Privacy Policy
How we collect, use and protect information from this website and from Meta assets that a business client chooses to connect to the ZAF platform.
Last updated:
1. Overview
This Privacy Policy explains how ZAF ("we", "us") collects, uses and protects information when you visit this website, submit an enquiry, or contact us through WhatsApp or email. It is written to be understood, not to hide behind legal language.
We process personal data in line with the Personal Data Protection Act 2010 (Malaysia) and applicable data-protection principles.
2. Information we collect
We collect information in three ways:
- Information you provide directly — for example your name, company, work email, phone or WhatsApp number, and the details of your project when you submit our enquiry form or message us.
- Information collected automatically — technical data such as IP address, browser type, device, pages visited, referring website and approximate location, collected through analytics and advertising technology described below.
- Marketing attribution data — campaign parameters attached to the link you used to reach us (for example UTM parameters and advertising click identifiers), which we store in your browser so we can understand which marketing activity led to your enquiry.
3. Enquiry and lead forms
When you submit the project enquiry form, the information you provide is transmitted securely to our server, validated, and recorded in our customer relationship management (CRM) system so we can respond to you. Attribution data (campaign source, landing page and referrer) is stored with your enquiry so we can measure the effectiveness of our marketing.
We use this information to respond to your enquiry, prepare proposals, and — where you have agreed — keep you informed about relevant services. We do not sell your information.
4. AI marketing platform and connected Meta data
When a business client chooses to connect its Meta account, an authorised user signs in through Meta and selects the Facebook Pages, Instagram accounts and other business assets that ZAF may access. The client retains ownership and control of those assets.
Depending on the features the client enables and the permissions it grants, the platform may process the following categories of connected data:
- Facebook Page and Instagram account information, published content and content performance.
- Advertising campaigns, ad sets, ads, delivery status, spend and performance insights.
- Messages, conversations and comments associated with authorised business accounts, so the client's team can manage customer enquiries.
- Leads, lead status, sales outcomes and attribution data supplied by the client or its connected business systems.
- Draft content, publishing schedules and approval records created by authorised users in the platform.
5. How we use connected platform data
ZAF uses connected Meta and business data only to provide the service requested by that client. This includes displaying campaign results, organising customer enquiries, tracking leads and sales, preparing or scheduling client-approved social posts, producing reports, generating marketing recommendations, maintaining security and providing support.
We do not sell connected client data, use one client's private data for another client, or take ownership of a client's Meta assets. AI-generated recommendations are decision support; publishing and campaign actions remain subject to the client's authorised users and approval settings.
6. Client control, disconnection and deletion
Clients decide which assets to connect and which available permissions to grant. Access can be removed through the client's Meta business settings or by asking ZAF to disconnect the integration. When access is removed, the platform stops retrieving new data from the affected assets.
A client may request deletion of connected account data by following the instructions on our Data Deletion page. We will remove data that we are not required to retain for security, contractual or legal reasons and will confirm when the request has been completed.
7. Analytics
We may use analytics tools to understand how visitors use the site — which pages are viewed, how long visitors stay, and how they arrived. This information is aggregated and used to improve the website and our services.
8. Advertising technology (Meta Pixel and Conversions API)
We use the Meta Pixel and the Meta Conversions API to measure the effectiveness of advertising on Meta platforms (Facebook and Instagram). These tools record events such as page views, form submissions ("Lead") and clicks on our WhatsApp button ("Contact").
For Conversions API events sent from our server, certain information — such as your email address and phone number when you submit an enquiry — is hashed (irreversibly transformed) before it is transmitted, together with technical data such as IP address, browser user agent and Meta browser identifiers. Meta uses this information to match events to advertising and to report campaign performance. Meta's use of this data is governed by Meta's own data policy.
Where consent for advertising cookies is required, these tools are only activated after you accept them.
9. Cookies and local storage
The website uses cookies and browser local storage for the following purposes:
- Attribution — remembering the campaign that brought you to the site (first and last visit) so an enquiry can be linked to it.
- Advertising measurement — Meta browser identifiers (_fbp, _fbc) used to match events to advertising.
- Consent — remembering your cookie preferences where a consent banner is shown.
- Essential functionality — security and rate-limiting protections on our forms.
10. API integrations and service providers
We use third-party services to operate the website and process enquiries — for example hosting, CRM, email delivery and advertising platforms. These providers process information only for the purpose of providing their service to us, under their own privacy terms. We select providers that apply appropriate security controls.
11. How we handle and protect data
Enquiry data is transmitted using encrypted connections, stored in access-controlled systems, and accessed only by people who need it to respond to you. API credentials used to integrate with third-party systems are kept on the server and are never exposed in the browser.
We keep personal data only as long as necessary for the purposes above, or as required by law, and remove it when it is no longer needed.
12. Your rights and how to contact us
You may request access to the personal data we hold about you, ask us to correct it, or ask us to delete it where we have no legal reason to keep it. You may also withdraw consent to marketing at any time.
To make a request, contact us using the details on our Contact page. We will respond within a reasonable period and may need to verify your identity before acting on a request.
13. Changes to this policy
We may update this policy from time to time. The date of the latest update is shown at the top of the page. Significant changes will be highlighted on the website.