Privacy Policy
ZEFR, Inc. Privacy Policy
Last Modified: October 2nd, 2026
ZEFR, Inc. (“ZEFR,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy (“Policy”) explains how we process Personal Data (defined below) when you visit www.zefr.com (the “Site”) or otherwise use our services (the “Services”), and describes your privacy choices and rights.
This Policy is designed to comply with the EU GDPR, UK GDPR, the California Consumer Privacy Act as amended by the CPRA, the Children’s Online Privacy Protection Act (“COPPA”), and other applicable U.S. state privacy laws, including Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Florida, Maryland, Minnesota, Indiana, Kentucky, and Rhode Island, each as may be amended (collectively, “State Privacy Laws”). By using the Site or Services, you acknowledge that you have read and understood this Policy. We will obtain your consent before processing your Personal Data. This Policy applies to visitors to the Site, current and prospective customers, and other business contacts who interact with us online or otherwise. If you have any questions about this Policy or how we handle your Personal Data, please contact us at privacy@zefr.com.
1. Key Definitions
“Personal Data” means information that identifies, relates to, or could reasonably be linked with an identifiable individual. “De-identified Data” cannot reasonably be linked to an individual; we may use it for any lawful purpose. “Processing” means any operation performed on Personal Data, including collection, use, storage, disclosure, or deletion. “Sale” and “Share” have the meanings given under the CCPA/CPRA. “Sensitive Personal Information” means categories of Personal Data subject to heightened protection under applicable law (e.g., precise geolocation, government ID numbers, health information, and biometric data used for identification). “Service Provider” means an entity that processes Personal Data on our behalf under a written contract and may not use it for its own independent purposes. “Third Party” means any person or entity other than you, ZEFR, or one of our Service Providers.
2. Lawful Basis for Processing (EU/UK GDPR)
Where the EU GDPR or UK GDPR applies, we process Personal Data only where a lawful basis exists: your consent; performance of a contract with you; compliance with a legal obligation; or our legitimate interests, where not overridden by your rights. You may withdraw consent at any time and this action does not affect the lawfulness of processing conducted prior to withdrawal. Where we rely on your consent, we will obtain it through a clear, affirmative action specific to the processing (for example, clicking “I Agree” or enabling a setting). Where we process Personal Data to perform a contract with you, that contract is the lawful basis, and withdrawing consent will not stop that processing. If you withdraw consent, you may lose access to some or all of the Services or Site features that depend on that Personal Data, and we may continue to process Personal Data under a different lawful basis (for example, where required by law or to establish, exercise, or defend legal claims).
3. Information We Process
We process Personal Data: (a) that you provide directly (e.g., name, email, company, contact, and billing details); (b) automatically when you visit the Site (e.g., IP address, device identifiers, browser type, pages viewed); and (c) from other sources, including advertising platforms such as YouTube and TikTok, ad exchanges, publishers, and business partners.
We process this data to provide, operate, and improve the Services; communicate with you; process payments; enforce our agreements; detect and prevent fraud and security incidents; comply with legal requirements; and, where permitted, send administrative or marketing communications. Our brand safety and content classification Services may use automated tools to analyze content. We will not use Personal Data for materially different purposes without notice and your consent.
4. California Disclosures: Categories of Personal Data
The table below identifies the categories of Personal Data we have processed in the preceding 12 months, consistent with the CCPA/CPRA (Cal. Civ. Code § 1798.140), along with their source, purpose, and whether we sell or share that category.
| Category | Examples | Source | Purpose | Sold / Shared? |
| Identifiers | Name, email, IP address, device ID | You; automatic collection | Providing Services, communications, security | No |
| Commercial Information | Payment and billing details | You; payment processors | Completing transactions | No |
| Internet/Network Activity | Browsing behavior, pages viewed, interactions | Automatic collection (cookies) | Analytics, service improvement, security | No |
| Professional Information | Company name, job title | You | Account management, business communications | No |
| Inferences | Content classification/brand-safety outputs | Derived from categories above | Providing brand safety and content classification Services | No |
We do not sell Personal Data and do not knowingly process Sensitive Personal Information. If you choose to submit Sensitive Personal Data to us, we will process such data only with your explicit consent and opt-in consent where required by applicable law. Please do not submit Sensitive Personal Information to us unless we have asked for it and obtained your consent.
5. Cookies and Opt-Out Signals
We use cookies and similar technologies for functionality, analytics, advertising, and security. These technologies include cookies (small files placed on your device); web beacons or pixel tags (small electronic files in web pages and emails that help us count visitors and email opens and verify system integrity); local storage; and device identifiers. Where required, we obtain consent before placing non-essential cookies; in the EU and UK we set only strictly necessary cookies before your consent, and you can manage preferences through your browser. If you refuse or disable cookies, some parts of the Site may not function properly. We recognize Global Privacy Control and other qualifying universal opt-out signals as a valid request to opt out of the sale or sharing of Personal Data and targeted advertising, as required under applicable State Privacy Laws.
Do Not Track. Some web browsers offer a “Do Not Track” setting. Because there is no uniform industry standard for responding to Do Not Track signals, we do our best to respond to such signals but do not guarantee a serviceable response.
6. How We Transfer Personal Data
We may transfer Personal Data to our affiliates; service providers (e.g., hosting, analytics, customer support); advertising technology partners (e.g., ad exchanges, supply- and demand-side platforms) in connection with our brand safety and content classification Services; payment processors; legal or regulatory authorities, courts, and other parties where we believe disclosure is required by law or necessary to comply with legal process, protect our rights or property, prevent fraud or illegal activity, or protect the safety of any person; successors in a merger, acquisition, or similar business transaction (in which case Personal Data may be among the assets transferred and, for EEA and UK residents, we will take reasonable steps to ensure an appropriate lawful basis and transfer safeguard continue to apply); and other parties at your direction or with your consent.
7. Your Privacy Rights
Depending on your location, you may have the right to:
- Know what Personal Data we process about you and how it is processed, and access or correct it;
- Delete your Personal Data or obtain a portable copy of it;
- Restrict or object to our processing, including profiling, and withdraw consent at any time;
- Opt out of targeted advertising, the sale or sharing of Personal Data, and certain automated profiling;
- Not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, and to request human intervention, express your point of view, and contest any such decision;
- Opt out of marketing communications by clicking the “Unsubscribe” link in any marketing email;
- Limit our use of Sensitive Personal Information; and
- Appeal a denied request or lodge a complaint with your applicable regulator (for EEA residents, your local data protection supervisory authority and, for UK residents, the Information Commissioner’s Office), without being discriminated against for exercising any of these rights.
To exercise these rights, submit a request via our Data Subject Rights Request Form at https://zefr.com/privacy/dsar or email privacy@zefr.com. You may also opt out of sale/sharing and targeted advertising by visiting Do not sell or share my information or by enabling a recognized opt-out signal (e.g., Global Privacy Control) in your browser. We may verify your identity before fulfilling a request; authorized agents may submit requests where permitted by law.
We will respond within the timeframe required by law, generally 45 days under U.S. state laws (extendable by 45 days) and one month under the EU/UK GDPR (extendable by two months). If we deny your request, you may appeal by emailing privacy@zefr.com with “Appeal” in the subject line; we will respond to appeals within 60 days.
If you opt out of marketing communications, we may still send you administrative messages relating to the Site or Services (such as security, account, or contract notices). We will not penalize you for exercising any of your rights. However, if you ask us to delete Personal Data that we need to provide a particular feature or Service, that feature or Service may become unavailable as a direct result of the Personal Data no longer being available, and not as a penalty. If we ever make a decision based solely on automated processing that produces legal or similarly significant effects on you, we will provide meaningful information about the logic involved and the significance and consequences of that decision at or before the time we make it. This list may not include every right you have under applicable law.
8. Additional Rights for California Residents
California residents have certain additional rights and disclosures under the CCPA/CPRA and California law, beyond those in Section 7:
- Notice at Collection: We provide the categories and purposes of Personal Data processed at or before the point of collection (see Section 3 and the California Disclosures table above), consistent with Cal. Civ. Code § 1798.100.
- Right to Opt Out of Sale/Sharing: California residents may opt out of the sale or sharing of Personal Data, and of cross-context behavioral advertising, at any time via our “Do Not Sell or Share My Personal Information” link in the Site footer, our cookie preference tool, or by enabling Global Privacy Control in your browser. No account or transaction is required.
- Shine the Light: Under Cal. Civ. Code § 1798.83, California residents may request, once per year and free of charge, information about any Personal Data we disclosed to third parties for their own direct marketing purposes in the prior calendar year.
- Authorized Agents: A California resident may designate an authorized agent to submit a request on their behalf by providing signed permission; we may still require the resident to verify their own identity directly with us.
California-specific requests may be submitted the same way as described in Section 7, or by emailing privacy@zefr.com with “California Privacy Request” in the subject line.
9. Retention, Security, and International Transfers
We process Personal Data only as long as necessary for the purposes described in this Policy or as required by law, considering its sensitivity, the purpose of processing, applicable legal and accounting requirements, and our legitimate needs to prevent fraud and abuse, resolve disputes, and enforce our agreements; de-identified and aggregated data may be processed indefinitely. We use reasonable administrative, technical, and physical safeguards to protect Personal Data and limit access to Personal Data to personnel and Service Providers who need it for the purposes described in this Policy, though no system is completely secure. Your data may be transferred to and processed in the United States or other countries; where required, we use appropriate safeguards such as Standard Contractual Clauses, a copy of which is available on request at privacy@zefr.com.
10. Children's Privacy
Our Site and Services are not directed to individuals under 18, and we do not knowingly collect Personal Data from anyone under 18. In accordance with COPPA, we do not knowingly collect Personal Data from children under 13 without verifiable parental consent. Consistent with the CCPA/CPRA and other State Privacy Laws, we do not sell or share, or use for targeted advertising, the Personal Data of a known minor under 16 without opt-in consent (from the minor if 13–15, or a parent or guardian if under 13). If you believe a minor has provided us with Personal Data, contact us at privacy@zefr.com. If we learn that we have processed Personal Data from a person under 18 in violation of this Policy or applicable law, we will delete it as soon as reasonably possible, subject to our legal obligations.
To the extent required by State Privacy Laws, we (i) obtain your opt-in consent before processing Sensitive Personal Information; (ii) conduct and document data protection assessments before engaging in processing that presents a heightened risk of harm, such as targeted advertising, the sale of Personal Data, or certain profiling; (iii) honor recognized universal opt-out preference signals, including Global Privacy Control; and (iv) provide a process to appeal a denied rights request, as described in Section 7.
11. Other Disclosures
Certain State Privacy Laws require businesses meeting applicable thresholds to publish annual metrics on privacy rights requests. We may update this Policy from time to time; the “Last Modified” date reflects the most recent revision, and material changes will be communicated as required by law.
12. Third-Party Platforms
ZEFR uses YouTube API Services and TikTok platform services in connection with the Services and complies with their respective terms. For more on their data practices, see Google’s Privacy Policy and TikTok’s Privacy Policy.
The Site may contain links to third-party websites and services that we do not control. This Policy does not apply to, and we are not responsible for, the privacy practices of those third parties, and the inclusion of a link does not imply our endorsement. We encourage you to review the privacy policies of any third-party site you visit.
13. Contact Us
Email: privacy@zefr.com | Mailing Address: 4101 Redwood Avenue, Los Angeles, Ca 90066