Last updated: 7 July 2026
This Privacy Policy explains how Zolvd for Teams collects, uses, and protects personal information when you use our platform. We are committed to handling your data responsibly and transparently.
Zolvd for Teams is operated by David Hildebrand, a sole proprietor based in the Republic of South Africa. References to "we", "us", or "Zolvd" in this policy refer to this entity. For privacy-related matters, contact us at [email protected].
Organisation and Member account information: organisation name, and for each Member — name, email address, and role within the Organisation.
Client information: name, contact name, contact email, and contact phone number for the Organisation's own clients — entered and maintained by the Organisation's Members, not collected directly from those clients by us.
Usage data: project and governance activity (RAID log entries, RACI assignments, escalations, change requests, and similar records), email delivery records (client status reports, automated alerts), and session information to operate the platform.
We do not use your data for advertising, and we do not sell your personal information to third parties.
We use the following third-party services to operate Zolvd for Teams:
Each provider operates under their own privacy policies and data processing agreements.
An Organisation's Members input data about the Organisation's own clients and projects. In this context, the Organisation is the responsible party (under POPIA) or data controller (under GDPR). Zolvd acts as the operator or data processor, processing that data solely to provide the Service. Organisations are responsible for ensuring they have a lawful basis to input their clients' personal information into the Service, and for managing which individuals hold Member access to their account.
We retain an Organisation's data for as long as its account is active. When an Organisation's account is closed, its data is deleted or anonymised within 90 days. Activity logs and email logs may be retained for up to 12 months for operational purposes.
We use industry-standard security practices including: encrypted data in transit (HTTPS/TLS), row-level security enforced at the database layer scoping every Organisation's data to its own Members, role-based access controls, and audited timestamps on key governance actions. No system is perfectly secure, and we cannot guarantee absolute security.
Depending on your location, you may have rights to access, correct, or delete your personal data. To exercise these rights, email [email protected]. We will respond within 30 days.
An individual Member may request deletion of their own personal account information (name, email, login credentials) at any time by emailing [email protected] — this does not delete the Organisation's own data (projects, clients, RAID logs, and similar records), which belongs to the Organisation as a whole.
To request deletion of an Organisation's entire account and all associated data, the Organisation's Owner/Admin should email [email protected] with the subject line Organisation deletion request. We will confirm receipt within 2 business days and complete the deletion within 30 days.
What is deleted: the Organisation's account, all Member accounts associated solely with it, all projects, clients, governance records, and activity logs.
What may be retained: records required for legal, tax, or compliance purposes (minimum period required by law), and anonymised aggregated usage statistics that cannot identify you or your Organisation.
We use session cookies to maintain your authenticated state. We do not use tracking or advertising cookies. No consent banner is required for session-essential cookies.
We may update this Privacy Policy from time to time. We will notify Organisation Owners/Admins by email of material changes. Continued use of the Service after changes are posted constitutes acceptance.
For privacy-related questions, email [email protected]. For general support, email [email protected].