Privacy
Which of us is responsible for your data, what we collect, and the control you keep over it.
Version 2.0 · last updated 17 August 2026 · Singapore law
Who this notice covers
Selza is one platform with four kinds of account on it, and not every clause below applies to all of them. So that you can tell which parts are yours:
- A licensed financial representative using the insurance register, and their clients.
- A CEA-registered salesperson using the property register, and their clients.
- A coach or studio owner on the fitness waitlist. That register is not open yet, so for now the only thing we hold about you is the message you sent us to join it — there is no account and no card.
- A business selling things through a shop on Selza, and their buyers.
- Anyone simply reading these pages, which is covered by the request logs any web server keeps and a cookie that remembers your theme. We do not build a profile of you from a visit.
Which of us is responsible for your data
The answer is not the same for everyone reading this, and getting it the wrong way round would tell a client we decide things about their data that we have no right to decide.
If you hold an account with us — a representative, an agent, a coach or a business — we are an Organisation under the Personal Data Protection Act 2012 in respect of your own data: your account, your billing, your use of the product. This notice governs that and we answer for it.
If you are the client of a representative or an agent who uses us, we are not the organisation that decides what happens to your data. Your representative and their firm are. We act as a Data Intermediary, processing it on their written instructions and for no purpose of our own. What we may and may not do in that role is set out clause by clause in the Data Processing Terms. A request about your data — to see it, correct it or have it deleted — should go to your representative first, because they hold both the relationship and the obligation. If you send one to us we will pass it to them and tell you we have.
If you are a buyer from a shop on Selza, the same shape applies: the business you bought from decides what happens to your data and we hold it for them.
What this policy is for
Selza is a seller operating system for small businesses. This policy explains what data we handle when you run your shop on Selza, how we use it, and the control you have over it. We keep it short and in plain language on purpose.
Who we are
Selza is operated by Atlas Agentic (UEN 53525496B), a business registered in Singapore. For any privacy question or request, email hello@selza.app.
What we collect
- Your account: your name, email and the shop details you set up.
- Your shop's data: the products, orders, messages and customer records you create or that flow through your connected channels.
- Payments: card and PayNow payments are processed by Stripe. Selza never sees or stores full card numbers.
- Usage: basic analytics about how the product is used, so we can keep it fast and fix problems.
What we collect from a representative, agent or coach
- Account details: your name, email address, mobile number, and the password or sign-in method you choose.
- Professional details you enter: your MAS representative number or CEA registration number, your firm or agency, and your photograph and biography if you publish a public page. What we publish beside a licence number is your own declaration of it — we are the publisher, not the regulator, and we neither verify nor badge it.
- How you use the product: pages opened, actions taken, documents uploaded and errors encountered — used to run and improve the service, not to profile you.
- Billing details where you pay us. Card details, if we ever take them, are handled by our payment provider and are never stored on our systems.
Client data we hold on a representative's or an agent's behalf
Where a representative or an agent uses the service with their clients, the data we hold for them is:
- The content of conversations between the client and the assistant, on whichever channel they arrive.
- The client's mobile number and email address where the representative has them. These are stored encrypted, alongside a one-way keyed fingerprint that lets an incoming message be matched to the right person without the number being readable in the index.
- Documents the representative uploads — policy and product summaries, or a listing's own particulars — and the passages extracted from them.
- Facts the representative records, or that are drawn from the documents they have provided: cover held, a renewal date, a viewing, an enquiry and how long it has waited.
- Recordings of meetings the representative chooses to record, and the transcripts made from them. See the clause on recordings below.
- A record of each answer the assistant gave, what it was based on, which checks ran, and whether it stopped and handed over.
What we never ask for
The system does not ask for, and has no field for, a NRIC or FIN number. The assistant never asks a client for contact details we do not already hold — it can only confirm one the representative gave it. We do not ask for health information, and we do not accept or use genetic test results, in line with the Moratorium on Genetic Testing and Insurance.
How we use it
- To run your shop — storefronts, order forms, pay-links, checkout and order tracking.
- To power your AI teammate, which drafts replies and proposals grounded in your own FAQ, catalogue and order history.
- To provide support and to improve the product.
How the assistant is used on a register, and what stops it
On the insurance and property registers the assistant answers from documents the representative has uploaded and approved, and from the facts they have recorded. It is a tool the representative operates. It is not a financial adviser, an agent or a doctor, and it does not give advice.
Every client-facing reply is checked before it is sent. Anything that reads as a recommendation, a suitability assessment, a coverage decision or a claim outcome is stopped and passed to the representative instead of being sent. Where a figure is quoted from a published source, it is quoted verbatim from the body that publishes it, with a link to their own page.
A client is told they are speaking to an assistant. Removing or obscuring that notice is a breach of our terms.
Who else processes it
We do not sell your data or your customers' data. We rely on a small set of trusted providers to deliver the service: Stripe for payments, Google Cloud for hosting, database and file storage, Clerk for sign-in, Resend for email, and Google Cloud Vertex AI (Gemini) for your teammate. Each processes data only to provide its part of the service, under its own security and privacy commitments.
Vertex AI is used on a paid, commercial plan whose terms prohibit it from using what we send to train or improve its models. We do not train, fine-tune or evaluate any AI or machine-learning model on your data or your customers' data, we do not use one business's data to serve another, and we run no model training of our own.
Connected chat channels (WhatsApp, Instagram, Facebook)
If you connect a WhatsApp Business, Instagram or Facebook account, we handle the messages that flow through it — their contents, and the sender's display name and phone number or handle — together with the account identifiers and access tokens needed to send and receive on your behalf. We use this only to run your conversations and your AI teammate. We never sell it, and never use it to build advertising or cross-app profiles. Data received from Meta is handled in line with the Meta Platform Terms, and you can remove it at any time (see the deletion steps below).
If you connect your own WhatsApp number, WhatsApp keeps working normally on your phone, and Meta mirrors the messages you send from the WhatsApp Business app to us, so your replies and your assistant's sit in one thread. We record such a message only when it belongs to a conversation someone has already started with you — anything else, including your personal chats, is discarded on arrival and never stored.
As part of connecting, WhatsApp asks whether to hand across your one-to-one chats from the last 180 days and the contacts saved on your phone. If you agree, we hold them apart from your account while you sort them: we group them for you, you choose which are your clients, and only those people and their conversations are added to your records. Everything you do not choose is deleted when you finish, and if you never finish we delete the whole batch after 30 days. We do not do this for any other kind of account, and group chats are never included — WhatsApp does not send them. Separately, you can choose to upload a chat export yourself — a file you send us, not something we take from your account — and we then store what that file contains, including the messages of anyone else in the conversation.
Connected Google Calendar
If you connect a Google Calendar, Selza reads when you are busy and writes the calls your assistant books for you. We request only the access needed for that: reading your calendar to work out which times you are free, and creating events on it. We store the connection token, encrypted, and you can disconnect at any time from Scheduling — which deletes it.
A calendar entry we create carries the client's first name, the channel they contacted you on and a link back to the conversation in Selza. It never carries their questions or anything about their policy.
Selza's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use your Google data only to provide the scheduling features described here and in the product, we do not sell or transfer it, we do not use it for advertising, we do not use it to train AI models, and no human at Selza reads it except where you have asked us to help, where security or the law requires it, or in aggregated and anonymised form.
Your calendar and AI, specifically. Your assistant runs on AI models operated by Google Cloud Vertex AI (Gemini). The contents of your calendar are never sent to them, because we never receive those contents in the first place: the free/busy access we request returns only intervals, not event titles, descriptions, attendees, locations or guest lists. The only thing derived from your calendar that an AI model ever sees is the short list of candidate appointment times our own servers compute from your busy intervals and the working hours you set — for example, "Tuesday 12 August, 3:00 pm" — so that the assistant can offer times you are genuinely free and no others. Vertex AI is used on a paid, commercial plan whose terms prohibit it from training or improving its models on what we send, it does not retain it for its own purposes, and no data derived from Google user data is used to develop, train, fine-tune or improve any generalised or foundational AI or machine-learning model, ours or anyone else's. We do not operate any self-hosted or offline model.
Meetings a representative records
A representative can record a meeting with a client. Consent is theirs to obtain and ours to hold: we store it against the client and copy it onto each recording made under it, so a recording can always be traced back to the permission it was made under.
The audio is stored in Singapore. It is transcribed by a speech recognition provider outside Singapore, on terms requiring a comparable standard of protection and prohibiting it from training its models on what we send. The transcript is held with the client's record and is exportable and deletable in the same way.
Where your data is held
In Singapore. The database, the uploaded files and the application itself all run in Singapore.
Where a transfer outside Singapore is necessary — model inference, the transcription of a recorded meeting, and our email and messaging providers — we transfer it under the Transfer Limitation Obligation, on terms requiring a comparable standard of protection. Inference, the moment a model reads a prompt and writes a reply, may happen on infrastructure outside Singapore; your stored data does not move.
How long we keep it
- Account data: while your account is open, and for as long afterwards as we are required to keep records.
- Conversations, documents, meeting recordings and client records: while the account is open, or until they are deleted.
- The record of what the assistant answered and what it stood on: five years, because that is the period a representative is expected to be able to account for.
- Ask us to delete and we will delete or return the data, other than anything we must keep by law — and we will tell you what that is.
Your data is yours
- Export your products, orders and customers at any time.
- Nothing about your data is held behind a payment — there is nothing to lapse and nothing to lock.
- Disconnect any WhatsApp, Instagram or Facebook channel from Settings → Support — this revokes our access and deletes the stored connection and its tokens.
- Disconnect Google Calendar from Scheduling — this deletes the stored token immediately, and you can also revoke Selza from your Google Account at any time.
- Erase a single customer's personal data, including their messages, from that customer's page — or delete your whole account by emailing hello@selza.app.
- Full step-by-step deletion instructions, including data received from Meta, live at selza.app/data-deletion.
Your rights, and how to use them
Under the PDPA you may ask for access to the personal data we hold about you and how it has been used, and ask us to correct it where it is wrong. Write to hello@selza.app and mark it for the Data Protection Officer, and we will respond within the time the Act allows.
If you are the client of a representative or an agent, please see the clause on responsibility above — they are the right first point of contact, and we will help them answer you.
You may withdraw consent to our use of your data at any time. We will tell you plainly what withdrawing means for the service, because in most cases it means we can no longer provide it.
If you are not satisfied with our response you may complain to the Personal Data Protection Commission of Singapore.
Security
Payments run on Stripe's PCI-compliant infrastructure, and money settles to your own connected account. Data is encrypted in transit. If you ever spot something that looks wrong, email us and we will act on it quickly.
How one account is kept out of another
Each workspace's data is separated at the database, not merely in the application, so a fault in the application cannot show one representative another's clients. Identifying contact details carry an additional layer of application-level encryption. Access by our staff is limited to what is needed to run the service, and is logged.
No system is perfect. If a breach occurs that is likely to cause significant harm, or that affects 500 or more individuals, it will be notified as the PDPA requires — and where we are acting for a representative or an agent, we will tell them without undue delay so that they can make their own notification.
Changes to this notice
This notice carries a version and a date, shown at the top. We will not change it retrospectively. Where a change is material we will tell account holders before it takes effect.
Questions
Email hello@selza.app and a real person will get back to you.
Status. This is a plain-language notice that reflects how the product actually works today. It is being reviewed by counsel; where the reviewed text differs we will publish it under a new version and tell account holders before it takes effect.
Client data on a register is governed in detail by the Data Processing Terms, which set out clause by clause which obligations sit with your firm and which sit with us. A licensed financial representative has a fuller notice, written for them alone, published on their own zone alongside those terms.
Any privacy question or request: hello@selza.app, marked for the Data Protection Officer.