Privacy Policy

Welcome to Zea. We hope that you will enjoy and appreciate using our “Services”, which includes (i) visiting our website at, including all subdomains, present and future (the “Website”); and (ii) using the “Platform” available on the Website to access Zea’s SaaS solution (the “Software”).

Zea takes your privacy and the security of personal data very seriously. We are providing this Privacy Policy (the “Policy”) to tell you about who we are, what personal data we collect from you and about you, and what we do with your personal data, all while you use the Services or otherwise interact with us. The Policy also explains your rights under the law, and how you can contact us and the necessary authorities to enforce those rights. We ask that you please read it carefully.



We take privacy seriously

If you have any questions about our policy or if you would like us to delete your information according to our policy

Get in Touch

Key Elements of this Policy

Here are the key elements of this Policy so that you can know the important parts right away to make an informed decision about your consent for our collection, use and disclosure of your personal data. By submitting any personal data to us via any means, you consent to such collection, use and disclosure. You can find the details in the rest of the Policy.

  • Personal data we collect from you but only with your consent
  • Contact Information

  • Account Information

  • Billing Information

  • Chat Information

  • What we do with it
  • Communicate with you

  • Manage your account and communicate with you about your account and your access to the Software

  • Process your payments of the SaaS Fees

  • Communicate with you and respond to your inquiry

  • Third parties we share it with
  • Companies that provide email services, such as HubSpot and Mailgun

  • Companies that provide the infrastructure for the Website and the Platform, such as HubSpot and Firebase

  • Payment processors, specifically Stripe

  • Companies that provide chat services, such as HubSpot, HelpScout, and Slack

Some Terms

Before we get started with the details, here are a few terms we think you should know as you read this Policy.

“Data Protection Laws” refers to the laws that are designed to protect your personal data and privacy in the place where you live. Zea is committed to adhering to all applicable Data Protection laws.

The Data Protection Laws include: (1) the “GDPR”, the European Data Protection Law which stands for “General Data Protection Regulation”, with the official name Regulation (EU) 2016/679 of the European Parliament and of the Council; (2) “PIPEDA” (Personal Information Protection and Electronic Documents Act), which is the Canadian Data Protection Law that applies to our activities in Canada; (3) Quebec’s an Act Respecting the Protection of Personal Information in the Private Sector (the “Quebec Privacy Act”) that applies to our activities in Quebec; and (4) the “UK GDPR” which applies to our activities in the United Kingdom; please note that when this Policy refers only to the “GDPR”, this includes the UK GDPR, as applicable.

“Personal data” – this is information we collect from you or about you and which is defined in the GDPR as “any information relating to an identified or identifiable natural person.” It can be as simple as your name or your email, or something more complicated like an online identifier (usually a string of letters and / or numbers) that gets attached to you. Under PIPEDA and the Quebec Privacy Act, the equivalent concept is “personal information”, which is roughly the same. Any mention of “personal data” in this Policy shall also mean personal information.

Other terms and definitions used in this Policy may be found in our Terms of Use, and will have the same meaning in this Policy as they do there.

About Us and Contacting Us

Zea Inc. (“Zea”) is a Canadian corporation located in Montréal, Canada at the address listed below. Where this Policy refers to “Zea”, it may refer to Zea Inc. and / or its affiliates, and their respective shareholders, officers, directors, employees, agents, partners, principals, representatives, successors and assigns (collectively “Representatives”), depending on the context. Any reference to “we”, “our”, or “us” in this Policy shall also refer to Zea. In this Policy, a Website visitor or User or any other individual for whom we hold personal data may be referred to as “you”.

Under the GDPR, Zea is a “data controller”. That means we collect personal data directly from you and determine the purpose and means of “processing” that data. “Processing” is a broad term that means collection, use, storage, transfer or any other action related to your personal data; it is used in this Policy in that way. Under PIPEDA, Zea is an “organization” and, under the Quebec Privacy Act, Zea is an “enterprise”.

If you want to ask us anything about what’s in this Policy, or anything else privacy- or data-related, or exercise any of your available privacy rights, you can contact our Privacy Officer tasked with overseeing privacy matters for Zea at the following address:

Zea Privacy Officer at

Zea Privacy Officer
4329 Saint-André Street
Montreal, Quebec
H2J 2Z3

Your Rights

You have the following rights regarding your personal data held by Zea, and other privacy rights. Please note that not necessarily all of these rights may be available to you; this depends on the Data Protection Laws where you are located that apply to you. Please note that exercising certain of these rights may affect your ability to use some or all of the Services.

If you wish to exercise any of these rights, please contact our Privacy Officer at the contact information above, or refer to certain relevant sections further in this Policy.

Limited Personal Data Collected from You and What We Use It For

Zea limits the amount of personal data we collect to what is necessary and appropriate for the identified purposes. We will not use or disclose your personal data for purposes other than those for which it was collected, except with your consent or as permitted or required by applicable law.

In the table below, please find all the personal data we may collect from you directly, what we use it for, and the legal basis under the GDPR for us having and processing this personal data. Under PIPEDA and the Quebec Privacy Act, the legal basis is your informed consent, and by submitting this personal data to us you acknowledge having granted this consent to Zea.

  • Personal data we collect from you but only with your consent
  • Contact Information

  • Account Information

  • Billing Information

  • Chat Information

  • Personal data processed
  • Email address

  • Email address and, optionally, your real first name, last name, job title, and the company that you work for

  • Credit card holder name, billing address, credit card number, expiration date, and CVV/CVC number

  • Any personal data submitted via the Website’s chat function(s) or Slack; the email address associated with your Slack account

  • What we use it for(the “purpose” of processing)
  • To communicate with you

  • To communicate with you about your account; to allow you to log in to your account; to manage your Software access

  • To process your payments of the SaaS Fees

  • To communicate with you and to respond to your inquiry

  • Legal basis for processing under the GDPR
  • Your consent in giving us this information

  • Your consent in giving us this information

  • Performance of a contract between you and us

  • Your consent in giving us this information

Personal Data Collected About You from Third Parties and What We Use It For

Zea does not collect personal data about you from third parties. However, to the extent that advertising and analytics identifiers are generated from third parties, these may be considered personal data collected from third parties, and you can find details about that further below in this Policy.

Sensitive Personal Data

We do not collect any of what the GDPR considers sensitive personal data (such as health data or data about your racial or ethnic origin) from you when you use the Services, unless you voluntarily submit it to us, which we encourage you not to do.

Who We Transfer Your Personal Data To

We routinely share some of your personal data with certain types of third parties who are identified in the table further below in this section. Some of these third-party recipients may be based outside your home jurisdiction. If you are in the European Economic Area or the U.K. — please see the “Transfer of Your Personal Data Outside of the European Economic Area” further down in this Policy for more information, including on how we safeguard your personal data when this occurs.

We will share personal data with law enforcement or other public authorities if: (1) we are required by applicable law in response to lawful requests, including to meet national security or law enforcement requirements; (2) if we believe it is necessary in order to investigate, prevent, or take action regarding illegal activities, fraud, or situations involving potential threats to the safety of any person, or any violation of the Zea Terms of Use; (3) if we believe it is necessary to investigate, prevent, or take action regarding situations that involve abuse of the Website’s infrastructure or the internet in general (such as voluminous spamming or denial of service attacks); (4) if we are required to do so under any applicable law.

We may also share personal data: (1) to a parent company, subsidiaries, joint ventures, or other companies under common control with Zea (in which case we will require such entities to honour this Policy); (2) if Zea merges with another entity, is subject to a corporate reorganization, sells or transfers all or part of its business, assets or shares (in which case we will require such entity to assume our obligations under this Policy, or inform you that you are covered by a new privacy policy).

We will never share your personal data with other third parties except under these circumstances. We do not sell or rent your personal data to any third party for direct marketing purposes or any other purpose.

  • Personal Information category
  • Contact Information

  • Account Information (including your IP address)

  • Billing Information

  • Chat Information

  • Advertising identifiers

  • Analytics identifiers and IP address

  • Personal Information category
  • Send you emails on our behalf, as further detailed in the Email Communications section below

  • Store it and manage it, so that you can access your account to use the Software and for other account functions

  • Billing Process your payments of the SaaS Fees

  • Operate the chat function(s) on the Website and allow us to communicate with one another using Slack

  • Show you ads for Zea and the Services when you are on the internet, as further detailed in the Zea Advertising section below

  • Provide us with analytics as to how the Services are used, as further detailed in the Limited Gathering of Information section below

Email Communications and Compliance with Anti-Spam Laws

Zea manages our mailing list internally. We use Firebase, HubSpot, Mailgun and Sendinblue to send out marketing and promotional emails and emails related to various Services functions, Stripe to send out emails related to your payments and HelpScout to answer User and Website visitor questions (Firebase, Hubspot, Mailgun, Sendinblue. Stripe and HelpScout, collectively, the “Email Service Providers”). Personal data (your email address) is transferred to the Email Service Providers in order to have emails sent out properly. Your personal data is only used to send out emails; the Email Service Providers do not use this personal data for any other purpose, and will not transfer or sell your personal data to any other third party. Zea also uses your email address for retargeting advertising, as described in the next section of this Policy.

You may unsubscribe from Zea’s newsletter and promotional mailing list at any time, by following the link at the bottom of the Zea emails. Other types of emails, such as transactional, relational, and other emails related to your payment of SaaS Fees or your account will not have an opt-out option, as they are necessary for the use of the Services.

Zea’s practices with respect to its emails are designed to be compliant with anti-spam laws, including, but not limited to, the law unofficially called “CASL”, or Canada’s Anti-Spam Law (S.C. 2010, c. 23) and the American CAN-SPAM Act of 2003. If you believe you have received email in violation of these laws, please contact our Privacy Officer using the contact information further up in this Policy.

Zea Advertising and Opting Out

Zea is continuously evaluating and modifying our use of various advertising networks, which may change from time to time. In this section you will find all the advertising networks that Zea currently uses and instructions for opting out of them. You may also opt out or decline such advertising by refusing or deleting the appropriate cookie, as described further in this Policy. We will always update this Policy if we use additional advertising networks.

Generally, these ad networks work by delivering you advertisements that will be of particular interest to you when you use their websites, apps, or services, based on your browsing and activity history interacting with the Website and the Platform. Certain advertising networks use your email address that you submit to us to match your profile in order to better target the advertising to your preferences, called email retargeting.

The table below identifies the advertising networks we currently use, as well as links and instructions on opting out. By visiting the Website , using the Services or submitting your email address to us, you consent to our advertising to you in this manner, understanding that you can generally opt out any time, as provided for in the table below. If opting out, we also suggest clearing your browsing history and deleting your cookies.

  • Advertising network
  • Google AdWords and Display Network

  • Meta Pixel (Facebook)

  • LinkedIn Ads

  • Twitter Ads

  • Reddit Ads

Limited Gathering of Information for Statistical, Analytical and Security Purposes

Zea automatically collects certain information using the “Third-Party Analytics Programs” Google Analytics, HubSpot, FullStory, Hotjar and Userpilot to help us understand more about our Website visitors and Users and how they use the Website and the Platform, but none of this information identifies you personally, except via an alphanumeric string. For example, each time you visit the Website, we automatically collect (as applicable) your IP address, browser and computer or device type, access times, the web page from which you came, the web page(s) or content you access, and other related information. We use information collected in this manner only to better understand your needs and the needs of Website visitors and Users in the aggregate. Zea also makes use of information gathered for statistical purposes to keep track of the number of visits to the Website, the specific pages visited on the Website, and the number of Users using the Platform with a view to introducing improvements to the Website, Platform, Services and our marketing activities.

Your IP address and other relevant information we collect using the Third-Party Analytics Programs may be used in order to trace any fraudulent or criminal activity, or any activity in violation of the Zea Terms of Use.

Tracking Technology ("Cookies") and Related Technologies on the Website

Zea uses tracking technology (“cookies” and related technology such as tags, pixels and web beacons) on the Website. Cookies are small text files placed on your computer or device when you visit a website or use an internet-connected service, in order to track use of the site or service and to improve the user experience by storing certain data on your computer or device. By visiting the Website or using the Services, you agree to their use, but only if you consent to such use when visiting the Website for the first time and clicking OK on the cookie banner.

Specifically, we use cookies and related technologies for the following functions:

Your browser can be set to refuse cookies or delete them after they have been stored. You can refer to your browser’s help section for instructions, but here are instructions for the most commonly-used browsers and operating systems:

Please note that if you choose to opt-out of our cookie policy, we will install a single cookie on your device to record your preference. Deleting these cookies may reduce your user experience on the Website. Furthermore, deleting cookies may prevent certain functions from working at all.

How We Protect Your Personal Data

We have implemented very strict technical and organizational procedures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed by us. These procedures prevent your personal data from being lost, used, or accessed in any unauthorized way. Examples of such procedures include restricted access to offices, training of personnel, using passwords and well-defined internal policies and information technology practices.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory authority of a suspected data security breach where the Data Protection Laws require us to do so, and within the time frame required by the applicable Data Protection Law.

Zea uses only industry best practices (physical, electronic and procedural) in keeping any data collected (including personal data) secure. In addition, we use third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to operate the Website, and these third parties have been selected for their high standards of security, both electronic and physical.

All information, including personal data, when transferred via the Website is done with encryption using Secure Sockets Layer (“SSL”) or Transport Layer Security (“TLS”), robust security standards for internet data transfer. You can use your browser to check Zea’s valid SSL security certificate on the Website.

Transfer of Your Personal Data Outside of the European Economic Area (EEA) and the U.K

For our European and British users, we endeavour to keep your personal data inside the EEA or the U.K. (as applicable). However, some of our data processors (and Zea) are in other countries where your personal data may be transferred. However, these countries are limited to countries with particular circumstances that protect your data, specifically:

You have the right to refuse to have your data transferred outside the EEA or the U.K. Please contact our Privacy Officer to make that request. Please note that making this request may prevent you from being able to use a portion or all of the Website or the Services.

Supervisory Authorities and Complaints

If you are in the EEA or U.K., under the GDPR, you have the right to make a complaint to the appropriate supervisory authority. If you are not satisfied with the response received or the actions taken by our Privacy Officer, or if you would like to make a complaint directly about Zea’s data practices, we invite you to contact the supervisory authority in your country. For example, if you are in the U.K., you should contact the Information Commissioner’s Office who is the supervisory authority. You can reach them in a variety of ways, including by phone (0303 123 1113 in the UK) and mail (Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF). If you are in France, you should contact the Commission Nationale de l'Informatique et des Libertés who is the supervisory authority there. Their contact information can be found here.

The full listing of all Data Protection Authorities (the supervisory authorities) across the EEA can be found here.

If you are in Canada and you are not satisfied with the response received or the actions taken by our Privacy Officer, you can make a complaint to the Office of the Privacy Commissioner of Canada. Instructions on how to do so can be found on their website. In Québec you can make a complaint to the Commission d’accès à l’information, with the instructions for contacting them on their website.

Data Retention

Your personal data will only be kept for as long as it is necessary for the purpose needed for that processing. For example, we will only retain your Account Information for as long as you seek to maintain your account on the Platform.

Automated Decision-Making

Zea does not use any automated decision-making processes in providing the Services.

Children’s Privacy Statement

The Services are not intended for children under the age of 13. We do not knowingly collect any Personal Information from a child under 13. If we become aware that we have inadvertently received Personal Information from a person under the age of 13 through the Services, we will delete such information from our records.

Changes to This Privacy Policy

The date at the top of this page indicates when this Policy was last updated. Because Data Protection Laws are constantly evolving, every now and then we will have to update this Policy. You can always find the most updated version at this URL. If we make significant changes to the Policy, we will always post a notice on the Website, and if we have your email address, we will also email you to tell you the Policy has been updated, and what the important changes are.