GDPR — Personal data protection

Zena GDPR policy — how we protect personal data under GDPR principles and applicable law.

1. Introduction

Zena is committed to protecting privacy and personal data under GDPR principles and applicable data-protection laws.

By accessing or using Zena, you confirm that you have read and agree to this Policy.

2. Data we collect

Identity data, account data (encrypted passwords), payment/transfer history (card data is not stored when paid via gateways), and technical/cookie data.

3–4. Purposes & legal bases

Account management, payments, matching customers and providers, support/disputes, service improvement, fraud prevention and legal compliance.

Bases: consent, contract performance, legal obligation and legitimate interests (security, fraud prevention, operations).

5. GDPR rights

Access, rectification, erasure (“right to be forgotten”), restriction, objection, portability and withdrawal of consent.

Email cskh@zenavietnam.com. Zena aims to respond within 30 business days or as required by law.

6–10. Retention, sharing, security, cookies & updates

Data is kept while accounts are active or as required by law, then deleted or anonymized.

Sharing may include payment partners, technical providers, service providers for bookings, and authorities when legally required. Zena does not sell personal data.

Safeguards include SSL, server security, access controls and monitoring. Cookies support login, analytics and UX.

This Policy may be updated; the latest version is effective when published on the website.