Top bar icon

Palantir and Zeta Global announce strategic partnership.Read News

Privacy Policy Recently Acquired Zeta Companies 

April 8, 2026

Zeta Global acquired the Recently Acquired Companies in November, 2025.  This Recently Acquired Companies Privacy Policy applies only to these companies, which Zeta continues to operate as independent business units.  To learn how Zeta collects and uses personal data in other parts of its business, please review Zeta’s Privacy Policy.  This Policy applies only to the following Recently Acquired Companies, and describes how they process personal data in compliance with the European Union’s General Data Protection Regulation (GDPR) and other applicable privacy laws: 

  1. Cheetah Digital by Zeta  
  2. Selligent by Zeta  
  3. Sailthru by Zeta  
  4. Live Clicker by Zeta
  5.   Zeta Loyalty / Grow  

 

All of these Recently Acquired Companies act solely as service providers, also known as data processors, to their B2B clients.  They provide a range of software and services that include tools for managing customer databases, sending emails and SMS messages, running brand loyalty programs, and related functionality.  The only personal data that these companies collect and use in their own right is data relating to applicants, employees, and people we are in contact with at client, vendor, and partner companies.  Or you, if you contact us.  We also analyze performance of our service systems in order to maintain and improve our core services, which involves looking across all of the personal data in our systems, but the Recently Acquired Companies are not data brokers and do not use Client Personal Data other than as directed by our Clients apart from this ongoing systems analysis.   

This Policy is divided into three parts: 

  1. Zeta’s Website Privacy Policy (since we are on www.zetaglobal.com)
  2. Our Services Policy (where we describe how we interact with the client-owned data that runs through the Recently Acquired Companies’ systems)
  3. Our Corporate Usage Policy (where we describe how and why we collect, use, and share data for our own purposes)
  • Applicant means a person who is applying for a role as an Employee with us but has not yet become an Employee.  Includes former applicants. 

  • Client means a company—usually a provider of goods or services—that uses our services and that has loaded personal data onto our systems. 

  • Client Personal Data means Personal Data that is owned or controlled by a Client and that the Recently Acquired Companies process as a data processor. 

  • Employee means a person who works for the Recently Acquired Companies, either as an employee or contractor. 

  • Personal Data means any data that is directly or indirectly linked to an identifiable individual.  It includes contact details like name, email address, phone number, street address, IP address, cookie IDs, or similar.  It also includes any other data that relates to the individual and that is linked to these identifiers.  

  • Processing means any action taken with respect to personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, use, disclosure, erasure or destruction.  

Recently Acquired Companies means: 

Zeta Global means Zeta Global Corporation, the parent company of the Recently Acquired Entities.  Zeta has other divisions and subsidiaries that provide different services and have different privacy practices than those described here. Read more in the Zeta Global Privacy Policy.

We Process Client Personal Data (Almost) Exclusively as a Data Processor.  The Recently Acquired Companies are providers of e-mail services and Software-as-a-Service (SaaS) marketing technologies (our “Services”) that we provide on a business-to-business basis to our clients.  Our Recently Acquired Companies act solely as service providers or data processors with regard to the personal data owned by our clients that are stored on or run through our systems.  This data is generally limited to contact details (name, email address, phone number, IP address) that enables us to send messages, but also includes the content of emails or SMS messages that companies are sending you through our systems, or data stored by loyalty programs that you participate in who use our services.  This is an illustrative list and not exhaustive.  The key point is that when we provide our services to other companies, we do not use their data—your data—for our own purposes.  We just provide the service we have been contracted to provide, and then we return or delete the associated personal data. 


Under the GDPR and other privacy laws that we are subject to outside of the European Economic Area (EEA), our role as a data processor means that compliance, for us, is focused on (1) providing adequate and reasonable information security for your data to protect it from external threats, and (2) to use it only as directed by our clients, and for no other purposes.  The only exception to this last rule is that we analyze performance of our systems in order to keep them running, identify and correct problems, and improve performance over time.  Although our analysis is done at a system level, most of the data being analyzed is at an individual level and constitutes personal data.  
     

Your Privacy Rights and How to Exercise Them.  Because we handle data on behalf of other companies with whom you have relationships, if you would like to exercise your legal privacy rights with respect to data stored on our systems you should contact the companies whose communications you have received through our service. 

Where data is processed. Processing may occur in any jurisdiction in which Zeta is established, including the United States, United Kingdom, European Union, and Australia. Our sub-processors may Process Personal Data in additional jurisdictions. The actual locations of Processing depend on the Client’s implementation of the Services. If you’re a Client, please consult your Agreement. For Client Data Subjects, all aforementioned jurisdictions apply to a Zeta entity’s Processing of Service Logs. 

Data Retention.  We will retain information we Process on behalf of our Clients as a Data Processor for as long as needed to provide Services to our Clients (unless deletion is requested at an earlier time by the Client) and as necessary to comply with our legal obligations, resolve disputes and enforce our agreements.  

System Analysis and Service Logs.  The services described in this policy are provided within processing environments controlled by each Recently Acquired Company. These environments may be cloud-based or physical infrastructure, single or multi-tenant, and in almost every circumstance, require additional Processing by sub-contractors or sub-processors engaged by the Recently Acquired Companies or by Zeta as a data processor. The proper working of these various systems necessitates the creation of Service Logs, and in limited circumstances, the Recently Acquired Companies may process Personal Data in Service Logs as a data controller.  

What are Service Logs? Service Logs are factual records of system events, created (for instance):   

  • When you receive an electronic message and/or interact with a company via our Services; or  
  • When one of our employees or contractors modifies or accesses Client Personal Data.  

Why are Service Logs created?  

Service Logs are created for a variety of reasons – e.g., to monitor the proper function of the system(s) and diagnostics, to create an auditable record of system events to assist with system security and reliability, and as best-practice for software development – but the overall idea is that without them, we would have no way to know what’s going on within the systems. Verifying that the Services are operating normally and in a secure manner, planning for current and future resource allocation, and ensuring compliance with our legal obligations and industry best practices are all functions which rely heavily on Service Logs.  

Personal Data is collected in Service Logs automatically whenever Personal Data is Processed by our services systems. Examples of this automatic collection include:  

  • Security and threat detection systems. As part of our technical and organisational measures, we employ hardware and software designed to detect and/or prevent unauthorized access to the Services. These logs contain Personal Data in the form of unique system IDs, IP addresses, browser and operating system information, and other data transmitted automatically as part of the connection to our servers. 
     
  • Transactional server logs. Within the Services, logs are kept of user logins, user actions within an account, API calls, and other system events. These logs contain unique system IDs for Users and Client Data Subjects, IP address, browser and operating system information, and other data transmitted automatically as part of the connection to our servers.  

  • Electronic message transmission. When our services are used to deliver electronic messages, logs are created in a standardized format within the message delivery server. These logs contain email address, IP address, information about your ISP or phone carrier, as well as metadata related to the message being sent.  

 

Personal Data is recorded in Service Logs to serve purposes vital to the effective and secure operation of the Services. Our purposes for Processing this Personal Data include:  

  • To Improve Our Services. To create new Services, features, content or make recommendations; improve our Services for you and all Users; and to fix bugs and troubleshoot product functionality.  

  • For Business Analytics. To infer your geographic location based on your IP address (where, e.g., a Client wants to target messages only to a specific geographic area); to track behavior at the aggregate/anonymous level to identify and understand trends in the various interactions with the Services; and to conduct internal business analysis based on meta-data about usage, feature adoption and forecasting.  

  • To Prevent Abuse/Illegal Activities. To screen for and prevent undesirable or abusive activity. For example, we have automated systems that screen content for phishing activities, spam, and fraud.  

  • For Legal Records. To identify who you are, including both identification and authentication purposes; to carry out our obligations and enforce our rights arising from any contracts entered into between you and us (including for billing and collection); and to respond to legal requests or prevent fraud. If we receive a subpoena or other legal request, we may need to inspect the data we hold to determine how to respond.  

Disclosures.  In the following limited situations, we may disclose Client Personal Data to someone other than the Client:  

  • to our contractors, service providers and other third parties who provide data processing services to us and with whom the sharing of your Personal Data is necessary to undertake the work e.g. to host data, messaging transport services, analytics services, to provide client support.  

  • as required by law, such as to comply with any court order, subpoena or other law or legal process, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a governmental or regulatory request.  

  • to our Employees for client support, marketing, technical operations, and account management purposes.  

  • to a buyer or other successor in the event of a merger, sale or transfer of some or all of the Recently Acquired Companies’ assets.  

Lawful Basis.  If you are a resident in the EEA, Switzerland or UK, then our legal basis for collecting and using your Personal Data will generally derive from the legal basis our Client has for processing it, since we are acting only as their agent.  However, we could also process data subject to a legal requirement (e.g. tax or employment laws) or to protect the health or safety of any person. 

If you have further questions concerning the legal basis on which we collect and use Personal Data, please contact us at privacy@zetaglobal.com.  

 

Data Privacy Officer - The Recently Acquired Companies have appointed HewardMills as Data Protection Officer for these products. You may contact them regarding data protection concerns at:  

  

HewardMills  

77 Farringdon Road  

London EC1M 3JU  

Email: privacy@zetaglobal.com 

 

Security Controls - The Recently Acquired Companies maintain appropriate administrative, technical, and physical safeguards designed to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These safeguards include access controls, monitoring of systems, and policies and procedures governing the handling of Personal Data. Security measures are implemented taking into account the nature of the Services, the sensitivity of the Personal Data Processed, and applicable legal requirements.  

This Policy applies to personal data that we collect, use, and disclose for our own purposes.  Also known as data for which we act as a “data controller.”  The Recently Acquired Companies are not data brokers and do not collect and compile consumer data for their own purposes, and so the categories described below are relatively limited. 

 

A. Whose Personal Data Do We Collect and Use For Our Own Purposes? 

 

a. Applicants.  We collect personal data from and about people who apply for jobs with us. 

 

b. Employees / Former Employees.  We collect personal data from and about our employees and contractors and preserve these records following termination of our employment relationship as required by applicable laws.  

 

c. Business Contacts.   We collect personal data from and about business representatives at other companies who we do business with.   

 

d. Other.  If you contact us, that will constitute our collection of your personal data.  We might also process other miscellaneous personal data, e.g. in connection with litigation, investigations, or otherwise. 

 

B. What Personal Data Do We Collect? 

 

a. Types of Personal Data We Collect and Use 

 

i. Data that You Provide 

 

ii. Data Collected by Pixels and Cookies on our Website - Information about data collected through cookies, pixels, and similar technologies on our website is described in the Zeta Global Website Privacy Policy, available at https://zetaglobal.com/privacy-policy/ 

 

iii. Data collected during the course of your application and employment - This may include information provided during the recruitment and employment process, such as background check information (where permitted by law), emergency contact details, and information related to enrollment in employee benefit programs. 

 

iv. Data collected during the course of a B2B business relationship -  

In connection with our business relationships, we collect and process information about individuals who represent our corporate clients, prospective clients, and other business partners. This includes contact information such as name, business email address, phone number, job title, and employer name, as well as account credentials and communication preferences necessary to provide access to and support for our services. We may also collect information exchanged during the course of our business relationship, including correspondence, meeting notes, support tickets, and records of service usage. Additionally, we collect billing and transactional information related to the purchase and administration of our services, such as invoicing details and payment history. This information is used to manage our client relationships, deliver and improve our services, fulfill our contractual obligations, and communicate about updates, renewals, or new offerings relevant to their account. We retain this information only for as long as necessary to support the business relationship and comply with our legal obligations. 

 

b. Children’s Personal Data - We do not knowingly process personal data of people under the age of 18, subject to extremely limited exceptions (e.g., enrollment of an Employee’s children in a company-sponsored health benefit plan) 

 

c. Sensitive Personal Data.  We may process various categories of sensitive personal data of our Applicants and Employees.  For instance, people may disclose health or disability information as part of the hiring process or during employment, people may voluntarily join employee resource groups with ethnic, gender, or sexual orientation themes, or people may be recorded on video exhibiting racial characteristics or clothing that indicates a religious affiliation.  This sensitive personal data is processed on the basis of consent, performance of an employment contract, and/or legitimate interest (e.g. in the case of security camera footage). 

 

C. Legal Basis for Data Processing 

 

a. Applicants - We process Applicants’ Personal Data to manage recruitment and hiring processes, to evaluate qualifications, conduct pre-employment screenings where permitted by law, and to comply with applicable legal obligations. 

 

b. Employees / former employees - We process Employees’ and former Employees’ Personal Data based on consent, to comply with applicable legal obligations, for the performance of an employment contract, to protect health and safety, and where necessary for our legitimate interests. 

 

c. Business Contacts  - We process Business Contacts’ Personal Data based on our legitimate interests and, where required, consent. 

 

d. Other - We process other Personal Data based on our legitimate interests and, where required, consent. 

 

D. What Do We Do with the Personal Data We Collect? 

 

a. Applicants.  We use applicants’ data to process applications for employment, conduct pre-employment screenings, and comply with applicable legal requirements. 

 

b. Employees / former employees - We use Employees’ and former Employees’ Personal Data to manage the employment relationship, administer payroll and benefits, support IT and security operations, comply with legal and regulatory obligations, and for other legitimate human resources and business operations. 

 

c. Business Contacts.  We use Business Contacts’ Personal Data to maintain commercial relationships with Clients, vendors, and partners. This may include routine communications, sales efforts, troubleshooting, audits, and other business communications..  This information is used to manage our client relationships, deliver and improve our services, fulfill our contractual obligations, and communicate about updates, renewals, or new offerings relevant to their account. 

 

d. Other.  We may use Personal Data in other limited circumstances, such as responding to inquiries or using data in investigations, complaints, litigation, or other situations that arise in the ordinary course of business. 

 

E. Your Privacy Rights and How to Exercise Them - Individuals who have a current or past relationship with us may exercise their applicable privacy rights by contacting us at privacy@zetaglobal.com. Where we act as a data processor, requests should be directed to the relevant Client. 

 

F. Where Personal Data is Processed - Personal Data may be processed in jurisdictions where the Recently Acquired Companies or their service providers operate, including the United States, United Kingdom, European Union, India, and other locations permitted by law. 

 

G. Who We May Share Your Personal Data With and Why 

 

a. Applicants - We may share Applicants’ Personal Data with third parties as necessary to conduct background checks, employment verification, reference checks, and education history checks, where permitted by law.  

 

b. Employees / former employees - We may share Employees’ or former Employees’ Personal Data with service providers who support payroll, benefits administration, IT services, legal compliance, and human resources functions, as required by law or in connection with our legitimate business operations. 

 

c. Business Contacts - We may share Business Contacts’ Personal Data with service providers, partners, and professional advisors as necessary to manage commercial relationships, provide services, conduct audits, and comply with legal obligations. 

 

d. Other - We may share Personal Data in other limited circumstances where required by law, in connection with legal claims or investigations, or as otherwise permitted by applicable data protection laws. 

 

H. How Long We Retain Personal Data - We retain Personal Data where we have an ongoing legitimate business need to do so (for example, to process your employment application, maintain an employment relationship with you, maintain a business relationship with you, or to comply with applicable legal, tax or accounting requirements). When we have no ongoing legitimate business need to Process your Personal Data, we will delete your Personal Data. If this is not possible (for example, because your Personal Data has been stored in backup archives), then we will securely store your Personal Data and isolate it from any further Processing until deletion is possible.  If you request deletion of your personal data then we will delete it unless we are prevented from doing so by a legal obligation (e.g. maintenance of employment or tax records) 

 

I. Security of Personal Data – We maintain appropriate administrative, technical, and physical safeguards designed to protect Personal Data collected for corporate purposes, taking into account the nature of the data and applicable legal requirements. 

 

J. Our Data Privacy Officer and How to Contact Us - Zeta Global has appointed HewardMills as Data Protection Officer for these products. You may contact them regarding data protection concerns at:  

 

HewardMills  

77 Farringdon Road  

London EC1M 3JU  

Email: privacy@zetaglobal.com