Zephira.ai · Legal
Service Providers
Identified providers used to operate Zephira’s website, account, billing and support functions.
1. Provider roles
We use the services below for identified operational functions. The information shared depends on the function used. Some providers act independently for particular purposes, including legal, fraud-prevention or payment obligations. A customer's selected AI client or integration can be its own provider rather than Zephira’s subprocessor.
| Provider | Purpose | Information involved / notice |
|---|---|---|
| OpenAI Sites / Cloudflare infrastructure | Hosting and operation of the redesigned website and dashboard. | Requests, technical logs and application records for the hosted service. https://openai.com/policies/privacy-policy/ · https://www.cloudflare.com/privacypolicy/ |
| WorkOS | Customer authentication and account identity. | Identity, email, authentication and session information. https://workos.com/legal/privacy |
| Stripe | Checkout, subscriptions, billing portal and payment administration. | Payment, billing, customer and subscription information. https://stripe.com/privacy |
| HubSpot | Business-contact management, signup attribution, enquiries and support-ticket integration. | Business contact, account, purchase, enquiry and support information relevant to the relationship. https://legal.hubspot.com/privacy-policy |
| Resend | Account, subscription and support email delivery. | Recipient, message content and delivery events. https://resend.com/legal/privacy-policy |
| Google Tag Manager | Tag delivery on the public marketing website. | The tags configured in the container determine any further recipients and data. https://policies.google.com/privacy |
2. Operational access
Authorised personnel and service providers may access information to operate, secure and support the service. Our operations include personnel in Moldova. The exact legal role of an affiliated company or contractor and the applicable transfer arrangement must reflect the actual processing relationship; a brand name alone is not a contractual entity.
3. Changes and enterprise authorisation
We update the notice when identified integrations change. Where we act as a processor, subprocessor authorisation, advance notice, objections and contractual flow-down are governed by the executed DPA. This page does not grant itself an unrestricted right to add subprocessors.
Contact office@zephira.ai to request the provider or subprocessor schedule for a specific order, including locations and relevant safeguards. Do not assume that a provider’s public policy proves the customer’s contract or region configuration.