This Privacy Policy explains how Software Programming Group LLC ("Provider," "we," "us," or "our") processes personal information in connection with GenZ OS including its website, hosted platform, applications, APIs, AI-assisted development functions, integrations, demonstrations, sales, support, and related services (collectively, the "Service").
Scope and Roles
This Policy applies to website visitors, prospects, customers, account administrators, Authorized Users, billing and support contacts, event or demonstration participants, integration users, and individuals who contact Provider or exercise privacy rights.
When a Customer determines why and how personal information is submitted to or processed through a workspace, the Customer ordinarily acts as controller, business, data fiduciary, or comparable principal, and Provider ordinarily acts as processor, service provider, contractor, or data processor. Individuals should usually direct requests concerning Customer-controlled project data to the relevant Customer. Provider may assist that Customer as required by law or contract.
Provider acts independently for account administration, billing, sales, Provider-controlled marketing, security and abuse prevention, service analytics, legal compliance, and management of its business.
Information We May Process
Identity and contact information: name, business email, telephone number, job title, employer, department, profile, and internal identifiers.
Account and authentication information: username, hashed credentials, single sign-on identifiers, roles, permissions, workspace membership, account status, authentication events, and security settings.
Project and requirements information: business ideas, stakeholder input, master input documents, BRDs, FRDs, SRS materials, user stories, tasks, comments, approvals, requirements, and traceability records.
Files, images, and source material: uploaded documents, images, wireframes, source code, schemas, datasets, configuration files, and metadata.
AI interaction information: prompts, instructions, retrieved project context, model selections, generated code, architecture, documentation, tests, prototypes, feedback, evaluation data, and usage metadata.
Development and repository information: repository identifiers, branches, commits, push events, code exports, integration settings, tokens or credentials handled through supported secret mechanisms, and GitHub or Bitbucket connection metadata.
Collaboration and governance information: team membership, roles, permissions, edits, comments, project activity, approvals, version or reversion events, and audit records.
Device, network, and technical information: IP address, browser, operating system, device and session identifiers, time zone, language, API events, logs, error reports, performance data, diagnostic data, and security telemetry.
Commercial information: plans, Order Forms, billing contacts, invoices, payment status, tax information, procurement records, and limited payment information received from payment providers.
Support, sales, and feedback information: inquiries, demonstrations, tickets, attachments, call or meeting notes, training records, surveys, and product feedback.
Website and cookie information: cookie identifiers, consent choices, page views, referring pages, campaign parameters, approximate location inferred from IP address, and interactions described in the Cookie Policy.
The standard Service is not designed to require Social Security numbers, national identifiers, payment-card numbers, protected health information, biometric templates, precise geolocation, children's data, export-controlled technical data, credentials, private keys, or other highly sensitive information. Customers should not submit such information unless the use is expressly supported, lawfully authorized, covered by appropriate contract terms, and protected by suitable technical and organizational measures.
Sources and Purposes
We may obtain information directly from users and Customers; from account administrators; through use of the Service; from Customer-selected repositories, identity providers, AI providers, APIs, or other integrations; from payment, support, security, analytics, and hosting providers; from public business sources; and from affiliates, partners, or event organizers where lawful.
We may process information to provide and support accounts, projects, collaboration, generation, preview, export, and integrations; route prompts to selected models; authenticate users; manage permissions; secure systems; prevent fraud and abuse; process orders and billing; diagnose errors; measure feature use; improve the Service; respond to inquiries and rights requests; send permitted marketing; comply with law; and establish or defend legal claims.
AI Models and Automated Processing
GenZos.ai may provide access to multiple third-party or Provider-managed AI models. Depending on Customer selection and deployment, prompts, files, code, project context, and related metadata may be transmitted to an AI provider or model-hosting service to generate Output. Model providers may apply distinct technical limits and contractual data-handling rules.
Unless an Order Form or clear in-product notice expressly states otherwise, Provider does not use Customer Content to train a third-party general-purpose model. Provider may use feedback and de-identified or aggregated operational information to improve routing, safety, quality, and performance. Customer should not assume that a model or Output is confidential, accurate, exclusive, or suitable for a consequential decision without appropriate configuration, contract terms, and review.
The Service may automate generation, classification, summarization, testing, or recommendations. Provider does not use the standard Service, on its own behalf, to make employment, credit, housing, insurance, medical, legal, educational-admission, or other decisions that produce legal or similarly significant effects on individuals. Customers are responsible for notices, lawful authority, impact assessments, human review, contestability, and other obligations arising from their deployments.
Legal Bases
Where applicable law requires a legal basis, processing may rely on performance of a contract or steps requested before contract; legitimate interests in providing, securing, supporting, and improving a business Service; compliance with legal obligations; consent; protection of vital interests; and establishment or defense of legal claims. A person may withdraw consent where processing relies on consent, without affecting prior lawful processing.
Disclosures
We may disclose information to affiliates and personnel; hosting, infrastructure, security, authentication, communications, support, analytics, billing, and professional-service providers; AI model, model-hosting, and evaluation providers; Customer-selected repositories, APIs, identity providers, and integrations; Customer administrators and Authorized Users; professional advisers; authorities or other parties where required by law or necessary to protect rights and safety; and participants in a corporate transaction subject to appropriate safeguards.
Provider does not sell personal information for money. If a website advertising or analytics disclosure is considered a "sale," "sharing," or targeted advertising under applicable law, Provider will provide the required notice and opt-out mechanism, including recognition of an applicable browser-based opt-out signal.
International Processing and Transfers
Provider and its service providers may process information in the United States, India, and other countries where Provider, a Customer, an enabled AI model, or a service provider operates. Laws in those places may differ from those in an individual's location.
Where required, Provider uses a recognized transfer mechanism, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or International Data Transfer Agreement, adequacy regulations or decisions, or another lawful safeguard. The Data Processing Addendum provides additional terms for Customer Personal Data.
Retention
Retention depends on the type of information, Customer configuration, deployment model, contract, legal obligations, security needs, and whether the information is Provider-controlled or Customer-controlled.
Customer Content is retained according to Customer settings and contract terms, then returned, deleted, or de-identified subject to backup cycles, legal holds, and law.
Account, billing, tax, contract, security, audit, consent, and support records may be retained after closure for compliance, fraud prevention, dispute resolution, and legitimate business needs.
Prompts, Output, logs, repository events, and model-routing metadata follow the applicable feature, plan, or enterprise configuration.
Cookie and consent records follow the Cookie Policy and displayed settings.
De-identified or aggregated information that cannot reasonably identify an individual may be retained for lawful business purposes.
Customer administrators are responsible for exporting and deleting project data as needed and for setting retention rules appropriate to Customer's legal obligations.
Security
Provider uses reasonable technical and organizational measures designed to protect information, which may include access controls, authentication, encryption in transit and at rest where appropriate, environment separation, logging, monitoring, backups, incident response, vendor review, secure development practices, and personnel confidentiality. Controls vary by plan, integration, and customer-managed or provider-managed deployment. No transmission or storage method is completely secure.
Privacy Rights and Choices
Subject to applicable law, role, verification, and exceptions, an individual may have the right to request access, confirmation, correction, deletion, portability, restriction, objection, withdrawal of consent, information about categories and recipients, or review of certain automated decisions. An individual may also have the right to opt out of sale, sharing, targeted advertising, profiling for significant decisions, or Provider-controlled marketing, and to appeal a denied request where required.
Requests about Customer Content should normally be directed to the relevant Customer. Requests about Provider-controlled information may be sent to privacy@genzos.ai. Provider may request information reasonably necessary to verify identity, authority, account, and jurisdiction. Authorized agents must provide legally sufficient authority.
Where technically applicable and required, Provider recognizes Global Privacy Control or another legally recognized browser-based opt-out signal for the browser and device from which it is received.
Individuals in the EEA, United Kingdom, or Switzerland may have the right to complain to a competent supervisory authority. Individuals in India may use the grievance process and, where applicable and in force, available statutory channels. U.S. residents may contact their state privacy regulator or attorney general as applicable.
Marketing, Children, and Third Parties
Provider-controlled marketing emails may be stopped using the unsubscribe link or by contacting us. Essential service, security, legal, billing, and transaction messages may continue. Customer-directed messages created through a Customer deployment are controlled by that Customer.
The Service is intended for organizations and adult business users. Provider does not knowingly offer accounts directly to individuals under 18 through the standard Service. Customers must not use the Service to process children's personal information unless the use is expressly supported, lawfully authorized, and subject to required parental consent and appropriate safeguards.
Third-party websites, repositories, models, and integrations are governed by their own terms and privacy notices for independent processing. Enabling an integration authorizes the exchanges necessary to operate it. Provider is not responsible for an independent third party's practices.
Changes and Contact
We may update this Policy to reflect legal, product, vendor, or operational changes. We will revise the last-updated date and provide additional notice where required. A material change will not retroactively reduce legally protected rights or expand consent-based processing without a valid legal basis.
Privacy questions, rights requests, appeals, or grievances may be sent to privacy@genzos.ai with the subject "GenZos.ai Privacy Request." Please identify your relationship to the relevant Customer, if any.
Provider: Software Programming Group LLC
Postal address: 5 Independence Way, Suite 300, Princeton, New Jersey 08540, United States
Telephone: +1 732-343-7688
Privacy email: privacy@genzos.ai
General support: support@genzos.ai