Privacy Policy

Privacy Policy

Effective Date: August 21, 2026
Last Updated: August 21, 2026

Zaberna, Inc. (“Zaberna,” “Zaberna AI,” “Company,” “we,” “us,” or “our”) respects your privacy and is committed to protecting personal information.

Zaberna, Inc. is a corporation organized under the laws of the State of New York and operates under the following trade names, brands, product names, or assumed names:

Zaberna AI

WriteLightning AI

DroneOps AI

VowBridge

Any related websites, applications, platforms, products, services, or successor brands operated by Zaberna, Inc.

For purposes of this Privacy Policy, references to “Zaberna,” “Zaberna AI,” “Company,” “we,” “us,” or “our” include Zaberna, Inc. and the brands listed above, as applicable.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit, access, create an account for, purchase, communicate with us about, or otherwise use our websites, applications, software, platforms, artificial-intelligence tools, CRM systems, automation systems, messaging tools, integrations, and related services (collectively, the “Services”).

By accessing or using the Services, you acknowledge the practices described in this Privacy Policy.

1. Information We Collect

We may collect personal information directly from you, automatically through your use of the Services, from your organization or account administrator, from connected third-party services, and from other sources permitted by law.

Information You Provide Directly

Depending on the Services you use, we may collect:

Your name, business name, job title, mailing address, email address, telephone number, and other contact information.

Account credentials, account preferences, authentication information, and profile information.

Billing, transaction, subscription, payment, and purchase information. Payment-card information may be collected and processed directly by our third-party payment processors rather than stored by Zaberna.

Communications with us, including support requests, emails, chat messages, survey responses, feedback, reviews, and other correspondence.

Content you submit, upload, import, create, or make available through the Services, including documents, images, videos, forms, templates, contact records, campaigns, CRM data, appointment data, customer records, prompts, workflow instructions, and other content (“Customer Content”).

Information you provide when registering for webinars, demonstrations, newsletters, events, marketing communications, or other programs.

Information Collected Automatically

When you visit or use the Services, we may automatically collect:

Internet protocol (“IP”) address.

Browser type, browser version, operating system, device type, device identifiers, and approximate location derived from IP address.

Log data, session data, pages viewed, features used, referring and exit pages, links clicked, timestamps, search terms, error reports, and diagnostic information.

Cookie, pixel, local-storage, and similar tracking-technology data.

Information about how you interact with our websites, applications, communications, content, and Services.

Messaging and Communications Information

If you opt in to receive communications from us or use Services that facilitate communications, we may collect and retain:

Telephone numbers, email addresses, communication preferences, and contact information.

Records of consent or opt-in, including the date, time, source, method, disclosures presented, and other evidence of consent.

Opt-out, unsubscribe, STOP, do-not-contact, revocation, and communication-preference records.

Message content, message-delivery information, delivery status, interaction data, response data, campaign information, and related metadata.

Appointment confirmations, support communications, transactional notices, service alerts, promotional-message records, and related communications data.

Information From Third Parties and Integrations

We may receive personal information from:

Your employer, business, agency, administrator, or other account users.

Third-party integrations that you authorize us to connect with.

Payment processors, communication providers, identity-verification providers, analytics providers, advertising partners, social-media platforms, and other service providers.

Publicly available sources, referral sources, business partners, and lead-generation sources, where permitted by applicable law.

Sensitive and Regulated Information

Please do not submit protected health information, Social Security numbers, government-issued identification numbers, payment-card data, nonpublic personal information, biometric data, precise geolocation, or other sensitive or regulated information through the Services unless we have expressly agreed in writing to support that data category and you have configured the Services in compliance with applicable law.

You are responsible for ensuring that you have the legal right to provide personal information and Customer Content to us for processing through the Services.

Information From Minors

Our Services are not directed to individuals under the age of eighteen (18), and we do not knowingly collect personal information from individuals under 18.

If we learn that we have collected personal information from an individual under 18 without appropriate authorization, we will take reasonable steps to delete that information as required by applicable law. If you believe that a minor has provided personal information to us, please contact us at [email protected].

2. How We Use Information

We may use personal information for the following purposes:

To provide, operate, maintain, personalize, secure, troubleshoot, and improve the Services.

To create and administer accounts, verify identity, manage subscriptions, process payments, and provide customer support.

To process and respond to inquiries, feedback, requests, and communications.

To deliver product features, workflows, automations, integrations, analytics, forms, communications, and other Services requested or configured by you.

To send transactional, administrative, account-related, security, billing, customer-service, and operational communications.

To send promotional, marketing, event, newsletter, product-update, or other communications when permitted by law and consistent with your preferences.

To administer opt-in, consent, opt-out, unsubscribe, STOP, and do-not-contact requests.

To monitor, detect, investigate, prevent, and address fraud, spam, abuse, security incidents, policy violations, unlawful activity, and technical problems.

To comply with legal obligations, enforce our agreements, respond to legal processes, and protect the rights, safety, property, and security of Zaberna, our users, and others.

To analyze trends, measure performance, understand usage, develop new features, and improve the user experience.

To create aggregated, anonymized, or de-identified information that does not reasonably identify you, which we may use and disclose for lawful business purposes.

To operate AI-enabled features, including processing prompts, Customer Content, and related data to generate requested outputs, automate workflows, provide recommendations, and improve the functionality and reliability of the Services, subject to applicable agreements and settings.

We may combine information we collect from different sources for the purposes described in this Privacy Policy.

3. Legal Bases for Processing

Where the GDPR, UK GDPR, or similar privacy laws apply, we process personal information only when we have a lawful basis to do so. Depending on the circumstances, our lawful bases may include:

Performance of a contract or taking steps at your request before entering into a contract.

Compliance with a legal obligation.

Our legitimate interests, such as operating, securing, improving, marketing, and protecting the Services, where those interests are not overridden by your rights and freedoms.

Your consent, including consent to receive certain marketing communications where required by law.

Protection of vital interests where permitted by applicable law.

Where we rely on consent, you may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal or processing based on another lawful basis.

4. AI Features and Customer Content

Certain Services offered through Zaberna AI, WriteLightning AI, DroneOps AI, VowBridge, or other Zaberna products may use artificial intelligence, machine learning, automated content generation, workflow automation, analytics, or similar technology (“AI Features”).

When you use AI Features, we may process prompts, instructions, files, text, images, documents, CRM records, workflow data, and other Customer Content you submit in order to provide the requested feature or output.

You are responsible for ensuring that:

You have the necessary rights, permissions, notices, and lawful basis to provide Customer Content to the Services.

Your use of AI Features complies with applicable law, contractual obligations, professional duties, and industry requirements.

You do not submit sensitive, confidential, regulated, or restricted information unless expressly authorized in writing by Zaberna and permitted by the applicable Service configuration and agreement.

You review AI-generated outputs before relying on, publishing, distributing, or acting upon them.

AI-generated outputs may be inaccurate, incomplete, non-unique, or unsuitable for a particular purpose. AI Features are not intended to provide legal, financial, tax, lending, insurance, medical, aviation, safety, regulatory, or other professional advice.

Unless expressly stated otherwise in a separate written agreement, we may use Customer Content only as necessary to provide, maintain, secure, support, and improve the Services. We will not use Customer Content to train broadly available or third-party AI models unless we clearly disclose that practice and obtain any consent required by applicable law or contractual commitments. Clear notice and, where appropriate, affirmative consent are particularly important if a company expands data uses for AI training beyond its existing privacy commitments.

5. Cookies and Similar Technologies

We and our service providers may use cookies, pixels, web beacons, local storage, software development kits, and similar technologies to:

Keep you signed in and remember preferences.

Maintain security and prevent fraud.

Understand how users access and use the Services.

Measure website and campaign performance.

Improve functionality, content, and user experience.

Deliver and measure advertising or marketing communications where permitted by law.

You may be able to control certain cookies through your browser settings, device settings, or our available cookie-preference tools. Disabling cookies may affect the availability or functionality of some portions of the Services.

Where required by applicable law, we will seek consent before placing or accessing non-essential cookies or similar technologies.

6. How We Share Information

We may share personal information as described below.

Service Providers

We may share information with vendors, contractors, and service providers that perform services on our behalf, including:

Cloud hosting, infrastructure, storage, security, and backup providers.

Payment processors and billing providers.

Email, telephone, SMS/MMS, messaging, communications, and carrier-related providers.

A2P registration and messaging-compliance providers, including The Campaign Registry (“TCR”), telecommunications carriers, and messaging-platform providers, where applicable.

Analytics, advertising, customer-support, form, scheduling, CRM, automation, and integration providers.

AI, machine-learning, transcription, content-processing, and related technology providers.

Professional advisers, including attorneys, accountants, auditors, insurers, and consultants.

These parties may access or process personal information only as necessary to provide services to us, comply with law, or fulfill their contractual obligations.

Business Users and Account Administrators

If you access the Services through an employer, agency, client, organization, reseller, administrator, or other business account, that organization and its authorized users may be able to access, manage, export, modify, or delete information associated with your account or use of the Services.

Third-Party Integrations

When you authorize an integration or connect a third-party account, we may share information with that third party as necessary to provide the requested integration. The third party’s own terms and privacy policy will govern its handling of information after it receives it.

Legal, Security, and Compliance Disclosures

We may disclose information if we believe in good faith that disclosure is necessary to:

Comply with applicable law, regulation, court order, subpoena, government request, or legal process.

Protect the rights, safety, property, security, or operations of Zaberna, our users, or others.

Detect, investigate, prevent, or address fraud, abuse, security incidents, policy violations, or technical issues.

Enforce our Terms of Service, contracts, policies, or legal rights.

Business Transfers

We may disclose or transfer information in connection with a merger, acquisition, financing, due diligence, reorganization, bankruptcy, sale of assets, or other corporate transaction involving all or part of Zaberna or its business.

Aggregated or De-Identified Information

We may use, disclose, sell, license, or otherwise share aggregated, anonymized, or de-identified information that does not reasonably identify you, subject to applicable law.

No Sale of Personal Information

We do not sell personal information for money. We do not knowingly sell the personal information of minors.

If applicable privacy law defines “sale,” “sharing,” or “targeted advertising” more broadly than the ordinary meaning of those terms, certain analytics, advertising, or cookie practices may be treated differently. Where required, we will provide applicable notices, choices, and consent mechanisms.

7. Communications and Messaging

We may send or facilitate communications, including:

Transactional messages, such as account notices, appointment confirmations, payment notices, security alerts, shipping notifications, or service updates.

Customer-support messages, such as responses to inquiries, onboarding communications, and service-related updates.

Promotional messages, such as offers, discounts, newsletters, product announcements, event invitations, and marketing campaigns.

Where required by applicable law, we obtain or require appropriate consent before sending certain marketing communications or enabling users to send such communications. You may opt out of marketing email by using the unsubscribe link in the message. You may opt out of SMS/MMS marketing messages by replying STOP or following the applicable opt-out instructions.

Opting out of marketing messages does not prevent us from sending non-promotional transactional, account, billing, security, legal, or service-related communications.

If you use our Services to send communications to others, you are responsible for obtaining and maintaining all required permissions, consents, notices, and opt-out mechanisms. You must comply with applicable laws and platform rules, including the TCPA, CAN-SPAM Act, CTIA guidelines, carrier rules, A2P 10DLC requirements, and applicable state, federal, and international laws.

8. Data Retention

We retain personal information for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, preserve records, and support legitimate business operations.

Retention periods vary based on the type of information, the purpose for processing, legal requirements, contractual commitments, and the nature of the Services. Our general retention approach may include:

Account and profile information: Retained while your account remains active and for a reasonable period thereafter, unless deletion is required or requested under applicable law.

Billing, transaction, and tax records: Retained for the duration of the customer relationship and generally up to seven (7) years thereafter, or longer where required by law.

Consent, opt-in, opt-out, and messaging-compliance records: Retained for at least five (5) years, or longer if required by law, carrier requirements, contractual obligations, or dispute-resolution needs.

Marketing information: Retained for up to three (3) years after your last meaningful interaction or until you withdraw consent or opt out, subject to legally required recordkeeping.

Inactive accounts: May be deleted or anonymized after two (2) years of inactivity, unless retention is required for legal, security, fraud-prevention, financial, backup, or contractual purposes.

Customer Content: Retained according to the applicable Service settings, subscription plan, agreement, account status, and legally required retention periods.

We may retain de-identified, anonymized, aggregated, backup, archival, or legally required information for longer periods. Where the GDPR or UK GDPR applies, we retain personal information for the period stated above or according to the criteria necessary to fulfill the relevant processing purpose. GDPR privacy notices should disclose the applicable retention period or the criteria used to determine it.[boisestate][gdpr-info]

9. Your Privacy Rights

Depending on your location and applicable law, you may have rights regarding your personal information. These rights may include:

The right to know or request access to personal information we hold about you.

The right to request correction of inaccurate or incomplete personal information.

The right to request deletion of personal information, subject to legal and operational exceptions.

The right to request restriction of processing.

The right to object to certain processing, including direct marketing and, where applicable, processing based on legitimate interests.

The right to data portability.

The right to withdraw consent where processing is based on consent.

The right to opt out of certain targeted advertising, sharing, sale, profiling, or automated decision-making activities where applicable.

The right to lodge a complaint with an applicable data-protection or regulatory authority.

New York Residents

New York residents may have rights and protections under the New York SHIELD Act and other applicable New York laws, including rights related to safeguarding private information and notification of certain data breaches. The SHIELD Act requires affected-consumer notice following discovery of a covered breach and also establishes notification obligations involving New York authorities in applicable circumstances.[ag.ny]

EEA and UK Residents

If you are located in the European Economic Area (“EEA”) or United Kingdom, you may have the GDPR or UK GDPR rights described above, including access, correction, erasure, restriction, objection, portability, withdrawal of consent, and the right to lodge a complaint with your local supervisory authority.

You may exercise applicable rights by contacting us at [email protected]. We may need to verify your identity before fulfilling a request. We will respond within the time required by applicable law; where GDPR or UK GDPR applies, we generally respond within one (1) month, subject to extensions permitted by law for complex or numerous requests.

10. Data Security and Breach Notification

We use reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, loss, or destruction. These measures may include access controls, authentication procedures, encryption where appropriate, secure infrastructure, logging, monitoring, backups, vendor-management practices, and incident-response procedures.

No method of transmission over the internet, electronic storage, or security control is completely secure. Therefore, we cannot guarantee absolute security.

If we discover a security incident involving personal information, we will investigate and take appropriate steps consistent with applicable law. Where legally required, we will provide notice to affected individuals, regulators, government authorities, carriers, or other parties. New York’s SHIELD Act requires notice to affected consumers after discovery of a covered breach, subject to applicable exceptions and timing requirements.[ag.ny]

11. International Transfers

Zaberna is based in the United States, and information may be collected, processed, stored, transferred to, or accessed from the United States and other countries where we, our affiliates, service providers, or integration partners operate.

Those countries may have data-protection laws that differ from the laws in your jurisdiction. Where required by applicable law, we use appropriate safeguards for international transfers, such as Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, contractual protections, or other legally approved transfer mechanisms.

If the Australian Privacy Act applies to your information, we take reasonable steps to ensure that overseas recipients handle personal information in a manner consistent with applicable Australian Privacy Principles or another permitted legal basis.

12. Third-Party Links and Services

The Services may contain links to third-party websites, applications, integrations, platforms, or services. We are not responsible for the privacy, security, content, availability, or practices of third parties.

Your use of third-party services is subject to the privacy policies, terms, and practices of those third parties. We encourage you to review their policies before providing information or connecting an account.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, data practices, technology, legal requirements, or business operations.

When we make changes, we will post the revised Privacy Policy and update the “Last Updated” date at the top of this page. If we make material changes, we may provide additional notice through the Services, by email, or through another appropriate method when required by law.

Your continued use of the Services after the effective date of an updated Privacy Policy means that you acknowledge the revised Policy, to the extent permitted by applicable law. Where a material change would require your consent, we will seek that consent before applying the change to your information. The FTC has cautioned that material expansions of consumer-data uses—such as using data for AI training in ways not covered by prior commitments—may require clear notice and affirmative consent.[loeb][hunton]

14. Contact Us

If you have questions, concerns, requests, or complaints regarding this Privacy Policy or our privacy practices, contact:

Compliance Officer
c/o Zaberna, Inc.
d/b/a Zaberna AI, WriteLightning AI, DroneOps AI, and VowBridge
1060 Broadway, #1186
Albany, New York 12204

Email: [email protected]
Phone: 1-888-526-1877

© Copyright Zaberna, Inc (Agency Account) 2026