Zypheral — Privacy Policy

Effective date: 10 September 2026 Last updated: 10 September 2026 Controller: Zypheral ("Zypheral", "we", "us"), operator of www.zypheral.com and the Zypheral customer dashboard at dash.zypheral.com. Contact: support@zypheral.com

Zypheral's company registration details will be added to this policy once the operating entity is formally registered. Until then, support@zypheral.com is the contact point for every matter covered by this policy, including data protection requests.


1. Scope of this policy

1.1 This policy explains how we handle personal data when you visit our website (www.zypheral.com), create an account, sign in to and use the Zypheral customer dashboard (dash.zypheral.com), purchase or use our hosting and email services, or contact us. Together these are referred to as the Services, and the dashboard is referred to as the application.

1.2 Two different roles. Our services involve personal data in two distinct capacities, and different rules apply to each:

We act asCoversGoverned by
Account dataControllerYour account, billing, support and security recordsThis policy
Customer ContentProcessorWebsite files, databases, mailboxes and email messages you store on the servicesOur Data Processing Agreement, on your instructions

1.3 Where we act as processor, we handle Customer Content on your documented instructions in order to provide the service. If Customer Content includes personal data about your own customers, employees or contacts, you are the controller of that data and are responsible for having a lawful basis for it, for informing those individuals, and for responding to their requests. This policy does not describe your obligations to them.


2. Personal data we collect

2.1 Data you give us

DataWhy we hold it
NameIdentifying your account and addressing communications
Email addressAccount identity, sign-in, service and billing notices, support
PasswordAuthentication. Stored only as a salted cryptographic hash, never in readable form
CountryTax determination and billing details for payment processing
Interface languagePresenting the dashboard and our notifications in your chosen language
Profile image referenceDisplaying your avatar in the dashboard, where you set one
Support correspondenceAnswering and evidencing your enquiry

2.2 Data created when you use the services

DataWhy we hold it
Sign-in sessions, including approximate device, operating system and browser, the IP address last used, and the time of last useLetting you review and revoke your own active sessions, and detecting unauthorised access
Records of significant account-administration actions, including which user performed them and the originating IP addressSecurity, dispute resolution and audit, particularly where several people share access to one account
Subscription and entitlement records — plan, status, renewal dates, and non-payment statusOperating the subscription and enforcing plan limits
Service records — the domains, websites and mailboxes on your account, storage used, and provisioning statusDelivering and supporting the service
Notifications we have generated for youShowing your notification history and preventing duplicates
Web-push subscription identifiers, if you enable browser notificationsDelivering push notifications you asked for
Operational and security logsDiagnosing faults, investigating abuse, and protecting the platform

2.3 Data from third parties

identifier and basic profile information. Signing in with Google is described in full in section 3. We never receive your password for that provider.

card details (brand, last four digits, expiry) so you can identify your payment method.


3. Signing in with Google

Creating a Zypheral account with Google, or signing in to the Zypheral dashboard with Google, is optional. You can instead register with an email address and password and never involve Google at all. This section describes exactly what happens if you do choose it.

3.1 The permissions we ask for

When you sign in with Google, we request only these three standard OAuth scopes:

ScopeWhy we ask for it
openidTo receive a stable identifier for your Google account so we can recognise you on your next sign-in
profileTo read your basic profile — your name and profile picture — so your account has a name and avatar without you typing them
emailTo read your email address and whether Google has verified it. Your email address is your Zypheral account identity, and the verified flag is what lets us create your account without a separate confirmation email

We request no other scopes. We do not ask for, and cannot access, your Gmail messages, your Google Drive files, your Contacts, your Calendar, your Photos, your location history, or any other Google service or data.

3.2 The Google user data we receive and store

We receive and store only the following:

DataStored asUsed for
Your Google account identifierAn opaque provider ID on your Zypheral account recordRecognising you on subsequent sign-ins and linking the correct account
Your nameYour Zypheral account nameAddressing you in the dashboard and in our email to you
Your email addressYour Zypheral account emailAccount identity, sign-in, and service, billing and security notices
Whether Google has verified that addressA verification timestampConfirming you control the address, so we can skip a separate confirmation step
Your profile picture URLA link on your accountDisplaying your avatar in the dashboard

You can change your name and profile picture in the dashboard at any time, and doing so does not affect your Google account.

3.3 What we do not do with it

completed at the moment you sign in and no Google credential is retained afterwards.

section 7 who process data on our behalf in order to run the Services, or where we are legally compelled to.

compelled by law, or where it is strictly necessary to investigate a security incident or abuse — and then only to the extent necessary.

3.4 Limited Use

Zypheral's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3.5 Why we are allowed to process it

We process this data to create and operate the account you asked us to create, which is performance of a contract with you, and in reliance on the permission you grant on Google's own consent screen. You are never required to use Google sign-in.

3.6 How long we keep it

For as long as your Zypheral account exists. If you close your account, or ask us to delete it, the account record and the Google identifier stored on it are deleted. See section 9.

3.7 How to withdraw it

Google Account → Third-party apps & services. This stops any further exchange between Google and Zypheral. It does not, by itself, delete the Zypheral account you already created.

without Google.

address on the account. See section 12.

3.8 Other sign-in providers

Signing in with GitHub or Facebook works the same way and is subject to the same limits in section 3.3. For GitHub we additionally request read:user and user:email, which are needed because GitHub does not return a verified email address without them; that address is read at the moment of sign-in and the GitHub token is not stored.

3.4 Payment card data — what we do not hold

We do not receive, process or store full payment card numbers, CVV codes or full card details. Card details are transmitted by you directly to our payment processor and held by it under its own security programme. We hold only a processor-issued reference and the limited non-sensitive details listed above.

3.5 Customer Content

Website files, databases, and the content of mailboxes and email messages are stored to provide the service. This is the processor role described in clause 1.2. We do not use the content of your websites or mail to build profiles, to train models, or for advertising.


4. Email content: what is and is not inspected

4.1 Inbound and outbound mail passes through automated spam and malware filtering. This necessarily inspects message headers, content and attachments by automated means in order to classify and block unsolicited, fraudulent or malicious mail. No person reads your mail as part of this process.

4.2 We do not scan the content of your mail for advertising, profiling or marketing, and we do not sell it or disclose it to third parties for those purposes.

4.3 Our staff do not access the content of mailboxes except where you explicitly ask us to in order to resolve a support issue, or where we are compelled by law, or where it is strictly necessary to investigate an active security incident or abuse of the platform. Such access is limited to what is necessary.


Where data protection legislation of the kind described in clause 12 applies to you, we rely on the following bases.

PurposeBasis
Creating and operating your account; providing the services you boughtPerformance of a contract
Taking payment, invoicing, managing renewals and non-paymentPerformance of a contract
Sending service, security, billing and lifecycle noticesPerformance of a contract; legitimate interests in operating the service
Keeping the platform secure, preventing and investigating abuse and fraudLegitimate interests in protecting our service, our customers and third parties
Retaining accounting and tax recordsLegal obligation
Establishing, exercising or defending legal claimsLegitimate interests
Analytics and product-usage measurement on our website and dashboardConsent — see clause 5
Marketing email, where sentConsent, or the soft opt-in where lawfully available

Where we rely on legitimate interests, we have considered the impact on you and you may object as described in clause 11.


6. Cookies, analytics and session recording

6.1 Authentication does not use cookies. Your sign-in session is held in your browser's local storage rather than in a cookie set by us.

6.2 We currently use the following third-party measurement tools on our public website and in the customer dashboard:

ToolProviderWhat it does
Google AnalyticsGoogleAggregated usage measurement — pages visited, approximate location, device and referrer
Microsoft ClarityMicrosoftUsage analytics including session recording and heatmaps, which may capture your interactions with pages, such as mouse movement, scrolling and clicks

6.3 These tools set their own cookies or equivalent identifiers and transmit data to their providers, who process it under their own privacy terms. They are used for measurement and product improvement, not for advertising by us.


7. Who we share personal data with

7.1 We do not sell personal data.

7.2 We share personal data only as follows:

analytics providers named in clause 5, infrastructure and data centre providers, and our transactional email delivery path. Each is bound to process data only on our instructions and to protect it.

confidentiality.

a competent authority, or where necessary to establish or defend legal claims, or to protect the rights, property or safety of Zypheral, our customers or the public.

confidentiality and subject to this policy continuing to apply.

see the account information their role permits.


8. Where data is stored and international transfers

8.1 The infrastructure that stores account data and Customer Content for the services described here is located in the European Union.

8.2 Some of our service providers, including the analytics providers named in clause 5 and our payment processor, are established outside the European Economic Area or may process data outside it. Where personal data is transferred outside the EEA or the UK, we rely on a lawful transfer mechanism, which may include an adequacy decision, or the European Commission's Standard Contractual Clauses together with any additional measures required.


9. Retention

9.1 We keep personal data for as long as needed for the purpose it was collected for, and then delete it or reduce it to a form that no longer identifies you. You can ask us to delete your account and the personal data on it at any time — see section 12.

CategoryRetention
Account record — name, email, country, language, avatar, and the sign-in provider identifier described in section 3For as long as your account is open. Deleted when you close your account or ask us to delete it
Subscription and payment recordsFor the period we are required to keep accounting and tax records under applicable law
Sign-in sessions, including device, browser and last IP addressUntil you or we revoke the session, or it expires
Account administration audit recordsFor as long as your account is open, so that account owners can review who did what on their account
Operational and security logsOnly as long as they remain useful for diagnosing faults and investigating abuse. We have not yet set a fixed maximum for these and are working towards one
Support correspondenceFor as long as needed to handle your enquiry, and for a reasonable period afterwards for reference
Email Hosting content after suspension for non-paymentRetained for 30 days from the date of suspension, after which it may be permanently deleted
Hosting Services content after suspension for non-paymentRetained. We do not delete it automatically, and we will give you notice before any deletion

10. Security

10.1 We take measures intended to protect personal data against unauthorised access, alteration, disclosure and loss. These include:

that support it;

to the account owner;

10.2 No system is perfectly secure. We cannot guarantee that the services or your data will never be compromised, and you are responsible for the security of the applications and code you run and for the credentials you and your users hold.


11. Data breach

11.1 We maintain procedures for detecting and responding to security incidents affecting personal data.

11.2 Where a personal data breach occurs and we act as controller, we will notify the competent supervisory authority where legally required, and will notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms.

11.3 Where we act as processor, we will notify the affected customer without undue delay after becoming aware of a breach affecting their Customer Content, as set out in the DPA.


12. Your rights

12.1 Depending on where you live, you may have rights to: access the personal data we hold about you; correct inaccurate data; request erasure; restrict or object to processing, including processing based on legitimate interests; receive your data in a portable format; and withdraw consent at any time where processing is based on consent, without affecting prior processing.

12.2 To exercise any of these rights, contact support@zypheral.com. We may need to verify your identity. We will respond within the period required by applicable law, ordinarily within one month.

12.3 Requests about Customer Content. If your request concerns personal data held inside a customer's website or mailbox, we are acting as processor and the customer is the controller. We will refer you to that customer, and will assist them in responding.

12.4 You may lodge a complaint with your local data protection authority. We would appreciate the chance to address your concern first.

12.5 We do not use automated decision-making that produces legal or similarly significant effects concerning you.


13. Applicable data protection legislation

13.1 The infrastructure that stores account data and customer content for the Services is located in the European Union, and we apply the standards of the EU General Data Protection Regulation to the personal data described in this policy, wherever in the world you are.

13.2 Depending on where you live, other laws may also give you rights over your personal data. Section 12 describes the rights we honour; where your local law gives you more, we honour that too.

13.3 Zypheral has not yet determined whether it is required to appoint a representative in the European Union or the United Kingdom, or a data protection officer, because that follows from the registration of the operating entity referred to at the top of this policy. This policy will be updated when it is settled. In the meantime every request reaches us at support@zypheral.com and is handled as described in section 12.

13.4 Nothing in this policy is a claim of certification under any regulation or standard. It is a description of what we actually do.


14. Children

The services are not directed at children and are not intended for use by anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact support@zypheral.com and we will delete it.


15. Changes to this policy

We may update this policy. We will change the "Last updated" date and, where changes materially affect how we use your personal data, notify you by email or by prominent notice in the dashboard before they take effect.


16. Contact

Zypheral

on your account

We aim to acknowledge privacy requests within a few working days and to answer them within one month, which is the period the General Data Protection Regulation allows.

Zypheral's registered company details and postal address will be published here once the operating entity is registered.