Polare Group Sàrl (CHE-221.062.769), Geneva, Switzerland, operates the ZHOLY platform at https://zholy.ai. This Privacy Policy explains what personal data we process, why, on what legal bases, and what rights you have under the Swiss Federal Act on Data Protection (nFADP, in force 1 September 2023) and, where applicable, the EU General Data Protection Regulation (GDPR).
This document is provided for transparency. It does not constitute legal advice. Businesses embedding ZHOLY on their own sites remain independent controllers for their visitors' data.
1. Data controller
- Controller: Polare Group Sàrl, Geneva, Switzerland
- UID: CHE-221.062.769
- Product: ZHOLY — conversational interface for websites and applications
- Privacy contact: privacy@zholy.ai
2. Scope
This policy applies when you:
- Visit https://zholy.ai or use the ZHOLY marketing site and voice demo
- Create or manage a ZHOLY account (dashboard at https://zholy.ai/app)
- Subscribe to paid plans processed via Stripe
- Interact with ZHOLY embedded on a customer website (we act as processor for that customer; see Section 10)
3. Categories of data we process
3.1 Account & billing
- Name, email address, organisation, billing address
- Subscription status, plan tier, invoices (payment card data is handled by Stripe — we do not store full card numbers)
- Authentication identifiers and session tokens
3.2 Voice & conversation data
- Audio you submit during voice sessions (processed in real time for speech-to-text)
- Transcripts of conversations when logging is enabled by the account holder
- Derived metadata: detected language, approximate emotion cues from audio (not biometric identification)
- Camera frames only when you explicitly enable vision mode and ask the agent to look
Voice recordings may qualify as sensitive personal data under GDPR Article 9 in some contexts. We treat voice data with heightened care: default demo sessions on https://zholy.ai do not persist raw audio unless you opt in; production retention is controlled by the subscribing organisation.
3.3 Technical & usage data
- IP address, browser type, device identifiers, referrer URL
- Embed configuration, page context sent for grounding answers, crash and performance logs
- Cookie and local-storage identifiers (see our Cookie Policy)
3.4 Lead capture
- Name, email, company, and custom fields submitted through ZHOLY lead forms after conversations
4. Purposes and legal bases
| Purpose | Legal basis (GDPR / nFADP) |
|---|---|
| Provide and secure the service | Contract; legitimate interest (security) |
| Voice transcription & agent replies | Contract; consent where required for optional features |
| Billing & subscription management | Contract; legal obligation (accounting) |
| Product improvement & abuse prevention | Legitimate interest (balanced against your rights) |
| Marketing communications | Consent or soft opt-in where permitted |
5. Processors & international transfers
We use carefully selected subprocessors, including:
- Hosting: Swiss and/or EU infrastructure (plan-dependent: LOCAL self-host, CLOUD Swiss, SOVEREIGN EU-dedicated)
- Stripe, Inc. — payment processing (US/EU; SCCs)
- Hetzner Online GmbH — infrastructure hosting (EU/CH)
- AI inference — on your server (LOCAL/SOVEREIGN) or managed nodes (CLOUD)
Transfers from Switzerland to countries without adequate protection rely on Swiss FDPIC-approved mechanisms or GDPR Standard Contractual Clauses plus supplementary measures where required.
6. Retention
- Account data: for the life of the account plus statutory retention (typically 10 years for accounting records under Swiss law)
- Voice/audio: not retained by default in demo mode; production retention configurable by the customer, default 90 days for transcripts unless deleted earlier
- Logs: rolling 30–90 days unless required for security investigations
7. Security
We apply encryption in transit (TLS 1.2+), access controls, least-privilege administration, and regular patching. Self-hosted (LOCAL) deployments remain your responsibility for infrastructure hardening.
8. Your rights
Under nFADP and GDPR (where applicable) you may request:
- Access, rectification, erasure, restriction, portability
- Objection to processing based on legitimate interests
- Withdrawal of consent (without affecting prior lawful processing)
- Lodging a complaint with the Swiss FDPIC or your EU supervisory authority
Contact privacy@zholy.ai. We respond within 30 days unless complexity requires extension.
9. Children
ZHOLY is not directed at children under 16. We do not knowingly collect their data. Contact us to request deletion if you believe a child has provided personal data.
10. Customer websites (processor role)
When a business embeds ZHOLY, that business is the data controller for its site visitors. Polare Group Sàrl processes visitor voice and conversation data on the customer's instructions under a Data Processing Agreement (DPA). End-users should also read the host website's privacy notice.
11. Changes
We may update this policy. Material changes will be announced on https://zholy.ai with a revised effective date. Continued use after the effective date constitutes acceptance where permitted by law.