encrypted OAuth credentials and API keys, tenant isolation, role-based access, HTTP-only cookies, login lockouts, audit logs, signed time-limited document links, non-public storage, backups, vulnerability review, incident-response procedures, confidentiality obligations, production-access controls, and deletion procedures.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

14. Your Privacy Rights

Depending on your location and our role, you may have rights to confirmation, access, a copy, correction, deletion, restriction, objection, withdrawal of consent, portability, marketing opt-out, appeal, complaint, and non-discrimination.

These rights are subject to legal exceptions, our processor role, other persons’ rights, privilege, security, fraud prevention, tax and accounting duties, legal claims, and other lawful limits.

Requests

Email privacy@zinq.co or call +972-74-820-458 during the listed hours. Identify the request, account, workspace, and information involved. We normally verify through the authenticated account or registered email and may request additional information where necessary.

The current automated export does not contain every category. Complete requests may be fulfilled manually.

Where we act as processor, we may refer the request to the customer.

Authorized agents

Where applicable, including California, an authorized agent may submit a request with proof of authority. We may verify directly with the individual.

Appeals

Email privacy@zinq.co with the subject “Privacy Appeal.” Describe the original request, decision, and reason for reconsideration. Where reasonably practicable, a person not materially involved in the original decision will review it.

15. Marketing Choices

You may unsubscribe through the communication or by contacting privacy@zinq.co. We may retain a limited suppression record. Product lifecycle and onboarding emails may include messages asking whether you need help, whether Zinq is providing value, or whether you want support with a paid subscription. Opting out of promotional or lifecycle/product messages does not stop necessary service, security, billing, legal, verification, or account communications.

16. Third-Party Services

Third-party services may have independent terms and privacy policies. Where a provider acts as our processor or subprocessor, we select and contract with it as required by law.

17. Children

Zinq is intended only for users aged 18 or older and is not directed to children. Information about a minor may appear incidentally in customer content. Customers must not provide such information unless strictly necessary, lawful, and appropriate.

18. Changes

We may update this Policy and will post the revised version at zinq.co. Material changes will be communicated by an appropriate additional notice, including email or in-app notice where required. Continued use will not be treated as consent where law requires an affirmative choice.

19. Contact

Yair Udi, Chief Executive Officer and Data Protection Officer
Pulsehound Ltd.
11 Menachem Begin Road, Ramat Gan, Israel<br> privacy@zinq.co
+972-74-820-458
Sunday–Thursday, 9:00 a.m.–4:00 p.m. Israel time


PART II — EEA AND UNITED KINGDOM SUPPLEMENT

This supplement applies where the EU GDPR or UK GDPR applies.

1. Controller, processor, and DPO

Pulsehound is controller for its own account, website, support, security, and business activities and processor for customer-controlled workspace content. The DPO is Yair Udi at privacy@zinq.co.

2. EEA and UK representatives

Pulsehound does not currently target the EEA or United Kingdom as a marketing market and presently conducts limited, occasional processing concerning persons there. Pulsehound has not appointed an EEA or UK Article 27 representative on that basis.

If our activities make an Article 27 appointment mandatory, we will appoint the required representative and update this Policy.

3. Transfers

Israel benefits from an EU adequacy decision for relevant transfers. For other transfers, we use Standard Contractual Clauses, an approved UK mechanism, or another lawful safeguard.

4. Rights

You may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and protection from solely automated significant decisions. Zinq does not currently make such decisions.

You may object at any time to direct marketing and may object to legitimate-interest processing based on your circumstances.

5. Complaints

You may complain to the supervisory authority for your residence, work, or the alleged infringement. UK residents may complain to the UK Information Commissioner’s Office.

6. Indirect collection

Where Pulsehound acts as controller and obtains information from documents, connected services, public sources, customers, or other persons, the categories, sources, purposes, recipients, retention, and rights are described in this Policy. Where individual notice would involve disproportionate effort in circumstances permitted by law, this public Policy and appropriate safeguards are used. Where Pulsehound acts as processor, the customer is responsible for transparency.


PART III — CALIFORNIA SUPPLEMENT

Pulsehound currently does not meet the CCPA business thresholds based on its present revenue and volume. We nevertheless voluntarily provide the following rights, subject to verification and exceptions.

1. Categories collected in the preceding 12 months

  • identifiers;
  • customer-record and contact information;
  • commercial and investment information;
  • internet and network activity;
  • approximate geolocation;
  • professional and employment information;
  • financial information;
  • communications;
  • sensitive personal information if supplied in customer content;
  • inferences such as calculations, matching, and relationship metadata; and
  • documents, tasks, screenshots, support records, and AI outputs.

Sources include users, customers, workspace administrators, documents, Gmail, cloud accounts, public and licensed sources, analytics and security technologies, providers, and business communications.

2. Purposes and disclosures

We use and disclose these categories for the purposes and to the recipient categories described in the Global Policy, including service providers and contractors.

3. No sale or sharing

During the preceding 12 months, Zinq has not sold personal information or shared it for cross-context behavioral advertising. Zinq does not knowingly sell or share information of persons under 16.

Because we do not sell or share, we do not currently provide a “Do Not Sell or Share” link. If practices change, we will implement required opt-outs and preference-signal recognition first.

4. Sensitive personal information

Zinq uses sensitive personal information only as reasonably necessary to provide requested services, secure Zinq, comply with law, and perform other permitted purposes. We do not use it to infer characteristics for advertising or marketing.

5. California rights

California residents may request disclosure, access, specific pieces, deletion, correction, portability, opt-out if sale or sharing is introduced, limitation if a limitation right becomes applicable, and non-discrimination.

Submit requests to privacy@zinq.co or +972-74-820-458. Authorized agents are accepted with verification.


PART IV — NEW JERSEY SUPPLEMENT

Pulsehound currently does not meet the NJDPL thresholds. We nevertheless voluntarily provide the following rights, subject to verification and exceptions.

Zinq does not sell personal data, use it for targeted advertising, or conduct profiling in furtherance of legal or similarly significant decisions.

New Jersey consumers may request confirmation, access, correction, deletion, portability, and applicable opt-outs. Submit requests to privacy@zinq.co.

To appeal, email privacy@zinq.co with the subject “Privacy Appeal.” Include the original request, decision date, reason for appeal, and relevant information. If an appeal is denied, we will provide available complaint information as required.


PART V — ISRAEL SUPPLEMENT

Pulsehound Ltd. is the relevant database owner or controller for information processed for its own purposes. Requests may be submitted to privacy@zinq.co.

You are not generally legally required to provide information, but required information is necessary for the relevant account, workspace, feature, or response.

Subject to Israeli law, an individual may request inspection and correction, and deletion where applicable. Processor-side requests may be referred to the customer.

Pulsehound applies reasonable data-security and outsourcing safeguards and will maintain the database documentation, security procedures, access controls, vendor arrangements, and other measures required by the applicable security level and law.

Pulsehound has not registered the Zinq database because registration is not currently considered required. This position must be reassessed if the database’s nature, purpose, sensitivity, source, scale, or use changes.

Information may be transferred from Israel to the United States and other countries. Pulsehound will rely on a lawful ground and obtain appropriate written assurances concerning privacy, security, use, and onward disclosure.

Where Israeli rules for information transferred from the EEA apply, Pulsehound will provide the applicable deletion, retention, accuracy, and notification protections, subject to legal exceptions.


PART VI — COOKIE POLICY

Effective Date: September 3, 2026

The public website uses Google Analytics. Strictly necessary technologies may support authentication, security, session continuity, workspace selection, and interface preferences.

Necessary technologies may include an HTTP-only refresh cookie, access token in browser memory, workspace ID in local storage, and interface preference keys.

Google Analytics may collect browser, device, approximate location, page, interaction, referral, date/time, and identifier information. Where consent is required, Google Analytics must not load until analytics cookies are accepted.

Zinq does not currently use advertising cookies for targeted or cross-context behavioral advertising.

The website must provide a consent interface where required that permits acceptance and rejection of non-essential cookies, category choices, later withdrawal, and applicable universal preference signals.

The live website must maintain an accurate cookie table:

NameProviderCategoryPurposeDuration
Authentication refresh cookieZinqNecessarySecure authenticated sessionConfigured token expiry
Workspace local-storage keyZinqNecessary/preferencesRemembers current workspaceUntil logout, deletion, or browser clearing
Interface preference keysZinqPreferencesRemembers interface settingsUntil deletion or browser clearing
Google Analytics cookiesGoogleAnalyticsWebsite analyticsActual deployed GA4 duration

PART VII — POINT-OF-COLLECTION AND FEATURE NOTICES

A. Account and Plan Signup Notice

Zinq collects your name, work email, firm or fund, role, portfolio size, primary use case, selected plan, and optional information to administer account creation, Free plan and paid plan onboarding, plan availability, user invitations, product communications, service updates, website security, and product operations.

We disclose information to providers used for hosting, analytics, communications, storage, security, and administration. We do not sell it or share it for cross-context behavioral advertising.

We retain prospect, signup inquiry, and unsuccessful account/request information until you withdraw consent or two years after your last interaction, whichever occurs first, subject to a limited suppression record.

By submitting a form or creating an account, you agree to receive Zinq-related account, product, and promotional communications where permitted. You may unsubscribe from promotional communications at any time.

B. Signup Notice

Pulsehound collects account, organization, role, authentication, device, and security information to create and secure your account, administer your workspace, provide features, communicate with you, and comply with law.

Workspace administrators may manage your role and access. Content contributed to an organization’s workspace may remain after your user account is removed.

C. Gmail Connection Notice

By connecting Gmail, you authorize Zinq to read messages available under the requested permissions for up to the preceding year and then at your selected synchronization frequency.

Zinq uses subjects and message content to identify portfolio updates and email addresses to create Connections Hub information. Relevant attachments may be processed. Zinq automatically determines relevance. Irrelevant messages are not intended to be stored as company updates. Spam and trash are excluded; archived messages may be examined.

Derived contact information may be visible to authorized workspace members, but mailbox bodies are not displayed through Connections Hub.

Disconnecting stops future synchronization and revokes or deletes credentials. Previously imported updates and derived connections remain until separately deleted. Deleting a message in Gmail does not delete Zinq’s copy.

Connect only a mailbox you are authorized to use.

D. Cloud-Storage Connection Notice

By connecting a provider, you authorize Zinq to view file/folder information needed for selection and download chosen files.

Zinq’s intended use is read/download only. Box may display broader permission because Box requires it for downloads. Zinq may retain identifiers for skipped or forgotten files to prevent repeat import.

Disconnecting stops future access and revokes or deletes credentials. Imported files remain until separately deleted.

E. External AI Opt-In Notice

Your workspace is enabling an external AI provider. Depending on the workflow, the provider may receive complete content or excerpts from documents, emails, attachments, cap tables, financial records, names, emails, and instructions.

External AI is optional except where a plan or workspace has expressly enabled an external LLM route for ZinqAI or document extraction. Customer content is not used for generalized model training without separate express authorization. Provider retention and use restrictions depend on the applicable provider and configuration.

AI output may be incomplete or inaccurate and must be reviewed.

  • Provider: OpenAI OpCo, LLC, a Delaware company
  • Model/endpoint: GPT 4.1 or a similar OpenAI API model/endpoint
  • LLM processing location: USA
  • Data residency: USA
  • All other services processing location: USA, except Pulsehound administration from Israel and provider/system-data limitations described in this Policy
  • Retention: OpenAI applies its default API retention policy unless different account, project, or contractual controls apply. Zinq does not represent that Zero Data Retention or Modified Abuse Monitoring is enabled unless confirmed separately. See OpenAI data residency controls, the OpenAI Privacy Policy, and Data controls in the OpenAI platform.
  • Training restriction: OpenAI states it does not use API interactions to train its models unless the customer expressly opts in. See Data controls in the OpenAI platform.

F. Upload Warning

Upload only information that is necessary and lawful for investment, portfolio, legal-document, or business-management purposes.

Do not upload unnecessary medical records, biometric data, government-identification documents, information about children, or unrelated sensitive information.

Deleting a document does not automatically delete extracted metrics, portfolio records, cap-table data, or other committed information.

G. Support Screenshot Warning

Screenshots may reveal confidential or personal information. Remove or obscure anything support does not need. Do not include passwords, tokens, government identifiers, banking details, medical information, or unnecessary sensitive data.

H. Privacy-Request Instructions

Email privacy@zinq.co, identify the request, account email and workspace, and describe the information involved. Do not send passwords or unnecessary identity documents. We normally verify through the account or registered email. Customer-controlled requests may be referred to the customer.

I. New Jersey Appeal Notice

Email privacy@zinq.co with the subject “Privacy Appeal.” Include the original request, decision, reason for appeal, and any further information.