Last updated: 15 July 2026
This Privacy Policy explains how Zarvin ("Zarvin", "we", "us", or "our") collects, uses, discloses, and protects personal information in connection with our website located at https://zarvin.net (the "Site") and the AI automation services we provide (the "Services").
Zarvin is operated by [LEGAL ENTITY NAME], registered in [COUNTRY / STATE OF REGISTRATION], with its principal place of business at [BUSINESS ADDRESS]. If you have any questions about this Policy, contact us at [PRIVACY EMAIL, e.g. [email protected]].
By using the Site or our Services, you agree to the practices described in this Policy. If you do not agree, please do not use the Site or the Services.
1. Our Two Roles: Controller and Processor
Because of the nature of our Services, we handle personal information in two distinct capacities. Understanding which applies to you matters for your rights.
(a) As a Data Controller. When you visit our Site, submit a form, request a demo, or engage us as a client, we decide how and why your information is used. In these situations we are the "controller" (or the equivalent under applicable law).
(b) As a Data Processor / Service Provider. When we operate AI messaging campaigns (such as our Database Reactivation, Speed to Lead, Out of Hours, and Google Reviews services) on behalf of a business client, we process the personal information of that client's own leads and customers strictly under the client's instructions. In those cases, our client is the controller and Zarvin is the "processor" or "service provider". This Policy describes our own practices; the collection and use of that end-customer data is governed by our client's privacy policy, and we handle it under a separate data processing agreement with the client.
Important: Our clients are solely responsible for ensuring they have a lawful basis and any required consent (including consent for marketing calls and text messages) before providing us with contact data to process. See our Terms of Service.
2. Information We Collect
2.1 Information you provide to us
Contact and demo requests: name, business name, email address, phone number, industry/niche, and details about your product or service, submitted through forms on our Site (including forms powered by LeadConnector / GoHighLevel).
Client onboarding information: billing details, business information, account credentials for platforms you ask us to integrate, and campaign configuration details.
Communications: the content of messages, emails, calls, and support requests you send us.
2.2 Information we collect automatically
Usage and device data: IP address, browser type, device information, pages viewed, referring URLs, and interactions with the Site.
Cookies and similar technologies: see Section 8.
2.3 Information processed on behalf of clients
When operating campaigns for a client, we process contact lists and conversation data (names, phone numbers, email addresses, message content, and engagement history) supplied by or generated for that client. We process this data only to deliver the Services.
2.4 Information we do not intend to collect
We do not seek to collect sensitive personal data through the Site. We do not accept or process protected health information (PHI) governed by HIPAA unless a separate Business Associate Agreement is in place with the relevant client. Do not send us PHI or other sensitive data outside of an agreed, compliant arrangement.
3. How We Use Information
We use personal information to:
respond to enquiries and build and deliver requested demos;
provide, operate, maintain, and improve the Services;
send AI-generated and human communications by SMS, WhatsApp, email, and phone where you or our client has a lawful basis to contact the recipient;
process payments and manage client accounts;
personalise and improve the Site and our AI models' performance (using aggregated or de-identified data where practicable);
comply with legal obligations and enforce our agreements;
detect, prevent, and address fraud, abuse, and security issues.
We rely on the following legal bases (where applicable): your consent; performance of a contract; our legitimate interests in operating and growing our business; and compliance with legal obligations.
4. SMS, WhatsApp, and Messaging Consent
Our Services and our own outreach may involve automated and AI-generated text messages via SMS and WhatsApp.
We (and our clients) send marketing messages only where the recipient has provided the consent required by applicable law, including the U.S. Telephone Consumer Protection Act (TCPA) and carrier/CTIA rules where relevant.
Message frequency varies. Message and data rates may apply.
Recipients can opt out at any time by replying STOP to any message, and can request help by replying HELP.
We honour opt-out requests promptly and maintain suppression lists.
Mobile opt-in data and consent records are not shared with third parties for their own marketing purposes.
If you receive messages you believe were sent without consent, contact us at [PRIVACY EMAIL] and we will investigate and, where we act as processor, notify the responsible client.
5. How We Share Information
We do not sell your personal information. We share it only as follows:
Service providers / subprocessors who help us run the Site and Services, including: GoHighLevel / LeadConnector (CRM, forms, messaging infrastructure) Communications carriers and messaging providers (e.g. SMS aggregators, WhatsApp Business API providers) AI processing providers (e.g. Anthropic and/or other large-language-model providers) used to generate message content Scheduling tools (e.g. Calendly) Analytics, hosting, and email providers Payment processors
Our clients, where we generate leads, bookings, or conversation data on their behalf.
Professional advisers, and in connection with a business transfer (merger, acquisition, or sale of assets).
Legal and safety disclosures, where required by law or to protect rights, safety, and property.
Each subprocessor is engaged under terms requiring appropriate confidentiality and security.
6. AI Processing Disclosure
Message content and conversation data may be processed by third-party artificial intelligence models to generate replies and qualify leads. We take reasonable steps to configure these tools so that data is used to provide the Service and not to train third-party public models where such controls are available. AI-generated messages may be reviewed or supplemented by humans. AI outputs can contain errors; the Services are not a substitute for professional advice.
7. International Transfers
Zarvin operates from [COUNTRY] and works with clients and providers located in the United States, the United Kingdom, the European Union, and elsewhere. Your information may be transferred to, stored in, and processed in countries other than your own, which may have different data-protection laws. Where required, we implement appropriate safeguards (such as standard contractual clauses) for such transfers.
8. Cookies and Tracking
We use cookies and similar technologies to operate the Site, remember preferences, and analyse traffic. You can control cookies through your browser settings. Some features may not function properly if cookies are disabled. Where required by law, we request consent before setting non-essential cookies.
9. Data Retention
We retain personal information for as long as necessary to fulfil the purposes described in this Policy, to comply with legal, tax, and accounting obligations, and to resolve disputes and enforce agreements. Data processed on behalf of a client is retained according to our agreement with that client and deleted or returned on request or on termination, subject to legal retention requirements.
10. Your Rights
Depending on where you live, you may have some or all of the following rights:
Access the personal information we hold about you;
Correct inaccurate or incomplete information;
Delete your information ("right to be forgotten");
Restrict or object to certain processing;
Data portability;
Withdraw consent at any time (without affecting prior lawful processing);
Opt out of marketing communications;
Lodge a complaint with your local data-protection authority.
California residents (CCPA/CPRA): you have the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information, and not to be discriminated against for exercising these rights. We do not sell personal information.
EU/UK residents (GDPR): you have the rights listed above and may contact the relevant supervisory authority.
Malaysia (PDPA): you have rights of access and correction and may limit processing in accordance with the Personal Data Protection Act 2010.
To exercise any right, email [PRIVACY EMAIL]. We will respond within the timeframe required by applicable law. If we process your data on behalf of a client, we may direct your request to that client as the controller.
11. Security
We use reasonable administrative, technical, and organisational measures to protect personal information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Children's Privacy
The Site and Services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
13. Third-Party Links
The Site may link to third-party websites and services. We are not responsible for their privacy practices. Please review their policies separately.
14. Changes to This Policy
We may update this Policy from time to time. The "Last updated" date reflects the latest revision. Material changes will be posted on this page and, where appropriate, communicated to you.
15. Contact Us
[LEGAL ENTITY NAME] (Zarvin) Email: [PRIVACY EMAIL] Address: [BUSINESS ADDRESS] Website: https://zarvin.net