zeta Regional Privacy Disclosures

Effective Date: August 21, 2026

Last Updated: August 14, 2026

This document provides additional privacy information for users in specific jurisdictions and is intended to supplement our Privacy Policy at [Privacy Policy]. Capitalized terms have the meanings given in our Privacy Policy and Terms of Service.

Where applicable law grants you specific privacy rights or requires us to make additional disclosures, those are set out below by region. These disclosures apply in addition to — and do not replace — the information provided in our Privacy Policy.

Current regional sections:

  • Section 1 — United States (U.S. State Privacy Notice)
  • Section 2 — Third-Party Service Providers and Subprocessors (all regions)
  • Section 3 — Additional Disclosures for Other International Regions (Canada, Australia, New Zealand, Singapore)

Additional regional sections will be added as zeta expands its services to other jurisdictions.

1. United States

This U.S. State Privacy Notice provides additional information for residents of U.S. states with applicable privacy laws, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), New Hampshire (NHPA), Delaware (DPDPA), Indiana (INCDPA), and other states that may enact privacy legislation. It supplements our Privacy Policy; please read both documents together.

1.1 Personal Information We Collect and Disclose

For a full description of the personal information we collect, its sources, and the purposes for which we use it, please refer to Sections 1 and 2 of our Privacy Policy.

The following table describes the categories of personal information we have collected and disclosed in the preceding 12 months, including any disclosures that may constitute a "sale" or "sharing" for targeted advertising under applicable state law. While these disclosures may be treated as "sales" under some state laws, we do not sell personal information for monetary consideration, and Scatterlab, Inc. is not a data broker.

Category of Personal InformationRecipients — Business Purpose DisclosuresRecipients — "Sales" / "Sharing" (Targeted Advertising)
Identifiers (name, username, email, phone, device ID, ADID, linked account IDs)Infrastructure & cloud providers; AI/ML model providers; analytics providers; security providers; advertising providers; other users (if you make content public)Advertising & attribution partners (see the category in Section 2 and our Subprocessor List)
Demographic information (date of birth, gender)Infrastructure & cloud providers; AI/ML model providers; SaaS providersAdvertising providers
User Content / Messages (conversation text, multimedia, send time, metadata)Infrastructure & cloud providers; AI/ML model providers; data labeling providers; CS support providersN/A
Usage Records (access logs, interaction patterns, error logs)Infrastructure & cloud providers; analytics providersAdvertising providers
Sensitive Personal Information (voluntarily provided — e.g., health, race/ethnicity, religion, sexual orientation)AI/ML model providers (solely to provide the Service)N/A — not sold or shared for targeted advertising

We may also disclose any of the above categories in connection with a business transfer, in response to legal process, or to protect safety and rights, as further described in the "How We Disclose Personal Information" section of our Privacy Policy.

Our advertising practices may vary depending on your location and whether you access the Services via website or mobile application. Where required by local law, we obtain consent before providing targeted advertising to, or disclosing personal information of, minors between the ages of 13 and 18.

1.2 Sensitive Personal Information

Because of the conversational nature of the Services, you may voluntarily include sensitive personal information in your interactions. For how we handle it (we do not solicit it, use it only to deliver the Service, do not use it to infer characteristics for other purposes, and do not sell or share it for targeted advertising), see Section 1.3 of our Privacy Policy.

Residents of California, Colorado, Virginia, Texas, and other states with applicable laws may have the right to limit the use and disclosure of their sensitive personal information. To exercise this right, email privacy@scatterlab.co.kr or submit a request through https://support.zeta-ai.io/.

1.3 Data Retention

We retain personal information for the time necessary for the purposes for which it is processed, unless a shorter retention period is required by law. For details about our data retention practices, including post-account-deletion retention and our approach to public content, see the "Data Retention" section of our Privacy Policy.

1.4 Your State Privacy Rights

Depending on your state of residence and subject to applicable exceptions, you may have some or all of the following rights:

  • Know / access the personal information we hold about you;
  • Correct inaccuracies in your personal information;
  • Delete your personal information;
  • Data portability — obtain a portable copy of your personal information;
  • Opt out of the "sale" or "sharing" of your personal information and of targeted advertising;
  • Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you;
  • Limit the use and disclosure of sensitive personal information;
  • Non-discrimination for exercising your rights; and
  • Appeal a denied request.

Which of these rights apply to you, and the exceptions and thresholds involved, depend on your state's privacy law — including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, New Hampshire, Delaware, Indiana, and other states with comparable laws — and may change as those laws and their implementing regulations evolve (for example, California's automated decision-making technology (ADMT) regulations affecting profiling). This summary is current as of the "Last Updated" date above. California residents also have a private right of action for certain data breaches ($100–$750 per consumer per incident; see Section 1.5). To exercise any of these rights, use the contact channels described below; we may need to retain certain information for legal compliance, to provide the Services, or to protect our and others' rights.

How to Exercise Your Rights. To submit a privacy rights request (other than opt-out requests — see below):

  • Email: privacy@scatterlab.co.kr
  • Customer Center: https://support.zeta-ai.io/

We will verify your identity before processing your request. If we are unable to verify your identity, we may be unable to fulfill the request. We will respond within the timeframes required by applicable state law — generally within 45 days, with an option to extend by an additional 45 days where reasonably necessary.

Authorized Agents. You may designate an authorized agent to submit requests on your behalf. To verify an authorized agent, you must provide signed written permission or a legally valid power of attorney. We may also contact you directly to verify your identity.

Appealing a Denied Request. If we deny your request, we will explain why in our response and provide information about how to submit an appeal, where required by applicable state law.

Opt-Out of Targeted Advertising and Sales. You can opt out of targeted advertising and the sale/sharing of your personal information using the methods available today: (i) limit or reset your mobile advertising identifier in your device settings; (ii) use industry opt-out tools such as the Network Advertising Initiative (thenai.org/how-to-opt-out) and the Digital Advertising Alliance (optout.aboutads.info); and (iii) email privacy@scatterlab.co.kr with the subject line "Do Not Sell or Share," and we will honor your request for the account and advertising identifiers associated with it to the extent technically feasible.

Please note that certain opt-out choices may be specific to your device, browser, or platform. If you use multiple devices or browsers, you may need to submit your request for each.

Minors' Personal Information. For users we know to be minors, we apply heightened protections: (i) we do not sell or share the personal information of a consumer at least 13 and under 16 without that consumer's affirmative opt-in, and we do not sell or share the personal information of a consumer under 13 (Cal. Civ. Code § 1798.120(c)); and (ii) for users we know or reasonably believe to be under 18, we do not engage in targeted advertising or the sale of personal information where prohibited or restricted by state law — for example, Connecticut prohibits targeted advertising and the sale of a known minor's data, and Colorado and Montana require prior consent.

Non-Discrimination. We will not discriminate against you for exercising any of your privacy rights. We will not deny you goods or services, charge different prices, or provide a different level of service based solely on the exercise of your privacy rights.

1.5 Additional Disclosures for California Residents

California Shine the Light (Cal. Civ. Code § 1798.83). California residents may request, once per calendar year, the following information about personal information we shared with third parties for their own direct marketing purposes during the immediately preceding calendar year: (i) the categories of personal information disclosed; and (ii) the names and addresses of those third parties.

To submit a Shine the Light request, email privacy@scatterlab.co.kr with the subject line "California Shine the Light Request." We may require additional information to verify your identity. We are required to respond to one request per calendar year per customer.

California Private Right of Action (CCPA, Cal. Civ. Code § 1798.150). California residents whose unencrypted or unredacted personal information is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of our failure to implement and maintain reasonable security procedures may bring a civil action to recover statutory damages of between $100 and $750 per consumer per incident, or actual damages, whichever is greater, as well as injunctive or declaratory relief.

This right is separate from and in addition to your rights to submit requests to us under CCPA/CPRA described above.

1.6 Additional Disclosures for Nevada Residents

Nevada law (NRS 603A.340) requires businesses to provide a designated address where Nevada consumers may submit requests directing the business not to sell certain personal information. Under Nevada law, a "sale" means the exchange of personal information for monetary consideration by the business to a third party for the third party to license or sell the personal information to additional third parties.

If you are a Nevada resident and wish to submit a request under Nevada law, please email privacy@scatterlab.co.kr with the subject line "Nevada Privacy Request." Note that Nevada's definition of "sale" is narrower than California's and does not include sharing personal information for targeted advertising purposes without monetary exchange.

1.7 Companion Chatbot Disclosures (California SB 243; Oregon SB 1546; Washington HB 2225)

Certain states regulate "companion chatbots." Where these laws apply, we provide the following:

  • AI disclosure. You are interacting with artificial intelligence, not a human. Characters are AI-generated and their responses are fiction.
  • Safety resources. zeta is not a crisis-support service. If you or someone you know may be considering self-harm or suicide, please seek help immediately — in the U.S. and Canada, call or text 988 (988 Suicide & Crisis Lifeline).
  • Minors. The Services' companion-style features (including romantic or dependency-building interactions) are not intended for users under 18. Where required by applicable law, we apply heightened protections for users we know or reasonably believe to be minors.
  • Notice. The Services may not be suitable for all minors.

California SB 243 is effective January 1, 2026; Oregon SB 1546 and Washington HB 2225 take effect January 1, 2027. In California, Oregon, and Washington, individuals may have a private right of action for certain violations.

1.8 International Data Transfers

Scatterlab, Inc. is established in the Republic of Korea. Your personal information is processed in the Republic of Korea and may be transferred to and processed in the United States, Singapore, and other countries where our service providers operate. These countries may have data protection laws that differ from those in your state or country.

Data stored or processed in these jurisdictions may be accessible to law enforcement and national security authorities under applicable local laws. By using the Services, you acknowledge that your information may be transferred to and processed in these locations.

For a list of our key service providers and their locations, see the categories in Section 2 and our Subprocessor List at [Subprocessor List].

1.9 Contact for U.S. Privacy Inquiries

For U.S. privacy-related questions or requests:

  • Email: privacy@scatterlab.co.kr
  • Customer Center: https://support.zeta-ai.io/
  • Postal Address: Scatterlab, Inc., 125 Wangsimni-ro, Seongdong-gu, Seoul, Rooms 901 and 902 (KD Tower), Republic of Korea

2. Third-Party Service Providers and Subprocessors

This section describes the categories of third-party service providers and subprocessors that may receive or process personal information on our behalf, together with the purpose of each category. This category-level disclosure supports transparency requirements under applicable U.S. state and international privacy laws, which require disclosure of the categories of recipients rather than the identity of each individual vendor.

CategoryPurposeSale / Sharing?
Cloud infrastructure & hostingService delivery, storage, and compute; pseudonymized data processingNo — processor acting on our behalf
AI / ML model providersConversational AI, AI image generation, and model research & developmentNo — processor acting on our behalf
Analytics providersService usage analytics and quality improvementNo — processor acting on our behalf
Customer service providersUser support and related service deliveryNo — processor acting on our behalf
Data labeling providersAnnotation of data used to improve the ServicesNo — processor acting on our behalf
Security providersFraud, abuse, and security monitoringNo — processor acting on our behalf
Advertising & attribution partnersTargeted advertising, attribution, and ad measurementYes — treated as a "sale" / "sharing" under applicable U.S. state law

Note on advertising partners. Vendors in the "Advertising & attribution partners" category act as independent third parties and may use the data for their own purposes; these disclosures are treated as a "sale" or "sharing" under applicable U.S. state law and are subject to your opt-out rights (see "Opt-Out of Targeted Advertising and Sales" above). Vendors in all other categories act only as our service providers/processors under contract.

Specific vendors. A current, versioned list of the specific vendors within each category — including their processing locations and contact points — is maintained separately in our Subprocessor List, available at [Subprocessor List]. That list is updated as our vendor relationships change, without requiring a revision of this document; the "Last Updated" date on the Subprocessor List reflects its most recent revision.

3. Additional Disclosures for Other International Regions

This Section supplements the main Privacy Policy for individuals who use the Services in Canada, Australia, New Zealand, and Singapore. The Services are provided to these regions in the English language. Where the law of your region grants rights or protections greater than those in the main Privacy Policy, those rights and protections apply. Unless a region-specific channel is stated below, you may exercise your rights by contacting privacy@scatterlab.co.kr.

Company and international transfers. Scatterlab, Inc. is established in the Republic of Korea. Your personal information is processed in the Republic of Korea and may be transferred to and processed in the United States, Singapore, and other countries where our service providers operate (see Section 2). Region-specific transfer safeguards are described in each section below.

AI interaction notice. You are interacting with an artificial-intelligence system, not a human. We disclose this at the first point of interaction.

Minors. We do not knowingly permit children under 13 to register. For users we know to be minors, targeted/behavioural advertising and disclosure of personal information for advertising are off by default, advertising based on profiling is not directed to minors, and companion features such as romantic role-play, emotional-dependency interactions, and sexually themed content are restricted.

3.1 Canada

  • Governing law: PIPEDA (federal); for Quebec residents, the Act respecting the protection of personal information in the private sector as amended by Law 25, and the Charter of the French Language (Bill 96); and CASL for commercial electronic messages.
  • Regulators / complaints: Office of the Privacy Commissioner of Canada (priv.gc.ca) and the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
  • Consent: meaningful consent for collection, use, and disclosure; express consent for sensitive information. Commercial electronic messages require opt-in consent with an unsubscribe mechanism (CASL).
  • Your rights: access, correction, and withdrawal of consent; for Quebec residents additionally de-indexing/erasure and data portability (in force since September 2024).
  • Automated decisions (Quebec): on request, we inform you when a decision is based exclusively on automated processing and of the personal information used to make it.
  • Privacy Officer: we designate a person responsible for the protection of personal information.
  • Transfers (Quebec): cross-border disclosures are assessed through a privacy impact assessment and contractual safeguards.
  • Breach: breaches of security safeguards that create a real risk of significant harm are reported to the Office of the Privacy Commissioner of Canada and to affected individuals, and records of breaches are maintained (PIPEDA).

3.2 Australia

  • Governing law: Privacy Act 1988 and the Australian Privacy Principles (APPs), as amended by the Privacy and Other Legislation Amendment Act 2024 (which also introduced a statutory tort for serious invasions of privacy).
  • Regulator / complaints: Office of the Australian Information Commissioner (OAIC, oaic.gov.au).
  • Collection notice (APP 5): we notify you of collection, purposes, and disclosures.
  • Your rights: access (APP 12) and correction (APP 13); opt out of direct marketing (APP 7). You may complain to us and then to the OAIC.
  • Cross-border (APP 8): we remain accountable for personal information disclosed overseas and take reasonable steps to ensure overseas recipients handle it consistently with the APPs.
  • Marketing: where we send commercial electronic messages, we obtain consent, identify ourselves, and provide a functional unsubscribe facility (Spam Act 2003).
  • Breach: eligible data breaches are notified to the OAIC and to affected individuals under the Notifiable Data Breaches scheme.

3.3 New Zealand

  • Governing law: Privacy Act 2020 and the Information Privacy Principles (IPPs).
  • Regulator / complaints: Office of the Privacy Commissioner (privacy.org.nz).
  • Your rights: access (IPP 6) and correction (IPP 7).
  • Cross-border (IPP 12): we disclose personal information overseas only where the recipient is subject to comparable safeguards or you have authorised the disclosure.
  • Marketing: unsolicited commercial electronic messages are handled under the Unsolicited Electronic Messages Act (unsubscribe/opt-out).
  • Breach: notifiable privacy breaches are reported to the Privacy Commissioner and to affected individuals.

3.4 Singapore

  • Governing law: Personal Data Protection Act (PDPA).
  • Regulator / complaints: Personal Data Protection Commission (PDPC, pdpc.gov.sg).
  • Consent & notification: we collect, use, and disclose personal data with consent and notify you of the purposes; you may withdraw consent with reasonable notice.
  • Your rights: access to your personal data (and its disclosure history) and correction.
  • Marketing: we obtain consent for marketing communications where required and honor opt-out/withdrawal requests.
  • Transfers (PDPA §26): overseas transfers are made only where comparable protection is ensured by legally enforceable obligations.
  • Breach: notifiable data breaches are reported to the PDPC within 3 calendar days and to affected individuals where significant harm is likely.

3.5 Region Quick Reference

RegionGoverning lawRegulatorCore rights / opt-out
CanadaPIPEDA + Quebec Law 25 + Bill 96 + CASLOPC / CAI (Québec)Access, correction, consent withdrawal; Quebec: de-indexing, portability, ADM info; CASL opt-in for e-marketing
AustraliaPrivacy Act 1988 / APPs (2024 reform)OAICAccess (APP 12), correction (APP 13), direct-marketing opt-out (APP 7)
New ZealandPrivacy Act 2020 / IPPsPrivacy CommissionerAccess (IPP 6), correction (IPP 7)
SingaporePDPAPDPCAccess, correction, consent withdrawal; marketing consent/opt-out
Scatter Lab, Inc.

Tel: (+82) 070-4099-5959 | Email: contact@zeta-ai.io

Privacy Policy|Terms of Service|Usage Policy|.
.|Partner Program|Customer Support