ZEUS Privacy and Data Policy
- Provider
- Omni Data Tech Inc., an Ontario corporation ("Zeus", "we", "us", "our")
- Registered address
- 3601 Highway 7 East, Suite 1006, Markham, Ontario, L3R 0M3, Canada
- Privacy contact
- [email protected]
- Effective
- 2024-04-01
- Version
- 1.5
- Last updated
- 2026-08-30
- Legal pages
- https://fieldzeus.com/legal
- This Policy
- https://fieldzeus.com/legal/privacy
This Global Privacy Policy (this "Privacy Policy" or "Policy") describes how Zeus collects, uses, discloses, stores and retains information — including Personal Information — in connection with the Services: the Zeus mobile applications, the Zeus web portal, tokenized link pages (document view, quote acceptance, payment, signing and price-book import links), and any websites and related services Zeus operates from time to time. It is written for every person the Services touch: Customers and their Account Owners, Administrators, Members and Helpers (together, Authorized Users), Invited Users, Link Recipients, and Clients whose information a Customer causes Zeus to process.
Capitalized terms used and not defined in this Policy have the meanings given in the Zeus Global Terms of Service and the defined terms used across the Zeus legal documents (including "Services", "Customer", "Account Owner", "Authorized User", "Helper", "Invited User", "Link Recipient", "Client", "Customer Content", "End-Customer Data", "Worker Data", "Account Data", "Personal Information", "Aggregated Data", "Usage Data", "Device Data", "Location Data", "Telemetry", "Offline Data", "Subprocessor", "DPA", "Third-Party Services" and "Supplement").
Jurisdiction-specific privacy disclosures for Canada, the United States, Australia and New Zealand are set out in the Canada Privacy Supplement, United States Privacy Supplement, Australia Privacy Supplement and New Zealand Privacy Supplement. Where mandatory law of your jurisdiction requires different or additional treatment, the applicable Supplement controls to the extent of that mandatory requirement, and only to that extent; this Policy's global positions otherwise remain in full force.
1. Scope, Status and Acknowledgment
Scope of this Policy. This Policy applies to information processed in connection with the Services on surfaces Zeus operates. It does not govern all information Zeus may process: it does not apply to Third-Party Services, third-party websites, products, applications, app stores or embedded content, even where they link to or are reachable from the Services (see Section 5.2), and it addresses Customer Content that Zeus processes for a Customer only through the two-roles structure in Section 2. A point-of-collection privacy notice for the public tokenized payment and acceptance pages is a required product surface:
This Policy is a notice, not a contract; acknowledgment and consent.
This Privacy Policy is a transparency notice: it is expressly NOT part of the Zeus Global Terms of Service or any other agreement between you and Zeus, and it creates no contractual rights or warranties. By creating an account, accessing or using any part of the Services, or otherwise providing information to Zeus, you acknowledge — and, where consent is the operative legal basis in your jurisdiction, consent to — the collection, use, disclosure, storage and retention of information described in this Policy, including as this Policy is revised from time to time. Zeus records your acknowledgment at signup together with the Policy version; continued access to or use of the Services after a new version takes effect constitutes acceptance of the then-current version (Section 15).
Providing information is voluntary; consequences of refusal; sole recourse. You may choose not to provide information to Zeus; however, because the Services cannot operate without core account, business and device information, refusal may prevent or severely constrain Zeus's ability to provide the Services or your ability to use them. If you disagree with the practices described in this Policy, your sole recourse is to not access or use — or to stop accessing and using — the Services and to close your account.
Privacy-related claims sit under the Terms.
Although this Policy is not part of any agreement, any claim, dispute or controversy relating to privacy, data protection, or Zeus's information practices is a claim arising out of or relating to the Services and remains subject to the Zeus Global Terms of Service — including its limitation-of-liability, damage-exclusion and dispute-resolution provisions — as stated in the Terms.
2. Zeus's Two Roles
Zeus as accountable organization (controller) for Account Data.
Zeus is the organization accountable for — and the independent "controller"-equivalent of — Account Data: registration and login information, billing and subscription records, device Telemetry and diagnostics, security logs, support communications, and Zeus's own website and product-usage data. This Policy governs Account Data directly. The Zeus Data Processing Addendum does not apply to Account Data.
Zeus as processor/service provider for Customer-entered data; routing.
For End-Customer Data, Worker Data and other Customer Content that a Customer or its Authorized Users enter into or collect through the Services — client and job-site records, contact details, job and financial documents, photos, signatures, time entries and similar records — the Customer controls that information, and, unless otherwise required by law, Zeus processes it solely as a service provider (processor) on the Customer's behalf and instructions. If you are an Client, worker, Helper, Invited User, Link Recipient or any other individual whose information a Customer has caused Zeus to process, direct any question, concern or request about that information to that Customer (the business you dealt with): the Customer is responsible for its own privacy practices, and Zeus will refer requests concerning Customer-processed data to the relevant Customer. Data Processing Addendum cross-reference. Zeus's processor-role obligations for End-Customer Data and Worker Data are set out exclusively in the Zeus Data Processing Addendum (the DPA), and are limited to those obligations that applicable data-protection law expressly requires of a processor/service provider. Nothing in this Policy adds to, or creates independent claims in respect of, the DPA; for Account Data the DPA does not apply (Section 2.1).
3. Information We Collect
This Section describes only Zeus's verified, live data practices. Zeus does not collect information for features it does not offer: Zeus has no advertising SDKs, no advertising cookies, no audience-matching technology and no session-replay technology; no data-enrichment or credit-check practices; no call or screen recording; no background or continuous location tracking; no facial recognition; no large-language- model processing of your information; and no customer portal accounts. Zeus does use third-party product-analytics processors — PostHog Inc. (United States) for the usage telemetry described in Section 3.7, and, on the Zeus website only, Google LLC (United States) where Zeus has enabled Google Analytics — and you can switch the mobile application's share of that off at any time; and one third-party crash-diagnostics processor, Functional Software, Inc. (d/b/a Sentry) (United States), for the crash and error diagnostics described in Section 3.7, which are a service-integrity and security function of the mobile application and of Zeus's backend services and are not governed by that switch. Push notifications to the Zeus mobile applications are delivered by Google LLC (Firebase Cloud Messaging) (United States), which acts as Zeus's push-delivery processor on both Android and iOS. On iOS, Firebase Cloud Messaging in turn hands each notification to Apple Inc. (Apple Push Notification service) (United States) for delivery to the device, so Apple receives the device token and the contents of each notification in transit. Both are described in Section 3.7. Receipt text recognition uses a machine-learning engine that Zeus hosts itself, described in Section 3.8. If and when Zeus enables an additional collection practice, this Policy will be updated and its version bumped before that practice applies.
Account, billing, support and business-profile data. When you sign up for or use the Services, Zeus collects: name, email address, password (stored as a hash), phone number where provided; business name, trade, logo and settings; where Google sign-in is used, the identity claims Google sends Zeus (name, email, subject identifier); subscription, plan, trial, coupon and referral records; support tickets and communications you send Zeus; and consent records (terms-acceptance and privacy-acknowledgment timestamps with policy versions). Zeus processes login IP addresses for security and rate-limiting purposes.
Customer Content your business enters. Customers and their Authorized Users enter Customer Content into the Services: client, job-site and general-contractor records (names, phones, emails, addresses, notes, site coordinates); jobs, schedules and appointments; quotes, invoices, payment records, price-book entries and purchase orders; plans and takeoff markups; subcontractor contracts; time entries and their approval state; crews and crew membership; team-availability records (a person, a date range, and a reason drawn from a fixed list that includes vacation, sick, personal, public-holiday, training, parental, bereavement, jury-duty and unpaid leave); job checklists and to-dos; skill, certification, licence and insurance records held about the people your business works with, which may include a licence or registration number, an issuing body and an expiry date; and photos, documents and signatures. Zeus stores and processes Customer Content to provide the Services, in its processor role described in Section 2.2; responsibility for the lawfulness of that data rests with the Customer as described in Section 10.
Location Data: six snapshot purposes only; no background tracking.
Zeus collects device location only as point-in-time snapshots, only for the following six purposes, and only where the operating-system permission has been granted and the relevant feature is used:
- Photo location tagging (fallback): when a photo you capture lacks embedded GPS metadata, the app may stamp the device's current location onto that photo (foreground only).
- Clock-in/clock-out snapshots: when a worker starts or ends a tracked time entry, the app may capture the device's coordinates at that moment (best-effort; recorded as empty if permission is denied).
- GPS at signing (optional): where enabled, a signing event may record the signer's coordinates as part of the signing evidence (Section 3.6).
- Address geocoding: street addresses your business enters are converted to coordinates through Zeus's backend geocoding service (Section 5.1).
- Map-tile requests: the day-board route map fetches map tiles from the OpenStreetMap tile server directly from your device, which exposes your device IP address and the viewed map area to that third-party server (Section 5.2).
- Receipt and expense capture: where the "record where I scanned this" switch is on, the app takes a coordinate snapshot when a receipt or expense form is opened and again when a receipt is scanned, and stores it on that record. It applies to a receipt entered by hand as well as one photographed. That switch is **on by default**; it is shown on the capture screen itself rather than in settings, so it is visible to the person it applies to at the moment it applies, and an individual who turns it off has that choice remembered on that device. These coordinates, and the distance to the nearest geocoded job site, appear on the receipt and expense reports and exports available to the Account Owner.
Location capture is snapshot-only: no background location collection, continuous tracking or geofencing capability exists in the Services, and location permission is requested from you before any collection, with denial degrading the feature gracefully rather than blocking the Services. Worker location snapshots and location-tagged records are collected for and made available to the Account Owner and its authorized users as described in Section 3.7. Location Data is never used for advertising or marketing and is never sold.
Photos and media metadata; no biometric identification.
When photos are captured or uploaded through the Services, Zeus reads embedded EXIF metadata (capture time and, where present, GPS coordinates). Before a photo is stored in Zeus's cloud storage, embedded EXIF data is stripped from the stored image file; the capture time and any GPS coordinates are retained as database metadata associated with the photo and are used to match photos to nearby job sites.
Photo metadata — including capture time and location metadata — is collected and made available to the Account Owner and its authorized users. Zeus does not process photos or videos to identify any individual; if a Customer's use of imagery ever involves biometric-type data, the Customer controls that data and bears all related notice, consent and retention duties (Section 10). Photo-library EXIF scan ("Find Nearby Photos"). If you use the "Find Nearby Photos" feature and grant the photo-library permission, the app reads the EXIF location and capture-date metadata of images in your device's photo library (scoped to the access you grant) solely to suggest photos taken near a job site. This scan runs on your device; library images are not uploaded by the scan itself, and only photos you then choose to attach are uploaded.
Signatures and signing-evidence data. When a document is signed through the Services, Zeus captures and stores an append-only signing evidence record: the signer's name and contact details as entered, the signature image, IP address, device summary, content hashes of the signed document, consent records, server timestamps, and — where the optional feature is enabled — the signer's GPS coordinates at signing (Section 3.3, purpose 3). Signer identity is recorded as unverified (link/PIN-based). Signing-evidence records are designed to survive account purge as processing evidence (Section 8).
Device Data, Usage Data and Telemetry; cookies. Zeus collects: Device Data (device model, operating system and version, locale, app install identifier, error stacks and crash diagnostics); Usage Data and Telemetry (server-side product events keyed to business and user identifiers, session heartbeats while logged in, feature-usage events); and, on web surfaces, strictly necessary first-party cookies and tokens (authentication, session, security, preferences) together with the analytics cookies described in the Zeus Cookie and Tracking Policy. Telemetry is collected into Zeus's own infrastructure and is also processed by PostHog Inc. (United States), which acts as Zeus's product-analytics processor for the mobile application, the Zeus website and Zeus's server-side product events, on Zeus's instructions and for no purpose of its own. On the Zeus website Zeus additionally deploys Google Analytics; where Zeus has enabled it, Google LLC (United States) acts as a website-analytics processor and sets first-party analytics cookies. Both website analytics processors run only where the visitor has allowed analytics under the Zeus Cookie and Tracking Policy, and neither runs where the browser signals Global Privacy Control. Error stacks, crash diagnostics and a sampled share of performance traces from the mobile application, together with server-side exception and performance events from Zeus's backend services, are additionally processed by Functional Software, Inc. (d/b/a Sentry) (United States), which acts as Zeus's crash-diagnostics processor on Zeus's instructions and for no purpose of its own. Server-side events carry request metadata and environment and release identifiers; personal data is not sent by default, and credentials, tokens and other sensitive fields are redacted before transmission. Zeus does not enable Sentry's session-replay or screenshot-attachment features. No third-party advertising SDK, advertising cookie, audience-matching technology or session-replay technology runs in the Services. How optional analytics are controlled differs between the mobile application and the website. In the Zeus mobile application, product analytics are on by default, and you can turn them off at any time in Settings › Privacy › Share Usage Data; turning them off stops both collection and transmission from that device. On the Zeus website, analytics load nothing and send nothing unless you affirmatively allow them when Zeus asks on your first visit or afterwards at https://fieldzeus.com/legal/privacy-choices, where a browser sending the Global Privacy Control signal is treated as a decline. That control governs product analytics only and does not stop the crash and error diagnostics described above, which Zeus processes as a service-integrity and security function. Raw telemetry is retained for 30 days and aggregated telemetry rollups for 365 days (Section 8.5). Coordinate fields are stripped from Zeus's analytics events, and diagnostic logs are scrubbed of emails, phone numbers, addresses and coordinates at the diagnostic layer.
When you sign in to the Zeus Android application, Zeus also collects a push registration token — an identifier that the Firebase Cloud Messaging service issues to a single application install so that a message can be routed to it — together with the member and business identifiers the install is signed in as, the device platform, the time Zeus last saw the token, and, where the application is new enough to send it, that install's own identifier. Zeus keeps one such record for each install and re-registers it whenever the operating system issues the install a new token; signing out marks the record deleted, after which the token can no longer be used to reach the device. The application asks for the device's notification permission at sign-in, and that permission, together with your operating system's notification settings, governs whether a notification is shown to you.
The registration token is the personal-information element in this collection. The notifications themselves are reduced to a short work label and record identifiers before they are sent — that a job has been assigned to you and that job's own title, or that a change you made needs a decision — and carry no client name, address, phone number or email address. Delivery is performed by Google LLC through Firebase Cloud Messaging, which acts as Zeus's push-delivery processor on Zeus's instructions and for no purpose of its own and which receives the registration token and each message Zeus sends through it (Section 5.1); the Firebase software development kit in the application also generates its own installation identifier on the device. Push notifications carry work events inside your Workspace and are never used for marketing. On iOS, delivery additionally passes through Apple's Push Notification service: the application registers a device token with Apple Inc., and each notification Zeus sends is handed by Firebase Cloud Messaging to Apple for delivery. Apple therefore receives that token and the contents of each notification in transit, acting as a push-delivery party on the same terms — on Zeus's instructions, for no purpose of its own, and never for marketing.
The Zeus Cookie and Tracking Policy describes Tracking Technologies in detail.
Receipt images and OCR; no third-party OCR; no significant automated decisions.
If your business uses the expenses module, receipt images you scan are EXIF-stripped and transmitted to Zeus's own infrastructure, where Zeus's self-hosted optical character recognition service produces draft parsed values (supplier, amounts, tax, categories). Receipt content leaves your device only to Zeus's own systems: no third-party OCR or AI vendor is involved.
OCR-parsed values are Machine-Generated Output — drafts requiring your review — and Zeus gives no warranty of the readability of receipts you upload or of the accuracy or completeness of values its OCR service extracts from them, as further described in the Machine-Generated Output provisions of the Zeus Global Terms of Service. Zeus does not make decisions producing legal or similarly significant effects about any individual solely by automated means; Zeus may use automated risk signals (for example, fraud or abuse flags and rate-limiting) to protect the Services. Workforce data visibility; always-on activity logging.
If you use the Services under a business's Workspace as a Member, Helper or other Invited User, your activity, time entries and the approval or rejection of them, clock-event location snapshots, any location snapshot taken when you record a receipt or expense, assignments and crew membership, time recorded against you as unavailable together with the reason given for it, any skill, certification, licence or insurance record held about you, and other in-tenant data are collected for, and are visible to and may be monitored, processed and analyzed by, the Account Owner and its authorized administrators; you should have no expectation that in-tenant data is private from the business that invited you. Two of those are worth stating plainly. A reason for absence — which may indicate sickness, a bereavement or parental leave — is recorded by whoever schedules work and, once recorded, is readable by every user of that Workspace rather than by managers alone, because it is shown on the shared planning board. And a pay rate, the hours approved against it and the resulting pay total are readable by, and exportable by, the Account Owner and the administrators it authorizes. Zeus does not decide who inside a business may see either; the business does, and Section 10.2 places the notice and authorization duties for both on it. No in-tenant "private" setting defeats the Account Owner's access: content you submit within the Workspace may be accessed, copied and processed by the business's administrators. The Services maintain an always-on, append-only activity and audit log that users cannot disable. The business you work for — not Zeus — decides how these features are used and is responsible for all workplace-monitoring notices and authorizations (Section 10.2).
4. How We Use Information
Purposes of use. Zeus uses the information described in Section 3 to: (a) provide, operate, maintain, secure and support the Services, including authentication, synchronization, document generation and sending, and the features you or your business enable; (b) administer accounts, plans, subscriptions, trials, coupons and the referral program; (c) process security-purpose data, including login IP addresses for rate limiting and abuse prevention, and automated fraud/abuse risk signals; (d) monitor, analyze and improve the Services using the analytics and Telemetry and to develop new features and products, including through Aggregated Data (Section 13); (e) communicate with you as described in Section 11; (f) comply with law, enforce the Zeus Terms of Service and other Zeus policies, and establish, exercise or defend legal claims; and (g) for any other lawful purpose, or other purpose that you consent to.
Zeus may also process information for any other lawful purpose, or other purpose that you consent to. Security-purpose processing includes automatically processing login and request IP addresses and related signals to detect fraud, abuse and unauthorized access.
5. How We Disclose Information
Service providers and Subprocessors.
Zeus discloses information to service providers that host and support the Services. Zeus's current Subprocessors and infrastructure providers are listed on the published subprocessor page at https://fieldzeus.com/legal/subprocessors, which currently comprises: Cloudflare, Inc. (network and security edge, and R2 object storage, region-pinned as described in Section 6.2; and the Cloudflare Turnstile bot challenge on sign-up, sign-in, password reset, partner registration and the public booking-request page, which sends Cloudflare a challenge token and the connecting IP address of the device solving it and nothing else); Resend, Inc. (transactional and document email delivery, United States); Geocodio (Dotsquare LLC) (conversion of the street addresses your business enters into coordinates for United States and Canadian addresses, United States), with the OpenStreetMap Nominatim service of the OpenStreetMap Foundation used for addresses outside those two countries, which are processed in Europe; PostHog Inc. (product analytics and usage telemetry, United States); Functional Software, Inc. (d/b/a Sentry) (crash and error diagnostics for the mobile application and for Zeus's backend services, with a sampled share of performance traces from the mobile application only — server-side performance tracing is switched off, United States); RevenueCat, Inc. (subscription and entitlement records for Zeus's own paid plans, United States); Google LLC (Google Analytics — website analytics for the Zeus website, where Zeus has enabled it and only where the visitor has allowed analytics, United States); Google LLC (Firebase Cloud Messaging — delivery of push notifications to the Zeus mobile applications, and the device registration tokens that make delivery possible, United States); Apple Inc. (Apple Push Notification service — delivery of push notifications to the Zeus iOS application, and the device tokens that make delivery possible, United States); and Google and Apple (identity providers, if you sign in with Google or with Apple). Zeus's receipt OCR processing is self-hosted (Section 3.8) — no OCR vendor exists to list.
Using a feature constitutes your ongoing consent to the disclosure of the associated information to that feature's Subprocessors — for example, photo backup discloses photo data to Zeus's storage provider, sending a document by email discloses recipient and content data to Zeus's email provider, and entering an address discloses it to Zeus's geocoding provider. No opt-out is available for providers Zeus deems critical to the Services, such as infrastructure, security, and fraud or abuse prevention. The subprocessor list may change over time; publication of the change on that page is the exclusive notice channel for subprocessor changes, and you are responsible for checking it. Third-Party Services are outside this Policy.
This Policy does not apply to — and Zeus is not responsible for — the personal- information practices of Third-Party Services, third-party websites, products, applications, app stores, embedded content or links, even where they link to or are reachable from the Services; you should review those third parties' own privacy policies carefully. This includes, today: the OpenStreetMap tile server (which receives your device IP address and viewed map area directly from your device when you use the route map); Google Maps (which receives a destination address or coordinates, and your device IP address, when you tap through for driving directions); YouTube (which receives device traffic when you play an embedded help video); Apple and Google app-store and review services; and your own device's SMS, dialer and email applications when you send messages from your device (Section 11.3).
Legal process, protection of rights, and lawful access.
Zeus reserves the right to access, read, preserve and disclose any information — including Personal Information and Customer Content — where Zeus believes, in its sole discretion, that doing so is appropriate or necessary to: (a) satisfy or comply with any applicable law, regulation, legal process or governmental request; (b) enforce the Zeus Terms of Service and other Zeus policies, including investigating potential violations; (c) detect, prevent or address fraud, abuse, security or technical issues; (d) collect amounts owed to Zeus; (e) respond to support requests; or (f) protect the rights, property or safety of Zeus, its users or the public. Such disclosures may be made to government or law-enforcement officials or to private parties, and Zeus makes no commitment to notify you before or after any such disclosure. Because information is stored and processed in the United States, Canada and other locations (Section 6), it may be subject to preservation or disclosure obligations under the laws of those jurisdictions, including lawful access by foreign courts, law enforcement and governmental authorities, and Zeus and its Subprocessors may disclose information without your consent where they believe in good faith that the law requires or permits it. Access by Zeus personnel (support access).
Zeus staff can access your Workspace to answer a support request or investigate a problem. Routine questions are answered from a read-only operator view of your account, which includes your business record; your team members with their names, email addresses and roles; your plan, subscription and entitlement records; how recently your devices synchronized; counts and recent entries for your clients, jobs, quotes, invoices and photos; your signature and support-ticket records; and your recent account-activity log. Where a question cannot be answered that way, a Zeus operator can open a time-limited support session and use the Services as one of your users. A support session must be tied to an existing support ticket, and to a ticket that does not belong to a different business. It is recorded as resting either on consent you gave or on an emergency ("break-glass") access where your consent could not be obtained in time. It is limited to the areas of the Services chosen when it is opened — clients and job sites, jobs and timesheets, quotes, invoices and receipts, documents and photos, or your business profile, user profile and preferences — and it cannot reach sign-in and account security, billing, the device synchronization interface, your team roster and permissions, or account export and deletion. It expires within thirty minutes of being opened and cannot be extended or renewed. It changes nothing in your account unless a Zeus operator separately approves that single change while the session is live.
Every access of either kind is recorded in Zeus's operator audit log, which is append-only and enforced as such by the database; a request whose audit record cannot be written is refused rather than performed unrecorded. Changes made in a support session are also written to your own business's audit trail. When a support session is opened, Zeus emails the user whose access is used, identifying the support case and the session, whether the session rests on consent or on break-glass, what it is limited to and when it expires; that email is sent on a best-effort basis and a delivery failure does not stop the session. Zeus does not currently provide a screen in the Services where you can read this access history yourself — Section 9 explains how to make an access request. The Zeus Security and Trust Statement describes these controls in more detail. Business transfers.
Zeus reserves the right to disclose and transfer information — including Personal Information and Customer Content — to third parties as part of, or in diligence for, any potential or actual business or asset sale, merger, acquisition, amalgamation, consolidation, investment, round of funding, financing, reorganization or similar transaction, including before closing. Information may likewise be disclosed and transferred in the event of insolvency, bankruptcy, receivership, liquidation or dissolution proceedings, as part of the sale or reorganization process. Any acquirer or successor will be subject to the obligations of this Privacy Policy as it applies to the transferred information. Supplier directory and listing flows (conditional). If and when Zeus makes a supplier directory, catalogue or similar listing feature available and you choose to contact or share your details with a listed third-party business, the information you share with that business is governed by that business's own privacy practices and policies, not by this Policy, and Zeus does not control that business's use of your information. No such feature is enabled today.
No sale of Personal Information; no third-party marketing sharing.
Zeus does not sell Personal Information, and no mobile information, SMS opt-in data or consent records will be shared with third parties or affiliates for their marketing or promotional purposes; disclosure to Subprocessors supporting the Services (Section 5.1) is permitted. Location Data is never used for advertising and is never sold or shared for advertising purposes. These statements describe Zeus's actual practices (they mirror the statement shipped in the live in-app legal pack); they are not a contractual warranty (Section 1.2), and if Zeus's practices ever change this Policy will be updated first (Section 15).
6. International Transfers and Storage Locations
Consent to cross-border transfer; weaker-law acknowledgment.
By using the Services or submitting information — and this applies expressly to users located in Canada, Australia and New Zealand — you consent to the transfer, storage and processing of your information in the United States, in Canada, and in any other location where Zeus or its service providers maintain facilities. You acknowledge that the laws of those jurisdictions may be less protective than the data-protection laws of your home jurisdiction and that your information may be subject to lawful access by courts, law enforcement and governmental authorities in those jurisdictions. If you do not consent to these transfers, you must not use the Services; your continued use constitutes consent. European Union / United Kingdom transfer mechanisms (standard contractual clauses, adequacy frameworks) are outside the scope of this Policy at this time: Zeus's launch jurisdictions are Canada, the United States, Australia and New Zealand, and Zeus makes no representation regarding EU/UK transfer frameworks.
Storage locations as fact; no data-residency warranty; relocation.
As a statement of current practice: Zeus's primary application data and object storage are hosted with Zeus's infrastructure providers with object storage region-pinned to an Eastern North America region, and Zeus's self-hosted OCR processing runs on Zeus's own infrastructure.
Zeus makes NO warranty that any specific hosting or storage location will be used or maintained or that a storage region will meet your data-residency requirements; the current-practice statement above is not a residency commitment. Regardless of storage region, traffic to and from the Services is processed at the network-edge data center closest to the connecting device, and copies of data may exist transiently or in backups, diagnostics and support tooling outside the primary region. Zeus may migrate accounts and relocate data between cloud facilities and regions at any time.
7. Security
Safeguards; no guarantee of security.
Zeus maintains commercially reasonable administrative, technical and physical safeguards designed to protect information under its control.
However, no system is perfectly secure: Zeus does not guarantee that unauthorized third parties will never defeat its safeguards or that information will never be accessed, disclosed, altered, lost, corrupted or destroyed, and you acknowledge that you provide your information at your own risk. To the maximum extent permitted by law, Zeus makes no warranty, express or implied, regarding the security of the Services, including with respect to the ability of unauthorized persons to intercept or access information transmitted through them. You acknowledge that the internet and telecommunications networks are inherently insecure and that Zeus will have no liability for any changes to, interception of, or loss of information while in transit over them. Zeus is not responsible for security issues that arise from Customer Content, Third-Party Services or applications, your own access administration, credential misuse or sharing, phishing of you or your users, your device configuration (including Offline Data on your devices), or circumvention of Zeus's measures. What Zeus's safeguards actually are; Security Statement. Zeus's verified current safeguards include: multi-tenant isolation enforced at the application and database level; append-only, hash-chained audit logs enforced by the database; append-only payment records; operating-system-level device encryption plus the application sandbox and secure keystore for tokens on mobile devices; application-layer encryption of the mobile application's local database using SQLCipher with a per-install key held in the platform secure keystore, which continues with an unencrypted local database on a device where the cipher library or the keystore is unavailable; PII scrubbing of diagnostic logs; and rate limiting and abuse controls. The Zeus Security and Trust Statement describes practices in more detail; it is a point-in-time, informational description only, does not constitute legal advice, is not incorporated into any agreement, and is subject to change without notice.
8. Retention and Deletion
Retention standard; Zeus sets retention parameters.
Zeus retains information for as long as reasonably required for the purposes described in this Policy, unless a longer retention period is required or permitted by law. Zeus may establish, and may change at any time, general practices and limits concerning use and storage, including the maximum period of time that data or content will be retained by the Services. Extended retention grounds.
Zeus may retain information beyond account closure or a deletion request — for a reasonable period or as long as the ground persists — for backup and archival cycles, fraud and abuse prevention, security, dispute resolution, enforcement of the Zeus Terms of Service and other agreements, establishment and defense of legal claims, legal and regulatory compliance, and other legitimate business purposes. Zeus may retain information for a longer period in the event of a complaint or where Zeus reasonably believes there is a prospect of litigation in respect of its relationship with you. Account deletion is two-phase; export first; what survives.
You can delete your account in-app (Profile → delete account) and can export your Workspace data in-app before doing so; export before deletion is solely your responsibility.
Account deletion is two-phase: the first phase immediately deactivates the account and revokes sessions; the second phase permanently purges account rows and stored objects on Zeus's schedule, which Zeus runs as soon as reasonably practicable — Zeus commits to no fixed automatic purge timing. Zeus's audit logs and its record that an erasure was performed are append-only and survive account purge by design, as evidence of the orderly and accurate processing of data, and are retained after termination or deletion. Other append-only records — including invoices, payments, signing evidence and the client communication timeline — cannot be edited or deleted while your Workspace exists, but they are erased with the rest of your Workspace's records on account purge; see Section 5 of the Zeus Data Retention and Deletion Policy, which governs what survives a purge. On or after account closure Zeus may delete, archive, retain or anonymize Customer Data in accordance with its policies and applicable law. Backups, residual copies, and uninstalling the app.
Backup copies are excluded from targeted deletion and are destroyed on Zeus's standard backup-rotation schedule, due to the cost and technical difficulty of deleting from backups. It is not technologically possible to remove each and every record of the information you have provided; residual copies may persist in systems and archives, and complete erasure cannot be assured. Uninstalling the mobile application deletes nothing server-side: Zeus may retain collected data after uninstallation, and the local on-device copy of Workspace data (Offline Data) remains on your device under your control until you remove it. Retention schedule (current parameters). Zeus's current retention parameters, published for transparency and subject to Section 8.1, are: raw device/session Telemetry — 30 days; aggregated synchronization-telemetry rollups — 365 days; photos after a plan downgrade — a 60-day grace period, at or after the end of which full-resolution files are reduced to thumbnails (thumbnails and records are retained, not hard-deleted); Zeus's own customer, billing and tax records — the statutory retention periods of the applicable jurisdiction (typically six to seven years); records inside your Workspace, including invoices and payments — for the life of the Workspace, then removed on account purge; account data after deletion — until the post-deletion purge. Zeus publishes a period only where a scheduled job enforces it; everything else is retained for as long as necessary for the purposes described in this Policy. The Zeus Data Retention and Deletion Policy carries the authoritative schedule.
Data after subscription end or termination.
Exporting your data before cancellation or termination is solely your responsibility; after termination Zeus has no obligation to maintain, retain or provide Customer Data, any post-termination retrieval window is discretionary and may be ended by Zeus at any time with or without notice, and Customer Data may thereafter be deleted. Zeus shall be entitled, except to the extent legally prohibited, to delete Customer Data by deleting the account. Offline Data remaining on your devices after termination is outside Zeus's systems and control; securing or deleting it is your responsibility.
9. Your Rights and How to Exercise Them
Rights exist as provided by applicable law and are not absolute.
Depending on your jurisdiction, you may have rights of access, correction, deletion, portability and objection or consent-withdrawal in respect of your Personal Information; these rights exist as provided by applicable law, are not absolute, and in some cases Zeus may limit or deny a request because the law permits or requires it, or because your identity cannot be adequately verified. The jurisdiction-specific rights, procedures and statutory response timelines for Canada, the United States, Australia and New Zealand are set out in Supplements 21–24.
Requests about Customer-processed data are routed to the Customer.
Zeus cannot honor requests concerning End-Customer Data, Worker Data or other Customer-processed information directly from Clients, workers or other individuals; those requests must be directed to the relevant Customer, and Zeus will assist that Customer in honoring them. Where a request reaches Zeus, Zeus may instruct you on how to fulfill it yourself through in-product self-service, refer you to the relevant Customer or its account administrators, or require additional information and documents before acting. Assistance Zeus provides to a Customer in connection with data-subject requests is provided at the Customer's expense as described in the DPA. Self-service channels first. For Account Data and your own Workspace, the designated request channels are the in-product tools: you can review and update profile and business information in-app, export your Workspace data in-app (Account → Export Data), and delete your account in-app (Section 8.3). Requests that in-product self-service can fulfill should be made through those tools; other requests may be sent to [email protected] or by mail to 3601 Highway 7 East, Suite 1006, Markham, Ontario, L3R 0M3, Canada.
Identity verification is a precondition.
Identity verification may be required before any data-rights request is fulfilled; failure to verify may result in denial of the request. Zeus may request up to three pieces of personal information to compare against its records, may ask for copies of relevant identity documents, and may take additional fraud-prevention steps. Where a request is made through an authorized agent, Zeus requires your written permission to the agent and direct verification of your identity with Zeus; failure to provide either may result in denial. Refusal grounds, fees, redaction and timing.
Zeus may refuse requests where allowed under law, including requests that are manifestly unfounded or excessive. Zeus may decline to process requests that are unreasonably repetitive, require disproportionate technical effort, jeopardize the privacy of others, are extremely impractical, or for which access is not otherwise required by local law, and may advise you accordingly where a request is frivolous or vexatious or cannot reasonably be processed in the manner requested. Where permitted by law, Zeus may charge a reasonable fee — or refuse to comply — where a request is clearly unfounded, repetitive or excessive. In certain limited circumstances Zeus may not be able to make all relevant information available, such as where information also pertains to another user or third party, in which case disclosures may be limited or redacted. Zeus responds within the timeline applicable law requires and reserves any extension that law allows.
Consent withdrawal and its limits.
Where processing is based on consent, you may withdraw consent at any time; however, withdrawal does not affect processing that occurred before withdrawal, and Zeus reserves the right to continue processing to the extent required or permitted by law. Because core processing is necessary to operate the Services, withdrawing consent may result in your inability to continue using the Services. You may not opt out of administrative or transactional communications (Section 11.1). Deletion-request carve-outs.
Zeus may decline to fulfill a deletion request, in whole or in part, where Zeus or its service providers are required or permitted to retain the information for enumerated purposes — including completing transactions and providing the Services; security, fraud and abuse prevention; debugging; legal compliance; establishing or defending legal claims; and internal uses compatible with the context in which the information was provided. Deletion is further subject to the two-phase mechanics, backup rotation, residual-copy limits and audit/financial-record survival described in Section 8, and Aggregated Data survives deletion as described in Section 13.
10. Business-Customer Responsibilities
The Customer's consent, notice and lawfulness duties.
Each Customer represents and warrants, on a continuing basis, that it has obtained and will maintain all legally and contractually required notices, consents, permissions and lawful bases for all information it or its Authorized Users submit to or collect through the Services — including End-Customer Data and Worker Data — and for its transfer to and processing by Zeus in the United States and Canada. The Customer is solely responsible for the accuracy, quality and legality of that information and of how it was acquired, for providing all legally required privacy notices to its own customers, employees, contractors and Authorized Users, for maintaining lawful bases, and for handling data-subject requests directed to it. The operative representations, warranties, prohibited-data rules and indemnities appear in the Zeus Terms of Service, Acceptable Use Policy and DPA; this Section summarizes them for transparency to individuals.
Workforce records belong to the business; monitoring authorizations.
Workforce records created under a business's Workspace — time entries, clock-event location snapshots, photos, assignments and crew membership, recorded absences and the reason given for them, skill and certification records, and activity data — belong to the business that owns the account, not to the individual users who created them, and location and time data are used to provide the Services to that business. Zeus is not permitted to delete those records at the request of an individual worker; workers should direct deletion and other requests to their employer or account administrator. The Customer is responsible for compliance with employment, workplace-monitoring, privacy, surveillance and consent laws applicable to its use of these features, and must obtain all requisite approvals and authorizations from its personnel for the creation, display, analysis and distribution of the data they generate. Location, photo, media and field-data consents; accuracy disclaimer.
Before enabling or using any location-dependent feature, and before collecting or processing location, GPS, photo, media or field data through the Services, the Customer represents and warrants that it has provided all required notices and obtained all required consents from employees, contractors, subcontractors, clients, property owners and other affected individuals, and the Zeus Acceptable Use Policy prohibits using location-based features without legally required notice and consent. Location, time and field data may be inaccurate, unavailable, delayed or incomplete, and may be affected by device settings, permissions, network conditions, user behavior, GPS limitations and third-party systems; Zeus disclaims all warranties that such data will be accurate, available, timely or complete. Zeus's liability for Customer-processed personal data.
Zeus explicitly disclaims any liability for the loss, disclosure or misuse of any personal data processed, uploaded or transmitted through the Services, except to the extent that such liability cannot be excluded or limited by law.
11. Communications and Marketing
Service and administrative communications are mandatory. Zeus sends service and administrative communications in connection with the Services. These are dispatched by email from Zeus's servers through its email delivery Subprocessor (Resend, United States — Section 5.1), and, where your business triggers them, include document-delivery messages (quote, invoice, purchase-order, signing and payment-link emails) sent at your direction (Section 11.3).
Service and administrative communications include account and email-verification notices, password and credential notices, security incident alerts, security and privacy update notifications, billing, subscription, trial and renewal notices, technical notices, and legal notices including notices of changes to the Terms or this Policy. You cannot opt out of service and administrative communications: they are integral to your use of the Services, and unsubscribing from marketing communications will not prevent you from receiving administrative messages regarding the Services or stop Zeus contacting you regarding administrative matters and your own requests. Where the mandatory law of your jurisdiction draws the transactional/commercial boundary differently, the applicable Supplement (21–24) controls to the extent of that mandatory requirement.
Marketing communications: opt-out only.
Zeus may communicate with you about products, services, features, offers and events we think may interest you; you can opt out of marketing communications at any time by following the unsubscribe instructions contained within the message or by contacting [email protected]. You may continue to receive marketing messages for a short period while an opt-out request is processed, and a marketing opt-out never applies to the service and administrative communications described in Section 11.1. Where the mandatory law of your jurisdiction requires express consent before marketing messages are sent (for example under Canadian anti-spam legislation or the Australian and New Zealand Spam Acts), Zeus sends marketing only on a lawful basis for that jurisdiction, as described in the applicable Supplement (21–24).
Messages your business sends through the Services. The Services let your business communicate with its own Clients, Helpers and suppliers in two ways, both at your direction: (a) device-originated SMS, phone calls and emails (invoice sends, "on the way" notifications, Order Supplies orders, Helper invites) composed in the Services but sent from your own phone's dialer, SMS and mail applications over your own carrier or mail account — Zeus's servers send no SMS; and (b) server emails (quote, invoice, purchase-order, signing and payment-link emails) that Zeus dispatches at your direction through Resend.
Your business is the sender and originator of every such communication, regardless of how it is transmitted, and is responsible for all such messages, including those sent by its employees, Members, Helpers, contractors or other users. Your business — not Zeus — must obtain all necessary consents from the recipients of its communications, and Zeus is not liable for communications your business sends to its users, employees, contractors, or potential or actual customers. The Customer's consent, lawfulness and record-keeping duties for these communications are set out in Section 10.1 and in the SMS, Email and Messaging Terms, which governs messaging conduct in full.
Messaging data and delivery providers.
Zeus does not sell, rent or share mobile telephone numbers, SMS opt-in or consent status, or related messaging consent data with third parties or affiliates for their own marketing or promotional purposes (Section 5.6); Zeus may share such information with service providers that assist in the delivery of messages — for Zeus today that is its email delivery Subprocessor (Resend, United States) — acting on Zeus's instructions.
12. Security Incident Response
What counts as a Security Incident.
A "Security Incident" is a confirmed unauthorized access to or disclosure of personal data processed by Zeus; Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of personal data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks and similar events. How and when Zeus notifies; no admission.
Zeus will notify affected Customers without undue delay after confirming a known or reasonably suspected Security Incident affecting their personal data, to the extent notification is required by applicable law, using the contact details provided under the Customer's account. The Customer is solely responsible for ensuring that its notification contact details are valid and accurate; incidents not specific to a particular Customer may be communicated through Zeus's status, blog or equivalent public channels. Zeus will take the remediation steps it in its sole discretion deems necessary and reasonable, within measures reasonably within its control, and no notification of or response to a Security Incident is or will be construed as an acknowledgment by Zeus of any fault or liability. Nothing in this Section limits any notification, record-keeping or reporting duty that applicable law imposes on Zeus and that cannot be excluded — including the statutory breach regimes of the launch countries, which are summarized in Supplements 21–24. Those duties are preserved in full.
Incidents involving Customer-processed data; carve-outs.
For End-Customer Data and Worker Data that Zeus processes for a Customer (Section 2.2), any and all regulatory and data-subject reporting obligations, decisions and filings related to a Security Incident are the responsibility of the Customer, as the party best placed to assess whether and to whom the incident must be reported; the DPA governs Zeus's processor-role incident duties and assistance. Zeus's incident-response obligations do not apply to incidents caused by the Customer, its Authorized Users or anyone using the Services on the Customer's behalf, or misuse of the Customer's access credentials, and Zeus's liability is excluded for incidents arising from Customer actions, third-party conduct outside Zeus's reasonable control, or force majeure, in each case to the maximum extent permitted by law. The Customer's own duty to notify Zeus of suspected incidents on its side is set out in the Terms.
13. Aggregated and De-Identified Data
Aggregated Data is not Personal Information.
Zeus may create, collect, use, disclose and share aggregated, anonymized and de-identified data derived from Customer Content, Personal Information and use of the Services — such as statistical or demographic data — for any purpose; the license and ownership terms for such data are set out in the Terms. Aggregated Data may be derived from your Personal Information but, once aggregated or de-identified so that individuals cannot be re-identified, it is not Personal Information and this Policy does not apply to it. Survival, benchmarks and the savings pack.
Zeus may continue to use Aggregated Data that does not identify any individual during and after your use of the Services — including after account deletion, a deletion request or withdrawal of consent (Section 8.3). Zeus may use Aggregated Data to improve and develop the Services and new products, and to generate market-research statistics, industry insights, benchmarks, reports and recommendations across its customer base, and may surface those insights and recommendations to other users of the Services. Aggregated Data will never identify your business, your clients or any individual; one account's underlying data is never exposed to another account; Zeus maintains and uses such data in de-identified form and will not attempt to re-identify it, except where necessary to satisfy requirements under applicable law; disclosure to third parties is limited to non-identifiable form; and no sale of data is made (Section 5.6).
14. Age Requirement and Children
The Services are for adults (18+); no knowing collection from children. The Services are business tools offered for use by field-service and construction businesses; they are not directed to children.
By using the Services, you represent that you are at least 18 years of age (or the equivalent age of majority specified by law in your jurisdiction); if you are under 18 or the age of majority you must not use the Services. Zeus does not knowingly collect data from or market to children under 18 years of age, and if Zeus learns that an account is held by a person under that age it will close the account and delete the associated Account Data as described in Section 8. If your business enters Personal Information about a minor into the Services as Customer Content (for example inside a client record), your business is solely responsible for the lawfulness of that collection, as described in Section 10.1 and in the Acceptable Use Policy's regulated-data rules.
15. Changes to this Policy
Zeus may revise this Policy; posting makes it effective.
Zeus may revise this Policy from time to time; changes are effective immediately upon posting of the updated Policy with a new version date, and each revision is recorded under a new policy version (see Section 1.2). Unless stated otherwise, the then-current Policy applies to all Personal Information Zeus holds, including information collected before the change. Continued use of the Services after a revision takes effect constitutes acceptance of the revised Policy; you should review this page periodically to remain familiar with the current version, and for material changes Zeus may additionally notify you by prominently posting a notice or by sending you a direct notification. Where the mandatory law of your jurisdiction limits the application of a revised policy to previously collected Personal Information or requires fresh consent for a new purpose, the applicable Supplement (21–24) controls to the extent of that mandatory requirement.
16. Contact, Accountability and Complaints
How to contact Zeus about privacy. Questions, concerns and requests about this Policy or Zeus's handling of Personal Information should be directed to:
Omni Data Tech Inc. Attn: Privacy Officer 3601 Highway 7 East, Suite 1006, Markham, Ontario, L3R 0M3, Canada Email: [email protected]
Your message should provide evidence of your identity and set out the details of your request (such as the Personal Information or the correction requested), as described in Sections 9.3 and 9.4.
Accountability and complaints. Zeus has designated its Privacy Officer (contact details in Section 16.1, above) as the individual accountable for Zeus's compliance with applicable privacy law. If you believe Zeus has not handled your Personal Information in accordance with this Policy or applicable law, contact Zeus first using the details in Section 16.1; Zeus will investigate complaints it receives. The regulator complaint routes, statutory escalation rights and jurisdiction-specific accountability disclosures for Canada, the United States, Australia and New Zealand are set out in Supplements 21–24.