Privacy Policy
How we collect, use, share and protect personal data across our Dataset Services and our Platform and API — and how you can exercise your rights over it.
Who we are and what we do
ZipLabs.ai is operated by Jesse Infotech Marketing Private Limited, a company registered in India. We run two service lines: Dataset Services, which deliver machine-readable datasets of publicly available information, and Platform and API Services, which let customers retrieve public data programmatically.
This policy distinguishes two groups. Dataset Subjects are individuals whose publicly available information appears in our datasets. Users are the customers and organisations who use the Services.
Scope and definitions
This policy covers how we collect, maintain, use, share, secure and process personal data for both Users and Dataset Subjects.
“Personal Data” means information relating to an identifiable natural person. “Processing” means any operation performed on that data. We do not intentionally collect data about children under 18.
What we collect and how we obtain it
User data
- Account and registration: name, work email, company, role, country, passwords and SSO identifiers, and information you submit through forms.
- Usage and device: IP address, browser information, authentication logs, API metrics and interaction telemetry.
- Communications: email content, support tickets, meeting notes, and recorded support calls where legally permitted.
Dataset Subject data
Sourced from public webpages, social media profiles and professional directories. Typically name, headline or position, employer, education, location at city or region level, languages, skills, public bios and publicly shareable links. We do not intentionally collect special categories such as health, religion, biometric data or sexual orientation.
Consumer intelligence (India)
Demographic, professional and credit profile data built from publicly available sources and licensed third-party providers, including NBFC-affiliated providers for credit profile data.
Our roles: controller and processor
We act as controller for Dataset Services in respect of Dataset Subject data, and for User account and website operations.
We act as processor for personal data that Users collect or submit through the Platform or API. In those cases the User, or their organisation, is the controller and their own privacy policy governs.
Purposes and legal bases
For Users
- Providing, operating and securing the Services — performance of contract; legitimate interests.
- Support, billing and administration — contract; legitimate interests; legal obligation.
- Service improvement and analytics — legitimate interests; consent for cookies and SDKs.
- Marketing about features and events — consent where required, with opt-out always available.
- Compliance, fraud prevention and safety — legal obligations; legitimate interests.
For Dataset Subjects
- Creating and maintaining a structured repository of information that was made publicly available, in order to provide Dataset Services — legitimate interests, with additional grounds such as public interest or consent in some jurisdictions.
- Data accuracy and quality checks — legitimate interests.
- Compliance and rights handling — legal obligations; legitimate interests.
Who we share data with
- Internal teams responsible for data collection and enrichment.
- Service providers for cloud hosting, security, logging, email, payments and support, under written agreements requiring data protection.
- Business partners, for integrations you ask us to enable.
- A successor entity in a merger or acquisition.
- Public authorities, where legally required or to protect rights and safety.
We do not sell your User account data. Making datasets built from public sources available for a fee may constitute a “sale” or “sharing” in some jurisdictions — see the regional notices below for opt-out rights.
International transfers
Personal data may be transferred, stored and processed outside your country. Where the law requires it, we put appropriate safeguards in place, such as adequacy decisions or contractual protections.
Security
We use encryption in transit, access controls and role-based permissions, network monitoring, vulnerability management, multi-factor authentication for staff, VPN for remote access, secure development practices and employee training.
No system is completely secure. We maintain incident response procedures and will notify where the law requires it.
Retention
We keep personal data for as long as needed for the purposes described here — delivering the Services, meeting legal obligations, resolving disputes and enforcing agreements — or for as long as otherwise permitted or required by law.
Data from public sources is refreshed periodically. If a Dataset Subject removes information at the original source, that change propagates during a standard refresh cycle.
Your choices and how to exercise your rights
Email support@ziplabs.ai. We verify identity, and authority where someone acts as an agent, before acting on a request.
- Access or obtain a copy of your personal data.
- Correct inaccurate data.
- Delete or erase data where legally required.
- Restrict or object to processing.
- Receive your data in a structured, machine-readable format.
- Opt out of marketing communications at any time.
Where we act as processor, we refer the request to the relevant controller.
Regional notices
United Arab Emirates
The UAE Personal Data Protection Law applies, giving rights to access, rectify, erase, restrict processing, obtain portability and object to automated decision-making. Cross-border transfers use approved mechanisms. The supervisory authority is the UAE Data Office. Free-zone regimes such as DIFC and ADGM may impose additional or alternative rules.
European Economic Area and United Kingdom
Under the GDPR and UK GDPR you have rights to transparent information, access, rectification, erasure, restriction, portability and objection, and protection against decisions based solely on automated processing that produce legal effects. Our legal bases are performance of contract, legitimate interests, consent where required, and legal obligations.
California
- Know and access the categories and specific pieces of personal information collected.
- Delete personal information, subject to exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information and of cross-context behavioural advertising.
- Limit the use and disclosure of sensitive personal information.
- Not be discriminated against for exercising these rights.
To opt out, email support@ziplabs.ai with the subject line “Do Not Sell or Share My Personal Information” and a link to your LinkedIn profile. Authorised agents may submit requests with proof of authorisation.
Automated decision-making and profiling
We do not make decisions producing legal or similarly significant effects based solely on automated processing. Datasets may contain inferences or classifications drawn from public fields, such as skills or seniority, but those do not drive solely automated decisions of that kind.
Third-party links and sources
The Services link to third-party sites that supply publicly available information. Those sites’ own settings and privacy policies govern their data, and we are not responsible for their practices.
Requests about public-source data
Dataset Subjects can contact support@ziplabs.ai to access, correct, delete or opt out of inclusion in a dataset. Where the law permits, we keep a limited opt-out record so the information is not reintroduced. You can also change or remove the information at its original public source, and that change propagates during a refresh cycle.
Contact us
Email: support@ziplabs.ai
Post: Jesse Infotech Marketing Private Limited (ZipLabs.ai), Bengaluru, India
If we process your data as a processor on behalf of a customer, please contact that customer first.
Changes to this policy
We may update this policy from time to time. The effective date above shows when it was last revised. If a change is material we will notify you through the website or by email.
Rebuilt for v3. This page reproduces the structure and substance of the policy published at ziplabs.ai/privacy-policy, restyled for the new site. It has not been re-drafted or reviewed by counsel — the operative wording should be confirmed by whoever owns the legal text before this replaces the live page.