Zevis

Privacy Policy

Last updated 15 September 2026

This policy explains what Zelix Labs does with personal data in Zevis. It covers the people who hold an account with us and the customer records an organisation keeps in its workspace.

Back to sign in

Who we are, and in which role

Zevis is built and operated by Zelix Labs Pte Ltd, a company registered in Singapore. This policy covers the application, the public pages on this site, and the knowledge pages an organisation chooses to publish for its AI.

We handle personal data in two roles, and the difference decides who you contact.

  • As a controller, for people who hold an account: the owners, admins, managers and staff of a workspace. We decide what we collect about you and why.
  • As a processor, for the records an organisation keeps about its own customers. That organisation decides what goes in and why. We act on its instructions.

If you are a customer of a business that uses Zevis and you want your record corrected or removed, contact that business. We act when they ask us to.

What we collect

Account data. Name, email address, role, and which workspaces you belong to. If you sign in with WhatsApp, your phone number. Passwords, two-factor secrets and passkeys are held by our authentication provider, not in our own records.

Workspace data. Whatever the organisation enters or imports: contact records, bookings, invoices and payments, class enrolments and attendance, notes and free text.

Data from connected systems. An organisation can connect its practice management system, its messaging platform, its point of sale or its accounting software. Those connections bring in the contact, appointment, message and transaction records the organisation chooses to sync.

Technical data. The cookies described below, your browser timezone at signup, and your IP address, which is used for rate limiting and sign-in security.

How we use it

  • Running the service: showing a workspace its own records and acting on them.
  • Sending the messages, reminders and campaigns an organisation configures.
  • Billing an organisation for its subscription, and processing payments it takes from its own customers.
  • Security, rate limiting and abuse prevention.
  • Support, when someone contacts us or reports a problem.
  • Improving the product, using counts and aggregates rather than individual records.
  • Improving an organisation’s own AI answers, by learning from that organisation’s own customer conversations which questions are asked and what its team answers. The organisation controls this and can switch it off. Conversations are masked before a model reads them, and no message is stored.

We do not sell personal data. We do not build advertising profiles from it. We do not use it to discriminate against people, to make eligibility decisions about them, or for surveillance.

Consent and withdrawal

Under Singapore's Personal Data Protection Act, we collect, use and disclose personal data with consent, or where the Act otherwise permits it. Creating an account, or entering records into a workspace, is done on that basis.

Consent can be withdrawn at any time by writing to hello@zelixlabs.com. We will stop the use you withdraw consent for, unless the law requires us to keep going. Withdrawing consent may mean we can no longer provide part of the service.

Where an organisation puts its customers' records into a workspace, that organisation is responsible for the consent covering them.

Cookies and browser storage

Zevis sets no analytics cookie, no advertising pixel and no third-party tracker. That is why you are not asked to accept cookies. The only cookies we set are the ones the service needs:

  • A sign-in cookie that keeps you signed in. It lasts for the browser session, or for 30 days if you chose to stay signed in.
  • A cookie that records whether you chose to stay signed in.
  • Preference cookies that remember which organisation and which outlet you were last viewing, so you return to the same place.

Your browser also stores small display preferences on your own device, such as your theme and layout choices. They never reach us, and clearing your browser data removes them.

AI features

Zevis uses AI models to draft messages, write knowledge pages, summarise enquiries and generate images. The model providers we use are listed on the subprocessors page. We do not train models on your data.

What reaches a model, and only for the feature that needs it:

  • Enquiry text, when an organisation runs its enquiry themes report.
  • A contact’s first name, the service they asked about, and the recent conversation, when staff draft a follow-up message.
  • A voice message an owner sends to their own assistant, so it can be turned into text. The recording is read once and not stored.
  • Chat exports an organisation uploads, and its own WhatsApp threads when it has switched on learning from its inbox, after masking.
  • Documents and photographs an organisation uploads, and photographs on its own public website when it runs a brand photo scan.
  • A customer’s recent messages on a WhatsApp conversation the organisation has handed to its assistant to answer, with the organisation’s own knowledge pages, after masking. The organisation switches this on and can hand any conversation back to a person at any time.

Conversations are masked first.Phone numbers, email addresses, identity and card numbers, addresses and links are replaced before any model reads a line, and customer names are masked using the organisation’s own contact list. An uploaded file is deleted when processing ends. What is kept is the list of questions, how often each was asked, and a paraphrased team answer.

The assistant an owner talks to reads the organisation’s own inbox only when asked about it and returns a first name at most, never contact details. Nothing in Zevis reads conversations held on another messaging platform.

Automated messages

An organisation can switch on follow-up sequences, booking reminders and other automatic messages. Once one is on, contacts who match its rules are messaged on a schedule, without a person approving each message. Those rules are set by the organisation, not by us, and every send first checks the sending window and whether the person has opted out.

Nothing here scores individuals, ranks them, or makes a decision with a legal or similarly significant effect on them. The only automated decision is whether and when a message is sent.

Your marketing choices

Email. Every marketing email carries an unsubscribe link. Service emails, such as booking confirmations, reminders and receipts, cannot be switched off, because they are the service working.

WhatsApp.Marketing messages carry opt-out instructions. A reply asking to stop reaches the organisation's own inbox, and once it is recorded, every sending path honours it. An opt-out is kept rather than deleted, so a person who asked not to be contacted is not contacted again by mistake.

Health and clinic data

An organisation in healthcare can connect its practice management system, which brings patient names, contact details, appointment history and recall records into the workspace. We treat this as sensitive data. We do not store clinical notes, diagnoses or treatment records, and we ask every clinic to connect with a dedicated, least-privilege account.

Children's data

Some organisations run programmes for children, and a workspace can link a student record to a parent record. The organisation is responsible for its lawful basis and, where it is required, for parental consent. We process those records on its instruction, under the same protections as any other contact record.

Sharing and subprocessors

We share personal data with the providers listed on the subprocessors page, and nowhere else except where the law requires it. Each is engaged under a written agreement to process data only on our instructions and to delete it when we stop using them.

WhatsApp and Meta

An organisation can connect its own WhatsApp Business Account. Connecting lets us manage its message templates, receive delivery and message notifications, and send the messages it configures. We act only on that organisation's instruction, never use its WhatsApp data for our own purposes, and never combine one organisation's data with another's. The terms for this are on the data processing page.

Messages are delivered by Meta and are subject to Meta's own terms and privacy policy. The organisation is responsible for having a lawful basis to message each recipient.

Where data is stored

The application and its database are hosted in Singapore, and backups stay in the same region. Some providers on the subprocessors page operate outside Singapore. Under the PDPA we stay responsible for that data and require comparable protection by contract.

If you are in the EEA or the United Kingdom, email us at the address below and we will tell you what we hold about you and how it is handled.

How long we keep it

Workspace records are kept while the workspace is active. Deactivating a workspace does not delete its data; it is kept so the workspace can be restored, and removed when the account owner asks.

Conversations with Zevis are private.A person’s conversation with their own assistant is visible only to them: not to colleagues, not to another owner of the same organisation, and not to Zelix Labs. They can delete it from their dashboard at any time, which removes it from our live systems straight away and from our encrypted backups as those age out. Photos and voice notes they send are not stored by us.

The one exception needs their approval. If something goes wrong, Zevis writes a short fault report, shows the person the exact text, and sends it to Zelix Labs only if they choose to. Nothing is sent if they decline.

Kept after deletion, deliberately: audit entries, which record who did what; opt-out records, so a person who asked not to be contacted is not contacted again; and invoices and payment records, for accounting and tax.

Deleting your data

This section is the deletion route referenced from our Meta app settings.

Most records can be removed from within the product: contacts, bookings, uploaded documents, knowledge pages, and what the AI has learned are each deleted from their own screen. For anything else, write to hello@zelixlabs.com from the address on the account and say what should be removed:

  • Your own account and the personal data attached to it.
  • A whole workspace and everything in it.
  • A single contact record.

We complete a deletion request within 30 days and confirm it by email. There is no charge. If you are a customer of a business that uses Zevis, ask that business first, because the record belongs to them. The audit, opt-out and payment records described above are kept after a deletion, for the reasons given there.

Security

We follow current security practice for a multi-tenant service. Every organisation's data is isolated from every other organisation's, data is encrypted in transit and at rest, and integration keys are encrypted and never sent to the browser. Our safeguards are checked automatically before every release.

Accounts support two-factor authentication and passkeys, and an owner can require two-factor authentication across a whole workspace. Zelix Labs staff access a workspace only to provide support or operate the service, and that access is recorded in the workspace audit trail where owners and admins can see it.

To report a security vulnerability, email hello@zelixlabs.comwith "security" in the subject. We aim to acknowledge within 2 working days.

If something goes wrong

If we become aware of a personal data breach affecting a workspace, we notify the account owner without undue delay and in any case within 72 hours, and we assist the organisation with any notification it must make to the Personal Data Protection Commission or to the people affected.

Your rights

Under the PDPA you may ask us to tell you what personal data we hold about you and how it has been used, to correct it, to delete it, or to withdraw consent you gave earlier. Email hello@zelixlabs.com from the address on your account. We respond within 30 days and there is no charge. If you are not satisfied with our answer you may raise it with the Personal Data Protection Commission in Singapore.

Data Protection Officer

We have appointed a Data Protection Officer, as the PDPA requires. Questions about this policy, requests about your personal data, and complaints all reach them at hello@zelixlabs.com. Write "data protection" in the subject line so it is routed correctly.

Changes to this policy

We update this policy when the service changes. The date at the top shows the last revision, and account owners are told about a material change before it takes effect.

Contact

Zelix Labs Pte Ltd, Singapore. Questions about this policy go to hello@zelixlabs.com.

Zelix Labs · Singapore · Terms of Service · Subprocessors · Data Processing Terms