Data Protection

Safeguarding Your Data with Integrity and Accountability

At Confluence by Zizo, data protection is fundamental to how we design, operate and evolve our platform.

We recognise that organisations entrust us with sensitive, operational and regulated data. Our responsibility is to ensure that information is processed securely, transparently and in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and relevant EU GDPR requirements.

Data security is not an add-on. It is embedded into our architecture and operational processes.

Our Data Protection Principles

We are committed to the following core principles:

Lawfulness, Fairness & Transparency

We process data in a lawful and transparent manner, ensuring organisations understand how their data is handled within the Confluence platform.

Purpose Limitation

Data is processed solely for agreed and legitimate business purposes.

Data Minimisation

We support structured data handling practices that limit unnecessary exposure of personal or sensitive information.

Accuracy

We provide tools that support validation, review and correction to maintain data integrity.

Storage Limitation

Data retention policies can be aligned with organisational and regulatory requirements.

Integrity & Confidentiality

Robust technical and organisational safeguards are in place to protect against unauthorised access, alteration, disclosure or loss.

Secure Architecture by Design

Confluence is built on Zizo’s high-performance, schema-flexible data engine, engineered with security at architectural level.

Key protections include:

Role-based access control (RBAC)

Environment segregation

Controlled execution pathways for AI-generated queries

Secure data interaction layers

Audit-friendly traceability

This ensures that access to data is appropriately restricted and monitored.

AI & Data Protection

AI integration must not compromise privacy or compliance.

Confluence addresses this through:

Human-in-the-loop validation before operational deployment

Transparent AI-generated logic

Segregation between draft and production workflows

Controlled prompt execution environments

Configurable governance controls

AI accelerates insight — but data protection remains constant.

Data Hosting & Infrastructure

Our infrastructure is designed to support secure, enterprise-grade deployment.

We implement:

  • Secure hosting environments
  • Encrypted data transmission
  • Access management controls
  • Regular system monitoring
  • Controlled infrastructure updates

Specific hosting and regional deployment details can be provided upon request to support compliance reviews.

Data Subject Rights

Where personal data is processed within customer environments, Confluence supports organisations in meeting their obligations under UK GDPR and related legislation, including:

Human-in-the-loop validation before operational deployment

Transparent
AI-generated logic

Segregation between draft and production workflows

Controlled prompt execution environments

Configurable governance controls

As a platform provider, we operate in alignment with customer-defined data governance frameworks.

Organisational Safeguards

In addition to technical controls, we maintain organisational safeguards including:

  • Controlled access to internal systems
  • Security-aware development practices
  • Defined data handling procedures
  • Incident response processes
  • Ongoing review of security controls

Data protection is integrated across engineering, product and operational functions.

Incident Response & Transparency

In the unlikely event of a data security incident, we maintain structured response procedures designed to:

  • Identify and contain the issue rapidly
  • Assess scope and impact
  • Notify relevant parties where required
  • Implement corrective measures

Transparency and accountability guide our response approach.

Supporting Regulated Sectors

Confluence is designed to support organisations operating in data-sensitive and regulated industries, including:

  • Maritime
  • Freight and logistics
  • Infrastructure management
  • Research and development
  • MedTech

Where compliance and governance standards are high, data protection cannot be optional.

Continuous Improvement

Data protection is not static. As regulatory frameworks evolve and technology advances, we continually review and enhance our controls to ensure alignment with best practice and legal requirements.

We remain committed to responsible innovation — particularly in the context of AI-enabled data systems.