Skip to content
Legal

Privacy policy built on restraint, not fine print.

Zyverra Labs builds AI agents, automation, SaaS, and custom software — work that only earns trust if we treat data properly, starting with our own. This policy explains exactly what we collect, why, who processes it, and the control you keep over it.

Last updated 23 July 2026GDPR alignedCCPA / CPRA alignedNo data selling
The short version

Four commitments, before the legal detail.

This summary is written for people, not lawyers. It does not replace the full policy below, but nothing below contradicts it.

We never sell your data

We do not sell, rent, or trade personal information, and we do not share it for cross-context behavioural advertising. We run no ad networks or retargeting pixels on this site.

We collect the minimum

We ask only for what a project conversation genuinely needs: your name, your email, and what you want built. Nothing on this site requires an account.

You stay in control

You can request a copy of your data, ask us to correct it, or ask us to delete it entirely. One email to our team is enough — no forms, no friction.

Security is engineered in

Encrypted transport, validated inputs, least-privilege access, and secrets kept out of the codebase. The same standard we apply to the software we build for clients.

Section 01

Who we are and what this covers

Zyverra Labs LLC(“Zyverra Labs”, “we”, “us”) is a software studio delivering web development, AI automation, SaaS products, AI voice agents, and custom software development. We are the data controller for the personal information described in this policy, and you can reach us at any time at hello@zyverralabs.com.

This policy applies to zyverralabs.com and to the enquiry, chat, and email channels we operate from it. It explains what we do with information about visitors, prospective clients, and people who contact us.

It does not cover the data inside systems we build and operate on behalf of a client — in those engagements the client is the controller and their own privacy notice governs. Section 8 explains that relationship. It also does not cover third-party sites we link to, each of which has its own policy.

This policy takes effect on 23 July 2026 and replaces any earlier version.

Section 02

Information we collect

We group what we collect by how it reaches us. Everything in the first two groups is information you actively choose to give us.

Information you give us through the enquiry form

  • Your name and email address, so we know who you are and can reply.
  • Your message — the description of the project, problem, or question you want to discuss.

Information you give us through the AI assistant

  • The messages you type into the assistant, and the replies it generates, stored as a conversation thread.
  • Project qualification details you volunteer during that conversation — such as business type, project type, indicative budget, timeline, and an optional phone number.
  • An anonymous session identifier, generated in your browser, that lets the assistant remember your thread across page loads. It is not linked to your identity unless you tell the assistant who you are.

The assistant is a sales and scoping tool. Please do not paste passwords, payment card numbers, health information, government identifiers, or confidential third-party material into it. If you do so by accident, email us and we will delete it.

Information collected automatically

  • Server and security logs, which record the request path, method, response status, timestamp, and the requesting IP address. We use these to keep the site available and to enforce rate limits against abuse.
  • Aggregate analytics events — pages viewed, approximate location at country or city level, device and browser type, and the referring site. See section 5.
  • Local storage entries set by your own browser to keep your assistant session and saved project threads. See section 4.

Information we do not collect

This site has no user accounts, no passwords, and no payment processing. We do not collect special-category or sensitive personal data, we do not use advertising or retargeting pixels, and we do not buy contact lists or enrich your record from data brokers.

Section 03

How and why we use it

We only process personal data where we have a lawful basis to do so. For visitors in the UK, EU, and EEA, those bases under the GDPR are set out explicitly below.

  • To respond to your enquiry and scope potential work — necessary to take steps at your request prior to entering a contract (Art. 6(1)(b)).
  • To deliver and support engagements you have signed with us — performance of a contract (Art. 6(1)(b)).
  • To operate, secure, and debug the website, including rate limiting and abuse prevention — our legitimate interest in running a safe, functioning service (Art. 6(1)(f)).
  • To understand which pages are useful and improve our content and performance — your consent, given through our cookie banner and withdrawable at any time (Art. 6(1)(a)).
  • To triage and prioritise enquiries using automated summarisation and scoring of the details you provided — legitimate interest in responding efficiently (Art. 6(1)(f)). See section 6 for the safeguards.
  • To meet legal, tax, and accounting obligations and to establish or defend legal claims — legal obligation and legitimate interest (Art. 6(1)(c) and 6(1)(f)).

We do not use your information for automated advertising profiles, and we will not add you to a marketing list from an enquiry alone. If we ever introduce a newsletter, it will be opt-in with a one-click unsubscribe.

Section 04

Cookies and local storage

We keep this deliberately light. The site sets no marketing cookies and no cross-site trackers.

Strictly necessary

A preference cookie may record your chosen language so the site loads in the right locale, and an administrator session cookie exists only for our own internal dashboard. Neither is used to track you across sites.

Browser local storage

The AI assistant stores a randomly generated session identifier and your saved project threads in your browser’s local storage. This never leaves your device except as the identifier attached to your own assistant messages, and clearing your browser storage removes it permanently.

Analytics

Google Analytics 4 sets first-party cookies to distinguish returning visits and measure traffic in aggregate. They are set only if you accept them in our cookie banner, and only on the production site. You can withdraw that consent at any time from our Cookie Policy, which also deletes the cookies already set.

Every browser lets you block or delete cookies and clear site storage. Blocking strictly necessary items may mean your language preference or assistant thread is not remembered, but the site will still work.

Section 05

Analytics

We use Google Analytics 4 to understand which pages people read, how they arrive, and where the experience is slow. It is opt-in: the Google script is not loaded until you accept analytics in our cookie banner. Measurement is also enabled only on the production site, so development and preview builds send nothing regardless.

Analytics data is pseudonymous. We see aggregate patterns — sessions, page views, approximate location, device and browser type, referrer — not the identity of individual readers, and we do not attempt to reverse it into an identity or match it to your enquiry. Google Analytics 4 truncates IP addresses and does not store them in reports.

How to opt out

  • Decline analytics in the cookie banner, or withdraw consent later from our Cookie Policy, which also deletes the cookies already set.
  • Install Google’s official browser add-on at tools.google.com/dlpage/gaoptout.
  • Block analytics cookies or scripts in your browser or extension settings.
  • Enable a tracking-prevention setting or Global Privacy Control signal — see section 14.
Section 06

The AI assistant and automated processing

Building AI systems is our work, so we hold our own to the standard we would expect of a client’s. Here is precisely how ours behaves.

  • Where your messages go.The assistant is powered by OpenAI models. Your messages, together with a short instruction prompt and relevant excerpts from our own service knowledge base, are sent to OpenAI’s API to generate each reply.
  • Training.We use OpenAI’s business API, under which data submitted through the API is not used to train their models. We do not train any model of our own on your conversations.
  • What we store. Conversation threads, and any contact or project details you volunteer, are stored in our database so we can pick up the conversation where you left it and prepare a useful reply.
  • Automated summarisation and scoring. We generate a short summary and a priority indication from the details you provided, purely to help a human decide what to read first.
  • No decisions with legal effect. No automated decision produces a legal or similarly significant effect on you within the meaning of GDPR Art. 22. Every reply that matters — whether we take on a project, on what terms, at what price — is made by a person.
  • Accuracy. Language models can be confidently wrong. Nothing the assistant says is a quote, a commitment, or professional advice until a person from our team confirms it in writing.

You can ask us to delete an assistant conversation at any time by emailing hello@zyverralabs.com with the approximate date of the chat.

Section 07

Third-party services and sub-processors

We use a small, deliberate set of providers to run the site and the business. Each is bound by its own contractual data-protection terms, receives only the data it needs, and processes it on our instructions.

ProviderPurposeData involvedProcessing region
VercelWebsite hosting, edge delivery, and server-side renderingIP address, user agent, request metadata in operational logsUnited States / global edge network
Neon / PostgreSQLManaged database for enquiries, leads, and assistant conversationsContact details and message content you submitConfigured cloud region
OpenAIPowers the AI assistant's replies and enquiry summarisationAssistant message content and any details you type into the chatUnited States
ResendDelivers enquiry notification emails to our teamYour name, email address, and enquiry messageUnited States
Google Analytics 4Aggregate traffic and page-performance measurementPseudonymous usage events, truncated IP address, device and referrer dataUnited States / EU

Beyond these, we disclose personal data only where the law requires it — a valid legal request, a regulatory obligation, or the need to establish or defend a legal claim — or where it is necessary to protect the rights and safety of our users. If our business is ever restructured or acquired, personal data may transfer as part of that transaction, and this policy will continue to apply until you are given notice of any change.

Section 08

Client project data and our role as processor

When we design, build, or operate software for a client — a SaaS platform, an automation pipeline, an AI voice agent, or a custom application — the client is the controller of the personal data flowing through that system and we act as a processor on their documented instructions.

  • We process client data only to deliver the agreed engagement: building, testing, debugging, migrating, and supporting the system.
  • We work against anonymised, synthetic, or minimised datasets wherever it is practical, and we ask for production access only when a task genuinely requires it.
  • Access is least-privilege and time-bound. Credentials live in managed secret stores, never in the codebase or in chat.
  • We enter a data processing agreement where one is required, engage sub-processors only with the client’s agreement, and support the client in answering requests from their own users.
  • At the end of an engagement we return or delete client data on request, apart from records we must retain for legal or accounting purposes.

If you are an end user of a product we built for someone else, please direct your privacy request to that organisation. If you send it to us, we will forward it to them.

Section 09

International data transfers

We operate from Pakistan and serve clients worldwide, and several of our providers are based in the United States. Personal data may therefore be transferred to and processed in countries outside your own, including ones whose data-protection laws differ from those where you live.

Where personal data is transferred out of the UK, EU, or EEA, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) in our agreements with those providers, alongside the technical measures described in section 11. You may request further detail on the safeguards applied to a specific transfer by emailing hello@zyverralabs.com.

Section 10

How long we keep data

We keep personal data only as long as it serves the purpose it was collected for, then delete it. Our working periods are:

  • Enquiries that do not become projects — up to 24 months from the last contact, so we have context if you come back to us.
  • AI assistant conversations — up to 12 months from the last message, unless linked to an active engagement.
  • Client and project records — for the life of the engagement and then as long as required by contract, tax, and accounting law, typically six to seven years.
  • Server and security logs — a short rolling window, normally under 90 days, unless a specific security investigation requires longer.
  • Analytics data — retained according to the retention period configured in Google Analytics 4, after which it is deleted by Google.

You can ask us to delete your data sooner. We will do so unless we have an overriding legal obligation to keep a specific record, in which case we will tell you what we are keeping and why.

Section 11

How we protect your data

Security is treated as a feature of the product, not a task before launch. The measures protecting this site are the same ones we build into client systems.

  • Encryption in transit via HTTPS/TLS across the site and every API call, with encryption at rest on our managed database.
  • Strict input validation on every endpoint, with typed, schema- validated payloads rejected at the boundary before they reach any logic.
  • Parameterised database access through an ORM, which removes entire classes of injection vulnerability by construction.
  • Rate limiting and abuse controls on public endpoints such as the contact form and the assistant.
  • Least-privilege access to production systems, with an authenticated internal dashboard and credentials held in managed secret storage, never committed to source control.
  • Hardened response headers and dependency updates as part of routine maintenance.

No system on the internet is perfectly secure, and we will not pretend otherwise. If a breach ever affects your personal data, we will notify the relevant supervisory authority and the people affected without undue delay, as the law requires. If you believe you have found a vulnerability, please report it to hello@zyverralabs.com and we will respond quickly.

Section 12

Your privacy rights

Your rights depend on where you live, but we apply the same process to every request we receive, wherever it comes from.

If you are in the UK, EU, or EEA (GDPR)

Access

Ask us to confirm what personal data we hold about you and receive a copy of it.

Rectification

Ask us to correct information that is inaccurate or incomplete.

Erasure

Ask us to delete your personal data where we have no overriding legal or contractual reason to keep it.

Restriction

Ask us to pause processing while an accuracy dispute or objection is being resolved.

Portability

Receive the data you gave us in a structured, machine-readable format, or have it sent to another provider.

Objection

Object to processing we carry out under legitimate interests, including any direct marketing.

Withdraw consent

Withdraw consent at any time where consent is the basis we rely on. This does not affect processing already carried out.

Complain

Lodge a complaint with your local supervisory authority if you believe we have handled your data unlawfully.

If you are in California (CCPA / CPRA)

Right to know

Request the categories and specific pieces of personal information we have collected about you, the sources, and the purposes.

Right to delete

Request deletion of personal information we collected from you, subject to the exceptions the statute allows.

Right to correct

Request correction of inaccurate personal information we maintain about you.

Right to opt out

Opt out of the sale or sharing of personal information. We do not sell or share personal information, so there is nothing to opt out of — but the right stands.

Right to limit

Limit the use of sensitive personal information. We do not collect sensitive personal information through this website.

Right to non-discrimination

Exercise any of these rights without receiving a different price, quality, or level of service from us.

In the twelve months before this policy was published we collected the categories of information described in section 2 — identifiers, commercial information about a prospective project, and internet activity — for the purposes in section 3. We did not sell or share any of it, and we did not disclose it for anyone else’s commercial purposes.

How to exercise a right

Email hello@zyverralabs.com and tell us what you want. There is no form to complete and no fee. We may ask a question or two to verify that the request really comes from you — usually by confirming details from the email address on record — and we will respond within 30 days (45 days for California requests, extendable once where the statute permits, with notice to you).

You may use an authorised agent where the law allows it. If you are unhappy with our answer you can complain to your local supervisory authority, and we would appreciate the chance to put it right first.

Section 13

Children's privacy

Our services are built for businesses. This site is not directed at children, and we do not knowingly collect personal data from anyone under 16 (or under 13 in the United States).

If you believe a child has provided us with personal data, email hello@zyverralabs.com and we will delete it promptly.

Section 14

Do Not Track and Global Privacy Control

There is still no common standard for how sites should interpret browser Do Not Track signals, so we do not respond to them differently — a position we would rather state plainly than imply otherwise.

We do recognise Global Privacy Control as a valid opt-out of the sale or sharing of personal information. In practice it changes nothing about our behaviour, because we never sell or share personal information in the first place.

Section 15

Changes to this policy

We will update this policy when our services, providers, or legal obligations change. The effective date at the top of the page always reflects the current version.

If a change materially affects how we handle your personal data, we will make it prominent on the site and, where we hold your address and the law requires it, notify you by email. Continuing to use the site after an update means you accept the revised policy.

Section 16

How to contact us

Privacy questions, access requests, deletion requests, and vulnerability reports all go to the same place, and a person reads every one.

Legal entity
Zyverra Labs LLC
Privacy contact
Website
zyverralabs.com
Response time
Within 30 days

Prefer to talk about a project instead? Start a conversation from the contact section and we will reply personally.

Still have a question?

Ask us anything about your data.

We would rather answer a direct question than have you guess at what a policy means. Email us and a person will reply.

Email hello@zyverralabs.com