ZAM does not sell personal information, serve advertising, or track people across apps or websites owned by other companies.
1. Scope
This Privacy Policy applies to the ZAM website at zamapp.app, the ZAM mobile application (listed as “ZAM Workforce” where applicable), and the ZAM cloud platform (together, the “Services”). It explains the categories of information processed, why they are processed, how they are protected, and the choices available to individuals.
Some organizations configure and provide ZAM to their employees, contractors, visitors, or other authorized users. Their own privacy notices and policies may also apply.
2. Our privacy role
Organization-managed accounts
When an organization uses ZAM to manage its workforce or operations, that organization generally determines why and how personal information is processed. In that context, the organization is the data controller or equivalent responsible party, and ZAM processes information on its documented instructions as a service provider or processor.
ZAM website and direct communications
ZAM is responsible for information submitted directly to us through support, product, security, or business communications and for limited technical information required to operate and protect this website.
If you are unsure which organization controls your ZAM account or operational record, contact your organization’s ZAM administrator first.
3. Information we process
The information processed depends on the features enabled by an organization and the user’s authorization.
Identity and contact information
- Name, work email address, phone number, employee or contractor identifiers, job and organization information.
- Account, membership, workspace, permission, session, and device-registration identifiers.
- Authentication information provided by an approved identity provider. ZAM does not receive or store the password used with that identity provider.
Workforce and operational information
- Departments, sections, positions, placements, sites, groups, workspaces, and organizational assignments.
- Schedules, shifts, rest days, holidays, working-hour policies, exceptions, requests, approvals, and related history.
- Shift handover summaries, pending items, acknowledgments, and corrections.
- Visitor, host, contractor, access-session, checkpoint, vehicle, badge, and building-entry information where configured and authorized.
- Announcements, attachments, notification state, operational notes, and audit records.
User content and files
Information a user chooses to enter or upload, including messages, notes, feedback, screenshots, images, documents, and attachments. Files are accepted only through enabled features and remain subject to organization and classification authorization.
Technical and security information
- Application version, operating system, device type, session status, network and request metadata, timestamps, safe error codes, and security events.
- Product interactions necessary for audit, synchronization, troubleshooting, fraud prevention, and service security.
Website information
This website does not use advertising cookies or analytics trackers. If you change the site appearance, your browser stores that preference locally on your device. Our hosting provider may process ordinary network information such as IP address, request time, requested page, and security signals to deliver and protect the site.
Local and demonstration modes
Information created in Local Mode remains on the device unless a user explicitly exports or shares it. The public demonstration workspace contains synthetic information and is isolated from user-created local organizations. Local or demonstration information does not silently become authoritative cloud data.
4. How we use information
ZAM processes information only where necessary for the following purposes:
- Provide, configure, maintain, and synchronize the Services.
- Authenticate users and enforce organization, workspace, capability, scope, and record authorization.
- Publish and display official schedules and authorized operational records.
- Support handovers, requests, approvals, announcements, attachments, notifications, and building-access workflows.
- Protect accounts, investigate misuse, preserve auditability, and maintain service integrity.
- Respond to support, privacy, security, and business inquiries.
- Comply with applicable legal obligations and enforce agreements.
Depending on the context and applicable law, processing may be based on performance of a contract, the organization’s documented instructions, legitimate interests in providing and securing the Services, legal obligations, or consent where consent is required.
5. Advertising and tracking
ZAM does not:
- Sell or rent personal information.
- Use personal information for third-party behavioral advertising.
- Use advertising identifiers.
- Track users across unrelated apps or websites.
- Share personal information with data brokers.
7. International processing
Service providers may process information in locations where they operate. ZAM and customer organizations are responsible for selecting approved service regions and applying contractual, organizational, and technical safeguards required for cross-border processing. Production hosting region and residency commitments may be defined in the applicable customer agreement.
8. Data retention
Information is retained only for as long as necessary to provide the Services, satisfy the organization’s documented retention requirements, maintain security and audit records, resolve disputes, and comply with legal obligations.
- Organization records follow the customer’s configured or contracted retention and archival policy.
- Account and membership information is retained while access is active and afterward where required for security, audit, or legal purposes.
- Support communications are retained only as long as reasonably necessary to resolve the request and maintain an appropriate support record.
- Local Mode information remains under the user’s device control until removed, the application is reset, or the application is uninstalled, subject to device backup behavior.
- Synthetic demonstration information can be reset from within the application.
Some records are archived rather than physically deleted where integrity, auditability, safety, or legal obligations require an append-only history.
9. Your privacy rights
Subject to applicable law, individuals may have rights to request access, correction, deletion, restriction, portability, or objection, and to withdraw consent where processing is based on consent.
For an organization-managed account, submit the request to your employer or organization first because it controls the relevant workforce and operational records. You may also contact ZAM at [email protected]. We may refer the request to the responsible organization and may need to verify identity before acting.
Users can request account and associated-data deletion through the instructions at zamapp.app/delete-account. Organization-controlled operational records may remain subject to the organization’s lawful retention, security, audit, and archival obligations. Deleting an application from a device does not automatically delete organization-controlled cloud records.
10. Security
ZAM uses administrative, technical, and organizational safeguards designed to protect information. These include authenticated access, server-side authorization, organization isolation, encrypted network transport, secure credential storage, private object storage, audit records, and restricted operational logging.
No system can guarantee absolute security. Users must protect their devices and accounts, use approved access methods, and promptly report suspected misuse.
11. Children
ZAM is a workplace and enterprise operations service and is not directed to children. We do not knowingly offer personal accounts to children or knowingly collect children’s personal information through this website. Organizations must not use ZAM to process information about minors unless they have a lawful, documented purpose and appropriate safeguards.
12. Changes to this policy
We may update this policy when the Services, legal requirements, or processing practices change. The effective date will be updated, and material changes may also be communicated through the application, website, or customer administrator.
13. Contact us
For privacy questions or requests:
ZAM Privacy
Email: [email protected]
Website: zamapp.app/contact
If your request concerns records controlled by your employer or another organization, please also contact that organization’s privacy contact or ZAM administrator.