Const Solutions FZ-LLC, operating as Zellio AI.
This Privacy Policy explains how Const Solutions FZ-LLC ("Zellio", "we", "us") collects, uses, stores and shares personal data when you use the Zellio platform, including the customer support, social, and ops surfaces.
We are registered in DIFC, Dubai (UAE) and in the Kingdom of Saudi Arabia, and Zellio is designed to align with GDPR (EU), KSA PDPL, UAE Data Protection Law, and US state privacy principles.
DIFC Innovation One, Level 4, Sheikh Zayed Road, Dubai · privacy@zellio.ai
The minimum required to run a useful product.
We collect three categories of data:
- Account data — name, email, role, workspace, billing details. Provided directly by you.
- Customer conversation data — messages, attachments, channel IDs (WhatsApp number, IG handle, etc.) for customers your store communicates with through Zellio. You are the controller; we are the processor.
- Usage telemetry — page views, feature interactions, error logs. Aggregated and pseudonymized for product analytics.
What we do not collect
- Customer payment card numbers (handled by Stripe / Tap directly)
- Browsing history outside the Zellio app
- Microphone / camera / location of your team members
Legal bases for processing.
The honest answer on training.
We do not train global foundation models on your conversations. Period. Our Zee agents use a combination of pre-trained foundation models (we work with Anthropic and OpenAI under enterprise no-training agreements) and per-tenant retrieval-augmented generation (RAG).
The RAG index for your workspace contains your knowledge base, your products, your past conversations — and it is queryable only by your workspace's agents. It is not shared, not pooled, not fine-tuned into a multi-tenant model.
If we ever want to train a shared model that benefits from your data, we will ask you, in writing, with an explicit opt-in toggle. Today, that toggle is off by default for every customer and has never been on.
Third parties we depend on.
To run the platform we use a small list of subprocessors — vetted, contractually bound, and audited. The full, current list (with role, region, and DPA links) lives at /subprocessors.
We notify customers within 30 days of any change. Enterprise customers can subscribe to the change feed.
Region-pinned, never crossed.
At workspace creation you pick one of three regions:
- EU · Frankfurt — eu-central-1 · GDPR · most EU customers
- KSA · Riyadh — me-south-1 · PDPL · most MENA customers
- US · Virginia — us-east-1 · US customers and cross-Atlantic teams
Your data — including backups, queue state, and per-tenant ML embeddings — stays in your region. Cross-region requests are blocked at policy level.
Default retention windows.
| Data category | Default retention | Configurable? |
|---|---|---|
| Conversation transcripts | 3 years from last activity | Yes · per workspace |
| Customer profiles | 5 years | Yes |
| Backups | 35 days rolling | System default |
| Audit logs | 7 years (Enterprise) | System default |
| Telemetry | 13 months | Anonymized after 6mo |
On account closure, all customer-controller data is purged within 30 days. Backups expire on the standard rolling schedule.
GDPR, PDPL and CCPA, in plain steps.
You can ask us to:
- Access — get a copy of personal data we hold
- Correct — fix anything inaccurate
- Delete — erase it, see deletion process →
- Restrict — pause processing for a defined scope
- Port — export in a machine-readable format (JSON or CSV)
- Object — stop processing where we rely on legitimate interest
Email privacy@zellio.ai or use the self-service tool in your workspace settings. We respond within 7 days; complete the request within 30.
Not for under-16s.
Zellio is a B2B platform sold to merchants. It is not directed at children and we do not knowingly collect data from anyone under 16. If we learn we have, we delete it.
How we handle policy changes.
Material changes (new categories of data, new subprocessor, new retention window) trigger a 30-day in-product notice before they take effect. Minor wording fixes are version-bumped and listed in the changelog at the foot of this page.
A human, not a webform.
Our Data Protection Officer is Layla Mahmoud. She responds to every inbound, in English or Arabic, within 5 business days.
Security documentation, DPA template, subprocessor list — direct downloads in the Trust Center.