Legal
Privacy policy
Last updated: 17 August 2026
This policy explains how Modulery Technologies handles personal data in the course of providing Zovibot. It covers two different groups of people, and the distinction matters throughout: customers, who sign up and install the assistant on their website, and visitors, who talk to an assistant on a customer’s website.
Our role, and yours
For data about our own customers — your account, your billing, your usage — we are the data controller.
For conversations and leads collected through the assistant on your website, you are the controller and we are the processor. You decide what the assistant asks for, what it says while asking, and what happens to the answers. We store and process it on your instructions. That means the legal basis for capturing a visitor’s contact details is yours to establish, and the privacy policy a visitor is shown before giving those details is yours, not this one.
What we collect
From customers
- Account: name, email address, hashed password, organisation name. Your password is stored as a bcrypt hash and is not recoverable by us.
- Sessions: a short-lived access token and a rotating refresh token, both in
HttpOnlycookies. We record the browser family and time of sign-in so you can spot access you did not authorise. - Billing: plan, subscription state, and payment records. Card details are handled entirely by our payment provider and never reach our servers.
- Usage: counts of conversations, messages and tokens per month, and what they cost us to serve. This is how quotas and invoices are calculated.
From your website
- Page content: the text of the pages we crawl, plus titles, headings and structured product data. We respect
robots.txtand identify ourselves asZovibotBot/1.0. - Uploaded files: documents you add to the knowledge base, and the text extracted from them.
From your visitors
- Messages: what the visitor typed and what the assistant answered, grouped into a conversation.
- Contact details: only the fields you configured, and only when the visitor supplied them. The assistant asks; the visitor’s own input is what is stored.
- Consent evidence: the exact wording that was shown, the time it was agreed to, and whether consent to marketing was given separately. This is stored so you can demonstrate the consent you rely on.
- Context: the page the conversation started on, and the origin of the website. We do not use tracking cookies in the widget, do not fingerprint devices, and do not build profiles of visitors across sites.
What we do not do
- We do not use one customer’s content or conversations to train any model shared with another customer, or to improve a general-purpose model.
- We do not sell personal data, and we do not share it for advertising.
- We do not let the assistant claim to be human. It identifies itself as AI on first contact and whenever asked.
Isolation between customers
Each customer’s content, conversations and leads are separated at the database level by row-level security, keyed to the organisation on the authenticated session — not by a filter in application code that a bug could omit. A query that fails to identify a tenant returns nothing rather than everything.
Who else processes this data
Our sub-processors, and what each one sees:
| Sub-processor | Purpose | What it receives |
|---|---|---|
| DeepSeek | Generating answers | The visitor’s question, the retrieved passages from your site, and recent conversation history. Not your account or billing data. |
| Dodo Payments | Subscription billing | Customer email and billing details. Card data goes to them directly and never through us. |
| Email relay | Notifications, password resets | Recipient address and message content. |
| Hosting provider | Running the service | All of the above, at rest and in transit. Servers and database are located in India. |
Embeddings — the numeric representations used to search your content — are generated on our own servers by default and are not sent to a third party.
How long we keep it
| Data | Retention |
|---|---|
| Conversations and messages | Per-site retention period you configure, then automatically purged |
| Leads | Until you delete them, or the organisation is deleted |
| Crawled content and embeddings | Until the source is removed or re-indexed |
| Usage records | 24 months, as billing evidence |
| Security audit log | 24 months, then purged |
| Account | Until you close it |
Deletion means deletion
When you delete a lead, a site, or your organisation, we perform a hard delete. That includes the derived artefacts — the extracted text, the chunks, and the vector embeddings — not only the parent records. A deletion that leaves the embeddings behind would leave your content searchable, so it is not one we consider complete.
Your rights
If you are in the UK, EU, or another jurisdiction with comparable law, you have the right to access, correct, export, delete and restrict processing of your personal data, and to object to it. You can export and delete leads and conversations yourself from the dashboard at any time. For anything else, contact us and we will act within one month.
If you are a visitor who spoke to an assistant on somebody else’s website and want your data removed, contact that website’s owner. They are the controller and we act on their instruction — we cannot make that decision for them. Tell us as well and we will make sure the request reaches them.
Security
- Everything is served over TLS. Session cookies are
HttpOnlyandSameSite-restricted, so browser JavaScript cannot read them. - Passwords are bcrypt-hashed at a work factor of at least 12.
- Third-party credentials you give us are encrypted at rest.
- We do not log passwords, tokens, API keys, or full contact details. Email addresses in logs are masked.
No system is perfect. If you find a security problem, please report it to us before disclosing it publicly, and we will work with you.
Where your data is, and where it goes
Modulery Technologies is established in India, and your account data, conversations, leads and indexed content are stored and processed in India.
Two of our sub-processors operate outside India: the language-model provider receives the text of a question and the passages retrieved to answer it, and the payment provider receives billing details. If you are in the UK or EEA, those transfers rely on the appropriate safeguards for an international transfer, and we will confirm which mechanism applies on request. If you need your data confined to a particular region, that is a Premium-plan arrangement rather than a default — ask us before you buy rather than after.
Children
Zovibot is a business product and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a visitor’s data was collected in error, tell us and we will delete it.
Changes
We will update this page when the product changes, and the date at the top always reflects the current version. If a change materially affects how we handle personal data, we will tell customers by email rather than relying on you noticing.
Who to contact
The data controller for your account data, and the processor for your visitors’ data, is:
Modulery Technologies
7, 1st Cross, Near Water Tank
Taralabalu Nagara, Hanumantha Nagara
Medehalli, Karnataka 577502
India
privacy@leadfella.com
Use that address for any request about personal data — access, correction, export or deletion — and say which it is so we can act on it without a round trip.
See also our terms of service and refund and cancellation policy.