Privacy Policy
Privacy Policy
Last updated: July, 2025.
1. Purpose of This Privacy Policy.
Zilliz Inc. is committed to protecting your privacy. We have prepared this Privacy Policy to describe to you our practices regarding the Personal Data (as defined below) we collect from users of our website located at Zilliz.com and in connection with our Zilliz products and services (the "Products"). In addition, this Privacy Policy tells you about your privacy rights and how the law protects you.
This website and our Products are not intended for children and we do not knowingly collect data relating to children. It is important that you read this Privacy Policy together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing Personal Data about you so that you are fully aware of how and why we are using your data. This Privacy Policy supplements the other notices and is not intended to override them.
2. Processor and Contact Details.
Zilliz Inc. (collectively referred to as "Zilliz," "we," "us" or "our" in this Privacy Policy) is the processor of Personal Data submitted in accordance with this Privacy Policy and is responsible for that Personal Data. We have appointed a data protection officer (DPO) who is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO at privacy@zilliz.com.
3. Types of Data We Collect.
We collect Personal Data and Anonymous Data from you when you visit our site, when you send us information or communications, when you download and use our Products, and when you register for white papers, web seminars, and other events hosted by us. "Personal Data" means data that identifies, relates to, describes, can be used to contact, or could reasonably be linked directly or indirectly to you, including, for example, identifiers such as your real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name, or other similar identifiers; commercial information, including records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies; Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding your interaction with an Internet website, application, or advertisement; and any other non-public information about you that is associated with or linked to any of the foregoing data. "Anonymous Data" means data that is not associated with or linked to your Personal Data; Anonymous Data does not permit the identification of individual persons. We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data).
3.1 The scenarios of data collection and purpose of data processing.
3.1.1 Account registration
When visiting our website, we may collect, store, use, disclose, transfer or delete (hereinafter “process”) process the following categories of personal data:
- Your contact information, such as name, email address, country;
- Organizational information, including company name;
- information on your operating system, sites and services accessed during your visit, the date and time, the IP address of each visitor request.
We process your personal data for the following purposes:
- To provide the Online Vector Database services and functions to the user;
- To verify your identity;
- To improve our product quality, service level and user experience.
3.1.2 User support
During the use of Zilliz Cloud services, we may process the following categories of personal data:
- Your contact information, such as name, email address, country;
- Organizational information, including company name;
- Technical support information, including description of issues, log file contents, screenshot of issues;
We process your personal data for the following purposes:
- To verify your identity;
- To provide remote support for user issue’s troubleshooting;
- To improve our product quality, service level and user experience.
3.1.3 Billing and payment
Following categories of personal data might be processed for user Cloud service billing and payment:
- Credit card information, including Card number, Expiration date, CVC;
- Billing profile, such as full name of user, company name, email, address, country, state, city, postal code;
We process your personal data for the following purposes:
- Calculate the service cost;
- Generate the bill and charge to the designated bank account/card.
3.1.4 Direct marketing and customer relationship management
Types of direct marketing and customer relationship management include:
- customer in-person/online event;
- newsletter subscribe;
- trial user registration;
- new customer acquisition program;
- marketing generate prospect qualification;
Customer info we collected:
- Company name/website/phone number/Contact name/email/phone number
Purpose of data process:
- Marketing will access customer data for profile updates, marketing qualified prospect qualification as well as sales leads validation as needed.
3.1.5 Cookies
We process your personal data for the following purposes:
- Authentication: Cookies help us authenticate users and prevent unauthorized access to accounts.
- Preferences: We use cookies to remember your preferences and settings, such as language preferences and display settings, to provide a more personalized experience.
- Analytics: Cookies enable us to collect data about how you interact with our website and services, including which pages you visit, how long you spend on each page, and any error messages you encounter. This information helps us analyze and improve our website and services.
- Advertising: We may use cookies to deliver targeted advertisements based on your browsing behavior and interests. This allows us to present you with relevant ads that may be of interest to you.
For more information about how we use cookies and how you can manage your cookie preferences, please refer to our Cookie Policy.
3.2 Legal basis for the data processing under each scenario.
3.2.1 Account registration
Purpose | Legal basis |
---|---|
To verify your identity | Contract Performance |
To provide the Online Vector Database services and functions to the user | Contract Performance |
To improve our product quality, service level and user experience | Legitimate Interest |
3.2.2 User support
Purpose | Legal basis |
---|---|
To verify your identity | Contract Performance |
To provide remote support for user issue’s troubleshooting | Contract Performance |
To improve our product quality, service level and user experience | Legitimate Interest |
3.2.3 Billing and payment
Purpose | Legal basis |
---|---|
Calculate the service cost | Contract Performance |
Generate the bill and charge to the designated bank account/card | Contract Performance |
3.2.4 Direct marketing and customer relationship management
Purpose | Legal basis |
---|---|
For profile updates, marketing qualified prospect qualification as well as sales leads validation | Legitimate Interest |
3.2.5 Cookies
Purpose | Legal basis |
---|---|
Authentication | Contract Performance |
Perferences | Contract Performance |
Analytics | Legitimate Interest |
Advertising | Legitimate Interest |
3.3 Recipients of your personal data.
We only provide your personal data to third parties described below:
Auth0
- The personal data type to be provided to Auth0:
- Your email address, your password;
- The purpose of such data sharing:
- Authentication when you log in.
Snowflake & Tableau
- The personal data type to be provided to Snowflake:
- Your contact information, such as name, email address, country,company,billing address;
- The purpose of such data sharing:
- User behavior analysis, revenue data monitoring
Strip
- The personal data type to be provided to Strip:
- Your payment information, such as email address,billing address, invoice,TAX ID;
- The purpose of such data sharing:
- Generate bills and deduct fees
Zendesk
- The personal data type to be provided to Zendesk:
- Your contact information, such as name, email address;
- The purpose of such data sharing:
- User support services to solve problems during the use of products
Hubspot
- The personal data type to be provided to Hubspot:
- Company name/website/phone number/Contact name/email/phone numbe.
- The purpose of such data sharing:
- Marketing will access customer data for profile updates, marketing qualified prospect qualification as well as sales leads validation as needed.
3.4 Personal Data That We Collect From You About Others.
If you decide to create an account for and invite a third party to join our network, we will collect your and the third party’s names and e-mail addresses (identifiers) in order to send an e-mail and follow up with the third party. You or the third party may contact us at privacy@zilliz.com to request the removal of this information from our database.
4 Data Storage.
Your personal data be stored and protected by our state-of-art technologies The following technical measures be implemented to prevent unauthorized access and misuses:
- Only authorized and approved person allowed access your personal data.
- Your personal data will be stored and transferred in encrypted form.
- Perform encryption and pseudonymization (a technique for replacing personally identifiable information with other similar data) of personal data
- Minimize network access policies to ensure that only necessary system services can access data
5 Retention Periods of Your Personal Data.
Unless indicated otherwise at the time of the collection of your personal data, we erase your personal data if
- the retention of that personal data is no longer necessary for the purposes for which they were collected or otherwise processed, or
- to comply with legal obligations (such as retention obligations under tax or commercial laws).
6 Your Rights.
As the party affected by the processing of your data, you may claim certain rights under the EU GDPR, UK GDPR, Swiss FADP and other relevant data protection regulations. Under the EU GDPR, UK GDPR and Swiss FADP, you are entitled to claim the following specific rights as the data subject (even if your personal data be transferred to US):
6.1 Right of access by the data subject
You have the right to request information on the data we hold about you from us at any time. This information includes, but is not limited to, the categories of data we process, the purposes for which it is processed, the source of the data if not collected directly from you, and, if applicable, the recipients with whom we have shared your data. You can obtain a copy of your data from us free of charge. If you require additional copies, we reserve the right to charge you for these copies.
6.2 Right to rectification
You have the right to request that we rectify inaccurate data relating to you. We will take appropriate steps to keep the data we store and process on an ongoing basis accurate, complete and current, based on the most up-to-date information available.
6.3 Right to erasure
You have the right to request that we erase your data, as long as the legal requirements for this are satisfied. This may be the case if
- The data is no longer required for the purposes for which it was collected or otherwise processed;
- You withdraw the consent on which data processing is based, and there is no other legal basis for processing;
- You lodge an objection to the processing of your data and there are no legitimate reasons for processing, or you object to data processing for direct marketing purposes;
- The data was processed unlawfully,
and provided that processing is not required
- To ensure compliance with a legal obligation that requires us to process your data;
- Especially with regard to statutory retention periods;
- To establish, exercise or defend legal claims.
6.4 Right to restriction of processing
You have the right to request that we restrict processing of your data if
- You dispute the accuracy of the data – in which case processing may be restricted during the time it takes to verify the accuracy of the data;
- Processing is unlawful, and you reject erasure of your data, requesting that its usage be restricted instead;
- We no longer need your data, but you need it to establish, exercise or defend your rights;
- You have lodged an objection to its processing, as long as it is not certain that our legitimate reasons outweigh yours.
You also have the right to request that we restrict disclosure your personal data to third party.
6.5 Right to data portability
In case technically possible, you have rights to request us transfer your personal data to another responsible party. According to the GDPR/UK GDPR and Swiss FADP, you may only raise this request in case data processing is based on your consent or is necessary for the performance of a contract. Rather than receiving a copy of your data, you may also ask us to submit the data directly to another responsible party specified by you.
6.6 Right to object
You have the right to object to the processing of your data at any time for reasons that arise from your particular situation, as long as data processing is based on your consent, on our legitimate interests or those of a third party. In this case, we will cease to process your data. This does not apply if we can show that there are compelling legitimate grounds for processing that outweigh your interests, or if we need your data for the establishment, exercise or defense of legal claims.
6.7 Restrictions of response of your request
We make a reasonable effort to respond to your requests within 30 (this 30 days limit to be confirmed by zilliz internal) days. This period may be extended for reasons relating to the specific right or complexity of your request.
Meanwhile, we may be unable to provide you with information about all your data, due to legal requirements. If we are unable to fulfil your request for information in such a case, we will notify you of the reasons.
6.8 Withdraw consent
You have the right to withdraw your consent at any time for reasons that arise from your particular situation, as long as data processing is based on your consent. In this case, we will cease to process your data and erase your data. But the data processing is still valid during your consent period.
6.9 Automated decision making
There’s no automated decision making mechanism be performed for your personal data processing in Zilliz.
7 Usage by Children.
Subject to technology restriction, it is difficult for us to actively identify the personal information of children in the account registration process. If you are the guardian of a child and you find that we have obtained the personal information of a minor without his or her authorization, please contact us through the contact information disclosed in this policy, and we will verify the information in a timely manner upon receipt of the notification, and delete or anonymize the information in a timely manner after verifying that it is true.
8 International Data Transfer Outside EEA.
8.1 Compliance with the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks
Zilliz complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.
Zilliz has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.
Zilliz has also certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. DPF Principles with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.
If there is any conflict between the terms in this privacy policy and the DPF Principles, the DPF Principles shall govern.
To learn more about the Data Privacy Framework program, and to view our certification, please visit the Data Privacy Framework website.
8.2 Transferred personal data list
8.2.1 Account registration
Type of personal data | Purpose | Legal basis | Recepient |
---|---|---|---|
Contact information, organizational information | To verify your identity | Contract Performance | Zilliz Inc. |
Information on your operating system, sites and services accessed during your visit, the date and time, the IP address of each visitor request | To provide the Online Vector Database services and functions to the user | Contract Performance | Zilliz Inc. |
Contact information, organizational information | To improve our product quality, service level and user experience | Legitimate Interest | Zilliz Inc. |
8.2.2 User support
Type of personal data | Purpose | Legal basis | Recepient |
---|---|---|---|
Contact information, organizational information | To verify your identity | Contract Performance | Zilliz Inc. |
Technical support information, including description of issues, log file contents, screenshot of issues | To provide remote support for user issue’s troubleshooting | Contract Performance | Zilliz Inc. |
Contact information, organizational information | To improve our product quality, service level and user experience | Legitimate Interest | Zilliz Inc. |
8.2.3 Billing and payment
Type of personal data | Purpose | Legal basis | Recepient |
---|---|---|---|
Billing profile | Calculate the service cost | Contract Performance | Zilliz Inc. |
Credit card information | Generate the bill and charge to the designated bank account/card. | Contract Performance | Zilliz Inc. |
8.2.4 Direct marketing and customer relationship management
Type of personal data | Purpose | Legal basis | Recepient |
---|---|---|---|
Customer in-person/online event, newsletter subscribe, trial user registration, new customer acquisition program, marketing generate prospect qualification | For profile updates, marketing qualified prospect qualification as well as sales leads validation | Legitimate Interest | Zilliz Inc. |
8.3 Jurisdiction authority
The Federal Trade Commission has jurisdiction over Zilliz’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).
8.4 Onward transfers
We have certified that we adhere to the Principles of Notice, Choice, Accountability for Onward Transfers, Security, Data Integrity and Purpose Limitation, Access, and Recourse Enforcement and Liability, in accordance with the EU-U.S DPF, the UK Extension to the EU-U.S DPF and Swiss-U.S DPF.
We will only process personal information in ways that are compatible with the purposes outlined above, in this Privacy Policy and uphold the rights of EU, UK and Swiss individuals.
We may provide your personal information to third parties who perform services on our behalf. If we transfer personal information received under the EU-US DPF, the UK Extension to the EU-U.S DPF and the Swiss-U.S DPF to a third-party agent or service provider and they process your personal information in a manner inconsistent with the EU-US DPF, the UK Extension to the EU-U.S DPF and the Swiss-U.S DPF, we will remain liable if they fail to meet those obligations and we are responsible for the event giving rise to damages, unless we can prove we are not responsible for the event giving rise to the damage. Zilliz complies with the EU-US DPF Principles, the UK Extension and the Swiss-U.S DPF Principles for all onward transfers of personal data from the EU, UK and Switzerland, including the onward transfer liability provisions.
Under certain circumstances, we may be required to disclose your personal information in response to valid requests by public authorities, including to meet national security or law enforcement requirements.
9 Inquiry and Complaint Handling.
9.1 Internal Complaint Resolution
If you believe your personal data has been processed in violation of the DPF principles, or for complaints regarding data privacy, you should first contact Zilliz's internal complaint mechanism at privacy@zilliz.com. We will investigate and attempt to resolve your concern promptly.
9.2 None EEA/UK/Swiss data subjects complaint handling
In case of data privacy related concerns and requests, we encourage you to contact our Data Privacy Office at privacy@zilliz.com. Besides contacting the Data Privacy Office, you are also have the right to approach the data protection authority with your request or complaint.
9.3 EEA/UK/Swiss data subjects inquiry and complaint handling
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Zilliz commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK and Swiss data subjects with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF should first contact Zilliz at privacy@zilliz.com.
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Zilliz commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs), and the UK Information Commissioner’s Office (ICO) and the Gibraltar Regulatory Authority (GRA), and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
10 Binding Arbitration.
If your complaint regarding our compliance with the Data Privacy Framework (DPF) Principles is not resolved through the other DPF mechanisms, you may have the option to invoke binding arbitration under certain conditions. This arbitration is a final mechanism available to you for resolving complaints that remain unresolved.
For more information on the conditions and requirements that must be met before initiating arbitration, please see Annex I of the DPF Principles: DPF ANNEX I–Introduction to Binding Arbitration.
11 Changes to This Privacy Policy.
This Privacy Policy is subject to occasional revision, and if we make any substantial changes in the way we use your Personal Data, we will notify you by sending you an e-mail to the last e-mail address you provided to us or by prominently posting notice of the changes on our website. Any material changes to this Privacy Policy will be effective upon the earlier of thirty (30) calendar days following our dispatch of an e-mail notice to you or thirty (30) calendar days following our posting of notice of the changes on our site. These changes will be effective immediately for new users of our website and Products. Please note that at all times you are responsible for updating your Personal Data to provide us with your most current e-mail address. In the event that the last e-mail address that you have provided us is not valid, or for any reason is not capable of delivering to you the notice described above, our dispatch of the e-mail containing such notice will nonetheless constitute effective notice of the changes described in the notice. In any event, changes to this Privacy Policy may affect our use of Personal Data that you provided us prior to our notification to you of the changes. If you do not wish to permit changes in our use of your Personal Data, you must notify us prior to the effective date of the changes that you wish to deactivate your account with us. Continued use of our website or products, following notice of such changes shall indicate your acknowledgement of such changes and agreement to be bound by the terms and conditions of such changes.
12 Accessibility.
We are committed to making our products and services accessible to everyone. If you need help with your accessibility-related requests and other servicing needs, please contact us at privacy@zilliz.com.
Our company contact details
Name: Zilliz Inc.
Address:201 REDWOOD SHORES PKWY,Ste 330,REDWOOD CITY, CA 94065-1134
E-mail: privacy@zilliz.com
Our DPO contact details
Name: Wendy Han
Address:201 REDWOOD SHORES PKWY,Ste 330,REDWOOD CITY, CA 94065-1134
- mail: wendy.han@zilliz.com