Privacy policy
Last updated
What personal data ZicReach handles, why, and how to use your rights. We do not sell personal data, and AI providers may not train on your content.
Google sign-in: if you use "Continue with Google", we receive only your name and email address (plus your Google account ID and whether the email is verified), and we use them only to create your ZicReach account and sign you in. We do not share Google user data with any third party. Full details are in section 2.
1.Who we are#
ZicReach ("ZicReach", "we", "us") is based in Aberdeen, United Kingdom, and is the data controller described in this policy. This policy explains how we handle personal data when you visit zicreach.com, use the platform at app.zicreach.com, or appear in the B2B directory behind the Leads Engine.
It works alongside our Terms of use.
2.How we use Google user data#
ZicReach lets you create an account and sign in with "Continue with Google". This section explains, in full, what Google user data our app receives, what we do with it, how we protect it, how long we keep it and how you can delete it.
What Google user data we access
When you choose "Continue with Google", we ask Google only for the basic sign-in permissions
openid,emailandprofile. From these we receive exactly four things:- your name,
- your email address,
- whether Google has verified that email address, and
- your Google account ID (a number that identifies your Google account to us).
We do not request or receive your Google password, Gmail messages, Google Drive files, Calendar, Contacts, profile photo or any other Google data. We do not ask for any permission beyond basic sign-in.
How we use Google user data
We use your name and email address for one purpose only: to create your ZicReach account and to sign you in to it. In practice this means:
- Creating your account: the first time you continue with Google, we create a ZicReach account with your name and email address, and mark the email as verified because Google has verified it.
- Signing you in: each later time, we match your Google account ID or email address to your existing ZicReach account and sign you in.
- Your account: your name is shown in your account, and your email address is the address of your ZicReach account, used for account and security messages such as sign-in alerts.
We do not use Google user data for advertising, marketing lists, profiling, selling, building our B2B directory or training or improving AI models. We do not use it for any purpose other than creating and signing in to your ZicReach account.
Sharing, transfer and disclosure
We do not share, sell, rent, transfer or disclose Google user data to any third party. It stays inside ZicReach and is used only by our own application to create and sign in to your account. The only exception would be if we are legally required to disclose information by a valid court order or law, and we would tell you unless the law forbids it.
How we store and protect it
- Your name, email address and Google account ID are stored in your ZicReach account record in our database.
- All data travels over encrypted connections (HTTPS/TLS), and our database and backups are encrypted at rest.
- Only our application and a small number of authorised staff who need it to support your account can access it, and that access is logged.
- We never write Google user data into logs, analytics tools or AI prompts.
- The temporary access token Google gives us during sign-in is used once to read your name and email, and is never stored.
How long we keep it and how to delete it
- We keep your name, email address and Google account ID only while your ZicReach account exists.
- You can ask us to delete your account, or to unlink Google sign-in from it, at any time through the chat at the bottom right of any page or through our Contact page. We confirm the request and complete it within 30 days.
- When your account is deleted, we remove your Google user data from our active systems within 30 days, and from backups when they expire.
- You can also remove ZicReach's access to your Google account yourself at any time at myaccount.google.com/permissions.
Limited Use
ZicReach's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3.Our two roles#
Data protection law gives us different responsibilities depending on whose data it is:
- Controller for data about our own customers, website visitors and the business contacts in our directory. We decide why and how that data is used.
- Processor for the data customers put into their workspaces: their leads, lists, campaigns, mailbox messages and CRM records. We process it only on the customer's instructions. If you are a lead in a customer's campaign, that customer is responsible for contacting you and is your first point of contact.
4.What we collect#
From you
- Account details: name, work email, company, password (stored as a salted hash), two-factor settings and workspace role.
- Billing details: plan, invoices and billing address. Card details go straight to our payment processor; we never see or store full card numbers.
- Connected mailboxes: addresses and the tokens or credentials needed to send and read mail, stored encrypted.
- What you send us: support chat messages, demo and custom plan requests, and feedback.
- If you sign up or sign in with Google: your Google account ID, name, email address and whether Google has verified that email. Section 2 explains exactly how we use this.
Automatically
- Usage data: pages and features used, actions taken, device and browser type, IP address and approximate location derived from it.
- Security logs: sign-ins, API key use and audit log entries.
- Cookies and similar technologies, described in section 10.
For the directory
- Business contact data about professionals: name, job title, employer, business email, business phone, work location and public professional profile information, gathered from public sources and licensed data providers.
5.How we use it#
Purpose Legal basis (GDPR) Providing the Service, running campaigns, warmup and enrichment you ask for Contract Billing, tax and accounting Contract, legal obligation Support through the chat, including handoff to a person Contract, legitimate interests Security, fraud and abuse prevention, protecting deliverability for all customers Legitimate interests, legal obligation Improving the product from aggregated usage Legitimate interests Product news and the monthly letter Consent or legitimate interests; you can opt out at any time Operating the B2B directory for prospecting Legitimate interests, balanced against your rights We do not sell personal data for money, and we do not use customer workspace content to build our directory.
6.AI processing#
Features such as ZicAgent, AI columns, the sequence writer and warmup email writing send the relevant text to an AI provider to generate a result. If you add your own model key, those requests go to your provider under your agreement with them.
- We send only what the task needs.
- Our AI providers may not use your content to train their models, and they keep it only as long as needed to provide the service and prevent abuse.
- Reply sorting (Interested, Neutral, Not interested) uses phrase rules, not AI.
- We do not make decisions with legal or similarly significant effects about you based solely on automated processing.
8.International transfers#
Our providers may process data outside your country, including outside the EEA and UK. When they do, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses (with the UK addendum where needed), plus supplementary measures where appropriate.
9.How long we keep it#
- Account and workspace data: for as long as your account is open.
- Deleted leads can be restored for 45 days and deleted tables for 90 days; after that they are erased.
- After an account closes: available for export for 30 days, then deleted from live systems, and from backups within a further 30 days.
- Billing records: as long as tax and accounting law requires, usually 6 to 10 years.
- Security logs: up to 12 months, unless needed longer to investigate an incident.
- Suppression lists (people who asked not to be contacted): kept as long as needed to keep honouring the request.
11.How we protect it#
We use encryption in transit, encryption at rest for mailbox credentials, API keys and other secrets, hashed passwords, two-factor sign in, role-based access inside workspaces, audit logs, IP blocking for abusive traffic and the least access necessary for our own staff. Support staff can view a workspace only with a logged, time-limited access session. No system is perfectly secure; if a breach affects your data, we will tell you and the relevant authorities as the law requires.
Google user data (section 2) gets the same protection: it travels only over TLS, is stored encrypted at rest in our database, is readable only by the application and by authorised staff who need it to support your account, and is never copied into logs, analytics or AI prompts.12.Your rights#
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy;
- correct data that is wrong or incomplete;
- have your data deleted, including removal from our B2B directory;
- object to processing based on legitimate interests, including prospecting, and to direct marketing at any time;
- restrict processing, or receive your data in a portable format;
- withdraw consent where we rely on it;
- complain to your data protection authority.
California residents have rights under the CCPA and CPRA to know, delete and correct personal information and to opt out of its sale or sharing. We do not sell personal information or share it for cross-context behavioural advertising, and we will not treat you differently for exercising your rights.
To use any of these rights, ask in the chat at the bottom right of this page. We may need to verify your identity, and we reply within one month (45 days under the CCPA). If your data is in a ZicReach customer's workspace, we will pass your request to that customer and help them respond.
13.Children#
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children.
14.Changes to this policy#
We will update the date at the top when this policy changes, and tell account owners in the app and by email before material changes take effect. If we ever change how we access, use, store or share Google user data, we will update section 2 first, notify affected users, and ask for consent again where it is required. Earlier versions are available on request.
15.Contact#
For any privacy question or request, use the chat at the bottom right of any page on zicreach.com or app.zicreach.com and say it is a privacy request, or reach us through our Contact page. Both go to the person responsible for data protection.
ZicReach, Aberdeen, United Kingdom.
If you are not satisfied with our answer, you can complain to the UK Information Commissioner's Office (ico.org.uk) or to the data protection authority where you live.
Questions about this policy?
Our team answers in the chat. Ask for a copy, a correction or a deletion there.