Zest Technologies DIFC Limited ("Zest DIFC", "we", "us", "our") is a private company established in the Dubai International Financial Centre ("DIFC"), Dubai, United Arab Emirates, with registered company number CL4831 and a registered office at Unit 502, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates.
Zest DIFC operates Tarth, an AI-assisted compliance platform accessible at www.tarth.ai and its subdomains (including app.tarth.ai and links.tarth.ai) (together, the "Platform"), and the website at www.tarth.ai (the "Site"). The Platform enables our customers to run compliance workflows relating to the onboarding, verification, assessment, and monitoring of individuals and entities — including identity verification, document collection and analysis, sanctions, PEP and adverse media screening, source of wealth analysis, risk assessment, client classification, and the generation of compliance records and reports (each such workflow, a "Screening").
This privacy policy (the "Privacy Policy") sets out how we collect, use, share, and protect personal data in connection with your use of the Site and the Platform. It applies globally. Zest DIFC is primarily regulated under the DIFC Data Protection Law (DIFC Law No. 5 of 2020, as amended) and honours equivalent rights under the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and other applicable data protection regimes where they apply to you. This Privacy Policy should be read together with the Tarth Terms and Conditions published on the Site (the "Tarth Terms"), which it forms part of.
Please read this Privacy Policy carefully so you understand your rights and how we handle your personal data. This Privacy Policy supersedes any previous privacy-related notice provided by us. If you do not agree with it, you should not access the Site or use the Platform.
The Site and Platform are not intended for children, and we do not knowingly collect data relating to children.
Tarth is a business platform used by regulated and risk-conscious organisations and by professionals acting in the course of their business (together, "Customers") to onboard, verify, screen, and assess individuals and entities ("Subjects"). A Subject may be an individual, or an entity — in which case the individuals connected to that entity (for example, its beneficial owners, directors, officers, authorized signatories, and points of contact) are the persons whose personal data is processed. Depending on the data in question, Zest DIFC acts in different capacities.
When we act as a data processor. For personal data relating to Subjects that Customers submit to, or generate through, the Platform in connection with a Screening — including onboarding, identity verification, screening, risk assessment, record generation, and, where made available, ongoing monitoring — the Customer is the data controller and we process that data on the Customer's instructions. The Customer's instructions include the standing instructions set out in the Tarth Terms, such as the instruction to access Screening data (where reasonably necessary, on an identified basis) to provide support, investigate and reproduce errors or unexpected results, validate corrections, and protect the security of the Platform. Our processor obligations — including retention, deletion, security, and sub-processor use — are set out in the Tarth Terms, this Privacy Policy, and, where entered into, our data processing agreement ("DPA") with the Customer. Subjects wishing to exercise rights in relation to their onboarding data should contact the Customer that onboarded them; we will assist that Customer in fulfilling those requests.
When we act as a data controller. We act as a controller for:
We may collect personal data when you create an account, log in, complete onboarding or verification workflows (including through a secure onboarding link sent to you by a Customer), upload documents, interact with the Site, or communicate with us or with a Customer through the Platform.
This may include:
When you visit the Site or use the Platform we collect:
We use this data to develop, improve, support, secure, and operate the Platform. We may use third-party analytics (such as Google Analytics) to understand aggregate usage.
We may receive personal data from:
We process personal data to:
The Platform uses artificial intelligence, including large language models, to assist in parts of a Screening — for example document classification and analysis, information extraction and pre-fill, adverse media analysis, source of wealth analysis, and the narration of findings. Findings are designed to be accompanied by citations to their underlying sources so they can be independently verified. Risk scores, risk bands, and escalations are computed deterministically from the Customer's selected configuration; artificial intelligence is used to classify and narrate, not to determine risk scoring. Outputs are reviewed and decided upon by the Customer — Zest DIFC does not make onboarding decisions about any Subject.
We do not use Subject data to train generalised AI models outside of the specific verification and compliance tasks for which it was provided, and we engage our AI model providers on terms under which they may not use data submitted through the Platform to train their models.
The Site uses cookies and similar technologies that are essential to functionality (session management, security, preference storage) and for analytics. You can manage cookie preferences via your browser settings. Non-essential cookies are set only where the required consent has been given.
We share personal data only as described in this Privacy Policy.
Sub-processors. We use the following service providers to operate the Platform:
| Sub-processor | Purpose |
|---|---|
| Onfido | Identity verification, liveness checks, biometric verification |
| ComplyAdvantage | AML, sanctions, PEP, and adverse media screening |
| Clerk | Authentication and user management |
| OpenAI | AI model services supporting verification and compliance workflows |
| Anthropic | AI model services supporting verification and compliance workflows |
| Amazon Web Services | Cloud infrastructure, document and report storage |
| Google Cloud Platform | Cloud infrastructure |
| Hetzner | Cloud infrastructure |
| MongoDB Atlas | Database hosting |
We may add, replace, or remove sub-processors from time to time as the Platform evolves — including additional identity verification and screening data providers — and will update this Privacy Policy accordingly. We require all sub-processors to provide at least equivalent data protection standards and to process personal data only on our instructions (or, for Subject data, on the instructions of the Customer through us). An up-to-date list of sub-processors is maintained in this Privacy Policy and made available to Customers.
Customer-connected providers. A Customer may connect its own accounts or credentials with certain third-party providers (for example, its own screening or identity verification provider subscription) for use in its Screenings. Where it does so, that provider processes data under the Customer's own agreement with the provider, and we store the relevant credentials encrypted and use them solely to provide the Platform to that Customer.
We may also share personal data with:
Personal data may be transferred to and processed in countries outside the DIFC, including where our sub-processors operate. We rely on:
Contact [email protected] for a copy of the relevant Model Clauses.
Depending on the regime that applies to you, you have rights to:
Where we act as a processor (Subject data), please direct requests to the Customer that onboarded you. We will support the Customer in responding.
Where we act as a controller (account data, site data, marketing, platform security), contact us at [email protected]. We aim to respond within one month. We will let you know if we need more time and explain why.
You have the right to lodge a complaint with the DIFC Commissioner of Data Protection (The Gate, Level 14, PO Box 74777, Dubai; +971 4 362 2222) or with the supervisory authority in your jurisdiction (for example, the Information Commissioner's Office in the UK, or your national data protection authority in the EU).
Certain personal data is required for us to provide the Platform or for Customers to meet their KYC, KYB, and AML obligations. Failure to provide it may delay or prevent onboarding and use of the Platform.
We apply appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit and at rest, audit logging, secure infrastructure, staff confidentiality obligations, and regular review of our security posture. Our information security management system is certified to ISO/IEC 27001:2022 (Certificate No. 123098, issued by Prescient Security LLC).
No transmission over the internet can be guaranteed 100% secure. Please contact us promptly at [email protected] if you suspect your data has been compromised.
Controller data (account, site, marketing). We retain this for the duration of your relationship with us plus up to two years after termination, to meet legal, accounting, and legitimate business requirements.
Processor data (Subject data). We retain this only as long as necessary to provide the Platform to the Customer. By default:
Anonymised and aggregated data that does not identify you, any Customer, or any Subject is not personal data and may be retained and used without these limits.
Customers are responsible for meeting their own AML, KYC, and record-keeping obligations. They may download Subject records, reports, and archives at any time to retain them in their own systems.
Deletion by Customers. Customers can delete Subject records directly through the Platform at any time. Deletion is permanent — once completed, records, uploaded documents, verification results, screening history, and associated metadata cannot be recovered. The Platform surfaces a confirmation step that warns of this before deletion is executed. Customers are reminded that they remain responsible for their own AML and record-keeping obligations and may wish to export records before deleting.
Deletion on subscription termination. Subject data is deleted in line with section 11 above.
Deletion of account (controller) data. Customer users can request deletion of their own account and admin data by contacting [email protected]. We will complete deletion within 30 days, subject to any legal retention requirements.
Deletion requests from Subjects. Subjects should direct deletion requests to the Customer that onboarded them, since that Customer is the data controller for Subject data. We will assist the Customer in executing such requests.
The Site and Platform may contain links to third-party websites, plug-ins, or applications. We do not control these third parties and are not responsible for their content, privacy policies, or handling of your information. Review their policies before providing any information.
We may amend this Privacy Policy from time to time to reflect changes in law or in how our business processes personal data — for example, when we add new sub-processors, providers, or Platform capabilities. We will post the updated version on the Site and update the "Last updated" date. Material changes may be notified directly.
For questions, requests, or complaints relating to this Privacy Policy or your personal data:
We endeavour to respond as soon as practicable.