Zephira.aiCustomer dashboard →
Home/Legal

Zephira.ai · Legal

Privacy Policy

How we use personal information about visitors, customers, account users and people named in business records.

Last reviewed: 18 September 2026 · Version 2026-09-18
On this page1. Controller and contact details2. Information we handle and its sources3. Purposes and legal bases4. Required information and marketing choices5. People in company and registry records6. Who receives information7. International access and transfers8. Retention9. Security and confidentiality10. AI, profiling and automated decisions11. Your rights and how to exercise them12. US and other local rights13. Complaints14. Children and updates

1. Controller and contact details

Global Data Intelligence Limited, trading as Zephira.ai, is the controller for the processing described here. We are registered in England and Wales, company number 09410808, at Artisans’ House, 7 Queensbridge, Northampton, Northamptonshire, NN4 7BF, United Kingdom. Contact office@zephira.ai or +44 20 4551 1901 and mark your request “Privacy”.

This notice covers Zephira’s websites, customer dashboard, APIs, support and business-information services. It also covers personal data we obtain from company registries and other business sources. It does not replace a customer’s own privacy notice or the notice of a separate payment, authentication or AI service you choose to use.

2. Information we handle and its sources

Information comes from you, your organisation or colleagues, the services you use, payment and identity providers, official business registries, filed documents, and identified business-information or enrichment sources. Company data can be personal data when it identifies a person, including a director, owner, sole trader or business contact. Public availability does not remove data-protection obligations.

CategoryExamples and source
Account and business contactsName, work email, company, phone, role, country, account and team identifiers; supplied by you, your organisation or the identity provider.
BillingBilling details, payment and subscription references, plan, status, invoice history and transaction information; supplied through Stripe or agreed invoice arrangements. Full payment card credentials are handled by the payment provider.
Use and securityAPI endpoint, timestamp, request identifier, status, usage, quota, sign-in and security events; dashboard navigation events and support diagnostics. Technical requests can include IP address, device and browser information.
Enquiries and supportMessages, business requirements, contact preferences, support correspondence and information you choose to provide.
Business recordsNames, professional roles, appointments, ownership interests, business identifiers and addresses, and other personal information contained in the source record or licensed data product. Field availability and filtering vary by product and source.
Derived informationEntity matches, links and structured interpretations derived from available records; a derived attribute is not necessarily a registry-confirmed fact.

3. Purposes and legal bases

We identify a lawful basis for each processing purpose. Contract applies when the individual is a contracting party or has asked for steps toward a contract; where we deal with an employee of a business customer, our basis is normally legitimate interests in managing that business relationship. Legitimate interests require necessity and balancing against individuals’ rights; they are not a blanket exemption.

PurposeBasis and interest
Set up accounts and deliver the ordered serviceContract where applicable; otherwise legitimate interests in providing the business service and managing authorised users.
Handle enquiries, onboarding and supportRequested pre-contract steps where applicable; otherwise legitimate interests in answering and administering business requests. Any specific consent collected is limited to its stated purpose.
Billing, invoicing and recordsContract and legitimate interests in administering payment; legal obligations for applicable tax and accounting records.
Security, fraud prevention, limits and incident investigationLegitimate interests in protecting accounts, systems and people, and legal obligations where applicable.
Business research, verification and licensed registry informationLegitimate interests in reliable business intelligence and due diligence, subject to necessity, proportionality and applicable restrictions.
Product usage analysisLegitimate interests in understanding and improving service use where appropriate; consent for non-exempt storage or access technologies. See Cookie Policy.
Relevant business marketingConsent where required, or legitimate interests where marketing law permits. You can object or unsubscribe at any time.
Rights requests, complaints and legal claimsLegal obligations and legitimate interests in addressing requests, establishing rights and resolving disputes.

4. Required information and marketing choices

Account identifiers, a working email and relevant payment or business details are needed to create and administer an account. We may be unable to fulfil a request without required information. Do not send unnecessary sensitive information in a general contact form.

Creating an account, paying, accepting terms or asking for support is not consent to unrelated marketing. Service emails about access, billing, security or a requested response are separate from promotional communications. You can stop direct marketing using the unsubscribe option provided or by contacting us; we may retain a limited suppression record so we respect that choice.

Any use of email addresses for matched advertising audiences, or non-exempt advertising tracking, requires the relevant notice, legal basis and consent where required. This notice does not itself grant permission for those activities.

5. People in company and registry records

We process professional and company-related information to make business records searchable, match legal entities, show ownership and appointments, provide provenance and support verification and research. Records may concern current and former directors, officers, shareholders, beneficial owners or sole traders. Historical records can remain relevant after a role ends, with dates and source context where available.

Information may be made available to licensed business customers through the platform, APIs, bulk delivery or authorised integrations. Those customers ordinarily determine their own purposes and act as independent controllers. They must establish their own lawful basis, observe licence restrictions and respect individual rights.

You can ask about a specific record or source, challenge a match, request correction, object or seek restriction or erasure. We will assess the request under the applicable law. Correcting Zephira’s copy does not change an official register; a separate request to the registry may be necessary. Public availability alone is not a reason to reject a request.

For information obtained indirectly, applicable transparency obligations normally require notice within one month, or earlier at the first communication or disclosure, unless a specific exception is justified. The existence of this page is not, by itself, proof that an individual-notification exception applies.

6. Who receives information

Recipients can include authorised staff; your organisation’s authorised account administrators; providers of hosting, authentication, payment, customer relationship management and communications; professional advisers; competent authorities where required; and a successor in a lawful business transaction subject to appropriate safeguards.

The Service Providers page identifies the integrations currently used in the website and dashboard. Not every recipient is a processor for every purpose: for example, payment providers may have independent legal duties. A vendor’s exact role depends on the activity and agreement.

Licensed customers receive company-dataset information as described above. We do not describe this business-data licensing as an unconditional ‘no sale’ of personal information: legal definitions differ by jurisdiction. Customer account information is used to operate the relationship and is not automatically added to a resalable contact dataset.

7. International access and transfers

Zephira is operated by a UK company with operational personnel in Moldova and service providers whose infrastructure or support may be outside the UK or EEA, including the United States. Data protection law can apply to remote overseas access as well as storage. We do not promise UK-only or EU-only processing unless a specific written arrangement establishes it.

For a restricted transfer, the applicable law requires a valid mechanism, such as an adequacy decision that covers the recipient or appropriate contractual safeguards, together with any required assessment and supplementary measures. The relevant mechanism must be established for the actual recipient and processing; naming a mechanism here does not incorporate or execute it.

Contact us to request information about the destinations and safeguards applicable to your service, or a copy of relevant safeguards subject to legitimate redactions. A specific residency or transfer requirement should be recorded in the enterprise agreement before data is supplied.

8. Retention

Retention depends on the purpose, the customer relationship, source-update cycle, sensitivity, dispute or security need and applicable legal duties. Account closure, cancellation and deletion are different actions. We do not represent that every system automatically deletes all data on cancellation.

Account and relationship records are kept while needed to administer the service. Inactive accounts are assessed against the existing three-year inactivity policy; this is not a guarantee of deletion exactly three years after a login. Billing and accounting records are generally retained for six years after the relevant accounting period, or longer where the applicable law or an identified legal hold requires it.

Support, query, usage and security records are retained for as long as reasonably necessary for their operational purpose, metering and billing evidence, investigation and claims. Relevant criteria include the age of a request, whether an issue is resolved, the contractual claims period and whether personal detail can be removed while retaining aggregate information.

Business-dataset records are assessed for continuing relevance, source status, historical due-diligence value and applicable restrictions. Marketing preferences and limited suppression records may outlast an active marketing relationship to prevent further unwanted contact. Backups and legally held copies may have different retention periods and remain protected while retained. Request details or deletion of a particular category through our privacy contact.

9. Security and confidentiality

Security measures include authentication, access restrictions, protected connections and controls over credentials and API use. Measures must be appropriate to the service and risk. No service is entirely risk-free. An enterprise security schedule, certification scope, audit report or service level applies only as specifically supplied and agreed; this notice is not a certification claim.

Keep your own credentials confidential and avoid sending full card details, passwords or API secrets to support. Report a suspected data or account security incident promptly to office@zephira.ai. We assess incidents and make required notifications under applicable law.

10. AI, profiling and automated decisions

Entity matching, data structuring and derived attributes may use automated processing. A customer may query Zephira through an AI client or an MCP integration. Data sent to a client or provider you select is also subject to that provider’s terms and your instructions; consider what information it can retain or use.

Zephira company outputs do not determine a natural person’s eligibility for a job, loan, housing or insurance. Customers who build consequential automated decisions must assess their own legal obligations and provide the required safeguards. If you believe a decision about your account or data has been made incorrectly by an automated process, contact us to request an explanation and human review.

Access to an API or AI integration does not itself authorise training on personal data or establish a lawful basis for training. Any separate training use requires appropriate rights and privacy review.

11. Your rights and how to exercise them

Depending on the law and circumstances, you may request access and a copy, correction, erasure, restriction, portability, or object to processing. You can withdraw consent without affecting earlier lawful processing. The right to object to direct marketing is unconditional. Other objections and erasure requests may require an assessment against lawful exceptions or compelling grounds.

Email office@zephira.ai with the subject ‘Privacy request’, or write to our registered office. You do not need to buy a subscription. Identify the relevant account or record and the right you wish to exercise. We may request proportionate evidence of identity or an authorised representative’s authority; do not send identity documents until necessary and a suitable channel is agreed.

For UK and EEA requests, the normal response period is one calendar month, with lawful extensions for complex or multiple requests and any permitted pauses or requests for clarification. We will explain an extension or refusal and your options. Other jurisdictions have different deadlines. Requests are generally free; any lawful fee or refusal must be justified.

12. US and other local rights

Where an applicable US state privacy law covers our processing, eligible residents may also have rights to know categories and recipients, delete or correct information, opt out of sale or sharing and certain profiling, and appeal a refusal. We will not unlawfully discriminate against you for exercising a right. Use office@zephira.ai for a request or authorised-agent submission.

Some professional records contain publicly available information that is excluded from particular state-law definitions; that does not mean all business contacts or enriched data are excluded. Applicability, sale or sharing status, recognised opt-out signals, data-broker obligations and relevant exceptions must be assessed for the actual data and activities. This notice does not claim an exemption simply because our customers are businesses.

13. Complaints

Tell us if you are unhappy about our use of personal data. Send a privacy complaint to office@zephira.ai or by post. We will acknowledge it within 30 days, make appropriate enquiries without undue delay, keep you informed and explain the outcome and any action taken.

You can complain to the UK Information Commissioner’s Office at https://ico.org.uk/make-a-complaint/ or telephone +44 303 123 1113, or to another competent supervisory authority, including in your EEA country of residence, work or the alleged infringement. You do not have to waive that right or accept binding arbitration to raise a privacy complaint.

14. Children and updates

The service is intended for adult business users and is not directed at children. If you believe a child has supplied account information, contact us. This statement does not assume that all public company records are incapable of referring to a minor.

We review this notice when our services or practices change and show the latest revision date. Where a change materially affects how personal data is used, we will provide any further notice or choice required by law. A changed notice does not retrospectively create consent.

Related documents

Terms and ConditionsCookie PolicyBilling, Cancellation and RefundsAcceptable Use and Data LicensingData Protection and Data ProcessingService Providers

Questions or rights requests: office@zephira.ai

Zephira.ai · Global Data Intelligence Limited · Company 09410808 · England and Wales
Artisans’ House, 7 Queensbridge, Northampton, NN4 7BF, United Kingdom

LegalTermsPrivacyCookiesBilling & refundsData protection