Your data is our responsibility.
16 formal security policies. End-to-end encryption. ISO 27001 alignment. Here is how we protect what belongs to you.
Documentation.
Public policies, processing agreements, and internal security documentation.
Privacy Policy
How we collect, use, and protect your personal information.
Terms of Service
The terms governing your use of Zeyntra's platform and services.
Cookie Policy
How we use cookies and similar tracking technologies.
Acceptable Use Policy
What is and isn't permitted on our platform.
Data Processing Agreement
How we process personal information on behalf of our customers.
Security Overview
High-level summary of our security practices and compliance posture.
Information Security Policy
Our comprehensive security governance framework aligned to ISO 27001:2022.
Identity and Access Management Policy
How we manage authentication, authorization, and access lifecycle.
Access Control Policy
Rules governing who can access what, and under which conditions.
Incident Response Policy
How we detect, respond to, and recover from security incidents.
Business Continuity and DR Plan
How we maintain operations and recover from disruptions.
Data Classification and Handling
How we categorize and handle data based on sensitivity.
Cryptography Policy
Standards for encryption, key management, and cryptographic controls.
Secure Development Policy
How we build and deploy secure software.
Third-Party Management Policy
How we assess and manage vendor and partner risk.
Risk Management Policy
Our framework for identifying, assessing, and mitigating risk.
Security controls.
The measures we maintain to protect your data.
Encryption at Rest
All stored data encrypted with AES-256.
Encryption in Transit
All data transmitted over TLS 1.3.
Multi-Factor Authentication
MFA enforced for all admin and production access.
Role-Based Access Control
Least-privilege access based on documented business need.
Continuous Monitoring
Automated alerting for suspicious access patterns.
Vulnerability Management
Regular scanning, patching, and penetration testing.
Automated Backups
Encrypted backups with tested recovery procedures.
Employee Security
Background checks, training, and 24-hour departure revocation.
Environment Isolation
Production, staging, and dev fully separated.
Regional Hosting Priority
Infrastructure hosted in-region where available.
Data practices.
What we collect
- Name, date of birth, government IDs
- Email, phone, mailing address
- Financial information (for screening and PAD)
- Rental history and lease details
How we store it
- Encrypted at rest (AES-256) and in transit (TLS 1.3)
- Canadian-hosted infrastructure where available
- Automated encrypted backups
- Full environment separation
Who can access it
- Authorized personnel with RBAC and documented need
- MFA required for all administrative access
- Monthly and quarterly access reviews
- No shared accounts permitted
Your rights
- Access your personal information
- Correct inaccurate data
- Request deletion (subject to legal retention)
- Withdraw consent at any time
Sub-processors.
Categories of third parties that process data on our behalf. Zeyntra is vendor-agnostic.
Credit Bureau Services
Credit checks and credit reporting
Equifax, TransUnion, Experian
Name, DOB, SIN, credit data
Canada
Identity Verification
Document and biometric verification
Plaid, Veriff, Persona
ID documents, biometric data
Canada, US, EU
Payment Processing
Pre-authorized debit and payment facilitation
Stripe, Plaid, Flinks, Rotessa
Banking info, transaction data
Canada
Cloud Infrastructure
Application hosting and data storage
AWS, Supabase, GCP
Encrypted application data
Canada, US
Communication Services
Transactional email and notifications
Resend, Twilio
Email, phone number
US
Analytics and Monitoring
Product analytics and error tracking
Mixpanel, Sentry
Anonymized usage data
US