ZentrolHQ is operated by Cabel Farnes, a sole trader in Victoria, Australia, ABN 28 910 682 314. Security and privacy contact: help@zentrolhq.com.
ZentrolHQ supplies a white-label service using DM Champ, operated by OneGlimpse B.V. DM Champ and its infrastructure suppliers operate the underlying platform. This overview describes their publicly documented controls and our responsibilities; it is not an independent technical audit, certification or guarantee that every connected service has the same controls. Our Terms and Privacy Policy explain the service and information handling. A customer-specific DPA is available on request where needed and applies only when separately agreed.
Storage and international processing
DM Champ describes core messaging/contact and related application storage on dedicated servers in Germany. Its documented file, export and backup storage uses EU locations, including Poland, Belgium and EU multi-region storage, depending on the function. This does not mean all Customer Data stays in the EU: authentication is a global service, some queue storage depends on the publishing server's region, and AI, messaging, networking and connected services can process information elsewhere.
Relevant AI inputs, files or messages are sent to providers needed for the features you use. Provider entities and processing can be in the United States and other countries. DM Champ's supplier register describes providers, purposes and locations; not every listed provider is used for every account. Your own connections can introduce additional recipients. European transfer clauses or adequacy arrangements, where applicable to a specific transfer, do not replace Australian overseas-disclosure duties or automatically cover every customer to ZentrolHQ transfer.
Encryption and access
DM Champ's published data-processing terms specify TLS 1.2 or higher for platform data in transit and encryption of backups and stored third-party credentials. This is not a promise of end-to-end encryption across every independent messaging service, or encryption at rest of every live database record. Password authentication is handled through the platform's authentication service; we do not claim an independently verified password-hashing algorithm or configuration.
The platform describes scoped API keys as hashed and displayed once. Its original full-access platform API key is encrypted and can be displayed again in account settings. Keys and tokens should therefore still be treated as sensitive credentials. This distinction does not establish the display behaviour of every BYOK or channel credential.
Available team roles and permissions help customers limit account access. Review users, connected services and permissions regularly. The platform offers two-factor authentication; availability is not a promise every user has enabled it. Agency access to a client workspace relies on the agency user's authenticated access, rather than prompting again for the client's second factor. ZentrolHQ limits its own access to service administration, support, security and lawful requirements, with appropriate confidentiality. Infrastructure access controls are provided by DM Champ; we do not directly administer its servers.
AI and customer-connected providers
ZentrolHQ does not sell Customer Data, use it for advertising, or use it to train general AI models. Using information to generate a requested response, summary or other configured function is distinct from training a general model.
DM Champ's published terms describe no training on Customer Data unless separately agreed in writing, and platform-selected AI processing under commercial API arrangements excluding that training. ZentrolHQ does not authorise such a training agreement. These are supplier contractual statements; they are not a blanket guarantee about every provider, model or future configuration.
If you connect your own AI provider account or API key, its independent terms, settings, product, region and training or feedback opt-ins matter. Check these before sending information and maintain lawful authority and safeguards. Do not enable training or submit identifiable Customer Data as provider feedback without the necessary authority. BYOK changes eligible routing/billing; it does not bypass the platform or remove our own handling duties. No universal zero retention or no-human-access promise is made.
Backups, export and deletion
DM Champ's current Security page describes daily database backups retaining the last seven daily copies, alongside continuous transaction-log archiving and recovery testing. Its contractual retention statements allow deleted information to remain in disaster-recovery backups for up to 90 days. These describe different backup/recovery aspects; they do not establish that every backup is continuous or that every deleted record is removed in seven days. No fixed recovery-time, recovery-point or successful-restoration guarantee is offered.
Contacts/conversations are retained until deletion by default. An optional inactivity-retention control deletes eligible inactive contacts and related data under platform rules and scheduled processing. It is not enabled for everyone automatically and is not an exact-time deletion guarantee.
Ordinary cancellation stops future renewal and normally preserves paid-period access. The documented export opportunity runs during the subscription and ordinarily for 30 days after termination, followed by normal-course live-system deletion. Permanent deletion or an earlier deletion instruction can end that opportunity. Export before deletion. Independent connected-provider copies and lawful business records can remain. Deleted live data can remain in recovery backups for up to 90 days; server/security logs are described as typically retained for up to 12 months. We do not promise instant removal from all systems or recovery of permanently deleted information. See the Privacy Policy for the full distinctions.
Monitoring and incidents
DM Champ documents operational monitoring, network protection, vulnerability assessment, dependency maintenance, incident and continuity procedures, and supplier-security assessment. These are provider-described measures, not an independently verified assessment frequency, external penetration-test certificate or uptime guarantee. ZentrolHQ remains responsible for reasonable safeguards and its own legal duties.
Report a suspected vulnerability or exposure to help@zentrolhq.com, with enough information to investigate. Avoid sending secrets or unnecessary personal information. We will assess reports and coordinate with the platform provider where relevant. After becoming aware of a personal data breach affecting Customer Data, we will notify the affected customer without undue delay, provide available information and further updates, and cooperate with applicable notification obligations. Legal duties to notify individuals or authorities depend on the incident and applicable law. We do not promise that every customer deadline will necessarily be met or apply a universal Australian 24/72-hour rule.
Certifications and security reviews
DM Champ states that the platform is not SOC 2 or ISO 27001 certified. ZentrolHQ does not claim either certification. A supplier's separate certification does not certify the whole ZentrolHQ service. Contact help@zentrolhq.com for relevant documentation or a customer-specific processing/security review. Any special security requirements must be assessed before agreement; we do not promise unrestricted access to supplier infrastructure.