Overview
This Policy describes how TLJ Tech Systems and Development, LLC handles information in connection with the Zelo Dev application. The Application is installed in your Bitrix24 account and offers a conversation with an artificial intelligence agent that proposes a structure plan for the CRM and, after a user reviews and confirms it, creates that structure in the account: deal pipelines, smart processes, stages and custom fields.
You — the owner of the Bitrix24 account — are the controller of the account data. TLJ Apps acts as a processor: it handles information on your behalf, to carry out what you asked for in the Application.
Data the Application Processes
| Data | Purpose | Retention |
|---|---|---|
| CRM structure: names of pipelines, stages, smart processes and fields of deals, leads, contacts and companies | Know what already exists, so the plan duplicates nothing and fits what the account already has | Cached for a few minutes. Does not include CRM records |
| Messages you write in the conversation with Zelo | Understand the request and draft the plan | Kept in your browser for the session. Not stored on our servers |
| Creation history: the plan that was run, the identifiers of what was created, the date and the name of whoever ran it | Show what was done and allow it to be undone | 90 days |
| User opening the Application: identifier, name and whether they are an account administrator | Confirm identity against the account and apply usage permission | The user link is kept for as long as the Application is installed |
| Bitrix24 access and refresh tokens | Read the account's structure | For as long as the Application is installed |
| Account domain, member_id, license status and daily message count | Identify the installation, control access and apply the usage limit | For as long as the Application is installed; the daily count is discarded after 2 days |
Artificial Intelligence
The conversation is answered by a language model run on Cloudflare's infrastructure (Workers AI). With each message, the Application sends the model the conversation text and the list of what already exists in your CRM structure — names of pipelines, stages, processes and fields.
- Your CRM records (deals, leads, contacts and companies) are neither read nor sent to the model.
- According to Cloudflare's documentation, content sent to Workers AI is not used to train models or to improve Cloudflare or third-party services.
- Avoid writing personal or confidential data in the conversation: it is not needed to describe the structure you want.
- The plan is a proposal produced by a statistical model, which can be wrong. Nothing is created in the account before a user reviews and confirms it.
What the Application Writes to Your Bitrix24
- Deal pipelines, smart processes, pipelines and stages inside processes, stages in existing pipelines and custom fields — only those in the confirmed plan.
- Creation runs with the permission of the user who confirmed: anyone who cannot create pipelines or fields in Bitrix24 cannot create them through the Application either.
- When a creation is undone, the Application deletes from the account the items it created in that run.
- The Application does not create or change customer records, does not send messages and does not create automations: for those, it only describes the steps.
What We Do Not Do
- We do not read or copy your customers' records.
- We do not sell, rent or transfer data to third parties.
- We do not use your information for advertising or to train models.
- We do not use tracking cookies or third-party pixels in the Application screens.
Where Data Lives
The Application runs on Cloudflare's network (Cloudflare Workers), which also holds the tokens, the cache and the creation history. The organization record and the user links live in a PostgreSQL database managed by Supabase. Traffic is always encrypted in transit (HTTPS/TLS).
Third-Party Services
- Bitrix24: source of the structure read and destination of what is created.
- Cloudflare: hosting, storage and artificial intelligence inference (Workers AI).
- Supabase: database for the organization and user records.
Your Rights
For what is under our custody — tokens, creation history and user links — you may request access or deletion at any time at contato@tlj.net.br. The Brazilian LGPD (Law 13.709/2018) and, where applicable, the GDPR apply.
Data Deletion
Uninstalling the Application from your Bitrix24 account invalidates the tokens immediately. To also erase the history and the records we hold, write to our contact — we respond within 30 days. The structures the Application created remain in your account, under your control.
Security
All calls use HTTPS. Every request made from the Application screen is checked against your Bitrix24 account before any response. The plan is validated against the account's current structure at execution time, and creation uses the permission of the very user who confirmed. Tokens are kept in restricted storage, reachable only by the Application.
Changes to This Policy
We may update this Policy to reflect changes in the Application or in applicable law. The update date at the top of this page indicates the current version.
Contact
Privacy questions: contato@tlj.net.br — TLJ Tech Systems and Development, LLC.
