Privacy Policy

Last Updated: [ ], 2024

Thank you for choosing to be part of our community at zast.ai, Inc. (“Company”, “we”, “us”, or “our”).

We are committed to protecting your personal information and your rights to privacy. If you have any questions or concerns about our notice, or our practices regarding your personal information, please contact us at support@zast.ai.

When you visit our website https://zast.ai and use our services, you trust us with your information, including personal information. We take your privacy very seriously. This privacy notice discloses what information we collect, how we use it and your rights about it.

This privacy notice applies to all information collected through our website (such as https://zast.ai), and/or any related services, sales, marketing and other activities (we refer to them collectively in this privacy notice as the "Services"). Please read this privacy notice carefully as it will help you make informed decisions about sharing information with us.

1. What information do we collect?

Information You Submitted to the Services

In Short: We collect information that you submit to the Services. We collect information that you submit to the Services, such as your name, email address, comments, suggestions, feedback, opinions, and media.

Information we collect to deliver and improve our services.

In Short: We collect necessary information to provide our Services.

deploy various services and may utilize technologies such as cookies to automatically collect information when you visit our website, operate, or maneuver our Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services and other technical information. This information is critical for our Services to operate properly and securely.

Following sections provide details about how cookies and customer data are used in our services.

Information from third parties

In Short: We collect various types of information from third under certain circumstances.

We receive various types of information from third parties on some occasions, for example, when we jointly offer services or sponsor events. We also collect data from third-party security providers and online databases in connection with our research activities that relate to active or historic threats, vulnerabilities, and risks around the world. This can include data like domain names, IP addresses, email accounts, and usernames that are associated with security risks (for example, known compromised accounts and usernames), and we use this information to enhance the security services and solutions we provide to you. Additionally, we also collect certain information from publicly available sources, including the dark web, in connection with our research activities, solutions, and services, in particular to identify and help our customers protect against the likes of historic and/or future security threats, vulnerabilities, and risks. This information can include the likes of domain names, IP addresses, email addresses, and usernames and any other data that might be associated with the applicable security risks of issues identified (for example, known compromised accounts and usernames).

2. How do we use cookies?

In Short: Cookie usage has been categorized. Non-essential cookie categories might be disabled by end users while essential categories, such as authentication related cookies, provide core service functions, and therefore must be enabled to ensure the proper operation of services.

Amongst technologies created and used at zast.ai, some of them rely on third-party services and APIs with cookie requirements. Any cookie that is not strictly required for the operation of our site, including any targeting advertising service, can be disabled via the Cookie Consent process. We also honor Global Privacy Control / Do Not Track signals that may be configured in your browser.

We categorize the third-party services that zast.ai relies on into three broad categories.

Strictly necessary (always active)

Strictly necessary services are essential for the operation of zast.ai’s Cloud Platform, and as such, they cannot be turned off. Examples include tracking security critical information (such as tracking a user’s authenticated session) or storing state in response to actions a user takes (e.g., setting privacy preferences or filling out forms). While you can configure your browser to block or notify you about these cookies, certain parts of the site may not function properly. These cookies do not store any personally identifiable information and are not shared with third parties.

Functional

Functional services enhance website functionality and personalization. They may be set by zast.ai or third-party providers whose services are incorporated into zast.ai’s Cloud Platform. Disabling these cookies may result in certain services not functioning correctly.

Performance

Performance services enable zast.ai to count visits and analyze traffic sources to measure and enhance the website's performance. They provide insights into the most and least popular pages and how visitors navigate the site. Targeting services help build profiles of our users and give us insights into the potential purchasers of our product. These services rely on identifying your browser and internet device uniquely.

Social media

Our site integrates various social media services and are used to let users share zast.ai content and information more broadly. They can track your browser across other sites and can be used by the social media services to create an interest profile. This may influence the content and ads you encounter on other websites. Blocking social media cookies will disable content sharing integrations.

You have the option to block cookies by adjusting your browser settings or using third-party tools such as uBlock Origin to refuse all cookies or specific ones. Please note that if you choose to block all cookies, including essential cookies, it may restrict your access to certain sections or features of zast.ai’s website.

3. How do we use this information?

In Short: We use the collected information to provide, improve, and secure our services. You can control certain uses of your information, but some are essential for our core operations.

To deliver, improve, and develop our offerings.

We are able to deliver our sites, solutions and services and better help our customers keep their environments safe by using the information we collect above.

To communicate with you

We use your information to communicate with you about our sites, solutions, services, features, surveys, newsletters, offers, promotions, and events, and to provide other news or information about us and our partners, in accordance with your communications preferences.

We will also use your information to respond to you when you contact us.

To conduct research initiatives

The vast majority of the data we collect through our research initiatives is data that’s publicly available. It is collected to educate and enrich the security community and foster secure adoption of technology.

For Advertising Purposes

We may use the information we collect to personalize our advertising and marketing communications and to deliver promotions and offers to you that we think may interest you.

For our Internal Business Purposes

We may use the information we collect for our internal business purposes, such as data analysis, audits, developing new products and services, enhancing our sites, solutions, and services, improving our products and services, identifying site usage trends, and determining the effectiveness of our promotional campaigns.

For Legal Purposes

We may use the information we collect as we believe to be necessary or appropriate: (i) under applicable law; (ii) to comply with legal process; (iii) to respond to requests from public and government authorities; (iv) to enforce this Privacy Policy and our Terms of Use; (v) to protect our operations; (vi) to protect our rights, privacy, safety or property, and/or that of you or others; and (vii) to allow us to pursue available remedies or limit the damages that we may sustain.

4. Will your information be shared with anyone?

In Short: We only share information with your consent, to comply with laws, to provide you with services, to protect your rights, or to fulfill business obligations.

We may process or share data based on the following legal basis:

• Consent: We may process your data if you have given us specific consent to use your personal information in a specific purpose.

• Legitimate Interests: We may process your data when it is reasonably necessary to achieve our legitimate business interests.

• Performance of a Contract: Where we have entered a contract with you, we may process your personal information to fulfill the terms of our contract.

• Legal Obligations: We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process, such as in response to a court order or a subpoena (including in response to public authorities to meet national security or law enforcement requirements).

• Vital Interests: We may disclose your information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person and illegal activities, or as evidence in litigation in which we are involved. More specifically, we may need to process your data or share your personal information in the following situations:

• Vendors, Consultants and Other Third-Party Service Providers. We may share your data with third party vendors, service providers, contractors or agents who perform services for us or on our behalf and require access to such information to do that work. Examples include: payment processing, data analysis, email delivery, hosting services, customer service and marketing efforts. We may allow selected third parties to use tracking technology on the Services, which will enable them to collect data about how you interact with the Services over time. This information may be used to, among other things, analyze and track data, determine the popularity of certain content and better understand online activity. Unless described in this Policy, we do not share, sell, rent or trade any of your information with third parties for their promotional purposes.

• Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

• Third-Party Advertisers. We may use third-party advertising companies for analytics when you visit the Services. These companies may use information about your visits to our website(s) and other websites that are contained in web cookies and other tracking technologies in order to provide advertisements about goods and services of interest to you.

• Business Partners. We may share your information with our business partners to offer you certain products, services, or promotions.

• Other Users. When you share personal information (for example, by posting comments, contributions, or other content to the Services) or otherwise interact with public areas of the Services, such personal information may be viewed by all users and may be publicly distributed outside the Services in perpetuity. Similarly, other users will be able to view descriptions of your activity, communicate with you within our Services, and view your profile.

5. Is your information transferred internationally?

In Short: We may transfer, store, and process your information in countries other than your own.

Our servers are located in United States. If you are accessing our Services from outside United States, please be aware that your information may be transferred to, stored, and processed by us in our facilities and by those third parties with whom we may share your personal information (see " WILL YOUR INFORMATION BE SHARED WITH ANYONE? " above), in United States, and other countries.

If you are a resident in the European Economic Area, then these countries may not have data protection or other laws as comprehensive as those in your country. We will however take all necessary measures to protect your personal information in accordance with this privacy notice and applicable law.

6. How long do we keep your information?

In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this privacy notice unless otherwise required by law.

We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this policy will require us keeping your personal information for longer than 2 years.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

7. How do we keep your information safe?

In Short: We aim to protect your personal information through a system of organizational and technical security measures.

We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. However, please also remember that we cannot guarantee that the internet itself is 100% secure. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the services within a secure environment.

8. Do we collect information from minors?

In Short: We do not knowingly collect data from or market to children under 18 years of age.

We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data, we have collected from children under age 18, please contact us at support@zast.ai.

9. What are your privacy rights?

In Short: In some regions, such as the European Economic Area, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.

In some regions (like the European Economic Area), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; and (iv) if applicable, to data portability. In certain circumstances, you may also have the right to object to the processing of your personal information. To make such a request, please use the contact details provided below. We will consider and act upon any request in accordance with applicable data protection laws.

If we rely on your consent to process your personal information, you have the right to withdraw your consent at any time. Please note however that this will not affect the lawfulness of the processing before its withdrawal.

If you are resident in the European Economic Area and you believe we are unlawfully processing your personal information, you also have the right to complain to your local data protection supervisory authority. You can find their contact details here: https://commission.europa.eu/about-european-commission/contact_en.

10. Does zast.ai support do-not-track or global privacy controls?

In Short: Yes, we support Do Not Track (DNT) and Global Privacy Control (GPC) signals.

Most web browsers offer Do Not Track (“DNT”) or Global Privacy Control (“GPC”) settings that you can activate to signal your privacy preferences. zast.ai’s Cookie Preferences honors both DNT and GPC requests and will disable the performance and social media categories when requested in this case.

See the Global Privacy Control or EFF Privacy Badger websites for more information on how to enable these features for your browser.

11. I'm from the European Economic Area/the UK – is there anything else I should know?

In Short: Yes, if you're in the EEA or UK, you have additional rights under GDPR, including data access, rectification, erasure, and portability. We comply with GDPR requirements and provide mechanisms for you to exercise these rights.

Legal basis for processing personal information

If you are an individual in the European Economic Area or the UK, our legal basis for collecting and using your information will depend on the information concerned and the specific context in which we collect it.

However, we will normally collect information from you only where we have your consent to do so, where we need the information to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. Where we collect and use your information in reliance on our legitimate interests (or those of any third party), it will normally be obvious from the context what those legitimate interests are. For example, in relation to personal data processed in connection with our provision of services and/or research activities, it is in the legitimate interests of us and our customers to detect, remediate and protect against a broad variety of cyber threats.

If we are processing information about you on behalf of a customer in the course of providing our services and solutions to them (i.e., as a data processor), then it is our customer's responsibility to determine the legal basis for the processing we conduct on their behalf. If you ask us about information we are processing on behalf of a customer, we will direct you to speak with the relevant customer.

Additional data protection rights

In addition to your rights to access, correct, update, and delete your information described above, and your right to opt-out of communications also explained above, you also have the right to object to processing of your information, ask us to restrict processing of your information or to request portability of your information.

If we have collected and process your information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your information conducted in reliance on lawful processing grounds other than consent.

If you are unhappy with the way we have processed your information, you have the right to complain to a data protection authority. For more information, please contact your local data protection authority.

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.

Data Protection Officer

To contact our Data Protection Officer, please e-mail support@zast.ai.

12.Do we make updates to this policy?

In Short: Yes, we may update this policy, including as we deem to stay compliant with relevant laws.

We may update this privacy notice from time to time. The updated version will be indicated by an updated “Revised” date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.

13. How can you review, update, or delete the data we collect from you?

Based on the laws of some countries, you may have the right to request access to the personal information we collect from you, change that information, or delete it in some circumstances. To request to review, update, or delete your personal information, please submit a request by clicking here We will respond to your request within 30 days.

14. How can you contact us about this policy?

If you have questions or comments about this policy, you may email us at support@zast.ai or by post to:

zast.ai, Inc.
XX  XXXX Street,
CITY, POST CODE
United States