Controller
TestZombie AI
QA Agile OOD
Verila 5
1463 Sofia, Bulgaria
Email: privacy@testzombie.ai
General information
Protecting personal data is important to us. This privacy policy explains which data we process when operating our website and platform, why we process it and which rights data subjects have.
Data processed when visiting the website
When you access our website, technically necessary access data is processed to deliver content, ensure stability and prevent misuse.
- IP address
- date and time of access
- requested page or file
- referrer URL
- browser type, operating system and device information
- HTTP status and amount of data transferred
Registration, user account and login
When registering and using an account, we process the data required to create, authenticate, manage and bill the account.
- name and business email address
- company and workspace assignment
- encrypted credentials or external identity attributes
- roles, permissions and account status
- login, security and session information
Processing of test automation data
TestZombie processes technical information generated during automated software testing. Processing is not limited to a specific framework such as Selenium and may include different test and application data depending on the integration.
- element selectors such as XPath, CSS, ID or name
- DOM structures, HTML snippets and technical page properties
- screenshots or visual comparison data, where enabled
- error messages, stack traces and execution logs
- test run, browser, device and operating system metadata
- healing events, element histories and change detection
- AI analyses, fix recommendations and code suggestions
- test metrics, timestamps and quality indicators
This data is processed solely to perform healing operations, detect changes, create technical recommendations and provide analyses and reports within the relevant workspace. It is not used for advertising or to create marketing profiles.
AI-assisted processing and confidentiality
Where AI features are used, the technical data required is processed only to provide the requested analysis or recommendation. Customer data remains assigned to the relevant workspace.
- no use of customer data to train public or general-purpose AI models
- no disclosure for marketing or advertising
- no publication of test data or source-code content
- access only by authorised systems and, where necessary, authorised personnel
- external providers used only on a contractual and data-protection-compliant basis
Enterprise SSO and external identity providers
When signing in through an external identity provider, particularly Microsoft Entra ID, we receive identity data approved by the relevant organisation, such as name, business email address, tenant ID and technical user identifier. Identity-provider passwords are never transmitted to TestZombie.
Contact, enquiries and support
When you contact us, we process your name, email address, enquiry content, attachments and the related support history. Processing is carried out to answer the request, perform a contract or pursue our legitimate interest in reliable customer communication.
Payment processing and billing data
For paid services, we process contract, invoice and transaction data. Where a payment provider is used, it receives the data required to process payment. TestZombie does not store complete credit-card details.
Purposes and legal bases
Processing is based in particular on performance of a contract and pre-contractual measures under Art. 6(1)(b) GDPR, legal obligations under Art. 6(1)(c) GDPR, legitimate interests under Art. 6(1)(f) GDPR or consent under Art. 6(1)(a) GDPR.
Processors / third parties
We may use hosting, infrastructure, email, support, payment or AI providers as processors to deliver our services. Where required, data processing agreements under Art. 28 GDPR are concluded. Transfers to third countries take place only where legal requirements and appropriate safeguards are met.
Retention and deletion
We retain personal data only for as long as necessary for the relevant purpose, contract performance or statutory retention obligations. Once the purpose no longer applies, data is deleted or anonymised unless legal obligations or legitimate reasons require continued retention.
Data security
We use appropriate technical and organisational measures, including TLS encryption, password hashing, role-based permissions, access restrictions, logging and regular backups. These measures are continuously developed in line with risk and the state of the art.
Your data protection rights
Data subjects may exercise their statutory rights against the controller.
- access to personal data being processed
- rectification of inaccurate data
- erasure or restriction of processing
- data portability, where applicable
- objection to processing based on legitimate interests
- withdrawal of consent with effect for the future
Right to lodge a complaint
You have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the place of your habitual residence, place of work or the place of the alleged infringement.
Changes to this privacy policy
We may update this privacy policy when legal requirements, our services or the procedures used change. The version published on this website at the relevant time applies.