Zephira.aiCustomer dashboard →
Home/Legal

Zephira.ai · Legal

Data Protection and Data Processing

Controller responsibilities, processor agreements and individual rights in company-data services.

Last reviewed: 18 September 2026 · Version 2026-09-18
On this page1. Business information can identify people2. Independent controllers for licensed registry data3. When a DPA is needed4. Transparency and legitimate interests5. Requests, corrections and complaints6. International processing and procurement evidence

1. Business information can identify people

UK GDPR, the Data Protection Act 2018 as amended, EU GDPR where applicable, and relevant local laws can apply to names, appointments, ownership interests and sole-trader records. There is no general GDPR exemption for B2B or public-register information. Our Privacy Policy explains the categories, purposes, recipients, retention criteria and rights route.

2. Independent controllers for licensed registry data

We generally determine how we collect and structure the registry intelligence we license. Customers determine how they use that information in their own workflows. Each party is normally an independent controller for its own activity and must meet its own requirements. Calling a supplier a processor in a procurement form does not change the factual role.

Controller-to-controller arrangements should define permitted purposes, data categories, source and quality information, security, onward sharing, rights-request cooperation and international transfers. A licence to data is distinct from a lawful basis to process personal information.

3. When a DPA is needed

Where an agreed service involves Zephira processing customer-provided personal data only on documented customer instructions, a data processing agreement is required before that processor activity begins. Contact office@zephira.ai to agree the scope and schedule. A website policy is not an executed DPA or a completed transfer agreement.

  • Define the subject matter, duration, purpose, operations, data types and data subjects.
  • Document instructions, confidentiality, appropriate security and restrictions on use.
  • Name and authorise relevant subprocessors, with the agreed change-notice and objection process.
  • Provide for rights requests, incident assistance, impact assessments, audit evidence and regulator cooperation.
  • Specify return or deletion, backups, legal holds, actual processing locations and applicable transfer safeguards.

4. Transparency and legitimate interests

A legitimate-interests assessment must address a defined purpose, necessity and the balance with individuals’ rights. It is not completed by saying the data is public or useful. Indirect collection requires an Article 14 transparency assessment; any exception must be specifically justified and supported by safeguards. A public notice alone does not demonstrate that assessment has been completed.

5. Requests, corrections and complaints

Individuals can contact office@zephira.ai without an account to exercise applicable rights or challenge a record. Include a relevant company identifier or record link if available. We assess requests, provide reasons where appropriate and cooperate with other controllers as required. An official registry may need a separate correction request.

Privacy complaints are acknowledged within 30 days and considered without undue delay. The Privacy Policy sets out response periods and regulator contact details. Contractual dispute clauses do not remove statutory complaint or redress rights.

6. International processing and procurement evidence

The service can involve overseas hosting and access, including operations in Moldova. Confirm actual locations, recipients, transfer mechanisms and required assessments for the purchased service. We do not describe unverified locations, a general certification or a reference to standard clauses as an executed safeguard.

For procurement, ask for the applicable signed data agreement, provider schedule, security measures, retention arrangements and any relevant assurance evidence. Documents should match the contracted product and their current scope; a generic GDPR statement cannot certify a customer’s compliance.

Related documents

Terms and ConditionsPrivacy PolicyCookie PolicyBilling, Cancellation and RefundsAcceptable Use and Data LicensingService Providers

Questions or rights requests: office@zephira.ai

Zephira.ai · Global Data Intelligence Limited · Company 09410808 · England and Wales
Artisans’ House, 7 Queensbridge, Northampton, NN4 7BF, United Kingdom

LegalTermsPrivacyCookiesBilling & refundsData protection