Privacy Policy

Last updated: June 2025

Introduction

This Privacy Policy explains how Zazitek (“we”, “us”) collects, uses, discloses, and protects personal data when you use our website and services. We are based in Singapore (UEN 53513942W) and aim to handle personal data in line with the Singapore Personal Data Protection Act (PDPA) and comparable laws in the markets we serve, including Malaysia.

Our role: controller and processor

For your account and our website, we act as a data controller. When you use Zazitek to message and collect from your own customers, you are the controller of that customer data and we act as a data intermediary (processor) handling it on your instructions. You are responsible for having a lawful basis to contact your customers.

Information we collect

We collect information you provide directly (such as your name, email, business details, and account credentials), information you process through the service (such as invoices, contacts, and messages, which may include your customers' personal data), and technical data collected automatically (such as device, browser, IP, and usage information).

How we use information

We use information to provide and improve the service, create and send invoices, send reminders and process replies on your behalf, facilitate payments and reconciliation, communicate with you, maintain security, and comply with legal obligations.

Consent and withdrawal

Where we rely on consent, you may withdraw it at any time by contacting us, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may affect our ability to provide parts of the service.

How we share information and sub-processors

We share information with trusted third parties who help us operate the service, under appropriate safeguards. These include: hosting (Hetzner, in Singapore); messaging (Meta WhatsApp Business, Twilio); payments (HitPay, Xendit, Stripe); accounting integrations (such as Xero); and third-party AI model providers (see below). We also disclose information where required by law. We do not sell personal data.

Use of artificial intelligence

Some features use third-party AI providers to generate invoices and draft or send replies. To do this, relevant message and invoice content may be sent to these providers for processing. We use providers on terms that do not permit your data to be used to train their general models, and we share only what is needed for the feature to work. Some AI processing may occur outside Singapore (see international transfers).

Data location and international transfers

Your core data is hosted in Singapore. Some sub-processors (such as messaging, payment, and AI providers) may process data outside Singapore. Where personal data is transferred overseas, we take steps intended to ensure a comparable standard of protection consistent with the PDPA's Transfer Limitation Obligation and applicable law.

Data retention

We retain personal data for as long as your account is active or as needed to provide the service, and thereafter only as required to meet legal, accounting, tax, or reporting obligations, after which it is deleted or anonymised.

Security

We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Data breach notification

If a data breach occurs that is likely to result in significant harm or meets applicable notification thresholds, we will notify the relevant authority and affected individuals or controllers without undue delay, in line with the PDPA and other applicable laws.

Cookies and analytics

Our website may use cookies and similar technologies for essential functionality and to understand usage. You can control cookies through your browser settings; disabling some cookies may affect how the site works.

Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data, request a copy of certain data, and withdraw consent. We will respond within the timeframes required by applicable law. Where we act as a processor for a business, such requests should be directed to that business.

Data Protection Officer and contact

You can reach our Data Protection Officer and privacy contact at advoworks@gmail.com for any questions, requests, or complaints regarding this policy or your personal data.

Regional notes

Singapore: we handle personal data in accordance with the PDPA. Malaysia: where we serve customers in Malaysia, we aim to comply with the Malaysian Personal Data Protection Act, including its data protection officer and breach notification requirements. As we expand across Southeast Asia, we will address additional local requirements accordingly.

Changes

We may update this policy from time to time. Material changes will be reflected by updating the date above and, where appropriate, by additional notice.