1. Who is the data controller
Zellap is the data controller for the personal data processed through zellap.com, including registration, purchases, the customer relationship, and enquiries. If you have questions about privacy, or want to exercise your rights, contact us at account@zellap.com.
The data controller is ZELLAP WEB AGENCY RAHIMI, organisation number 937 103 050.
For the websites we run on behalf of our customers (a hair salon's own website, for example), the customer is the data controller for their own end customers' data, and Zellap is the data processor. That relationship is governed by the data processing agreement.
2. What data we process
| Purpose | Data | Legal basis |
|---|---|---|
| Account and login | Email, password (encrypted), optionally your name | Contract (GDPR Art. 6(1)(b)) |
| Purchase and subscription | Company name, contact email, organisation number, chosen plan, domain | Contract |
| Payment | Payment and subscription data via Stripe | Contract and legal obligation (Norwegian Bookkeeping Act) |
| Domain registration | The domain holder's name, address, email, phone number, and organisation number, sent to the registrar and on to the registry for the top-level domain | Contract and legal obligation |
| AI-assisted text and design | The text and content you enter yourself, or ask for help with, in the website builder | Contract |
| The Zellie AI assistant in the admin panel | The question you type, and a redacted snapshot of your admin panel: which pages and features you have, your services and prices, opening hours, and figures in aggregate form | Contract |
| Enquiries | Name, email, and the content of your message | Legitimate interest in responding to you |
| Marketing to businesses | Company name, organisation number, contact email, contact person, phone number, industry, location or region | Legitimate interest (GDPR Art. 6(1)(f)) |
| Security and operations | IP address, browser signals, technical logs | Legitimate interest (security, troubleshooting) |
| Statistics | Anonymous usage statistics via Google Analytics | Consent (GDPR Art. 6(1)(a)) |
3. Cookies and statistics
We don't load statistics or marketing cookies until you've given consent. Statistics are collected only through Google Analytics, in anonymised form: we measure how the site is used so we can improve it, with no profiling or advertising. Under Marketing sits the Meta pixel, which measures whether a visit to zellap.com came from an ad on Facebook or Instagram, and whether it resulted in an order. We don't send Meta any name, email address, or organisation number, and the pixel isn't present on the websites we run for our customers. You can change or withdraw your consent at any time. You'll find a full overview in the cookie policy.
We also measure visits to the websites we run for our customers. When a customer's own domain goes live, we create a Google Analytics property for that domain in our own Google account, and count page views on the public pages. Here Zellap is the data controller, not the salon: the purpose is our own — to see how the websites we deliver are performing, and to improve them. Nothing loads until the visitor has agreed to statistics in that website's consent panel, the IP address is anonymised, and Google signals and ad personalisation are turned off. We don't collect names, contact details, orders, point-of-sale data, or payment data through this, and the salon's own admin panel isn't counted. If the salon has pasted in their own Google Analytics ID, it belongs to the salon alone — we neither read nor change it.
4. Marketing to businesses
We contact businesses that could benefit from Zellap and send them an offer by email. This applies only to businesses, at the business's own contact address. We don't send marketing to private individuals.
What we process, and where it comes from
For a business we're considering contacting, we store the company name, organisation number, contact email, contact person's name, phone number, industry, and location or region. This information comes from three places:
- information one of our salespeople has entered manually,
- lists we've compiled ourselves,
- Enhetsregisteret (Brreg), a public, open register of Norwegian businesses.
The legal basis
The basis is legitimate interest (GDPR Art. 6(1)(f)). Our interest is to present a business tool to companies in an industry it's built for. We've weighed this against the privacy of the person receiving the email, and we stay within bounds: we use the business's own contact address, we clearly say who we are, and you can say no at any time without giving a reason. Once you do, you won't hear from us again.
What we log per recipient
Every offer has its own link per recipient. On that link, we log:
- that the email was sent, and when,
- when the offer was first opened,
- when a link in the offer was clicked,
- whether the offer was accepted.
We use this to see whether the offer is being read and whether it's worth following up. We don't use tracking pixels in the email, we don't build a profile of you, and we don't share anything with ad networks. This information is never sold on.
How to opt out
Every single email has an unsubscribe link. Click it, and we block the address permanently. The block is checked before every send, and it survives us pulling in fresh lists from Enhetsregisteret or other sources. You can also write to account@zellap.com, and we'll do it for you.
How long we keep it
If a business hasn't responded to anything we've sent, we delete its information 12 months after the last contact. If the business becomes a customer, the information moves into the customer relationship and follows the retention periods in section 7.
We keep the unsubscribe itself permanently. It's the only way we can guarantee your address won't turn up again the next time we pull data from a public register.
5. Who we share data with
We use a number of sub-processors that handle data on our behalf. We require a data processing agreement with each of them, and they may only process the data for what we've asked:
- Supabase: database and login (stored in the EU)
- Vercel: operations and hosting
- Stripe: billing for your Zellap subscription
- Resend: sending email, both notifications and offers
- Realtime Register: domain registration and renewal
- Cloudflare: security and bot protection
- Anthropic: AI-assisted text and design in the website builder
- Google: anonymous visit statistics on zellap.com and on the websites we run (only with consent), and — where the customer has Managed SEO — Search Console and ownership verification
- OpenRouter: runs the language model behind the Zellie AI assistant in the customer's dashboard
Domain registration
If you register a domain through us, we send the domain holder's information to our registrar, Realtime Register B.V. (Netherlands), which passes it on to the registry for the top-level domain. For .no domains that's Norid. Norid requires the holder to be identified by organisation number, and that the business itself, not Zellap, is listed as the domain holder. This follows from the rules for .no and isn't something we can opt out of.
AI-assisted text and design
If you use the helper functions in the website builder, the text you're working on is sent to Anthropic PBC to generate a suggestion. We send the content you've written yourself, or asked for help with. We don't send customer lists, bookings, or payment data there. The content isn't used to train models.
The Zellie AI assistant
Zellie is an AI assistant in the admin panel. If you use it, your question and a redacted snapshot of your panel are sent to OpenRouter, which runs the language model for us. The snapshot contains which pages and features you have, your services and prices, opening hours, and figures in aggregate form.
Information about your own customers is never sent without consent. Names, emails, phone numbers, notes, and message content about your customers stay on your own website unless that individual customer has consented to Zellie seeing them. Without consent, Zellie only sees aggregate figures and opaque references, such as "3 bookings on Thursday." This redaction happens on your own website, before anything is sent onward. The default is that consent hasn't been given, and consent can be withdrawn at any time.
The content isn't used to train or improve models. Training on the data we submit is turned off on our OpenRouter account.
Your conversation with Zellie is stored in your own database, so you can see what was asked and what was confirmed, and it's deleted after 90 days. We also measure how much Zellie is used, to run the feature and enforce the usage limit. This measurement contains the time, the model, and the usage — not the content of the conversation.
If you don't want to use Zellie, simply don't write to it. If you want the feature turned off for your business, or the conversation log deleted, write to account@zellap.com.
Payment
Payment is handled by two different providers, depending on who the seller is.
Your own subscription with Zellap is paid through Stripe. There, Zellap is the seller. Stripe processes the card details and the payment transaction itself. Your card number never reaches Zellap and isn't stored with us. We store the payment reference, amount, currency, status, and the link to the purchase.
Payments from your own customers go through Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, the Netherlands, or through Stripe, depending on which provider your account is set up with. Mollie is a payment institution supervised by the Dutch central bank, De Nederlandsche Bank. This only applies if you connect your own account with one of them. In that case you're the seller, and we send the provider your name, email, company name, and organisation number as part of the connection.
The provider processes card details and the payment transaction itself on its own responsibility, under the rules that apply to payment institutions. Your customer's card number never reaches Zellap. We store the payment reference, amount, currency, status, and the link to the order.
Which payment methods your customer can choose depends on the provider. Through Mollie, Vipps and Riverty are offered alongside cards, among others; through Stripe, card payment is offered. If your customer chooses one of these payment methods, the provider of that payment method also processes the payment information on its own responsibility. Vipps requires you to have your own agreement with Vipps MobilePay before it can be enabled in your checkout.
We never sell personal data, and we don't share it for marketing purposes with third parties.
6. Storage outside the EEA
Our starting point is that personal data is stored in the EU/EEA. Your database, login, and websites are located in the EU.
Two providers process data outside the EEA. Anthropic (USA) processes the text you submit to the AI-assisted features. Google Analytics (USA) processes the anonymous usage statistics, and only if you've consented. Both transfers rely on the European Commission's Standard Contractual Clauses (SCCs).
If you use the Zellie AI assistant, OpenRouter may process the information outside the EEA. We require a valid transfer basis, such as the European Commission's Standard Contractual Clauses (SCCs), before the feature goes live.
7. How long we store data
- Account information: for as long as you have an account, deleted within 30 days of the account being closed.
- Invoice and payment data: 5 years, as required by the Norwegian Bookkeeping Act.
- Enquiries: for as long as needed to follow up the matter.
- Marketing prospect data: 12 months after the last contact if the business hasn't responded.
- Unsubscribes: permanently, so the block actually holds.
- Zellie AI assistant conversation log: 90 days.
- Technical logs: in line with each provider's standard retention period.
8. Your rights
You have the right to:
- access the information we hold about you,
- have errors corrected,
- have information deleted (except what we must retain by law),
- request restriction of, or object to, processing,
- receive your data in a machine-readable format,
- withdraw consent at any time.
The right to object to marketing
If you receive marketing from us, you can object to it. This is an unconditional right: you don't need a reason, and we can't weigh it against our own interests. If you say no, we stop.
Use the unsubscribe link at the bottom of the email, or write to account@zellap.com. The address is blocked permanently, and the block is checked before every send. If you want to know what we've stored about your business, or have it corrected or deleted, use the same address.
Send a request to account@zellap.com, and we'll normally reply within one month. If you believe we're processing data incorrectly, you can complain to Datatilsynet.
9. Changes
We update this policy when the service or the regulations change. For material changes, we ask for consent again where that's required.
Every version of this policy has a version number and a date, and we keep the old ones. In the changelog you can see which versions have applied, when they took effect, and what changed in each of them. The same goes for the cookie policy, the terms, and the data processing agreement.