Application Privacy Policy
Effective date 1 August 2026 · Version 1.0 · Data controller / processor Zintra LLC
This policy covers the Kerovento application. For the Kerovento website, see the website privacy notice.
1. About the application
Kerovento is a private, internally deployed web application that consolidates financial, accounting, operational and workforce data from systems a customer owns or is authorized to access, and presents it to that customer's authorized personnel as management dashboards and reporting.
1.1 Where it runs
Each instance is deployed either in infrastructure the customer controls, or in infrastructure operated by the customer’s authorized partner on the customer’s behalf. Except where a customer’s order states otherwise, Kerovento does not host the application. Where a partner hosts the deployment, that partner is responsible for the security of the infrastructure it operates, and customers should satisfy themselves as to its controls.
1.2 How it behaves
Two characteristics are central to this policy. It is read-only — it reads from connected systems and displays the result, and does not create, post, modify or delete records in any connected accounting, ERP or payroll system. It is internal-only — there is no public interface, no customer portal, no self-service sign-up and no consumer user base. Access is limited to named personnel of the customer.
2. Who we are
The Application is provided by Zintra LLC, a Florida limited liability company, under the Kerovento name. Our address and contact details are in Section 15.
2.1 Our role
For data read from a customer's connected systems, the customer is the controller and Kerovento is a processor acting on the customer's instructions. We do not decide the purposes for which that data is processed.
Where a customer’s deployment is served by an authorized partner, and that partner configures, supports, or hosts the application, the partner acts as a sub-processor. The customer’s appointment of that partner constitutes authorization, and we impose data-protection obligations on that partner equivalent to those we accept ourselves.
3. What the application accesses
Only what a customer's administrator has explicitly connected, and only the fields required for the reporting described here. The categories below are illustrative rather than exhaustive: additional connectors may be made available over time, and each is subject to the same principles of read-only access, field minimization and explicit administrator authorization. Depending on which systems a customer connects, this may include:
QuickBooks Online (Intuit Inc.) — chart of accounts, trial balance, general-ledger balances and transactions, receivable and payable balances, customer and vendor lists, invoices and bills, and related company financial records for the company files connected.
SAP Business One — sales orders and invoices, purchase documents, production and work-order data, inventory items, quantities and valuations, business-partner master records, and general-ledger and cost-center data.
Payroll and human capital management systems — employee-level workforce and payroll records. See Section 5.
Business intelligence datasets — aggregated and modelled metrics derived from the systems above, within the customer's own tenant.
Production and machine systems — machine run-time, output, downtime, changeover and scheduling telemetry. Where telemetry can be associated with a shift or operator it is treated as workforce data.
Planning and budget workbooks — budget, forecast and capacity-planning figures prepared by the customer.
4. Personal data within business records
Personal data appears inside business records: the name of an employee who entered or approved a transaction; the name, business address, business email or business telephone of a customer or vendor contact; the name of a sales representative on an order; and operator or shift identifiers on production records. This is processed as an integral part of the underlying business record, solely for internal reporting.
To operate and secure the application we also log the authenticated user identifier, date and time of access, the reports requested, and error diagnostics. These logs are used for security, troubleshooting and access control, and for no other purpose.
5. Employee and payroll data
Where a payroll system is connected, the application processes employee-level records as primary content. We apply data minimization at the connector: only the fields required for workforce and labor-cost reporting are retrieved, even where more exist in the source system.
Accessed: employee name and internal identifier; job title, department, cost center and work location; employment status, hire date and termination date; hours worked, overtime, shift and paid-time-off balances; gross pay, employer burden and fully loaded labor cost; labor cost allocated to cost center, work order or production line.
Not accessed: social security numbers and other government tax identifiers; bank account and direct-deposit details; home address, personal telephone and personal email; date of birth and demographic characteristics; health, medical, benefit-election and dependent information; disciplinary records, performance ratings and immigration status.
This data is used only to calculate labor cost, overhead absorption and cost of goods sold; to report headcount, hours, overtime and productivity by cost center and line; to support budgeting, forecasting, capacity planning and month-end close; and to support internal financial controls and audit. It is not used for individual performance management, discipline, ranking, or automated decision-making producing legal or similarly significant effects. The application does not build profiles of individual employees and does not conduct behavioral monitoring.
Access to modules containing employee-level compensation data is restricted by role to a defined group with a documented business need, enforced technically through role-based access control and contractually through the End-User License Agreement, and requires multi-factor authentication.
6. Intuit and QuickBooks Online
Access is granted exclusively through Intuit's OAuth 2.0 authorization process, initiated and approved by an administrator of the relevant QuickBooks company file. We do not request, store or use QuickBooks user names or passwords at any time.
We request read-only accounting scopes only, and only those necessary for the reporting functions described here. The application does not write to, modify or delete any record in QuickBooks Online.
We store only the OAuth access token, refresh token, realm (company) identifier and connection metadata required to maintain the connection, together with the financial data needed for reporting. Tokens are stored encrypted, are accessible only to the application's server process, and are never exposed to the browser, written to source control, or shared with any third party.
An administrator may revoke the connection at any time from within QuickBooks Online (Apps → Manage → Disconnect) or by contacting us. On revocation the application immediately ceases all access to that company's Intuit data, and stored tokens for that connection are deleted within 24 hours.
We access Intuit data through Intuit's authorized API and in accordance with Intuit's applicable developer terms and data-handling requirements, including their restrictions on the use, retention and disclosure of Intuit data. Where a security incident involves Intuit data we will notify Intuit in accordance with their developer requirements.
7. How data is used
Exclusively to generate internal financial statements, dashboards, key performance indicators and management reporting; consolidate results across a customer's entities and locations; support financial analysis, budgeting, forecasting and planning; support operational visibility; calculate labor cost and overhead absorption; support internal controls, close, reconciliation and audit preparation; and operate, secure, troubleshoot and improve the application.
We do not use it for advertising or marketing. We do not sell, rent or share it with any third party for that party's own purposes. We do not use it to train, fine-tune or develop any generally available machine-learning or artificial-intelligence model, and we do not permit any third party to do so.
8. Security
Data at rest is stored on access-controlled systems. Data in transit is protected using TLS. Connection credentials and API tokens are stored encrypted, held in environment configuration, and excluded from source control. Access is limited to authorized personnel on a need-to-know basis under role-based access control with unique named accounts; administrative access is restricted to a small number of designated individuals. Accounts with administrative or credential-management rights, and accounts with access to employee-level payroll data, require multi-factor authentication. Application access and administrative actions are logged and periodically reviewed. Access rights are reviewed periodically and revoked promptly on a change of role or termination.
No method of electronic storage or transmission is completely secure, and while we work to protect this information we cannot guarantee absolute security. We maintain an internal process for identifying, investigating, containing and remediating security incidents. Where we become aware of a personal data breach affecting a customer’s data, we will notify that customer without undue delay and in any event within 48 hours, so that the customer can meet its own obligations as controller. We will notify affected individuals and supervisory authorities directly where applicable law requires us to.
9. Retention and deletion
OAuth tokens and connection credentials are retained for the life of the connection and deleted within 24 hours of disconnection or revocation. Financial and accounting data is retained for the period the customer's retention policy and applicable tax, accounting and statutory obligations require. Employee and payroll data is retained no longer than necessary for labor-cost reporting and financial close, and not less than applicable wage-and-hour, tax and employment recordkeeping law requires; the payroll system remains the system of record. Machine telemetry is retained for operational analysis then aggregated or deleted. Access and security logs are retained for a limited period sufficient for security review, then deleted.
When a connected account is disconnected we cease all further access to it. Underlying data already used to produce financial records may be retained where necessary to preserve the integrity and auditability of financial statements already issued, under the safeguards above and not for any new purpose.
10. Disclosure
We do not sell or share data processed by the application. We disclose it only: to service providers who host or support the application, under written confidentiality and data-protection obligations and solely to operate it on the customer's behalf; to the customer's authorized implementation partner, where the customer has appointed one; to the customer's own affiliates for consolidated reporting; to the customer's auditors and professional advisors at the customer's direction; or where required by law, regulation, subpoena or other valid legal process.
11. International transfers
Where a customer operates in more than one country, data may be accessed by authorized personnel in more than one country for consolidated reporting. Where such transfers involve personal data subject to non-US data-protection or employment law, appropriate safeguards apply, including intra-group confidentiality and data-protection commitments, role-based access limits, and the controls described in Section 8.
12. Individual rights
Individuals whose personal data is processed by the application should direct requests to the customer organization that employs or engages them, which is the controller of that data. We will assist our customers in responding to such requests. Because the application is read-only, corrections are made in the source system and flow through on the next refresh.
The application is a business tool. It is not directed to children and does not knowingly process personal information relating to any individual under the age of 16.
13. Automated and AI-assisted tools
We use software development and analysis tools, which may include AI-assisted tools, in building and maintaining the application. Where used, they are used for engineering, documentation and analytical support, not as an automated decision-maker over individuals; production financial data, payroll data and credentials are not submitted to any third-party tool permitted to retain that data for its own model training; and any such tool is subject to the confidentiality and access-control requirements in Section 8.
14. Changes
We may update this policy to reflect changes in the application, its connected systems, or applicable legal requirements. Material changes will be reflected by updating the effective date and version above and notified to customers.
15. Contact
Questions, requests or concerns regarding this policy or our data practices should be directed to:
Zintra LLC
3651 Percival Ave
Miami, FL 33133
United States
Email info@zintra.de
Attention Privacy — Kerovento
This policy is governed by the laws of the State of Florida, United States, without regard to its conflict-of-laws provisions.