Zephira.ai · Legal
Data Protection and Data Processing
Controller responsibilities, processor agreements and individual rights in company-data services.
1. Business information can identify people
UK GDPR, the Data Protection Act 2018 as amended, EU GDPR where applicable, and relevant local laws can apply to names, appointments, ownership interests and sole-trader records. There is no general GDPR exemption for B2B or public-register information. Our Privacy Policy explains the categories, purposes, recipients, retention criteria and rights route.
2. Independent controllers for licensed registry data
We generally determine how we collect and structure the registry intelligence we license. Customers determine how they use that information in their own workflows. Each party is normally an independent controller for its own activity and must meet its own requirements. Calling a supplier a processor in a procurement form does not change the factual role.
Controller-to-controller arrangements should define permitted purposes, data categories, source and quality information, security, onward sharing, rights-request cooperation and international transfers. A licence to data is distinct from a lawful basis to process personal information.
3. When a DPA is needed
Where an agreed service involves Zephira processing customer-provided personal data only on documented customer instructions, a data processing agreement is required before that processor activity begins. Contact office@zephira.ai to agree the scope and schedule. A website policy is not an executed DPA or a completed transfer agreement.
- Define the subject matter, duration, purpose, operations, data types and data subjects.
- Document instructions, confidentiality, appropriate security and restrictions on use.
- Name and authorise relevant subprocessors, with the agreed change-notice and objection process.
- Provide for rights requests, incident assistance, impact assessments, audit evidence and regulator cooperation.
- Specify return or deletion, backups, legal holds, actual processing locations and applicable transfer safeguards.
4. Transparency and legitimate interests
A legitimate-interests assessment must address a defined purpose, necessity and the balance with individuals’ rights. It is not completed by saying the data is public or useful. Indirect collection requires an Article 14 transparency assessment; any exception must be specifically justified and supported by safeguards. A public notice alone does not demonstrate that assessment has been completed.
5. Requests, corrections and complaints
Individuals can contact office@zephira.ai without an account to exercise applicable rights or challenge a record. Include a relevant company identifier or record link if available. We assess requests, provide reasons where appropriate and cooperate with other controllers as required. An official registry may need a separate correction request.
Privacy complaints are acknowledged within 30 days and considered without undue delay. The Privacy Policy sets out response periods and regulator contact details. Contractual dispute clauses do not remove statutory complaint or redress rights.
6. International processing and procurement evidence
The service can involve overseas hosting and access, including operations in Moldova. Confirm actual locations, recipients, transfer mechanisms and required assessments for the purchased service. We do not describe unverified locations, a general certification or a reference to standard clauses as an executed safeguard.
For procurement, ask for the applicable signed data agreement, provider schedule, security measures, retention arrangements and any relevant assurance evidence. Documents should match the contracted product and their current scope; a generic GDPR statement cannot certify a customer’s compliance.