Skip to content
Zovos AIZovos AI
Platform
All features13 sections · 19 pages
My work
Findings & issue managementAI agents
Compliance
Consumer complianceMonitoring & testing
Exams & regulatory change
Regulatory change managementExam & supervisory management
AML/CFT & fraud
AML/CFT program
Risk
Enterprise risk management
Third parties
Third-party risk management
Cybersecurity
CybersecurityInformation security program
Model & AI
Model & AI governance
Credit risk review
Credit risk review
Internal audit
Internal audit
Board
Board reporting
Library
Frameworks & crosswalksControls & continuous coveragePolicies & drafting
Administration
Integrations & connectors
Solutions
All solutions12 scenarios · 12 roles
By scenario
01Regulatory change managementCompliance02Exam readinessCompliance03Audit prep & evidenceInternal audit04Vendor & third-party riskThird-party risk05Policy & procedure authoringCompliance06Issue & finding managementCompliance07Control mapping (FFIEC, NIST, ISO)Compliance08Exam prep and the examiner roomCompliance09Internal audit engagementsInternal audit10Compliance monitoring & testingCompliance11Model risk managementModel & AI governance12AML/CFT program managementAML/CFT & fraud
By role
ComplianceFair lending & CRAAML/CFT & fraudEnterprise & operational riskThird-party riskCybersecurityModel & AI governanceInternal auditCredit risk reviewBoard / Supervisory CommitteeExecutive managementBusiness-line owner
IntegrationsPricingRadarDocs
Company
About usCareersContact usFind us
Request access →
Legal · Privacy

Privacy Policy

Zovos AI, Inc. ("Zovos AI," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit zovos.ai (the "Site") or interact with our products and services, including the Regulatory Radar email newsletter and any future paid offerings (collectively, the "Services").

EffectiveApril 29, 2026
Last updatedOctober 4, 2026
Plain-EnglishYes
On this page
01Who We Are02Scope of This Policy03Information We Collect04How We Use Personal Information05Legal Bases for Processing06How We Share Personal Information07International Data Transfers08Data Retention09Your Privacy Rights10Security11Email Communications and CAN-SPAM12AI and Automated Processing13Do Not Track14Changes to This Policy15Contact Us
Back to top ↑

This policy is written for our audience: compliance professionals at community banks, credit unions, and other financial institutions. We aim for the same plain-English clarity we expect from our own product.


1. Who We Are

Zovos AI, Inc. is a Texas C-Corporation headquartered in Austin, Texas. We build agentic compliance infrastructure for financial institutions of every size.

DetailValue
Legal entityZovos AI, Inc.
Mailing address5900 Balcones Drive STE 100, Austin, TX 78731, USA
Privacy contactprivacy@zovos.ai
Security contactsecurity@zovos.ai
General contacthello@zovos.ai

2. Scope of This Policy

This policy covers personal information we collect:

  • When you visit the Site
  • When you sign up for the Regulatory Radar newsletter
  • When you contact us through web forms, email, or LinkedIn
  • When you become a customer, prospective customer, or design partner of any current or future Zovos AI product
  • When you interact with us through third-party services we use (hosting, email delivery, bot protection on our forms)

This policy does not cover:

  • Personal information we process on behalf of a customer institution under a separate written agreement (such as a Master Services Agreement or Data Processing Addendum). In those cases, the customer is the controller of that data and their privacy practices govern. Zovos AI acts as a processor.
  • Third-party websites linked from our Site. Their privacy practices are their own.

3. Information We Collect

We collect the minimum information needed to deliver the Services. Specifically:

3.1 Information You Provide Directly

  • Email address. It is required for Regulatory Radar signup, contact forms, and any future product account creation.
  • Name. We collect it when you provide it on a contact form, in correspondence, or as part of a customer onboarding.
  • Institution information. This covers institution name, type (community bank, credit union, consultant, regulator, other), asset size range, state, and your role. This is voluntary and used to personalize content.
  • Communications. These are messages you send to us via email, contact forms, or other channels, including any attachments.
  • Payment and billing information. For paid Services (when offered), this is collected and processed by Stripe, our payment processor. Zovos AI does not store full credit card or bank account numbers on our own systems.

3.2 Information Collected Automatically

When you visit the Site, we automatically collect limited technical information through standard server logs:

  • IP address (truncated where feasible)
  • Browser type, browser version, and operating system
  • Referring URL and pages viewed
  • Approximate region (country and state level). We do not collect precise geolocation.
  • Date and time of access

We do not use third-party advertising trackers, cross-site behavioral advertising pixels, or session replay tools on the Site. We do not sell or share personal information for cross-context behavioral advertising.

3.3 Cookies and Similar Technologies

The Site sets no cookies and runs no analytics.

  • Theme preference. If you choose the light or dark theme, the Site remembers that choice in your browser's local storage. It stays in your browser and is not sent to us.
  • Form submissions. When you send a message through a form on the Site, it goes to our own endpoint on Amazon Web Services, which forwards it to hello@zovos.ai through Amazon SES. That relay serves the Site only. The Zovos product itself does not send email today. When you sign up for Regulatory Radar, your signup goes to our own endpoint on Amazon Web Services and is passed to Resend, the service that sends the newsletter.
  • Bot protection on forms. When you first click or tab into a form on the Site, it loads Cloudflare Turnstile to tell people from bots. Turnstile receives your IP address and signals from your browser. When you submit, our endpoint sends Cloudflare the one-time token Turnstile issued, with your IP address, to confirm it. Turnstile sets no cookie on zovos.ai.

You can clear the theme preference at any time by clearing your browser's site data for zovos.ai.

We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request from "sale" or "sharing" of personal information, even though we do not engage in either.

3.4 Information We Do Not Collect

We do not knowingly collect:

  • Sensitive personal information as defined under U.S. state privacy laws (e.g., precise geolocation, biometric identifiers, racial or ethnic origin, religious beliefs, citizenship status, genetic data, health data)
  • Government identifiers such as Social Security numbers, driver's license numbers, or passport numbers
  • Personal financial account numbers from website visitors
  • Information from children under the age of 13. The Site is not directed to children, and we do not knowingly collect children's information.

If you believe a child has submitted information to us, contact privacy@zovos.ai and we will delete it promptly.


4. How We Use Personal Information

We use personal information only for the purposes for which it was collected, and for compatible purposes consistent with this policy. Specifically, we use personal information to:

  1. Deliver the Regulatory Radar newsletter and other communications you request.
  2. Personalize content by institution type, state, or compliance focus area where you have provided that information.
  3. Respond to inquiries sent through web forms, email, or other contact methods.
  4. Operate and secure the Site, including detecting and preventing abuse, fraud, and security incidents.
  5. Improve the Services based on what people tell us in messages, signups and support requests. We do not use individual subscriber behavior to make automated decisions that produce legal or similarly significant effects.
  6. Comply with law and enforce rights, including responding to lawful requests from public authorities, complying with tax and corporate recordkeeping requirements, and enforcing our Terms & Conditions.
  7. Communicate about products that may be relevant to your role. You can opt out of marketing emails at any time using the unsubscribe link in any message. Transactional and account messages will continue.

We do not use personal information to train large language models, foundation models, or other AI systems. When we use AI to generate Regulatory Radar content, the inputs to those AI systems are publicly available regulatory materials, not subscriber data.


5. Legal Bases for Processing

We process personal information based on:

  • Your consent. This applies when you sign up for the newsletter or contact us.
  • Performance of a contract. This applies when you become a customer and we need to deliver Services.
  • Legitimate interests. These are operating and securing the Site, improving the Services, and communicating with prospects who have engaged with us in a business context. We weigh these interests against your rights and interests.
  • Legal obligations. These are tax, corporate, anti-fraud, and similar obligations.

You may withdraw consent at any time. Withdrawal does not affect processing that already occurred.


6. How We Share Personal Information

We do not sell personal information. We do not "share" personal information for cross-context behavioral advertising as defined under California, Texas, or other state privacy laws.

We share personal information only in the following limited categories:

6.1 Service Providers (Processors)

We use vendors to deliver the Services. Each is bound by a written agreement that limits their use of personal information to the services they provide to us.

We keep one current list of those vendors at zovos.ai/subprocessors.html. It shows who each one is, what it does for us, and what data it touches. That page is the maintained list, so we do not repeat it here. A second copy would only drift out of date. Customers receive 30 days notice before any new subprocessor begins processing customer data.

6.2 Legal and Safety

We may disclose personal information if we believe in good faith that disclosure is necessary to:

  • Comply with applicable law, subpoenas, court orders, or other valid legal process
  • Enforce our Terms & Conditions or other agreements
  • Protect the rights, property, or safety of Zovos AI, our customers, our subscribers, or the public
  • Investigate or prevent fraud, security incidents, or other unlawful activity

When legally permitted, we will notify affected individuals before disclosure.

6.3 Business Transfers

If Zovos AI is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction. We will require any successor to honor the commitments in this policy or provide notice and choice if material changes apply.

6.4 With Your Direction

We share personal information when you direct us to. For example, we do so when you ask us to introduce you to a partner or include your name in a public reference.


7. International Data Transfers

Zovos AI is based in the United States. If you access the Site or Services from outside the United States, your information will be transferred to, stored in, and processed in the United States. By using the Site, you consent to that transfer.

We do not currently market the Services to individuals in the European Economic Area, the United Kingdom, or other jurisdictions with comprehensive cross-border transfer requirements. If we expand to those markets, we will update this policy and implement appropriate safeguards (such as Standard Contractual Clauses) before doing so.


8. Data Retention

We retain personal information only as long as necessary for the purposes described in this policy:

Data categoryRetention period
Newsletter subscriber email and preferencesUntil you unsubscribe, plus 30 days for suppression list maintenance
Contact form submissions and email correspondenceUp to 3 years from last interaction, unless tied to an active customer relationship
Customer account informationDuration of the customer relationship plus 7 years for tax, audit, and contractual recordkeeping
Server logs (raw)90 days
Backups30 days, then automatically purged

We may retain information longer if required by law, to resolve disputes, or to enforce our agreements.


9. Your Privacy Rights

Depending on where you live, you may have rights regarding your personal information. Zovos AI honors the following rights for all U.S. residents, regardless of whether the law of your state currently grants them:

  • Access. You may request a copy of the personal information we hold about you.
  • Correction. You may request that we correct inaccurate information.
  • Deletion. You may request that we delete your personal information, subject to legal exceptions.
  • Portability. You may request a copy in a portable, machine-readable format.
  • Opt out of marketing. You may unsubscribe from our newsletter and other marketing emails at any time.
  • Opt out of "sale" or "sharing." Zovos AI does not sell or share personal information for cross-context behavioral advertising. We honor GPC browser signals.
  • Limit use of sensitive personal information. We do not collect sensitive personal information for purposes beyond those permitted by law.
  • Non-discrimination. We will not retaliate against you for exercising these rights.

9.1 How to Exercise Your Rights

Email privacy@zovos.ai with the subject line "Privacy Request" and describe what you would like us to do. We will respond within 45 days. If we need more time, we will let you know within that initial 45-day window and may extend by an additional 45 days as permitted by applicable law.

We may need to verify your identity before fulfilling certain requests. We will use the minimum information necessary to do so and will not use verification information for any other purpose.

If we deny your request, we will explain why. You may appeal by replying to our denial. We will respond within 60 days.

9.2 Authorized Agents

You may designate an authorized agent to submit requests on your behalf. We will require written proof of authorization and may verify your identity directly.

9.3 California, Texas, Virginia, Colorado, and Other State Residents

Several states have enacted comprehensive privacy laws. Whether a particular law's full obligations apply to Zovos AI depends on revenue and processing thresholds we do not currently meet. Regardless, we honor the substantive rights described above for residents of all U.S. states.

If you are a Texas resident and believe we have violated the Texas Data Privacy and Security Act, you may also file a complaint with the Texas Attorney General at https://www.texasattorneygeneral.gov/.

If you are a California resident and would like to learn more about California-specific rights under the CCPA/CPRA, contact privacy@zovos.ai.


10. Security

We take reasonable and appropriate administrative, technical, and physical safeguards to protect personal information. Current measures include:

  • TLS encryption in transit (HTTPS) on all Site traffic and API calls
  • Encryption at rest for databases and backups
  • Principle of least privilege for staff access
  • Multi-factor authentication on all administrative accounts
  • Regular dependency and vulnerability scanning
  • Vendor due diligence before adding any new processor
  • Security event monitoring and logging

No system is perfectly secure. If we discover a security incident affecting your personal information, we will notify you and applicable regulators as required by law.

To report a security vulnerability, email security@zovos.ai. We appreciate good-faith disclosures and will work with you in line with industry-standard coordinated disclosure practices.


11. Email Communications and CAN-SPAM

The Regulatory Radar newsletter and other marketing emails comply with the federal CAN-SPAM Act:

  • Every marketing email includes a clear unsubscribe link
  • Unsubscribe requests are processed within 10 business days (typically immediately)
  • Every email identifies Zovos AI as the sender and includes our valid postal address
  • We do not use deceptive subject lines or "from" addresses

Transactional emails (e.g., security alerts, billing notices for paid customers, replies to your inquiries) are not subject to unsubscribe and will continue as long as the underlying relationship is active.


12. AI and Automated Processing

Zovos AI builds AI-powered compliance tools. We are transparent about how AI interacts with personal information:

  • The Regulatory Radar newsletter uses AI to summarize and categorize publicly available regulatory documents. Subscriber personal information is not used as input to AI models.
  • We do not use personal information to train, fine-tune, or improve any AI or machine learning model, ours or a third party's.
  • We do not use AI to make automated decisions about you that produce legal or similarly significant effects.
  • For paid Services, we will provide separate, product-specific disclosures about AI processing in the applicable agreement and product documentation.

13. Do Not Track

Some browsers transmit a "Do Not Track" (DNT) signal. There is no consensus standard for how websites should respond to DNT, and we do not currently respond to DNT signals. We do, however, honor the Global Privacy Control (GPC) signal as described in Section 3.3.


14. Changes to This Policy

We may update this policy from time to time. When we do:

  • The "Last Updated" date at the top will reflect the change.
  • For material changes, we will provide reasonable advance notice. We will typically give it by email to subscribers and a prominent notice on the Site.
  • Continued use of the Site or Services after the effective date constitutes acceptance of the updated policy.

Prior versions are available on request from privacy@zovos.ai.


15. Contact Us

For any privacy question, complaint, or rights request:

Zovos AI, Inc. Attn: Privacy 5900 Balcones Drive STE 100 Austin, TX 78731 USA

Email: privacy@zovos.ai

We aim to acknowledge privacy inquiries within 5 business days. That is a separate commitment from the one for security reports, which we acknowledge within one business day when they are sent to security@zovos.ai.


This Privacy Policy is provided for transparency and to support compliance with applicable U.S. state privacy laws. It is not legal advice. Before launching paid Services or expanding into regulated processing of customer personal information, Zovos AI will engage qualified counsel to review and refine these terms.

Related
Terms & Conditions →Contact us →
PDFDownload full Privacy PolicyPDF · Letter · v1.0 · Apr 29, 2026↓

Opens a print-ready page that auto-launches your browser's Save as PDF dialog.

Regulatory change feed

Primary-source regulatory updates, in your inbox.

Once a month, Regulatory Radar covers the rule changes, economic data and AI developments that matter to your institution. Every item links to its primary source.

No spam. Unsubscribe anytime.

Zovos AI
Stay ahead of regulatory change, with your team in control.
Platform
All featuresMy workComplianceExams & regulatory changeAML/CFT & fraudRiskThird partiesCybersecurityModel & AICredit risk reviewInternal auditBoardLibraryAdministration
Company
About usCareersContact
Resources
PricingSolutions by scenarioSolutions by roleIntegrationsRadarDocsSupportSecurityStatus
© 2026 Zovos AI, Inc.
Privacy · Terms