This Privacy Policy explains how Ziroo, Inc. (“Ziroo”, “we”, “us” or “our”) collects, uses, discloses, stores, and protects your personal data when you use the Ziroo platform and services (the “Service”). It applies to all users of the Service regardless of location, with additional specific protections in Sections 12 through 14.
Ziroo is a context-aware AI platform that accesses native professional data, including stored content, apps, calendar, messaging, call and meeting data, via tools with responsibility and access controls. This policy is designed to be specific to how our product actually works, not a generic template.
1. Data controller and contact information
The data controller responsible for your personal data is:
Ziroo, Inc.
A Delaware C Corporation, United States
2. Categories of personal data we collect
Depending on how you use the Service, we process a broad range of personal data that may include the categories described below.
2.1 Account data
Name, email address, and password or single-sign-on identifier. Profile information you optionally provide, such as company name, professional title, billing information, and workspace details.
2.2 Service content
When we connect your workspace to Ziroo, we may process content you or your authorized users make accessible to us, including:
- Slack workspace content and associated metadata, including public channels, private channels, threads, files, and direct messages where Ziroo is invited or authorized.
- Connected documents, Drive files, email, calendar events, and meeting information where you grant access.
- Prompts, requests, outputs, summaries, drafts, recommendations, and other content generated through the Service.
We do not capture screenshots, images, video, recordings, passwords, or financial account data unless you expressly provide or authorize that information through a connected tool.
Your content is only processed in Ziroo systems or by approved service providers to perform the Service. You can revoke specific application permissions at any time.
2.3 Device and usage information
When you access the Service, we may collect device and browser information, operating system, IP address, app version, timestamps, feature usage, diagnostic events, and performance information.
2.4 Calendar data
Event titles, descriptions, attendee lists, times, locations, and conferencing links when you connect a calendar integration. Ziroo processes calendar content only under the permissions and scopes you authorize.
2.5 Business and transaction data
Billing contact information, subscription details, payment status, invoices, and transaction metadata. Payment card details are processed by payment providers and are not stored by Ziroo.
2.6 Public data
Public-source business, professional, or company information used to support requested workflows, enrich connected records, or complete a task you have directed Ziroo to perform.
2.7 Visual and analytics data
Visual data, charts, reports, system events, and aggregated analytics generated in the Service. Product usage, crash reports, and performance diagnostics may also be collected.
2.8 Information received from third parties
Information received through customer-authorized integrations, identity providers, payment providers, support tools, analytics providers, and other service providers. This data is processed according to the permissions you grant and the terms of the connected service.
3. How we use your personal data
We use personal data for the following purposes: providing the Service features; personalizing outputs; account management and customer support; billing and payment processing; product improvement and analytics; security and fraud prevention; legal compliance; and communicating with you about the Service.
4. AI model training and your data
We do not train our own general-purpose AI models on your User Data.
Where we use third-party large language model providers, we use contractual and technical configurations designed to prevent customer content from being used for general model training. Our AI providers operate under zero-data-retention or equivalent restricted-processing arrangements where available.
We do not sell User Data, and we do not use customer content for advertising.
5. Who we share your data with
We may share personal data with:
- Cloud infrastructure providers: Google Cloud Platform.
- Payment processors: Stripe, Inc.
- AI providers: Anthropic, Google, and OpenAI under zero-data-retention or equivalent contractual arrangements.
- Logging and monitoring providers: only where necessary to operate and secure the Service.
We do not share or sell your data to third parties for their own advertising purposes.
6. International data transfers
Ziroo is incorporated in the United States. Depending on your location, personal data may be transferred to and processed in countries other than the country where you live. Where required, we use appropriate safeguards such as Standard Contractual Clauses and equivalent transfer mechanisms.
7. Data retention
- Account data: Retained for the duration of your account, plus 30 days after deletion.
- Session content: Retained for the duration of your subscription and deleted after account termination unless a shorter period is requested or required.
- Email and messaging data: Retained for the duration of your subscription. Active recordings are deleted after 90 days.
- Derived data: Deleted within 30 days of account termination.
- Usage and analytics data: Retained in a rolling period of up to 15 months.
- Billing records: Retained for 7 years as required by law.
You can request deletion of specific data categories at any time by contacting privacy@ziroo.ai.
8. Data security
- Encryption at rest: AES-256 encryption for all stored data.
- Encryption in transit: TLS 1.2 or higher for all data transmission.
- Access controls: Role-based access, least-privilege principles, and multi-factor authentication.
- Infrastructure: Monitored, SOC 2 Type II-certified data centres and security controls.
- Monitoring: Real-time intrusion detection, vulnerability scanning, and security incident response.
In the event of a security incident affecting your personal data, we will notify affected users and regulators where required by law.
9. Your rights
Depending on your location, you may have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate personal data.
- Right to deletion: Request deletion of your personal data, subject to legal retention requirements.
- Right to data portability: Request your data in JSON or CSV format.
- Right to restrict processing: Request that we limit how we use your data.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Withdraw consent at any time where processing relies on consent.
- Right to lodge a complaint: Contact your local data protection authority.
To exercise any of these rights, contact us at privacy@ziroo.ai. We will respond within 30 days.
10. Cookies and tracking technologies
Strictly necessary: Session management, authentication, and security. These cannot be disabled.
Analytics: First-party, privacy-preserving usage analytics only. These can be disabled through available cookie controls.
Marketing: None. We do not use third-party marketing cookies or advertising trackers.
11. Children’s privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@ziroo.ai.
12. Supplemental notice for EU/EEA users (GDPR)
If you are located in the European Union or European Economic Area, additional GDPR protections apply. You may contact our GDPR representative at privacy@ziroo.ai. We process personal data only on recognized legal bases and do not conduct automated decision-making with legal or similarly significant effects under Article 22 of the GDPR.
13. Supplemental notice for UK users (UK GDPR)
If you are located in the United Kingdom, you have the rights and protections available under the UK GDPR and the Data Protection Act 2018. You may lodge a complaint with the UK Information Commissioner’s Office.
14. Supplemental notice for US users (CCPA/CPRA)
If you are a resident of California or another US state with applicable privacy laws, you may have rights relating to access, correction, deletion, portability, and restriction of sensitive personal information. Ziroo does not sell or share personal information as defined under the CCPA/CPRA.
Contact us for privacy requests at privacy@ziroo.ai.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days before they take effect or when required by law.
16. Contact us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
General privacy inquiries: privacy@ziroo.ai
