Effective Date: November 7, 2025
Last Revised: November 7, 2025
Previous Versions: This is the first version
Legal Entity & Address: Metrix Zenith X Artificial Intelligence; IFZA Business Park – Dubai Silicon Oasis – Dubai – United Arab Emirates
Privacy Contact: privacy@mzx.ai
EU/UK Representative:
This Privacy Policy explains how Metrix Zenith X Artificial Intelligence (“MZX AI,” “we,” “us,” or “our”) collects, uses, shares, and safeguards personal information when you use our websites, portals, and services that link to this Policy (collectively, the “Services”), including:
This Policy does not alter terms in any agreement between MZX AI and its enterprise customers. Where those terms conflict with this Policy, the agreement controls with respect to Customer Content.
We use cookies and similar tools for authentication, preferences, analytics, and performance. See our Cookie Notice for details and controls.
We may de-identify or aggregate information (removing direct identifiers) and use it for analytics, benchmarking, and improving the Services.
We do not perform automated decision-making that produces legal or similarly significant effects.
Where the GDPR/UK GDPR applies, we rely on:
We do not sell personal information.
Depending on your location, you may have rights to access, correct, delete, restrict, object, or port your personal information, and to withdraw consent where processing is based on consent. To exercise rights, contact us (Section 13). We may verify your identity and, where applicable, direct you to your organization’s administrator.
U.S. State Notices (e.g., CA/CO/VA/CT/UT). See our U.S. State Privacy Notice for state-specific disclosures and opt-out mechanisms (e.g., targeted advertising).
We may process data in countries that may have different data protection laws than your home jurisdiction (e.g., transfers to the U.S.). Where required, we use appropriate safeguards such as Standard Contractual Clauses and supplementary measures. Details available upon request.
We implement technical and organizational measures aligned with industry practices, including encryption in transit and at rest, least-privilege access, logging/monitoring, and vulnerability management. No system is perfectly secure; we cannot guarantee absolute security.
Our Services are not intended for individuals under 18. If you believe a child has provided personal information, contact us and we will delete it as required by law.
We keep personal information only as long as necessary for the purposes described above or as required by law.
Default retention parameters (subject to customer configuration and legal requirements):
We may retain de-identified or aggregated data for longer.
If you are an enterprise end user, please contact your organization first for requests about Customer Content processed under our agreement.
We may update this Policy from time to time. If we make material changes, we will update the “Effective Date” above and provide additional notice where required. Your continued use of the Services after the effective date means you acknowledge the updated Policy.
| Purpose | Categories | Legal Basis |
|---|---|---|
| Service delivery & account administration | Contact, account, device/log data, Customer Content | Contractual necessity |
| Security, fraud prevention, and misuse detection | Any relevant categories | Legitimate interests; legal obligation where applicable |
| Product improvement & analytics | De-identified/aggregated data, device/log data, limited usage metrics | Legitimate interests; consent for optional cookies |
| Marketing to business contacts | Contact & preference data | Legitimate interests; consent where required |
| Compliance (tax, accounting, legal requests) | Billing/transaction data; any as required | Legal obligation |
This section applies only to individuals located in the European Economic Area (“EEA”) and the United Kingdom (“UK”) and supplements the MZX AI Privacy Policy.
For personal data we collect and process in connection with our websites, marketing, trials/demos, accounts, and billing, Metrix Zenith X Artificial Intelligence (“MZX AI”) is the controller.
For Customer Content (e.g., files, attachments, generated content and files) that we process on behalf of an enterprise customer inside
its tenant, MZX AI generally acts as a processor (service provider). In that case, the enterprise customer is the controller. Please contact your organization first for requests about Customer Content.
You may contact our EU/UK representatives for matters related to GDPR/UK GDPR.
We process your personal data only where a legal basis applies:
| Purpose | Examples of Data | Legal Basis |
|---|---|---|
| Service delivery & account administration | Contact details, account credentials, device/log data, Customer Content metadata | Contractual necessity |
| Security & fraud prevention | IP address, logs, telemetry, abnormal activity indicators | Legitimate interests; legal obligation where applicable |
| Product improvement & analytics | De-identified/aggregated metrics, device/log data, cookie data (where applicable) | Legitimate interests; consent for optional cookies/analytics |
| Marketing (B2B) | Work email, name, role, preferences | Legitimate interests; consent where required |
| Compliance | Billing/transaction data; records required by law | Legal obligation |
Training notice. We do not use Customer Content to train foundation models unless you explicitly opt in.
We may transfer personal data outside the EEA/UK (e.g., to the United States). Where we do so, we implement appropriate safeguards such as the EU/UK Standard Contractual Clauses and, where relevant, supplementary measures. You can request a copy or summary of the applicable
safeguards by contacting us at privacy@mzx.ai.
Subject to conditions and exemptions in the GDPR/UK GDPR, you have the right to:
How to exercise your rights. Contact us at privacy@mzx.ai. We may need to verify your identity. If we process your data as a processor for your organization, we will direct your request to the relevant controller (your organization).
We do not engage in automated decision-making, including profiling, that produces legal or similarly significant effects.
Our Services are not designed to process special categories of personal data (including and not limited to, health, biometric, racial/ethnic origin, political opinions). We request that you do not intentionally submit this information. If we become aware that we have inadvertently processed such data, we will take steps to securely delete it or otherwise treat it in accordance with legal requirements.
We retain personal data only for as long as necessary for the purposes described in our Privacy Policy or as required by law (see Retention section). Customer-configurable deletion schedules may apply to Customer Content.
If you believe our processing of your personal data infringes GDPR/UK GDPR, you have the right to lodge a complaint with your local supervisory authority.
You may also contact us first at privacy@mzx.ai and we will do our best to resolve your concern.
Contact (EU/UK matters):
Copyright © 2025 MZX.AI