ZeroshotCloud
DocsLegalPlatform

Legal

OverviewBusiness TermsPrivacyDPAImprint

Privacy Notice

Effective 20 August 2026 · Version 2026-08-19

On this page

  • 1. Who we are
  • 2. Scope
  • 3. Data we handle
  • 4. Why we use it
  • 5. When we disclose data
  • 6. Locations and international transfers
  • 7. Retention
  • 8. Your rights
  • 9. United States notices
  • 10. Cookies and local storage
  • 11. Security
  • 12. Changes and contact

1. Who we are

COVIBES LABS AS, doing business as The Open Engine Company, organization number 937 377 266, (“we”, “us”, or “our”) is the controller for the account, billing, security, website, and business-administration processing described here. Its address is Romsdalveien 78, 9537 Tverrelvdalen, Norway. Contact legal@theopenengine.com about privacy.

“Customer Content” means content submitted to or generated through Zeroshot Cloud by or for a business customer. When we process personal data in Customer Content solely on that customer’s instructions, the customer is the controller and we are its processor. The Data Processing Agreement (“DPA”) governs that processing, and requests about it should normally go to the customer.

2. Scope

This Notice covers Zeroshot Cloud websites, accounts, APIs, command-line tools, support, billing, and invitations (collectively, the “Service”). The Service is intended for people acting in a business or professional capacity and is not directed to children.

Third-party identity, payment, model, source-control, and cloud services have their own privacy notices for processing they control.

3. Data we handle

We receive data from users, customer administrators, identity providers, connected services, payment providers, and normal use of the Service.

  • Account data: name, email address, avatar, identity-provider identifiers, and account settings.
  • Organization data: organization name, memberships, roles, invitations, and administrative actions.
  • Technical data: session and device labels, IP address or prefix, user agent, timestamps, logs, and audit records.
  • Service data: run names, status, usage, metering, inputs, code, prompts, results, and connection metadata.
  • Connection data: encrypted credentials or references for integrations a customer chooses to connect.
  • Billing data: plan, usage, billing contact, tax details, provider identifiers, invoices, and payment status. Our payment provider, not us, collects full payment-card details.
  • Communications: support messages, legal or abuse reports, feedback, and invitation recipient addresses.

4. Why we use it

Our legitimate interests are operating a secure B2B service, supporting customers, preventing abuse, improving reliability, and managing our business. We balance those interests against individual rights and do not use this basis where those rights override our interests.

Identity, authentication, billing, and Service data marked as required are needed to create an account or provide the requested Service. Without them, we cannot provide the relevant account, transaction, or feature; other data is optional unless we say otherwise.

  • Provide accounts and the Service — contract where the user is the customer; otherwise legitimate interests.
  • Administer organizations, support users, and communicate service information — legitimate interests and contract.
  • Measure usage, bill customers, and keep financial records — contract and legal obligations.
  • Protect accounts, investigate abuse, prevent fraud, and maintain reliability — legitimate interests and law.
  • Handle legal or abuse reports, comply with legal requests, and enforce agreements — legal obligations and legitimate interests.
  • Improve the Service’s functionality, reliability, security, and user experience by analyzing run metadata and technical diagnostic information—such as status, timing, resource-use information, and error codes—and by using aggregated or otherwise anonymized findings that cannot reasonably be linked to a particular customer, individual, household, or device and that we do not attempt to re-identify — legitimate interests.

5. When we disclose data

Our current subprocessor information is in DPA Schedule 3. We do not sell personal data or share it for cross-context behavioral advertising, and we do not use third-party advertising trackers in the Service.

  • Customer administrators and authorized users, according to organization roles.
  • Hosting, infrastructure, security, communications, support, and other subprocessors.
  • Identity, payment, model, source-control, and cloud providers selected or enabled by the customer.
  • Authorities or other parties when law requires it or rights, safety, and security need protection.
  • A buyer, investor, affiliate, or adviser in a corporate transaction, subject to confidentiality.

6. Locations and international transfers

We store and primarily process Service data, including account data and Customer Content, in AWS regions in the European Union. Support may access data from Norway and the European Union. AWS and customer-selected providers may process data in other countries as described below.

Processor-side subprocessor entities, locations, and safeguards are listed in DPA Schedule 3. Stripe Payments Europe, Limited (Ireland) and its affiliates process payment and billing data in the European Economic Area (“EEA”), United States, and other countries under Stripe’s DPA and Data Transfers Addendum. Stripe acts as a processor for some processing and as an independent controller for other processing. Customer-selected identity and connected-service providers are subject to their own transfer terms. Contact us for a copy of an applicable safeguard.

7. Retention

We delete or de-identify personal data under the periods or criteria below unless law requires retention:

  • Account and membership records: until the account is deleted; organization records while the organization is active.
  • Run input: scrubbed when the run reaches a terminal state.
  • Run watch and log history: 60 days.
  • Application process and load-balancer access logs: 14 days.
  • Run metadata, latest status (including terminal output), and audit records: while the related organization is active and afterward only as needed for security, audit, disputes, or law.
  • Backups: removed under documented backup and recovery cycles after source data is deleted.
  • Billing and tax records: retained for the periods required by applicable accounting and tax law.
  • Support and business communications: retained while needed to resolve the matter, handle follow-up or disputes, or comply with law.

8. Your rights

Depending on location and context, individuals may ask to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and may withdraw consent without affecting earlier processing. The right to object applies to processing based on legitimate interests.

Submit a request to legal@theopenengine.com. We may verify identity and authority and may direct a request about Customer Content to the relevant customer. Where applicable, a person may appeal our decision by replying to it.

EEA individuals may complain to Datatilsynet or their local supervisory authority. We encourage contacting us first so we can address the issue.

9. United States notices

Where a US state privacy law applies, residents may have rights to know, access, correct, delete, or obtain personal data, and to appeal a denied request. Because we do not sell personal data, use it for targeted advertising, or conduct qualifying profiling, there is presently no such processing to opt out of.

Where applicable, an authorized agent may submit a request on a resident’s behalf. We will not discriminate against a person for exercising an applicable privacy right.

10. Cookies and local storage

We use strictly necessary cookies for login, session security, CSRF protection, and device flows. We use local storage for the selected theme and session storage for short-lived navigation state. These technologies are not used for advertising.

11. Security

We use technical and organizational measures designed for the nature and risk of the data, but no system is completely secure. Current measures are summarized in DPA Schedule 2.

12. Changes and contact

We will post updates here and change the effective date. We will give additional notice where a change materially affects rights or is otherwise required.

Privacy contact: legal@theopenengine.com. Postal contact: COVIBES LABS AS, Romsdalveien 78, 9537 Tverrelvdalen, Norway.

Back to Legal HubQuestions: legal@theopenengine.com