ZowaLab

Privacy Policy

Last updated: July 2026

This Privacy Policy explains how [COMPANY LEGAL NAME]("ZowaLab", "we", "us") collects, uses, shares, and protects personal data when you use our website and the ZowaLab Services. It applies to visitors of our marketing site and to Authorized Users of a ZowaLab Workspace. It should be read together with our Terms of Service and Cookie Notice.

Where your organization is our Client and has its own end customers whose data lives inside your Workspace (contacts, deals, invoices, and similar records), we act as a processor for that data on your behalf, and your organization is the controller. This Policy describes our role as controller for account, billing, and usage data about you and your Authorized Users. Our processor obligations for your Client Data are set out in our Data Processing Addendum.

1. Personal Data We Collect

CategoryExamplesSource
Account dataName, work email, password (hashed), phone, job title, workspace nameProvided by you at registration
Billing dataBilling address, tax ID, subscription plan; card details are handled directly by our payment processor and are never stored on our serversProvided by you at checkout
Client DataContacts, companies, deals, documents, messages and files you or your team create in the ServicesEntered by you and your Authorized Users
Email integration dataMessages and metadata from Gmail/Outlook/IMAP accounts you connect, limited to the scopes you authorizeThird-party account you connect
Usage & log dataPages visited, features used, IP address, browser type, timestampsCollected automatically
CookiesSee our Cookie Notice for the full list and categoriesYour device

2. How We Use Personal Data

PurposeLegal basis (GDPR)
Provide, maintain, and secure the ServicesPerformance of a contract
Process payments and manage your subscriptionPerformance of a contract
Respond to support requestsPerformance of a contract / legitimate interest
Send service notices (billing, security, changes to these terms)Legal obligation / legitimate interest
Improve and secure the product (bug fixing, abuse prevention)Legitimate interest
Send product updates or marketing communicationsConsent (you can opt out anytime)
Comply with legal obligations (tax, accounting, law enforcement requests)Legal obligation

Every marketing email we send includes an unsubscribe link; opting out of marketing does not opt you out of essential service notices (billing, security, or legal notices) tied to your account. We do not use your personal data to make automated decisions that produce legal or similarly significant effects on you.

3. How We Share Personal Data

We share personal data only in the following circumstances:

  • Sub-processors — vendors who help us run the Services (hosting, email delivery, payment processing). See our full Sub-processor list. Each is bound by a data processing agreement no less protective than this Policy.
  • Within your Workspace — data you enter is visible to Authorized Users in your Workspace according to the permissions your organization configures.
  • Legal requirements — where required to comply with law, regulation, legal process, or governmental request.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to the acquirer honoring this Policy.

We do not sell personal data, and have not sold personal data in the preceding 12 months.

4. International Data Transfers

Where we transfer personal data across borders (for example, from the EU/UK to a sub-processor located elsewhere), we rely on recognized transfer mechanisms such as the European Commission's Standard Contractual Clauses, together with supplementary security measures where needed.

5. Data Retention

We retain account and Client Data for as long as your Subscription is active, and for a reasonable period after termination to allow export and to meet legal, tax, and accounting obligations, after which it is deleted or anonymized. Usage/log data is retained for a limited period sufficient for security and troubleshooting purposes, then deleted or aggregated.

6. How We Protect Your Data

We apply layered security controls appropriate to the sensitivity of the data involved:

  • Passwords are hashed (never stored in plain text) before being saved.
  • Connected email account credentials and OAuth tokens (Gmail, Outlook, IMAP) are encrypted at rest using AES-256-GCM.
  • API keys are stored as one-way hashes; the raw key is shown to you only once, at creation.
  • Data in transit is encrypted via HTTPS/TLS between your browser and our servers.
  • Access control — every request is scoped to your Workspace and to the permissions assigned to the requesting user, so one client can never access another client's data.
  • Infrastructure — our database runs on infrastructure with disk-level encryption at rest.

No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we work to keep these protections current.

7. Your Rights Under GDPR (EU/UK/EEA residents)

If applicable data protection law grants you these rights, you may:

  • Request access to the personal data we hold about you;
  • Request correction of inaccurate data;
  • Request erasure of your data, subject to legal retention requirements;
  • Request restriction of, or object to, certain processing;
  • Request a portable copy of data you provided to us;
  • Withdraw consent at any time, where processing is based on consent;
  • Lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact [email protected]. If your data lives inside a Client's Workspace (i.e. you are their contact, not our direct Client), please also contact that organization directly, as they control that data.

8. Your Rights Under CCPA/CPRA (California residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose;
  • Request deletion of your personal information, subject to legal exceptions;
  • Correct inaccurate personal information;
  • Opt out of the sale or sharing of personal information — we do not sell or share personal information as those terms are defined by the CCPA;
  • Not be discriminated against for exercising these rights.

To exercise these rights, contact [email protected]. We will verify your request using the information associated with your account before acting on it.

Third-Party Links

The Services and our website may link to third-party sites we do not control. This Policy does not apply to those sites; we encourage you to review their own privacy notices.

9. Children's Privacy

The Services are intended for business use by adults and are not directed to children. We do not knowingly collect personal data from anyone under 16.

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified by email or in-app notice before taking effect; the "Last updated" date above always reflects the current version.

Contact

Questions about this Policy, or to exercise your rights, contact us at [email protected].

© 2026 ZowaLab
All documentsTermsPrivacyCookiesBack to ZowaLab