Privacy Policy
Last updated: July 25, 2026
ziema29 Tech("we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our website, contact us, subscribe to updates, apply for roles, register interest in our products, or use our client portal, software products (including ZiemaOps AI), and related services (collectively, the "Services").
We are based in Brantford, ON, Canada. If you are in Canada, our handling of personal information is also subject to applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies.
1. Who this policy applies to
This policy applies to:
- Visitors to our website and marketing pages
- Prospective and current clients using our client portal or professional services
- Users who sign up for product waitlists, early access, or subscriptions (including ZiemaOps AI)
- Employees and contractors of customer organizations who access a workspace we host
- Job applicants and newsletter subscribers
Where we provide software products to business customers, we typically process personal information about our customers' users on behalf of the customer organization. In those cases, the customer is generally the controller of its users' data and we act as a service provider processing data under the customer's instructions, subject to our agreement and this policy.
2. Information we collect
Depending on how you interact with us, we may collect:
- Contact and inquiry data — name, email, company, phone, job title, project details, and messages you submit through contact forms, hosting sign-up, product waitlists, or sales inquiries.
- Account and portal data — login email, account status, profile information, support tickets, messages, and documents you upload or receive through the client portal.
- Product and workspace data — organization name, workspace settings, user roles, agent and workflow configuration, connector authorizations, approval decisions, run history, audit logs, and operational records created within ZiemaOps AI or other ziema29 products.
- AI and automation data — prompts, inputs, outputs, classifications, tool calls, citations, confidence scores, knowledge-source content you upload, and metadata needed to operate, secure, and improve AI features. We do not use customer workspace content to train public foundation models unless you explicitly opt in to a separate program.
- Billing data — invoice details, subscription status, plan entitlements, and payment-related metadata. Payment card details are processed by our payment provider (e.g. Stripe) and are not stored on our servers.
- Hosting and service data — company name, selected plan, AWS account identifiers, and operational data needed to provision and manage hosting services.
- Careers data — information you provide when applying for a role, including résumé/CV details if you email us or use an application link.
- Newsletter and product updates — email address and communication preferences if you subscribe to updates or register for early access.
- Technical data — IP address, browser type, device information, pages viewed, session identifiers, and similar usage data collected through standard server logs, cookies, or analytics tools.
3. How we use information
We use personal information to:
- Respond to inquiries and provide requested Services
- Create and manage client accounts, workspaces, and project environments
- Deliver project updates, documents, invoices, and support communications
- Operate software products, including running agents, workflows, approvals, and integrations
- Process payments, manage subscriptions, hosting plans, and usage metering
- Provision and operate cloud infrastructure where applicable
- Maintain security, audit trails, fraud prevention, and abuse detection
- Review job applications and manage recruiting
- Send newsletters, product updates, or early-access communications where permitted
- Improve our website, products, reliability, and customer experience
- Comply with legal obligations and enforce our agreements
4. Legal bases for processing
We process personal information based on one or more of the following, as applicable:
- Your consent (e.g. newsletter signup, optional marketing, or certain product registrations)
- Performance of a contract or steps taken at your request before entering a contract
- Our legitimate interests, such as operating and securing the Services, improving products, and communicating about similar services, provided those interests are not overridden by your rights
- Compliance with legal obligations
5. AI processing and automated decision-making
ZiemaOps AI and related products use artificial intelligence to classify requests, retrieve knowledge, generate drafts, propose actions, and assist with workflow automation. This may involve sending relevant inputs to approved model providers through our infrastructure.
Automated outputs may inform or trigger actions in your workspace, but high-risk actions can be configured to require human approval. You are responsible for reviewing automated recommendations before they affect your business, customers, or employees.
We implement guardrails such as access controls, knowledge-source restrictions, logging, and policy checks. We do not guarantee that AI outputs will always be accurate or free from bias.
6. How we share information
We do not sell your personal information. We may share information with trusted service providers who assist us in operating the Services, including:
- Cloud infrastructure providers (e.g. Amazon Web Services)
- Payment processors (e.g. Stripe)
- Email and notification delivery providers (e.g. Resend)
- Approved large language model and AI infrastructure providers
- Identity, collaboration, and integration partners you connect (e.g. Microsoft 365, Google Workspace)
- Professional advisors where reasonably necessary
These providers are authorized to use personal information only as needed to perform services for us or, where you connect an integration, as directed by your configuration. We may also disclose information if required by law, to protect rights and safety, or in connection with a business transaction such as a merger or acquisition.
Enterprise customers may request additional detail about sub-processors or a data processing addendum by contacting us.
7. Multi-tenant isolation and workspace security
Our software products are designed for multi-tenant use. Customer workspaces are logically isolated so that agents, knowledge, credentials, logs, billing, and indexes are segregated by tenant. Access within a workspace is further controlled through roles, permissions, and policies configured by the customer organization.
Our internal support staff do not access customer workspace content by default. Where troubleshooting requires access, it should occur only through an approved, time-limited, audited support process with customer authorization where appropriate.
8. International transfers
We and our service providers may process or store information in Canada, the United States, or other countries. Where information is transferred across borders, we take reasonable steps to ensure appropriate safeguards are in place consistent with applicable law.
AI model providers and cloud infrastructure partners may process data in regions outside Canada. Customers with specific data residency requirements should discuss available deployment options with us before subscribing.
9. Data retention
We retain personal information only as long as necessary for the purposes described in this policy, to meet legal, accounting, or reporting requirements, or to resolve disputes. Retention periods vary by data type, including:
- Active client and workspace records — for the duration of the relationship and a reasonable period afterward to support exports, billing, or legal obligations.
- Agent runs and audit logs — as configured by plan, workspace policy, or agreement, to support troubleshooting, governance, and compliance.
- Marketing and waitlist data — until you unsubscribe, withdraw interest, or we no longer need it for the original purpose.
- Backups — for a limited period consistent with our disaster recovery practices before rolling deletion.
When you cancel a subscription, we may delete or anonymize workspace data after any applicable export window, unless retention is required by law or your agreement.
10. Security
We implement administrative, technical, and organizational measures designed to protect personal information, including access controls, encryption in transit, tenant isolation, logging, and secure cloud infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
You are responsible for safeguarding your account credentials, reviewing user access within your workspace, and configuring appropriate approval and connector permissions.
11. Cookies and similar technologies
Our website and web applications may use cookies and similar technologies to maintain sessions, remember preferences, protect against abuse, and understand how visitors use the site. You can control cookies through your browser settings. Disabling cookies may affect certain features, such as staying signed in to the client portal or a product workspace.
12. Your rights and choices
Depending on your location, you may have rights to access, correct, update, or delete personal information, withdraw consent where processing is consent-based, or object to certain processing. You may also unsubscribe from marketing emails at any time using the link in the message or by contacting us.
If you are an employee or user of a customer organization, many requests relating to workspace data should be directed to your organization's administrator, who controls the account. We will assist our customers in responding where appropriate.
To exercise your rights directly with us, contact support@ziema29.com. We may need to verify your identity before responding. If you are not satisfied with our response, you may have the right to contact your local privacy regulator.
13. Children
The Services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
14. Third-party links and integrations
Our website may link to third-party sites or services, including product subdomains such as ops-ai.ziema29.com. Connected integrations (e.g. email, CRM, or collaboration tools) are governed by their own terms and privacy policies. We are not responsible for third-party practices outside our reasonable control.
15. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top indicates when it was last revised. Material changes will be posted on this page. Where required, we will provide additional notice.
16. Contact us
For privacy-related questions, sub-processor inquiries, or data processing requests, contact us at support@ziema29.com.