How this feature connects to others
What EU processing means in practice
Many AI products say that data is hosted in Europe without explaining where the actual model work happens. Those are two different questions. Hosting describes where stored data lives. Processing describes where the computing that reads an input and generates an answer takes place.
Zigzag uses Microsoft Azure as its AI platform. Our Azure resource is located in West Europe, and ordinary AI generation uses EU Data Zone deployments. That means Microsoft may route a request between supported Azure locations within the European Union for capacity and reliability, but not to a data zone outside the EU.
We describe this as EU processing rather than promising that every request stays inside one particular data centre. The EU Data Zone is designed to provide a European processing boundary while allowing Microsoft to operate the service reliably across eligible EU locations.
What happens when you use an AI-powered feature
When you ask zigzag to create or improve something, the platform first selects the project information needed for that task. For example, generating a Lean Canvas may require your startup description, while reviewing an interview may require the interview questions and transcript.
Zigzag sends that task-specific content through our private Azure service endpoint. Microsoft processes it inside the EU Data Zone and returns the generated result to zigzag. The result is then shown to you or stored in your zigzag project when the feature requires it.
The model provider does not receive your zigzag account password, and zigzag does not intentionally add your account name, email address, or billing information to generation requests. Information you write inside a business field can still contain personal data, so you should only include personal information when it is genuinely needed for the task.
The ordinary request flow is
- ✓You choose an AI-powered action inside zigzag.
- ✓Zigzag sends only the relevant business content to its Microsoft Azure endpoint.
- ✓The request is processed within the EU Data Zone.
- ✓The generated output is returned to zigzag and presented or saved as part of your project.
Why zigzag uses Microsoft Azure
Zigzag uses Microsoft Azure because it provides a clear enterprise service boundary, geographic deployment controls, encryption, access management, and contractual data-protection commitments. Microsoft Azure is the subprocessor that operates the AI infrastructure for zigzag.
The underlying models are hosted and operated inside Microsoft's Azure environment. Inputs and outputs submitted through this setup are not sent to a separate consumer AI product or to the model provider's public API. This lets zigzag use capable AI systems without making a founder's business information part of a public AI account or consumer chat history.
We intentionally do not publish the exact model version used by each feature. Models change as providers improve their services, and different tasks can require different capabilities. Our commitments are attached to the processing environment and data-handling rules, not to one model name that may later be replaced.
What does not happen to your inputs and outputs
Your business inputs and generated outputs are used to provide the feature you requested. Zigzag does not sell that content, use it for advertising, or use it to train its own foundation models.
Zigzag does not give Microsoft, the underlying model provider, or another model provider permission to use your inputs or outputs to train generative AI foundation models. Microsoft states that data submitted to models sold through Azure is not made available to the underlying model provider and is not used to train foundation models or improve Microsoft or third-party products without the customer's explicit permission or instruction. Zigzag does not provide that permission.
This is a contractual and architectural safeguard, not a setting that depends on a founder finding a hidden privacy switch. It applies to our Azure service use by default, and zigzag reinforces it by limiting which providers, endpoints, and deployments the application is allowed to call.
How storage and safety checks are handled
Ordinary zigzag generation requests are configured as stateless requests, with response storage disabled at the Azure Responses API layer. The model does not build a memory of your startup from one request to the next. Zigzag supplies the context needed for each task from the project data that you control in the platform.
Microsoft still applies automated safety systems while a request is being processed. These systems check for harmful or abusive use and are separate from model training. Depending on Microsoft's standard abuse-monitoring rules, content associated with suspected abuse may be retained within the Azure service boundary and reviewed through controlled processes. This does not permit the content to be used for foundation-model training.
Zigzag also keeps its own project records where a feature needs to save your work. Disabling service-side response storage does not delete the Lean Canvas, document, interview result, or other output that you asked zigzag to keep in your account. Those records follow zigzag's published retention and deletion rules.
The important exception for live web research
Some zigzag features need current public information rather than relying only on the model's existing knowledge. Market research and competitive analysis are examples. For those features, zigzag may use Microsoft's web-grounding capabilities to search public web sources.
The core AI generation still uses zigzag's Azure deployment, but search queries used for Microsoft web grounding may be processed outside the EU Data Zone. Zigzag limits those queries to the research task and does not intentionally add your account identifiers. This exception is disclosed because a promise of universal EU-only processing would otherwise be misleading.
If a workflow does not require live web information, zigzag does not add web grounding merely for convenience. The ordinary EU Data Zone path remains the default for AI generation.
What you can do when working with sensitive information
Treat an AI workspace with the same care you would use for any business collaboration tool. Give zigzag the information needed to produce useful work, but avoid pasting passwords, payment-card details, government identification numbers, medical records, or confidential third-party information that is not necessary for your startup task.
When working with interviews or customer evidence, consider replacing names with roles or participant codes unless identity matters to the analysis. When summarizing contracts or diligence material, provide the relevant section rather than an entire document if the rest is not needed.
You remain in control of the project records stored by zigzag. The account tools allow you to export your data and request deletion, while the Privacy Policy and Trust Centre explain the applicable retention periods, legal rights, subprocessors, and security measures in more detail.
A useful rule of thumb is
- ✓Share the minimum information needed for the result you want.
- ✓Remove unnecessary personal identifiers before submitting interviews or customer evidence.
- ✓Use the Privacy Policy and Trust Centre when you need the formal legal or operational detail behind this guide.