Legal

Privacy Policy

This policy explains how Zavabase handles account information, workspace data, connected-service data, and information used to operate and secure the service.

Last updated: July 27, 2026

1. Scope and our role

This Privacy Policy applies to the Zavabase websites, applications, APIs, support channels, and related services (collectively, the “Service”). “Zavabase,” “we,” “us,” and “our” refer to the operator of the Service.

Organizations use Zavabase to collect, organize, process, analyze, and deliver business data. For workspace content and personal information submitted by or for a customer, the customer generally determines why and how that information is processed, and Zavabase processes it on the customer's behalf. For account administration, product operations, security, billing, and our own business records, Zavabase may determine the purposes and means of processing.

If you use Zavabase through your employer or another organization, that organization's privacy notices and instructions may also apply. Questions about workspace records should usually be directed to the relevant workspace administrator first.

2. Information we collect

Account and organization information

We collect information such as names, email addresses, authentication and multi-factor settings, organization and workspace membership, roles, preferences, support contacts, and account-administration records.

Customer content and configuration

The Service processes information that customers upload, import, create, query, or configure. This may include datasets, files, documents, form responses, pipeline inputs and outputs, dashboard configurations, workflow definitions, prompts, messages, and other records selected by a customer. Customers are responsible for determining what information is appropriate to submit to the Service.

Connection and integration information

When a user connects a third-party service, we receive the authorization credentials, account identifiers, configuration, provider metadata, file or folder information, and content needed to perform the requested integration. OAuth access and refresh tokens are stored in encrypted form.

Usage, device, and operational information

We collect logs and technical information such as IP address, browser and device details, timestamps, requested routes, feature usage, pipeline and workflow events, errors, security signals, delivery receipts, and audit history. We may also receive information when you contact support or otherwise communicate with us.

3. How we use information

We use information to:

  • Provide, maintain, and improve the Service.
  • Authenticate users and administer organizations, workspaces, permissions, and subscriptions.
  • Run imports, pipelines, schedules, workflows, queries, dashboards, forms, connected deliveries, and customer-requested AI features.
  • Monitor executions, verify delivery results, troubleshoot failures, and provide support.
  • Protect the Service, customers, users, and third parties from fraud, abuse, security threats, and unlawful activity.
  • Comply with law, enforce agreements, and maintain business, financial, and compliance records.
  • Communicate about the Service, including operational, security, support, and administrative notices.

4. Google user data

When you authorize a Google Drive connection, Zavabase may receive Google account identifiers and profile information, OAuth credentials, and Drive information available under the permissions shown during authorization. Drive information may include file and folder names, identifiers, paths, metadata, permissions, content, and files produced for delivery.

We use Google user data to let authorized users browse and configure Drive sources and destinations, import selected or configured files, run scheduled source checks and pipeline operations, deliver outputs, display connection and execution status, verify remote delivery, and investigate errors or security events.

We do not sell Google user data, use it for advertising, or use it to train generalized artificial-intelligence or machine-learning models. Human access is limited to circumstances where it is requested or consented to by the user, necessary for security or abuse investigation, required by law, or permitted for internal operations using appropriately aggregated or de-identified information.

Zavabase's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can stop future Google Drive access by deleting the connection in Zavabase or revoking Zavabase in your Google Account permissions. Deleting a connection removes its stored OAuth credentials. Content already imported into a workspace, included in a retained execution artifact, or delivered to another configured destination remains subject to the workspace's deletion and retention controls.

5. Connected services and AI features

The Service can connect to providers such as Google Drive, Microsoft OneDrive, S3-compatible storage, SFTP servers, email systems, and customer-configured APIs. Your use of those services remains governed by their terms and privacy practices. Zavabase accesses a connected service only after it is configured or authorized and uses the connection to perform requested Service functions.

If a customer chooses to use an AI feature, relevant customer content may be sent to an AI service provider to produce the requested result. Access is bounded by workspace permissions and configured governance controls. Customers should review AI-generated results before relying on them.

6. How we disclose information

We may disclose information:

  • To vendors that provide infrastructure, storage, communications, monitoring, security, support, payment, and other services for Zavabase under contractual safeguards.
  • To connected services and destinations when an authorized user configures an import, action, or delivery.
  • To workspace owners and administrators who manage the applicable organization and its users.
  • When required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Service.
  • In connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and notice requirements.
  • With your direction, consent, or as otherwise disclosed.

We do not sell personal information or share personal information for cross-context behavioral advertising.

7. Retention and deletion

We retain information for as long as needed to provide the Service, meet the customer's configured or contractual requirements, protect the Service, resolve disputes, and comply with legal obligations. Retention varies by record type and workspace plan.

Pipeline execution artifacts are retained according to the applicable workspace plan or contractual override shown in the Service and are scheduled for deletion after that period. Connection credentials are retained while the connection remains active and are deleted when the connection is deleted. Customer datasets and other workspace content remain until deleted by an authorized user, removed under the customer's instructions, or deleted after termination in accordance with the applicable agreement.

Limited copies may persist temporarily in backups, security records, or logs until those systems complete their normal retention cycles. We may retain information longer when required by law, a litigation hold, or a valid contractual obligation.

8. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encryption for stored connection secrets, transport encryption, workspace authorization boundaries, logging, monitoring, and operational backup practices. No system can guarantee absolute security, and customers remain responsible for protecting their credentials, selecting appropriate permissions, and configuring their workspaces safely.

9. Your choices and rights

Depending on your location, you may have rights to request access, correction, deletion, portability, restriction, or objection regarding personal information. You may update certain profile and workspace information in the Service, disconnect third-party connections, or ask your workspace administrator to manage customer-controlled records.

To submit a privacy request, email support@zavabase.com. We may need to verify your identity and authority. If Zavabase processes the relevant information solely for a customer, we may direct the request to that customer.

10. International processing

Zavabase and its providers may process information in countries other than where you live. Where required, we use contractual or other recognized safeguards for cross-border transfers.

11. Children

The Service is intended for organizations and is not directed to children under 13 or the minimum age required by applicable law. We do not knowingly collect personal information from children through the Service.

12. Changes to this policy

We may update this Privacy Policy to reflect changes in the Service, our practices, or legal requirements. We will post the updated policy with a revised date and provide additional notice when required.

13. Contact us

Questions or requests concerning this Privacy Policy can be sent to support@zavabase.com.