Legal
Privacy Policy
Last Updated: 1 October 2026
This Privacy Policy ("Policy") describes how personal data and confidential business records are collected, utilized, processed, stored, and protected by AgileOps, a sole proprietorship established under the laws of The Commonwealth of The Bahamas, doing business as Zirano (which, upon corporate conversion or incorporation, includes its corporate successor entity, parent, or subsidiaries; collectively, "Zirano", "AgileOps", "we", "us", or "our"), through the Zirano Finance bookkeeping application hosted at app.zirano.finance and our website at zirano.finance (collectively, the "Service").
We are dedicated to respecting personal privacy and protecting commercial financial confidentiality. We structure our data processing operations to comply with the statutory principles of The Bahamas’ Data Protection (Privacy of Personal Information) Act, 2003 ("DPA 2003"), as amended, and recognize recognized international standards for cross-border data handling where applicable.
1. Fundamental Privacy Commitments
- No Data Commercialization: We do not sell, rent, monetize, lease, or trade your personal data, business ledgers, or customer contacts to third parties or marketing networks.
- No Invasive Trackers: We operate no third-party behavioral analytics, ad retargeting pixels, social media widgets, or consumer tracking beacons within our web application or website.
- Statements Read in Your Browser: Bank and card statements (PDF or CSV) and supplier bill PDFs are read within your browser, as text; scanned images are not read. Only the transaction lines you choose to import are stored on our servers, together with the statement's column layout so that the next statement from the same bank reads automatically. A bill PDF is stored only if you attach it to the bill.
- Zero Financial Credential Retention: We never inspect, handle, or store credit card numbers, debit card PANs, banking PINs, or Kanoo login credentials. Checkout and digital wallet processing occur directly on Kanoo's regulated payment platform.
- No Model Training on Customer Ledgers: We do not train, fine-tune, or instruct artificial intelligence models on your ledger data or proprietary financial records.
2. Categories of Data Collected and Processed
| Category | Specific Elements | Source | Lawful Basis & Purpose |
|---|---|---|---|
| Account Data | Email address, full name, workspace administrative role, authorized session tokens, and the record of when you accepted these policies. For twenty-four (24) hours, the email addresses to which sign-in codes were sent. | Provided directly by you or via workspace administrator invitation. | Performance of contract; identity verification; tenant security; preventing abuse of sign-in. |
| Enquiries | Name, email address, company, topic and message sent through the contact form on our website. | Provided directly by you. | Legitimate interest; responding to your enquiry. |
| Problem Reports | Your description of a problem, an optional screenshot (which may show figures from your workspace), the screen you were on, your browser and window size, and any error message shown. | Sent by you through "Report a problem" in the application. | Legitimate interest; fixing the problem and replying to you. |
| Bookkeeping Ledgers | Reconciled bank lines, income/expense classifications, sales invoices, bills, quotes, purchase orders, asset registries, VAT summary worksheets. | Uploaded, synchronized, or approved by your authorized workspace users. | Performance of contract; core bookkeeping functionality. |
| Contact Data | Names, corporate designations, emails, physical addresses, telephone numbers, and Tax Identification Numbers (TINs) of your clients/suppliers. | Supplied directly by you when issuing billing or recording receipts. | Performance of contract; dispatch of user-generated business documentation. |
| Source Attachments | PDF receipts, images of supplier bills, corporate logos. | Uploaded directly by your team to substantiate transactions. | Performance of contract; audit trail maintenance. |
| Adam AI Prompts | Natural-language conversational queries, ledger context sent to Adam, Adam's generated suggestions. | Supplied interactively by you during conversational sessions. | Performance of contract; providing assistive productivity workflows. |
| Billing Records | Current plan tier, payment history, renewal dates, Kanoo order references, transaction hashes. (No raw payment cards). | Transmitted via Kanoo webhooks and user subscription selections. | Legal obligation; accounting; contractual fulfillment. |
| Technical Metadata | Internet Protocol (IP) addresses, browser user-agent, operating system, server access error logs. | Automatically recorded by network and edge hosting infrastructure (e.g., Vercel). | Legitimate interest; platform security; threat mitigation. |
3. Purpose and Legal Grounds for Processing
We process personal data solely under legitimate legal bases recognized under Bahamian and international privacy frameworks:
- Contractual Necessity: To instantiate workspaces, maintain double-entry bookkeeping journals, compile Bahamian VAT summaries, and send platform-generated invoices to your designated recipients.
- Consent: Where you affirmatively elect to forward an accounting or tax inquiry to an independent Partner Firm through our platform.
- Legitimate Interests: To prevent software abuse, investigate platform performance degradations, maintain multitenant isolation, and protect network infrastructure.
- Statutory Compliance: To satisfy corporate recordkeeping, tax documentation, and regulatory audit mandates under Bahamian law.
4. Technical Sub-Processors and Data Distribution
We partner only with cloud infrastructure and application service providers that maintain strict industry-standard technical security practices. We share only the minimum data necessary for each provider to perform its function:
| Provider | Operational Role | Data Transmitted | Data Location |
|---|---|---|---|
| Convex Inc. | Scalable relational backend and operational database. | All workspace ledgers, account records, and application data. | United States (US East / Northern Virginia). |
| Vercel Inc. | Application deployment, static asset distribution, edge routing. | Network requests, IP addresses, browser headers. (Stores no ledger data). | Global CDN distribution network. |
| Resend Inc. | Transactional email transmission (sign-in OTPs, invoice delivery). | Recipient email addresses, message body text, invoice attachments. | United States. |
| Anthropic, PBC | Enterprise artificial intelligence model hosting (powers Adam). | User query text and specific ledger extracts required to formulate responses. (Covered by commercial terms barring model training). | United States. |
| Kanoo (CaribPay Ltd.) | Regulated electronic payment gateway and wallet processing. | Order references, payment amounts, workspace identifier. Kanoo collects card/wallet data directly. | The Bahamas. |
| Google Fonts | Dynamic loading of optimized typography. | Technical IP address and browser header upon browser asset request. | Global network. |
4.1 Bookkeeping Partners
If your workspace registered through an authorized Bookkeeping Partner referral link, your workspace name, subscription status, and payment totals are reflected on the partner's quarterly statement to compute their referral revenue share. Partners cannot access, view, or modify your financial ledgers or books unless you deliberately add them as an authorized user to your workspace.
4.2 Cross-Border Data Transfers
By accessing the Service, you acknowledge and agree that your data is hosted and processed on secure cloud infrastructure located in the United States and global edge servers. We select sub-processors that maintain recognised security certifications (such as SOC 2) and encrypt data at rest and in transit.
5. Internal Access Controls and Staff Oversight
AgileOps operates under a strict principle of least privilege. Internal technical personnel access production databases and customer workspaces solely under the following limited conditions:
- To diagnose and resolve an explicit technical bug or support ticket raised by the workspace Owner;
- To investigate, defend against, or mitigate platform security breaches or system errors;
- In compliance with a legally enforceable warrant, subpoena, or order issued by a court of competent jurisdiction in The Commonwealth of The Bahamas.
Administrative actions we take on billing and workspace records (such as recording refunds, granting plans, and deleting workspaces) are recorded with their date, reason and the staff member who took them.
6. Browser Storage, Cookies, and Local State
We avoid tracking or commercial advertising cookies. The Service utilizes browser local storage and essential session tokens solely to preserve:
- Active authentication tokens (to keep you securely signed in);
- Last-visited workspace, active ledger view, and display preferences;
- The referring bookkeeping partner's link, kept until your workspace is created.
Users may clear browser cookies and local storage at any time; doing so simply logs you out of the application.
7. Data Retention, Archival, and Deletion Lifecycle
- Active Subscription Retention: We retain workspace ledgers and associated documentation for as long as your workspace remains registered and open (including during active trials, paid tiers, and the Free Plan).
- Workspace Deletion Procedure: When an Owner initiates workspace deletion:
- The workspace becomes instantly inaccessible to all members;
- Live application database records are retained for a seven (7) day recovery buffer (during which the Owner may request restoration);
- Upon day seven (7), data is permanently purged from production databases;
- Residual data completely purges from rolling encrypted backups within ninety (90) days.
- Account Deletion: Account deletion requests are completed within thirty (30) calendar days, subject to the resolution of any sole-owned active workspaces.
- Problem Reports: Problem reports and their screenshots are seen only by Zirano's team. They are deleted twelve (12) months after the problem is resolved, or earlier with the workspace or your account.
- Statutory Accounting Retention: We retain billing history, invoices, payment transaction hashes, and related commercial records for a minimum of seven (7) years to satisfy Bahamian statutory commercial and tax record retention requirements.
8. Statutory Rights under the Bahamian DPA 2003
Under the Bahamian Data Protection (Privacy of Personal Information) Act, 2003, and international data protection standards, you have the following rights:
- Right of Access & Portability: You may export your reports, ledgers and contacts in structured CSV format at any time directly in the application (for example, from Reports, the accountant view and Contacts). On request, we will provide a full export of your workspace.
- Right of Rectification: You may correct inaccurate or incomplete ledger data directly inside the application. For administrative credentials, you may submit an update request to privacy@zirano.finance.
- Right of Erasure ("Right to be Forgotten"): Workspace Owners may permanently purge their workspaces. Non-owner users may request removal from workspaces.
- Right of Inquiry and Complaint: Inquiries or complaints regarding our data handling practices may be addressed to our privacy officer at privacy@zirano.finance. We review and respond to formal requests within thirty (30) calendar days.
9. Technical and Organizational Security Measures
We implement multi-layered administrative, technical, and physical safeguards:
- Encryption Standards: All data in transit across public networks is encrypted using Transport Layer Security (TLS, the protocol behind HTTPS). Data at rest within our cloud databases and object stores is encrypted by our hosting providers using industry-standard algorithms.
- Tenant Isolation: Multi-tenant databases strictly enforce workspace-level authorization barriers at the query level, preventing cross-tenant leakage.
- Passwordless Authentication: The elimination of static, reusable passwords eliminates credential-stuffing vulnerabilities.
- Data Breach Protocols: In the event of a confirmed security breach compromising personal data, we will notify affected workspace Owners without undue delay, and within seventy-two (72) hours of technical verification, providing details regarding the nature of the breach and our mitigation response.
10. Children’s Privacy
Zirano is strictly a commercial business-to-business (B2B) enterprise accounting tool. We do not knowingly solicit, process, or collect personal information from individuals under the age of eighteen (18).
11. Corporate Restructuring and Assignment
In the event that AgileOps undergoes corporate restructuring, transformation, conversion, or formal incorporation into a Bahamian or foreign corporate body, or enters into a merger, asset sale, or transfer of software operations, your personal data and Customer Data will be assigned and transferred to the continuing corporate entity. The successor entity shall remain legally bound to process your personal data in strict compliance with the material terms of this Privacy Policy.
12. Policy Revisions
We reserve the right to amend this Policy to reflect operational, technical, or legal changes. We will provide registered workspace Owners with at least thirty (30) days' advance electronic notice via email prior to the effective date of any material modifications.
13. Privacy Contact Information
For inquiries, statutory data requests, or compliance notices:
AgileOps Privacy Officer
Nassau, New Providence, The Commonwealth of The Bahamas
Direct Email: privacy@zirano.finance