This Privacy Policy explains how Zira Group Inc. and its affiliates, including Lightapp Technologies Ltd. (collectively, "Zira," "we," "us," or "our"), collect, use, disclose, retain, and protect personal data. It also explains the choices and rights that may be available to you.
"Personal data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual, and includes "personal information" and similar terms under applicable law.
This Policy applies to our websites, customer and partner portals, applications, dashboards, APIs, AI-enabled cameras and edge devices, professional and support services, communications, events, and related products and services (collectively, the "Services"). Employment and candidate data may be covered by a separate notice when one is provided.
1Purpose and scope
Data protection laws often distinguish between a controller, which decides why and how personal data is processed, and a processor, which processes personal data on a controller's documented instructions. Under California law, analogous terms include business and service provider or contractor.
This Policy covers both roles. Section 2 describes Zira's practices when Zira is a controller. Section 3 describes Zira's practices when Zira processes Customer Data for a customer. If you interact with Zira through your employer or another Zira customer, that organization is usually the appropriate contact for questions or requests about Customer Data.
"Customer Data" means data that a customer or its authorized users submit to the Services, or that the Services collect or generate for that customer, as further defined in the customer's agreement with Zira.
2Zira as a controller
2.1 Personal data we collect and sources
Depending on how you interact with Zira, we may collect personal data from the following sources:
- Directly from you, such as when you request a demonstration, create an account, purchase or register a product, contact support, attend an event, visit an office, participate in a survey, communicate with our team, or otherwise provide information.
- Automatically from your device or use of the Services, including through logs, cookies, pixels, SDKs, and similar technologies.
- From your organization, such as an account administrator, employer, customer, partner, or reseller that provides contact or account information.
- From third parties and public sources, such as service providers, referral sources, professional networks, event organizers, business directories, social media, and other lawfully available sources.
2.2 Categories of personal data
The table below describes categories of personal data Zira may collect as a controller. The examples are illustrative; not every category applies to every person. Customer Data handled in Zira's processor role is described in Section 3.
| Category | Examples | Sources | Typical recipients |
|---|---|---|---|
| Identifiers and contact data | Name, business email, phone number, postal address, account ID, username, IP address, and similar identifiers. | You; your organization; devices; partners and public sources | Cloud hosting, communications, CRM, support, security, professional advisers, and transaction providers |
| Account and authentication data | Login credentials, permissions, authentication events, and account settings. | You; your organization; devices | Hosting, identity, security, and support providers |
| Commercial and transaction data | Products or services considered or purchased, orders, subscriptions, invoices, payment status, and customer relationship history. Full payment card data is generally handled by payment providers. | You; your organization; payment and sales partners | Payment, accounting, fulfillment, professional advisers, and transaction providers |
| Professional data | Employer, role, job title, department, authority, business contact details, and professional interests. | You; your organization; partners and public sources | CRM, communications, events, support, and professional advisers |
| Internet, network, and device activity | Browser and device type, operating system, referring page, pages viewed, links clicked, timestamps, cookie IDs, diagnostic logs, and security events. | Devices; cookies and similar technologies | Hosting, analytics, security, communications, and advertising providers, subject to your choices |
| Communications and content | Emails, support requests, feedback, survey responses, meeting notes, and, where notice or consent is provided as required, call or meeting recordings and transcripts. | You; your organization; communications tools | Communications, transcription, support, CRM, and professional advisers |
| Audio, visual, and facility data | Photos or video you submit, event photographs, visitor records, and facility security footage. | You; cameras and facility systems; event organizers | Security, event, hosting, and professional advisers |
| Approximate location | Approximate location derived from IP address and the location of a business site or deployed device. | Devices; your organization | Hosting, security, analytics, mapping, and connectivity providers |
| Inferences | Business interests, likely product needs, account health, and engagement indicators derived from the information above. | Derived from other controller data | CRM, analytics, sales, and support providers |
2.3 Sensitive personal data
Account login credentials may be considered sensitive personal data under some laws. Depending on customer configuration, Customer Data may also include information that is considered sensitive, such as precise geolocation or visual data that incidentally reveals characteristics about individuals. Zira uses and discloses sensitive personal data only as reasonably necessary to provide the requested Services, authenticate users, maintain security and integrity, prevent fraud, comply with law, or for other purposes permitted by applicable law. Zira does not use sensitive personal data in its controller role to infer characteristics about individuals.
2.4 How and why we use personal data
Zira may use controller personal data for the following purposes and, where applicable, legal bases:
- Provide and administer the Services. Process orders and payments; create and manage accounts; provision devices and subscriptions; authenticate users; deliver notices; and perform contracts. Legal bases may include contract performance, legitimate interests, and legal obligations.
- Support and communications. Respond to questions, troubleshoot issues, provide customer success services, administer renewals, and communicate about service availability. Legal bases may include contract performance and legitimate interests.
- Operate, secure, and improve our business. Monitor system health, analyze usage, prevent fraud and abuse, protect users and facilities, debug errors, develop features, evaluate performance, and conduct internal reporting. Legal bases may include legitimate interests, legal obligations, and consent where required.
- Sales, marketing, and events. Respond to requests, manage opportunities, personalize business-to-business outreach, administer events, and send marketing communications. Legal bases may include legitimate interests or consent. You may opt out of marketing emails at any time.
- Quality assurance and training. Record or transcribe calls or meetings when notice or consent is provided as required, review interactions, and train personnel. Legal bases may include legitimate interests and consent.
- Legal, compliance, and corporate transactions. Keep records, enforce agreements, exercise or defend legal claims, respond to lawful requests, comply with legal obligations, conduct audits, and evaluate or complete a financing, merger, acquisition, reorganization, or sale. Legal bases may include legal obligations and legitimate interests.
- Other disclosed purposes. Use data for another compatible purpose disclosed at collection or with your consent where required.
2.5 AI and automated processing
Zira uses artificial intelligence, machine learning, and computer vision to provide and improve the Services. In Zira's controller role, these technologies may help detect fraud or security issues, classify support or sales interactions, summarize communications, analyze product performance, and assist personnel. Zira does not use Product visual data in its controller role to make decisions that produce legal or similarly significant effects about individuals without appropriate notice, safeguards, and rights required by law.
The standard Zira Services are designed to analyze industrial operations, objects, processes, defects, measurements, counts, downtime, and workflow events. They are not designed to identify individuals through facial recognition or to create biometric identifiers. If Zira and a customer expressly agree to a feature that uses biometric data or makes significant decisions about individuals, the feature will be subject to additional terms, notices, and controls as required by law.
2.6 Cookies and similar technologies
Zira and its partners may use cookies, pixels, local storage, SDKs, and similar technologies to operate the website and Services, remember preferences, authenticate users, protect security, understand performance and usage, measure communications, and, where enabled, support advertising. These technologies may collect device and browser information, IP address, cookie or advertising identifiers, pages viewed, links clicked, referring URLs, and timestamps.
You can manage cookies through your browser and, where presented, Zira's cookie controls. Blocking some technologies may affect functionality. Where required by law, Zira honors recognized opt-out preference signals, such as Global Privacy Control, as a request to opt out of sale or sharing for the browser or device that sends the signal.
2.7 Marketing choices
You may unsubscribe from marketing emails using the link in the message or by contacting us. We may continue to send non-promotional messages about your account, orders, security, support, or other service matters. You may ask us not to use your information for direct marketing where applicable law provides that right.
2.8 Disclosure of personal data
Zira may disclose personal data to the following categories of recipients for the purposes described in this Policy:
- Affiliates. Companies under common control with Zira that support operations, product development, sales, support, and administration, subject to appropriate safeguards.
- Service providers and contractors. Cloud hosting, connectivity, identity, security, analytics, communications, CRM, payment, logistics, transcription, support, consulting, and other vendors that process data for Zira.
- Business partners. Resellers, implementation partners, integration partners, event sponsors, and other partners when necessary for a joint offering, referral, requested integration, or event, or with your direction.
- Professional advisers. Lawyers, accountants, auditors, insurers, lenders, and other advisers bound by confidentiality or professional duties.
- Authorities and other parties for legal or safety reasons. Courts, regulators, law enforcement, government agencies, fraud prevention bodies, and others when disclosure is required by law or reasonably necessary to protect rights, safety, security, or integrity.
- Transaction participants. Potential or actual buyers, investors, lenders, successors, or advisers in connection with a financing, merger, acquisition, reorganization, bankruptcy, or transfer of assets.
- Other recipients. Parties you direct us to disclose data to, or recipients you consent to, as permitted by law.
2.9 Sale and sharing
Zira does not sell Customer Data. Zira also does not sell personal data for money. If Zira enables advertising or measurement technologies that disclose website identifiers or Internet activity to third parties for cross-context behavioral advertising, that disclosure may be considered "sharing" or a "sale" under certain U.S. state privacy laws even when no money changes hands. Where applicable, you may opt out using available cookie controls, a recognized browser-based opt-out signal, or the contact methods in Section 8. Zira does not knowingly sell or share the personal data of individuals under 16 years of age.
2.10 Retention
Zira retains controller personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain the business relationship, comply with legal and accounting obligations, resolve disputes, enforce agreements, preserve security, and support legitimate business operations. Retention periods vary by category and context. In determining the period, Zira considers the amount, nature, and sensitivity of the data; the purposes for processing; the risk of harm from unauthorized use or disclosure; contractual commitments; whether the purpose can be achieved by other means; and legal requirements.
For example, account and transaction records may be retained for the term of the relationship and an appropriate period afterward; security logs are retained for a period appropriate to investigation and security needs; marketing and prospect data is retained until it is no longer useful for the relevant business relationship or you object, subject to suppression records; and call recordings or transcripts are retained according to the purpose stated at collection and Zira's retention schedule. Data may be retained longer when required for legal holds, disputes, audits, or compliance.
2.11 Security
Zira maintains technical, administrative, and organizational measures designed to protect personal data against unauthorized or unlawful access, use, alteration, loss, destruction, or disclosure. Measures may include access controls, authentication, encryption in transit and where appropriate at rest, logging and monitoring, network and endpoint protections, secure development practices, vendor oversight, backups, incident response procedures, and personnel confidentiality obligations.
No transmission, storage system, or security program is completely secure. You are responsible for safeguarding account credentials and promptly notifying Zira of suspected unauthorized access.
2.12 International transfers
Zira operates from the United States and Israel and uses service providers that may process personal data in other countries. Those countries may have data protection laws that differ from the laws where you live. Zira takes steps designed to provide appropriate protection for international transfers. Where required, these steps may include adequacy decisions, the European Commission's Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum or other approved mechanism, contractual safeguards, and supplementary technical or organizational measures. You may contact us for more information about applicable transfer safeguards.
3Zira as a processor or service provider
Zira customers use the Services to monitor, measure, inspect, analyze, and improve industrial operations. For Customer Data, the customer generally determines why and how personal data is processed, and Zira processes that data on the customer's documented instructions, under the customer agreement and applicable data protection addendum.
3.1 Customer Data the Services may process
Depending on the products, configuration, deployment, and customer instructions, Customer Data may include:
- Authorized-user account data, such as name, business contact information, role, user ID, permissions, authentication events, and dashboard activity.
- Images, video, or audio captured by or uploaded to the Services, which may incidentally depict workers, contractors, visitors, or members of the public near a deployed camera.
- Industrial and operational data, such as counts, dimensions, quality results, defect labels, machine or line status, cycle time, downtime, timestamps, shift information, work-station activity, and alerts.
- AI or analytics outputs, including classifications, measurements, event detections, confidence scores, summaries, and other inferences about industrial operations. Depending on customer use, some outputs may relate to an identifiable worker or user.
- Device, network, and diagnostic data, such as device identifiers, operating system, IP address, connectivity status, configuration, logs, performance metrics, and approximate or customer-provided device or facility location.
- Customer-submitted content, such as specifications, product images, labels, files, messages, notes, forms, integration data, and support materials.
Edge processing and image retention. Zira is designed to perform computer-vision inference on edge devices. Depending on configuration and the customer agreement, continuous raw video may be processed locally and not retained by Zira, while selected recordings, event images, snapshots, metadata, and AI outputs may be transmitted or stored to provide validation, dashboards, alerts, traceability, troubleshooting, and customer-requested features.
3.2 How Zira processes Customer Data
Subject to the customer agreement and documented instructions, Zira may process Customer Data to:
- Provide, configure, host, maintain, secure, and support the Services and integrations.
- Perform computer-vision inference and generate counts, measurements, quality results, downtime classifications, alerts, reports, dashboards, and other customer-selected outputs.
- Deploy, validate, calibrate, troubleshoot, and tune customer-specific models and workflows. Authorized Zira personnel or systems may access limited recordings, images, metadata, or outputs when necessary and permitted for these purposes.
- Authenticate users, administer accounts and permissions, monitor performance, diagnose errors, prevent fraud or abuse, and protect the Services.
- Improve and optimize the Services when permitted by the customer agreement or instructions. Zira may use data that has been aggregated or deidentified so it cannot reasonably identify an individual or customer, and will not attempt to reidentify it except to test deidentification safeguards as permitted by law.
- Comply with law, respond to valid legal process, and exercise or defend legal claims.
Zira does not use Customer Data to advertise to individuals, does not sell Customer Data, and does not use customer images or video to train unrelated third-party or general-purpose generative AI models without the customer's authorization.
3.3 Customer responsibilities
Customers are responsible for the lawfulness of the Customer Data and their instructions to Zira. This includes determining the legal basis for processing; providing required privacy, workplace, labor, surveillance, camera, and automated-decision notices; obtaining required consents; configuring the Services appropriately; controlling authorized-user access; responding to individual rights requests; and complying with collective bargaining, employment, biometric, and sector-specific requirements that apply to their use of the Services.
The standard Services analyze industrial operations rather than identity. Customers must not configure or use the Services for facial recognition, biometric identification, unlawful surveillance, or decisions about employment, compensation, access to essential goods or services, or other legally significant matters unless expressly authorized in writing by Zira and implemented with all notices, assessments, human review, rights, and safeguards required by law.
3.4 Requests concerning Customer Data
If your personal data was collected through a Zira customer, please direct your request to that customer. Zira will assist the customer with verified requests as required by the customer agreement and applicable law. If Zira receives a request and can identify the relevant customer, Zira may refer the request to the customer or notify the customer, unless prohibited by law.
3.5 Retention, disclosure, and transfers of Customer Data
Zira retains Customer Data according to the customer's configuration, instructions, agreement, support needs, and applicable law. At the end of the Services, Zira will make Customer Data available for return or deletion and will delete it according to the agreement and backup cycle, unless retention is required by law or permitted for security, dispute, or deidentified-data purposes.
Zira may disclose Customer Data to affiliates and approved subprocessors that help provide the Services, to parties selected or authorized by the customer, in a corporate transaction, or when legally required. Zira requires subprocessors to protect Customer Data through contractual obligations appropriate to the services they provide. International transfers of Customer Data are handled under the customer agreement and applicable transfer mechanism.
4Your privacy rights
4.1 Rights that may apply
Depending on your location and Zira's role, you may have the right to:
- Know whether and how Zira processes your personal data and receive information about categories, sources, purposes, recipients, and retention.
- Access personal data and, in some jurisdictions, obtain a portable copy.
- Correct inaccurate personal data.
- Delete personal data, subject to legal exceptions.
- Object to or restrict certain processing, including direct marketing and processing based on legitimate interests.
- Withdraw consent where processing is based on consent, without affecting prior lawful processing.
- Opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling where applicable.
- Limit certain uses and disclosures of sensitive personal data where applicable.
- Appeal a decision on a privacy request where applicable.
- Complain to a data protection authority in the country or state where you live or work, or where you believe a violation occurred.
These rights are not absolute. Zira may deny or limit a request when an exception applies, such as when data is needed to provide a requested service, protect security, comply with law, maintain privileged material, or establish or defend legal claims. Zira will not discriminate against you for exercising a privacy right.
4.2 How to submit a request
To exercise a right concerning data for which Zira is the controller, email privacy@zira.us with the subject line "Privacy Request," call +1 650-701-7026, or write to the address in Section 8. Describe the right you want to exercise and the relationship or interaction that allows us to locate the relevant data.
Zira may need to verify your identity and authority before completing a request. Verification may require matching information you provide with information Zira already maintains or requesting additional information appropriate to the sensitivity of the request. An authorized agent may submit a request where permitted by law; Zira may require proof of authorization and may also verify your identity directly. If Zira denies a request and applicable law provides an appeal right, you may appeal by replying to the decision or using the same contact methods with the subject line "Privacy Appeal."
4.3 California and other U.S. state disclosures
In the preceding 12 months, Zira may have collected the controller categories described in Section 2.2 for the sources, purposes, and recipient categories described in Sections 2.1, 2.4, and 2.8. Zira retains each category using the criteria in Section 2.10. Zira may also have processed the Customer Data categories in Section 3 on behalf of customers, which is governed by the customer relationship and not used outside the permitted business relationship except as allowed by law.
California residents may have the rights to know, access, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal service and pricing. Zira does not sell personal data for money. As explained in Section 2.9, limited website data may be considered shared if advertising technologies are enabled. Zira uses sensitive personal information only for permitted purposes and not to infer characteristics in its controller role. Requests are handled within the periods required by law, subject to verification and exceptions.
Some U.S. states also provide rights to opt out of targeted advertising, certain sales, or profiling in furtherance of decisions producing legal or similarly significant effects, as well as a right to appeal. Zira will honor such rights when applicable to Zira and the processing at issue.
4.4 EEA, United Kingdom, and Switzerland
If the GDPR, UK GDPR, or Swiss data protection law applies and Zira is the controller, Zira relies on one or more legal bases described in Section 2.4, including performance of a contract, legitimate interests, compliance with legal obligations, protection of vital interests, or consent. Where Zira relies on legitimate interests, it considers Zira's interests, the effects on individuals, and appropriate safeguards. You may object to processing based on legitimate interests and have an absolute right to object to direct marketing.
You may lodge a complaint with the supervisory authority in your country. If you need help identifying the appropriate authority or applicable Zira contact or representative, contact us using Section 8.
5Children
The Services are intended for businesses and are not directed to children under 16. Zira does not knowingly collect personal data directly from children under 16 through its website or account-registration process. If you believe a child has provided personal data to Zira, contact us. This section does not prevent Customer Data from incidentally depicting minors near a customer's facility; the customer remains responsible for the lawful deployment of cameras and related notices.
6Third-party sites and integrations
The Services may link to third-party websites, services, applications, or integrations. Their privacy practices are governed by their own notices, not this Policy. When a customer enables an integration, Zira may exchange Customer Data with the provider at the customer's direction. Review the third party's privacy terms before using the integration.
7Changes to this Policy
Zira may update this Policy to reflect changes in the Services, practices, technologies, legal requirements, or other factors. Zira will update the "Last updated" date and provide additional notice of material changes when required by law. The current version will be posted on Zira's website.
8Contact us
For questions, privacy requests, or complaints, contact:
Zira Group Inc., Attention: Privacy, 400 Concar Drive, San Mateo, California 94420, United States. Email: privacy@zira.us | Telephone: +1 650-701-7026 | Website: zira.us