Privacy Policy
Effective date: see the version banner at the top of this page. Last updated: see the version banner at the top of this page.
This Privacy Policy describes how Zilo Software (Pty) Ltd ("Zilo", "we", "us") collects, uses, shares, and protects personal information when you use the ItsSuite service (the "Service"). It applies to (a) you as a workspace owner or team member; (b) end customers of your business whose messages flow through the Service; and (c) anyone who visits our public website.
We comply with the Protection of Personal Information Act, 4 of 2013 ("POPIA") and apply equivalent standards where the General Data Protection Regulation ("GDPR") or other foreign data-protection law applies.
1. The role of Zilo
When you, the Customer, use the Service to operate your own WhatsApp Business communications:
- You are the responsible party / data controller for personal information of your end customers.
- Zilo is the operator / data processor for that personal information. We process it only on your instructions, as set out in the Terms of Service and this Policy.
For the personal information of you, your team members, and visitors to our website, we are the responsible party in our own right.
2. Information we collect
2.1. Information you give us
- Account information — name, email, password (hashed), preferred locale and time zone, two-factor secret (encrypted at rest), profile username, IP address at sign-up.
- Workspace information — workspace name, slug, branding settings (logo, colours, custom domain on higher-tier plans), team-member details, role assignments, invitations.
- Connection information — WhatsApp Business Account ID, phone-number ID, display name, BYO Meta credentials (access token, app secret) where applicable, registration status, quality and messaging-limit tier as reported by Meta.
- Communication content — flow definitions, broadcast content, template definitions, canned replies, knowledge-base documents and Q&A pairs, custom contact-attribute schemas, segment rules, drip campaign content, A/B variants.
- Billing information — plan, wallet balance, top-up history, payment-method tokens (held by the payment processor, not stored with us), invoice line items.
2.2. Information collected automatically
- Service usage — login times, IP addresses, browser user agent, pages visited, actions taken, audit-loggable events (template approval, branding edit, wallet topup, support session, RBAC change, plan migration, referral payout, and similar).
- Cookies and similar technologies — session cookies, CSRF token, language preference. We do not use third-party advertising cookies.
- Performance and error data — diagnostic metrics, structured logs, and (where configured) anonymised crash reports sent to Sentry.
2.3. Customer Data — messages and contacts (your end customers)
When your end customers send messages to your business through WhatsApp:
- Identifying data — their WhatsApp number (wa_id), profile name (as reported by WhatsApp), and any custom attributes you store against their contact record;
- Conversation content — message text, media (images, audio, documents), interactive-message payloads, the timing and direction of each message, the agent who handled the conversation;
- Lead and pipeline data — when you promote a contact to a lead, status changes, owner assignments, free-text notes;
- Activity timeline — events on the conversation and the lead;
- Derived data — segment membership, A/B variant assignment, conversation summary (where AI summarisation is enabled).
You are the responsible party for this Customer Data and you instruct us (via the Service) to process it. Your privacy notice to end customers must cover this processing.
3. How we use information
3.1. To operate the Service for you
- Authenticate sign-ins, including two-factor verification;
- Route messages to and from Meta's WhatsApp Business Platform on your behalf;
- Render the workspace inbox, dashboard, flow builder, knowledge base, segments, broadcasts, drip campaigns, A/B reporter, analytics;
- Charge your wallet for each billable action and produce invoices;
- Run AI features you have enabled (replies, classification, translation, conversation summary, assistant, template drafting), which involves sending the relevant prompts to an upstream AI provider — see clause 4.
3.2. To support you
- Respond to your support requests;
- Sign in to your workspace under a documented, audit-logged support session — only with a reason, only with two-factor reauthentication, and only short-lived. The workspace shows a visible banner for the duration.
3.3. To run the platform itself
- Maintain security: detect, prevent, and respond to fraud, abuse, and unauthorised access;
- Meet our regulatory obligations and respond to lawful requests;
- Audit our compliance with POPIA, Meta's policies, and our own internal controls;
- Improve the Service: aggregate, anonymised usage analytics inform what we build next. We do not train AI models on Customer Data.
3.4. With consent and to communicate
- Send service-related email (verification, password reset, low-balance alert, billing receipts, security notices) — this is part of providing the Service and not subject to a separate opt-out;
- Send marketing emails about new features and product updates — these carry an unsubscribe link and are subject to your opt-in preference on the profile page;
- Run the referral program — when a user signs up via your referral link, we credit your wallet according to the active reward configuration.
4. Sharing — who else processes the information
We do not sell personal information. We share it only with the following categories of recipient, only as needed, and under written contracts that require equivalent protection.
| Recipient | Why | Where they are |
|---|---|---|
| Meta Platforms, Inc. and its subsidiaries (WhatsApp LLC) | To deliver your messages over the WhatsApp Business Platform — the core function you have asked us to perform | USA, Ireland, global |
| Anthropic, PBC | AI-feature inference (Claude) when AI features are enabled | USA |
| OpenAI, OpCo, LLC (where you configure OpenAI rather than Anthropic) | AI-feature inference | USA |
| Cloud hosting provider | Compute, storage, backup of the Service | Specified at /legal/subprocessors |
| Email provider | Delivery of transactional and notification email | Specified at /legal/subprocessors |
| Payment processor | Wallet topups and subscription billing | Specified at /legal/subprocessors |
| Sentry (Functional Software, Inc.) | Anonymised error reporting where configured | USA |
| Government, regulator, court | Where required by law, regulation, or valid legal process | Subject to applicable due process |
The current list of sub-processors and their location is published at /legal/subprocessors, with at least 30 days' notice of any material change.
5. International transfers
Some of our sub-processors are based outside South Africa. Where we transfer personal information across borders we rely on (a) standard contractual clauses or equivalent; (b) the receiving country being recognised as adequate by South African regulators; or (c) your documented authorisation. Where the upstream service is Meta's WhatsApp Business Platform, transfer is intrinsic to the function of the Service and is what you have asked us to perform.
6. Retention
We retain personal information for as long as needed to provide the Service and to comply with our legal, accounting, and tax obligations:
| Data | Retention |
|---|---|
| Workspace + team member account data | Lifetime of the account + 12 months after last activity |
| Audit log rows | 7 years from event date (statutory minimum) |
| Conversation and message history | 24 months rolling, or until you delete the contact |
| Knowledge-base documents and embeddings | Until you delete them, or 24 months after account closure |
| Billing records (invoices, ledger) | 7 years (tax law) |
| Backups | 30 days rolling |
| Support-session token mint / consume records | 7 years (audit) |
You may request earlier deletion subject to legal retention obligations.
7. Your rights (POPIA & GDPR)
You have the right to:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Delete personal information no longer needed for the purposes collected (right to erasure);
- Object to processing for direct marketing at any time;
- Restrict processing in certain circumstances;
- Data portability — receive personal information in a structured, commonly used, machine-readable format;
- Lodge a complaint with the Information Regulator of South Africa (or your local supervisory authority if GDPR applies). Their contact details are at the end of this Policy.
To exercise any of these rights, email privacy@zilo.co.za. We will respond within the timelines POPIA prescribes (without undue delay and in any event within a reasonable time). End-customer rights against the Customer (you) are addressed by you, the responsible party, in your own privacy notice.
8. Security
We take the security of personal information seriously. Our measures include (without limitation):
- Transport encryption — TLS in transit;
- At-rest encryption — for secrets, two-factor seeds, and other sensitive fields;
- Access control — role-based access in the application, two-factor authentication for platform administrators, audit-logged support sessions, signed API tokens;
- Rate limiting and abuse protection on webhook ingest and other exposed surfaces;
- Backups — daily, with verified restore harness;
- Vendor risk — contractual security clauses with sub-processors;
- Incident response — we will notify you and, where required by law, the Information Regulator without undue delay (within 72 hours where reasonably practicable) of a security compromise that is likely to result in harm.
No security system is impenetrable. You also share responsibility — use strong, unique passwords, enable two-factor authentication, do not share your access tokens, and tell us promptly of any suspicious activity.
9. Children
The Service is not directed to children under 18 years of age and we do not knowingly collect personal information of children. If you become aware that a child has provided us with personal information through your workspace, contact us and we will assist with removal.
10. Cookies
We use only operationally necessary cookies (session, CSRF, language preference, security token). We do not place third-party advertising cookies. We do not use third-party tracking pixels in our application.
11. Changes to this Policy
We may update this Policy. Material changes will be notified by email to the workspace owner at least 14 days before they take effect, and the change summary will appear on this page above the body. The "Effective date" at the top reflects the current version.
Previous versions remain available at /legal/privacy/version/
12. Information Officer and contact
The Information Officer of Zilo Software (Pty) Ltd is the role identified at /legal/contact.
- Email: privacy@zilo.co.za
- Postal: see /legal/contact
12.1. Information Regulator (South Africa)
If you are not satisfied with our handling of your personal information you may lodge a complaint with:
- Information Regulator (South Africa)
- Email: complaints.IR@justice.gov.za
- Web: https://inforegulator.org.za/
— end of Privacy Policy —