Zevis
by ZelixLabs
Privacy Policy
Last updated 6 September 2026
This policy explains what Zelix Labs does with personal data in Zelix AgentOS. It covers the people who hold an account with us and the customer records an organisation keeps in its workspace.
Who we are, and in which role
Zelix AgentOS is built and operated by Zelix Labs Pte Ltd (UEN 202619950K), a company registered in Singapore. This policy covers the application, the public pages on this site, and the public knowledge pages served at /kb.
We handle personal data in two roles, and the difference decides who you contact.
- As a controller, for people who hold an account: the owners, admins, managers and staff of a workspace. We decide what we collect about you and why.
- As a processor, for the records an organisation keeps about its own customers. That organisation decides what goes in and why. We act on its instructions.
If you are a customer of a business that uses Zelix AgentOS and you want your record corrected or removed, contact that business. We act when they ask us to.
What we collect
Account and staff data. Name, email address, role, and which workspaces you belong to. Passwords, two-factor secrets and passkey credentials are held by our authentication provider and are never stored in our own tables. If you enable WhatsApp sign-in, we store your phone number.
Workspace data. Whatever the organisation enters or imports. Contact records with names, phone numbers, email addresses, dates of birth and tags. Bookings, vehicles and licence plates, invoices and payments, class enrolments and attendance, notes and free text.
Data from connected systems. Cliniko and Plato send patient names, contact details, dates of birth, appointments and recall records. respond.io and Meta send contact and message webhooks, which we store as received. Point of sale feeds send customer and job records. Xero receives contact and invoice data from us.
Technical data. The cookies and browser storage listed below, and your browser timezone at signup. IP addresses are used for rate limiting and sign-in security.
Public knowledge pages. A request to a /kb page records which page was read, whether the reader was signed in, and a shortened browser user agent. No IP address is recorded.
How we use it
- Running the service: showing a workspace its own records and acting on them.
- Sending the messages, reminders and campaigns an organisation configures.
- Billing an organisation for its subscription, and processing payments it takes from its own customers.
- Security, rate limiting and abuse prevention.
- Support, when someone contacts us or reports a problem.
- Improving the product, using counts and aggregates rather than individual records.
- Improving an organisation’s own AI answers, by learning from that organisation’s own customer conversations which questions are asked and what its team answers. The organisation is the controller of those conversations and we act on its instructions. It switches this on and can switch it off, the conversations are masked before a model reads them, and no message is stored.
We do not sell personal data. We do not build advertising profiles from it. We do not use it to discriminate against people, to make eligibility decisions about them, or for surveillance.
Consent and withdrawal
Under Singapore's Personal Data Protection Act, we collect, use and disclose personal data with consent, or where the Act otherwise permits it. Creating an account, or entering records into a workspace, is done on that basis.
Consent can be withdrawn at any time by writing to hello@zelixlabs.com. We will stop the use you withdraw consent for, unless the law requires us to keep going. Withdrawing consent may mean we can no longer provide part of the service.
Where an organisation puts its customers' records into a workspace, that organisation is responsible for the consent covering them.
Cookies and browser storage
Zelix AgentOS sets no analytics cookie, no advertising pixel and no third-party tracker. There is no Google Analytics, no Meta Pixel and no session recorder in the product. That is why you are not asked to accept cookies: every cookie below is needed to sign you in or to remember a choice you made.
sb-…
Keeps you signed in. Set by our authentication provider.
30 days, extending as you use it, if you chose to stay signed in. Otherwise it ends when you close the browser.
stay
Records whether you chose to stay signed in.
30 days, or the browser session. Removed when you sign out.
relay_org
Which organisation you are currently viewing, if you belong to more than one.
1 year.
revol_branch_scope
Which outlet or workspace you have selected in the sidebar.
1 year.
Your browser also stores small preferences on your own device, which never reach us: light or dark theme, whether the sidebar is collapsed, your calendar and class view choices, which tabs and tips you have dismissed, and any answer you start typing in Knowledge before you save it. Clearing your browser data removes them.
AI features
Zelix AgentOS uses AI models to draft messages, write knowledge pages, summarise enquiries and generate images. Two providers process data for this: Anthropic for text and document understanding, and OpenAI for image generation only.
What reaches a model:
- Enquiry text your customers submitted, when an organisation runs the enquiry themes report. The summary can quote short extracts, and those extracts are saved with it.
- A contact first name, the service they asked about, and the recent WhatsApp conversation, when staff draft a follow-up message.
- Uploaded chat exports, after masking. See the next paragraph.
- The audio of a voice message an owner sends to their own assistant, so it can be turned into text and acted on. The recording is read once and we do not store it; only the words reach the conversation.
- Messages in an organisation’s own WhatsApp threads, after masking, when it has switched on learning from its inbox. Only the questions customers ask and the answers its own team gave are read. No message is stored.
- Documents and photographs an organisation uploads, and photographs found on its own public website when it runs a brand photo scan.
Conversations are masked first.Phone numbers, email addresses, links, NRIC and FIN numbers, card numbers, unit numbers, postcodes and handles are replaced before any model reads a line. Customer names are masked as well, using the organisation’s own contact list. This applies both to a chat export an organisation uploads and to its own WhatsApp threads when it has switched on learning from its inbox. An uploaded file is deleted when processing ends. Only the resulting questions, how often each was asked, and a paraphrased staff answer are kept.
What does not reach a model.The assistant returns a first name at most, never a phone number, an email address or a message, and it never reads a customer conversation. Memory reads an organisation’s own WhatsApp threads only when that organisation has switched it on, and only after masking. Neither ever reads conversations held on another messaging platform.
We do not train models on your data.
Automated messages
An organisation can switch on follow-up sequences, booking reminders and other automatic messages. Once one is on, contacts who match its rules are enrolled and messaged on a schedule, without a person approving each message.
Those rules are set by the organisation, not by us. Before anything sends, the service checks the sending window, whether the person has opted out, and whether their status has changed. A reply from the recipient pauses that sequence so a person can take over.
Nothing here scores individuals, ranks them, or makes a decision with a legal or similarly significant effect on them. The only automated decision is whether and when a message is sent.
Your marketing choices
Email. Every marketing email carries an unsubscribe link, and mail apps can unsubscribe in one click. The preference page linked from any of our emails turns marketing email off for that organisation, and the choice can be undone from the same page.
Some emails cannot be switched off, because they are the service working: booking confirmations, reschedules, cancellations, reminders, no-show notices, enquiry acknowledgements, collection notices, and payment requests and receipts.
WhatsApp.Marketing templates must carry opt-out instructions before they can be published. A reply asking to stop reaches the organisation's own inbox, and the organisation, or we on its request, records it. Once recorded, every sending path honours it.
An opt-out is kept rather than deleted, so that a person who asked not to be contacted is not contacted again by mistake.
Health and clinic data
An organisation in healthcare can connect Cliniko or Plato. That sync brings patient names, contact details, dates of birth, appointment history and recall records into the workspace. A recall record includes the recall type and any note attached to it.
We treat this as sensitive data. We do not store clinical notes, diagnoses or treatment records. A connection uses a key the organisation creates, and we ask for a dedicated least-privilege account rather than a clinician or administrator login.
Children's data
Some organisations run programmes for children, and a workspace can link a student record to a parent record. Those records hold a name, a date of birth and attendance history.
The organisation is responsible for its lawful basis and, where it is required, for parental consent. We process the records on that organisation's instruction, under the same access controls and retention rules as any other contact record.
Sharing and subprocessors
We share personal data with the providers listed on the subprocessors page, and nowhere else except where the law requires it.
Each provider is engaged under a written agreement requiring it to process data only for us, on our instructions, consistent with this policy, and to place the same obligation on anyone it engages in turn. When we stop using a provider, it must delete the data it holds for us.
WhatsApp and Meta
An organisation can connect its own WhatsApp Business Account. Connecting grants us access to that account so we can create and manage message templates, receive delivery and message webhooks, and send the messages the organisation configures.
We act only on that organisation's instruction. We do not use its WhatsApp data for our own purposes, and we never combine one organisation's data with another's. The terms we give clients for this are on the data processing page.
Messages are delivered by Meta and are subject to Meta's own terms and privacy policy. The organisation is responsible for having a lawful basis to message each recipient.
Where data is stored
The application runs in Singapore and the database is hosted in Singapore. Backups stay in the same region.
Some providers on the subprocessors page operate outside Singapore, and personal data is transferred to them for the purposes described there. Under the PDPA we stay responsible for that data and require comparable protection by contract.
If you are in the EEA or the United Kingdom, email us at the address below and we will tell you what we hold about you and how it is handled.
How long we keep it
Kept while the workspace is active: contact records, bookings, invoices, attendance, the message and webhook logs we receive from connected systems, and assistant conversations.
Kept on a fixed schedule:
- Public knowledge page reads: 90 days.
- Background job records: 30 days once finished, 60 days after an error.
- Uploaded chat exports: deleted when processing ends.
- What memory learned from an inbox: the questions and counts are kept while the workspace is active, and an owner can remove them. A question nobody has asked for 180 days is deleted.
Kept after deletion, deliberately:
- Audit entries, which record who did what and can name a record that was later deleted. There is no way to edit or remove an audit entry, including for us.
- Unsubscribe and suppression records, so a person who opted out is not contacted again.
- Invoices and payment records, for accounting and tax.
Deactivating a workspace does not delete its data. It is kept so the workspace can be restored, and it is removed when the account owner asks.
Deleting your data
This section is the deletion route referenced from our Meta app settings.
What you can delete yourself. Memory pages, from Memory then Settings then Start again, where an owner can clear the pages a run wrote or all of it. What memory learned from an inbox, and any page change it made, from Memory then What it learned. Uploaded documents, reference photographs, templates, bookings and calendar events are each removed from their own screen.
What to email us for. Write to hello@zelixlabs.com from the address on the account and say what should be removed:
- Your own account and the personal data attached to it.
- A whole workspace and everything in it.
- A single contact record, which we remove for you on request.
We complete a deletion request within 30 days and confirm it by email. There is no charge. If you are a customer of a business that uses Zelix AgentOS, ask that business first, because the record belongs to them.
The audit entries, suppression records, invoices and payment records described above are kept after a deletion, for the reasons given there.
Security
Every table is protected by row-level security, and every write made with our service role is scoped to a single organisation. Both layers are checked by an automated scan before a release ships.
Integration keys and access tokens are encrypted, are never sent to the browser, and are sealed to the organisation that created them. Sign-in codes are stored as hashes; the code itself is never stored.
Accounts support two-factor authentication and passkeys, and an owner can require two-factor authentication across a whole workspace.
Zelix staff access a workspace only to provide support or to operate the service. That access is recorded in the workspace audit trail as a Zelix actor, where owners and admins can see it.
To report a security vulnerability, email hello@zelixlabs.comwith "security" in the subject. We aim to acknowledge within 2 working days.
If something goes wrong
If we become aware of a personal data breach affecting a workspace, we notify the account owner without undue delay and in any case within 72 hours. The notice says what we know, which data is affected, and what we are doing about it.
We assist an organisation with any notification it must make to the Personal Data Protection Commission or to the people affected.
Your rights
Under the PDPA you may ask us to tell you what personal data we hold about you and how it has been used, to correct it, to delete it, or to withdraw consent you gave earlier.
Email hello@zelixlabs.com from the address on your account. We respond within 30 days and there is no charge. If you are not satisfied with our answer you may raise it with the Personal Data Protection Commission in Singapore.
Data Protection Officer
We have appointed a Data Protection Officer, as the PDPA requires. Questions about this policy, requests about your personal data, and complaints all reach them at hello@zelixlabs.com.
Write "data protection" in the subject line so it is routed correctly. We respond within 30 days.
Changes to this policy
We update this policy when the service changes. The date at the top shows the last revision, and account owners are told about a material change before it takes effect.
Contact
Zelix Labs Pte Ltd (UEN 202619950K), Singapore. Questions about this policy go to hello@zelixlabs.com.
Zelix Labs · Singapore · Terms of Service · Subprocessors · Data Processing Terms