Zorro MCP is live. Plug private markets into Claude. Try it
Legal

Privacy Policy

How we collect, use, share, and protect personal data — across our platform, website, and any associated services.

Last updated
July 2026
Entity
Zorro AI Ltd
Registration
No. 16358589 · England & Wales

This Privacy Policy explains how Zorro AI Ltd ("Zorro AI", "we", "us", or "our") collects, uses, shares, and protects personal data in connection with our software-as-a-service platform, website, and any associated services (collectively, the "Platform").

Zorro AI Ltd is a company registered in England and Wales (Company No. 16358589) with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

1. Data we collect

We collect and process the following types of information:

1.1 Personal information you provide

  • Name, company name, job title
  • Email address, phone number
  • Login credentials and profile information
  • Any content or messages submitted through forms, chat, or emails

1.2 Automatically collected information

When you interact with the Platform, we automatically collect:

  • Device data: IP address, browser type, operating system, screen resolution
  • Usage data: pages visited, links clicked, time spent, navigation paths
  • Interaction events: buttons clicked, forms submitted, inputs changed
  • Session replays: full recordings of user interactions within the Platform
  • API call logs: full capture of API calls and related metadata

1.3 Cookies and tracking technologies

We use cookies and similar technologies to:

  • Authenticate users
  • Remember preferences
  • Enable functionality
  • Track engagement for product improvement
  • Conduct marketing analytics

Cookies may be set by us or third-party providers such as Google Analytics, the LinkedIn Insight Tag, and other ad and retargeting networks.

You can manage cookie settings via your browser or device settings.

1.4 Public-register and business contact data

The Platform provides company intelligence and B2B prospecting features. To deliver these, we process personal data that we do not collect from the individuals concerned:

  • Public-register data (Companies House and other official registers): names of company directors and persons with significant control (PSCs), their appointments and resignations, role, nationality, country of residence, correspondence (service) address, and partial date of birth (month and year only), as published by Companies House. We use the partial date of birth solely to derive the approximate age or age range of directors and PSCs — for example, to help our customers identify companies whose owners may be approaching retirement. We never collect or process a full date of birth, and we do not process residential addresses where a service address is available.
  • Business contact data (licensed data providers): name, employer, job title, business email address, business phone number, and LinkedIn profile URL of individuals at companies our customers research, obtained through the licensed contact-data providers listed in Section 2.
  • Registered property ownership: proprietor name and title details for commercial and corporate property in England and Wales, taken from HM Land Registry's Commercial and Corporate Ownership Data under licence.
  • Outreach records: messages sent to a contact on a customer's behalf, delivery and engagement events, the content of any email reply received, and — where a customer connects their LinkedIn account — connection requests sent and the content of messages received to that account.

This data relates to individuals in their professional or corporate capacity only. We do not intentionally process special category data or data relating to individuals acting in a purely personal (consumer) capacity, and our services are not directed at children.

2. Tools and providers we use

To operate and improve the Platform, we use the following services:

Public registers & company data
  • Companies House · company filings, accounts, and officer/PSC records (source of the public-register data described in Section 1.4)
  • HM Land Registry · commercial and corporate ownership data, refreshed from a monthly snapshot
  • PlanIt · planning application data
  • PredictLeads · company growth and hiring signals
  • Creditsafe · company credit and officer data
Contact enrichment
  • Snov.io · business email discovery and verification
  • FullEnrich · business email (fallback) and business phone number enrichment
  • Apollo · contact discovery and employer validation
  • Reoon · email deliverability verification
AI & language model processing
  • OpenAI · drafting outreach messages, classifying inbound replies, analysing calls, and web search for company research. Prompts may include the company record and the contact and reply data relevant to the task.
  • Anthropic · used for some agent functions
  • Pinecone · vector search over industry classification data
Web & search data
  • DuckDuckGo · primary web search source
  • Oxylabs · web search fallback
  • SimilarWeb · website traffic estimates
Email sending & sequencing
  • Instantly · outreach email sequencing and delivery
  • Snov.io · outreach email delivery
  • SendGrid · transactional and report email
  • Resend · account verification and onboarding email
  • Zapmail · sending domains and mailboxes
LinkedIn & CRM
  • Unipile · connects your LinkedIn account, retrieves your connections list, sends connection requests on your instruction, and receives inbound messages sent to that account. We do not store your LinkedIn password.
  • HubSpot and Pipedream · exporting contacts and deal information to your CRM, where you enable it
Internal workflow
  • Slack and Atlassian Jira · when you submit a feature request from the Platform, the request text and your email address are sent to our internal Slack workspace and Jira project so we can triage it
Analytics, infrastructure & payments
  • PostHog · user behaviour, event data, logs, replays, API usage
  • Sentry · technical errors and stack traces
  • Google Analytics · aggregated data on visits, traffic sources, UTMs, conversions
  • LinkedIn Insight Tag · ad optimisation and retargeting
  • Google Cloud · hosting and infrastructure
  • Elastic Cloud · search infrastructure
  • Cloudflare · content delivery and bot protection
  • Stripe · payment processing

Our enrichment providers process limited identifiers (such as name, employer, and LinkedIn profile URL) in order to return verified business contact details. Each of the providers above acts as our sub-processor for the purpose described.

3. How we use personal data

We use your data for the following purposes:

  • To provide and improve our Platform
  • To provide company intelligence, including director and PSC information sourced from Companies House and other public registers
  • To find and verify business contact details on behalf of our customers for legitimate B2B outreach
  • To personalise the user experience
  • To monitor, analyse, and optimise Platform performance
  • To offer user support and troubleshoot issues
  • To communicate updates, service notices, and product news
  • To run marketing campaigns and retargeting
  • To meet legal obligations and enforce terms

Our processing is built for UK GDPR, EU GDPR, and US privacy regulation (CCPA/CPRA). Data is sourced from public registers and licensed providers and processed on a legitimate-interest basis for B2B; outbound is CAN-SPAM and PECR aligned. We rely on the following legal grounds:

  • Contractual necessity · to deliver the services agreed with you
  • Legitimate interests · product improvement, security, business operations, and B2B prospecting from public and licensed sources
  • Consent · for optional tracking and marketing where legally required
  • Legal obligation · for recordkeeping, compliance, and rights protection

4.1 Companies House-derived personal data (directors & PSCs)

We process personal data about company directors and persons with significant control — including the partial date of birth (month and year only) that Companies House makes publicly available — on the basis of our legitimate interests (UK GDPR / EU GDPR Article 6(1)(f)): enabling our business customers to research, screen, and originate transactions with UK companies.

In relying on this basis we have considered that:

  • this data is made public by law under the Companies Act 2006, and individuals acting as directors or PSCs can reasonably expect it to be used for corporate research and due diligence;
  • we apply data minimisation — Companies House publishes only the month and year of birth for directors and PSCs, and that partial date is all we take from the register, which we use solely to derive an approximate age or age range;
  • the data relates to individuals in their corporate capacity, and processing it in this way has limited impact on their private life; and
  • individuals retain the right to object at any time (see Section 8).

4.2 Enriched business contact data

Business contact details obtained from our licensed enrichment providers (Section 2) are processed on the same legitimate interests basis, for B2B prospecting on behalf of our customers. Where an individual objects or opts out, we honour the request and add their details to a suppression list so they are not processed again.

5. Sharing and disclosure

We do not sell your personal data. We may share it with:

  • Cloud service providers and subcontractors (data processors), including the contact-enrichment providers listed in Section 2
  • Marketing and analytics vendors
  • Legal authorities, when required by law

We put a data processing agreement in place with the providers who process personal data on our behalf.

6. International transfers

Some of our service providers — including certain contact-enrichment providers — may store or process data outside the UK. We ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement/Addendum (IDTA) or Standard Contractual Clauses (SCCs).

7. Data retention

We retain personal data only as long as necessary for the purposes stated in this policy, or to comply with our legal obligations.

Specific periods we apply:

  • Call transcripts and recordings · deleted 180 days after the call, with only the derived analysis retained
  • Uploaded import previews · held for up to 30 minutes and discarded once the import is confirmed or abandoned; we do not retain the uploaded file itself
  • Company signal data · refreshed on a 14-day cycle
  • AI assistant (MCP) tool-call records · deleted after 90 days. These include the parameters of the requests the assistant makes and the results returned, which can contain the text of a request you asked it to make.

Other records — including account and usage data, contact records, outreach history and message content — are retained for as long as the account is active and for as long as they remain necessary for the purposes described in this policy. Public-register data is refreshed against the source register and corrected or removed when the register changes. Where an individual opts out of processing, we retain the minimum information needed on a suppression list to ensure their data is not processed again. You can request deletion at any time under Section 8.

8. Your rights

Under the UK GDPR and EU GDPR — and, where applicable, US privacy regulation (CCPA/CPRA) — you have the right to:

  • Access your data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict or object to processing
  • Port your data to another provider
  • Withdraw consent (where applicable)

If we hold data about you that we did not collect from you directly — for example, director or PSC information from Companies House, or business contact details from a licensed provider — you may object to this processing or ask us to delete your details at any time by emailing privacy@getzorro.ai. We will action objections to B2B prospecting without undue delay and suppress your details from future processing.

To exercise your rights or submit a complaint, email us at privacy@getzorro.ai.

You may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9. Security

We use technical and organisational measures to protect personal data, including:

  • Encryption in transit and at rest
  • Access controls and role-based permissions
  • Monitoring and alerting for suspicious activity

10. AI assistant and MCP integrations

You can connect Zorro to an AI assistant such as Claude through our Model Context Protocol (MCP) server. When you do, the assistant sends requests to Zorro on your instruction and receives the results.

  • Zorro receives the parameters of the requests the assistant makes — for example a company name, a set of search filters, or a list identifier — together with the results we return. We log these requests as described in Section 1.2.
  • Zorro has no access to your wider conversation with the assistant, to files you have shared with it, or to any other tool you have connected to it.
  • How the assistant provider handles the conversation itself is governed by their own privacy policy, not this one.
  • Access is authorised using OAuth. You can revoke it at any time from your Zorro account, which immediately ends the connection.

Some features reachable through the connector send data to the AI providers listed in Section 2 — for example drafting an outreach message or classifying a reply.

11. Changes to this policy

We may update this Privacy Policy from time to time. The latest version will always be available at getzorro.ai/privacy. We will notify you of material changes where required.

Contact us
Zorro AI Ltd
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
privacy@getzorro.ai
Book a demo Available this week