Skip to content
Effective date: 25/08/2026

Privacy Policy for ZentraSnap

Introduction

ZentraSnap (“we”, “us”, “our”) operates the ZentraSnap application, a business-to-business document extraction service designed primarily for accountants, bookkeepers and other business users.

ZentraSnap processes financial documents using different technical pipelines depending on the type of document submitted. Bank statements are processed using ZentraSnap's own document-extraction technology running on cloud computing infrastructure, while invoices and receipts are processed using the Google Gemini API.

Because these documents may contain personal and confidential financial information, we seek to minimise the amount of data retained, restrict access to processing infrastructure and use service providers that provide appropriate security and data-protection safeguards.

1. Who We Are

ZentraSnap is operated by Cristin Griu, trading as ZentraSnap, operating in Celbridge, Co. Kildare, Ireland.

For questions concerning this Privacy Policy, data protection or our security practices, contact:

Cristin Griu

Trading as ZentraSnap

Celbridge, Co. Kildare, Ireland

cristingriu25@gmail.com

2. Data Protection Roles and Customer Responsibilities

Account and Business Data

ZentraSnap acts as a Data Controller in relation to personal information used to create and administer your ZentraSnap account, manage subscriptions, provide customer support, secure the service and operate our business.

Client Financial Data

Where you submit bank statements, invoices, receipts or other financial documents relating to your clients or other third parties, you or the organisation on whose behalf you use ZentraSnap normally determines why that data is being processed.

In those circumstances, ZentraSnap acts as a Data Processor, or where appropriate a sub-processor, and processes the financial document data only for the purpose of providing the ZentraSnap service and in accordance with the customer's instructions and our Data Processing Agreement.

You are responsible for ensuring that you have an appropriate lawful basis, authority and any required notices or permissions to process and submit personal data to ZentraSnap. This does not necessarily require consent; the appropriate legal basis depends on the circumstances and is the responsibility of the relevant Data Controller.

Device Security

You are responsible for maintaining appropriate security for the computer, browser, network and working environment from which you access ZentraSnap.

3. How Financial Documents Are Processed

3.1 Bank Statements

  • When a bank statement is submitted to ZentraSnap, the document is temporarily uploaded to private object storage provided by Cloudflare R2.
  • Where a user uploads a JPG, JPEG, PNG or WebP image of a bank statement, ZentraSnap may first convert the image into PDF format locally within the user's browser before uploading it for processing.
  • Bank statements are then processed using cloud computing infrastructure provided by Modal Labs. Processing may include native PDF text extraction and ZentraSnap's trained document-extraction models.
  • Where a bank statement is image-based, scanned, does not contain usable native text, or where the initial extraction does not identify transaction data, ZentraSnap may use Microsoft Azure AI Document Intelligence as an OCR service. In these circumstances, the relevant document or page is transmitted to Microsoft Azure for text recognition and document-coordinate extraction before the recognised text is processed by ZentraSnap's document-extraction model.
  • Microsoft Azure Document Intelligence temporarily stores submitted input data and analysis results in Azure Storage in the same Azure region as the request. Microsoft currently states that this information is automatically deleted after 24 hours. ZentraSnap may also request deletion of analysis results earlier where supported by the service.
  • The processing system extracts structured transaction information such as transaction dates, descriptions, debit amounts, credit amounts and balances. Document-coordinate information may also be generated to enable features such as locating an extracted transaction within the source document.
  • Temporary job-status information and extracted results may be stored in Cloudflare R2 while the extraction is being processed and delivered to the user.
  • The original uploaded bank statement is deleted from ZentraSnap's temporary R2 storage after processing completes or fails. Automated storage-lifecycle controls are also used as a secondary mechanism to remove temporary files that are no longer required.
  • Modal may retain limited technical information associated with function execution in accordance with Modal's own published retention policies.
  • ZentraSnap does not use customer-uploaded bank statements to train its own machine-learning models.

3.2 Invoices and Receipts

  • When you use ZentraSnap's invoice or receipt extraction functionality, the document or image submitted for extraction is transmitted to Google's paid Gemini API.
  • Google processes the document to return structured information such as supplier details, invoice numbers, dates, totals, tax information and line items.
  • ZentraSnap uses the paid tier of the Gemini API. Under Google's applicable terms for paid Gemini API services, customer prompts and responses are not used to improve Google's products by default.
  • Where Gemini API project logging is enabled, request and response logs may be retained within the relevant Google AI Studio project. Google currently allows project logging retention periods of 7, 14, 28 or 55 days, with a default maximum retention period of 55 days. Google may separately process limited information for security, abuse-prevention and legal-compliance purposes in accordance with its applicable terms and policies.
  • ZentraSnap does not intentionally contribute customer financial documents, API logs or datasets to Google for model training or product improvement.

4. Information We Process

ZentraSnap may process account information such as your first and last name, email address, user identifier, authentication information, subscription status and account preferences. Where applicable, we also process billing and transaction information necessary to manage subscriptions. Payment-card information is processed by the relevant payment provider and is not stored directly by ZentraSnap.

ZentraSnap also processes and stores limited service-usage and credit-accounting information associated with your account. This may include your Clerk user identifier, subscription status, billing-cycle identifiers and dates, current credit balance, credits used, document and page counts, OCR page counts, invoice and receipt counts, extracted transaction counts, usage-event or job identifiers, processing status and relevant timestamps.

This service-usage information is used to administer the ZentraSnap service, apply usage allowances, prevent abuse, investigate billing or technical issues, maintain account statistics and produce aggregate service-usage statistics.

What the usage-accounting database does not store

ZentraSnap's usage-accounting database is not intended to store the contents of customer financial documents. In particular, it does not store transaction descriptions, bank balances, transaction amounts, bank-account numbers, uploaded document filenames, invoice contents or receipt contents as part of credit and usage accounting.

When you use document extraction, the information processed may include:

  • Bank statements, invoices, and receipts
  • Document images
  • Account-holder or customer names
  • Account identifiers & IBANs
  • Transaction dates and descriptions
  • Debit and credit amounts, and balances
  • Supplier details and invoice numbers
  • Addresses, tax information, and line items

Documents may incidentally contain additional personal or sensitive information. ZentraSnap processes such information only as part of providing the document-extraction service. We may also process limited technical information such as application requests, security events, rate-limiting identifiers, browser/device information and service diagnostics where necessary to operate and secure the service. If you contact us for support, we process the information that you provide as part of that communication.

Third-Party Authentication:

If you create or access an account using a third-party identity provider such as Google, the authentication provider may provide ZentraSnap or our authentication provider with basic account information such as your name, email address and profile image for the purpose of creating, authenticating and managing your account.

5. How We Use Personal Data

We use Account Data and Service Usage Data to provide and administer ZentraSnap, authenticate users, manage subscriptions and billing, administer credit allowances, record service usage, enforce applicable usage limits, provide customer support, maintain security, prevent fraud and abuse, diagnose technical problems, maintain account and aggregate usage statistics and improve the operation and reliability of the service.

Client Financial Data is processed only to provide the document-extraction functionality requested by the customer, including temporarily storing documents, extracting text and structured financial data, performing OCR where necessary and delivering extraction results.

ZentraSnap does not sell Client Financial Data.

Cookies and Authentication:

ZentraSnap does not use advertising cookies or tracking pixels to track users across unrelated websites. Strictly necessary cookies and similar technologies may be used for authentication, security, subscription management and other functionality required to provide the service. These may be provided by services such as Clerk.

Website Analytics:

ZentraSnap uses Vercel Web Analytics to understand aggregate website usage and improve the performance and reliability of the service. We do not use Google Analytics for behavioural advertising or cross-site advertising tracking.

6. Legal Bases for Processing

Where ZentraSnap acts as Data Controller for Account Data:

Our legal bases may include performance of a contract where processing is required to provide the ZentraSnap service, legitimate interests in operating, securing, supporting and improving the service, and compliance with legal obligations where applicable.

Where ZentraSnap processes Client Financial Data as a Data Processor:

ZentraSnap does not independently determine the customer's lawful basis for processing that data. Instead, we process the data on the customer's documented instructions and subject to our Data Processing Agreement. The customer or relevant Data Controller is responsible for establishing the appropriate lawful basis under applicable data-protection law.

7. Third-Party Service Providers and Subprocessors

ZentraSnap uses a limited number of third-party service providers to operate the service. These providers are permitted to process personal data only as necessary to provide their relevant services, subject to their applicable contracts, data-processing terms and legal obligations:

Clerk:

Provides authentication, user-account management and subscription functionality.

Stripe:

Processes payments used through Clerk Billing. Clerk currently uses Stripe for payment processing. ZentraSnap does not directly store full payment-card numbers.

Vercel:

Provides hosting, server-side application infrastructure and website analytics.

Cloudflare R2 and D1:

Cloudflare R2 provides private temporary object storage used for bank statements, extraction results and processing metadata. Cloudflare D1 is used to store limited account and service-usage records required for usage tracking and credit accounting, including credit balances, usage counts, billing-cycle information, processing-event status and timestamps. D1 is not used to store the contents of customer financial documents as part of usage accounting.

Modal Labs:

Provides cloud computing and GPU infrastructure used to process bank statements using ZentraSnap's document-extraction and OCR systems. Modal publishes a Data Processing Addendum and security safeguards for processing customer personal data.

Google Gemini API / AI Studio:

Used to process invoices and receipts and, where enabled, provide API project logging and operational monitoring.

Upstash:

Used for API rate limiting and abuse prevention and may process limited technical identifiers required for that purpose. Upstash publishes a Data Processing Addendum covering processing of customer personal data.

8. International Data Transfers

Some of ZentraSnap's service providers operate infrastructure or personnel outside Ireland or the European Economic Area. Where personal data is transferred internationally, ZentraSnap relies on appropriate safeguards required by applicable data-protection law, which may include European Commission adequacy decisions, the EU-U.S. Data Privacy Framework where applicable, Standard Contractual Clauses or other legally recognised transfer mechanisms.

Cloudflare's current DPA expressly covers situations in which it acts as a processor or sub-processor and contains provisions governing transfers from the EEA. Modal also provides a GDPR Data Processing Addendum addressing international transfers and subprocessors.

9. Data Retention

Account Data

Account information is retained while your ZentraSnap account remains active and for such additional periods as may be reasonably required for security, fraud prevention, dispute resolution, accounting, taxation or compliance with legal obligations. Where an account is deleted, account information will be deleted or anonymised from active systems where appropriate, subject to legitimate legal, security, backup and service-provider retention requirements.

Service Usage and Credit Records

Limited usage and credit-accounting records may be retained while your ZentraSnap account remains active and for such additional periods as are reasonably necessary to administer the service, investigate billing or usage disputes, prevent fraud or abuse, maintain security, satisfy accounting or taxation requirements and comply with legal obligations.

These records may include usage totals, credit balances, billing-cycle information, document and page counts, transaction counts, usage-event status and timestamps. Aggregate or anonymised statistics that no longer identify an individual may be retained for longer periods for business, operational and statistical purposes.

Bank Statements

Original bank-statement documents uploaded to Cloudflare R2 are deleted by ZentraSnap's processing system after the extraction job completes or fails.

As an additional safeguard, temporary bank-statement files, extraction results, job-status information and related processing data stored in Cloudflare R2 are subject to an automated lifecycle rule configured to expire those objects after one day. This lifecycle rule acts as a secondary deletion mechanism in case temporary data is not removed earlier by the normal processing workflow.

Invoices and Receipts

Documents submitted for invoice or receipt extraction are processed using the paid Gemini API. If Gemini API project logging is enabled, request and response logs may be retained according to the retention setting configured for the project. Google's current available project-log retention settings are 7, 14, 28 or 55 days. Separate security and abuse-prevention information may be retained by Google in accordance with its applicable policies.

Support and Business Records

Support correspondence and business or billing records may be retained for as long as reasonably necessary to respond to requests, resolve disputes and comply with legal, accounting or taxation obligations.

10. Security

ZentraSnap uses technical and organisational measures intended to protect information processed through the service. Data transmitted between users and ZentraSnap's service providers is protected using encrypted HTTPS/TLS connections where supported.

Bank-statement files are stored in private Cloudflare R2 storage rather than being made publicly accessible. Cloudflare R2 automatically encrypts stored objects using AES-256 encryption. Modal states that user data processed through its infrastructure is encrypted in transit and at rest.

Access to account-specific usage and credit information is linked to the authenticated ZentraSnap account. Communication between ZentraSnap's server-side application and the private usage-accounting service is protected using server-side credentials that are not intentionally exposed to browser code.

ZentraSnap relies on Clerk for authentication and does not store user passwords directly. Payment-card details are processed by Stripe through Clerk Billing and are not stored directly by ZentraSnap.

No internet-based service can guarantee absolute security, but we take reasonable measures intended to minimise unauthorised access, disclosure, alteration or loss.

11. Your Data Protection Rights

Under the General Data Protection Regulation and other applicable data-protection laws, individuals may have rights including access, rectification, erasure, restriction of processing, objection and data portability, depending on the circumstances.

For requests concerning your ZentraSnap account or information for which ZentraSnap acts as Data Controller, contact us at cristingriu25@gmail.com.

Where a request concerns Client Financial Data processed by ZentraSnap on behalf of an accountant, bookkeeping firm or other customer, the relevant customer will normally be the Data Controller. Individuals should normally direct such requests to that organisation. ZentraSnap will provide reasonable assistance to our customers in responding to valid data-subject requests as required under our Data Processing Agreement and applicable law.

Right to Lodge a Complaint:

You also have the right to lodge a complaint with the Data Protection Commission in Ireland if you believe that your personal data has been processed unlawfully.

12. Data Processing Agreement

Our Data Processing Agreement governs ZentraSnap's processing of Client Financial Data on behalf of customers and forms part of the contractual terms for use of the service.

View DPA

13. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to our service, processing activities, service providers, legal requirements or security practices. Where a material change is made, we will update the effective date of this Privacy Policy and take any additional notification steps required by applicable law.

14. Contact

For questions concerning this Privacy Policy or ZentraSnap's data-protection practices, contact:

Cristin Griu

Trading as ZentraSnap

Celbridge, Co. Kildare, Ireland

cristingriu25@gmail.com