Updated: January 1, 2023
In this European Economic Area (“EEA”) and United Kingdom (“UK”) supplement (“EEA/UK Supplement”) to the Zuora Privacy Statement (“Statement”), we, Zuora, Inc. (“Zuora”), provide to residents of the EEA and the UK additional information about our processing of personal data from the EEA and UK.
Zuora, Inc. operates http://www.zuora.com and other publicly-available web pages that directly link to this EEA/UK Supplement (collectively the “Site”) and is the controller of any personal data collected or otherwise processed on the Site. Unless defined specifically in this EEA/UK Supplement, capitalized terms shall have the meaning set forth in the Statement.
Purposes and Legal Bases for Processing
We process your personal data based on several different legal bases, which include the performance of or entering into contracts (where the processing is necessary to provide you contractual services or support, respond to your request or otherwise for the performance of a contract), legitimate interests (such as the security and safety of the Site, our IT and users of the Site, to prevent and detect fraud, and to track your activities on the Site for purposes of personalization, optimization and advertising), compliance with legal obligations and consent (for placing certain cookies on your device or sending you marketing communications).
Marketing Communications to You
On the Site, you can register to receive newsletters or other information on the products or services of Zuora and our affiliated companies. During registration, we ask you to provide us with certain information, including your contact information, company, job title and location. We may also log and store additional personal information such as the date, time and IP address associated with your registration. If you are located in certain jurisdictions such as Germany, we verify the authorized use of an email address by sending an email to confirm your registration via a contained link. You may withdraw your consent at any time by following the unsubscribe link in email communication to you or by sending us an email at firstname.lastname@example.org.
Types of Third Parties to Which We Disclose Personal Data and Purposes
We disclose your personal data to third parties, as required or permitted by applicable law. We share personal data of data subjects in the EEA or UK (“EEA/UK Data”) with our subsidiaries, affiliates and contractors, who process personal data on behalf of Zuora. We also provide information to our channel partners, such as distributors and resellers, to fulfill product and information requests, and to provide customers and prospective customers with information about Zuora and its products and services. We also share EEA/UK Data with other third parties for the purposes for which we receive the EEA/UK Data (e.g., performance of contractual obligations and rights), and we may also disclose EEA/UK Data where we are legally required to disclose (e.g., under statutes, contracts or otherwise) or where the disclosure is permitted by law and we have a legitimate business interest in such disclosure.
Data Transfers to Recipients Outside of the EEA/UK
Zuora is a global corporation headquartered in the United States. We transfer your data to the United States and to the countries where our affiliated companies and third-party service providers are located. For a list of Zuora affiliates and subprocessors, please see the Legal and Security Resources page, here.
In July 2020, the European Court of Justice held that the EU-US Privacy Shield Framework was no longer valid as a transfer mechanism for personal data from the European Union. The U.S. Department of Commerce continues to administer the Privacy Shield Framework and continues to hold participants to their obligations under Privacy Shield Framework. Zuora, as a participant in the Privacy Shield Framework, will continue to comply with its commitments under the Privacy Shield Framework and its robust internal data protection policies as further explained in our Privacy Shield Notice.
Zuora has executed Standard Contractual Clauses, as approved by the European Commission in June 2021 and the UK ICO in March 2022, with each of its affiliates and third-party service providers along with implementing such other appropriate safeguards required under applicable law. These steps permit Zuora to transfer data from the EEA and UK to third countries, including the United States. You can ask for more information by contacting email@example.com.
We will retain your information for as long as needed to provide you services and fulfill the purposes described in this EEA/UK Supplement. We will retain and use your information as required or permitted by applicable law, including to comply with our legal obligations, resolve disputes, and enforce our agreements. More information about retention is available by contacting firstname.lastname@example.org.
Your Rights Regarding Processing of Your Personal Data
Subject to the conditions set out in the applicable law, you have the rights to understand how your personal data is processed and access, download, update or change, delete or restrict certain processing of the personal data which Zuora collects about you through the Site. If you need to update, change, remove or have any other request related to personal data that we control, you can do so by contacting email@example.com. In the case of concerns, you also have the right to contact your local data protection authority.
Your Provision of Personal Data to Us
Your use of the Site and your provision of personal data is purely voluntary. You can stop using the Site or, where applicable, opt out of certain processing activities while on the Site as described in this EEA/UK Supplement. If you ask us to provide a service or want to enter into a contract with us, providing us with your related personal data is necessary for us to be able to enter into the contract with or provide any contractual services to you.
We may update this EEA/UK Supplement periodically and without prior notice to you to reflect changes in our relevant practices. If we make material changes to this EEA/UK Supplement, we will notify you here, by email, or by means of a notice on our home page prior to the change becoming effective. You should review the EEA/UK Supplement each time you visit one of our Sites to learn of any changes.
Zuora Global Headquarters
101 Redwood Shores Parkway
Redwood City, CA 94065
Date: January 1, 2023