Privacy Policy
Last Updated: 22/07/2026 · Effective: 23/12/2024
Pending legal review. This Policy was updated on 22/07/2026 to reflect our current providers and features; the update is pending review by legal counsel. Until this update is finalized, the previous version (effective 23/12/2024) continues to apply; it is available on request at info@qtoolsrl.it.
This Privacy Policy explains how QTOOL S.r.l. (trading as “Zephyra”) (“Zephyra”, “we”, “us”) collects, uses, discloses, and protects Personal Data when you visit our websites or use our platform and services.
1. Who we are and how to contact us
Controller: QTOOL S.r.l. (Zephyra)
Registered address: Via Sarus 4, 11026 Pont Saint Martin, Italy
Email (privacy): privacy@zephyra.tech (certified mail: qtool@pec.it)
2. Scope
This Policy applies to:
- Our websites (including zephyra.tech and app.zephyra.tech).
- The Zephyra SaaS platform and related services (the “Services”).
- Sales, support, onboarding, and professional services interactions.
Desktop edition — local processing. Where the Zephyra desktop edition reads and processes files locally on your own hardware, and the data concerned is not transmitted to or stored on systems operated by Zephyra or its subprocessors, Zephyra does not process that data and this Policy does not apply to it (see also clause 2.4 of our DPA).
3. Roles under data protection laws: Controller vs Processor
3.1 When Zephyra is the Controller
We act as Controller for Personal Data we process to:
- Create and manage accounts and workspaces.
- Provide customer support and manage the commercial relationship.
- Send service communications (security, product, billing, legal notices).
- Administer billing, accounting, and tax compliance.
- Manage sales and marketing (where permitted).
- Operate in-platform product analytics of how the platform is used (see Section 5(5)); for this processing Zephyra acts as an independent controller under Article 28(10) GDPR, and it is outside the scope of the DPA.
3.2 When Zephyra is the Processor
When a business customer uploads or inputs data into the Services (“Customer Data”), Zephyra typically processes that data as a Processor on behalf of the customer (the Controller). Customer Data may include files and metadata (e.g., CAD/mesh files, simulation inputs/outputs, project data) and may contain Personal Data if the customer uploads it.
Processor terms are governed by the applicable contract/Order Form and (where applicable) a Data Processing Agreement. Our standard DPA is published in draft at /legal/dpa (pending legal review); upon finalization it will be incorporated into the Master Terms of Service for all customers, and enterprise customers may alternatively execute a countersigned copy.
4. Personal Data we collect
Depending on your interaction with Zephyra, we may collect:
A. Account and identity data Name, business email, phone number, company, job title, country.
B. Authentication and access data Login credentials (stored securely), single sign-on identifiers where you log in via Microsoft Entra ID, roles/permissions, workspace membership.
C. Billing and commercial data Billing contact details, invoicing address, VAT/tax identifiers, payment status, purchase history. Subscription billing and payments are handled by our payment provider, Stripe; payment card data is processed by Stripe and not stored by Zephyra.
D. Usage, device, and log data IP address, device/browser identifiers, timestamps, logs, feature usage, diagnostic and security events.
E. Communications Support tickets, emails, call notes, meeting notes, feedback, survey responses.
F. Customer Data (Processor data) Customer-uploaded files/content and related metadata that may include Personal Data if included by the customer.
5. Purposes and legal bases (GDPR)
We process Personal Data only when we have a lawful basis.
1) Provide the Services and manage accounts Purpose: authentication, workspace administration, access control, service delivery. Legal basis: Contract.
2) Customer support and service operations Purpose: support, troubleshooting, incident management, service communications. Legal basis: Contract and Legitimate Interests (service quality and continuity).
3) Security and abuse prevention Purpose: detect and prevent fraud, misuse, security incidents, and to protect the platform. Legal basis: Legitimate Interests and/or Legal Obligation.
4) Billing, accounting, and tax compliance Purpose: invoicing, collections, accounting records, statutory compliance. Legal basis: Contract and Legal Obligation.
5) Product analytics and improvement Purpose: understand usage, improve performance and reliability, capacity planning. On our marketing website (zephyra.tech), analytics tags load only after you grant consent via the cookie banner. Within the platform (app.zephyra.tech), we currently use Google Analytics 4 for product-usage analytics and Sentry for error and performance monitoring (which receives IP addresses and user context together with diagnostic events); Zephyra processes this platform-usage data as an independent controller. Legal basis: Legitimate Interests. Where consent is required for cookies/trackers: Consent.
6) Sales and marketing (B2B) Purpose: respond to inquiries, outbound sales, newsletters, events follow-ups. Legal basis: Legitimate Interests (where permitted) and/or Consent (where required). You can object to direct marketing at any time.
6. Customer Data and model improvement
When we process Customer Data as a Processor, we process it only on documented instructions from the Customer and as necessary to provide the Services.
We may generate aggregated and anonymized statistics and diagnostics from service usage to operate, secure, and improve the Services (to the extent permitted by law and contract). Where contractually required, we will provide opt-in/opt-out mechanisms for specific improvement uses.
Customers should not upload special category data (e.g., health data, biometric identifiers, sensitive personal data) unless explicitly agreed in writing and covered by appropriate contractual safeguards.
AI-assisted features. Certain features of the Services (e.g., AI-assisted analysis, chat, and drawing review) use Google’s Gemini generative-AI API, a US-based service. When these features are used, the relevant prompts and project context are transmitted to Google for processing. For customers under our DPA, the use of AI-assisted features on Customer Data is governed by the DPA’s AI gate (clause 3.4: no-training term, AI-specific impact assessment, and a valid transfer safeguard; default off).
7. Sharing and disclosures
We may share Personal Data with:
A. Service providers (processors/subprocessors) We use service providers for infrastructure, hosting, storage, compute, logging, email delivery, customer support tooling, CRM, analytics, and payment processing. We require appropriate contractual protections and security measures.
Our principal providers include:
- Google Cloud Platform (GCP) — hosting, object storage, and content delivery for the platform (app.zephyra.tech) and websites, in EU regions with global CDN edge locations;
- Microsoft — single sign-on via Entra ID, transactional and operational email via Microsoft 365 / Microsoft Graph, in-app calling and chat via Azure Communication Services, and desktop-release distribution via Azure Blob Storage;
- SendGrid (Twilio) — transactional email (US);
- Google (Gemini) — AI-assisted features (US; see Section 6);
- Stripe — subscription billing and payments;
- Sentry — error and performance monitoring (EU ingest).
B. Professional advisors Legal counsel, auditors, and accountants where necessary.
C. Authorities Where required by law, or to protect rights, safety, and security.
D. Corporate transactions In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate safeguards.
We do not sell Personal Data.
Subprocessor transparency: We maintain an up-to-date list of subprocessors at: /legal/subprocessors.
8. International transfers
Your data is processed primarily in the EU; some of our providers (see /legal/subprocessors) process data in the US or at global edge locations. When Personal Data is transferred outside the EEA, we rely on safeguards under Chapter V GDPR, such as adequacy decisions, EU Standard Contractual Clauses (SCCs), or the EU–US Data Privacy Framework where a recipient’s certification is current. The safeguard documentation for each provider is being executed and documented as part of our ongoing compliance programme.
9. Data retention
We retain Personal Data only for as long as needed for the purposes described above:
- Account data: retained for the duration of the customer relationship and for a limited period thereafter for audit/dispute purposes (typically 12–24 months, unless required longer).
- Billing and tax records: retained for the period required by law (often up to 10 years).
- Support communications: retained for 10 years after ticket closure.
- Customer Data (Processor): retained as instructed by the Customer and under the contract. Automated self-service deletion and export are not yet available; on request, we perform a manual, best-efforts return or removal of stored Customer Data, as described in our DPA. Customers should maintain their own backups.
10. Cookies and similar technologies
We use cookies and similar technologies for:
- Strictly necessary functions (authentication, security, session management);
- Analytics (to understand usage and improve the Services);
- Marketing (only where enabled and permitted).
On our marketing website (zephyra.tech), a consent banner allows you to manage preferences before analytics or marketing tags load. The analytics and monitoring tools used within the platform are described in Section 5(5). See our Cookie Policy.
11. Security
We apply commercially reasonable technical and organizational measures to protect Personal Data, including role-based access controls and least-privilege practices, logical tenant isolation, single sign-on via Microsoft Entra ID, encryption in transit (TLS), provider-managed encryption at rest on cloud object storage, application audit logging, and a web application firewall on the public web tier. Some measures — such as multi-factor authentication and centralized security monitoring — are on our security roadmap and not yet in place. No system is perfectly secure; we cannot guarantee absolute security.
12. Your rights
Depending on your location and applicable law, you may have rights to:
- access, rectify, erase, restrict, or object to processing;
- data portability (where applicable);
- withdraw consent (where processing is based on consent);
- lodge a complaint with a supervisory authority.
Contact us to exercise rights. If we process your data as a Processor, we may refer you to your organization (the Controller).
13. Children
The Services are intended for business users and are not directed to children. We do not knowingly collect Personal Data from minors.
14. Changes to this Policy
We may update this Policy from time to time. We will post the updated version and revise the “Last Updated” date. If changes are material, we may provide additional notice (e.g., in-app or by email).