Privacy Policy

Zira Group Inc.

Last updated: August 25, 2026 | Applies to zira.us, ziravision.com, lightapp.com and the Zira Services

Important distinction. Zira acts as a controller for personal data used to run its business and website. For most data captured or submitted through customer-deployed cameras, applications, dashboards, and APIs, the customer determines the purposes and means of processing and Zira acts as a processor or service provider on the customer's behalf.

This Privacy Policy explains how Zira Group Inc. and its affiliates, including Lightapp Technologies Ltd. (collectively, "Zira," "we," "us," or "our"), collect, use, disclose, retain, and protect personal data. It also explains the choices and rights that may be available to you.

"Personal data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual, and includes "personal information" and similar terms under applicable law.

This Policy applies to our websites, customer and partner portals, applications, dashboards, APIs, AI-enabled cameras and edge devices, professional and support services, communications, events, and related products and services (collectively, the "Services"). Employment and candidate data may be covered by a separate notice when one is provided.

1Purpose and scope

Data protection laws often distinguish between a controller, which decides why and how personal data is processed, and a processor, which processes personal data on a controller's documented instructions. Under California law, analogous terms include business and service provider or contractor.

This Policy covers both roles. Section 2 describes Zira's practices when Zira is a controller. Section 3 describes Zira's practices when Zira processes Customer Data for a customer. If you interact with Zira through your employer or another Zira customer, that organization is usually the appropriate contact for questions or requests about Customer Data.

"Customer Data" means data that a customer or its authorized users submit to the Services, or that the Services collect or generate for that customer, as further defined in the customer's agreement with Zira.

2Zira as a controller

2.1 Personal data we collect and sources

Depending on how you interact with Zira, we may collect personal data from the following sources:

2.2 Categories of personal data

The table below describes categories of personal data Zira may collect as a controller. The examples are illustrative; not every category applies to every person. Customer Data handled in Zira's processor role is described in Section 3.

CategoryExamplesSourcesTypical recipients
Identifiers and contact dataName, business email, phone number, postal address, account ID, username, IP address, and similar identifiers.You; your organization; devices; partners and public sourcesCloud hosting, communications, CRM, support, security, professional advisers, and transaction providers
Account and authentication dataLogin credentials, permissions, authentication events, and account settings.You; your organization; devicesHosting, identity, security, and support providers
Commercial and transaction dataProducts or services considered or purchased, orders, subscriptions, invoices, payment status, and customer relationship history. Full payment card data is generally handled by payment providers.You; your organization; payment and sales partnersPayment, accounting, fulfillment, professional advisers, and transaction providers
Professional dataEmployer, role, job title, department, authority, business contact details, and professional interests.You; your organization; partners and public sourcesCRM, communications, events, support, and professional advisers
Internet, network, and device activityBrowser and device type, operating system, referring page, pages viewed, links clicked, timestamps, cookie IDs, diagnostic logs, and security events.Devices; cookies and similar technologiesHosting, analytics, security, communications, and advertising providers, subject to your choices
Communications and contentEmails, support requests, feedback, survey responses, meeting notes, and, where notice or consent is provided as required, call or meeting recordings and transcripts.You; your organization; communications toolsCommunications, transcription, support, CRM, and professional advisers
Audio, visual, and facility dataPhotos or video you submit, event photographs, visitor records, and facility security footage.You; cameras and facility systems; event organizersSecurity, event, hosting, and professional advisers
Approximate locationApproximate location derived from IP address and the location of a business site or deployed device.Devices; your organizationHosting, security, analytics, mapping, and connectivity providers
InferencesBusiness interests, likely product needs, account health, and engagement indicators derived from the information above.Derived from other controller dataCRM, analytics, sales, and support providers

2.3 Sensitive personal data

Account login credentials may be considered sensitive personal data under some laws. Depending on customer configuration, Customer Data may also include information that is considered sensitive, such as precise geolocation or visual data that incidentally reveals characteristics about individuals. Zira uses and discloses sensitive personal data only as reasonably necessary to provide the requested Services, authenticate users, maintain security and integrity, prevent fraud, comply with law, or for other purposes permitted by applicable law. Zira does not use sensitive personal data in its controller role to infer characteristics about individuals.

2.4 How and why we use personal data

Zira may use controller personal data for the following purposes and, where applicable, legal bases:

2.5 AI and automated processing

Zira uses artificial intelligence, machine learning, and computer vision to provide and improve the Services. In Zira's controller role, these technologies may help detect fraud or security issues, classify support or sales interactions, summarize communications, analyze product performance, and assist personnel. Zira does not use Product visual data in its controller role to make decisions that produce legal or similarly significant effects about individuals without appropriate notice, safeguards, and rights required by law.

The standard Zira Services are designed to analyze industrial operations, objects, processes, defects, measurements, counts, downtime, and workflow events. They are not designed to identify individuals through facial recognition or to create biometric identifiers. If Zira and a customer expressly agree to a feature that uses biometric data or makes significant decisions about individuals, the feature will be subject to additional terms, notices, and controls as required by law.

2.6 Cookies and similar technologies

Zira and its partners may use cookies, pixels, local storage, SDKs, and similar technologies to operate the website and Services, remember preferences, authenticate users, protect security, understand performance and usage, measure communications, and, where enabled, support advertising. These technologies may collect device and browser information, IP address, cookie or advertising identifiers, pages viewed, links clicked, referring URLs, and timestamps.

You can manage cookies through your browser and, where presented, Zira's cookie controls. Blocking some technologies may affect functionality. Where required by law, Zira honors recognized opt-out preference signals, such as Global Privacy Control, as a request to opt out of sale or sharing for the browser or device that sends the signal.

2.7 Marketing choices

You may unsubscribe from marketing emails using the link in the message or by contacting us. We may continue to send non-promotional messages about your account, orders, security, support, or other service matters. You may ask us not to use your information for direct marketing where applicable law provides that right.

2.8 Disclosure of personal data

Zira may disclose personal data to the following categories of recipients for the purposes described in this Policy:

2.9 Sale and sharing

Zira does not sell Customer Data. Zira also does not sell personal data for money. If Zira enables advertising or measurement technologies that disclose website identifiers or Internet activity to third parties for cross-context behavioral advertising, that disclosure may be considered "sharing" or a "sale" under certain U.S. state privacy laws even when no money changes hands. Where applicable, you may opt out using available cookie controls, a recognized browser-based opt-out signal, or the contact methods in Section 8. Zira does not knowingly sell or share the personal data of individuals under 16 years of age.

2.10 Retention

Zira retains controller personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain the business relationship, comply with legal and accounting obligations, resolve disputes, enforce agreements, preserve security, and support legitimate business operations. Retention periods vary by category and context. In determining the period, Zira considers the amount, nature, and sensitivity of the data; the purposes for processing; the risk of harm from unauthorized use or disclosure; contractual commitments; whether the purpose can be achieved by other means; and legal requirements.

For example, account and transaction records may be retained for the term of the relationship and an appropriate period afterward; security logs are retained for a period appropriate to investigation and security needs; marketing and prospect data is retained until it is no longer useful for the relevant business relationship or you object, subject to suppression records; and call recordings or transcripts are retained according to the purpose stated at collection and Zira's retention schedule. Data may be retained longer when required for legal holds, disputes, audits, or compliance.

2.11 Security

Zira maintains technical, administrative, and organizational measures designed to protect personal data against unauthorized or unlawful access, use, alteration, loss, destruction, or disclosure. Measures may include access controls, authentication, encryption in transit and where appropriate at rest, logging and monitoring, network and endpoint protections, secure development practices, vendor oversight, backups, incident response procedures, and personnel confidentiality obligations.

No transmission, storage system, or security program is completely secure. You are responsible for safeguarding account credentials and promptly notifying Zira of suspected unauthorized access.

2.12 International transfers

Zira operates from the United States and Israel and uses service providers that may process personal data in other countries. Those countries may have data protection laws that differ from the laws where you live. Zira takes steps designed to provide appropriate protection for international transfers. Where required, these steps may include adequacy decisions, the European Commission's Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum or other approved mechanism, contractual safeguards, and supplementary technical or organizational measures. You may contact us for more information about applicable transfer safeguards.

3Zira as a processor or service provider

Zira customers use the Services to monitor, measure, inspect, analyze, and improve industrial operations. For Customer Data, the customer generally determines why and how personal data is processed, and Zira processes that data on the customer's documented instructions, under the customer agreement and applicable data protection addendum.

3.1 Customer Data the Services may process

Depending on the products, configuration, deployment, and customer instructions, Customer Data may include:

Edge processing and image retention. Zira is designed to perform computer-vision inference on edge devices. Depending on configuration and the customer agreement, continuous raw video may be processed locally and not retained by Zira, while selected recordings, event images, snapshots, metadata, and AI outputs may be transmitted or stored to provide validation, dashboards, alerts, traceability, troubleshooting, and customer-requested features.

3.2 How Zira processes Customer Data

Subject to the customer agreement and documented instructions, Zira may process Customer Data to:

Zira does not use Customer Data to advertise to individuals, does not sell Customer Data, and does not use customer images or video to train unrelated third-party or general-purpose generative AI models without the customer's authorization.

3.3 Customer responsibilities

Customers are responsible for the lawfulness of the Customer Data and their instructions to Zira. This includes determining the legal basis for processing; providing required privacy, workplace, labor, surveillance, camera, and automated-decision notices; obtaining required consents; configuring the Services appropriately; controlling authorized-user access; responding to individual rights requests; and complying with collective bargaining, employment, biometric, and sector-specific requirements that apply to their use of the Services.

The standard Services analyze industrial operations rather than identity. Customers must not configure or use the Services for facial recognition, biometric identification, unlawful surveillance, or decisions about employment, compensation, access to essential goods or services, or other legally significant matters unless expressly authorized in writing by Zira and implemented with all notices, assessments, human review, rights, and safeguards required by law.

3.4 Requests concerning Customer Data

If your personal data was collected through a Zira customer, please direct your request to that customer. Zira will assist the customer with verified requests as required by the customer agreement and applicable law. If Zira receives a request and can identify the relevant customer, Zira may refer the request to the customer or notify the customer, unless prohibited by law.

3.5 Retention, disclosure, and transfers of Customer Data

Zira retains Customer Data according to the customer's configuration, instructions, agreement, support needs, and applicable law. At the end of the Services, Zira will make Customer Data available for return or deletion and will delete it according to the agreement and backup cycle, unless retention is required by law or permitted for security, dispute, or deidentified-data purposes.

Zira may disclose Customer Data to affiliates and approved subprocessors that help provide the Services, to parties selected or authorized by the customer, in a corporate transaction, or when legally required. Zira requires subprocessors to protect Customer Data through contractual obligations appropriate to the services they provide. International transfers of Customer Data are handled under the customer agreement and applicable transfer mechanism.

4Your privacy rights

4.1 Rights that may apply

Depending on your location and Zira's role, you may have the right to:

These rights are not absolute. Zira may deny or limit a request when an exception applies, such as when data is needed to provide a requested service, protect security, comply with law, maintain privileged material, or establish or defend legal claims. Zira will not discriminate against you for exercising a privacy right.

4.2 How to submit a request

To exercise a right concerning data for which Zira is the controller, email privacy@zira.us with the subject line "Privacy Request," call +1 650-701-7026, or write to the address in Section 8. Describe the right you want to exercise and the relationship or interaction that allows us to locate the relevant data.

Zira may need to verify your identity and authority before completing a request. Verification may require matching information you provide with information Zira already maintains or requesting additional information appropriate to the sensitivity of the request. An authorized agent may submit a request where permitted by law; Zira may require proof of authorization and may also verify your identity directly. If Zira denies a request and applicable law provides an appeal right, you may appeal by replying to the decision or using the same contact methods with the subject line "Privacy Appeal."

4.3 California and other U.S. state disclosures

In the preceding 12 months, Zira may have collected the controller categories described in Section 2.2 for the sources, purposes, and recipient categories described in Sections 2.1, 2.4, and 2.8. Zira retains each category using the criteria in Section 2.10. Zira may also have processed the Customer Data categories in Section 3 on behalf of customers, which is governed by the customer relationship and not used outside the permitted business relationship except as allowed by law.

California residents may have the rights to know, access, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal service and pricing. Zira does not sell personal data for money. As explained in Section 2.9, limited website data may be considered shared if advertising technologies are enabled. Zira uses sensitive personal information only for permitted purposes and not to infer characteristics in its controller role. Requests are handled within the periods required by law, subject to verification and exceptions.

Some U.S. states also provide rights to opt out of targeted advertising, certain sales, or profiling in furtherance of decisions producing legal or similarly significant effects, as well as a right to appeal. Zira will honor such rights when applicable to Zira and the processing at issue.

4.4 EEA, United Kingdom, and Switzerland

If the GDPR, UK GDPR, or Swiss data protection law applies and Zira is the controller, Zira relies on one or more legal bases described in Section 2.4, including performance of a contract, legitimate interests, compliance with legal obligations, protection of vital interests, or consent. Where Zira relies on legitimate interests, it considers Zira's interests, the effects on individuals, and appropriate safeguards. You may object to processing based on legitimate interests and have an absolute right to object to direct marketing.

You may lodge a complaint with the supervisory authority in your country. If you need help identifying the appropriate authority or applicable Zira contact or representative, contact us using Section 8.

5Children

The Services are intended for businesses and are not directed to children under 16. Zira does not knowingly collect personal data directly from children under 16 through its website or account-registration process. If you believe a child has provided personal data to Zira, contact us. This section does not prevent Customer Data from incidentally depicting minors near a customer's facility; the customer remains responsible for the lawful deployment of cameras and related notices.

6Third-party sites and integrations

The Services may link to third-party websites, services, applications, or integrations. Their privacy practices are governed by their own notices, not this Policy. When a customer enables an integration, Zira may exchange Customer Data with the provider at the customer's direction. Review the third party's privacy terms before using the integration.

7Changes to this Policy

Zira may update this Policy to reflect changes in the Services, practices, technologies, legal requirements, or other factors. Zira will update the "Last updated" date and provide additional notice of material changes when required by law. The current version will be posted on Zira's website.

8Contact us

For questions, privacy requests, or complaints, contact:

Zira Group Inc., Attention: Privacy, 400 Concar Drive, San Mateo, California 94420, United States. Email: privacy@zira.us | Telephone: +1 650-701-7026 | Website: zira.us