Privacy
Short, because we collect little.
Last updated: 24 August 2026
This notice covers the website www.zapio.ai. If you use the Zapio platform as a customer — or answer a survey built on it — that processing is covered by the product privacy policy.
1. Who we are
Zapio SRL, Avenue Louise 231, 1050 Brussels, Belgium — registered with the Belgian Crossroads Bank for Enterprises under BCE 0791.872.069 (VAT BE 0791.872.069). For anything in this notice: privacy@zapio.ai.
2. No cookies
This site stores nothing on your device — no cookies, no local storage, no fingerprinting. That's why there is no cookie banner: there is nothing to consent to. If you leave and come back tomorrow, we genuinely don't know it's you.
3. What we do measure
We keep anonymous usage statistics — which sections get read, where visitors stop, which buttons get clicked — through PostHog, processed and stored in theEuropean Union (Frankfurt). These events aren't linked to your identity, and we use them for one thing: making this site better. Legal basis: our legitimate interest in understanding how the site is used (Art. 6(1)(f) GDPR).
4. Which network you visit from
Alongside those statistics we record the name of the network a visit comes from— the organisation that owns the block of internet addresses your connection belongs to. For a visitor at work in a large company that is often the company itself; for everyone else it is simply their internet provider or mobile operator. We use it for one thing: knowing which kinds of organisation read this site. Your IP address is never stored — the network name is read at the edge and the address is discarded — and it identifies a connection, never a person. Legal basis: our legitimate interest in understanding who this site reaches (Art. 6(1)(f) GDPR).
5. Session replays and heatmaps
Within the same PostHog account, we record anonymous replays of visits to this site: a reconstruction of what the page did and how it was used — scrolling, mouse movement, clicks — so we can see where the site loses people. Anything typed into a field is masked in your browser before it is sent, and the booking calendar is excluded. Clicks and mouse positions are also aggregated into heatmaps. None of it is linked to your identity, it is stored in the EU with the rest, and it is deleted automatically after 30 days. Legal basis: our legitimate interest in understanding how the site is used (Art. 6(1)(f) GDPR) — write to us at the address below if you would rather not be recorded.
6. If you book a call
The calendar on this site is run by Cal.com, Inc. (US, under EU Standard Contractual Clauses). When you book, you give a name, an email address and a time slot — we use them to hold the meeting and follow up on it, nothing else. The resulting calendar entry and email thread live in our Google Workspace and are kept as ordinary business correspondence. Legal basis: taking steps at your request prior to a contract (Art. 6(1)(b) GDPR).
7. Where the site runs
The site is static and served by Cloudflare's edge network. Fonts are self-hosted — visiting this site triggers no requests to Google or any other font or advertising service.
8. Your rights
Under the GDPR you can ask us for:
- access to the data we hold about you (Art. 15) — for most visitors, the honest answer will be "none";
- correction (Art. 16) or deletion (Art. 17) of it;
- a copy in a portable format (Art. 20);
- or object to a processing (Art. 21).
Write to privacy@zapio.ai — we answer within a month. You can also complain to the Belgian supervisory authority, the APD/GBA.
9. Changes
If this notice changes, the date at the top changes with it. We won't quietly start collecting more than this page says.