Legal
Privacy Policy
This policy explains what personal information Zivoke collects when you visit zivoke.com or work with us on a Salesforce engagement, how we use it, who we share it with, and the choices you have.
1. Who we are
Zivoke LLC (“Zivoke”, “we”, “us”) is a Salesforce consulting partner headquartered in New York, with a UK office in London. We provide Salesforce consulting, implementation, integration, custom development, managed support, staff augmentation and AI consultation services.
Zivoke is the controller of the personal information described in this policy, except where we handle information inside a client’s systems on that client’s instructions — see Client data in your Salesforce org.
- Company
- Zivoke LLC
- Address
- 447 Broadway, 2nd FL #198, New York, NY 10013, United States
- info@zivoke.com
- Phone
- +1 (347) 254 7642
2. Scope of this policy
This policy covers the zivoke.com website, our contact and enquiry forms, the Salesforce Health Check self-assessment, consultation bookings, email and phone correspondence, and the business relationships we have with clients, prospects, partners and suppliers.
It does not cover the privacy practices of Salesforce, AppExchange vendors or any other third-party platform you use. Those services are governed by their own agreements and privacy notices.
3. Information we collect
Information you give us
- Contact details — name, work email, phone number and company name submitted through our enquiry forms or booking pages.
- Project context — what you tell us about your goals, current systems, industry and the challenge you want to work through, including the answers you give in the Salesforce Health Check.
- Correspondence — emails, call notes, meeting records and support requests exchanged during an engagement.
- Engagement and billing records — statements of work, purchase orders, invoices and payment references for client organizations.
- Recruitment information — if you apply for a role with us, the details in your application and CV.
Information collected automatically
- Device and usage data — IP address, browser type, operating system, pages viewed, referring page and timestamps.
- Cookies and similar technologies — see Cookies and analytics.
We do not ask you for special categories of personal data (such as health or biometric information), and we ask that you do not send such information to us through our website forms.
4. How we use information
- To respond to enquiries, answer questions and schedule consultations.
- To scope, deliver, support and improve the services set out in an agreement or statement of work.
- To administer our business — contracts, invoicing, accounting and record keeping.
- To send service communications, and, where you have asked for them or where permitted by law, occasional insights and updates. Every marketing email includes an unsubscribe link.
- To operate, secure and improve our website, including troubleshooting and measuring which content is useful.
- To meet legal, tax and regulatory obligations, and to establish or defend legal claims.
We do not sell personal information, and we do not use the information you share with us to build profiles for third-party advertising.
5. Legal bases
Where the EU or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to deliver the services you or your organization have engaged us for, and to take steps at your request before entering a contract.
- Legitimate interests — to run and promote our consulting business, respond to enquiries, keep our services secure, and understand how our website is used, balanced against your rights.
- Consent — for optional analytics and for marketing emails where consent is required. You can withdraw consent at any time.
- Legal obligation — where we must retain or disclose information to comply with the law.
6. Client data in your Salesforce org
During an engagement we may be granted access to a client’s Salesforce environment or connected systems, which can contain personal data about that client’s customers, employees or contacts. In that situation the client remains the controller of that data and Zivoke acts as a processor or service provider, handling it only on the client’s documented instructions and under the terms of the applicable agreement or data processing addendum.
- We request the minimum access needed for the work, and we use named accounts rather than shared credentials.
- We work in sandboxes or with anonymised sample data where practical, and we do not copy client data to systems outside the agreed scope.
- Access is removed when the engagement or the relevant phase ends.
- We do not use client data for our own purposes, including training models or marketing.
If you are an individual whose data sits in a Zivoke client’s Salesforce org and you want to exercise your rights over it, please contact that organization directly; we will support them in responding.
9. International transfers
Zivoke operates in the United States and the United Kingdom, and some of our service providers process data in other countries. Where we transfer personal information out of the EEA, the UK or another region with transfer restrictions, we use an appropriate safeguard such as the European Commission’s Standard Contractual Clauses, together with technical and organizational controls suited to the data.
10. How long we keep information
- Enquiries that do not become engagements — normally up to 24 months from the last contact.
- Client records, contracts and project documentation — for the life of the relationship and then as required for legal, tax and audit purposes, normally up to 7 years.
- Website analytics — in aggregated or pseudonymised form, according to the retention settings of the analytics tool.
- Access to client systems — removed at the end of the engagement or phase.
When information is no longer needed we delete it or anonymise it.
11. Security
We use access controls, least-privilege permissions, encryption in transit, managed devices, multi-factor authentication on business systems and regular reviews of who can access what. Our team is trained on handling client information and on the confidentiality terms in our agreements.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities where the law requires it.
12. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you, and receive a copy of it.
- Correct information that is inaccurate or incomplete.
- Ask us to delete information, or to restrict or object to how we use it.
- Receive information you gave us in a portable format.
- Withdraw consent where we rely on it, and unsubscribe from marketing at any time.
- Not be discriminated against for exercising these rights.
California residents: we have not sold or shared personal information as those terms are defined under the CCPA/CPRA in the preceding 12 months, and we do not knowingly sell the personal information of minors.
To exercise any right, email info@zivoke.com. We will respond within the time the applicable law allows — normally within 30 days — and may need to verify your identity first. You also have the right to complain to your local data protection authority.
13. Children’s privacy
Our website and services are intended for business use by adults. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
14. Third-party links
Our website and articles link to other sites, including Salesforce, AppExchange listings and review platforms. We are not responsible for the content or privacy practices of those sites, and we encourage you to read their privacy notices.
15. Changes to this policy
We review this policy regularly and will update it when our services, systems or legal obligations change. The effective date at the top of this page shows when the current version took effect. Material changes will be highlighted on this page, and where appropriate we will notify clients directly.
16. Contact us
Questions about this policy, or about how we handle information on an engagement? We are happy to talk it through.
- info@zivoke.com
- Phone
- +1 (347) 254 7642
- Post
- Zivoke LLC, 447 Broadway, 2nd FL #198, New York, NY 10013, United States
Working with us
If you are reviewing this policy as part of a procurement or security review, we can share our standard data processing addendum, security overview and engagement governance model on request.
