Who is responsible for your information
Zempo is the product name. The company that runs Zempo is responsible for your personal information. Use the contact page for any privacy question or request.
This notice covers the Zempo website, accounts and services. A separate provider, employer or household member may have their own responsibilities for information they collect or share. Their privacy notices apply to their own activities; this does not remove our responsibilities.
Information we collect
We collect information you provide directly, information created when you use the service, and information other authorised people provide about you. Financial records can contain information about other people and sensitive details about your life.
- Account and contact details: your name, email, sign-in credentials or authentication identifiers, preferences and support messages.
- Financial records: statements you upload, extracted transactions, categories and corrections, budgets, goals, investments you record, currencies and reports.
- Shared records: household membership and permissions, invitations, and information an authorised member adds. Workplace features may also involve employer-provided benefit or eligibility information.
- Documents: files and details you choose to add where document features are available. The storage mode and any processing you enable affect what can be accessed.
- Billing records: plan, subscription status and payment-provider references. A payment provider collects the payment details requested in its checkout.
- Technical information: IP address, browser and device information, sign-in and security events, errors and service logs. Optional usage analytics are a separate choice.
Why we use it
We use information to provide the features you request, manage your account and subscription, organise your records, respond to support requests, protect the service and meet legal obligations. Required information is identified at the point of collection; without it, the relevant feature may not work.
Where applicable law permits, account and service processing relies on performing our contract with you; legally required records rely on our legal obligations. Optional analytics and marketing rely on consent where required. Security, fraud prevention and service administration may rely on legitimate interests only where that legal basis is available and the necessary assessment supports it. We do not assume that every jurisdiction recognises the same legal bases.
Statement processing and AI
When you ask Zempo to extract or organise a statement, the relevant file or its contents may be processed by external document-processing or AI services. The result can include transaction descriptions, categories and summaries. Review the result: automated extraction and AI can be wrong.
Do not assume that uploading a document means it stays only on your device, or that all AI processing has zero retention. Provider access, processing location, retention and any use for model improvement must be disclosed for the actual service configuration.
Before we switch on a new AI feature we name the provider, say what is sent to it, check its contract and retention settings, and show you any notice or choice the law requires before the upload or processing begins.
Zempo’s tools are intended to organise information, not decide credit eligibility, insurance cover or other matters with legal or similarly significant effects. Any future use of that kind needs its own assessment and notice.
Households, employers and documents
Sharing a record can make it available to other people according to their role and permissions. Check the intended audience before sharing. Someone who can view a record may retain a copy; removing access cannot recall copies they already made.
Only add information about another person when you have the right to do so. Give them the relevant information about how it will be used. A family relationship or employment relationship alone is not blanket permission.
DocuVault access and storage limits depend on your plan. Private Vault and Smart Storage have different access, processing and recovery requirements. Do not treat Smart Storage as end-to-end encrypted, or assume that Zempo can recover a Private Vault if the required keys or recovery material are lost.
Workplace and document features tell you which records each role can see and what each storage mode does before you enable them. Where an employer or another organisation is responsible for some of the information, we say so at that point.
Will Writer information
If you use the Will Writer, you add details about your family, the people you want to name, what you own and how you want it shared. Some of this is sensitive. A will may reveal religion, health or family circumstances.
We only use this information to build your will inventory and document, keep your drafts and finalised copies, show readiness checks and compare your inventory with the records you keep in Zempo. We do not use it to sell you anything else.
We ask for your explicit consent before recording religion for an Islamic framework. You can withdraw it by deleting the draft. Information about other people in your will, such as executors and beneficiaries, is kept only to prepare your document; only add people you are entitled to name.
Drafts stay while your account is open, or until you delete them. A finalised document is kept so you can download it again, and we keep the record of which template version produced it. After a death, information about the person who has died is no longer personal data about them, but the living people named in the document are still protected.
The document is built from your typed instructions using a fixed template. The optional wording suggestion for an asset description uses an AI model; it sees the asset details you typed, and you choose whether to apply the suggestion.
The AI provider used for wording suggestions is named in the tool when you use the suggestion.
Who may receive information
Information may be shared with people you authorise and providers needed for hosting, storage, authentication, document processing, payments, email delivery, security or support. Optional analytics providers are subject to your choices and applicable law. A provider may act on our instructions or be independently responsible for some processing, such as payment compliance.
We may disclose information when lawfully required, to establish or defend legal claims, or to address fraud and security risks. A business transfer may involve relevant records, subject to applicable law, safeguards and any required notice.
We do not sell your personal information. This does not mean there are no service providers or other lawful disclosures.
We keep a register of the providers we use, what they do for us and where they process information. You can ask for a summary through the contact page.
Where information is processed
Hosting, support or providers may involve processing outside your country. A Dubai address does not mean every record remains in the UAE.
Where information leaves your country we rely on the safeguards the applicable law requires, such as an adequacy decision or approved contract terms. You can ask about those safeguards through the contact page.
How long we keep information
Retention depends on why information is needed: providing your account and records, resolving support requests, securing the service, meeting applicable accounting or legal duties and handling disputes. Information should be deleted or irreversibly anonymised when its purpose and any lawful retention requirement end.
The account-deletion workflow includes a 30-day cancellation window. That is not a promise that every provider record, backup or legally required record disappears after 30 days, and it does not extend statutory deadlines for a privacy request.
Shared household records may need to be separated from your personal account so that deletion does not erase another person’s records without authority. We must explain any information retained and its legal basis, rather than treating shared membership as a blanket refusal of your rights.
Uploaded files, extracted records, provider copies, security logs, billing records, support messages and backups each have their own retention period, set by the purpose they serve and any legal duty to keep them. You can ask through the contact page how long a particular category is kept.
Keeping information safe
Security requires technical and organisational safeguards appropriate to the data and risks. Access controls, secure authentication and encryption have different roles; no system can promise absolute security.
Protect your sign-in and recovery information, use the security options available to you, and tell us if you suspect unauthorised access. Do not send passwords, recovery keys or full financial statements in an ordinary support message.
If a personal-data breach triggers a legal duty to notify you or a regulator, we will follow it. This notice is not a security certification and is not a promise that everything is end-to-end encrypted.
Your choices and rights
Depending on the law that applies, you may have rights to access and obtain a copy of your information; correct it; request deletion or restriction; receive portable data; object to certain processing or direct marketing; and challenge qualifying automated decisions.
Where processing relies on consent, you can withdraw it. Withdrawal does not undo processing that was lawful before withdrawal. Optional cookie choices can be changed without signing in through Cookie preferences.
You may contact us even if you do not have an account. We may need proportionate information to verify your identity or authority. Some requests have lawful exceptions; we must explain any refusal and respond within the applicable legal deadline. You can also complain to the competent data protection authority without first completing our internal complaints process.
Send requests through the contact page. We handle them within the legal deadline. The data protection authority you can complain to depends on the country you are in.
Children’s information
Zempo accounts are intended for adults with legal capacity to enter the service agreement, not for children to use independently. Information about dependants in family or planning records still needs an appropriate legal basis and safeguards. Do not add more than the feature needs.
Contact us if you believe a child has opened an account or that their information has been provided without appropriate authority.
Questions and changes
Use the contact page for a privacy question or request.
Each version of this notice shows its effective date and version number. If we make a material change we will tell you first and, where the law requires it, ask for a new choice or consent. A new version does not change what you agreed to or consented to before it.
Contact Zempo