Legal

Privacy Policy

How ZevoFlow collects, uses and protects personal data across the EU/EEA, UK and GCC markets.

Overview

ZevoFlow ("we", "us") provides an AI workforce operations platform to corporate customers. This policy describes how we process personal data as a controller for our website and marketing, and as a processor for data our enterprise customers submit through the platform.

Legal bases we rely on

  • Performance of a contract with our customer.
  • Legitimate interests in operating, securing and improving the service.
  • Consent, for optional analytics cookies and marketing communications.
  • Compliance with legal obligations under EU GDPR, UK GDPR, Swedish law, UAE PDPL, KSA PDPL and Qatar PDPPL.

Data we process

  • Account data: name, work email, role, organisation, authentication metadata.
  • Workforce data submitted by the customer: employee names, phone numbers, skills, availability.
  • Messaging metadata: WhatsApp/SMS delivery status, opt-in and opt-out records.
  • Usage and security logs for abuse prevention and audit.

International transfers

When personal data is transferred outside the EEA/UK or the origin GCC jurisdiction, we rely on Standard Contractual Clauses, adequacy decisions or the applicable local transfer mechanism.

Your rights

You may request access, correction, deletion, restriction, portability and objection. Contact privacy@zevoflow.com.

Retention

We retain personal data for as long as necessary for the purposes above and to meet legal, tax and audit obligations, after which data is deleted or anonymised.

This page is customer-facing summary content and does not replace the signed data protection terms in your ZevoFlow enterprise agreement.