Privacy Policy
Last updated: December 4, 2024
1. Introduction
Zapyon ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI employee platform and related services (collectively, the "Service").
By using Zapyon, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Information You Provide
Account Information: Name, email address, company name, industry, phone number, billing address, and payment information.
Business Configuration: Services, pricing, business hours, AI personality settings, custom fields, and workflow configurations.
Customer Data: Contact information, conversation histories, appointment details, CRM records, and other data you input or generate through the Service.
2.2 Information Collected Automatically
Usage Data: AI messages sent, tool executions, API calls, login times, feature usage, and performance metrics.
Device Information: IP address, browser type, operating system, device identifiers, and referral URLs.
Cookies and Tracking: We use cookies, web beacons, and similar technologies to track activity and store preferences.
2.3 Information from Third Parties
When you connect third-party services (WhatsApp, Instagram, HubSpot, Stripe, etc.), we collect data necessary to provide integrations, including:
- OAuth tokens and refresh tokens
- Customer messages and conversation data
- CRM contacts, deals, and pipeline information
- Calendar events and booking details
- Payment transaction data
- E-commerce orders and inventory
3. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the Service
- Process AI conversations and execute workflows
- Sync data across your connected apps and channels
- Process payments and manage subscriptions
- Send service updates, security alerts, and support messages
- Analyze usage patterns to improve the Service
- Train and improve our AI models
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our Terms
4. AI Model Training
Important: We may use conversation data, workflow executions, and usage patterns to improve our AI models and Service quality. This includes:
- Training AI to better understand customer inquiries
- Improving response accuracy and workflow execution
- Developing new features and capabilities
- Benchmarking performance and identifying issues
We anonymize and aggregate data used for model training to protect individual privacy. Personal identifiers are removed or pseudonymized before use in training datasets.
5. Information Sharing and Disclosure
5.1 Service Providers
We share information with third-party service providers who perform services on our behalf:
- Payment Processing: Paddle (payment processing and subscription billing)
- Cloud Infrastructure: AWS, Google Cloud, or similar (data storage and hosting)
- Communication Channels: Meta (WhatsApp, Instagram, Facebook), Telegram, Twilio (SMS)
- Analytics: Google Analytics, Mixpanel, or similar (usage analytics)
- AI Infrastructure: OpenAI, Anthropic, or similar (AI model access)
5.2 Integrated Services
When you connect third-party apps, we share data necessary for integration functionality (e.g., syncing CRM contacts, booking calendar appointments, processing payments).
5.3 Legal Requirements
We may disclose information if required by law, court order, subpoena, or to:
- Comply with legal obligations
- Protect our rights, property, or safety
- Investigate fraud or security incidents
- Enforce our Terms of Service
5.4 Business Transfers
If Zapyon is acquired, merged, or sells assets, your information may be transferred to the acquiring entity.
6. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
- Access Controls: Role-based access with multi-factor authentication
- OAuth Security: All integrations use OAuth 2.0 (no API keys stored)
- Regular Audits: SOC 2 Type II certified with annual security audits
- Monitoring: 24/7 security monitoring and incident response
However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service:
- Active Accounts: Data retained indefinitely while account is active
- Closed Accounts: Data deleted within 90 days of account closure (unless legally required)
- Backup Systems: Backups retained for 30 days, then permanently deleted
- Anonymized Data: Aggregated analytics may be retained indefinitely
8. Your Privacy Rights
8.1 General Rights
You have the right to:
- Access: Request a copy of your data
- Correction: Update inaccurate information
- Deletion: Request deletion of your data (subject to legal obligations)
- Export: Download your data in machine-readable format
- Opt-Out: Unsubscribe from marketing emails (service emails still sent)
8.2 GDPR Rights (EU Users)
If you are in the European Economic Area, you have additional rights under GDPR:
- Right to data portability
- Right to restriction of processing
- Right to object to processing
- Right to lodge a complaint with your supervisory authority
8.3 CCPA Rights (California Users)
California residents have the right to:
- Know what personal information is collected and how it's used
- Request deletion of personal information
- Opt-out of the sale of personal information (we do not sell your data)
- Non-discrimination for exercising your rights
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure adequate safeguards through:
- EU-US Data Privacy Framework compliance (if applicable)
- Standard Contractual Clauses (SCCs)
- Data residency options (US, EU, Asia-Pacific available for Enterprise plans)
10. Children's Privacy
The Service is not intended for children under 18. We do not knowingly collect information from children. If you believe we have collected data from a child, contact us immediately.
11. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Essential Cookies: Required for Service functionality (authentication, security)
- Analytics Cookies: Track usage patterns and performance
- Preference Cookies: Remember your settings and preferences
You can control cookies through your browser settings, but disabling cookies may affect Service functionality.
12. Third-Party Links
The Service may contain links to third-party websites and services. We are not responsible for the privacy practices of these third parties. Review their privacy policies before providing information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Continued use after changes constitutes acceptance.
14. Data Protection Officer
For GDPR compliance, our Data Protection Officer can be reached at:
Email: dpo@zapyon.com
15. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, contact us at:
Email: privacy@zapyon.com
Website: https://zapyon.com
Address: [Your Business Address]
By using Zapyon, you acknowledge that you have read, understood, and agree to this Privacy Policy.