1. Scope
This Policy applies to information we process when you visit our websites, create an account, connect infrastructure, and use the Service. It does not apply to third-party services you connect or use, such as your cloud providers, which are governed by their own privacy policies.
Where we process data on behalf of a business customer as part of providing the Service, for example, data drawn from that customer's Connected Infrastructure, we act as a processor and the customer is the controller. See Section 12.
2. Information We Collect
2.1 Account and Contact Information
When you join the waitlist, request access, or create an account, we collect information such as your work email, name, organization, role, and any information you provide when communicating with us.
2.2 Infrastructure and Operational Data
To provide the Service, agents access and process information from the infrastructure you connect ("Connected Infrastructure"). This may include:
- infrastructure metadata, such as cluster, node, workload, namespace, service, and resource names and states;
- configuration data, such as deployment specifications, environment definitions, and IAM roles and policies relevant to the Service;
- logs, events, and metrics that agents read in the course of investigating issues or operating systems;
- the content and results of Agent Actions, plans, and approvals; and
- operational history and "agent memory" derived from your environment to help agents understand your services, workflows, and prior incidents.
2.3 Credentials and Access
To connect infrastructure, you provide credentials or grant access, for example, through IAM roles or OAuth. We process this access to enable agents to operate within the scope you configure. Where supported, we encourage scoped, temporary, or least-privilege access, and we handle credentials and access tokens using technical and organizational safeguards designed to protect them. We do not use your credentials for any purpose other than operating the Service for you.
2.4 Usage, Device, and Cookie Data
We collect information about how you use the Service, such as feature usage, session activity, log data, device and browser information, and IP address. Our websites may use cookies and similar technologies for functionality, security, and analytics. Where required, we will provide cookie controls and seek consent for non-essential cookies.
2.5 Payment Information
If you purchase Paid Services, payment is processed by our third-party payment processor, currently Stripe. We do not store full payment card numbers; Stripe processes that information under its own terms and privacy policy.
3. How We Use Information
We use the information we collect to:
- provide, operate, maintain, secure, and support the Service, including enabling agents to investigate and operate your Connected Infrastructure within the permissions you configure;
- generate operational memory and context to make agents more useful within your environment;
- maintain audit logs and records of Agent Actions;
- communicate with you about the Service, including service, security, and administrative messages;
- detect, prevent, and respond to security incidents, fraud, abuse, and violations of our Terms;
- comply with legal obligations and enforce our agreements; and
- analyze and improve the Service, using aggregated and de-identified data that does not identify you, your organization, or your Connected Infrastructure.
Processor Use
Where we act as a processor for a business customer, we use Customer Data only to provide the Service in accordance with the customer's instructions, our Terms, and any applicable Data Processing Addendum.
4. Legal Bases (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we process personal data on the following legal bases: performance of a contract, to provide the Service; our legitimate interests, to operate, secure, and improve the Service, where not overridden by your rights; your consent, where required, such as for certain cookies or communications; and compliance with legal obligations.
5. How We Share Information
We do not sell your personal information. We share information only as follows:
- Service providers and subprocessors: with vendors who help us provide the Service, such as cloud and hosting providers, AI/model providers, payment processing, analytics, and support tooling, under contracts that require them to protect the information and use it only to provide services to us. See Section 6.
- Your cloud providers and connected services: as necessary to perform the operations you direct on your Connected Infrastructure.
- Within your organization: with other users in your workspace, consistent with the permissions and roles you configure.
- Legal and safety: when required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Zeabur, our users, or others.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
6. Subprocessors
We use third-party subprocessors to provide the Service, including providers of cloud infrastructure, AI/large language model processing, payment, analytics, and support. We maintain a current list of subprocessors and make it available to customers. Information about our subprocessors and security program is available through our Trust Center at trust.zeabur.com. We require subprocessors to protect information consistent with this Policy.
7. AI and Model Processing
Agent functionality is powered by AI and large language models, some operated by third-party providers acting as our subprocessors. Customer Data may be processed by these models solely to provide the Service to you. We require our model providers to process Customer Data only to provide services to us and not to use Customer Data submitted through the Service to train third-party foundation models, except where you expressly enable or agree to such use or where it is otherwise expressly disclosed in an applicable agreement.
8. Data Retention
We retain personal data and Customer Data for as long as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type and customer configuration. For example, account data is generally retained while your account is active; logs, audit records, and agent memory are retained according to the applicable product settings, customer agreement, Data Processing Addendum, or retention schedule made available through our Trust Center. When data is no longer needed, we delete or de-identify it. Business customers may configure or request deletion of Customer Data as described in their agreement or Data Processing Addendum. Backups are deleted in the ordinary course according to our backup retention schedule.
9. Data Security
We maintain technical and organizational measures designed to protect information, including encryption in transit, access controls, least-privilege practices, and audit logging. Zeabur maintains a security program; details are available through our Trust Center at trust.zeabur.com. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for configuring appropriate permissions, approvals, and safeguards for your Connected Infrastructure, as described in our Terms.
10. International Data Transfers
Zeabur is incorporated in the United States, and we and our subprocessors may process information in the United States and other countries. Where we transfer personal data from the EEA, the UK, or other regions with cross-border transfer restrictions, we rely on appropriate safeguards, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms where applicable.
11. Your Rights and Choices
Depending on your location, you may have rights regarding your personal data, including the right to access, correct, delete, or port your data, to object to or restrict certain processing, and to withdraw consent. Where applicable law provides, you may also have the right to opt out of certain uses of personal information. To exercise these rights, contact us at contact@zeabur.com. We will respond as required by applicable law. If you are a user within a business customer's workspace, please direct certain requests to that customer, who controls the relevant Customer Data; we will assist them as required.
You may also manage certain communications and, where available, cookie preferences directly. Some service-related communications are necessary and cannot be opted out of while you maintain an account.
12. Business Customers: Controller and Processor Roles
For Customer Data that we process on behalf of a business customer in order to provide the Service, the business customer is the controller and Nuphos acts as a processor, processing Customer Data in accordance with the customer's instructions, our Terms, and any applicable Data Processing Addendum. For account registration data, website data, and our own operation of the Service, Nuphos acts as a controller. Where a Data Processing Addendum applies and conflicts with this Policy regarding Customer Data, the Data Processing Addendum controls.
13. Children's Privacy
The Service is intended for use by organizations and professionals and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
14. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will post a notice on our website and update the "Last updated" date, and where appropriate we will notify you by email. Your continued use of the Service after the changes take effect means you accept the updated Policy.
Contact Us
If you have questions about this Policy or our data practices, contact us at contact@zeabur.com.
2026 © Zeabur Pte. Ltd.