Last updated 19.05.2026

Privacy
Policy

Question? privacy@zama.org

We are committed to maintaining the confidentiality of your personal information and attach great importance to protecting your privacy, when processing some of your Personal Data, in accordance with current regulations, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of Personal Data (the "GDPR"), as well as French law No. 78-17 of January 6, 1978 (as amended).

We invite you to read this document (the "Privacy Policy") carefully. If you have any questions about our Privacy Policy and, in general, about the collection and processing of your Personal Data by Zama please do not hesitate to contact us at: privacy@zama.org

Scope

This Privacy Policy governs and details the main principles that Zama applies to the Personal Data we collect and process in relation to our corporate website zama.org (the "Website"), products, services, events, and experiences that reference this Privacy Policy.

The purpose of this Privacy Policy is to provide you with all the important information and explanations about how and why some of your Personal Data may be collected and processed by Zama when you browse on the Website.

This Privacy Policy also aims to remind you about your data protection rights and to provide you with all the elements you need to exercise them.

This Privacy Policy does not apply to any products, services, websites, or content that are offered by third parties or have their own privacy notice.

Important Definitions

"Personal Data" means any information relating to an identified or identifiable natural person that identifies the person directly (e.g. the name, an identification number) or indirectly (e.g. connection data)

"Processing" (of Personal Data) means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, storage, disclosure by transmission, etc.

"Controller" means someone who determines the purposes and means of Processing

"Processor" means someone who processes Personal Data on behalf of and on the instructions of the Controller

"Zama Group" means Zama SAS and its affiliated entities, including Zama Switzerland AG (registered in the Commercial Register of the Canton of Zug under company number CHE-186.971.062, with registered office at Grafenauweg 8, 6300 Zug, Switzerland). References to "Zama", "we", "our" or "us" in this Privacy Policy include the Zama Group where the context requires.

How we collect and process some of your Personal Data?

We collect and process:

Personal Data you voluntary and knowingly provide us

We confirm that providing the Personal Data in this context is voluntary and that it is not subject to a statutory or contractual requirement

You do not have a legal duty to provide any of the above information. However, you may not be able to submit an inquiry or an application for a job position on our Website without providing the required information.

Inquiries / Requests

You can submit an inquiry through our Website. You may be asked to provide information such as your name, email address, and other relevant information related to the request.

Job Opportunities

You may apply for career opportunities at Zama through the Website.

To do so, we will ask you to provide information such as your name, current position, postal address, email, phone number, your web presence, and an option to provide additional information in an email and your CV. The mandatory fields for completion will be marked.

When you apply for a job via the Website, your Personal Data is managed by Coruscant SAS (Welcome Kit / Welcome to the Jungle), our services provider. All the information concerning the Processing of your Personal Data in this context can be accessed here: https://www.welcometothejungle.com/fr/pages/privacy-policy

Newsletters

You may subscribe to our Newsletters by providing your email address.

GitHub, Community Forum, and FHE.org Discord

You may use these tools to communicate with Zama's Team, other Website's visitors, and FHE.org Community members.

When using GitHub (GitHub B.V.), your Personal Data is managed by GitHub B.V. We inform you that we have no control over the use of your Personal Data by GitHub B.V. which acts as Controller within the meaning of the GDPR. All the information concerning the Processing of your Personal Data in this context can be accessed here: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement.

When using the FHE.org Discord (Discord Inc.), your Personal Data is managed by Discord Inc. We inform you that we have no control over the use of your Personal Data by Discord Inc. which acts as Controller within the meaning of the GDPR. All the information concerning the Processing of your Personal Data in this context can be accessed here: https://discord.com/privacy

Telegram

Zama uses Telegram for community engagement and business communications. This includes broadcast channel announcements, group chats (which may be created by Zama staff, leads, users, or community members), and direct messages initiated by either party. When you interact with Zama via Telegram, we may process your Telegram username or handle, message content exchanged with Zama representatives, channel and group membership data, and associated timestamps. Telegram is operated by Telegram FZ-LLC. We inform you that we have no control over the use of your Personal Data by Telegram FZ-LLC, which acts as Controller within the meaning of the GDPR. All information concerning the Processing of your Personal Data by Telegram can be accessed here: https://telegram.org/privacy

Analytics information

When you visit our Website, we may record and collect certain information in relation to your visit and use of the Website and your interaction with the Website's contents: IP address and the general location corresponding to the address, time and date of access, type of browser used, language(s) used, links clicked, and the web pages you accessed.

This data is collected through Google Analytics 4 (GA4) and HubSpot analytics cookies, which are only activated after you have given your explicit consent via the cookie consent banner.

Contact details and consent records

When you interact with Zama (via the Website, email, Telegram, or events), we may collect and store your contact details (name, email address, company) and consent records. Consent records include: what you consented to (e.g. cookies, marketing communications, specific communication channels), when consent was given or withdrawn, and via which touchpoint (e.g. cookie banner, sign-up form, Telegram). These records are maintained as required by applicable data protection law to demonstrate that valid consent was obtained.

Why do we collect and process some of your Personal Data?

When you browse on the Website, we can collect and process some of your Personal Data for various legitimate purposes.

You will find below explanations regarding the reasons why Zama may collect some of your Personal Data and the legal basis Zama relies on in each case.

We collect and process some of your Personal Data:

To respond to your inquiry / request

We will use your information to contact you about and handle your inquiry or request.

Legal basis: Article 6-1(f) of the GDPR - Legitimate interest (responding to your request)

To consider your application for a job position

We will use your information to review your candidacy, consider you for the open job position (or other relevant open positions we may have), and update you as to the status of your candidacy.

Legal basis: Article 6-1(f) of the GDPR - Legitimate interest (responding to your candidacy) + Article 6-1(b) of the GDPR – Pre-contractual measures (taking pre-contractual steps in evaluating your application for an open position)

To manage contact forms

We will use your information to contact you about and handle your inquiry or request.

Legal basis: Article 6-1(f) of the GDPR - Legitimate interest (responding to your request)

To provide you with the latest information about our products and services

Subject to your consent, we may send you marketing communications about Zama's products, services, research, and events. These communications may be delivered via email and Telegram (including broadcast channel announcements, group chat messages, and direct messages). Consent is collected separately for each communication channel. You can opt out of marketing communications at any time by: using the unsubscribe link in any marketing email; leaving the relevant Telegram channel or group chat; or contacting us at privacy@zama.org. If you opt out from one channel, we will continue to use other channels for which you have given consent, unless you instruct us otherwise. Please note that even if you opt out of marketing communications, we may still send you service-related messages that are necessary for the operation of the Website or for community management purposes (such as security alerts or essential project updates). Where you opt in to marketing, your contact details may also be shared with Zama Switzerland AG so that it may send you information about Zama Group products, services, research, and events relevant to your region. We will always obtain your express opt-in consent before any Zama Group entity sends you marketing communications.

Legal basis: Article 6-1(a) of the GDPR – your consent

To manage Newsletters sending

We will use your information to send you Zama's newsletters upon your request.

Legal basis: Article 6-1(f) of the GDPR - Legitimate interest (responding to your request)

To manage consent records and communication preferences

We will use your information to record, store, and manage your consent choices and communication preferences across all channels (cookie consent, marketing opt-in/opt-out, Telegram channel preferences).

Legal basis: Article 6-1(c) of the GDPR – Compliance with a legal obligation (obligation to demonstrate valid consent) and Article 6-1(f) of the GDPR – Legitimate interest (record-keeping and preference management)

To communicate via Telegram

We will use your information to communicate with you and our community via Telegram, including broadcast announcements, group chats, and direct messages for community engagement, business development, and support purposes.

Legal basis: Article 6-1(f) of the GDPR – Legitimate interest (community engagement and business communications) and Article 6-1(a) of the GDPR – your consent (for marketing messages sent via Telegram)

To manage Zama's Blog

We will use your information to run Zama's Blog and 'News' pages.

Legal basis: Article 6-1(f) of the GDPR - Legitimate interest (blog management)

To provide communication tools

Our Website also offers access via third-party tools including GitHub and the FHE.org Discord, and Telegram, which are communication tools allowing users to share content and code on social networks and online storage facilities. When you interact with such social media widgets, "share buttons", or third-party code review sites, these social networks and companies may collect information about you and/or your device and connection. Your interactions with these services are governed by the respective privacy policies of the companies providing these services. For more information on the data protection and privacy practices of these companies, you can refer to their specific policies listed below:

Github
https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement

Discord
https://discord.com/privacy

Telegram
https://telegram.org/privacy

To manage requests to exercise GDPR rights

We will use your information to contact you about and handle your GDPR inquiry or request.

Legal basis: Article 6-1(c) of the GDPR – Compliance with a legal obligation

To manage compliances and disputes

We will use your information to resolve any potential disputes or problems in connection with the use of the Website.

Legal basis: Article 6-1(f) of the GDPR - Legitimate interest (defense of our rights)

To share Personal Data within the Zama Group

We may share your Personal Data with other entities within the Zama Group, in particular Zama Switzerland AG, via our shared CRM platform (HubSpot) for the purposes of coordinating business development activities, managing community engagement across jurisdictions, organising events, and conducting commercial outreach. We will obtain your express opt-in consent before sharing your Personal Data with any Zama Group entity for direct marketing purposes.

Legal basis: Article 6-1(f) of the GDPR – Legitimate interest (intra-group administrative and business coordination, Recital 48 GDPR) and Article 6-1(a) of the GDPR – your consent (for marketing communications sent by Zama Group entities)

Who are the recipients of your Personal Data?

Internal recipients of your Personal Data: The recipients of your Personal Data are the authorized staff of Zama SAS and, where necessary for the purposes described in this Privacy Policy, the authorized staff of other Zama Group entities, in particular Zama Switzerland AG. Personal Data is shared within the Zama Group via a shared CRM platform (HubSpot) for the purposes of coordinating business development, community engagement, and commercial outreach activities. Appropriate intra-group data sharing arrangements are in place to ensure that your Personal Data is protected in accordance with the GDPR.

External recipients of your Personal Data which act as Processors within the meaning of the GDPR and process data on behalf of Zama, according to our instructions and in compliance with any appropriate security and confidentiality measures:

Webflow (hosting service provider)
11th Street, 2nd Floor San Francisco, CA 9410

Coruscant SAS (Welcome Kit / Welcome to the Jungle RH Solution)
24 rue du Mail – 75002 Paris
RCS Paris No. SIREN 802 162 628

HubSpot, Inc. (Marketing Hub Professional / Sales Hub Starter/ Onboarding)
2 Canal Park
Cambridge, MA 02141 USA
Paris (Paris Office)
91 Boulevard Haussman
75008 Paris

Google LLC (Google Analytics 4)
1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Sillage (B2B prospect identification)
https://www.getsillage.com

External recipients of your Personal Data which act as Controllers within the meaning of the GDPR:

GitHub B.V. (hosting service provider)
Prius Bernhardplein 200 99135
The Netherlands
Registration No. 808709794

Discord Inc. (messaging social platform)
444 De Haro St Suite 200 San Francisco
CA 94107, United States

Telegram FZ-LLC (messaging platform)
First Floor, Bldg 1, IFZA Properties, Dubai Silicon Oasis, Dubai, UAE
https://telegram.org/privacy

Zama Switzerland AG (Zama Group entity)
Grafenauweg 8, 6300 Zug, Switzerland Commercial Register of the Canton of Zug, CHE-186.971.062 Contact: privacy@zama.org

Zama Switzerland AG receives Personal Data from Zama SAS via a shared CRM platform (HubSpot) for the purposes of coordinating business development, community engagement, event organisation, and commercial outreach. Zama Switzerland AG acts as an independent controller for the Personal Data it receives and processes in the context of its own activities.

Authorities
Only to the extent we are obliged to by applicable laws and regulations.

For how long is your Personal Data stored?

We undertake to keep your Personal Data only for as long as strictly necessary for the processing operation(s) declared for the purposes mentioned above, and in any event within the limits imposed by law.

  • Administration of the Website: login data, where relevant, is kept for a maximum of 6 months
  • Personal Data in forms: we erase your Personal Data immediately by receiving a withdrawal and unsubscribe request or objection or in case of two (2) years of ongoing inactivity
  • Management of Newsletters sending: your Personal Data is erased within one month after you exercise your opt-out option
  • Processing of job applications: your Personal Data is kept for two (2) years from the time of Zama's last contact with you (except your previous erasure request); in the event of legal action, your Personal Data is archived for five (5) years (civil prescription)
  • Management of general inquiries and requests: your Personal Data is erased within one month after Zama's last contact with you
  • Management of requests to exercise GDPR rights: your Personal Data is kept for six (6) years for the exercise of the right of opposition (criminal prescription) and for five (5) years for other rights (civil prescription)
  • Management of compliances and disputes: your Personal Data is kept for five (5) years (civil prescription)
  • Cookie data: cookie lifetimes do not exceed thirteen (13) months; data collected through cookies is not retained beyond twenty-five (25) months
  • Sillage data: professional data collected through Sillage is retained for a maximum of six (6) months
  • Telegram communications data: retained for the duration of the relationship
  • Consent records: retained for five (5) years (French civil prescription period)

In any event, we undertake to delete your Personal Data from our databases at the end of these various periods, subject to the retention of certain information in order to meet our legal, accounting and tax obligations.

Do we transfer your Personal Data outside the EEA?

The global economic context and the associated internationality of our activity mean that data can be exceptionally accessed outside the Economic European Area ("EEA") via our contractors and partners, provided such access is necessary and based on legal grounds.

In such case, we ensure that:

  • The Personal Data is transferred to countries recognized as offering an adequate level of protection or,
  • For Personal Data exceptionally transferred outside of countries recognized by the European Commission as having a sufficient level of protection, any of the mechanisms offering appropriate guarantees is used, for which provision is made by applicable regulations, and notably the adoption of the standard contractual clauses of the European Commission.

In particular, the use of Google Analytics 4 (Google LLC) and HubSpot, Inc. may involve transfers of personal data to the United States. These transfers are governed by the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs) adopted by the European Commission.

Telegram FZ-LLC is established in the United Arab Emirates, which does not benefit from an adequacy decision by the European Commission. Any transfers of Personal Data to Telegram are governed by Standard Contractual Clauses (SCCs) or other appropriate safeguards in accordance with the GDPR.

Personal Data shared with Zama Switzerland AG is transferred to Switzerland. Switzerland benefits from an adequacy decision by the European Commission (Decision 2000/518/EC, as confirmed), meaning that Personal Data transferred to Switzerland is considered to benefit from an adequate level of protection under the GDPR.

How do we protect your Personal Data?

We are committed to ensuring that your Personal Data is duly protected.

To prevent unauthorized access, disclosure, modification, damage or destruction, we have taken appropriate physical, technical, and organizational security measures to protect the Personal Data we collect and process.

To this end, Zama and our technical and hosting service providers implement necessary measures to ensure the integrity, confidentiality, and security of your Personal Data (in particular by complying with the requirements of applicable personal data protection regulations).

As such, we have chosen to host your data on servers located within the European Union, more precisely in Frankfurt and Amsterdam.

Children's Privacy

The Website is not directed at individuals under the age of 18. We do not knowingly collect Personal Data from children. If you believe that we have inadvertently collected Personal Data relating to a child, please contact us at privacy@zama.org and we will promptly delete such data.

Are there cookies on the Website?

When you visit the Website, cookies and similar tracking technologies may be placed on your device, subject to your choices. Zama uses the following categories of cookies:

Strictly necessary cookies: These are essential for the Website to function and are exempt from consent.

Analytics cookies (Google Analytics 4): These cookies help us measure and improve Website performance by collecting anonymised usage data. They are only placed with your prior consent.

Marketing and CRM cookies (HubSpot): These cookies enable us to track visitor interactions, manage live chat, and measure marketing campaign effectiveness. They are only placed with your prior consent.

A full cookie consent banner is deployed on the Website, allowing you to accept all cookies, refuse all non-essential cookies, or manage your preferences by category. You may change your preferences at any time via the Cookie Settings link in the Website footer.

For further details, please refer to our Cookies Policy, available on the Website.

In addition, Zama uses Sillage, a B2B prospect identification tool, to support its business development activities. Sillage processes only publicly available professional data (name, job title, company, professional email, and public professional interactions) on the basis of Zama's legitimate interest (Article 6(1)(f) GDPR). No cookies are placed by Sillage. A Legitimate Interest Assessment is available upon request.

What are your rights and how can you contact us?

Regarding the use of the Website, you have the following rights under the conditions provided for in the regulations:

  • The right of access, rectification and erasure of your Personal Data (Art. 15 to 17 of the GDPR
  • The right to withdraw your consent (opt out) at any time (Art. 13-2(c) of the GDPR)
  • The right to restriction of Processing of your Personal Data (Art. 18 of the GDPR)
  • The right to object the Processing of your Personal Data (Art. 21 of the GDPR)
  • The right to object to the Processing of your Personal Data for direct marketing purposes at any time, without condition (Art. 21(2)-(3) of the GDPR). This right is absolute: upon receipt of your objection, we will immediately cease all Processing of your Personal Data for direct marketing purposes, including any related profiling.
  • The right to Personal Data portability (Art. 20 of the GDPR)
  • The right to file a complaint with the CNIL (the French data protection authority) (https://www.cnil.fr/fr/plaintes)
  • The right to issue instructions allowing access to your Personal Data in the event of death (Art. 85 of the French law No. 78-17 of January 6, 1978, as amended).

Additional information for specific jurisdictions

If you are located in the European Economic Area (EEA): Zama SAS, as a French company, is subject to the supervision of the Commission Nationale de l'Informatique et des Libertés (CNIL). You may lodge a complaint with the CNIL or with the supervisory authority of the EU Member State of your habitual residence or place of work.

If you are located in Switzerland: the Swiss Federal Act on Data Protection (nFADP/DSG) also applies. You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) at https://www.edoeb.admin.ch. For Swiss residents, Zama Switzerland AG may be contacted at privacy@zama.org.

If you are located in the United Kingdom: the UK GDPR applies. You may lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk.

If you are located in the United States: Zama does not sell or share your Personal Data as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) or other applicable US state privacy laws. Zama does not use tracking pixels or targeted advertising technologies. If you are a California resident and wish to exercise your rights under the CCPA/CPRA, please contact us at privacy@zama.org.

You can exercise these rights by e-mail at privacy@zama.org, specifying the right you wish to exercise and attaching proof of your identity (if necessary) or a power of attorney if you are being represented.

If you exercise these rights, we will endeavor to respond to your requests as soon as possible and at the latest within one month.

This Privacy Policy should be read together with our Cookies Policy, available on the Website.