Last updated: August 16, 2026
Privacy Policy
This Privacy Policy explains what information Keepit collects, how we use it, and how users can control or delete their data.
1. Who We Are
Keepit is a SaaS platform operated by ZAF VENTURES SDN BHD. The platform helps businesses manage customers, products, quotations, proformas, invoices, payments, expenses, WhatsApp workflows, AI Workforce features, and Meta Ads workflows.
2. Information We Collect
We may collect and process the following information when you use Keepit:
- Account and workspace information, such as name, email, company name, staff roles, permissions, and subscription details.
- Business records entered into the system, including customers, suppliers, products, quotations, proformas, invoices, payments, expenses, production jobs, and uploaded files.
- Communication data connected by your workspace, such as WhatsApp messages, Telegram messages, email intake documents, and related media when integrations are enabled.
- AI Workforce data, including prompts, replies, tool actions, approvals, automation logs, token usage, and performance records.
- Meta Ads data when connected, including Meta App ID, encrypted App Secret, encrypted access tokens, Ad Account IDs, Pages, Instagram accounts, WhatsApp destinations, campaign drafts, campaign results, insights, and attribution signals.
- Technical data such as IP address, browser type, device information, logs, diagnostics, and security events.
3. How We Use Information
We use information to:
- Provide, operate, secure, and improve the Keepit platform.
- Generate and manage business documents, reports, approvals, reminders, and operational workflows.
- Process connected WhatsApp, Telegram, email, payment, AI, and Meta Ads features requested by your workspace.
- Support AI-assisted workflows, including business summaries, draft documents, customer follow-up, finance review, marketing plans, and ad recommendations.
- Maintain audit logs, prevent abuse, troubleshoot errors, and enforce permissions.
- Manage subscriptions, billing, customer support, and service communications.
4. AI Processing
If your workspace enables AI features, selected business context may be sent to the AI provider configured by your workspace to generate replies, summaries, drafts, or tool instructions. Keepit aims to send only the information needed for the requested task. API keys, secrets, and encrypted credentials are not intentionally included in prompts.
AI output may be inaccurate and should be reviewed before important decisions. Actions that affect external customers, payments, publishing, or sensitive records may require human approval depending on workspace policy.
5. Meta Platform Data
When you connect a Meta App, Keepit uses Meta Platform Data only to provide the requested Meta Ads features, such as creating drafts, reading account details, preparing campaigns, publishing approved campaigns, syncing insights, and measuring sales outcomes. We do not sell Meta Platform Data.
You remain responsible for ensuring that your Meta App, Ad Account, Page, Pixel, WhatsApp Business assets, permissions, consent notices, and advertising content comply with Meta policies and applicable law.
6. Google API Services Data
When a workspace owner connects Google Drive, Keepit requests basic account identity and per-file Google Drive access. These permissions let Keepit identify the connected account and create and manage only the production folders and files created or explicitly used through Keepit. Keepit does not request access to enumerate unrelated Drive metadata and does not request Google Sheets access.
Keepit does not sell Google user data, use it for advertising, or allow humans to read it except when necessary for security, legal compliance, user-requested support, or with the user's explicit permission. Google user data is used only to provide or improve the user-facing integration and is not transferred for unrelated purposes.
Keepit's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. OAuth access and refresh tokens are protected with access controls and encrypted storage where supported. Users can disconnect Google Drive in Keepit settings or revoke access from their Google Account at any time.
7. Sharing With Service Providers
We may share information with service providers that help operate Keepit, such as hosting, storage, payment processing, email delivery, logging, analytics, AI providers, communication platforms, and Meta integration services. These providers process information only for the services we request from them.
8. Data Retention
We keep information for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, and maintain backups. Workspace owners may request deletion or export of their data subject to legal, accounting, security, and backup retention requirements.
9. Security
We use reasonable technical and organizational safeguards, including access controls, tenant isolation, audit logs, encrypted secrets where supported, and restricted permissions. No online service can guarantee absolute security, so users should protect their passwords, devices, and connected third-party accounts.
10. Your Choices
You may update account information, disconnect integrations, revoke third-party tokens, manage staff permissions, request export, or request deletion. For data requests, contact us at [email protected].
11. Changes To This Policy
We may update this Privacy Policy from time to time. The latest version will be posted on this page with the updated date.