Legal document

Privacy Policy

Product: ZevoBot — AI Chatbot SaaS platform

Operated by:Akula Palkish (sole proprietor) (“ZevoBot”, “we”, “us”, “our”)

Effective date: 7 July 2026  |  Last updated: 7 July 2026

Contact: akulapalkish01@gmail.com · [REGISTERED ADDRESS, CITY, STATE, PIN, INDIA]

Only the registered address remains to be filled before publishing. This policy is written for a service that serves customers in India, the EU/EEA, and the UK. Have it reviewed by counsel.


1. Who we are and what this policy covers

ZevoBot is a software-as-a-service platform that lets businesses (“Customers”) build, train, and deploy AI chatbots on their websites, Shopify or WordPress stores, and WhatsApp. This Privacy Policy explains how we handle personal data.

We handle personal data in two distinct roles:

  • As a controller — for the personal data of our Customers (the people who sign up for and administer ZevoBot accounts) and visitors to our own marketing website.
  • As a processor — for the personal data of our Customers' end-users (website visitors, WhatsApp contacts, leads, and booking customers) that flows through the chatbots. For that data, the Customer is the controller and decides why and how it is processed. Our processing of that data is governed by our Data Processing Addendum (DPA)and the Customer's own privacy notice.

If you are an end-userinteracting with a chatbot built by one of our Customers, please also read that business's own privacy notice — they decide what data to collect and why.


2. The personal data we collect

2.1 Data you give us as a Customer (we are controller)

  • Account & profile: name, email address, company name, country, website, and timezone (via Clerk-managed sign-up and your profile).
  • Billing: subscription plan, billing cycle, and payment identifiers returned by Razorpay (subscription ID, customer ID, payment ID). We do not store your full card or bank details — those are handled directly by Razorpay.
  • Support & communications: messages you send us, demo/contact form submissions, and notification preferences.
  • API keys: we store only a hashed form of any API key you generate; we cannot recover the original.

2.2 Data processed through the chatbots (we are processor, on the Customer's behalf)

Depending on how a Customer configures their chatbot, we process, on their behalf:

  • Conversation data: chat messages and transcripts, session identifiers, visitor IDs, and any visitor email captured during a chat.
  • Leads: name, phone number, email, stated requirement, the channel used, and a consent timestamp.
  • Bookings: name, phone number, email, and appointment date/time.
  • WhatsApp data: phone numbers, contact names, opt-in/opt-out status and timestamps, message content, and any media sent to the bot.
  • Broadcast audiences: phone lists uploaded by the Customer for WhatsApp broadcasts.
  • Training / knowledge-base data: documents the Customer uploads and the content of websites the Customer asks us to crawl, which we convert into text chunks and vector embeddings so the bot can answer questions.

2.3 Data collected automatically

  • Technical/usage data: IP address, device and browser type, pages viewed, timestamps, and diagnostic logs, collected to run, secure, and improve the service.
  • Cookies and similar technologies: see Section 9.

We do not intentionally collect special-category / sensitive personal data (e.g., health, biometric, financial account data) and we ask Customers not to configure bots to collect it.


3. How we use personal data and our legal bases

PurposeData usedLegal basis (GDPR/UK-GDPR)DPDP basis
Provide and operate the service (accounts, chatbots, training, messaging, bookings)Account, conversation, training dataPerformance of a contractNecessary for providing the service (consent at sign-up)
Billing and subscription managementBilling identifiersPerformance of a contractConsent / contract
Security, fraud prevention, abuse detection, rate-limitingUsage, technical, conversation metadataLegitimate interestsLegitimate/lawful use
Product analytics and improvementUsage/technical data (aggregated where possible)Legitimate interests / consentConsent
Service and transactional emails (lead alerts, booking notifications, billing)Contact dataContract / legitimate interestsConsent / contract
Marketing emails and product updatesContact data + your preferencesConsent (you can opt out any time)Consent
Legal compliance (tax, records, responding to lawful requests)As requiredLegal obligationLegal obligation

For end-user data processed on a Customer's behalf, the Customer determines the purpose and legal basis; we act on their documented instructions.

AI processing. To generate answers, chatbot messages and relevant training-content chunks are sent to our AI subprocessors (OpenAI and Google Generative AI / Gemini) at query time. We use these providers' API (business) tiers; we instruct them not to use your content to train their models. See Section 6 and the Subprocessor list in the DPA.


4. AI, automated processing, and accuracy

ZevoBot uses large language models and a retrieval-augmented generation (RAG) pipeline to generate responses from a Customer's own knowledge base. Responses are generated automatically and may be inaccurate, incomplete, or out of date. Chatbot output should not be relied on as professional (legal, medical, financial) advice. We do not use chatbot conversations to make decisions that produce legal or similarly significant effects about an individual. Customers are responsible for reviewing bot behaviour and adding appropriate disclaimers.


5. How we share personal data

We share personal data only as needed to run ZevoBot:

  • Subprocessors / service providers that host and power the platform (hosting, database, AI, email, payments, storage, messaging). The current list is published in our Data Processing Addendum / Subprocessor list.
  • Integration partners you choose to connect — e.g., Google Calendar, WhatsApp/Meta, Shopify, WooCommerce. Data flows to these only when a Customer connects the integration, and their handling is governed by their own policies.
  • Payment processor — Razorpay, to take and manage payments.
  • Legal / safety — where required by law, court order, or to protect the rights, safety, and property of ZevoBot, our Customers, or the public.
  • Business transfers — in a merger, acquisition, or asset sale, subject to this policy.

5.1 Google Calendar integration

When a Customer connects Google Calendar, ZevoBot reads the Google Calendar list and event availability data needed to determine booking availability. It writes booking events on the single calendar the Customer selects for that chatbot, including creating, updating, and deleting those events. A booking event may contain the customer's name, phone number, service, appointment time, and ZevoBot booking ID so the business owner can identify and manage the appointment. Access is limited to the connected account's selected calendar. Disconnecting revokes the Google token and deletes the stored access and refresh credentials from ZevoBot.

We do not sell personal data, and we do not share it for third-party advertising.


6. International data transfers

We are based in India and use infrastructure and subprocessors located in India, the United States, and the EU (e.g., Vercel, Neon, Clerk, OpenAI, Google, Cloudinary, Razorpay). When we transfer personal data across borders:

  • For EU/EEA and UK personal data, we rely on Standard Contractual Clauses (SCCs) / the UK IDTA and equivalent safeguards with our subprocessors.
  • For India (DPDP Act 2023), we transfer only to jurisdictions not restricted by the Government of India and apply contractual safeguards.

Details and the mechanism for each subprocessor are in the DPA. You may request a copy of the relevant safeguards via the contact details above.


7. Data retention

  • Customer account data: kept while your account is active. When you delete your account, your chatbots, documents, conversations, leads, and associated assets are deleted immediately (cascading deletion); residual copies in backups are purged on the normal rotation cycle.
  • Billing records: retained for the period required by Indian tax/accounting law (typically up to 8 years).
  • Conversations and chat messages (including WhatsApp messages, attached media, and human-handoff records): automatically purged 12 months after the conversation's last activity.
  • Leads, bookings, and broadcast delivery records: automatically purged 24 months after creation (bookings: after the appointment date).
  • WhatsApp opt-in records: purged after 24 months of inactivity. Opt-out records are retained as a suppression list so an opt-out is never forgotten.
  • Training data & embeddings: retained until the Customer removes the source or deletes the chatbot.
  • Backups & logs: may persist for a limited additional period before rotation.

An automated retention job runs daily to enforce these windows. A Customer can also delete conversations, leads, chatbots, or the whole account at any time — the windows above are a maximum, not a minimum.


8. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. Under India's DPDP Act you also have the right to nominate another person to exercise your rights and to grievance redressal.

  • Customers can exercise several of these directly: download all your data via Account → Export data and delete your account via Account settings / Danger Zone.
  • Customers can also act on a single End-User's request: the platform provides per-End-User export and erasure tooling (by phone number, email, or chat session). Erasures are recorded in an audit log.
  • To make any other request, email akulapalkish01@gmail.com. We respond within the timelines set by applicable law.
  • If you are an end-user of a Customer's chatbot, direct access/deletion requests to that business (the controller). We will assist them as their processor.

You may also lodge a complaint with your data protection authority (e.g., your EU/EEA supervisory authority, the UK ICO) or, in India, with the Data Protection Board once operational, and with our Grievance Officer(see Grievance Redressal & Contact).


9. Cookies and similar technologies

We and our providers use cookies and similar technologies for:

  • Strictly necessary functions — authentication and session management (via Clerk), security, and load balancing.
  • Analytics — to understand usage and improve the product.

On your first visit, a cookie consent banner asks whether you accept analytics cookies; analytics (Google Analytics) is loaded only after you accept. Strictly necessary cookies are always active. You can change your choice at any time via the “Cookie Preferences” link in the site footer, or control cookies through your browser.


10. Security

We apply technical and organisational measures appropriate to the risk, including: AES-256-GCM encryption at rest for stored third-party credentials and OAuth tokens; hashing of generated API keys; signature/HMAC verification on inbound webhooks (Razorpay, WhatsApp/Meta, Shopify, WooCommerce, Clerk); encryption in transit (TLS); access controls and tenant isolation; automated time-based data purging (Section 7); and rate-limiting plus audit loggingof sensitive operations. No system is perfectly secure; we cannot guarantee absolute security. See the DPA, Annex “Security Measures,” for detail.


11. Children

ZevoBot is not intended for individuals under 18. We do not knowingly collect personal data from children, and Customers must not configure chatbots to collect personal data from children. If you believe a child's data has been collected, contact us and we will delete it.


12. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or an in-product notice. The “Last updated” date shows the latest revision. Continued use after changes take effect constitutes acceptance.


13. Contact

Akula Palkish (sole proprietor)

Email: akulapalkish01@gmail.com

Address: [REGISTERED ADDRESS, CITY, STATE, PIN, INDIA]

Grievance Officer: see Grievance Redressal & Contact