Privacy Policy

Your privacy is important to us. This privacy policy explains how Zfuro collects, uses, and protects your personal information. Zfuro is the data controller responsible for your personal data and is established in Ireland. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Irish data protection law.

1. Information We Collect and Lawful Basis

We collect and process personal data under the following lawful bases:

Contract Performance

Data necessary to provide the service you signed up for:

  • Account Information: Name, email address, and password for authentication and account management.
  • Profile Information: Job title, language preferences, timezone, and profile picture for personalizing your experience.
  • Content: Files, translations, glossaries, and other content you upload or create on our platform.
  • Payment Information: Billing details collected through our payment processor for subscription management.

Legitimate Interest

Data processed to improve and secure our services:

  • Usage Data: Information about how you use our service, including features used and workflow activity, to improve the platform.
  • Technical Data: Browser type, IP address, and device information for security monitoring and performance optimization.

Legal Obligation

Data we are required to retain by law:

  • Billing Records: Transaction history and invoices retained for tax and accounting compliance.
  • Audit Logs: Records of significant account actions retained for security and regulatory purposes.

2. How We Use Information

Your data helps us to:

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Respond to your comments, questions, and requests
  • Send technical notices, updates, security alerts, and support messages
  • Monitor and analyze trends, usage, and activities in connection with our services
  • Personalize and improve the services

3. Sub-Processors and Third-Party Services

We do not sell your data to third parties. We use the following categories of sub-processors to deliver our services:

  • Cloud Infrastructure & Storage: Hosting, file storage, and content delivery.
  • Payment Processors: Secure handling of subscription billing and transactions.
  • Error Monitoring & Analytics: Application performance monitoring and error tracking to maintain service reliability.
  • Translation APIs: Machine translation services used as part of the translation workflow.
  • OCR Processing: Optical character recognition services for extracting text from manga pages.

We may also share information with professional advisors (such as lawyers and accountants) where necessary, and with government bodies or law enforcement when required by law.

4. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or damage. These measures include:

  • Encryption of sensitive data both in transit and at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication systems
  • Regular backups of essential data

5. Data Retention

We retain personal data according to the following schedule:

  • Active accounts: Data is retained for the duration of your active use of the service.
  • Inactive accounts: Accounts inactive for more than two years may be scheduled for deletion after notification, with a 30-day grace period before permanent removal.
  • Account deletion requests: Upon request, your account enters a 30-day grace period. After the grace period, all personal data is permanently deleted.
  • Audit logs: Retained for up to 5 years for security and compliance purposes.
  • Billing records: Retained for 7 years to comply with tax and accounting regulations.
  • Session data: Sessions expire after 120 minutes of inactivity.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal data we hold about you. You can download your data from your profile settings.
  • Correction: Correct inaccurate or incomplete data. You can update your name, email, and other profile information directly in your profile settings.
  • Deletion: Request deletion of your personal data, subject to a 30-day grace period.
  • Restriction: Request that we restrict the processing of your personal data in certain circumstances.
  • Objection: Object to the processing of your personal data where we rely on legitimate interests, and object at any time to processing for direct marketing.
  • Portability: Export your data in a machine-readable format (JSON) from your profile settings.
  • Withdrawal of consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, you can use the self-service tools in your profile settings or contact us at the email address below.

You also have the right to lodge a complaint with a data protection supervisory authority. As Zfuro is established in Ireland, our lead supervisory authority is the Irish Data Protection Commission (DPC). You may contact the DPC or find further information at www.dataprotection.ie.

7. International Users and Japan (APPI)

This policy is led by the GDPR, but we honor equivalent data protection rights for users wherever they are located. If you are located in Japan, we honor rights equivalent to those set out above under Japan's Act on the Protection of Personal Information (APPI), including:

  • Disclosure: You may request disclosure of the personal information we hold about you.
  • Correction: You may request correction, addition, or deletion of your personal information if it is inaccurate.
  • Cessation of use: You may request that we cease using or delete your personal information if it was acquired improperly or is no longer necessary for the purpose of use.
  • Suspension of third-party provision: You may request that we stop providing your personal information to third parties.

The European Union and Japan recognize each other's data protection frameworks as adequate under the EU-Japan mutual adequacy decision (2019). As a result, personal data may be transferred between the European Union and Japan without the need for additional safeguards. To exercise these rights, please contact us at the email address below.

8. International Data Transfers

Zfuro is established in Ireland and processes personal data within the European Economic Area (EEA), as well as in other regions where our sub-processors operate. Where we transfer personal data outside the EEA, we rely on appropriate safeguards recognized under the GDPR, such as European Commission adequacy decisions (including the EU-Japan mutual adequacy decision) or standard contractual clauses with our sub-processors, so that your personal data continues to receive an equivalent level of protection.

9. Cookies and Tracking

We use cookies and similar tracking technologies to track activity on our service and hold certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.

10. Children's Privacy

Our service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

11. Changes to This Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the effective date. For material changes, we will notify registered users via email.

12. Contact

For any questions regarding your data or this policy, please contact us at [email protected].

Last updated: September 6, 2026