This agreement covers the Power BI certified Zebra BI Tables, Charts and Cards for Power BI installed from Microsoft AppSource, and Zebra BI for Office. Zebra BI Tables+ and Zebra BI Charts+, and any Zebra BI visual for Power BI obtained other than from its AppSource listing, are licensed under the End-User License Agreement for Uncertified Visuals.
Date of publication: 22.9.2025
This End-User License Agreement ("EULA" or the "Agreement") applies between ZEBRA BI d.d. ("ZEBRA BI", "Company", "We") and you (the "Licensee", "End-User", "you"), whereas you accept all these terms and conditions for licensing ZEBRA BI product(s) hereunder, which may include associated software components, media, printed materials, and "online" or electronical documentation (collectively, the "Software Product").
By using the Software product in any manner, you are bound by this Agreement, as well as any terms incorporated by reference in this Agreement. If you are accepting this Agreement on behalf of a company, organization, government, or other legal entity, you represent and warrant that (i) you are authorized to do so, (ii) the entity agrees to be legally bound by this Agreement, and (iii) neither you nor the entity are barred from using the Software product or accepting this Agreement under the laws of the applicable jurisdiction. This Agreement is enforceable against you and any entity that obtained the Software product and, on whose behalf, they were used. IF YOU DO NOT HAVE SUCH AUTHORITY OR IF YOU DO NOT WISH TO BE BOUND TO THIS AGREEMENT DO NOT USE THE SOFTWARE PRODUCT.
This Agreement governs your use of the Software product. Except as otherwise specified, this Agreement does not apply to Third-Party Products, which are governed by their own terms and conditions.
For the avoidance of doubt, where the Licensee purchases Software product for Office, the Data Processing Agreement ("DPA") attached as Annex 1 shall apply and form an integral part of this Agreement.
"ZEBRA BI" means the ZEBRA BI entity with which you are entering into this Agreement. If you have previously entered into an agreement with a ZEBRA BI entity, then "ZEBRA BI" means that entity. If you have not previously entered into an agreement with a ZEBRA BI entity, then "ZEBRA BI" means the entity identified in the following:
"Business Partner"
means a legal entity or individual that requires access to the Software product in connection with Licensee's internal business operations, such as suppliers, distributers or customers of Licensee.
"Confidential Information"
means, with respect to Licensee: Licensee's marketing and business plans and/or financial information, and with respect to ZEBRA BI: (A) the Software product and other ZEBRA BI materials, including without limitation the following information regarding the Software product: (i) computer software codes, programming techniques and programming concepts, methods of processing, system designs embodied in the Software product; (ii) benchmark results, manuals, program listings, data structures, flow charts, logic diagrams, functional specifications, file formats; and (iii) discoveries, inventions, concepts, designs, flow charts, documentation, product specifications, application program interface specifications, techniques and processes relating to the Software product; and (B) product offerings, product pricing, product availability, technical drawings, algorithms, processes, ideas, techniques, formulas, data, schematics, trade secrets, know-how, improvements, marketing plans, forecasts and strategies. In addition, Confidential Information of either ZEBRA BI or Licensee (the party disclosing such information being the "Disclosing Party") includes information which the Disclosing Party protects against unrestricted disclosure to others that (i) the Disclosing Party or its representatives identifies as confidential at the time of disclosure; or (ii) should reasonably be understood to be confidential given the nature of the information and the circumstances surrounding its disclosure; including, without limitation, information from, about or concerning any third party that is disclosed under this Agreement.
"Designated User/s"
means the identified quantity of users (whether as editors, viewers or in any other capacity), including employees, internal or external collaborators and other business partners of the End-User/ Licensee that are agreed upon in EULA Order Form or otherwise approved by the parties as appropriate for Use of the Software product.
"Data Processing Agreement"
means the data processing terms attached hereto as Annex 1, which apply in case the Licensee purchases Software product for Office. Annex 1 forms an integral part of this Agreement.
"Effective date"
means the effective date set out in this Agreement or EULA Order Form as "Effective date". In the event that the Licensee has not concluded an EULA Order Form with ZEBRA BI or the Effective date is not set out in this Agreement, the Effective date should mean the date that the Software product is made available by ZEBRA BI to Licensee in accordance with required steps, as described on ZEBRA BI's Website.
"EULA"
means this "End-User License Agreement" executed between ZEBRA BI and Licensee for the purchase of License to use the Software product as well as any terms incorporated by reference in this Agreement.
"EULA Order Form"
means the "EULA Order Form" that is executed between ZEBRA BI and Licensee and is incorporated by reference to this Agreement and governed by the terms of this Agreement.
"Intellectual Property Rights"
means patents of any type, design rights, utility models or other similar invention rights, copyrights, mask work rights, trade secret or confidentiality rights, trademarks, trade names and service marks and any other intangible property rights, including applications and registrations for any of the foregoing, in any country, arising under statutory or common law or by contract and whether or not perfected, now existing or hereafter filed, issued, or acquired.
"Keycode"
means a password protected member account, generated by ZEBRA BI, which grants the Licensee access to the Software product.
"Licensee"
means the end-user who is further identified in this Agreement as the "End-User", to whom this Agreement, as well as any terms incorporated by reference in this Agreement, apply.
"Party" or "Parties"
mean Licensee and/or ZEBRA BI.
"Software product"
means either:
depending on which Software product the Licensee has purchased under this Agreement and EULA Order Form, as well as corresponding online electronic documentation, associated media and printed materials, including the source code (where applicable), example programs and the documentation, licensed to the Licensee under this Agreement. Software product does not include Third-Party products.
"Subscription"
means the subscription-based model of Software product purchase with automatically renewal at the end of each subscription period, as determined in this Agreement or EULA Order Form.
"Third-Party product"
means any third-party information, website, product, service, or materials referenced in, accessible through, or provided in connection with, the Website or Software product.
"Use"
means to, directly or indirectly, activate the processing capabilities of the Software product, install, execute, access, employ the Software product, or display information resulting from such capabilities.
"Use Tracking"
means ZEBRA BI's possibility to track, monitor, collect and analyse Licensee's Use of the Software product for Office (including Software products Zebra BI Charts for Office and Zebra BI Tables for Office), as determined in this Agreement.
"Website"
means ZEBRA BI website located at www.zebrabi.com (including all associated internet country codes), together with all ZEBRA BI websites and webpages accessible there.
The use of the singular in capitalized terms also includes the plural and vice versa. The use of either gender in capitalized terms also includes others. The headings, paragraphs and highlights in this Agreement are intended for convenience only and do not affect the very interpretation of this Agreement and have no legal or contractual effect. This Agreement will be interpreted without application of any strict construction in favour of or against you or ZEBRA BI.
Software product is protected by copyright laws and international copyright treaties, as well as other intellectual property laws and treaties. All of the ZEBRA BI's Intellectual Property Rights are and shall remain the exclusive property of ZEBRA BI respectively. The Software product is licensed, not sold. ZEBRA BI is willing to grant the Licensee a right to use Software product pursuant to this Agreement and/or EULA Order Form.
Subject to Licensee's compliance with this Agreement and/or EULA Order Form, ZEBRA BI grants to Licensee a non-exclusive, non-transferable, subscription-based license to Use the Software product at specified site(s) to run Licensee's internal business intelligence operations, unless terminated in accordance with this Agreement. ZEBRA BI grants the Licensee a right to install and use copies of the Software product by Designated users on its computer and in cloud service running a validly licensed copy of the Microsoft Power BI application and/or Power BI service and/or Microsoft Office for which the Software product were designed (e.g. "Power BI Desktop", "Power BI Desktop Optimized for Report Server", "Power BI Service", "Power BI mobile app for Android or iPhone", "Microsoft Excel", "Microsoft PowerPoint", etc.).
ZEBRA BI may generate and make available to the Licensee a Keycode that will allow the Licensee/s Designated users to access and Use the Software product. The license to Use the Software product is embedded into the Keycode and Software product itself and is valid for Designated users (i.e. quantity of Licensee's Designated users as agreed upon in EULA Order Form or as selected by the Licensee). Licensee agrees that the Use of Software product will only be made available for Designated users and installed on devices in direct possession of the Licensee. Licensee must comply with all applicable laws and regulations regarding the Use of Software product, including domestic and international export legislation that applies to the Software product. The use of the Software product may be permitted to Licensee's Business Partners only through screen access, solely in conjunction with the Licensee's Use, and may not be used to run any of Business Partner's business operations.
Licensee is permitted to back up data in accordance with good information technology practice and for this purpose to create the necessary backup copies of the Software product. Backup copies on transportable discs or other media devices must be determined as backup copies and bear the same copyright and authorship notice as the original media devices, unless technically infeasible.
It is technically possible to add automation and embed the Software product's functionality into another products or service. Adding or embedding the Software product's functionality is compliant with this Agreement, if: (i) the added automation or embedding does not exceed the quantity of agreed upon Designated users; (ii) the added automation or embedding is conducted in accordance with Software product's Use restrictions under this Agreement or EULA Order Form.
ZEBRA BI may allow End-Users to Use the Software product in object-code form only, for a determined trial period and solely for the purpose of allowing End-Users to evaluate the Software product. By applying for a trial use, fulfilling the trial use form, clicking the "I agree" button or otherwise accessing or Using the Software product, End-Users are bound by this Agreement as well as any terms incorporated by reference in this Agreement and confirm that they have read and understood this Agreement. The trial use shall commence on the date the Software product is made available by ZEBRA BI to End-Users and will automatically terminate upon expiration of the determined trial period. Upon expiration or termination of the trial use, the granted license for Software product shall immediately terminate and the End-User shall irretrievably destroy the Software product.
Licensee may request and ZEBRA BI may provide support services related to the Software product ("support services"). All support services shall be considered as a part of the Software product and are subject to this Agreement and EULA Order Form. Support services are charged in accordance with ZEBRA BI's price list and agreed upon in EULA Order Form.
Except as permitted and non-excludable under applicable law, this Agreement or EULA Order Form, the Licensee will not, directly or indirectly (i) reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, object code, or underlying structure, ideas, or algorithms of / or included in the Software product, documentation or data related to the Software product; (ii) modify, translate or create derivative works based on Software product; (iii) copy (except for archival purposes or in accordance with this Agreement distribute, lease, pledge, assign, sublicense or otherwise transfer or encumber rights to the Software product; (iv) distribute or publish Keycodes; (v) Use the Software product for timesharing or service bureau purposes or otherwise for the benefit of a third party; (vi) or remove any proprietary notices, labels; (vii) make any Use of or perform any acts with respect to Software product other than as expressly permitted in accordance with this Agreement or EULA Order Form.
ZEBRA BI shall be permitted to audit the Use of Software product by the Licensee in its sole discretion, which may include on-site and/or remote audits. Licensee shall reasonably cooperate in the conduct of such audits. In the event an audit reveals that the Licensee underpaid license fees and or ZEBRA BI's support services, the Licensee shall pay such underpaid fees based on ZEBRA BI's price list and terms and conditions in effect at the time of the audit. In the event an audit reveals that the Licensee has Used the Software product in excess (i.e. has exceeded the agreed upon quantity of Designated users in EULA Order Form or as selected by Licensee), the Licensee shall pay such excess Use of Software product based on ZEBRA BI's price list and terms and conditions in effect at the time of the audit, and shall execute an additional EULA Order Form to affect the required licensing of any excess Use of Software product. ZEBRA BI may delegate or request an internal / external collaborators or other business partner to perform such an audit.
Licensee acknowledges that ZEBRA BI may collect information on Licensee's Use of the Software product for Office, including Personal Information, and may use such Personal information: (i) to modify, improve, or enhance the Software product for Office or Licensee's ability to access and Use the Software product for Office; (ii) to provide the Licensee with better support services, including understanding of the Use of Software product for Office; (iii) to maintain and promote contact with the Licensee, including managing relationships and marketing; (iv) to ensure compliance with applicable legislation; (v) for the purposes of legitimate interests pursued by ZEBRA BI in accordance with applicable legislation, except where such interests are overridden by the interests of fundamental rights and freedoms of the Licensee; or (vi) for a secondary purpose where it is closely related, such as storing, deleting or anonymizing Personal information and statistical, historical or scientific research. Use Tracking is subject to Confidentiality obligations under this Agreement and ZEBRA BI does not track, monitor, collect or analyze any Confidential Information of the Licensee used or inputted for visualization in the Software product for Office. Use Tracking is turned on by default and the Licensee may contact ZEBRA BI's support team to opt-out of Use Tracking, whereas the Licensee cannot opt-out of Use Tracking for the purpose of modifying, improving, or enhancing the Software product for Office or Licensee's ability to access and Use the Software product for Office.
ZEBRA BI will invoice and Licensee will pay in advance annual fees for Use of Software product during the duration of Subscription as set forth in EULA Order Form or in accordance with the subscription rate the Licensee has selected. Annual fees shall include the price of the Software product Use for Designated users (i.e. quantity of Licensee's Designated users as agreed upon in EULA Order Form or as selected by Licensee). Unless otherwise specified in EULA Order Form, Licensee shall pay annual fees in advance upon receipt of invoice or payment by credit card, if enabled by ZEBRA BI. Payment by credit card shall be subject to the conditions separately agreed upon between ZEBRA BI and the payment provider.
ZEBRA BI will not modify the annual fees charged to Licensee during each Subscription year (i.e. during a period of one year), unless otherwise specified in EULA Order Form. Upon the expiration of each Subscription year (i.e. at the beginning of each renewal term), ZEBRA BI reserves the right to increase the annual subscription fees for the Use of Software product. Licensee acknowledges that the annual fees are subject to change in accordance with this Agreement and agrees to pay applicable annual fees in advance, unless this Agreement and/or EULA Order Form is terminated.
All withholdings, value added tax ("VAT"), Sales and other taxes or other contributions required by applicable legislation, if any, resulting from the payments made to ZEBRA BI pursuant to this Agreement will be the sole responsibility of Licensee, and Licensee will be responsible for paying any such VAT, sales, use, excise and other taxes relating to its receipt of the Software Product this Agreement. A failure on ZEBRI BI's part to invoice Licensee for any applicable taxes does not relieve Licensee of the liability to pay such taxes, and Licensee must pay to the applicable taxing authority any such taxes which may be due as a result of your purchase.
All payments to be made for the use of the Software Product shall be made without any deductions or withholding for or on account of any taxes, levies imports or duties. If you are compelled to make any such deduction or withholding, you shall pay such additional amounts as are necessary to ensure us the full amount which we would have received but for the deduction or withholding.
We are not responsible for any bank fees, interest charges, finance charges, overdraft charges, or other fees resulting from charges billed by us. Any and all such fees or charges shall be paid by you.
In the event that a currency conversion takes place, Licensee agrees that it will be completed at the transaction exchange rate set for the relevant currency exchange. The transaction exchange rate is adjusted regularly and includes a currency conversion spread applied and retained by payment providers on the base exchange rate to form the rate applicable to Licensee's conversion. If any currency conversions apply, you will pay the difference up to the whole amount owed to us. Payments can be made either in EUR or in USD. We will not make any other currency conversions and do not accept any payments in other currencies.
This Agreement, jointly with rights and obligations arising hereunder, shall become effective as of the Effective date and shall continue in effect thereafter unless this Agreement or EULA Order Form are terminated. The Software product will be made available for Use to the Licensee for the duration of Subscription as determined in EULA Order Form or as selected by the Licensee. This Agreement will automatically terminate upon the termination of EULA Order Form. This Agreement can also be terminated, without prejudice to rights hereunder, in accordance with the following: (i) the Licensee may terminate this Agreement for any reason, but only after payment of all fees then due and owing to ZEBRA BI, with a written notice with at least a 30-day notice period; (ii) ZEBRA BI may immediately terminate this Agreement, jointly with a termination of EULA Order Form, in the event of Licensee's material breach of any provisions of this Agreement, including Licensee's failure to pay any fees due and owed to ZEBRA BI, Licensee's bankruptcy, insolvency or other assignment for the benefit of creditors. For the avoidance of any doubt, termination of this Agreement shall strictly apply to all Software product under this Agreement and/or EULA Order Form, their appendices and other binding documents. Partial terminations of this Agreement by Licensee shall not be permitted in respect of any part of this Agreement and/or EULA Order Form, their appendices and other binding documents. Termination of this Agreement results in automatic termination of EULA Order Form.
Upon termination of this Agreement by either party for any reason or expiration of Licensee's Subscription: (i) ZEBRA BI will cease to make available the Use of Software product and the Licensee will cease Use of all Software products; (ii) Licensee shall irretrievably destroy or upon ZEBRA BI's request deliver to ZEBRA BI all copies of the documentation and Confidential Information in every form, except to the extent it is legally required to keep it for a longer period in which case such return or destruction shall occur at the end of such period; (iii) Licensee shall not be entitled to a refund for any months that the Software product was not used, but paid in advance; and (iv) any fees owed to ZEBRA BI will immediately become due and payable in full (i.e. termination shall not relieve Licensee from its obligation to pay fees that remain unpaid). All sections of this Agreement that expressly provide for survival, or by their nature should survive, will survive termination of this Agreement, including, without limitation, confidentiality, indemnification, warranty disclaimers, and limitations of liability.
All rights not expressly granted by ZEBRA BI to Licensee in this Agreement are hereby reserved by ZEBRA BI. There are no implied rights save to the extent rights cannot be excluded by applicable legislation. Licensee may not use, imitate, or copy, in whole or in part, any ZEBRA BI trademark, service mark, logo, or other branding without, in each instance, ZEBRA BI's prior written consent, in ZEBRA BI's discretion.
As between the parties, the Software product, including, without limitation, any and all application programming interfaces, software, documentation, images, video, content, logos, page headers, custom graphics, design and user interface elements, scripts, and other materials contained therein or provided in connection therewith, and all modifications, enhancements, and updates thereto, as well as all Intellectual Property Rights associated with any of these materials are owned by ZEBRA BI. Licensee has no right or license in/or to the ZEBRA BI's Intellectual Property Rights other than the right to Use the Software product, in compliance with this Agreement, during the Subscription.
ZEBRA BI does not claim Intellectual Property Rights and Licensee retains all rights in and related to the Licensee's data. ZEBRA BI may use the Licensee provided trademarks solely for the purpose of providing and supporting Software product. Licensee represents and warrants that, for all such data provided, Licensee owns or otherwise controls all necessary rights to do so and to meet your obligations under this Agreement. To the extent permitted by applicable legislation, ZEBRA BI takes no responsibility and assumes no liability for any data provided by Licensee or any third party.
Licensee will defend, indemnify, and hold ZEBRA BI and its suppliers or affiliates, and the respective directors, officers, employees and agents of each, harmless from and against any and all claims, losses, damages, liabilities and costs (including, without limitation, reasonable attorneys' fees and court costs) arising out of or relating to your breach of / incompliance with this Agreement, EULA Order Form, or use by Licensee or any third party (authorized, permitted or enabled by Licensee) of the Software product, except to the extent the foregoing directly result from ZEBRA BI's own gross negligence or willful misconduct. ZEBRA BI reserves the right, at its own expense, to assume the exclusive defense and control of any matter otherwise subject to indemnification by Licensee.
ZEBRA BI hereby represents and warrants that properly licensed Software product will perform substantially as described by ZEBRA BI. ZEBRA BI furthermore represents and warrants that it has the power and authority to grant the rights and licenses granted to Licensee under this Agreement.
The Software product is licensed to Licensee on an "as is", "as available" and "with all faults" basis. ZEBRA BI on behalf of its licensors, suppliers and affiliates, disclaims all other warranties, express or implied, including but not limited to, any implied warranties of merchantability, fitness for a particular purpose, title and non-infringement with regards to the Software product, to the extent permitted under applicable legislation. ZEBRA BI does not warrant that the Software product will satisfy Licensee's requirements or that it will operate without defect or error.
ZEBRA BI gives no warranties, guarantees, or conditions about (i) the ability of the Software product to perform without limitation, restriction or interruption in any given environment, (ii) the accuracy, completeness, or content of the Software product, (iii) the accuracy, completeness, or content of any linked sites, and / or (iv) Third-party products, and ZEBRA BI assumes no liability or responsibility therewith, to the extent permitted under applicable legislation.
ZEBRA BI shall be liable for intentional conduct, gross negligence, as well as, in situations where ZEBRA BI is liable according to mandatory and/or statutory legislation. In cases of slight negligence that do not represent a breach of material contractual obligations, the fulfilment of which facilitates the performance of this Agreement, ZEBRA BI will not be liable.
ZEBRA BI will not be responsible under this Agreement (i) if the Software product is not used in accordance with this Agreement and/or EULA Order Form; (ii) if the liability is caused by Licensee; (iii) if the Software product is used in conjunction with any Third-Party products for which the Licensee lacks sufficient rights from the Third-Party for such use; or (iv) for any Licensee's activities not permitted under this Agreement or EULA Order Form.
ZEBRA BI will in no event be liable in aggregate amount or in excess of the total fees / payments received by ZEBRA BI from Licensee for the Software product licenses during the 12-month period immediately preceding the event resulting in such liability. ZEBRA BI will not be liable in any amount for special, incidental, consequential, or indirect damages, loss of good will or profits, work stoppage, data loss, computer failure or malfunction, legal fees, court costs, interest or exemplary or punitive damages.
Confidential Information must not be used or reproduced in any form except as required to accomplish the intent of this Agreement. Any reproduction of any Confidential Information of the Disclosing Party shall remain the property of the Disclosing Party and shall contain any and all confidential or proprietary notices or legends which appear on the original. With respect to the Confidential Information of the Disclosing Party, the party receiving the Confidential Information ("Receiving Party") shall: (i) keep the Confidential Information strictly confidential and not disclose such information to any person within or outside its organization, except as permitted according this Agreement; (ii) prevent disclosure of Confidential Information to any third party, using at least the same degree of care one usually employs in own affairs of similar character, whereas the parties shall limit internal dissemination of Confidential Information within its own organization to individuals on a "need to know basis", provided that there is a clear understanding by such individuals of their obligation to maintain the confidential status of such information and restriction of its use solely to the purpose specified herein, (iii) not use the Confidential Information for any purpose other than the purpose of Using the Software product, without the prior written consent of the disclosing Party; (iv) keep all documents in hardcopy or electronic form prepared or obtained in connection with the Software product safe and separate from other documents, and not to make them available to any person, except to those employees, who are bound to an equivalent confidentiality obligation; (v) make only such copies of Confidential Information as strictly necessary for the purpose of Using Software product; (vi) not keep any copies and, at the request of the disclosing Party, destroy or hand over all documents and data obtained or prepared in connection with this Agreement or EULA Order Form; (vii) notify the disclosing Party immediately, if Confidential Information has been disclosed to or is in the possession of a third party. The obligation of confidentiality shall continue to remain in force for a period of 5 (five) years after the last disclosure, and, with respect to trade secrets, for so long as such trade secrets are protected under applicable legislation.
Obligation of confidentiality shall not apply and the Receiving Party shall have no confidentiality obligation with respect to information that: (i) is or becomes publicly known through no fault of the Receiving Party; (ii) is already known to the Receiving Party at the time of disclosure; (iii) is received by the Receiving Party from a Third-Party without similar restriction as to non-disclosure and without breach of this Agreement; (iv) has been or is independently developed by the Receiving Party; (v) is required to be disclosed by law, or by a requirement of a regulatory body or stock exchange, where disclosure shall not occur until, where reasonable practicable, the Receiving Party has notified the Disclosing Party of any possible disclosure and the Disclosing Party has been afforded the opportunity to review such disclosure and to attempt to prevent or limit any such disclosure.
Licensee may not assign its rights or obligations under this Agreement or EULA Order Form without the prior written consent of ZEBRA BI, which ZEBRA BI may refuse in its sole discretion. Any attempted assignment without prior written consent from ZEBRA BI will be deemed null and void. In the event that ZEBRA BI consents to an assignment, there will be a license assignment fee imposed by ZEBRA BI in the amount set forth in EULA Order Form. ZEBRA BI may assign its rights and/or obligations under this Agreement or EULA Order Form at any time. Subject to the foregoing, this Agreement will bind and inure to the benefit of the parties, their respective successors and permitted assigns.
ZEBRA BI reserves the right, in its discretion, to change, modify, add to, or remove portions of this Agreement (collectively, "Changes"), at any time. ZEBRA BI will notify you of Changes by sending an email to the address identified in your ZEBRA BI account and by posting a revised version of the Agreement incorporating the Changes to its Website. Your continued use of the Software product following notice of the Changes (or posting of this Agreement incorporating the Changes in the event your email address is no longer valid, is blocked, or is otherwise not able to receive the notice) will mean that you accept and agree to the Changes. Such Changes will apply prospectively beginning on the date the Changes are posted to the Website.
If any provision of this Agreement is found to be illegal, invalid or unenforceable, that provision will be limited or eliminated to the minimum extent necessary so that the Agreement will otherwise remain in full force and effect and enforceable. The illegal, invalid or unenforceable provision will be replaced by a valid and enforceable provision which approximates as closely as possible the intent of the invalid or unenforceable provision. This will also apply in the event of contractual gaps.
This Agreement, jointly with any applicable EULA Order Form, constitutes the complete agreement between ZEBRA BI and Licensee and supersedes all prior or contemporaneous discussions, representations, and proposals, written or oral, with respect to the subject matters discussed herein.
If either Party should waive any breach of any provision of this Agreement, it shall not thereby be deemed to have waived any preceding or succeeding breach of the same or any other provision hereof.
All notices shall be in writing and shall be deemed duly given when delivered to the address identified in your ZEBRA BI account or addresses set forth in EULA Order Form. Apart from any notice of termination or notice of material breach, which shall occur by exchange of letters in writing, the requirement of a written form ("in writing") is met by exchange of letters or other written form, including email or other electronic means used by both parties.
This Agreement and any claims arising out of or relating to this Agreement and its subject matter shall be governed by and construed under the laws of the Republic of Slovenia, without reference to its conflicts of law principles. In the event of any conflicts between foreign law, rules, and regulations, and Slovenia law, rules, and regulations, Slovenian law, rules, and regulations shall prevail and govern, and the parties hereby submit to the exclusive jurisdiction of the Slovenian Courts. The United Nations Convention on Contracts for the International Sale of Goods shall not apply to this Agreement and is hereby expressly excluded.
Except for the payment obligations hereunder and as agreed upon in EULA Order Form, neither Party shall be liable to the other for any delay or non-performance of its obligations hereunder in the event and to the extent that such delay or non-performance is caused by conditions beyond the reasonable control of the performing party that prevents either Party for fulfilling its obligations under this Agreement and which such Party cannot avoid or circumvent ("Force Majeure Event").
Licensee acknowledges and agrees that for the purpose of this Agreement, ZEBRA BI may collect, use, transfer and disclose personal data pertaining to Designated Users as well as any other employees and directors of the Licensee relevant for carrying out the intent of this Agreement. Such personal data may be collected from the Licensee or directly from the relevant individuals. The Parties acknowledge that with regard to such personal data processed hereunder, ZEBRA BI shall be regarded as the Data Controller under the applicable General Data Protection Legislation. ZEBRA BI shall process any such personal data in accordance with its privacy policies and practices, which will comply with all applicable requirements of the General Data Protection Legislation.
Where the Licensee purchases Software product Office, ZEBRA BI may act as a Data Processor with respect to certain personal data. In such cases, the Parties' respective rights and obligations are further governed by the Data Processing Agreement attached hereto as Annex 1.
Annexes attached to this Agreement constitute an integral part hereof. In case of any conflict between this Agreement and an Annex, the provisions of the Annex shall prevail with respect to its subject matter.
END OF EULA
This personal data processing agreement (the "DPA") is made between the Licensee (referred to hereunder as the "Controller") and ZEBRA BI (referred to hereunder as the "Processor") as parties to the EULA (the Controller and the Processor hereinafter jointly referred to as the "Parties" and each individually as a "Party").
(a) The Parties have entered into the EULA, subject to which the Parties shall be considered to have entered into this DPA in case the Processor shall at any time process any personal data of the Controller, as such personal data is specified in Attachment A hereto (the "Personal Data"). The Parties will in this way ensure compliance with the Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the "GDPR").
(b) With this DPA, the Parties wish to regulate the interrelations with regard to the processing of Personal Data.
(c) In case of discrepancies between the EULA and this DPA, this DPA shall prevail.
NOW, THEREFORE, in consideration of the premises and the mutual covenants and agreements hereinafter contained, the Parties hereby agree as follows:
In this DPA and in any communication under or in connection with this DPA by the Parties, the terms defined in the relevant clauses of this DPA shall have the meanings ascribed to them therein. The terms written in capital letters which are not defined in this DPA, shall have the meaning ascribed to them in the EULA.
2.1. This DPA is entered into in connection with and for the purposes of the EULA in relation to the processing of Personal Data (as defined herein), if and when it occurs. The Parties agree that the primary purpose of the Software Product is not to process any Personal Data, but that the Licensee might nevertheless insert Persona Data into the Software Product from time to time. In such case, the processing of Personal Data shall be carried out in accordance with the GDPR.
2.2. Pursuant to the DPA, the Controller shall entrust to the Processor the personal data specified in Attachment A hereto (the "Personal Data") for processing purposes.
2.3. The Processor shall process the Personal Data solely for the purposes of the performance of the EULA, to the extent necessary for the performance of obligations during its term.
2.4. The Processor shall process the Personal Data in conformity with the GDPR, other applicable legal regulations, this DPA, the EULA and instructions of the Controller.
2.5. The Processor declares that they have the infrastructure, experience, knowledge and qualified staff necessary for the proper performance hereof in conformity with all applicable regulations.
3.1. The Processor shall:
3.2. The Processor shall be entitled to and the Controller hereby expressly authorizes the Processor to subcontract the processing of the Personal Data to further processors, which are listed in Attachment B hereto. The Processor shall inform the Controller of each intended change in the list of further processors in conformity with the provisions of the EULA. In this case the process shall be as follows:
The Processor declares that they shall use only the services of such further processors who provide sufficient guarantees of implementing appropriate technical and organisational means ensuring processing in conformity with the provisions of the GDPR and protecting the rights of persons to whom such data relates. The Processor shall ensure that such further processors are contractually bound to the same obligations as those imposed on the Processor hereunder.
3.3. The Processor shall make available to the Controller any information required to perform their obligations related to the processing of the Personal Data and to demonstrate compliance with the obligations of the Controller with the GDPR. The Processor shall enable the Controller to carry out audits (no more than once per year), including inspections within the scope related to the processing of the Personal Data and shall cooperate therein to this effect. The Controller may charge a fee (based on Controller's reasonable costs) for such audits, whereas the Controller will provide the Processor with an estimate of the fees in advance to a respective audit.
3.4. The Controller shall be obliged to act in compliance with all applicable data protection legislation and warrants to the Processor that it has the necessary legal basis to process the Personal Data it inserts into the Software Product, including the relevant authority to share such data with the Processor.
3.5. Without prejudice to any obligations of the Processor, the Controller is responsible for its use of the Software Product and its storage of any copes of the Personal Data outside of the Controller's systems. This shall include appropriate level of security measures, securing the account authentication credentials, systems and devices the Controller uses to access the Software Product, backing up or retaining copies of the Personal Data, and ensuring that any individuals using the Software Product on their instructions or credentials, to act in accordance with the data protection legislation and this DPA.
4.1. The Processor shall process the Personal Data in any country where the Processor or its sub-processors are located.
5.1. Governing Law. This DPA and all matters or disputes arising out of or connected to it shall be governed by and construed in accordance with the laws of the Republic of Slovenia, excluding its conflict of laws rules.
5.2. Dispute Resolution. All disputes and claims arising out of or in connection with this DPA shall be resolved and settled by the competent court in Ljubljana.
6.1. Effectiveness. This DPA enters into force at the same time as the EULA in cases where the Processor processes any Personal data of the Controller.
6.2. Termination of DPA. The Controller may terminate this DPA with immediate effect in the case of material or repeated breaches of this DPA, the GDPR or other regulations referring to personal data protection by the Processor. The termination shall be submitted in writing. The Controller is in this case obliged to make sure that it and its employees, contractors or other persons using the Software Product in their name or under their instructions, no longer insert any Personal Data in the Software Product. This DPA shall be considered to be terminated in case of termination of the EULA.
6.3. Entire agreement. This DPA constitutes and contains the entire agreement and understanding between the Parties with respect to the subject matter hereof and supersedes any and all prior understandings, agreements, letters of intent and arrangements between the Parties with respect to the subject matter hereof to the exclusion of any and all terms implied by law, which may be excluded by contract.
6.4. Severability. If any provision of this DPA is or becomes wholly or partially invalid, unenforceable or ineffective, this shall not affect the validity of other provisions. In such case, it shall be deemed that the invalid, unenforceable or ineffective provision has been replaced by a valid, enforceable or effective provision, which corresponds most to the invalid, unenforceable or ineffective provision and to the business purpose of the Parties, as pursued by the Parties and reflected in this DPA.
6.5. Further Assurances. Each Party shall, on being required to do so by the other Party, promptly and at its own costs, take all necessary steps and/or procure the execution of all such documents in a form satisfactory to the other Party for giving full effect to and valid performance of its obligations under this DPA.
6.6. Costs and Expenses. Each Party shall bear its own costs and expenses in relation to the preparation, negotiation, execution and coming into effect of this DPA. Each Party shall bear the costs and expenses of other own legal, financial and other advisers and representatives.
6.7. Waivers. Any failure to exercise or delay in exercising, on the side of the Parties, any right or remedy shall not operate as a waiver thereof, nor shall any single or partial exercise of any right or remedy preclude any further or other exercise of these rights or remedies or the exercise of any other right or remedy.
6.8. Amendments. This DPA, including this Article 6.8., may only be amended, changed, supplemented, novated or modified by a written agreement of both Parties.
6.9. Assignment. No Party may assign its rights and/or obligations under this DPA or transfer the entire or parts of this DPA to any person without the prior written consent of the other Party.
6.10. No set-off. No Party shall be entitled (i) to unilaterally set off, discount, request relief for, or otherwise reduce or limit any rights or claims it may have against any rights or claims the respective other Party may have under or in connection to this DPA, or (ii) to refuse to pay or perform any obligation it may have under or in connection to this DPA unless the rights or claims to be set-off have been acknowledged in writing by the respective other Party or have been established by a final decision of a competent court or arbitral tribunal.
6.11. Interpretation. Notwithstanding its authorship, this DPA has been drawn up by both Parties as equal business entities, and therefore for the interpretation of this DPA, to the fullest extent permitted by the applicable law, the rule that this DPA shall be interpreted to the detriment of the Party that proposed or drafted the relevant wording of this DPA in part or in whole, shall not apply.
6.12. Attachments. The Attachments form an integral part of this DPA. List of Attachments:
SPECIAL WARNING: THE LICENSEE, ACTING AS CONTROLLER, WHEN COMPLETING THE PURCHASE PROCESS AND ACCEPTING THE EULA, MUST CAREFULLY SELECT WHICH CATEGORIES OF PERSONAL DATA WILL BE PROVIDED TO THE PROCESSOR AND FOR WHICH PURPOSES. THE PROCESSOR WILL PROCESS ONLY THE PERSONAL DATA AND PURPOSES EXPLICITLY SELECTED BY THE CONTROLLER IN THE PURCHASE/ORDER FLOW OR IN SUBSEQUENT DOCUMENTED INSTRUCTIONS, OR THOSE DATA ELEMENTS CLEARLY IDENTIFIED AS BEING MADE AVAILABLE TO THE PROCESSOR THROUGH USE OF THE PROCESSOR'S SOLUTIONS. THE PROCESSOR DOES NOT DETERMINE WHICH DATA ARE PROVIDED AND CANNOT INFLUENCE THE CONTROLLER'S SELECTION; ACCORDINGLY, THE CONTROLLER IS SOLELY RESPONSIBLE FOR ENSURING THAT ONLY APPROPRIATE DATA ARE PROVIDED AND THAT A VALID LAWFUL BASIS AND REQUIRED TRANSPARENCY/CONSENT ARE IN PLACE. THE FOLLOWING SECTION PRESENTS THE FULL POSSIBLE SCOPE OF PROCESSING; IT DOES NOT MEAN THE PROCESSOR WILL PROCESS ALL LISTED ITEMS. THE PROCESSOR WILL PROCESS ONLY THE ITEMS AUTHORISED BY THE CONTROLLER DURING THE PURCHASE PROCEDURE OR VIA LATER WRITTEN COMMUNICATION WITH THE PROCESSOR.
1) Nature and purpose of processing:
2) Categories of persons to whom the data pertains:
3) Personal data type:
4) Territory on which personal data shall be processed: EU
Processor's Technical and Organisational Measures (Art. 32 GDPR) are described in detail in:
Controller may review these documents; Processor will keep them current and notify Controller of any material changes.
Effective Date: 8.9.2026
Contracting entity: ZEBRA BI informacijske rešitve d.d., Pot za Brdom 104, 1000 Ljubljana, Slovenia (Company ID: 6629997000; VAT ID: SI 35190108) ("ZEBRA BI").
This End-User License Agreement for Uncertified Visuals (the "Agreement" or "EULA-UV") governs the End-User's/Licensee's access to and use of the entire portfolio of ZEBRA BI's Uncertified Visuals, being every Zebra BI Power BI custom visual that ZEBRA BI distributes without Microsoft Power BI certification, whether now existing or released in the future, as identified in the Schedule set out in Annex 2 (the "Schedule"). As at the Effective Date the portfolio comprises the Zebra BI "+" visuals, Zebra BI Tables+ and Zebra BI Charts+, together with any associated services, documentation and media.
This Agreement supplements and, solely with respect to the Uncertified Visuals, prevails over the general Zebra BI End-User License Agreement ("General EULA") in the event of a conflict. It applies to the whole batch of Uncertified Visuals collectively; adding a new uncertified visual to the Schedule brings it within this Agreement without the need for a separate agreement.
The Uncertified Visuals may be made available within the Licensee’s existing Zebra BI packages, with entitlement and fees as set out in the applicable Order Form.
By installing, accessing or using any Uncertified Visual, the Licensee accepts this Agreement. If the Licensee does not agree, it must not install, access or use the Uncertified Visuals.
Capitalised terms not defined here have the meaning given in the General EULA available here: https://zebrabi.com/legal/?doc=eula.
1.1 "Uncertified Visuals" means, collectively, all Zebra BI Power BI custom visuals distributed by ZEBRA BI that have not been submitted for, and do not carry, Microsoft Power BI certification, including without limitation the Zebra BI "+" visuals, being Zebra BI Tables+ and Zebra BI Charts+ (together the "+ visuals", also referred to as the "Plus Visuals"), and any additional, successor or renamed uncertified visuals identified in the Schedule (Annex 2), as updated from time to time.
1.2 "Schedule" means Annex 2 (Schedule of Uncertified Visuals), which lists the Uncertified Visuals covered by this Agreement and may be updated by ZEBRA BI as new uncertified visuals are released.
1.3 "Microsoft Certification" means the "Power BI certified" designation granted by Microsoft to a custom visual, a defining requirement of which is that the visual makes no external network calls. The Uncertified Visuals intentionally do not hold this designation because they require network communication to deliver their features.
1.4 "Software product" for the purposes of this Agreement means the Uncertified Visuals, consistent with items (i) "ZEBRA BI visuals for Power BI" and (vii) "other Software products offered by ZEBRA BI" of the "Software product" definition in clause 2.1 (Definitions and interpretation) of the General EULA.
1.5 "Comment Data" means the annotations and comments created by Designated Users through an Uncertified Visual, together with related metadata (timestamps, data/filter context, author attribution and soft-deletion flags).
1.6 "Customer Tenant" means the Licensee's own Microsoft 365 / Microsoft Fabric tenant, including its SharePoint Online environment and its Microsoft Entra ID directory.
1.7 "Zebra BI Server" means ZEBRA BI operated backend service components used, depending on the visual and feature, for authentication, Designated User management, license validation and management, and feature enablement.
1.8 "Microsoft Graph API" means the official Microsoft APIs through which certain Uncertified Visuals read from and write to the Customer Tenant (e.g. SharePoint Excel comment storage) on behalf of the signed-in user.
1.9 "Usage Analytics" (also "Use Tracking") means the product telemetry information about how the Uncertified Visuals are used, as described and bounded in Section 8.
1.10 "Analytics Processor" means the third-party product analytics processor engaged by ZEBRA BI to process Usage Analytics on its behalf, being PostHog, the product analytics sub-processor identified in Annex 1 (Data Processing Terms) of this Agreement. Hosting: EU (PostHog Cloud EU, Frankfurt) or self-hosted EU, as configured.
1.11 "Keycode" means a password protected member account, generated by ZEBRA BI, which grants the Licensee access to the Software product.
1.12 "Designated User/s" means the identified quantity of users (whether as editors, viewers or in any other capacity), including employees, internal or external collaborators and other business partners of the End-User/Licensee that are agreed upon in the EULA Order Form or otherwise approved by the parties.
1.13 "Beta / Preview" means any Uncertified Visual (or feature) made available for evaluation and testing prior to general availability in accordance with Section 12 of this Agreement.
2.1 Subject to the Licensee's compliance with this Agreement and payment of the applicable fees (if any) for the package under which the Uncertified Visuals are made available, ZEBRA BI grants the Licensee a non-exclusive, non-transferable, non-sublicensable, subscription-based license to install and use the Uncertified Visuals for the Licensee's internal business intelligence operations, for the number and type of Designated Users set out in the applicable EULA Order Form or otherwise agreed between the Parties.
2.2 The license covers all Uncertified Visuals listed in the Schedule, associated documentation and media, and the use of the Zebra BI Server, Microsoft Graph API and Analytics Processor integrations to the extent required to operate their features.
2.3 The Licensee must use the Uncertified Visuals in compliance with all applicable laws and with Microsoft's applicable terms for Power BI, AppSource and Microsoft 365.
3.1 The Licensee acknowledges and expressly accepts that the Uncertified Visuals make external network calls. Such external network communications are a necessary condition of their features (for example, viewer commenting in Power BI "view" mode).
3.2 Depending on the specific Uncertified Visual and the features enabled, external communication may include the following. The Schedule and product documentation identify which apply to each visual:
3.3 Data residency and control. Where an Uncertified Visual stores Comment Data, that data is stored in the Customer Tenant, and the Licensee controls retention, backup, audit and access through its own SharePoint governance. The precise data flows for each visual are described in the applicable product and security documentation, which prevails over any general statement in this Section.
3.4 Verification and administrative control. The Licensee may at any time use standard browser developer tools to inspect the external communications made by an Uncertified Visual and to confirm the data transmitted. The Licensee's IT administrators retain full control over deployment, including the ability to restrict the environment to certified visuals only (blocking uncertified visuals), to add the Uncertified Visuals to the organizational store, to scope or exclude SSO by security group, and to block the Analytics Processor endpoint at the network level in accordance with Section 8 of this Agreement.
4.1 Enablement of the identity and commenting features requires two layers of control:
4.2 The Licensee configures SharePoint and Microsoft 365 permissions to determine which Designated Users may read, add or manage Comment Data. Absence of access does not disrupt the core reporting experience.
The Licensee shall not, and shall not permit any third party to:
5.1 reverse engineer, decompile or disassemble the Uncertified Visuals, except to the extent such restriction is prohibited by applicable law;
5.2 modify, adapt or create derivative works of the Uncertified Visuals;
5.3 sublicense, rent, lease, sell, distribute or otherwise transfer the Uncertified Visuals or any Keycode;
5.4 use the Uncertified Visuals on a timesharing or service bureau basis or for the benefit of any third party other than as permitted for Designated Users;
5.5 circumvent or disable the Zebra BI Server authentication, licensing or feature-enablement mechanisms;
5.6 use the Uncertified Visuals other than in accordance with applicable law and Microsoft's applicable terms; or
5.7 remove, alter or obscure any proprietary notices, labels or marks on or in the Uncertified Visuals.
Backup copies are permitted in accordance with good information technology practice.
6.1 ZEBRA BI retains all right, title and interest in and to the Uncertified Visuals, the Zebra BI Server and all associated intellectual property. No rights are granted other than as expressly set out in this Agreement. The Licensee shall not use, imitate or copy, in whole or in part, any ZEBRA BI trademark, service mark, logo or trade name without ZEBRA BI's prior written consent.
6.2 The Licensee retains all right, title and interest in and to its own data, including the data displayed in the visuals and the Comment Data. The Licensee grants ZEBRA BI a limited right to use Licensee provided trademarks solely to provide and support the Software product.
6.3 The Licensee warrants that it owns or holds all necessary rights to the data it provides or displays through the Uncertified Visuals. ZEBRA BI assumes no responsibility or liability for any data provided or displayed by the Licensee.
7.1 Fees (where and if applicable) for the Uncertified Visuals are as set out in the applicable EULA Order Form, are charged annually in advance, and are exclusive of all taxes, which are the sole Licensee's responsibility. Amounts are payable in EUR or USD only. ZEBRA BI reserves the right to adjust fees at subscription renewal. During any Beta / Preview period, access may be provided complimentary in accordance with Section 12 of this Agreement.
8.1 Applicability. This Section applies only to Uncertified Visuals, and only where Use Tracking is active for the relevant visual, as indicated in the Schedule and the applicable product documentation. It does not apply to ZEBRA BI's Microsoft-certified visuals.
8.2 Scope. Use Tracking is limited to product usage analytics, being pseudonymous interaction and technical/session telemetry. It does not capture the business or financial data displayed in or bound to the visual, and does not capture the content of Comment Data.
8.3 Controller and processor. For Usage Analytics, ZEBRA BI is the data controller, the Analytics Processor (PostHog) acts as ZEBRA BI's processor, and the individual Designated Users whose interaction events are collected are the data subjects. The Licensee's organisation is neither controller nor processor of this Usage Analytics.
8.4 Lawful basis and purpose. ZEBRA BI processes Usage Analytics on the basis of its legitimate interests under Article 6(1)(f) GDPR in understanding feature adoption, activation and retention, in order to operate, secure, support and improve the Uncertified Visuals and to simplify licensing. The processing is limited to interaction and technical telemetry and its impact on data subjects is minimal.
8.5 What is collected. Usage Analytics is limited to pseudonymous interaction and technical or session telemetry. The specific events and data categories collected are set out in the Zebra BI Privacy Policy for Visuals, and are updated there as the product evolves.
8.6 What is not collected. ZEBRA BI does not in any way collect through Use Tracking: (a) the business or financial data displayed in or bound to the visual; (b) cleartext user names, email addresses or Microsoft Entra ID identifiers; (c) screenshots or visual renders; (d) keystroke or free-text input content; or (e) data from other visuals on the same report page. The content of Comment Data is not collected through Use Tracking.
8.7 Analytics processor and data residency. Usage Analytics is processed on ZEBRA BI's behalf by PostHog, the analytics sub-processor identified in Annex 1 of this Agreement, hosted in the EU (PostHog Cloud EU, Frankfurt) or self-hosted EU, with geolocation lookup disabled, so that for EU data subjects no cross-border transfer arises.
8.8 Retention. Usage Analytics is retained for 24 months and is then deleted or irreversibly aggregated.
8.9 Control and opt-out. Use Tracking can be disabled. The mechanism to do so is described in the Zebra BI Privacy Policy for Visuals and the applicable security documentation. Usage Analytics strictly necessary for authentication and license validation cannot be disabled without disabling the corresponding feature.
8.10 Data-subject rights. Data subjects may exercise their rights of access, objection, rectification and erasure in respect of Usage Analytics by contacting ZEBRA BI at privacy@zebrabi.com. ZEBRA BI responds without undue delay. ZEBRA BI honours right-to-erasure requests in respect of the analytics store. Because Usage Analytics does not identify individual data subjects, ZEBRA BI may be unable to locate the events of a particular individual and is not obliged to obtain additional information in order to do so (Article 11 GDPR).
9.1 Each party shall comply with applicable data protection laws, including the GDPR. Roles differ by data category:
9.2 Controller role analytics. Because Zebra BI acts as a controller for Usage Analytics it is not the subject of a customer data processing agreement. ZEBRA BI's controller terms are set out in Section 8 of this Agreement.
10.1 The Uncertified Visuals are provided “as is”, “as available” and “with all faults”. To the extent permitted under applicable legislation, ZEBRA BI disclaims all warranties, including the implied warranties of merchantability, fitness for a particular purpose, title and non-infringement.
10.2 Uncertified status. The Uncertified Visuals do not hold Microsoft Certification and by design, make external network calls and may involve Zebra BI managed service components. ZEBRA BI makes no representation that the Uncertified Visuals qualify for, or will be submitted for, Microsoft Certification, and is under no obligation to provide a certified equivalent. Nothing in this Agreement shall be read as an unqualified guarantee that no data is ever processed by Zebra BI managed components. The applicable product and security documentation governs the data flows for each visual.
10.3 ZEBRA BI has followed Microsoft's development guidelines and code quality requirements and provides the same level of maintenance and support for the Uncertified Visuals as for its certified visuals; however this Section 10.3 does not expand the warranties disclaimed above.
ZEBRA BI shall be liable for intentional conduct, gross negligence, as well as, in situations where ZEBRA BI is liable according to mandatory and/or statutory legislation. In cases of slight negligence that do not represent a breach of material contractual obligations, the fulfilment of which facilitates the performance of this Agreement, ZEBRA BI will not be liable.
11.1. LIMITATIONS OF LIABILITY
ZEBRA BI will not be responsible under this Agreement (i) if the Software product is not used in accordance with this Agreement and/or EULA Order Form; (ii) if the liability is caused by Licensee; (iii) if the Software product is used in conjunction with any Third-Party products for which the Licensee lacks sufficient rights from the Third-Party for such use; or (iv) for any Licensee's activities not permitted under this Agreement or EULA Order Form.
11.2. AGGREGATE LIABILITY
To the maximum extent permitted by law, ZEBRA BI's aggregate liability under this Agreement is capped at the fees paid by the Licensee during the twelve (12) months preceding the event giving rise to liability.
ZEBRA BI shall not be liable for any special, consequential, indirect or incidental damages, including loss of goodwill or profits, work stoppage or data loss.
12.1 Uncertified Visuals or features may be made available as Beta or Preview. Beta or Preview access may be complimentary, is provided for evaluation and testing only, is not intended for production use, and may change, be delayed or be withdrawn without notice. It is provided "as is" with no warranties or service level commitments. Forward looking descriptions of features do not constitute a commitment to deliver them, and pricing/packaging will be confirmed before general availability.
13.1 Each party shall protect the other's confidential information for five (5) years from disclosure, and trade secrets for as long as they remain trade secrets, subject to customary exceptions (public domain, independent development, and legally required disclosure).
14.1 The Licensee may terminate on thirty (30) days' written notice, and only after payment of all fees then due and owing to ZEBRA BI. ZEBRA BI may terminate immediately for material breach or non payment.
14.2 On termination, the Licensee must cease use of and destroy all copies of the Uncertified Visuals. No refunds are due for unused periods. Comment Data stored in the Customer Tenant remains with the Licensee.
15.1 This Agreement is governed by and construed under the laws of the Republic of Slovenia, without reference to its conflicts of law principles and excluding the UN Convention on Contracts for the International Sale of Goods. The parties submit to the exclusive jurisdiction of the Slovenian Courts.
16.1 ZEBRA BI may modify this Agreement from time to time, including the Schedule, in its sole discretion. ZEBRA BI will notify the Licensee of changes by email and by posting a revised version online. Continued use after the effective date of a revised version constitutes acceptance. Where a change materially affects the Licensee (including changes to Use Tracking under Section 8), ZEBRA BI will provide reasonable notice describing the change and its rationale, and will make clear where a change does not apply to a given Licensee's configuration.
17.1 Assignment. The Licensee may not assign or transfer this Agreement or any of its rights or obligations under it, in whole or in part, without ZEBRA BI's prior written consent, which ZEBRA BI may refuse in its sole discretion. ZEBRA BI may assign this Agreement to an affiliate or in connection with a merger, acquisition or sale of all or substantially all of its assets. Any purported assignment in breach of this clause is void.
17.2 Entire agreement. This Agreement, together with the applicable EULA Order Form and the General EULA, constitutes the entire agreement between the parties with respect to the Uncertified Visuals and supersedes all prior discussions, representations and agreements on that subject matter. In the event of a conflict, the following order of precedence applies: (i) the EULA Order Form; (ii) this Agreement; and (iii) the General EULA.
17.3 Notices. All notices under this Agreement shall be in writing and shall be deemed duly given when delivered to the address or account identified in the Licensee's ZEBRA BI account or the applicable EULA Order Form. Notices to ZEBRA BI shall also be sent to legal@zebrabi.com.
17.4 Severability. If any provision of this Agreement is held to be illegal, invalid or unenforceable, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall continue in full force and effect.
1. Roles. ZEBRA BI acts as Processor and the Licensee as Controller for the limited Personal Information processed via SSO and the Zebra BI Server for authentication, Designated User management, license validation/management and comment attribution. This Personal Information is limited to Designated User’s identity, name and email address, carried in Microsoft Entra SSO tokens. This identity reaches and is processed by ZEBRA BI infrastructure to support authentication, licensing and comment attribution, and is then returned: it is processed but not stored on ZEBRA BI systems. Comment Data content and the data displayed in the visuals are processed by the Licensee within the Customer Tenant.
2. Duration / nature / purpose. Processing is in transit for the purposes in clause 1 and recurs for the term of the Agreement; ZEBRA BI does not retain this Personal Information beyond the processing and does not store any of it.
3. Data subjects / data. Designated Users; identity (name and email/UPN) contained in SSO tokens, and authentication and license validation events. Data is processed in transit and is not stored by ZEBRA BI.
4. Security & breach. Appropriate technical and organizational measures in accordance with the Security Assessment available here: https://zebrabi.com/legal/?doc=security; notification of a personal data breach affecting this Personal Information without undue delay and within 36 hours of becoming aware of such a breach.
5. Location. European Union: the Netherlands (Microsoft Azure, West Europe region) for the processing under this Annex, and Germany (PostHog Cloud EU, Frankfurt) for Usage Analytics under Section 8.
6. Sub-processors. For the processing under this Annex, ZEBRA BI will maintain a current list of any sub-processors it engages (for example, hosting or infrastructure providers for the Zebra BI Server). ZEBRA BI will give the Licensee at least 30 days' notice after addition or replacement of a sub-processor. The Licensee may object within 14 days on reasonable data-protection grounds; if ZEBRA BI cannot accommodate the objection, the Licensee may terminate the affected part of this Agreement. The product analytics sub-processor (PostHog) is engaged only for Usage Analytics under Section 8, as described in clause 7 below, and not for the processing under this Annex.
7. Sub-processor (analytics). PostHog is the product analytics sub-processor. It collects and processes pseudonymous usage/event telemetry (for example, page views, clicks, and performance and errors). Session replay/recording is not enabled for the Uncertified Visuals. Hosting: EU (PostHog Cloud EU, Frankfurt) or self-hosted EU, as configured.
This Schedule lists the Uncertified Visuals covered by this Agreement. ZEBRA BI may update this Schedule as new uncertified visuals are released. The updated Schedule forms an integral part of this Agreement as determined in Section 16 of this Agreement. The current status of each + visual, and its external communications and data flows, are set out in the applicable product and security documentation, which is updated per release.
| Uncertified Visual | Distribution |
| Zebra BI Tables+ | Microsoft AppSource (uncertified listing); organizational store; direct/private package |
| Zebra BI Charts+ | Microsoft AppSource (uncertified listing); organizational store; direct/private package |
| Future uncertified visuals, including all Zebra BI future visuals or versions that are not certified through Power BI | Microsoft AppSource / organizational store / direct package |
Date of publication: 02.11.2021
This privacy policy ("Privacy Policy") seeks to explain how ZEBRA BI d.d. and its affiliates (“ZEBRA BI”, “Company”, “we”, "us", "our") use the data you give us through www.zebrabi.com ("Website") and Zebra BI for Power BI Custom Visual - Published ("Custom Visual") on Microsoft AppSource or Privately distributed. Your use of the Website, Custom Visual, or any submission of any information by you to the Website or Custom Visual (directly or indirectly) means that you agree that we may use that data submitted by you in accordance with this Privacy Policy.
At ZEBRA BI d.d. we are aware of the importance of personal data protection. As the controller of personal data, we handle the collected personal data responsibly and in accordance with the applicable regulations in the field of personal data protection, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“General Data Protection Regulation”, “GDPR”), other applicable regulations on the protection of personal data and our internal acts. In order to implement the principle of fair and transparent processing, we have prepared this Personal Data Protection Policy (“Privacy Policy”), which enables individuals to obtain all relevant information relating to their personal data when using our website https://zebrabi.com/.
The "provider", "website owner", "Custom Visual owner" and "personal data controller" (jointly the "Controller") of https://zebrabi.com/ as defined by the GDPR and other applicable regulations on the protection of personal data is:
Company: ZEBRA BI informacijske rešitve d.d.
Registered seat: Pot za Brdom 104, 1000 Ljubljana, Slovenia
Company ID: 6629997000
VAT ID: SI 35190108
The seat of incorporation: Republic of Slovenia
For all questions and assistance in exercising the rights of individuals, we have appointed a contact center for personal data protection that can be reached via the e-mail address at: support@zebra.bi or via regular post addressed to our Registered seat: ZEBRA BI d.d., Pot za Brdom 104, 1000 Ljubljana, Slovenia with the annotation “Protection of Personal Data”.
The “User” of our website or Custom Visual is any person who uses the website https://zebrabi.com/ and any of the associated websites of Zebra BI d.d. as a visitor or uses Custom Visuals developed by Zebra BI and published on Microsoft AppSourse or Privately distributed.
Personal data is any data that can be used to directly or indirectly identify an individual. A natural person is identifiable directly or indirectly, in particular by providing an identifier, such as name, identification number, location data, web identifier, or by specifying one or more factors specific to the natural person. Depending on the circumstances of each case, we may collect and process the following personal data:
Apart from the user information content you voluntarily share by signing up or authenticating via a 3rd Party Authentication Provider, no other information is collected or aggregated in the Custom Visual and transmitted to our servers. We do not log any actions, events, or data being managed or visualized within the Custom Visual involuntarily.
We are committed to protecting the data you share with us. Zebra BI uses a combination of industry-standard security technologies, procedures, and organizational measures to help protect your data from unauthorized access, use, or disclosure. Company supports online security using secure server technology because we want your data to be safe. We bind our employees and data processors to observe your privacy and confidentiality rights.
We collect and process personal data for the purpose of fulfilling contractual obligations pursuant to Article 6(1), lit. b GDPR or under the equivalent article under other national laws, when applicable. Processing when necessary to fulfill contractual obligations includes processing the personal data of the contracting parties (e.g. employment contracts, employment contracts, company contracts, sales contracts, etc.) and possibly collecting and processing personal data of external contractual collaborators. Personal data required for the fulfillment of contractual obligations (in particular data on date of birth, gender, tax number, contact details, residence data, transaction account data, profession, education, registration number, data on submitted personal documents, and other submitted documents or those personal data necessary for the purpose of the legal relationship) is collected exclusively to the minimum extent permitted for the individual purpose. The stated data is also collected and processed in the phase of concluding agreements, negotiations, responding to your related inquiries, processing your feedback, or providing you with support. We keep several records of personal data processing activities, which show the types of personal data, the purposes of their processing, the basis for collection and processing, retention periods, access to data, etc.
We collect and process personal data in order to ensure compliance. Our products, technologies, and services are subject to export laws of various countries including, without limitation, those of the European Union and its member states, and of the United States of America. You acknowledge that pursuant to the applicable export laws, trade sanctions, and embargoes issued by these countries, we are required to take measures to prevent entities, organizations, and parties listed on government-issued sanctioned-party lists from accessing certain products, technologies, and services through our website or other delivery channels controlled by us. This could include (i) automated checks of any User registration data as set out herein and other information a User provides about his or her identity against applicable sanctioned-party lists; (ii) regular repetition of such checks whenever a sanctioned-party list is updated or when a User updates his or her information; (iii) blocking of access to SAP’s services and systems in case of a potential match; and (iv) contacting a User to confirm his or her identity in case of a potential match. Any such use of your personal data is based on the permission to process personal data in order to comply with statutory obligations (Article 6 para. 1 lit. c GDPR or the equivalent articles under other national laws, when applicable) and our legitimate interest (Article 6 para. 1 lit. f GDPR or the equivalent articles under other national laws, when applicable).
We collect and process personal data based on our legitimate interest pursuant to Article 6 para. 1 lit. f GDPR or the equivalent article under other national laws, when applicable, such as for the purpose of preventing or prosecuting criminal activities (e.g. fraud and to assert or defend against legal claims). When processing personal data based on our legitimate reason, we always weigh the interests of individuals for such processing and our interests as Controllers to determine, whether the interests and fundamental rights of individuals prevail over our interests, to which personal data relate and which require the protection of personal data. In particular, during processing, we respect the principle of minimum data use, whereas personal data has to be relevant and limited to what is necessary for the purposes for which they are processed.
We also collect and process personal data, if you granted prior consent of your personal data in accordance with Article 6(1) lit. a GDPR or the equivalent article under other national laws, when applicable. Processing based on the consent of individuals is conducted for the purpose of direct marketing of our services and products, e.g. for informing about novelties of our services and products, responding to your related inquiries, processing your feedback, or providing you with support via e-mail, telephone or regular mail.
You may at any time withdraw a consent granted hereunder by “unsubscribing”. In case of withdrawal, we will not process personal data subject to this consent any longer unless legally required to do so. In case we are required to retain your personal data for legal reasons, your personal data will be restricted from further processing and only retained for the term required by law. However, any withdrawal has no effect on the past processing of personal data by us up to the point in time of your withdrawal. Furthermore, if your use of our offering requires your prior consent, we will not be able to provide the relevant service or offer to you after your revocation. For more information regarding the processing of personal data based on consent, you may contact our contact center for personal data protection that can be reached via the e-mail address at: support@zebra.bi or via regular post addressed to our Registered seat: ZEBRA BI d.d., Pot za Brdom 104, 1000 Ljubljana, Slovenia with the annotation “Protection of Personal Data”.
In addition to ZEBRA BI, the personal data of individuals is also processed by external processors, in particular accounting. In that events, we have concluded an appropriate written agreement on the processing of personal data or a similar agreement in terms of content. We provide personal data to other users of personal data if so required under applicable legislation if there is a legitimate interest or if we have the consent of the individual.
We do not transfer the collected personal data to third countries. In the event that we have transferred the personal data of an individual to third countries, we will ensure the provision and implementation of appropriate measures to ensure the security of personal data and the fundamental rights and freedoms of individuals, in accordance with applicable legislation.
An individual may address a written request to the contact center for personal data protection that can be reached via the e-mail address at: support@zebra.bi or via regular post addressed to our Registered seat: ZEBRA BI d.d., Pot za Brdom 104, 1000 Ljubljana, Slovenia with the annotation “Protection of Personal Data”, to provide the following information regarding the collection and processing of personal data, namely the individual has the following rights:
We will provide the individual with the requested information upon written request without undue delay and in any case within 1 (one) month of receiving the request. This period may be extended, if necessary, by a maximum of 2 (two) additional months, taking into account the complexity and number of requirements. We shall notify the individual of such an extension within 1 (one) month of receiving the request, together with the reasons for the delay. The information provided in this way is provided to the individual free of charge. Where the individual’s requests are manifestly unfounded or excessive, in particular, because they are repeated, we may charge the individual a fee or refuse to act on the request.
We will only retain your personal data for the needs in accordance with the conditions and for the purposes defined in this Privacy Policy. Personal data is stored on our website and in case of further processing and communication with the User in other databases of the Controller.
The retention period of personal data may vary depending on the applicable legislation (i.e. mandatory law). In the event that the applicable legislation sets mandatory time limits for the storage of personal data, we shall delete personal data after the expiry of the mandatory time limit prescribed by applicable legislation. We shall also delete, destroy, block or pseudonymize personal data after the purpose of processing has been fulfilled, unless the applicable legislation provides otherwise.
Zebra BI is committed to ensuring that your identifiable and non-identifiable personal information is secure. We have put in place suitable physical, electronic and managerial procedures to prevent unauthorized access, modification, disclosure, or loss of your identifiable personal information. However, Zebra BI may disclose personally identifiable information under special circumstances, such as to comply with subpoenas when a users actions may violate this privacy policy and the Terms of Service. Additionally, we are not responsible for any breach of security or actions undertaken by any third parties that receive the information.
If you believe that your personal data is processed in contravention of applicable regulations governing the protection of personal data, you have the right to lodge a complaint with the competent state authority:
State Authority: Information Commissioner of the Republic of Slovenia
Address: Dunajska cesta 22, 1000 Ljubljana, Slovenia
Contact:
T: +386 1 230 97 30
E: gp.ip@ip-rs.si
W: https://www.ip-rs.si/
ZEBRA BI’s website https://zebrabi.com/ uses cookies in order to provide online services, advertising systems, and functionalities that it would not be able to provide without cookies. By visiting and using the website, the User of the website agrees to cookies, and express their consent by clicking on an empty field for a particular purpose of data processing.
A cookie is any information that a website sends to the User's browser, which then stores it in the User's system. A cookie allows a website to remember information about the User's settings until the User closes the current browser window (if the cookie is temporary) or until the cookies are disabled or deleted. Cookies are essential to provide User-friendly online services. The most common e-commerce features would not be possible without cookies. The interaction between the User and the website is faster and easier with the help of cookies. With their help, the website remembers the individual's preferences and experiences, which saves time and makes browsing the website more efficient.
If the User of the website wants to change the way cookies are used in the browser, including blocking or deleting, he can do so by changing the browser settings accordingly. Cookies stored by the browser can be deleted by the User. The process for managing and deleting cookies varies from browser to browser. The User can find more detailed information on how to delete cookies on the website of the browser he is using.
Our website uses the following cookies:
Necessary cookies
Help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Duration: 13 months
Analytics cookies
These cookies help us to understand how visitors engage with the website. We may use a set of cookies to collect information and report site usage statistics. In addition to reporting site usage statistics, data collected may also be used, together with some of the advertising cookies described, to help show more relevant ads across the web and to measure interactions with the ads we show.
Duration: 13 months
Functionality cookies
We use a set of cookies that are optional for the website to function. They are usually only set in response to information provided to the website to personalize and optimize your experience as well as remember your chat history.
Duration: 13 months
Marketing cookies
We use cookies to make our ads more engaging and valuable to site visitors. Some common applications of cookies are to select advertising based on what’s relevant to a user; to improve reporting on ad campaign performance, and to avoid showing ads the user has already seen.
Duration: 13 months
Zebra BI reserves the right, in its discretion, to change, modify, add to, or remove portions of this Privacy Policy (collectively, “Changes”), at any time. Zebra BI will notify you of Changes by posting a revised version of this Privacy Policy incorporating the Changes to its website. Your continued use of the website or Custom Visual following notice of the Changes will mean that you accept and agree to the Changes. Such Changes will apply prospectively beginning on the date the Changes are posted to the website.
END OF PRIVACY POLICY
Last updated: 8.9.2026
This privacy policy ("Privacy Policy") seeks to explain how ZEBRA BI d.d. and its affiliates ("ZEBRA BI", "Company", "we", "us", "our") use the data you give us through Zebra BI for Excel and Zebra BI Visuals for Microsoft Power BI (jointly "Custom Visuals") published on Microsoft AppSource or privately distributed.
Your use of Custom Visuals or any submission of any information by you to Custom Visuals, directly or indirectly, means that you agree that we may use that data submitted by you in accordance with this Privacy Policy.
Please read this Policy before using Custom Visuals. If you do not want your information to be processed by Custom Visuals, please do not use Custom Visuals and/or provide it to us.
The "Custom Visuals" as described in this Policy apply to any of the visuals from the following list of Custom Visuals developed by Zebra BI:
Some of the visuals above are Microsoft certified and some are uncertified.
Zebra BI Tables+ for Power BI and Zebra BI Charts+ for Power BI (together, the "+ visuals") are uncertified visuals: they can make external calls to deliver certain features (for example, fetching comments from your Microsoft 365 tenant, and authentication and license validation). Because of this, additional processing described in this Policy applies to the + visuals and not to our Microsoft certified visuals.
Apart from the user information content you voluntarily share by signing up or authenticating via a 3rd Party Authentication Provider, no other information about the data you visualise is collected or aggregated in the Custom Visual and transmitted to our servers. We do not log any actions, events, or data being managed or visualized within the Custom Visual involuntarily.
This statement concerns the data you visualize in the Custom Visual.
For our uncertified visuals (the "+ visuals"), we additionally collect limited pseudonymous usage analytics as described in Section 5 ("Usage analytics for the + visuals") below.
With Zebra BI Tables + for Power BI and Charts + for Power BI Custom Visuals, viewers can comment on specific data points (months, categories, variances) directly within Power BI reports. The comments are stored in SharePoint Excel files within your Microsoft 365 tenant, using Microsoft Graph API, no dataset refresh is required. The permission management leverages your existing Microsoft 365 infrastructure, the same SharePoint access model your teams already use. All comment data stays within your tenant, governed by your organization’s data residency and compliance policies.
Custom Visuals provided by Zebra BI use information that is provided through either the Microsoft Power BI platform or Office 365 platform and/or application to convert it into a visual representation. The process of transformation is executed in the memory of the device that the user is using. Custom Visuals are not storing, sending, and/or reusing your Data for any other purpose than rendering the interactive visualizations in your Microsoft Power BI platform and/or Excel instance.
Zebra BI Tables+ for Power BI and Zebra BI Charts+ for Power BI Custom Visuals' comments are fetched via Microsoft Graph API, completely independent of your Power BI data model. There is no new data source to connect, no semantic model to modify and no data set refresh to schedule. When a user opens or refreshes a report page, the Custom Visual Zebra BI Tables+ for Power BI and Zebra BI Charts+ for Power BI loads the latest comments directly from SharePoint governed by your organization.
Your data is never transferred/shared with other parties by Custom Visual, except that, for the + visuals, limited pseudonymous usage analytics is processed on our behalf by our analytics processor as described in Section 5.
Custom Visuals are designed so that customer business data and data visualized within the Custom Visuals are not stored on Zebra BI servers.
Zebra BI may process limited technical, account, usage, diagnostic, and support-related information as described in the applicable End User License Agreement, Data Processing Agreement, and related privacy documentation, including for product improvement, security, support, compliance, and service operation purposes. Such processing is subject to applicable confidentiality, security, and data protection obligations. For the + visuals, the usage analytics we process is described in Section 5.
All comment data from Zebra BI Tables+ for Power BI or Zebra BI Charts+ for Power BI is stored in Excel files within your organization's SharePoint environment. Comment content stays within your Microsoft 365 tenant. You control retention, backup and audit policies using your existing SharePoint governance. The Excel file uses a standard readable format. All communication uses standard Microsoft Graph API.
Scope. This section applies only to Zebra BI's uncertified visuals (the "+ visuals", currently Zebra BI Tables+ and Zebra BI Charts+) and only where usage tracking is active. It does not apply to our Microsoft-certified visuals, which make no external calls and collect no usage analytics.
What we collect (event list). Because the + visuals can make external calls, we collect a small, defined set of pseudonymous product usage events, for example: visual loaded, comment added, filter applied, view mode toggled, data refreshed and export triggered, together with technical and session context (visual version, the Power BI environment (Desktop, Service or Embedded) and the browser) and a pseudonymous identifier. Automatic capture of undefined events is not used.
What we do not collect. We do not collect through usage tracking: any of the business or financial data shown in or bound to the visual, cleartext names, email addresses or Microsoft Entra ID identifiers, screenshots or visual renders, keystrokes or free-text input, or data from other visuals on the same report page. We do not use session replay or session recording for the + visuals. Comment content is not collected through usage tracking.
Controller and processor. For this usage analytics, Zebra BI is the data controller and PostHog acts as our processor. The individual users of the + visuals are the data subjects. Your organization is neither controller nor processor of this usage analytics.
Legal basis. We process this usage analytics on the basis of our legitimate interests (Article 6(1)(f) GDPR) in understanding feature adoption, activation and retention, in order to operate, secure, support and improve the visuals and to simplify licensing. The processing is limited to interaction and technical telemetry and its impact on data subjects is minimal. A Legitimate Interests Assessment is maintained by Zebra BI.
Processor and location. Usage analytics is processed by PostHog, hosted in the EU (PostHog Cloud EU, Frankfurt) or self-hosted in the EU, with geolocation lookup disabled, so that for EU data subjects no cross-border transfer arises.
Retention. We retain usage analytics for 24 months and then delete or irreversibly aggregate it.
How to disable it (opt-out). Power BI does not offer a per-visual telemetry opt-out at tenant-administrator level. The tenant administrator’s choice is to allow, or to block, uncertified visuals entirely. You can block usage tracking at your network by blocking the analytics endpoint host names used by the + visuals. These host names are listed in the Zebra BI security documentation, which is kept current and updated per release. Usage analytics strictly necessary for authentication and license validation cannot be disabled without disabling the corresponding feature.
Your rights. You may exercise your rights of access, objection, rectification and erasure in respect of usage analytics by contacting us at privacy@zebrabi.com. We respond without undue delay and within one month. We honor right to erasure requests in respect of the analytics store. Because usage analytics does not identify individual data subjects, we may be unable to locate the events of a particular individual and are not obliged to obtain additional information in order to do so (Article 11 GDPR).
We are committed to protecting the data you share with us. Zebra BI uses a combination of industry standard security technologies, procedures, and organizational measures to help protect your data from unauthorized access, use, or disclosure. Zebra BI supports online security using secure server technology because we want your data to be safe. We bind our employees and data processors to observe your privacy and confidentiality rights.
You are liable for the appropriate use of Custom Visuals. All copyrights in or to the Custom Visual are owned by Zebra BI. If any provision of the Policy is held invalid or unenforceable by a court of competent jurisdiction, the remaining provisions will remain in full force and effect, and such invalid or unenforceable provisions or portion thereof will be deemed omitted. This Policy is governed by and construed in accordance with the laws of the Republic of Slovenia, and the courts of the Republic of Slovenia will have exclusive jurisdiction to adjudicate any dispute arising under or in relation to the Policy.
Should you have any questions about this Policy, the privacy aspects of our Software and/or Services, or would like to submit any request, please contact us:
ZEBRA BI d.d.
Pot za Brdom 104, 1000 Ljubljana, Slovenia
Email: support@zebrabi.com
For requests concerning usage analytics for the + visuals (access, objection, rectification, erasure), please contact privacy@zebrabi.com.
Zebra BI reserves the right, in its discretion, to change, modify, add to, or remove portions of this Privacy Policy (collectively, "Changes"), at any time. Zebra BI will notify you of Changes by posting a revised version of this Privacy Policy incorporating the Changes to its website. Your continued use of Custom Visuals following notice of the Changes will mean that you accept and agree to the Changes. Such Changes will apply prospectively beginning on the date the Changes are posted to the website.
END OF PRIVACY POLICY
Date of publication: 28.9.2021
The sole "website owner" and "operator" (jointly "ZEBRA BI", “Company”, “We”) of https://zebrabi.com/ and associated websites is:
Company: ZEBRA BI informacijske rešitve d.d.
Registered seat: Pot za Brdom 104, 1000 Ljubljana, Slovenia
Company ID: 6629997000
VAT ID: SI 35190108
Seat of incorporation: Republic of Slovenia
Access to and use of the website are subject to this Terms of use for ZEBRA BI’s website (“Terms of use”), applicable legislation and other regulations referred to in this Terms of use.
The website, including all content and publications, is for informational purposes only. ZEBRA BI does not assume any responsibility for any damage resulting from the use of the website or the content on it. ZEBRA BI carefully and diligently strives to ensure that the content published on the website shows the current and true situation but does not assume any responsibility for any linguistic or content deficiencies, the accuracy of information, technical or other errors, occasional website malfunctions or insufficiently updated content on the site. As there are certain links on the website to other, external websites that are not directly associated with ZEBRA BI, we do not assume any responsibility for the content obtained through external websites, as well as for the protection of personal data and respect for privacy on these websites.
The User of the website (the “User”) is any individual who uses this website and associated websites of ZEBRA BI as a registered or unregistered visitor. Use of the website means that the User agrees to this Terms of use and, as a User of the website, has been previously clearly and comprehensively acquainted with this Terms of use.
ZEBRA BI is the sole owner of all intellectual property rights and copyrights in the broadest sense over the copyrighted content published on the website. Any further reproduction, distribution, modification, public display and broadcasting or other forms of use of copyrighted work, copyrighted content and logo without prior knowledge or permission of ZEBRA BI are prohibited. The website is also not allowed to be used in any connection between the User and ZEBRA BI that does not exist. In the event that the User uses a link to the website in a way that is contrary to this Terms of use or applicable law, ZEBRA BI may request the immediate cessation of use of the website or its link. Users may use the content on the website solely for their private use, and the content may be used in a manner consistent with applicable legislation and without prejudice to our good name, reputation or business. ZEBRA BI and the authors of the content are not responsible for any harmful consequences of further private use.
ZEBRA BI constantly strives to protect personal data and ensure privacy. We handle the personal data you entrust us with in accordance with applicable regulations in the field of personal data protection, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“General Data Protection Regulation”, “GDPR”), other applicable regulations on the protection of personal data and our internal acts. More information on the processing of personal data and the protection of privacy is available in our Privacy Policy.
Zebra BI reserves the right, in its discretion, to change, modify, add to, or remove portions of this Terms of use (collectively, “Changes”), at any time. Zebra BI will notify you of Changes by posting a revised version of this Terms of use incorporating the Changes to its website. Your continued use of the website following notice of the Changes will mean that you accept and agree to the Changes. Such Changes will apply prospectively beginning on the date the Changes are posted to the website.
These Terms of use and any claims arising out of or relating to this Terms of use and its subject matter shall be governed by and construed under the laws of the Republic of Slovenia, without reference to its conflicts of law principles. In the event of any conflicts between foreign law, rules, and regulations, and Slovenia law, rules, and regulations, Slovenian law, rules, and regulations shall prevail and govern, and the parties hereby submit to the exclusive jurisdiction of the Slovenian Courts.
For all questions and assistance to Users, we have appointed a contact centre that can be reached via e-mail address at: support@zebra.bi or via regular post addressed to our Registered seat: ZEBRA BI d.d., Pot za Brdom 104, 1000 Ljubljana, Slovenia.
END OF TERMS OF WEBSITE USE
Date of publication: 13 August 2026. Supersedes the version published 29 May 2022.
Applies to: every Zebra BI custom visual for Microsoft Power BI. A package is certified, and covered by section 3, only if it comes from a Zebra BI listing in Microsoft AppSource that Microsoft marks as certified. Three of our listings carry that mark as of this publication date: Zebra BI Tables, Zebra BI Charts and Zebra BI Cards. Every other package is uncertified and covered by section 4, including Tables+ and Charts+, and any build of those visuals that you obtain from us rather than from AppSource, for which section 1.1 applies as well.
Certification is a property of the package, not the product name. This document describes certified and uncertified packages separately, because the controls that hold for one do not all hold for the other.
The certified visuals make no network calls of any kind. They run inside the Power BI custom visual sandbox, receive data through the Power BI Custom Visuals API, render it in the browser, and send nothing anywhere. Microsoft re-tests this at each release as a condition of certification, and section 3.3 sets out what that testing covers.
The uncertified visuals on AppSource make external network calls. Viewer commenting cannot work without them: writing a comment means writing to storage, and identifying its author means an authenticated identity. Microsoft's certification programme forbids external calls, so these visuals are not certified and cannot be while they carry commenting.
Not every uncertified package makes those calls. Packages we supply you directly, rather than through an AppSource listing, are uncertified because Microsoft never verified them, and in the versions shipping today they make no external calls. A future version may make external calls where a feature requires it. Section 1.1 covers them and is the section to read if that is what you hold.
In every package covered by this document, the data you put into a Zebra BI visual is never transmitted to Zebra BI. Your report data stays in your Power BI tenant. Comment data is written to a file in your own SharePoint. Zebra BI operates no store of customer report data or comment content, and our staff have no access to either unless you share a report with us yourself.
These four hold for every Zebra BI Power BI visual, certified or not, in every version we ship. They are not conditional on configuration, tier or which package you installed.
We do store product usage analytics from Zebra BI Tables+ on AppSource: a small set of interaction events that carry no report data and no comment content, and that identify your organization. Section 4.6 sets out what those events contain and how long we keep them, and section 4.4 covers the one operational log our token service keeps. Section 4.6 names the endpoint to block if you want none of it.
Certification attaches to a specific package from a specific place, not to a product name. A Zebra BI visual is certified only if its package comes from a Zebra BI listing in Microsoft AppSource that Microsoft marks as certified. Coming from AppSource is not sufficient, because we list uncertified visuals there too. Everything without that mark is uncertified, including builds of the certified visuals that you obtain from us directly.
Microsoft, not Zebra BI, awards and displays the mark, and Microsoft's documentation on certified Power BI visuals sets out where it appears: a badge titled PBI Certified on the AppSource listing, a certified badge on a visual imported from within Power BI Desktop or the Power BI service, and a Power BI Certified filter in the in-product gallery that shows certified visuals only. The same documentation states that Microsoft reserves the right to remove a visual from the certified list at its discretion, so check the badge on the listing you install from.
| What you have | Certification | External network calls | Which section applies |
|---|---|---|---|
| Zebra BI Tables, Charts or Cards, from an AppSource listing with the certified badge | Microsoft-certified | None | Section 3 |
| Zebra BI Tables+ or Charts+ Beta, from an AppSource listing without the certified badge | Not certified, by design | Yes, see section 4 | Section 4 |
| Zebra BI Tables, Charts or Cards supplied by us as a package, for your organizational store or with a licence embedded | Not certified | None in the packages shipping today, see 1.1 | Section 4, with 1.1 |
Both uncertified cases above are covered by the Zebra BI End-User License Agreement for Uncertified Visuals, which governs every Zebra BI Power BI visual we distribute without Microsoft certification, whether it exists today or is released later. As of this publication date the uncertified visuals on AppSource are Zebra BI Tables+ and Zebra BI Charts+, both listed as Beta.
Zebra BI for Microsoft Excel and PowerPoint is a separate product with its own assessment at zebrabi.com/legal/?doc=security-office. Zebra AI is a separate hosted service and is not covered here.
Some organizations install Zebra BI Tables, Charts or Cards as a package we supply directly, either for upload to the Power BI organizational store or with a licence already embedded. These are separate builds with their own identifiers, not the certified AppSource package. They do not carry Microsoft certification. The assurance in section 3 rests on Microsoft's verification and does not extend to them, so they are assessed as uncertified.
In the versions shipping today these packages make no external network calls at runtime. The code paths that would make those calls are removed at compile time, in the same way they are for the certified build, so they are not present to be called. The manifest may nonetheless declare hosts the package never contacts: the manifest and the compiled behaviour are produced by different steps of our pipeline, and the manifest does not follow the code when the code changes. To have the declared list reconciled against the build for the version you hold, contact support@zebrabi.com.
These packages are not barred from communicating externally in the way the certified ones are, and a future version may do so where a feature requires it. The preceding paragraph is therefore a statement about the versions shipping today rather than a property of the package type. Where a package we supply begins making external calls, the hosts are listed in section 4.3.
A Power BI administrator can also add a certified AppSource visual to your organizational store. That remains the certified package, with section 3 applying unchanged. What determines certification is where the package came from, not how it reaches the user.
Most of section 4 does not apply to these packages. They are governed by the EULA for Uncertified Visuals and by the release, vulnerability and organizational controls in sections 6 to 10. Sections 4.2 to 4.6 do not describe the packages shipping today: those make no external calls, so they contain no commenting, no identity flow and no usage analytics to assess. Read 4.1, 4.7 and 4.8, then sections 6 to 10.
ZEBRA BI informacijske rešitve d.d., Pot za Brdom 104, 1000 Ljubljana, Slovenia. Company ID 6629997000, VAT ID SI 35190108.
Zebra BI is an independent software vendor. We publish standard software products and do not provide custom development or professional services engagements.
Report security vulnerabilities and suspected security incidents to security@zebrabi.com. Everything else, including questions about this document, privacy and data-subject requests, and anything arising from a security review, goes to support@zebrabi.com or +386 1 256 0286.
Zebra BI management holds accountability for information security, with roles and responsibilities assigned in writing for risk assessment, access control, system ownership, incident reporting and personnel security.
The visual runs in the Power BI custom visual sandbox, an iframe with no access to the host page, to other visuals on the report, or to the network. It receives data through the Power BI Custom Visuals API, transforms it in the memory of the user's device, and draws the result. It cannot modify or write back the underlying data.
Your report data resides in the Power BI platform and in your own upstream data sources. Data residency for that data is determined by your Power BI tenant and Microsoft's service design, not by Zebra BI.

Figure 1. Certified visuals, installed from Microsoft AppSource. Data reaches the visual through the Power BI Custom Visuals API and nothing crosses the tenant boundary.
The certified packages declare no external hosts and no authentication privilege in their manifest, and the code paths that would make network calls are removed at compile time rather than merely switched off. There is no telemetry, no licence call, no feature-flag lookup and no analytics endpoint. Nothing leaves the Power BI platform.
The declared privileges of the certified packages published on AppSource are, in full, ExportContent and LocalStorage. This is a property of how the certified build is produced, and This is a property of how the certified build is produced. Microsoft's certification requirements do not permit a certified visual to declare external host access; see section 3.3. It holds for the packages live today and for every update that follows, for as long as they carry Microsoft certification.
You can confirm this yourself. In Power BI, open the visual's About dialog and review its declared privileges, or download the package from AppSource and read capabilities.json inside it. Section 4.7 describes the same procedure for the uncertified visuals.
Microsoft states that certified Power BI visuals in AppSource are tested to verify that they do not access external services or resources and that they follow secure coding patterns and guidelines, that every submitted update goes through the same checks, and that its testing includes code review, static analysis, data-leakage testing and injection testing. See Microsoft's documentation on certified Power BI visuals.
Certification is a code-level verification performed by Microsoft on each submitted update. It is not a statement about Zebra BI's internal security programme, our training, our tooling or our corporate controls. Those are covered in sections 6 to 10. Because this testing is Microsoft's rather than ours or an independent assessor's, we cannot supply a third-party penetration test report for the certified visuals.
The certified visuals require no Zebra BI login and no identity. They are unlocked by a licence key, valid for one year and reissued on renewal. Sign-in, user provisioning, group membership, workspace access and row-level security are handled entirely by Power BI and Microsoft Entra ID. The visual neither monitors nor manages access to Power BI. Where you use shared or generic Power BI accounts, the visual sees only that account and cannot distinguish the individuals behind it.
Zebra BI personnel have no access to your Power BI tenant, reports, datasets or report data. Even for troubleshooting, our staff can only see a report if you explicitly share one with us.
Sections 4.2 to 4.7 describe Zebra BI Tables+ and Charts+ as installed from Microsoft AppSource, the uncertified visuals that communicate externally. Any other uncertified package is covered by 4.1, 4.7 and 4.8 and by sections 6 to 10: a package we supply directly, covered in section 1.1, and any package from a listing that does not carry the certified mark when you install it. For those, contact support@zebrabi.com about the version you hold.
Packages we supply to you directly, covered in section 1.1, are also uncertified and are governed by the same agreement, but almost none of what follows describes the ones shipping today: they make no external calls, so there is no commenting flow, no identity exchange and no usage analytics to assess. For those packages, read 4.1, 4.7 and 4.8, then go to sections 6 to 10. Check 1.1 for the version you hold.
A defining requirement of Microsoft's "Power BI certified" designation is that the visual makes no external network calls. Viewer commenting requires them. A comment has to be stored somewhere durable and shared, and it has to be attributed to a real person, which means an authenticated identity. The two requirements are mutually exclusive. These visuals are therefore not certified, and will not be while they include commenting.
This is a deliberate product decision, not a lapsed certification. We make no representation that these visuals will be submitted for certification, and your Power BI administrator can block uncertified visuals tenant-wide.

Figure 2. Uncertified visuals. Report data and comment text stay in the customer tenant. Two things cross to Zebra BI in the EU: the identity token, verified and exchanged in transit for a Microsoft Graph token and not stored, and pseudonymous product usage events from Tables+.
Report data reaches the visual exactly as it does in the certified build, through the Power BI Custom Visuals API, and it does not leave. Comment data travels to Microsoft Graph and lands in a file in your own SharePoint. Only two things cross into Zebra BI infrastructure: an identity token, which we exchange for a Microsoft Graph token and hand back to the visual, and a small set of product usage events. Both are described below.
The table below lists every host declared in the manifest of an uncertified visual on AppSource, and states which of them the visual contacts at runtime. The two sets are not the same.
A Power BI visual declares an allowlist of hosts in its manifest. That allowlist is what the platform permits; it is not a record of what the visual does. Ours is broader than our traffic, because the manifest and the compiled behaviour are produced by different steps of our pipeline and the manifest does not follow the code when the code changes. The Host column lists every host the manifest declares. The "Contacted at runtime" column states which of them a shipped package contacts.
Two qualifications apply to the declared list. Zebra BI Tables+ packages before version 8.3.1 declared a wildcard host allowlist rather than the explicit list below. That was a manifest defect, not additional traffic; every Tables+ package from 8.3.1 onward declares the explicit list. Charts+ already declares the explicit list, minus the analytics host, which it does not contact. A package you open today may declare more hosts than this table lists. No shipped package contacts more than the "Contacted at runtime" column states.
If a manifest and this table do not reconcile, ask us at support@zebrabi.com about the version you hold.
| Host | Contacted at runtime | Purpose | Processing location | If you block it |
|---|---|---|---|---|
graph.microsoft.com | Yes | Reads and writes comment data in your own SharePoint, and reads the signed-in user's own profile for comment attribution | Your Microsoft tenant, region set by Microsoft | Commenting stops working. Reporting is unaffected. |
api.zebrabi.com | Yes | Exchanges your Microsoft Entra SSO token for a Microsoft Graph token, so the visual can reach SharePoint as the signed-in user | Microsoft Azure, West Europe, behind Azure Front Door | Commenting stops working. Reporting is unaffected. |
eu.i.posthog.com | Yes | Product usage analytics, section 4.6 | PostHog Cloud EU, Frankfurt, Germany | Usage analytics stops and reporting is unaffected. See the note below on what else it forecloses. |
flagsmithzebra.eastus.cloudapp.azure.com | No | Feature flags. Flag values are compiled into the package when we build it, so the shipped visual never contacts this host. | Microsoft Azure, East US. Contacted by our build servers, never by your browser. | No effect. No request is made. |
apidev.zebrabi.com | No | Our non-production host, which our development and QA teams use to exercise the same package against a test environment. A production build resolves to api.zebrabi.com and never calls this host. Removing it from the manifest of production packages is tracked as a maintenance change. | Not contacted | No effect. No request is made. |
The manifest also declares wss://app.powerbi.com:8080, which is a Microsoft Power BI platform address rather than one of ours. No Zebra BI code calls it. Removing it from the declaration is tracked as a maintenance change; ask support@zebrabi.com for its status. Of the visuals on AppSource as of this publication date, only Tables+ contacts the analytics endpoint. Charts+ declares every host above except that one and sends no usage analytics.
On blocking the analytics endpoint, one consequence is worth stating rather than discovering later. Licensing does not depend on usage analytics today, so blocking it costs you nothing you currently have. It does close the path to things the data is meant to support: showing you your own utilisation and adoption across the seats you pay for, and simplifying provisioning and renewal so that you are not reconciling seat counts by hand. If that matters to you, block the endpoint now and tell us, and we will treat you as opted out when those capabilities arrive rather than assuming otherwise.
Commenting needs to know who is writing, so the uncertified visuals use Microsoft Entra single sign-on. Enabling it requires two steps by you: your Power BI administrator turns on SSO for AppSource visuals, and grants a one-time organizational consent to the Zebra BI application. Individual users then sign in as themselves. Without those steps the commenting features do not operate, and the reporting features are unaffected.
The application requests three Microsoft Graph permissions. All three are delegated: they are exercised in the user's browser, as that user, and are bounded by what that user can already reach. It grants the visual no access the person using it does not already have, and it grants Zebra BI nothing: nobody here holds these permissions or can act with them.
| Delegated permission | Why the visual needs it | What it does not allow |
|---|---|---|
Files.ReadWrite.All | Writing comments into the comment workbook, and reading them back. The workbook is the only file the visual touches. | It reaches no file the signed-in user cannot already open, and it grants no access to your tenant as an organization. |
Sites.Read.All | Letting a report author browse SharePoint to choose the site and file where comments should be stored. | It is read-only, and it surfaces only sites and files the signed-in user can already find. It cannot write anywhere. |
User.Read | Reading the signed-in user's own profile, which is where a comment's author name comes from. | It is self-only. The visual cannot read your directory, enumerate users, or look up anyone other than the person using it. |
On the word "All" in two of those names. In a delegated permission, .All does not mean the whole tenant. It means everything the signed-in user already has access to, and nothing beyond it. Files.ReadWrite.All exercised by a user who can open three SharePoint files reaches exactly those three files. The scope name describes the breadth of the permission type, not the reach of the app. The equivalent application permission, which would grant tenant-wide access under Zebra BI's own identity, is not requested and is not held: there is no Zebra BI service account anywhere in this flow. Microsoft sets out the difference between delegated and application permissions in its overview of Microsoft Graph permissions.
None of these touches mail, calendars or Teams, and the visual writes to no file other than the comment workbook the report author selected. Consent is granted by your administrator, and revoked by your administrator, in Microsoft Entra without involving us. Section 4.5 covers what is stored in that workbook.
The permissions granted in your tenant are shown on the Microsoft Entra consent screen before approval, and afterwards at any time under Enterprise applications, in the permissions view. If that set does not match the three above, tell us at support@zebrabi.com. If it does not match the description here, tell us at support@zebrabi.com.
Two tokens are involved, with different audiences.
api.zebrabi.com. Our service verifies the signature against your own tenant's published keys at login.microsoftonline.com, and checks the issuer and the audience.Identity reaches Zebra BI infrastructure. From the verified token our service reads the signed-in user's Microsoft Entra object identifier, the tenant identifier and the token's subject claim. It uses them for the exchange and nothing else. Tokens issued by Microsoft Entra may carry further claims such as a name or user principal name; our service neither reads nor requires them.
Nothing is retained from the token itself. The service holds no database and no storage account, writes no token to any log, and keeps no user identity after the request ends.
Our service logs three records. The tenant identifier, as an operational metric so that we can count how many organizations use the feature; it is an organization GUID, not a person. The platform access log records the source IP address and user agent of each request. A failed request also writes a diagnostic entry carrying the error Microsoft Entra or Microsoft Graph returned. All of it sits in Microsoft Azure, West Europe, and is held for 90 days. We write no token or secret to any log, and we record no user object identifier or user name of our own.
Comments are stored in an Excel workbook that you choose, in a SharePoint site that you own, inside your own Microsoft 365 tenant. You pick the site, folder and file through a picker in the visual. Zebra BI keeps no copy. Throughout this document, comment data means the whole stored record. Comment content means everything the visual writes into the content column: the comment text, the filter context it was made in, and the value of the data point it is anchored to.
Each comment is one row in a worksheet named Annotation, with columns for a unique identifier, type, tenant ID, user ID, user name, content, created and updated timestamps, and status. The content column holds the comment as a JSON string, including its text, the filter context it was made in, and the data point it is anchored to.
Permissions are file-level. SharePoint's securable object is the file, so every user who can open the comment workbook can read all of the comments in it. Read and write access are enforced by SharePoint and Microsoft Graph, because the visual calls Graph with the signed-in user's own delegated token: a user with read-only access to the file receives an authorization error on any attempt to write, and bypassing the visual's interface does not change that. The finer distinctions the interface makes, such as whether you may delete someone else's comment, are enforced in the browser and are enforced in the browser and are not a security boundary.
Row-level security does not extend to comments. A comment is anchored to a data point, and the value of that data point is written into the stored comment. A user whose row-level security scope hides a figure in the report can therefore read that figure by opening the comment workbook, if they have access to the file. The control is file placement: put the comment file where its SharePoint permissions match the audience that should see the underlying data, and use separate comment files for audiences with different data scopes.
Deletion is a status change. Deleting a comment in the visual marks its row as deleted and hides it. The text remains in the workbook and is readable by anyone who opens the file. To remove it, edit or delete the workbook in SharePoint. Earlier versions persist in SharePoint version history until you purge them.
Comment content is stored in clear text. The workbook carries no Zebra BI encryption or obfuscation layer. Encryption at rest and in transit for that file is Microsoft 365's, on your tenant's terms.
Everything else about that file is governed by you: retention, backup, versioning, audit and access all run through your own SharePoint and Microsoft 365 governance. SharePoint version history is the restore path, and you can use it without involving us. Audit logging of who opened or changed the file is Microsoft's, in your tenant, not ours. The visual provides no way to edit a saved comment: a comment can be added and marked deleted. The updated timestamp records status changes such as deletion.
An uncertified visual may send a small set of product usage events to our analytics processor. Of the visuals on AppSource, this applies to Tables+ from version 8.3.1 onward. Charts+ sends none, earlier Tables+ packages contain no analytics code at all, and the certified visuals cannot carry it. To determine whether the version you have installed sends analytics, use the network-tab check in section 4.7 and look for a request to eu.i.posthog.com. The purpose and retention commitments below are the ones set out in the EULA for Uncertified Visuals.
One event is emitted, once, when the visual loads. It carries the visual name and version, which Power BI environment it is running in (Desktop, Service or Embedded), whether the report is open in view or edit mode, the licence tier and variation, and whether the licence has expired. Events are sent by a direct HTTPS request written for this purpose. There is no analytics SDK in the visual, so there is no automatic event capture, no session recording, no heatmaps and no click tracking.
We do not collect the business or financial data displayed in or bound to the visual, the content of comments, screenshots or renders of the visual, free-text input, or data from other visuals on the report page.
The per-user identifier is a random value generated fresh each time the visual loads. It is not stored on the device and does not follow a user between sessions or reports, so we cannot follow an individual's behaviour over time or connect events to a named person. At the organization level we do identify you: each event carries a one-way hash of your licence key, and your organization name is recorded against that hash so that we can tell one customer's usage from another's. The connecting IP address reaches the analytics processor as part of the HTTPS request and is stored with the event. Geolocation lookup is disabled on every event we send, so no city, postal code or coordinates are derived from it.
This data is therefore pseudonymous, not anonymous.
Our analytics processor is PostHog, acting as processor on Zebra BI's instructions, hosted in the European Union (PostHog Cloud EU, Frankfurt). For this processing Zebra BI is the data controller and the individual users are the data subjects; your organization is neither controller nor processor of it. Our lawful basis is legitimate interests under Article 6(1)(f) GDPR, supported by a documented assessment. Under the EULA for Uncertified Visuals we retain usage analytics for 24 months at event level, then delete or irreversibly aggregate it.
Power BI offers a tenant administrator no per-visual telemetry switch: the administrator's choice is to permit uncertified visuals or to block them. We do not currently ship a setting in the visual to turn usage analytics off. What we publish instead is the endpoint, eu.i.posthog.com, so your IT team can block it at the network level. Blocking it stops usage analytics. It does not change how the visual works; section 4.3 states what it forecloses.
Data-subject requests relating to usage analytics go to support@zebrabi.com, the contact named in our Privacy Policy for Visuals.
Three checks you can run yourself, in rising order of effort:
.pbiviz package, which is a zip archive, and read capabilities.json inside it. That file is the manifest: the list of hosts the platform will permit, not a record of what the visual contacts.These checks cover the declared privileges, the declared host list and the traffic a package generates. They do not cover what our token service logs or how long it or our analytics processor retains data; those are stated in section 4.4 and section 4.6.
If you find a discrepancy between this document and what you observe, please tell us at support@zebrabi.com. We will correct the document, or the behaviour, whichever is wrong.
These apply to any uncertified visual, whether you obtained it from AppSource or from us.
Your report data stays in your Power BI tenant and your own data sources. Comment data stays in your SharePoint. Zebra BI hosts neither. Report data and comment data do not leave your Power BI tenant, your own data sources and your SharePoint, so no Zebra BI sub-processor processes either.
Zebra BI operates no production hosting facilities of its own. Two sub-processors are involved in operating the uncertified visuals:
Where a signed agreement gives you a right to advance notice of a change to this list, that right governs and we will notify you as it requires; this document is not the notification mechanism.
Sub-processor certifications are the sub-processor's own and are not Zebra BI assurance. Our own position on certifications is in section 10.
The visuals are written in TypeScript. All product code is version controlled with access restricted by role. Changes require review and approval by senior developers before merging to a production branch. No one person carries out development, testing and deployment for a release without documented approval and oversight. Development, test and production environments are segregated. Secure-by-design and privacy-by-design principles are documented and applied, and developers receive secure development training appropriate to their role.
No code reaches production until acceptance testing is complete, findings are remediated or formally excepted, and the release is approved. Every release goes through an automated end-to-end regression suite covering visual and functional behaviour, manual QA against the acceptance criteria of each included ticket, platform compliance validation against Microsoft AppSource submission requirements where applicable, and a final test on the assembled package. Test results are retained as evidence. The certified package is built only from a controlled certification branch in a separate repository.
Confidential customer data is not used for testing. Development and testing run on our own data, because we have no access to yours.
Updates are published through Microsoft AppSource, typically monthly. Reports pick up the new version the next time they are opened. To control which version is in use, distribute through your organizational store, subject to section 1.1. Certified updates go through Microsoft's re-certification at each release, which extends the release cycle; an update that fails is rejected rather than published.
Zebra BI runs a continual vulnerability management process covering identification, prioritization, mitigation, remediation and tracking. Inputs include vulnerability scans and vendor and dependency advisories. Managed devices and servers are enrolled in our MDM platform and scanned for known vulnerabilities using authenticated scans, with endpoints updated automatically. Dependency advisories for the product are pulled twice weekly, and the release pipeline runs a dependency audit on every build and records the result. That audit step is currently advisory rather than blocking, because of an unresolved upstream dependency we do not control; findings are triaged and tracked, and the step returns to blocking when that clears. Remediation is prioritized by severity against internal timeframes that start when a vulnerability is detected; those timeframes are part of the policy set available under NDA during a security review.
Zebra BI does not commission independent penetration testing of any Zebra BI Power BI visual, certified or uncertified. What exists instead:
A customer's own Power BI penetration test covers the platform and the report, not the code of a third-party visual running inside it.
This section states what we commit to. It does not describe how any control is implemented; that detail, and the underlying policy set, are available under NDA during a security review.
Zebra BI maintains a documented Information Security Policy supported by topic-specific policies covering access control, asset management, cryptography, data management, human resource security, physical security, secure development, third-party management, incident response and business continuity. Security responsibilities are communicated at hire and whenever they change. Information security risks are identified, assessed, ranked by likelihood and impact and treated, with the results held in a risk register. Formal risk assessment runs at least annually.
People. Background verification is carried out in accordance with applicable law, proportional to the role and the classification of information accessed. Employees and third parties with access to confidential data sign confidentiality obligations and acknowledge their security responsibilities. Security awareness training is completed at hire and annually thereafter. Offboarding requires return of company equipment.
Access. Access follows least privilege and role-based access control, requires documented approval from the system or data owner, and is reviewed quarterly. Multi-factor authentication is required for privileged and confidential systems and for approved remote access. Access is removed within one business day of termination.
Encryption. Confidential data under Zebra BI's control is encrypted at rest to AES-256 and in transit over untrusted networks using TLS 1.2 or higher.
Endpoints and premises. Company devices are centrally managed and carry anti-malware, endpoint detection and response, and disk encryption, and only approved software may be installed. Our Ljubljana premises are office space with controlled access, not a hosting environment, and no customer data is held there. Facility-level environmental controls such as fire suppression and backup power are therefore not applicable to our premises; for hosted services those controls are Microsoft's.
Suppliers. Due diligence is performed on service providers that may access Zebra BI confidential data, systems or networks before access is provisioned. We do not share confidential data with a third party without a completed risk assessment and an executed agreement setting security requirements. Supplier security and service delivery are reviewed at least annually.
Continuity. Zebra BI maintains a Business Continuity and Disaster Recovery Plan covering disruption to services and to the Ljubljana office. Because we operate no production hosting infrastructure, availability and disaster recovery for hosted services are inherited from Microsoft, and for the Power BI visuals, from your own Power BI tenant and data platform. We do not publish recovery time or recovery point objectives for customer report data, because that data is not ours to recover.
Zebra BI maintains an Incident Response Plan covering reporting, triage, severity classification, investigation, containment, recovery, remediation and documented lessons learned. All personnel are required to report known or suspected security events immediately. Report a suspected incident or vulnerability to security@zebrabi.com.
On verifying an incident that affects a customer, we notify that customer without undue delay, keep them informed of the measures we are taking, and use all reasonable efforts to prevent recurrence. Where the incident is a personal data breach affecting personal data we process on your behalf under the applicable data processing terms, we notify you within 36 hours of becoming aware of it. Separately, and independently of any commitment to you, a controller's duty to notify a supervisory authority within 72 hours arises under the GDPR where the conditions in Article 33 are met.
Our visuals run inside Power BI, so monitoring of the platform itself is Microsoft's. Where a failure is in the visual, reloading the Power BI environment restarts it.
Zebra BI is aligning its security programme and internal controls with ISO 27001 and ISO 27002 requirements and is pursuing ISO 27001 certification. Zebra BI does not currently hold an ISO 27001 certificate. Zebra BI does not hold a SOC 2, HITRUST, PCI DSS, Cyber Essentials Plus or equivalent independent assurance report. We do not publish a target date for certification, and we will update this section when it changes.
The certified visuals carry Microsoft's "Power BI certified" designation, which is a product-level verification by Microsoft and not an assurance report about Zebra BI as an organization.
Support is provided in-house by a dedicated team, by email and by telephone, Monday to Friday during business hours in Central European Time (UTC+1, UTC+2 during summer time). Support does not require access to your report data unless you choose to provide information for troubleshooting.
No standalone service level agreement is offered by default; the scope of support is defined in the applicable End-User License Agreement. Enterprise agreements may add support commitments, including response and escalation targets and a named support contact. Eligibility and terms are set in the applicable order form.
This assessment describes the packages identified in section 1 as at the publication date above. Where it conflicts with a signed agreement, the agreement governs. We review it at each significant change to the data flows it describes, and on request during a security review.
END OF SECURITY ASSESSMENT
Version: 1.0.0
Last modified: 30. 1. 2023
Zebra BI for Microsoft Office is an add-in for Microsoft Excel and Microsoft PowerPoint obtainable solely via Microsoft AppSource. Zebra BI empowers users to create standardized and impactful dashboards in a few clicks with only limited training and no programming. It runs entirely in the Office sandbox environment and neither collects nor stores any user data outside its local running environment. As such it avoids most of the security risks SaaS BI solutions usually introduce.
Zebra BI for Office comprises of two add-ins:
Both add-ins are available for Excel and PowerPoint.
Zebra BI Tables for Excel, Zebra BI Tables for PowerPoint, Zebra BI Charts for Excel, and Zebra BI Charts for PowerPoint are all official Microsoft Office Add-ins and thereby comply with all of Microsoft’s publishing requirements and processes as specified in Deploy and publish Office Add-ins and Commercial marketplace certification policies.
Zebra BI for Office can only be obtained from Microsoft AppSource. The add-in code is served via HTTPS from an Azure App Server controlled by Zebra BI.
As with all AppSource add-ins, updates are seamless and automatic.
Zebra BI for Office runs in a sandboxed environment within Microsoft Office and accesses user data only through Microsoft's Office add-ins API.
After the add-in has been inserted no further data or code is fetched from anywhere.
Retail license: Office 2016, 2019, 2021, Office 365: Version 2105 (Build 14026.20308)
Volume license: Office 2021: Version 1808 (Build 10730.20102)
Authentication is done via Microsoft SSO.
Permissions required to run Zebra BI for Office are profile and openid as defined in Microsoft Graph API.
These are in term used to get the following account data via MSAL:
tenant ID - unique identification of the organization to which the user belongs as assigned by Microsoft,object ID - unique identification of the user as assigned by Microsoft,full name - full name of the user identified by object ID,email - email of the user identified by object ID.Data obtained thereby is used for license verification and is not retained.
Users wishing to use data linking from Excel to PowerPoint also need to grant Zebra BI for Office read permission to Microsoft Sharepoint.
License is verified each time the Zebra BI for Office add-in is loaded. The verification is performed via an external license server fully developed and run by Zebra BI.
The licensing server receives a JSON Web Token (JWT) containing tenant ID, object ID, and email and responds with license information. Communication with the Zebra BI licensing server is done via a secure HTTPS connection. The server is running on Microsoft Azure.

As Zebra BI of Office is an Office Add-in all user and permission management is done in Microsoft Office itself.
Zebra BI for Office runs in a sandboxed environment within Microsoft Office and accesses user data only through Microsoft's Office add-ins API. Zebra BI does not collect nor store any user data outside the local running environment.
For the most part user data access is read-only. Only exceptions are:
Code for Zebra BI is stored using version control. We employ 4-eye review with branch protection and push to production deployment only possible by a pull request. Therefore any changes to the code and the deployed version have an audit trail and can only be done by select employees.
Zebra BI checks the background of all employees to the extent permissible by applicable national and EU legislation.
We annually review permissions and access levels of all employees.
Permission and access revocation is part of our standard offboarding.
We have in place a continual process of identifying, prioritizing, mitigating and remediating vulnerabilities.
We apply the same vulnerability management process to all Zebra BI software as well all systems that are involved in serving or operating the former.
Security vulnerabilities are to be reported to security@zebrabi.com and only there.
Our Vulnerability handling processes follows the ISO/IEC 30111 standard.
END OF SECURITY ASSESSMENT
Certified Power BI visuals are Power BI visuals in AppSource that meet the Microsoft Power BI team code requirements. These visuals are tested to verify that they don't access external services or resources, and that they follow secure coding patterns and guidelines.
Certified Power BI visuals offer more features than non-certified visuals. For example, you can export to PowerPoint, or display the visual in received emails when a user subscribes to report pages.
The certification process tests include but aren't limited to:
Yes. Every time a new version of certified visual is submitted to the Marketplace, the visual's version update goes under the same certification checks.
The version update certification is automatic. If the update is rejected because of a violation, an email is sent to the developer explaining what needs to be fixed.
No. A certified visual can't lose its certification with a new update. Instead, the update would be rejected.
https://docs.microsoft.com/en-us/power-bi/developer/visuals/power-bi-custom-visuals-faq
To get your Power BI visual certified, it must meet the requirements listed in this section.
Power BI visual has to be approved by Partner Center. Before requesting certification, it is recommended that you publish your Power BI visual in AppSource.
Before submitting Power BI visual for certification,we verify that:
Although you don't have to publicly share your code in GitHub, the code repository has to be available for a review by the Power BI team. The best way to do this is by providing the source code (JavaScript or TypeScript) in GitHub.
The repository must contain:
If your Power BI visual uses private npm packages, or git submodules, you must provide access to the additional repositories containing this code.
To understand how a Power BI visual repository looks, review the GitHub repository for the Power BI visuals sample bar chart.
Use the latest version of the API to write the Power BI visual.
The repository must include the following files:
Command requirements
Make sure that the following commands don't return any errors.
Use the latest version of powerbi-visuals-tools to write the Power BI visual.
Compile your Power BI visual with pbiviz package. If you're using your own build scripts, provide a npm run package custom build command.
Make sure you follow the Power BI visuals additional certification policy list. If your submission doesn't follow these guidelines, you'll get a rejection email from Partner Center with the policy numbers listed in this link.
Follow the code requirements listed below to make sure that your code is in line with the Power BI certification policies.
The policies listed in this section apply only to Power BI visuals offers.
Your visual source code must conform to the visual code repository requirements. The code repository for your visual should be available and correctly formatted.
Your source code should be readable, maintainable, expose no functionality errors, and correspond to the provided visual's package.
Your source code should comply with all security and privacy policies. Source code must be safe and not pass or transmit customer data externally.
Running visual development related commands on top of your visual source code should not return any errors.
Visual consumption should not expose any errors or failures and must ensure the functionality of any previous version is preserved.
Power BI Visual additional certification does not apply automatically to updated visuals. All updates to certified Power BI Visuals must also be certified as part of the submission process.
Visuals that rely on access to external services or resources are not eligible to be certified Power BI visuals. You may submit duplicate versions of visuals to the Marketplace: a non-certified version that uses external services or resources, and a certified version that does not use external services or resources. The offer that accesses external services or resources must clearly state so in the description.
https://docs.microsoft.com/en-us/legal/marketplace/certification-policies#1180-power-bi-visuals