ZebOS

Privacy Policy

Effective 29 August 2026 · Last updated 30 August 2026

ZebOS is a finance and operations platform for investment managers and their advisers. It brings bookkeeping, budgeting, fund administration, compliance, CRM and email into one workspace, and connects to the systems where that work already lives.

This policy explains what personal data ZebOS processes, why, who it is shared with, and the rights you have. It covers the ZebOS web application at zebos.ai and the services behind it.

1. Who we are

Soderman Consulting Ltd ("we", "us") is the provider of ZebOS and the data controller for the purposes described in section 3. We are registered in England and Wales, company number 13423641, registered office 3a Ridley Road, London, NW10 5UB.

For privacy questions, requests or complaints, contact privacy@zebos.ai.

2. Who this policy is for

3. Controller and processor

The two roles matter because they decide who you go to with a request.

DataOur role
Account and sign-in details, billing, support correspondence, product usage analyticsController — we decide why and how it is processed
Everything inside a customer's workspace: mailbox contents, accounting records, invoices and receipts, CRM records, documents, tasksProcessor — the customer decides, we process on their documented instructions

Where we are a processor, our processing is governed by our agreement with that customer. If you are a customer and require a data processing agreement, contact us at the address above.

4. What data we process

Account data

Name, email address, hashed password or federated sign-in identifier, the companies and modules you have access to, your role, and invitations you send or accept.

Mailbox data

Where you connect a mailbox, we process message headers, addresses, subjects, bodies, snippets, labels, attachment metadata, thread structure and, for Gmail, message and history identifiers. Section 5 covers Google data specifically.

Accounting and financial records

Where you connect Xero or QuickBooks, or upload documents, we process invoices, bills, receipts, line items, nominal codes, contacts and suppliers, bank accounts and transactions, journals, trial balances, budgets, forecasts and headcount records. Headcount records may include salary, pension and benefit figures for named individuals, which the customer supplies.

CRM and relationship data

People and company records, email addresses, job titles, interaction history and connection strength derived from correspondence you took part in.

Fund and compliance records

Fund structures, limited partner records and capital accounts, portfolio company and valuation data, compliance obligations, registers and tasks.

Technical and usage data

IP address and approximate location derived from it, browser and device information, pages and features used, and timestamps. We use this to operate the service, investigate faults and understand which features are used.

5. Google user data

ZebOS accesses Google data only after you explicitly connect a mailbox, and only for the mailbox you connect. You can disconnect it at any time from CRM settings or Communication settings.

ScopeWhat it allowsWhat ZebOS does with it
gmail.readonlyRead messages and labelsImport threads so they can be read, searched, triaged and shown against a CRM record
gmail.modifyRead and change messages and labels, short of permanent deletionApply the label in Gmail that matches the category you choose in ZebOS, so both stay in step
gmail.sendSend mail as youSend a reply you have written and chosen to send from within ZebOS
gmail.settings.basicRead and write basic mailbox settingsRead your Gmail signature and keep it in step with the one set in ZebOS
userinfo.emailRead your email addressIdentify which mailbox was connected

ZebOS never permanently deletes anything in your mailbox. Replies drafted with AI assistance are always presented to a person for review and are never sent automatically.

Limited Use disclosure

ZebOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we do not use Google user data to serve advertising, we do not sell it, and we do not use or transfer it to develop, improve or train generalised artificial intelligence or machine learning models. We transfer it only to the sub-processors listed in section 8, and only as necessary to provide or improve the features you have asked for, to comply with applicable law, or as part of a merger or acquisition, in which case we would give notice first. Human beings do not read your Google data except where you have given specific consent, where it is necessary for security purposes or to investigate a fault you have reported, where the law requires it, or where the data has been aggregated and anonymised for internal operations.

6. Artificial intelligence in ZebOS

Some ZebOS features use AI models operated by third parties. We are explicit about this because it involves sending your content outside our own systems.

FeatureWhat is sentProvider
Invoice and receipt extractionThe document image or textOpenAI
Similar-invoice matching and nominal code suggestionsInvoice text and vector embeddings of itOpenAI
Email topic classification and suggested repliesMessage subjects and bodies from the thread, and the procedures you have writtenAnthropic
Internal prompt-quality suggestionsAnonymised extraction prompts and correction patterns, not customer documentsOpenAI, OpenRouter

These providers process the content to return a result to you and are contractually restricted from using it to train their models. AI output is a suggestion. Classifications can be corrected, and a suggested reply is a draft a person reads, edits and sends. Nothing is sent, filed or posted to an accounting system on the strength of an AI output alone.

AI features can be switched off per company and per mailbox in ZebOS settings.

7. Why we process data, and our lawful bases

PurposeLawful basis
Providing the service you or your organisation has signed up forPerformance of a contract
Keeping the service secure, investigating faults, preventing abuseLegitimate interests — running a secure and reliable service
Improving features and understanding which are usedLegitimate interests — improving a product our customers rely on
Accessing a connected mailbox or accounting systemYour consent, given at the point of connection and withdrawable at any time by disconnecting
Meeting our own legal, accounting and regulatory obligationsLegal obligation

Where we act as a processor, the lawful basis for the underlying data is the customer's to determine.

8. Who we share data with

We do not sell personal data and we do not share it for advertising. We use the following sub-processors to run the service.

Sub-processorPurposeLocation
SupabaseDatabase, file storage, authentication, server-side functionsLondon, United Kingdom (eu-west-2)
CloudflareHosting and delivery of the web applicationUnited States, with global edge delivery
GoogleGmail access for connected mailboxesUnited States and global
XeroAccounting data for connected organisationsUnited States and New Zealand
Intuit (QuickBooks)Accounting data for connected companiesUnited States
OpenAIDocument extraction, embeddings, coding suggestionsUnited States
AnthropicEmail classification and suggested repliesUnited States
OpenRouterRouting for internal prompt-quality suggestionsUnited States
ResendTransactional and system alert emailUnited States

We may also disclose data where the law requires it, to establish or defend legal claims, or to a buyer as part of a sale or reorganisation of our business, in which case we would notify affected customers first.

9. International transfers

Your workspace data is stored in the United Kingdom. Some sub-processors listed above are outside the UK. Where data is transferred internationally we rely on the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or on UK adequacy regulations where they apply, together with the supplementary measures described in section 10.

10. How we protect data

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, and notify you where the risk is high.

11. How long we keep data

12. Your rights

Under UK data protection law you have the right to access your personal data, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict or object to processing, to data portability, and to withdraw consent where consent is the basis we rely on. Withdrawing consent does not affect processing carried out before you withdrew it.

To exercise any of these, email privacy@zebos.ai. We will respond within one month. If your data sits inside a customer's workspace, we will pass your request to that customer and support them in answering it.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or by calling 0303 123 1113. We would rather you came to us first so we can put it right.

13. Cookies and analytics

ZebOS sets only the cookies and local storage entries needed to keep you signed in and to remember your workspace and interface preferences. We do not use advertising cookies and we do not use third-party tracking or advertising networks. We record product usage events, including IP-derived approximate location, to operate and improve the service; these are held in our own database rather than shared with an analytics vendor.

14. Children

ZebOS is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.

15. Changes to this policy

We will update this page when the service changes. The effective date at the top always reflects the current version. Where a change materially affects how we use personal data, we will tell account holders by email before it takes effect.