1. Data Ownership & Orchestration Layer Architecture
Zepiva acts strictly as an authorized orchestration layer, not as a data warehouse.
- WhatsApp Conversations & Data: All WhatsApp message history and media remain within Meta's own cloud infrastructure. Zepiva accesses the official Meta WhatsApp Business Cloud API only to send and receive messages on your behalf via OAuth authorization. We do not store or own your customer conversation archives.
- Email Communications & Data: All email data remains stored within your Google Workspace or Gmail account. Zepiva accesses your inbox via authorized Google OAuth2 scopes to read incoming messages and draft responses. Zepiva does not retain, export, or warehouse your inbox data outside Google's ecosystem.
- Voice Calls & Telephony: Telephony audio streams are routed through certified carrier infrastructure (Telnyx/Vapi) to deliver real-time AI voice responses.
- Zero Model Training: Your business rules, agreements, and customer communications are never used to train public AI foundational models.
2. Third-Party Service Providers & Sub-Processors
To deliver reliable AI communication services, Zepiva securely routes necessary operational data through vetted industry partners:
3. Information We Collect
We collect only the minimal information required to provide the orchestration service:
- Account Information: Your name, email address, and authentication credentials when you create an account.
- Business Rules & Agreements: Operating parameters, service descriptions, FAQs, and pricing rules you define to instruct your AI agent.
- Payment Information: Billing details processed securely through our payment provider. We do not store credit card numbers on our servers.
- System Telemetry: Operational event timestamps and API delivery receipts necessary for dashboard analytics.
4. What We Do NOT Do With Your Information
- We do not sell, rent, or monetize your business or customer data.
- We do not act as a permanent data warehouse for customer message histories.
- We do not use your private communications to train public AI models.
- We do not share your account details or settings with other customers.
5. Data Security Standards
We implement enterprise-grade security controls across our infrastructure:
- All data is encrypted in transit using modern TLS 1.3 protocols and at rest with AES-256 encryption.
- Access to customer accounts is restricted via scoped OAuth2 tokens with role-based access security.
- Payment processing is handled via certified PCI-DSS Level 1 compliant payment gateways.
6. Your Data Rights & Deletion
You maintain complete control over your account. You have the right to:
- Export your workspace settings and operational logs anytime from your dashboard.
- Request immediate, permanent account purging by contacting support@zepiva.com.
7. Contact Our Privacy Officer
If you have any questions regarding our data practices, sub-processors, or privacy controls, please contact:
Email: support@zepiva.com