Zevis

by ZelixLabs

Data Processing Terms

Last updated 6 September 2026

These terms govern personal data that Zelix Labs processes on behalf of an organisation using Zelix AgentOS. They form part of the Terms of Service and apply to every workspace.

Back to sign in

1. Roles

The organisation operating a workspace is the controllerof the customer records in it, and a data intermediary's principal under the PDPA. Zelix Labs Pte Ltd (UEN 202619950K), a company registered in Singapore, is the processor, and acts only on that organisation's instructions.

For account data about the organisation's own staff, Zelix Labs is the controller. That is covered by the privacy policy rather than by these terms.

2. What we process, and why

Subject matter and purpose. Providing Zelix AgentOS: storing and presenting customer records, sending the messages an organisation configures, syncing the systems it connects, and the AI features it chooses to use.

Duration. For as long as the workspace exists, plus the retention periods set out in the privacy policy.

Categories of data subject.The organisation's customers, enquirers, patients, students and their parents, and its own staff.

Categories of personal data. Names, phone numbers, email addresses, postal addresses, dates of birth, vehicle and licence plate details, appointment and attendance history, payment records, message content, and any free text the organisation enters. Where a practice management system is connected, appointment and recall records.

3. Our obligations

  • Process personal data only on the organisation's documented instructions, which include its configuration and use of the product, unless the law requires otherwise.
  • Never use the data for our own purposes, and never combine one organisation's data with another's.
  • Keep the data confidential and bind our staff to confidentiality.
  • Apply the security measures described in section 6, and not weaken them during the term.
  • Assist with data subject requests, breach handling and regulator enquiries.
  • Never sell the data, and never use it for advertising.
  • Not train AI models on the data.

4. Your obligations

  • Have a lawful basis for the data entered, imported or synced into the workspace, and for every message sent from it.
  • Obtain any consent the law requires, including parental consent where a record concerns a child, and honour opt-outs.
  • Give us accurate instructions, and not ask us to process data in a way that breaks the law.
  • Use a dedicated least-privilege account when connecting a practice management system or any other sensitive integration.
  • Manage access within the workspace, and remove staff who no longer need it.

5. Subprocessors

The organisation gives general authorisation for the providers listed on the subprocessors page. Each is engaged under a written agreement imposing the same obligations that apply to us, and we remain responsible for their acts and omissions.

We tell account owners before a new subprocessor starts processing their data. When we stop using one, it must cease processing and delete what it holds for us.

6. Security

  • Row-level security on every table, plus organisation-scoped filtering on every write made with our service role. Both are checked by an automated scan before a release.
  • Encryption in transit, and encryption at rest by our database provider.
  • Integration keys and access tokens encrypted, never sent to the browser, and sealed to the organisation that created them.
  • Two-factor authentication and passkeys available to every account, and an owner can require two-factor authentication workspace-wide.
  • An audit trail recording who did what, including access by Zelix staff, visible to owners and admins.

To report a vulnerability, email hello@zelixlabs.com with "security" in the subject.

7. Data subject requests

Requests from an organisation's own customers should go to that organisation, which can act on most of them directly in the product.

Where a request needs us, we act on the organisation's written instruction and complete it within 30 days. If a data subject contacts us directly about a workspace record, we refer them to the organisation rather than acting on our own.

8. Breach notification

If we become aware of a personal data breach affecting a workspace, we notify the account owner without undue delay and in any case within 72 hours. The notice states what we know, which data is affected, and what we are doing about it.

We assist with any notification the organisation must make to a regulator or to affected people.

9. WhatsApp Business Solution

Where an organisation connects a WhatsApp Business Account, Zelix Labs acts as its Third Party Service Provider under the WhatsApp Business Solution Terms.

We agree to use the WhatsApp Business Solution and to process Business Solution Data only on that organisation's behalf, pursuant to its instructions and authorisation, in order to provide the services it has asked for, and for no other purpose and no other party.

The organisation stays the owner of its WhatsApp Business Account and can revoke our access at any time from its Meta Business settings. Meta bills it directly for messaging. We do not resell WhatsApp messaging.

10. International transfers

Zelix AgentOS runs in Singapore and its database is hosted in Singapore. Some subprocessors operate elsewhere, so data is transferred outside Singapore for the purposes stated on the subprocessors page.

We remain responsible for that data under the PDPA and require comparable protection by contract.

11. Return and deletion

Two exports are available in the app while a workspace is active: the activity log and the payments list, each as a CSV of up to 5,000 rows. There is no whole-workspace export. For anything broader, email us and we will produce it.

On request, or within a reasonable period after the workspace closes, we delete the personal data we hold for it and instruct our subprocessors to do the same. We complete a deletion request within 30 days.

Three things are kept, as the privacy policy explains: audit entries, unsubscribe and suppression records, and invoices and payment records. Backups age out on their own cycle.

12. Information and audit

We provide the information reasonably needed to show we are meeting these terms. An organisation may audit that compliance once in any twelve months, on 30 days written notice, at its own cost, and without access to another organisation's data.

13. Precedence and liability

These terms form part of the Terms of Service. Where they conflict on the handling of personal data, these terms govern. On anything else, the Terms of Service govern.

Liability under these terms is subject to the limitation of liability in the Terms of Service. The two documents share one cap; they do not stack.

14. Changes

We update these terms when the service changes. The date at the top shows the last revision, and account owners are told about a material change before it takes effect. These terms are governed by the laws of Singapore.

Zelix Labs 路 SingaporePrivacy PolicySubprocessorsTerms of Service