Privacy policy
Zigzaag respects your privacy. This policy explains what personal information we collect through Zigzaag, why we collect it, how we store it, and the choices you have. It is written to align with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Last updated 17 September 2026
1. Our two roles
We handle personal information in two distinct capacities, and different parts of this policy apply to each.
As a controller, we handle information about you — our customer — such as your account details, billing information and support correspondence. As a processor, we handle information about your customers — the people who call or message your business — strictly on your instructions and only to provide the service.
2. Information we collect
- Account information: name, email address, business name, phone number and password credentials.
- Billing information: billing name, address, ABN and payment method details, which are processed by our payment provider and never stored in full on our systems.
- Usage data: call minutes, message counts, feature usage, log data, device and browser information, and IP address.
- Conversation content processed on your behalf: call audio, transcripts, messages across connected channels, and the contact details and enquiry details your customers provide.
- Knowledge content you upload: price lists, service documents, FAQs and site content used to ground your agents.
- Support and sales correspondence, including information you submit through our contact form.
3. How we use information
We do not sell personal information. We do not use your conversation content, recordings or uploaded documents to train third-party foundation models, and we engage model providers under zero-retention terms where they are offered.
- To provide the service: answering calls and messages, generating replies, making bookings and running workflows.
- To operate your account: authentication, workspace and team management, billing and usage metering.
- To support you: responding to enquiries, troubleshooting, and notifying you about service changes.
- To keep the service safe: fraud prevention, abuse detection, rate limiting and security monitoring.
- To improve the product in aggregate: we analyse usage patterns and error rates, using de-identified or aggregated data.
4. When we disclose information
We disclose personal information only to service providers who help us deliver the platform, and only to the extent necessary. These include cloud hosting and database infrastructure, telephony and messaging providers, AI model providers, email delivery, payment processing, and error monitoring.
We may also disclose information where required by Australian law, to enforce our terms, or to protect the rights and safety of our users. If we are ever involved in a merger or acquisition, we will notify you before your information becomes subject to a different privacy policy.
5. Storage location and overseas disclosure
Conversation content and customer records are stored on infrastructure located in Australia. Some subprocessors — in particular AI model providers and error monitoring — may process data in the United States or the European Union. Where that occurs, we contract for appropriate protections and process only the minimum necessary.
A current list of subprocessors, including their location and function, is available on request.
6. Retention and deletion
Call recordings and transcripts are retained for the period you configure, with a default of twelve months. Account and billing records are retained for seven years to meet Australian tax and corporate record-keeping obligations. Everything else is retained only while your account is active.
You can delete individual conversations at any time from your workspace. When you close your account, we delete your workspace data from primary storage within thirty days and from encrypted backups within thirty-five days after that.
7. Security
We protect personal information with encryption in transit and at rest, application-layer encryption of stored third-party credentials, workspace-level data isolation, role-based access control, audit logging, and restricted, multi-factor-authenticated production access. Our security practices are described in more detail on our security page.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify affected customers and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
8. Accessing and correcting your information
You can access and correct most of your information directly in your workspace settings, and export your workspace data at any time. For anything you cannot do yourself, email support@zigzaag.com.au and we will respond within thirty days.
If you are a customer of a business that uses Zigzaag and you want your information accessed, corrected or deleted, please contact that business directly. They control the data and we will act on their instruction.
9. Cookies and analytics
We use strictly necessary cookies for authentication, session management and security. We use privacy-respecting, aggregate analytics to understand which pages are useful; we do not run third-party advertising trackers or sell audience data.
10. Complaints and contact
If you have a privacy question or complaint, email support@zigzaag.com.au with "Privacy" in the subject line. We will acknowledge your complaint within five business days and aim to resolve it within thirty days. If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au.
11. Changes to this policy
We may update this policy as the product and the law change. Material changes will be notified by email to workspace owners and announced in-product at least fourteen days before they take effect. The date at the top of this page always reflects the current version.