Skip to content

Privacy Policy

Counso AI is an AI workspace for individuals and teams to work with AI models, create and use agents, connect knowledge and business tools, and carry out supported workflows. This Privacy Policy explains how ZERO BYTE LABS PTE. LTD., the operator of Counso AI ("Counso AI", "we", "us", or "our"), handles personal data in connection with counso.ai, app.counso.ai, and the Counso AI applications, APIs and related services that link to this Policy (the "Services").

Counso AI is our product name. ZERO BYTE LABS PTE. LTD. is the Singapore company responsible for operating the Services. This Policy does not automatically apply to other products operated under a different notice.

We determine how personal data is used to administer accounts, manage our customer relationship, provide support, protect the Services and meet our legal obligations. For these activities, we act as an organization responsible for personal data under applicable law, or as a controller where that term applies.

When a business customer provides personal data through its documents, conversations, connected systems or workflows, we generally process that data on the customer's behalf to provide the Services and follow its documented instructions. In that context, the customer determines the purpose of processing and we act as a data intermediary or processor, as applicable. A service firm may itself be processing data for its clients; the contractual allocation of responsibilities must reflect that relationship.

If you use an organization-managed workspace, your organization controls its membership, permitted uses, integrations and sharing arrangements. Contact its administrator about information it controls. Your organization is responsible for providing relevant notices and establishing a lawful basis for the personal data it provides.

Account and contact information. We collect information you or your organization provide when registering, inviting users, managing an account or contacting us. Depending on the login method and features used, this may include your name, email address, telephone number, profile information, organization, role, account identifiers and authentication records. A sign-in provider may supply the profile information and identifiers you authorize it to share.

Workspace content. We process prompts, messages, uploaded files, connected documents, knowledge sources, agent instructions, workflow settings, generated outputs and related metadata. These materials may contain personal data about you, your colleagues, customers or other people. The information processed depends on what you submit, connect or ask an agent to use.

"Private Workspace Content" means prompts, conversations, uploaded or connected materials, agent instructions, workflow configurations, generated outputs and related metadata processed in your workspace.

Connected-service information. When you or an authorized administrator enable an integration, we process the permissions, account identifiers, authorization credentials, selected content and action results needed for that integration. Credentials are used to establish and maintain the authorized connection. Do not put passwords, access tokens or other secrets into ordinary conversation content when a designated connection method is available.

Usage and technical information. We collect service activity and operational information, such as IP addresses, browser and device details, sign-in events, feature usage, model and tool usage, timestamps, errors, security events and consumption records. Operational records may include personal data associated with a request or an action. They are subject to this Policy rather than being presumed anonymous.

Billing and communications. If you purchase a paid service, we process billing contacts, invoice details, subscription information, transaction references and payment status. Payment providers process the payment information required by their payment methods. We also process support requests, feedback and other communications you send us.

You can choose which optional information to provide. If information is needed to create an account, authenticate access, fulfill a request or meet a legal requirement, we may be unable to provide the related feature without it.

We use personal data to provide the Services you request, including managing accounts and workspaces, retrieving relevant knowledge, routing requests to selected models, generating responses, running authorized tools and retaining the work needed for ongoing tasks.

We also use it to manage subscriptions and invoices, answer support requests, diagnose failures, prevent fraud and misuse, enforce permissions and agreements, investigate security incidents, and comply with legal obligations. To understand and improve the operation of the Services, we use operational and usage information, with aggregated or de-identified information where practical. General service improvement does not authorize the use of Private Workspace Content for unrelated advertising or model training.

We may send essential service, security, billing and policy notices. Where permitted by law, we may also send information about our products or events. You can opt out of promotional messages using their unsubscribe mechanism or by contacting us. Opting out does not stop essential service notices.

Where Singapore's Personal Data Protection Act 2012 ("PDPA") applies, we collect, use and disclose personal data with consent or under an applicable exception, and for purposes notified to you. You may withdraw consent with reasonable notice by contacting us using the details in Section 14. We will explain the likely consequences, including any Services we can no longer provide. We will cease the collection, use or disclosure covered by your withdrawal, and cause our data intermediaries and agents to do so, unless it is required or permitted without consent under applicable law.

To answer a request, the Services may combine your instructions with selected files, prior conversation context, retrieved knowledge and tool results. Relevant information is transmitted to the model and service providers involved in completing that request. Model choice and workspace configuration affect which providers receive information and where processing occurs.

A connected tool may read information from, or send information to, an external system. For example, an authorized workflow may retrieve a customer record or create a document in a connected application. The external service receives the information needed for that action and handles it under its own terms and privacy arrangements. Disconnecting an integration stops future access through that connection but does not, by itself, remove copies or actions already created in either system. Deletion requests and third-party records may require separate steps.

Content may be available to authorized workspace members, administrators or other recipients according to the feature, role and sharing settings in use. Administrators may manage accounts, access settings and activity records to the extent the Services provide those capabilities. Do not assume that a document's original permissions automatically carry over when it is copied, synchronized or shared into a workspace; review the integration and destination access settings.

We may access content where necessary to provide requested support, resolve an operational issue, investigate suspected abuse or security incidents, or comply with law. Access is limited to authorized people with a relevant purpose and appropriate confidentiality obligations. An AI-generated response can contain errors or personal data from the sources used, so review it before sharing or relying on it.

We do not use Private Workspace Content to train general-purpose AI models, and we do not authorize our contracted model providers to do so, unless you give separate, express authorization for a specified training use. Sharing or publishing the content does not constitute that authorization. Before seeking that authorization, we will explain the proposed use, the content involved, the recipients and how to manage your choice.

Retrieval, indexing, embedding generation, maintaining task context and generating an answer are processing activities needed to provide a requested service; they do not, by themselves, mean that content is used to train a general-purpose model. Providers may retain information for operational, security or legal purposes, depending on the provider and the service configuration.

If you independently connect a third-party service or use your own provider account, the provider's handling of information is also governed by the arrangements you or your organization have with it. Review those arrangements before enabling the connection.

Service providers. We use providers for functions such as hosting, storage, AI inference, authentication, service communications, operational monitoring, support and payment processing. They receive information relevant to their function and must handle it under applicable contractual and legal requirements. Providers engaged to process customer personal data on our behalf are subprocessors where that term applies. Contact us for information about the providers and processing locations relevant to your deployment.

Your organization and chosen recipients. We disclose information to authorized users and administrators as described above, and to connected applications or other recipients when you or your organization instruct us to do so, including through enabled workflows and sharing features.

Professional advisers and legal requirements. We may disclose information to advisers who need it for a legitimate professional purpose, or where reasonably necessary to comply with law or valid legal process, protect people and systems, or establish, exercise or defend legal rights. Where permitted, we will seek to limit legally compelled disclosure to what is required.

Business changes. Personal data may be disclosed in connection with a proposed or completed merger, financing, reorganization or transfer of a business, subject to appropriate confidentiality and data protection arrangements. A successor must handle the information consistently with applicable law and the relevant notice or agreement.

We do not sell personal data or share it for cross-context behavioral advertising. We do not give another customer access to Private Workspace Content for its independent use unless you or your organization direct that sharing.

Your personal data may be processed outside the country where you live, depending on the hosting arrangement, selected models, integrations and providers used.

We handle international transfers of personal data in accordance with applicable law. When we transfer personal data outside Singapore under the PDPA, we take appropriate steps to ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection at least comparable to that under the PDPA, such as through appropriate contractual obligations, or use another transfer mechanism permitted by the PDPA. You can contact us for information about the processing locations and safeguards relevant to your data.

Deployment-specific requirements for hosting location, private deployment or model routing are addressed in the terms agreed for that deployment.

We retain personal data only for as long as needed for the purpose for which it is processed, including providing the Services, maintaining security, keeping necessary business records and meeting legal obligations. Relevant factors include the account's status, workspace instructions, the sensitivity of the information, the need to resolve a dispute and applicable retention requirements.

Workspace content is retained and deleted in accordance with the customer's instructions, the available settings and the applicable agreement. You or your administrator can request deletion through the available controls or by contacting us. Closing your individual account may not delete content controlled by your organization or copies shared with other recipients.

Deletion from active systems may not immediately remove residual copies in backups or disaster-recovery systems. Those copies remain protected and are removed or overwritten according to the applicable backup cycle. Where information must be retained for law, security or a dispute, we restrict further use to the relevant purpose. Disconnecting a data source and deleting its imported content are separate operations unless the feature expressly states otherwise.

The Services use cookies or similar storage for functions such as keeping you signed in, securing sessions and remembering settings. Where optional analytics or marketing technologies are used, we provide the notices and consent choices required by applicable law before deploying them.

You can manage browser storage through your browser settings and use any cookie controls offered by the Services. Blocking essential storage may prevent sign-in or other features from working. You can use the core service without accepting optional tracking.

We maintain reasonable technical and organizational safeguards appropriate to the personal data and the processing risks. The measures relevant to a particular enterprise deployment may also be set out in its agreement. No online system can guarantee absolute security.

You and your organization should protect credentials, review access and sharing settings, remove access that is no longer needed and promptly report suspected compromise.

If we have reason to believe that a personal data breach has occurred in relation to personal data we process on a customer's behalf, we will notify that customer without undue delay and provide reasonable assistance with its assessment and response. For personal data for which we are responsible as an organization, we assess the breach and make the notifications required by applicable law. Where notification to Singapore's Personal Data Protection Commission is required, we notify it as soon as practicable and no later than three calendar days after the day we determine that the breach is notifiable. We notify affected individuals where required by law and honor applicable contractual notification obligations.

Under the PDPA, you may request access to personal data about you in our possession or control and information about how it has been or may have been used or disclosed in the year preceding your request. You may also request correction of errors or omissions and withdraw consent as described in Section 3. These rights are subject to applicable conditions and exceptions. You may request deletion as described in Section 8, and other applicable laws may provide additional privacy rights.

We make reasonable efforts to ensure that personal data collected by us or on our behalf is accurate and complete where it is likely to be used to make a decision affecting an individual or disclosed to another organization. Please keep your account information current and tell us about errors. When processing data on a customer's behalf, we assist the customer with corrections in accordance with its instructions and our agreement.

For information we control, send your request to the contact in Section 14. We may need proportionate information to verify your identity and authority. We handle access requests as soon as reasonably possible and correction requests as soon as practicable. If we cannot respond to an access or correction request under the PDPA within 30 days after receiving it, we will inform you in writing within that period of when we will respond. We explain any permitted refusal or limitation. Where information is controlled by your organization, we may direct your request to it or assist it under our agreement.

You may also complain to the relevant data protection authority, including Singapore's Personal Data Protection Commission where applicable. Contacting us first can help resolve a concern but does not remove your right to complain.

Customers who configure automated workflows remain responsible for the lawful use of those workflows and appropriate human review. If a proposed use involves a decision with legal or similarly significant effects on a person, the customer must ensure that the relevant legal requirements and safeguards are met.

The Services are intended for adults using AI for work and related professional activities. They are not directed to children under 18. If you believe a child has provided personal data to us without appropriate authority, contact us so we can investigate and take appropriate action.

We may update this Policy as the Services or our processing practices change. We will publish the revised version and its effective date, and give additional notice of material changes where appropriate or required by law. If a new use requires consent, we will request it; continued use alone does not replace consent where the law requires it.

Counso AI — Privacy enquiries and complaints

Operator: ZERO BYTE LABS PTE. LTD.

UEN: 202211433Z

Email: sales@counso.ai

Contact address: 71 Robinson Road #15-148, Singapore 068895

For privacy questions, complaints or requests to exercise your privacy rights, contact us using the details above. Please use the subject line "Counso AI — Privacy" and describe your request without including unnecessary sensitive information.