Privacy Policy
Effective July 2026
This policy describes how Rezolyn (“we”, “us”) handles data when you use our dashboard, API, or the customer support conversations Rezolyn processes on your behalf. It's written to reflect what the system actually does. If something here changes, this page changes with it.
What we collect
From businesses using Rezolyn (our customers): account details (email, organisation name), API usage, and billing information processed by our payment providers.
From end customers messaging through Rezolyn (on behalf of our customers): the message content, detected language, and channel metadata needed to generate and deliver a reply.
How conversation data is protected
- Passwords, API keys, and refresh tokens are hashed with bcrypt. Never stored or logged in plaintext.
- Credentials for connected third-party systems (partner APIs) and customer PII are encrypted at rest with authenticated encryption (AES-128-CBC + HMAC, Fernet).
- All traffic is encrypted in transit (TLS).
- Privileged platform actions are written to an append-only audit log.
How long we keep it
Conversation records are retained for as long as your organisation's account is active, so you can review history and export training data. You can request deletion at any time by contacting us.
Who we share data with
We share data with the infrastructure and AI providers required to run the service, cloud hosting, database and cache providers, and the language model providers that generate responses, under contracts that restrict them from using your data for their own purposes. We do not sell customer data.
Your rights
Depending on where you or your customers are located, you may have rights to access, correct, export, or delete personal data. To exercise these, contact hello@rezolyn.com.
Changes to this policy
We'll update the effective date above when this policy changes and, for material changes, notify account owners by email.