Privacy Policy
This policy explains what The Zorro Group™ collects, why we collect it, who we share it with, and the control you and your customers keep over that information.
- Effective August 26, 2026
- Applies to our site and services
- Written in plain English
1. Scope and our role
This policy covers information handled by The Zorro Group™ ("we", "us") through this website, our marketing communications, and the AI response and marketing systems we design, implement and support, including The Response Desk™.
We act in two different roles, and the role determines who controls the data:
- As a business, for our own website visitors, prospects and contacts — we decide how that information is used, and this policy governs it.
- As a service provider to our clients, for the end-customer data that flows through a system we build and operate for them — the client remains the owner of that data, our written agreement with them governs it, and we process it on their instructions. If you are an end customer of one of our clients, please direct privacy requests to that business; we will support them in responding.
2. Information we collect
Information you give us. Name, company, work email, phone number, and anything you write in a form, email or chat with us — including messages you send to Zeus, our website assistant.
Information collected automatically. Standard technical data such as IP address, device and browser type, pages viewed, referring page, and timestamps. Zeus stores your conversation in your own browser so it is still there when you come back; you can clear it at any time by clearing your browser storage.
Client system data. When we operate a system for a client, that system handles the records that make it work — call transcripts and recordings, SMS and email threads, web form submissions, lead source and campaign identifiers, appointment and CRM records, and the performance metrics generated from them.
Information from other sources. Data passed to us by a client's own systems (CRM, scheduler, ad platforms, phone system) as part of an integration they authorize.
3. How we use information
- To respond to inquiries, schedule walkthroughs, and provide proposals.
- To design, build, run, support and improve the systems our clients hire us to deliver.
- To route, answer, qualify, follow up on and log conversations on a client's behalf.
- To produce dashboards, campaign and call reporting, and Systems Adjustment Reporting for the client.
- To detect anomalies and send alerts by SMS, email or outbound call when a system's metrics move outside expected ranges.
- To secure our services, prevent abuse and fraud, and troubleshoot problems.
- To meet legal, tax, contractual and recordkeeping obligations.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
4. AI processing and model training
Our systems use commercial AI models — including speech-to-text, language models and text-to-speech — supplied by third-party providers under contract. Content is sent to those providers only as needed to produce a response, a transcript, a summary or a report.
- We do not use client or end-customer data to train our own general-purpose models.
- We contract for model provider terms that do not permit our submitted content to be used to train their general-purpose models. Where a provider's terms change, we will review the arrangement rather than silently continue.
- Configuration we tune per client — prompts, scripts, routing rules, escalation policy, knowledge sources — is built from that client's own approved material and is not reused for another client.
- AI output can be wrong. Systems are built with rules, escalation paths and human handoff for cases that need a person, and clients review reporting rather than relying on the model unsupervised.
5. Calls, recordings and messaging
Where a system records or transcribes calls, recording notice and consent requirements vary by state and country, and some jurisdictions require all parties to consent. We configure disclosure prompts, opt-out handling and message frequency at the client's direction, and each client is responsible for the notices and consents required for their own operations, including telephone, texting and marketing rules that apply to them.
Recipients of SMS from a system we operate can opt out using the standard keywords advertised in the message; opt-outs are honored by the system and logged.
7. Retention
We keep information for as long as it is needed for the purpose it was collected, and then delete it or render it unidentifiable. Website inquiry records are kept for our normal business and recordkeeping needs. Client system data is retained on the schedule agreed with that client; when an engagement ends, we return or delete client data according to that agreement.
8. Security
We use access controls, encrypted transport for data moving between systems, credential management and least-privilege access for the people who support a deployment. No method of transmission or storage is completely secure, and we do not claim our services are immune from compromise. If we become aware of a security incident affecting information we handle, we will notify affected clients as required by our agreements and applicable law.
9. Your choices and rights
Depending on where you live, you may have the right to request access to the personal information we hold about you, correction of inaccurate information, deletion, a portable copy, or to object to or limit certain processing. You may also withdraw consent where processing is based on consent, and you will not be treated differently for exercising a right.
To make a request about information we hold as a business, contact us through our contact page. We will verify your identity before acting. If your request concerns data inside a system we run for a client, we will forward it to that client, who is the controller of that data.
You can also opt out of our marketing emails using the unsubscribe link in any message, and control cookies and similar technologies through your browser settings.
10. Regional disclosures
United States. Residents of states with consumer privacy laws, including California, may exercise the rights described above. We do not sell personal information or share it for cross-context behavioral advertising, and we do not knowingly process sensitive personal information for purposes beyond providing our services.
Outside the United States. Our services are operated from the United States, and information may be processed there and in other countries where our service providers operate. Where a transfer mechanism is required for data originating in the EEA or UK, we address it in our agreement with the relevant client.
11. Children
Our services are built for businesses and are not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided information to us, tell us and we will delete it.
12. Changes and how to reach us
We may update this policy as our services and the law change. When we do, we will revise the effective date at the top of this page, and we will provide additional notice for material changes.
Questions, requests or complaints about privacy can be sent through our contact page, addressed to The Zorro Group™, Privacy.
Effective August 26, 2026.
Your data stays yours.
We build and support the system. The records it produces belong to the business that owns the customer relationship.
