Zorro MCP is live. Plug private markets into Claude. Try it
Legal

Privacy Policy

How we collect, use, share, and protect personal data — across our platform, website, and any associated services.

Last updated
September 2026
Entity
Zorro AI Ltd
Registration
No. 16358589 · England & Wales

This Privacy Policy explains how Zorro AI Ltd ("Zorro AI", "we", "us", or "our") collects, uses, shares, and protects personal data in connection with our software-as-a-service platform, website, and any associated services (collectively, the "Platform").

Zorro AI Ltd is a company registered in England and Wales (Company No. 16358589) with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

1. Data we collect

We collect and process the following types of information:

1.1 Personal information you provide

  • Name, company name, job title
  • Email address, phone number
  • Login credentials and profile information
  • Any content or messages submitted through forms, chat, or emails

1.2 Automatically collected information

When you interact with the Platform, we automatically collect:

  • Device data: IP address, browser type, operating system, screen resolution
  • Usage data: pages visited, links clicked, time spent, navigation paths
  • Interaction events: buttons clicked, forms submitted, inputs changed
  • Session replays: full recordings of user interactions within the Platform
  • API call logs: full capture of API calls and related metadata

1.3 Cookies and tracking technologies

We use cookies and similar technologies to:

  • Authenticate users
  • Remember preferences
  • Enable functionality
  • Track engagement for product improvement
  • Conduct marketing analytics

Cookies may be set by us or third-party providers such as Google Analytics, the LinkedIn Insight Tag, and other ad and retargeting networks.

You can manage cookie settings via your browser or device settings.

1.4 Public-register and business contact data

The Platform provides company intelligence and B2B prospecting features. To deliver these, we process personal data that we do not collect from the individuals concerned:

  • Public-register data (Companies House): names of company directors and persons with significant control (PSCs), their appointments and resignations, role, occupation, nationality, country of residence, correspondence (service) address, and partial date of birth (month and year only), as published by Companies House. We use the partial date of birth solely to derive the approximate age or age range of directors and PSCs — for example, to help our customers identify companies whose owners may be approaching retirement. We never collect or process a full date of birth, and we do not process residential addresses where a service address is available.
  • Business contact data (contact-data providers): name, employer, job title, business email address, business phone number, and LinkedIn profile URL of individuals at companies our customers research, obtained through the contact-data providers described in Section 2. Where a customer specifically requests it, a personal email address for that individual may also be looked up; the request is priced and confirmed separately, and the same objection route in Section 8 applies.
  • Registered property ownership: proprietor name and title details for commercial and corporate property in England and Wales, taken from HM Land Registry's Commercial and Corporate Ownership Data under licence.
  • Outreach records: messages sent to a contact on a customer's behalf, delivery and engagement events, the content of any email reply received, and — where a customer connects their LinkedIn account — connection requests sent and the content of messages received to that account; calls made to a contact from the Platform, their live transcripts and, where recording is enabled and announced on the call, the recording; and contact files a customer uploads for import, held as a preview for up to 30 minutes.

This data relates to individuals in their professional or corporate capacity, except for the personal email lookup described above, which a customer must specifically request. We do not intentionally process special category data or data relating to individuals acting in a purely personal (consumer) capacity, and our services are not directed at children.

2. Data sources and recipients

This section has two parts. First, the sources we take company and officer data from: the public registers, and the commercial data providers we buy data from. Second, the categories of recipient we share personal data with in order to operate the Platform. How to obtain the specific names is at the end of this section.

Public registers we take data from
  • Companies House · company filings, accounts, and officer/PSC records. The non-personal content of the register is published under the Open Government Licence v3.0, which does not extend to personal data; our lawful basis for the personal data on the register is in Section 4.1. Source of the public-register data described in Section 1.4.
  • HM Land Registry · commercial and corporate ownership data, under licence, refreshed from a monthly snapshot

These are sources of data to us, not our processors. We do not share customer or contact data with them.

Commercial data providers we buy data from
  • Planning data · planning application records
  • Growth signals · company growth and hiring events
  • Credit data · company credit and officer records
  • Web data · website traffic estimates

These providers supply data to us. They receive lookup queries, such as a company identifier, and no personal data from us.

Where we hold personal data we did not obtain from you, Article 14(2)(f) UK GDPR requires us to tell you where it came from. Company and officer data comes from Companies House; property ownership data from HM Land Registry. Both are publicly accessible sources. Business contact details, and company credit and officer records, come from commercial data providers under contract, not from a publicly accessible source. Planning records and growth signals come from commercial aggregators of public sources. We do not write to each director, PSC or contact individually: doing so for every person on the register would be a disproportionate effort (Article 14(5)(b)), so we publish this notice and keep it current. On request we will name the specific provider that supplied any record about you; see the end of this section.

To operate the Platform we share personal data with the following categories of recipient. Unless stated otherwise they are in the United States or the European Economic Area; Section 6 covers the transfers.

Our customers
  • UK lenders, advisers and business-development teams · receive company, officer and business-contact records through the Platform, the API and connected AI assistants, under terms that restrict use to business-to-business purposes
Contact-data providers
  • Email discovery and verification · business email addresses
  • Phone enrichment · business phone numbers
  • Deliverability verification · whether an email address accepts mail

These providers receive limited identifiers (such as name, employer, and LinkedIn profile URL) in order to return verified business contact details.

AI and language-model providers
  • Drafting and classification · drafting outreach messages, classifying inbound replies, analysing calls, and web search for company research. Prompts may include the company record and the contact and reply data relevant to the task.
  • Agent reasoning · a second language-model provider runs some agent workflows; prompts may include the company record and the contact fields relevant to the task
  • Web search · company-research search queries, which can contain a company name and a person's name
  • Call analysis · transcripts of calls made through the Platform are analysed by these providers; retention is in Section 7
  • Vector search · over industry classification data; receives no personal data
Telephony
  • Voice calls and live transcription · where you call a contact from the Platform, a third-party telephony carrier connects the call, receives the number dialled and the call audio, and produces the live transcript. Recording, where enabled, is announced on the call.
Web-page rendering
  • Page rendering · where a company's website does not return a usable page on a plain request, because it needs a browser to display or because it declines automated requests, we route that page through a third-party rendering service, which receives the page URL. We read and obey each site's robots.txt before requesting any page.
Email delivery and sequencing providers
  • Outreach sequencing and delivery · sending the outreach emails you approve
  • Transactional and report email · reports and account notices
  • Onboarding email · account verification
  • Sending domains and mailboxes · a third party provisions and holds the mailboxes used for outreach

These providers receive the recipient's name and email address, the message content, and any reply.

Professional-network and CRM integrations
  • LinkedIn account integration · where you connect your own LinkedIn account, a third-party account-integration provider, named on the authorisation screen before you connect and available on request, operates that account on your instruction: it retrieves your connections list, sends the connection requests you instruct, and receives inbound messages sent to that account. The account is yours, you authorise the connection, and every action is one you have instructed. We do not store your LinkedIn password, and you can disconnect at any time.
  • CRM export · exporting contacts and deal information to your CRM through a third-party integration service, where you enable it
Team messaging and issue tracking
  • Feature requests · when you submit a feature request from the Platform, or approve feedback for sending from the Zorro connector, the request text and your email address are sent to the third-party team-messaging and issue-tracking services we use, so we can triage it
Analytics, infrastructure and payment providers
  • Product analytics and session replay · user behaviour, event data, logs, API usage
  • Error monitoring · technical errors and stack traces
  • Website analytics and advertising measurement · visits, traffic sources, UTMs and conversions, together with the cookie and device identifiers used for advertising and retargeting. The cookie providers are described in Section 1.3.
  • Hosting and search infrastructure · running the Platform and its search index
  • Content delivery and bot protection · serving the website and filtering abusive traffic
  • Payment processing · card payments; we do not hold card numbers

We are the controller for the company, officer and business-contact records we compile. Where a customer uploads its own contacts or instructs outreach, the customer is the controller for that data and we act as its processor under our customer terms. A provider that processes personal data only on our instructions acts as our processor under a written data processing contract; this covers the email delivery, hosting, analytics, AI, telephony and integration services above. The contact-data providers and the commercial data providers we buy data from decide their own purposes for the records they hold and act as independent controllers, processing the identifiers we send them on our instruction. The payment processor and the advertising and retargeting networks act as independent or joint controllers. Your CRM and your LinkedIn account are yours, under your own terms with those platforms; the integration services we use to connect to them act as our processors on your instruction.

We keep a current list of the specific providers in each category. Article 15(1)(c) UK GDPR entitles you to know the recipients of your personal data. We go further than the categories above: on request we name the specific providers, and the specific provider that supplied any record about you. Email privacy@getzorro.ai. We answer free of charge within one month, or within three months for a complex request, in which case we will tell you why. Customers receive the same list under our customer terms. Where your data has been transferred outside the UK we will also tell you which safeguard applies and give you a copy of it.

3. How we use personal data

We use your data for the following purposes:

  • To provide and improve our Platform
  • To provide company intelligence, including director and PSC information sourced from Companies House
  • To find and verify business contact details for use by our customers in legitimate B2B outreach
  • To personalise the user experience
  • To monitor, analyse, and optimise Platform performance
  • To offer user support and troubleshoot issues
  • To communicate updates, service notices, and product news
  • To run marketing campaigns and retargeting
  • To meet legal obligations and enforce terms

Our processing is built for UK GDPR and EU GDPR. Data is sourced from public registers and commercial data providers and processed on a legitimate-interest basis for B2B. Outbound email is sent to corporate addresses in line with PECR, and the Platform does not send outreach to a personal email address. We rely on the following legal grounds:

  • Contractual necessity · to deliver the services agreed with you
  • Legitimate interests · product improvement, security, business operations, and B2B prospecting from public registers and commercial data providers
  • Consent · for optional tracking and marketing where legally required
  • Legal obligation · for recordkeeping, compliance, and rights protection

4.1 Companies House-derived personal data (directors & PSCs)

We process personal data about company directors and persons with significant control — including the partial date of birth (month and year only) that Companies House makes publicly available, and equivalent officer records supplied by commercial credit-data providers — on the basis of our legitimate interests (UK GDPR / EU GDPR Article 6(1)(f)): enabling our business customers to research, screen, and originate transactions with UK companies.

In relying on this basis we have considered that:

  • this data is made public by law under the Companies Act 2006, and individuals acting as directors or PSCs can reasonably expect it to be used for corporate research, due diligence and business-to-business approaches, and they have an absolute right to object to direct marketing (Article 21(2));
  • we apply data minimisation — Companies House publishes only the month and year of birth for directors and PSCs, and the month and year is the only date-of-birth information we take from the register, which we use solely to derive an approximate age or age range;
  • the data relates to individuals in their corporate capacity, and processing it in this way has limited impact on their private life; and
  • individuals retain the right to object at any time (see Section 8).

4.2 Enriched business contact data

Business contact details obtained from our contact-data providers (Section 2) are processed on the same legitimate interests basis, for use by our customers in B2B prospecting. In relying on this basis we have considered that the data relates to individuals in their professional capacity at their employer, that it is limited to the business contact details described in Section 1.4, and that an individual can object at any time under Section 8. Where an individual objects or opts out, we honour the request and add their details to a suppression list so they are not processed again. Where a customer specifically requests a personal email address, we look it up on that customer's instruction as its processor; the customer is responsible for its own lawful basis and for the consent rules that apply to marketing to a personal address.

Scores and qualification outputs from our models are estimates about companies; the approximate age range we derive for directors and PSCs relates to individuals. Both are used only to prioritise which companies our customers approach. We make no decision based solely on automated processing that produces legal or similarly significant effects on any individual.

5. Sharing and disclosure

We do not sell personal data to advertisers or data brokers. Our customers access company, officer and business-contact records through the Platform, the API and connected AI assistants under terms that restrict use to business-to-business purposes. We may also share personal data with:

  • The categories of recipient described in Section 2, in the roles stated there
  • Legal authorities, when required by law
  • Professional advisers and auditors, including our information-security certification auditor
  • A successor in a business transfer, under the same terms

We put a data processing agreement in place with the providers who process personal data on our behalf.

6. International transfers

Most of our providers store or process personal data outside the UK, principally in the United States and the European Economic Area. Transfers to the EEA rely on the UK adequacy regulations. Where no UK adequacy regulations cover the transfer, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses with the provider. To obtain a copy of the safeguards for any transfer, email privacy@getzorro.ai; we will provide it free of charge within one month, or within three months for a complex request. Where you connect an AI assistant, CRM or LinkedIn account, data you send to that provider is transferred under your own arrangement with it.

7. Data retention

We retain personal data only as long as necessary for the purposes stated in this policy, or to comply with our legal obligations.

Specific periods we apply:

  • Call transcripts and recordings · deleted 180 days after the call, with only the derived analysis retained
  • Uploaded import previews · held for up to 30 minutes and discarded once the import is confirmed or abandoned; we do not retain the uploaded file itself
  • Company signal data · refreshed on a 14-day cycle
  • AI assistant (MCP) tool-call records · deleted after 90 days. These include the parameters of the requests the assistant makes and the results returned, which can contain the text of a request you asked it to make and the company, officer and contact records returned.

Other records — including account and usage data, contact records, outreach history and message content — are retained for as long as the account is active and for as long as they remain necessary for the purposes described in this policy. Public-register data is refreshed against the source register and updated when the register changes; resigned appointments are retained as history. Where an individual opts out of processing, we retain the minimum information needed on a suppression list to ensure their data is not processed again. You can request deletion at any time under Section 8.

8. Your rights

Under the UK GDPR and EU GDPR you have the right to:

  • Access your data
  • Be told which specific providers received your data, not only the categories (see Section 2)
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict or object to processing
  • Port your data to another provider
  • Withdraw consent (where applicable)

If we hold data about you that we did not collect from you directly — for example, director or PSC information from Companies House, or business contact details from a contact-data provider — you may object to this processing or ask us to delete your details at any time by emailing privacy@getzorro.ai. We will action objections to B2B prospecting without undue delay and suppress your details from future processing.

To exercise your rights or submit a complaint, email us at privacy@getzorro.ai.

You may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9. Security

We use technical and organisational measures to protect personal data, including:

  • Encryption in transit and at rest
  • Access controls and role-based permissions
  • Monitoring and alerting for suspicious activity

10. AI assistant and MCP integrations

You can connect Zorro to an AI assistant such as Claude or ChatGPT through our Model Context Protocol (MCP) server. When you do, the assistant sends requests to Zorro on your instruction and receives the results.

  • Zorro receives the parameters of the requests the assistant makes — for example a company name, a set of search filters, or a list identifier — together with the results we return. We log these requests as described in Section 1.2.
  • The results we return to the assistant can contain personal data about people other than you: the names, roles, occupations, appointment dates, nationalities, countries of residence, month and year of birth and correspondence addresses of company directors and persons with significant control, as published on the Companies House public register; and, where you request contact enrichment, a work email address, telephone number or LinkedIn profile URL, and on your specific request a personal email address, obtained from the providers described in Section 2. Sections 4.1 and 4.2 set out the lawful basis for that processing, and Section 8 how any person can object or ask to be removed.
  • Zorro has no access to your wider conversation with the assistant, to files you have shared with it, or to any other tool you have connected to it.
  • How the assistant provider handles the conversation itself is governed by their own privacy policy, not this one.
  • Access is authorised using OAuth. You can revoke it at any time from your Zorro account, which immediately ends the connection.

Some features reachable through the connector send data to the AI providers described in Section 2 — for example drafting an outreach message or classifying a reply.

11. Changes to this policy

We may update this Privacy Policy from time to time. The latest version will always be available at getzorro.ai/privacy. We will notify you of material changes where required.

This version, September 2026, replaces the July 2026 version. No provider changed. Section 2 now describes our data sources and the categories of recipient rather than naming individual providers; the specific names remain available on request, and the cookie providers in Section 1.3 remain named. This version also discloses activities the July version omitted: officer occupation, personal email lookup on a customer's specific request, calls and their transcription, web search, and the web-page rendering service. Our website fetching now reads and obeys each site's robots.txt. Section 4 states the legitimate-interests balancing and our position on automated scoring, and no longer claims alignment with US privacy law. Section 6 states our transfer mechanism. Section 10 names ChatGPT alongside Claude and lists the personal data an assistant can receive.

Contact us
Zorro AI Ltd
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
privacy@getzorro.ai
Book a demo Available this week