ZENTARRA APPLICATION
Zentarra application privacy
Information about evaluation accounts, application use and workspace records.
Updated 27 September 2026. Application privacy information remains incomplete.
Scope and responsibility
Gary Cowan operates AICowan, a UK-based independent business that develops and sells Zentarra. Gary Cowan is responsible for AICowan's handling of personal information. For privacy questions or requests about your information, email contact@aicowan.co.uk.
Our business address is listed on the Legal information page.
This page concerns use of the Zentarra application. Visiting the AICowan website, sending an enquiry and submitting a beta application are covered separately by website and enquiry privacy information.
Information processed by Zentarra
Account and access records include user ID, name, email address, authentication provider and Microsoft Entra identifier, workspace membership, roles and permissions, demo start and expiry dates, magic-link requests and expiry, and sign-in activity.
Application records can include submitted questions, saved queries and governed configurations, dashboards, reports, stored results, data-source configuration and encrypted or referenced credentials. Usage records include exports, refreshes, email-delivery activity and feedback. Audit and operational records include timestamps, resource identifiers, status, diagnostic, cancellation and error metadata.
These records support authentication, permissions, analytical features, service delivery, security, governance and troubleshooting. Without the information needed to identify and provision a named user, AICowan may be unable to provide access.
Demo telemetry and support records
Demo and trial telemetry may retain redacted question and feedback text, limited to 2,000 characters. Standard workspaces disable this raw-text telemetry by default. Redaction does not guarantee that all personal information is removed; do not submit confidential customer records or secrets.
Support bundles are designed to omit SQL text, query-result rows, connection strings, credentials, tokens and raw email addresses. This does not establish what every monitoring or provider log contains. Production checks of Application Insights, console logs, authentication and rate-limiting IP records, and any provider-side AI payload logging remain outstanding.
AI use and human review
Zentarra uses AI and deterministic analytics to interpret questions, select governed business definitions, generate or execute analytical plans, and produce results, summaries, recommendations and trust indicators. Questions and relevant analytical context may be processed by Microsoft Azure OpenAI. Outputs may be inaccurate and should be reviewed by an authorised person; a trust indicator is not a guarantee of correctness.
Assessment of actual uses involving profiling or significant automated decisions remains outstanding. No assurance is made here that every customer use avoids decisions with legal or similarly significant effects on individuals. Appropriate usage restrictions, assessments and safeguards must be established before such uses are permitted.
Beta evaluation data
The beta normally runs for 30 days from workspace activation, with dates confirmed in your invitation. Access expires at the end of the agreed period unless extended. Expiry does not automatically delete the workspace, and no automatic post-expiry deletion job is currently implemented. Administrators can delete a workspace manually. That deletion removes workspace-scoped records, including its audit events, but does not automatically delete the user account. Workspace contents may remain stored pending a separate deletion action. Export permitted results before access ends. The period between expiry and deletion, and retention of account and correspondence records, still need to be finalised.
The product has configurable retention controls for mapping traces, semantic changes, audit events and optional artifacts. Operational records can have different retention periods from evaluation workspace content. Product audit defaults are 365 days in standard mode or 90 days in minimal mode while the workspace exists; workspace deletion removes those audit events earlier. Product Log Analytics retention is reported as 30 days. These product settings do not describe marketing-website logs or the Microsoft 365 mailbox. Source-code defaults do not by themselves establish successful deletion; the final notice needs confirmed schedules and deletion evidence for each category.
Database backups
The current Azure SQL configuration has seven days of point-in-time backup retention, with weekly, monthly and yearly long-term retention disabled. Deleted database information may remain in existing backup copies until those copies expire under the backup schedule. This is not a promise that every copy held by every service is erased within seven days; email, monitoring and other records have separate retention arrangements.
Application service providers and locations
The current production configuration reported by AICowan uses Microsoft Azure OpenAI in UK South, with GPT-4.1, GPT-4o and GPT-4o-mini deployments. Authentication uses Microsoft Entra ID. Product-generated transactional email uses Azure Communication Services Email with an Azure-managed sender domain; the separate contact@aicowan.co.uk corporate enquiry mailbox is hosted by Microsoft 365.
The application backend, Azure SQL database, storage queue, container registry and Application Insights/Log Analytics resources are reported in UK South. The application frontend and Admin Portal use Azure Static Web Apps resources reported in West Europe.
Resource regions do not prove that all processing stays in those locations. Azure OpenAI data-handling settings, email processing/storage arrangements, Microsoft contractual terms, relevant subprocessors and any applicable international-transfer safeguards still need verification.
Lawful bases and remaining privacy work
Product data flows, Azure providers and core retention defaults have been identified. Final production log verification, purpose-specific lawful bases and any legitimate-interests assessments, live retention settings and successful purge evidence, processor and transfer documentation, and automated-decision assessments remain outstanding.
Privacy and terms links at sign-in, magic-link requests, onboarding and other relevant collection points also remain to be implemented and verified in the application. Publishing this page does not establish that those collection points provide it.
The completed notice must be available before the relevant personal information is collected. Proposed policies and retention defaults are not evidence of adopted policies or successful production deletion. Website visits, email enquiries and website beta applications have a separate privacy page.
Your data-protection rights
Depending on the circumstances and the lawful basis used, you may have the right to:
- Access your personal information and obtain a copy.
- Have inaccurate information corrected or incomplete information completed.
- Request deletion or restriction where the relevant conditions apply.
- Object to processing based on legitimate interests, and object to direct marketing.
- Receive certain information in a portable format where that right applies.
- Withdraw consent where processing relies on consent, without affecting the lawfulness of earlier processing.
These rights are not absolute. If a request cannot be fulfilled in full, you can ask for an explanation.
Requests and complaints
Email contact@aicowan.co.uk with enough detail to identify the information and your request. Relevant identity checks may be needed to protect your information; do not send identity documents unless requested through an appropriate route.
Rights requests are normally handled without a fee and within one month, subject to the applicable rules on identity checks, clarification and extensions. Read the ICO's explanation of response times.
Raise concerns with Gary using the same email address. You also have the right to complain to the Information Commissioner's Office.
Changes to this information
The date on this page identifies its latest revision. Changes in how the service handles information need to be reflected in the notice and communicated where required.
