Data retention policy
"15.3 On termination of this Agreement for any reason:
(a) all licences granted to the Customer under this Agreement shall immediately terminate and the Customer shall immediately cease all use of the Services;
(b) zeroheight may destroy or otherwise dispose of any of the Customer Data in its possession following termination, unless zeroheight receives, no later than ten days after the termination of this Agreement, a written request for the delivery to the Customer of the then most recent back-up of the Customer Data. zeroheight shall use reasonable commercial endeavours to deliver the back-up to the Customer within 30 days of its receipt of such a written request, provided that the Customer has, at that time, paid all fees and charges outstanding at and resulting from termination (whether or not due at the date of termination). The Customer shall pay all reasonable expenses incurred by zeroheight in returning or disposing of Customer Data; and
(c) any rights, remedies, obligations or liabilities of the parties that have accrued up to the date of termination, including the right to claim damages in respect of any breach of the agreement which existed at or before the date of termination shall not be affected or prejudiced.
For details, see Data Management Policy at https://zeroheight.com/14bb9b256/p/137c39-security-documents Data archiving and removal policy
Data center location(s)
Ireland
Data hosting details
All data is hosted and backed up in AWS EU-West-1 Dublin Ireland, across nine data centers.
App/service has sub-processors
yes
Guidelines for sub-processors
App/service uses large language models (LLM)
yes
LLM model(s) used
OpenAI GPT-5
LLM retention settings
Standard retention: 30 days for abuse monitoring, then auto-deleted. Zero Data Retention (ZDR) enabled where available: inputs/outputs never logged or stored. Non-ZDR endpoints follow 30-day retention before deletion unless legally required to retain.
LLM data tenancy policy
OpenAI does not use API data to train models. Customer data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Access restricted to authorized personnel for support, abuse monitoring, and legal compliance. SOC 2 Type 2 compliant with DPA for GDPR.
LLM data residency policy
API configured for European data residency. All requests processed exclusively in Europe (EEA/Switzerland) with zero data retention. Data handled in-region via eu.api.openai.com and never leaves European borders.