Who we are
ZIFFER is a product of code75 SASU, a company registered in Paris under number 948 211 941. Its President is Yacine Kellib. ZIFFER is a registered trademark of code75 SASU. Write to us at hello@ziffer.io.
This website
There is no account here, no sign-up and no form. The contact links open your own mail program, so nothing you write reaches us until you send it. We run no analytics and no tracking scripts, and the fonts are served from this site rather than from a third party.
Two things are worth naming, because they are the only two there are.
- The site sets one cookie,
NEXT_LOCALE. It holds the language you are reading in and nothing else. It is not an identifier and it is not read by anyone but this site. - The site carries Intercom’s chat widget. It loads on every page and Intercom can store data in your browser. If you open a chat, what you write goes to Intercom and to us, and we keep it while the conversation is useful to you.
The site is hosted by Railway. Its servers see the ordinary request data any web server sees, including your IP address, and we do not build anything from it.
What ZIFFER holds for a customer
ZIFFER is a gate. A customer’s AI agent proposes an action, ZIFFER decides it against rules the customer wrote and signed, and the customer’s own systems carry the action out. We do not run those systems and we do not hold the credentials that touch them.
What reaches us is the proposal, which is the description of the action the agent asks to take, the decision, the signed receipt for it, and the audit record. The customer chooses what goes into a proposal.
The rules stay with the customer. A policy lives in the customer’s own git repository and is signed with the customer’s key, so we cannot edit it. That is the point of the design, and it is why we cannot add or remove an approver when someone asks us to.
The service runs on Amazon Web Services. Today that is the European Union, in Ireland. A customer’s data is processed in the region their deployment uses, and their agreement names it.
Email notices
How we get your address. Only from a policy a customer organisation signed, in which it enrolled you as an approver. We never buy, rent or import lists, and we never send to an address that is not in a signed policy.
What we send. Transactional notices, one at a time. Each one is triggered by an action an AI agent proposed under that organisation’s policy: a request to approve or refuse it, and the outcome. We send no marketing to these addresses.
How to stop receiving them. Ask your organisation to remove you from its policy. We cannot edit a customer’s policy. A reply to any notice reaches a person at ZIFFER.
Bounces and complaints. If an address bounces, or if someone marks a notice as spam, we stop sending to that address and tell the organisation so it can correct its policy.
Notices are sent from an address at ziffer.io through Amazon SES, from the region the service runs in. The domain publishes SPF and DKIM records, so a receiving server can check that the mail is ours.
What we hold about an approver, and for how long
- Your name, as your organisation wrote it in the policy it signed. Held while that policy is in force.
- Your email address, from the contact list your organisation gives us to go with that policy. Held while you are named in the policy.
- The delivery outcome of each notice, which is whether it was delivered, bounced or reported. Held with the audit record of the action it belonged to.
- The audit record of a decision. Held for as long as the customer’s agreement with us requires, because it is that customer’s evidence that the action was authorised.
Who decides what
For this website, ZIFFER (code75 SASU) is the data controller. For the notices, the customer organisation decides who is enrolled and why, so it is the controller; ZIFFER processes those addresses on that organisation’s instructions and for nothing else.
Your rights
Under the GDPR you can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, or object to it. Write to privacy@ziffer.io and say which of those you want. Where the data is in a customer’s signed policy we will tell you which organisation to ask, because we cannot change their policy for them. You can also complain to the CNIL, the French data protection authority.