Zuvo Business AI
← Back to Zuvo

Privacy Policy

Draft — not yet published
Before you launch: South Africa's POPIA requires you to appoint and register an Information Officer with the Information Regulator before processing personal information at scale — do this before going live. One thing is still genuinely unfilled below: Section 9 needs the Information Officer's real name (usually the business owner — that's you, unless you appoint someone else). If you'll have EU/UK users, you'll also need GDPR-specific clauses (a lawful basis table, EU representative if required, SCCs for transfers).

1. What we collect

DataWhy
Name, business name, email, hashed passwordCreate and secure your account
Billing details (handled by Paystack — we never see your card number)Process your subscription
Messages and documents you send to ZuvoGenerate the assistant's response to you, via our AI provider (see below)
Basic usage data (login times, message counts)Enforce plan limits, fix bugs, improve the product

2. How your conversations are processed

When you ask Zuvo something, the message is sent to Anthropic's Claude API to generate a reply. Per Anthropic's API terms, this content is not used to train Anthropic's models. We don't sell your data, and we don't use your business's content to train any third-party AI model.

3. Who we share data with

  • Anthropic, PBC — processes message content to generate AI responses.
  • Paystack — processes payment details to bill your subscription.
  • Render, Netlify and Supabase — Render and Netlify host the application; Supabase hosts the database.

We don't sell personal information, and we don't share it with anyone else except where required by law.

4. Your rights

Under POPIA (and GDPR, if it applies to you), you can ask us to: give you a copy of your data, correct it, delete it, or stop processing it. Email operations@mrhelium.com to make a request — we'll respond within the time your applicable law requires.

5. Data retention

We keep account and billing records for as long as your account is active and for 5 years after closure to meet accounting and legal obligations. Chat content is retained for 12 months to let you review past conversations, then deleted.

6. International transfers

Our AI provider and hosting infrastructure may process data outside South Africa — Anthropic's Claude API runs in the United States, and our hosting providers may operate servers in other jurisdictions. Where this happens, we rely on those providers' standard contractual clauses and security certifications to protect your data during such transfers.

7. Security

Passwords are hashed, not stored in plain text; connections to the Service are encrypted in transit (HTTPS); access to the database is restricted. No system is 100% secure, and we'll notify affected users and the Information Regulator as required by law if a breach occurs.

8. Cookies

We use only the minimum needed to keep you signed in (a login token stored in your browser). [Update this section if you later add analytics/marketing cookies, and add a consent banner.]

9. Contact / Information Officer

[Name — the business owner, unless you appoint someone else], Information Officer, operations@mrhelium.com.