ZYGHT
Privacy policy
ZYGHT is a brand operated by Datamine Chile S.A. This Privacy Policy explains how ZYGHT collects, uses, shares, retains and protects personal data through www.zyght.com, customer instances of the ZYGHT service, applications, support channels and enabled artificial intelligence functionality.
1 Scope and Our Role
For website enquiries, marketing contacts, account administration, security and ZYGHT’s own business operations, Datamine Chile S.A. generally acts as the organisation responsible for deciding why and how personal data is processed.
When a Customer uploads or makes personal data available through the Service, the Customer generally decides the purposes and means of that processing and ZYGHT processes the data on the Customer’s instructions under the applicable customer agreement and data processing agreement. In that situation, individuals should normally direct requests about their data to the relevant Customer.
This Policy supplements, and does not replace, any customer agreement or data processing agreement. If those documents impose stronger protections, the stronger protection applies to the relevant Customer Content.
2 Personal Data We Collect
Depending on how you interact with ZYGHT, we may collect:
- contact and professional details, such as name, email address, telephone number, company and job title;
- account and access data, such as username, role, authentication events and permissions;
- website and device data, such as IP address, browser, operating system, device identifiers, pages viewed and necessary cookie information;
- Customer Content, including information about workers, contractors, incidents, hazards, actions, documents, health and safety processes or other records selected by the Customer;
- AI interaction data, such as prompts, instructions, files, retrieved source material, AI Outputs, feedback and related logs;
- support and communications data, including requests, correspondence and diagnostic information; and
- commercial and administrative data, such as subscription, billing and contract contacts.
Some Customer Content may include sensitive data. Customers and Users must submit sensitive data only where it is necessary, authorised, supported by a valid legal basis and protected by appropriate access controls.
3 How We Collect Personal Data
We collect personal data directly from you, from the Customer that provides your account, from authorised integrations and data sources selected by the Customer, automatically from use of the Service, and from service providers acting on our behalf.
4 Why We Use Personal Data
We process personal data as necessary to:
- provide, configure, authenticate, support and maintain the Service;
- respond to enquiries, demonstrations and support requests;
- process authorised Customer Content and generate requested reports, analytics and AI Outputs;
- monitor performance, troubleshoot, prevent fraud, protect security and investigate incidents;
- administer contracts, billing, accounts and business relationships;
- send service communications and, where permitted, relevant marketing communications;
- comply with legal obligations and enforce applicable agreements; and
- improve the Service using aggregated, de-identified or otherwise permitted information.
5 How Artificial Intelligence Processes Data
When an AI Feature is enabled, information selected by the User or retrieved under that User’s permissions may be sent to AI models and related infrastructure to generate an AI Output. This may include prompts, relevant Customer Content, files, metadata and the resulting output. AI Providers may process this information only to provide, secure, support and maintain the relevant functionality, subject to the applicable contractual arrangements.
AI Features may analyse information, identify patterns, summarise records, classify content or generate recommendations. Their results are probabilistic and may be incorrect or incomplete. ZYGHT does not design AI Features to make final decisions about individuals. Customers must not use an AI Output as the sole or decisive basis for a high impact decision and must provide meaningful human review where required.
Unless a Customer expressly agrees otherwise in writing, ZYGHT will not use Customer Content submitted to an AI Feature to train a general-purpose AI model for use by other customers. We may retain limited AI interaction logs where necessary for security, auditability, support and legal compliance, in accordance with the applicable agreement and retention settings.
6 Legal Bases
Depending on the context and applicable law, we process personal data with consent, to perform a contract or take requested pre-contract steps, to comply with legal obligations, on the Customer’s documented instructions, or for legitimate interests such as providing and securing the Service, responding to business enquiries and improving operations where those interests are not overridden by individual rights.
Where consent is the legal basis, it may be withdrawn at any time without affecting processing already carried out lawfully. The Customer is responsible for establishing the appropriate legal basis for Customer Content it controls.
7 Sharing and Service Providers
We do not sell personal data. We may share it only as reasonably necessary with:
- companies in the Datamine and Vela Software group that support the Service or business relationship;
- contracted providers of cloud hosting, artificial intelligence, security, communications, analytics, support and other technical services;
- professional advisers, auditors, insurers and transaction counterparties subject to appropriate confidentiality obligations;
- the relevant Customer and its authorised users; and
- courts, regulators, law enforcement or other parties where disclosure is required by law or necessary to protect legal rights, safety or security.
Providers are authorised to process personal data only for the contracted services and under applicable confidentiality, security and data protection obligations. Current subprocessor information may be provided through the applicable customer agreement or on request.
8 International Transfers
ZYGHT and its providers may process personal data in countries other than the country where it was collected. Where required, we use appropriate contractual, organisational and technical safeguards for international transfers and comply with applicable transfer requirements.
9 Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, the applicable customer agreement, legal and regulatory requirements, dispute management, security and backup cycles. Retention periods vary by data type and configuration. At the end of the applicable period, data is deleted, de-identified or securely retained where the law requires it.
The Customer controls retention of Customer Content to the extent provided by the Service and the applicable agreement. Temporary copies and logs may remain for a limited period in backups, security systems or service provider infrastructure.
10 Security
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, loss, disclosure or destruction. No system is completely secure, and we cannot guarantee that a security incident will never occur. Customers must also manage user access, devices, integrations, exports and internal security controls.
11 Individual Rights
Subject to applicable law, you may have rights to request access, information, correction, deletion, objection, restriction, portability, withdrawal of consent and review of certain automated decisions, and to lodge a complaint with the competent data protection authority.
To exercise a right relating to ZYGHT’s own processing, contact contacto@zyght.com. We may need to verify your identity and may retain a record of the request. If your data was submitted by a Customer, please contact that Customer first; we will assist the Customer as required by the applicable agreement and law.
12 Automated Decisions
ZYGHT’s AI Features provide assistance and do not independently make final decisions that produce legal or similarly significant effects for individuals. If a Customer chooses to use the Service in a decision-making process, the Customer is responsible for ensuring a valid legal basis, transparency, data quality, meaningful human involvement, an opportunity to challenge the decision and any other safeguards required by law.
13 Cookies and Similar Technologies
We use cookies and similar technologies that are necessary to operate, secure and remember settings for the website and Service. If optional analytics or marketing technologies are used, we will provide any notice and choice required by law. Browser settings may allow you to block cookies, but some functions may not work correctly.
14 Children
The website and Service are intended for business use and are not directed to children as independent users. Where a Customer lawfully records information relating to a minor, the Customer is responsible for the required authority, notices, safeguards and access restrictions.
15 Changes to This Policy
We may update this Policy to reflect changes in law, technology, providers or our processing. We will publish the revised Policy with a new effective date and provide additional notice where required.
16 Contact and Governing Law
Questions, complaints and rights requests may be sent to contacto@zyght.com or through the contact details published at www.zyght.com. This Policy is governed by Chilean law, without limiting mandatory rights or jurisdiction rules that apply to an individual.