Thanks for entrusting Zamzar with your files and your personal information. Handling your data is a serious responsibility, and we want you to know how we go about doing that.
Zamzar is registered in England as a limited company (number 6463494).
- This policy is effective from 25th May 2018
- This policy was last modified on 16th September 2020
We are Zamzar Limited, a provider of file conversion services based in England. Our company number is 6463494 and our registered office is at The Courtyard, Shoreham Road, Steyning, West Sussex, BN44 3TN. All references in this policy to "Zamzar", "our", "us" or "we" refer to Zamzar Limited, or our suppliers which provide services to us, as appropriate.
Information from website browsers
What do we collect?
If you are browsing the website, we collect the same basic information that many other websites collect. We use common Internet technologies, such as cookies and web server logs. This is information we collect from everybody who visits our website, whether they have an account or not. More information on cookies may be found here.
The information we collect about all visitors to our website includes the visitor's browser type ("User Agent"), language preference, referring site, and the date and time of each visitor request. We also collect potentially personally-identifying information like Internet Protocol (IP) addresses.
Why do we collect this?
We collect this information to better understand how our website visitors use Zamzar, to monitor and protect the security of the website and to protect against abuse of the Services. We also use this information to recognise you when you return to our website, to store information about your preferences, and to allow us to customise the website according to your individual interests.
Information from users converting files
What do we collect?
If you convert a file using our services we may collect your email address (if you provide it) along with details of the filename or file URL.
Why do we collect this?
We collect this information in order to provide our file conversion services to you – without this information we are not able to convert your files or provide you with a link to download your converted files.
Information from users with accounts
What do we collect?
If you create an account with us on our website, we require some basic information at the time of account creation. You will create your own password, and we will ask you for your full name and a valid email address. We will also collect your billing details, including credit card information (card name, number, expiry and CVV), a billing address and for some customers a valid VAT number.
Why do we collect this?
- We need this information in order to set up your account, and to provide any services you have requested from us.
- We use your email address to identify you on Zamzar and send important system and account notices to you. We do not use your email address for marketing purposes unless you have specifically consented to us doing this. We don't share or sell your email address with any 3rd parties.
People who contact us with enquiries
What do we collect?
If you contact us with an enquiry, we will collect the information provided when you correspond with us, such as your name, your address, your email address and your telephone number.
Why do we collect this?
We will collect, use and store the personal information listed above to deal with any enquiries or issues you have about our Services, including any questions you may have about how we collect, store and use your personal information, or any requests made by you for a copy of the information we hold about you.
We do not intentionally collect or store special categories of personal data, such as genetic data, health information, or religious information. Although Zamzar does not request or intentionally collect any special categories of personal data, we realize that you might store this kind of information in your account, via the files that you convert.
If you ask us to convert or store any files containing special categories of personal data on our servers, located in the United States, we will only do so on your instructions as a data processor and in accordance with our Data Processing Agreement with you. You are the controller of this data and you must ensure that you have a legal basis to share this data with us.
We use the information you provide to us in a number of ways and we have set out our legal basis for processing your information below:
To provide, update and maintain the Services we offer to you
This is the most common usage of your information. We use your personal information to provide various file conversion Services to you, in accordance with our Terms of Service. In particular, we will use your data to: set-up an account; convert the files that you provide us with into different formats; and if you provide us with an email address, send you links to download those files to that email address.
Our use of your personal information in this way is necessary to perform our obligations to provide the Services to you, under our Terms of Service.
To communicate with you by responding to your requests, comments and questions
If you contact our support team we may use the information that you provide to us in order to help us respond to your enquiry.
Our use of your personal information in this way is necessary to perform our customer service obligations to you, under our Terms of Service.
If we do not have a contract with you, we may process your personal information for these purposes where it is in our legitimate interests to do so for customer services purposes.
For billing, account management and other administrative matters
Zamzar may need to contact you for invoicing, account management and similar reasons and we use account data to administer accounts and keep track of billing and payments.
Our use of your personal information in this way is necessary to perform our obligations to you under our Terms of Service.
As required by applicable law, legal process or regulation
We may use your information to comply with court orders and similar legal or regulatory obligations which apply to us.
This may include where we reasonably consider it is in our legitimate interests or the legitimate interests of others to comply, as well as where we are legally required to do so.
To investigate and help prevent abuse or security issues
We may use information such as your IP address to help us prevent abuse of the Services we provide and investigate any potential unauthorized use of those Services or other security breaches.
In these circumstances, we believe we have a legitimate interest in handling your data, and do not believe that this storage and use of your data will be of particular concern to you.
If we rely on our (or another person's) legitimate interests for using your personal information, we will undertake a balancing test to ensure that our (or the other person's) legitimate interests are not outweighed by your interests or fundamental rights and freedoms which require protection of the personal information. You can ask us for information on this balancing test by using the contact details at section 5.5.
We also collect and use data which is aggregated or anonymised for certain business purposes, such as creating aggregate statistics or reporting. However, no single individual will be identifiable from the anonymised details we collect for these purposes.
What are cookies?
Cookies are small text files (typically made up of letters and numbers) placed in the memory of your browser or device when you visit a website or view a message. They allow a website to recognize a particular device or browser. Session-based cookies last only while your browser is open and are automatically deleted when you close your browser. Persistent cookies last until you or your browser delete them or until they expire.
For further information on deleting, disabling, blocking and controlling cookies please visit http://www.allaboutcookies.org
Where possible, security measures are set in place to prevent unauthorized access to our cookies.
How is Zamzar using cookies?
We use several types of cookie:
|Categories of Use||Description|
|Authentication||If you are signed in to the Services, authentication cookies help us personalize your experience and show you the right information.|
|Security||We use security cookies to enable and support our security features, and to help us detect malicious activity.|
|Performance, Analytics and Research||Cookies help us and our third party suppliers to learn how well our sites and Services perform. We also use performance, analytics and research cookies to understand, improve, and investigate products, features, and services.|
What cookies does Zamzar use?
We use the following cookies:
|Categories of Use||Description|
These cookies are used to collect information about how visitors use our site. We use the information to compile reports and to help us improve the site. The cookies collect information in an anonymous form, including the number of visitors to the site, where vistors have come to the site from and the pages they visited.
To opt out of being tracked by Google Analytics across all websites visit: http://tools.google.com/dlpage/gaoptout
These cookies are used by us to help manage load to the website (to provide the best possible performance to users), to allow users to register for Zamzar and login, and to allow users to switch between old and new website designs. They do not contain any personally identifiable information.
If you do not wish these cookies to be set then you should not use the Zamzar website. To block cookies from the zamzar.com domain in your web browser you should follow browser instructions at: http://www.allaboutcookies.org/manage-cookies/stop-cookies-installed.html
What can you do if you don't want any cookies to be set or want them to be removed?
Some people prefer not to allow cookies, which is why most browsers give you the ability to manage cookies to suit you. In some browsers you can set up rules to manage cookies on a site-by-site basis, giving you more fine-grained control over your privacy. What this means is that you can disallow cookies from all sites except those that you trust.
Browser manufacturers provide help pages relating to cookie management in their products. Please click on the links below for more information on how to manage your cookie settings.
- Google Chrome
- Internet Explorer
- Mozilla Firefox
- Safari (Desktop)
- Safari (Mobile)
- Android Browser
- Opera Mobile
We use Google Analytics as a third party tracking service, but don't use it to track you individually. We use Google Analytics to collect information about how our website performs and how our users, in general, navigate through and use Zamzar to help us evaluate our users' use of Zamzar; compile statistical reports on activity; and improve our content and website performance.
We look to protect your privacy by anonymizing your IP address prior to sending it to Google Analytics and we only gather certain basic information, such as your browser type, referring and exit pages, time stamp, and similar data about your use of Zamzar. We do not link this information to any of your personal information.
Google provides further information about its own privacy practices and offers a browser add-on to opt out of Google Analytics tracking.
We may integrate functionality from third party social media websites (such as Facebook or Twitter) into our Services, for example by providing "like" or "share" buttons on some pages. These buttons may enable those services to track your visit to Zamzar.
We do not share, sell, rent or trade your email address with any third parties for any commercial purposes.
We will share your personal information with the following third party vendors:
- Amazon Web Services, Inc who provides server hosting and content distribution networks (CDN's) services;
- MacStadium, Inc and Keyweb AG who provides server hosting services;
- SoftLayer Technologies. Inc who provides server hosting services;
- PayPal (Europe) S. r.l. et Cie, S.C.A. who provides payment processing services; and
- Google LLC, WeTransfer B.V., Habla, Inc and Slack Technologies Inc, who provide customer support tooling services.
When we transfer your data to our vendors, we remain responsible for it. We try to ensure that any third parties with whom we share your personal information are limited (by law and by contract) in their ability to use your personal information for any purpose other than to provide services for us.
We may share personal information where it is in our legitimate interests to do so to run, grow and develop our business if we are involved in a merger, sale, or acquisition. If any such change of ownership happens, we will ensure it is under terms that preserve the confidentiality of personal information, and we will notify you on our website or by email before any transfer of your personal information.
We do not host any third party advertising at zamzar.com.
Zamzar may disclose personally-identifying information or other information we collect about you in response to a valid subpoena, court order, warrant, or similar government order, or when we believe in good faith that disclosure is reasonably necessary to protect our property or rights, or those of third parties or the public at large. This may include exchanging personal information with other organisations for the purposes of fraud protection and credit risk reduction.
We will also disclose your personal information to third parties in order to enforce or apply our terms and conditions or any other agreement or to respond to any claims, to protect our rights or the rights of a third party, to protect the safety of any person or to prevent any illegal activity.
Zamzar takes the security of data very seriously, and we work hard to protect any information you provide to us from loss, misuse, and unauthorized access or disclosure. We take all reasonable precautions to safeguard the confidentiality of your personal information, including through use of appropriate organisational and technical measures. These measures take into account the sensitivity of the data we collect, process and store, and the current state of technology.
Given the nature of communications and information processing technology, Zamzar cannot guarantee that information, during transmission through the Internet or while stored on our systems or otherwise in our care, will be absolutely safe from intrusion by others, but we do our utmost to protect it. Once we have received your personal information, we will use strict procedures and security features to prevent unauthorised access to it.
As a minimum we take the following measures to secure your data:
- Physical Security - Zamzar infrastructure is only hosted in data centres which meet rigorous security standards. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilising video surveillance, intrusion detection systems, and other electronic means.
- Data Transfer Integrity - All traffic to and from Zamzar servers is secured by transport level security (TLS) sent over a Secure Socket Layer (SSL), and secured using an AES 256-bit SSL certificate. This ensures that data sent between your systems and ours is encrypted using military grade encryption.
- Password Encryption - Zamzar user account passwords are stored in our database after being salted and hashed using the Bcrypt encryption algorithm.
- Firewalls - Zamzar enforces network level control for access to infrastructure by using multiple different firewall technologies to ensure that different components of its systems are logically isolated from one another.
- Operational Access Controls - Zamzar employees require access to production services for operational reasons. We employ multiple authentication mechanisms to ensure that production systems are accessed only by authorised members of staff and are protected from unauthorised access.
- Software Updates - Zamzar regularly applies software patches to production infrastructure in order to ensure a strong security posture to known software vulnerabilities.
- External Accreditation - Zamzar takes a pro-active approach to security by employing an external company to perform monthly security scans of its infrastructure.
- Bug Bounty Program - Zamzar operates an informal "bug bounty" program that encourages security researchers to perform limited and authorised testing of the integrity of Zamzar systems.
If you have an account with Zamzar
If you have an account with Zamzar, we will retain your personal information for as long as your account is active or as needed to provide you with Services that you request (in accordance with our Terms of Service).
Once your account is deactivated we will permanently remove any files associated with your account 35 days after deactivation.
We may retain certain other personal information (such as your email address) for 18 months after your account is deactivated, unless you delete it or request its deletion. For example, we don't automatically delete inactive user accounts, so unless you ask us to permanently delete your account we will retain some account information to enable you to return and use our Services more easily in future.
If you do not have an account with Zamzar
We will store any files you submit to us for conversion, and their converted outputs on our systems for no longer than 7 days following receipt. After this time they are permanently removed from our storage systems.
We will retain personal information such as your IP address, email address (if provided by you) and browser details for no longer than 30 days. After this time we permanently delete your browser data and anonymise your IP address and email address (if provided by you) so that we can no longer personally identify you.
Zamzar may transfer your personal data to countries other than the one in which you live, including to our file server suppliers located in the United States.
- in the case of US based entities, entering into European Commission approved standard contractual arrangements with them, or ensuring they have signed up to the EU-US Privacy Shield (see further https://www.privacyshield.gov/welcome); or
- in the case of entities based in other countries outside the EEA, entering into European Commission approved standard contractual arrangements with them.
Further details on the steps we take to protect your personal information, in these cases is available from us on request by contacting us by email at email@example.com at any time.
If you have a user account for the Services you may review and edit any personal data you have supplied to us in your user profile. If you do not have a user account, or if you have questions about your account information or other personal data please contact us by email at firstname.lastname@example.org.
Individuals located in certain countries, including the European Economic Area and Switzerland, have certain statutory rights in relation to their personal data. While some of these rights apply generally, certain rights apply only in certain limited circumstances. We describe these rights below.
Please note that we may ask you to verify your identity before taking further action on your request. Additionally your request and choices may be limited in certain cases: for example, if fulfilling your request would reveal information about another person, or if you ask to delete information which we are permitted by law or have compelling legitimate interests to keep.
You have the right to be provided with information about the data we hold, our data processing activities and whether we transfer personal data outside of the EAA, along with the methods we use to safeguard such data.
In some jurisdictions, applicable law may entitle you to request copies of your personal information held by us.
You have the right to ask us to correct inaccurate, out of date or incomplete personal information concerning you (and which you cannot update yourself within the Services).
We generally retain any personal information for as long as is necessary for the performance of the contract between you and us and to comply with our legal obligations. If you no longer want us to use your information to provide the Services to you, you can request that we erase your personal information and (if you have one) close your user account. Please note that if you request the erasure of your personal information:
- We may retain some of your personal information as necessary for our legitimate business interests, such as fraud.
- We may retain and use your personal information to the extent necessary to comply with our legal obligations.
- Because we maintain the Zamzar Services to protect from accidental or malicious data loss and destruction, residual copies of your personal information may not be removed from our backup systems for a limited period of time.
In some jurisdictions, applicable law may entitle you to request Zamzar not to process your personal information for certain specific purposes where such processing is based on our (or another party's) legitimate interests. If you object to such processing Zamzar will no longer process your personal information for these purposes unless we can demonstrate compelling legitimate grounds for such processing or such processing is required for the establishment, exercise or defence of legal claims.
You may be entitled to request copies of personal information that you have provided to us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible). This right only applies where we use your personal information on the basis of your consent or performance of a contract; and where our use of your information is carried out by automated means.
Subject to applicable law, you also have the right to lodge a complaint with your local data protection authority or the UK Information Commissioner's Office, which is Zamzar's lead supervisory authority in the European Union.
To the extent that we act as a data processor on your behalf in connection with the performance of our Services, we will enter into a separate "Data Processing Agreement" with you. You can find out more information on this Data Processing Agreement by emailing us at email@example.com.
If you are a resident of the European Economic Area and believe we are the controller of your personal data within the scope of the General Data Protection Regulation (GDPR), you may direct questions or complaints to our lead supervisory authority:
UK Information Commissioner
Information Commissioner's Office
Phone: +44 1625 545 745
Fax: +44 1625 524 510
If you're a child under the age of 13, you may not use Zamzar's Services. Zamzar does not knowingly collect information from or direct any of our content specifically to children under 13. As set out in our Terms of Service, if we learn or have reason to suspect that you are a user who is under the age of 13, and you have an account with us we will unfortunately have to close your account.
Zamzar Ltd Data Protection Representative