Zypheral — Privacy Policy
Effective date: 10 September 2026 Last updated: 10 September 2026 Controller: Zypheral ("Zypheral", "we", "us"), operator of www.zypheral.com and the Zypheral customer dashboard at dash.zypheral.com. Contact: support@zypheral.com
Zypheral's company registration details will be added to this policy once the operating entity is formally registered. Until then, support@zypheral.com is the contact point for every matter covered by this policy, including data protection requests.
1. Scope of this policy
1.1 This policy explains how we handle personal data when you visit our website (www.zypheral.com), create an account, sign in to and use the Zypheral customer dashboard (dash.zypheral.com), purchase or use our hosting and email services, or contact us. Together these are referred to as the Services, and the dashboard is referred to as the application.
1.2 Two different roles. Our services involve personal data in two distinct capacities, and different rules apply to each:
| We act as | Covers | Governed by | |
|---|---|---|---|
| Account data | Controller | Your account, billing, support and security records | This policy |
| Customer Content | Processor | Website files, databases, mailboxes and email messages you store on the services | Our Data Processing Agreement, on your instructions |
1.3 Where we act as processor, we handle Customer Content on your documented instructions in order to provide the service. If Customer Content includes personal data about your own customers, employees or contacts, you are the controller of that data and are responsible for having a lawful basis for it, for informing those individuals, and for responding to their requests. This policy does not describe your obligations to them.
2. Personal data we collect
2.1 Data you give us
| Data | Why we hold it |
|---|---|
| Name | Identifying your account and addressing communications |
| Email address | Account identity, sign-in, service and billing notices, support |
| Password | Authentication. Stored only as a salted cryptographic hash, never in readable form |
| Country | Tax determination and billing details for payment processing |
| Interface language | Presenting the dashboard and our notifications in your chosen language |
| Profile image reference | Displaying your avatar in the dashboard, where you set one |
| Support correspondence | Answering and evidencing your enquiry |
2.2 Data created when you use the services
| Data | Why we hold it |
|---|---|
| Sign-in sessions, including approximate device, operating system and browser, the IP address last used, and the time of last use | Letting you review and revoke your own active sessions, and detecting unauthorised access |
| Records of significant account-administration actions, including which user performed them and the originating IP address | Security, dispute resolution and audit, particularly where several people share access to one account |
| Subscription and entitlement records — plan, status, renewal dates, and non-payment status | Operating the subscription and enforcing plan limits |
| Service records — the domains, websites and mailboxes on your account, storage used, and provisioning status | Delivering and supporting the service |
| Notifications we have generated for you | Showing your notification history and preventing duplicates |
| Web-push subscription identifiers, if you enable browser notifications | Delivering push notifications you asked for |
| Operational and security logs | Diagnosing faults, investigating abuse, and protecting the platform |
2.3 Data from third parties
- Sign-in providers. If you choose to sign in with Google, GitHub or Facebook, we receive an
identifier and basic profile information. Signing in with Google is described in full in section 3. We never receive your password for that provider.
- Payment processor. We receive confirmation of payment outcomes and limited non-sensitive
card details (brand, last four digits, expiry) so you can identify your payment method.
3. Signing in with Google
Creating a Zypheral account with Google, or signing in to the Zypheral dashboard with Google, is optional. You can instead register with an email address and password and never involve Google at all. This section describes exactly what happens if you do choose it.
3.1 The permissions we ask for
When you sign in with Google, we request only these three standard OAuth scopes:
| Scope | Why we ask for it |
|---|---|
openid | To receive a stable identifier for your Google account so we can recognise you on your next sign-in |
profile | To read your basic profile — your name and profile picture — so your account has a name and avatar without you typing them |
email | To read your email address and whether Google has verified it. Your email address is your Zypheral account identity, and the verified flag is what lets us create your account without a separate confirmation email |
We request no other scopes. We do not ask for, and cannot access, your Gmail messages, your Google Drive files, your Contacts, your Calendar, your Photos, your location history, or any other Google service or data.
3.2 The Google user data we receive and store
We receive and store only the following:
| Data | Stored as | Used for |
|---|---|---|
| Your Google account identifier | An opaque provider ID on your Zypheral account record | Recognising you on subsequent sign-ins and linking the correct account |
| Your name | Your Zypheral account name | Addressing you in the dashboard and in our email to you |
| Your email address | Your Zypheral account email | Account identity, sign-in, and service, billing and security notices |
| Whether Google has verified that address | A verification timestamp | Confirming you control the address, so we can skip a separate confirmation step |
| Your profile picture URL | A link on your account | Displaying your avatar in the dashboard |
You can change your name and profile picture in the dashboard at any time, and doing so does not affect your Google account.
3.3 What we do not do with it
- We do not store your Google access token or refresh token. The sign-in exchange is
completed at the moment you sign in and no Google credential is retained afterwards.
- We do not use Google user data to call any other Google API, at sign-in or later.
- We do not use it for advertising, ad targeting, or building advertising profiles.
- We do not sell it, rent it, or trade it.
- We do not transfer it to third parties, except to the service providers described in
section 7 who process data on our behalf in order to run the Services, or where we are legally compelled to.
- We do not allow humans to read it, except where you ask us to in support, where we are
compelled by law, or where it is strictly necessary to investigate a security incident or abuse — and then only to the extent necessary.
- We do not use it to train machine learning or artificial intelligence models.
3.4 Limited Use
Zypheral's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3.5 Why we are allowed to process it
We process this data to create and operate the account you asked us to create, which is performance of a contract with you, and in reliance on the permission you grant on Google's own consent screen. You are never required to use Google sign-in.
3.6 How long we keep it
For as long as your Zypheral account exists. If you close your account, or ask us to delete it, the account record and the Google identifier stored on it are deleted. See section 9.
3.7 How to withdraw it
- Disconnect Zypheral from your Google account at any time from
Google Account → Third-party apps & services. This stops any further exchange between Google and Zypheral. It does not, by itself, delete the Zypheral account you already created.
- Set a password on your Zypheral account from Settings, so you can continue to sign in
without Google.
- Delete your Zypheral account and its data by contacting
support@zypheral.comfrom the
address on the account. See section 12.
3.8 Other sign-in providers
Signing in with GitHub or Facebook works the same way and is subject to the same limits in section 3.3. For GitHub we additionally request read:user and user:email, which are needed because GitHub does not return a verified email address without them; that address is read at the moment of sign-in and the GitHub token is not stored.
3.4 Payment card data — what we do not hold
We do not receive, process or store full payment card numbers, CVV codes or full card details. Card details are transmitted by you directly to our payment processor and held by it under its own security programme. We hold only a processor-issued reference and the limited non-sensitive details listed above.
3.5 Customer Content
Website files, databases, and the content of mailboxes and email messages are stored to provide the service. This is the processor role described in clause 1.2. We do not use the content of your websites or mail to build profiles, to train models, or for advertising.
4. Email content: what is and is not inspected
4.1 Inbound and outbound mail passes through automated spam and malware filtering. This necessarily inspects message headers, content and attachments by automated means in order to classify and block unsolicited, fraudulent or malicious mail. No person reads your mail as part of this process.
4.2 We do not scan the content of your mail for advertising, profiling or marketing, and we do not sell it or disclose it to third parties for those purposes.
4.3 Our staff do not access the content of mailboxes except where you explicitly ask us to in order to resolve a support issue, or where we are compelled by law, or where it is strictly necessary to investigate an active security incident or abuse of the platform. Such access is limited to what is necessary.
5. Why we process personal data, and our legal bases
Where data protection legislation of the kind described in clause 12 applies to you, we rely on the following bases.
| Purpose | Basis |
|---|---|
| Creating and operating your account; providing the services you bought | Performance of a contract |
| Taking payment, invoicing, managing renewals and non-payment | Performance of a contract |
| Sending service, security, billing and lifecycle notices | Performance of a contract; legitimate interests in operating the service |
| Keeping the platform secure, preventing and investigating abuse and fraud | Legitimate interests in protecting our service, our customers and third parties |
| Retaining accounting and tax records | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests |
| Analytics and product-usage measurement on our website and dashboard | Consent — see clause 5 |
| Marketing email, where sent | Consent, or the soft opt-in where lawfully available |
Where we rely on legitimate interests, we have considered the impact on you and you may object as described in clause 11.
6. Cookies, analytics and session recording
6.1 Authentication does not use cookies. Your sign-in session is held in your browser's local storage rather than in a cookie set by us.
6.2 We currently use the following third-party measurement tools on our public website and in the customer dashboard:
| Tool | Provider | What it does |
|---|---|---|
| Google Analytics | Aggregated usage measurement — pages visited, approximate location, device and referrer | |
| Microsoft Clarity | Microsoft | Usage analytics including session recording and heatmaps, which may capture your interactions with pages, such as mouse movement, scrolling and clicks |
6.3 These tools set their own cookies or equivalent identifiers and transmit data to their providers, who process it under their own privacy terms. They are used for measurement and product improvement, not for advertising by us.
7. Who we share personal data with
7.1 We do not sell personal data.
7.2 We share personal data only as follows:
- Service providers acting on our behalf, which currently include a payment processor, the
analytics providers named in clause 5, infrastructure and data centre providers, and our transactional email delivery path. Each is bound to process data only on our instructions and to protect it.
- Professional advisers — lawyers, accountants and auditors — where necessary and under
confidentiality.
- Authorities and third parties where required by law, court order or a lawful request from
a competent authority, or where necessary to establish or defend legal claims, or to protect the rights, property or safety of Zypheral, our customers or the public.
- A successor in the event of a merger, acquisition, restructuring or sale of assets, under
confidentiality and subject to this policy continuing to apply.
- Other users of your account. If you grant delegated access, the people you authorise can
see the account information their role permits.
8. Where data is stored and international transfers
8.1 The infrastructure that stores account data and Customer Content for the services described here is located in the European Union.
8.2 Some of our service providers, including the analytics providers named in clause 5 and our payment processor, are established outside the European Economic Area or may process data outside it. Where personal data is transferred outside the EEA or the UK, we rely on a lawful transfer mechanism, which may include an adequacy decision, or the European Commission's Standard Contractual Clauses together with any additional measures required.
9. Retention
9.1 We keep personal data for as long as needed for the purpose it was collected for, and then delete it or reduce it to a form that no longer identifies you. You can ask us to delete your account and the personal data on it at any time — see section 12.
| Category | Retention |
|---|---|
| Account record — name, email, country, language, avatar, and the sign-in provider identifier described in section 3 | For as long as your account is open. Deleted when you close your account or ask us to delete it |
| Subscription and payment records | For the period we are required to keep accounting and tax records under applicable law |
| Sign-in sessions, including device, browser and last IP address | Until you or we revoke the session, or it expires |
| Account administration audit records | For as long as your account is open, so that account owners can review who did what on their account |
| Operational and security logs | Only as long as they remain useful for diagnosing faults and investigating abuse. We have not yet set a fixed maximum for these and are working towards one |
| Support correspondence | For as long as needed to handle your enquiry, and for a reasonable period afterwards for reference |
| Email Hosting content after suspension for non-payment | Retained for 30 days from the date of suspension, after which it may be permanently deleted |
| Hosting Services content after suspension for non-payment | Retained. We do not delete it automatically, and we will give you notice before any deletion |
10. Security
10.1 We take measures intended to protect personal data against unauthorised access, alteration, disclosure and loss. These include:
- transport encryption (HTTPS/TLS) for the website, dashboard and API, and for mail connections
that support it;
- storage of account passwords only as salted cryptographic hashes, never in readable form;
- separation of customer website environments from one another;
- role-based access control for delegated account access, with sensitive operations restricted
to the account owner;
- an audit record of significant account-administration actions;
- restricted administrative access to production systems, limited to personnel who need it;
- automated filtering of mail for malware and unsolicited content;
- monitoring intended to detect faults and abuse.
10.2 No system is perfectly secure. We cannot guarantee that the services or your data will never be compromised, and you are responsible for the security of the applications and code you run and for the credentials you and your users hold.
11. Data breach
11.1 We maintain procedures for detecting and responding to security incidents affecting personal data.
11.2 Where a personal data breach occurs and we act as controller, we will notify the competent supervisory authority where legally required, and will notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
11.3 Where we act as processor, we will notify the affected customer without undue delay after becoming aware of a breach affecting their Customer Content, as set out in the DPA.
12. Your rights
12.1 Depending on where you live, you may have rights to: access the personal data we hold about you; correct inaccurate data; request erasure; restrict or object to processing, including processing based on legitimate interests; receive your data in a portable format; and withdraw consent at any time where processing is based on consent, without affecting prior processing.
12.2 To exercise any of these rights, contact support@zypheral.com. We may need to verify your identity. We will respond within the period required by applicable law, ordinarily within one month.
12.3 Requests about Customer Content. If your request concerns personal data held inside a customer's website or mailbox, we are acting as processor and the customer is the controller. We will refer you to that customer, and will assist them in responding.
12.4 You may lodge a complaint with your local data protection authority. We would appreciate the chance to address your concern first.
12.5 We do not use automated decision-making that produces legal or similarly significant effects concerning you.
13. Applicable data protection legislation
13.1 The infrastructure that stores account data and customer content for the Services is located in the European Union, and we apply the standards of the EU General Data Protection Regulation to the personal data described in this policy, wherever in the world you are.
13.2 Depending on where you live, other laws may also give you rights over your personal data. Section 12 describes the rights we honour; where your local law gives you more, we honour that too.
13.3 Zypheral has not yet determined whether it is required to appoint a representative in the European Union or the United Kingdom, or a data protection officer, because that follows from the registration of the operating entity referred to at the top of this policy. This policy will be updated when it is settled. In the meantime every request reaches us at support@zypheral.com and is handled as described in section 12.
13.4 Nothing in this policy is a claim of certification under any regulation or standard. It is a description of what we actually do.
14. Children
The services are not directed at children and are not intended for use by anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact support@zypheral.com and we will delete it.
15. Changes to this policy
We may update this policy. We will change the "Last updated" date and, where changes materially affect how we use your personal data, notify you by email or by prominent notice in the dashboard before they take effect.
16. Contact
Zypheral
- Privacy, data protection and data-deletion requests:
support@zypheral.com - General and support enquiries:
support@zypheral.com - Questions about Google sign-in specifically:
support@zypheral.com, quoting the email address
on your account
We aim to acknowledge privacy requests within a few working days and to answer them within one month, which is the period the General Data Protection Regulation allows.
Zypheral's registered company details and postal address will be published here once the operating entity is registered.