Last updated: 13 September 2026
Zenit does not request bundled consent during registration for marketing, health data, location or an applicant pool. A privacy notice is separate from consent, and accepting the Terms of Service is not consent to process personal data.
If a customer company relies on consent for optional processing such as employee health data, location at the moment of clock-in or a future-opportunities applicant pool, it must provide a separate notice in its own name as controller. The notice must identify the data, narrow purpose, recipients, retention period, any international transfer and an easy withdrawal route. The box must not be pre-ticked, and refusal must not affect services for which the processing is not necessary.
For health data, the customer must first assess non-consent conditions under KVKK Article 6 or GDPR Article 9. Employee location requires a necessity and proportionality assessment and an equivalent alternative. An applicant pool must remain independent from the current application. Zenit does not make these legal decisions for the customer. Consent records must include the date, text version, scope and withdrawal status; withdrawal applies prospectively.