1. Scope
This policy covers zephior.com, zelius.ch, the Ziva software platform, Zelius tender intelligence and managed bid services, Zeke software engineering engagements, Zenith automation engagements, related forms, email communications, checkout flows and support interactions.
Zephior LLC acts as controller for website, account, billing, relationship and operational data. When we process information supplied by a client solely to deliver a contracted project, Zephior generally acts as processor and the client remains controller. The Data Processing Agreement governs that processing where applicable.
2. Data we process
Depending on the service, we process:
- Contact and account data: name, work email, company, role, authentication identifiers and support communications.
- Commercial data: subscriptions, order forms, invoices, billing address, tax details and payment status. Payment-card data is handled by a payment provider and is not stored by Zephior.
- Client data: documents and other information submitted, stored or generated through a service or engagement.
- Service data: customer preferences, service configuration, relevant public or licensed business information, reports and account activity.
- Business outreach data: professional identity and role, employer, work contact details, public company identifiers, public procurement participation and award information, opportunity relevance, message history, replies, delivery status and opt-out records.
- Technical data: IP address, user agent, timestamps, service logs, security events, performance data and feature usage.
- Communications data: messages and related delivery or interaction information.
3. How we use data
We use data to provide, secure and administer requested services, communicate with users, process payments, respond to enquiries, produce requested output, tailor the service experience, maintain reliability, prevent abuse, improve service quality and meet legal, accounting and tax obligations.
We also use limited business contact and public company data to identify corporate suppliers that may benefit from our procurement intelligence and proposal services, select an accountable professional contact, send relevant B2B communications, respond to replies and maintain suppression records.
Client data is used to perform the client’s instructions. We do not use client data to train general-purpose models for Zephior or third parties.
4. Legal bases
Where a legal basis is required, we rely on performance of a contract, steps requested before entering a contract, legitimate interests in operating, securing and responsibly promoting a relevant B2B service, compliance with legal obligations and consent where the law requires it.
For carefully selected corporate outreach, our legitimate interests are to make relevant organisations aware of our own procurement intelligence and proposal services and to develop business relationships. We limit the data and audience, assess relevance, avoid sole traders and non-corporate subscribers unless an applicable permission exists, make objection easy and balance these interests against the rights and expectations of business contacts. A client remains responsible for establishing a lawful basis for personal data it instructs Zephior to process on its behalf.
5. Service-specific processing
Ziva
Ziva processes content submitted to or generated through the service, together with the account and usage data needed to operate it. Human access to client data is limited to authorized support or delivery work and is governed by access controls and confidentiality obligations.
Zelius
Zelius processes customer profile information and relevant external business information to provide intelligence and agreed services. Its outputs are decision-support material.
Zeke and Zenith
These engagements process the data made available by the client for the agreed project. The applicable agreement defines the scope and purpose, and access is limited to the assigned team.
6. Email and communications
We process contact details and delivery information to send requested and operational messages and, where permitted, relevant B2B communications. This data is used to operate communications, maintain reliability and respect opt-outs. Our first-contact B2B messages identify Zephior, explain why the communication is relevant, link to this policy and provide a direct way to opt out.
We do not use tracking pixels or link-rewriting for behavioural monitoring in first-contact B2B messages. Non-essential communications can be stopped at any time.
7. Public-source business outreach
We may obtain business contact and company information from public company websites, Companies House and other official company registers, public procurement portals and award notices, public framework directories, public professional profiles and reputable business-data providers. We do not buy consumer marketing lists for this activity.
We use this information to contact a limited company or other corporate body about Zephior’s own services where its public procurement activity indicates a reasonable professional relevance. We select contacts in roles likely to be accountable for bids, tenders, sales, business development or company leadership. We do not infer sensitive personal characteristics or make decisions about individuals.
Where we obtained personal data from another source, the first communication provides access to this policy. You can ask for the source and categories of data we hold by contacting [email protected].
8. Service providers and subprocessors
We disclose personal data only to providers needed to operate or deliver a requested service. Provider categories include payment and billing, cloud hosting and storage, identity and access management, compute and AI processing, communications, security, service operations and professional advisers where required.
Providers may process data only for the agreed purpose and under applicable contractual and legal duties. Current subprocessor information for a contracted service is available to clients from [email protected] or in the applicable agreement.
9. International transfers
Depending on the service, providers may process data in Switzerland, member states of the European Economic Area, the United Kingdom or the United States. Where required, we rely on adequacy decisions, standard contractual clauses or equivalent safeguards. More specific location commitments are stated in the applicable agreement or subprocessor information.
10. Retention
We keep data for as long as necessary for the purpose for which it was collected and to meet contractual or legal obligations. Account and client content is retained during the relationship and for the export or deletion period stated in the applicable terms or order form. Payment and tax records may be retained for statutory periods.
Business outreach records are reviewed for continued relevance and are removed or refreshed when they are no longer needed. Delivery, reply and campaign records are normally kept for up to 24 months after the last contact. Minimal suppression records may be retained for longer so that we can honour an objection and prevent future unwanted sending. Backups expire under controlled retention schedules.
11. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability of your personal data. You have an absolute right to object to the use of your personal data for direct marketing. Reply “unsubscribe” to a message or contact [email protected]. We will stop the marketing use and keep only the minimal suppression information needed to respect your choice. We may need to verify your identity before acting on another type of request.
You may also lodge a complaint with the competent data-protection authority. For processing subject to the UK GDPR, this is the UK Information Commissioner’s Office.
For client content processed on behalf of your employer or another client, please direct the request to that controller first. We will assist the controller as required by the Data Processing Agreement.
12. Security
We use technical and organizational measures appropriate to the service and risk, including access controls, encryption in transit, protected storage, logging, backup and incident-response procedures. No system is completely secure. Deployment-specific controls and commitments are described in the relevant agreement and security documentation.
13. Changes
We update this policy when services or processing practices change. The version and effective date identify the policy currently in force. Material changes will be communicated where required.
14. Contact
Zephior LLC
Reiffergässli 4
6300 Zug, Switzerland
Privacy and legal requests: [email protected]
Security reports: [email protected]
UK representative
For processing subject to the UK GDPR, Zephior LLC has appointed Prighter Ltd as its representative in the United Kingdom under Article 27 UK GDPR. You may contact our representative about UK GDPR matters at:
Prighter Ltd
20 Mortlake Mortlake High Street
London SW14 8JN
United Kingdom
Online contact: Prighter privacy portal