Privacy policy

Covers the eve & ai workplace platform, the Kai personal app, our websites and our professional services. Last updated 16 August 2026.

The short version. What you tell ai, write in your journal, or discuss with a therapist is yours. Your employer never sees it. They see anonymous, aggregated patterns across groups large enough that nobody can be identified. You can ask us to delete your data at any time, and we do it within seven days.

1. Who we are

eve & ai is operated by the Zoala group. In this policy, "we", "us" and "our" mean the eve & ai entity contracting with you or your employer. We are the data controller for personal data processed through our services, except where we act as a data processor on an employer's instructions, which we explain in section 5.

For any privacy question, or to exercise a right described here, write to hello@eveand.ai. We aim to answer within seven days.

2. The services this policy covers

  • eve & ai workplace platform, provided to employees through an employer: ai the AI companion, eve for human therapy on chat, mood check-ins, journaling, self guided programmes, Run My Day, Flip-to-Win, therapist booking and counselling sessions.
  • Kai, our personal app for individuals, whether on the free tier, a paid tier, or a place subsidised by an Employer Partner.
  • Professional services: workshops, training, coaching, and psychosocial risk assessments including PRisMA assessments in Malaysia.
  • Our websites, including eveand.ai, and enquiry forms and tools such as the PRisMA readiness check.

3. What we collect

CategoryExamplesWhere it comes from
Account dataName or nickname, email or mobile number, language, employer code, countryYou, or your employer at onboarding
Wellbeing contentConversations with ai, journal entries, mood check-ins, assessment responses, goalsYou, as you use the app
Care recordsSession bookings, therapist notes, care plans, risk escalationsYou and your therapist
Usage dataFeature use, session counts, device type, app version, approximate regionAutomatically, as you use the service
Assessment dataPsychosocial screening responses tied to a work unit, not a nameEmployees during a PRisMA or similar assessment
Business contact dataName, work email, company, role, enquiry detailsEmployer representatives, website forms

We do not collect payment card details directly; payments are handled by our payment providers. We do not buy personal data from data brokers, and we do not use tracking that follows you across other websites for advertising.

4. Sensitive personal data

Information about mental health is sensitive personal data. We collect it only to provide care to you, we process it on the basis of your explicit consent (and, where a clinician is involved, for the provision of health care under professional confidentiality), and we apply the strictest handling controls we operate. You may withdraw consent at any time, which ends the service for you and triggers deletion under section 10.

5. How we use it, and our legal bases

  • To provide the service (performance of contract, and consent for sensitive data): running ai, storing your journal, booking and delivering sessions, personalising content, and reminding you about things you asked to be reminded about.
  • To keep people safe (vital interests, and consent): detecting indications of risk of harm, escalating to a human care team member, and showing verified crisis resources for your country.
  • To report to employers in aggregate (legitimate interests, subject to the limits in section 6): producing anonymised engagement and wellbeing insights.
  • To improve the service (legitimate interests): understanding which features help, fixing problems, and improving safety. This uses aggregated or de-identified data.
  • To meet legal duties (legal obligation): keeping records required by law, including PRisMA assessment records retained for seven years at work unit level.
  • To run our business (legitimate interests): responding to enquiries, contracting, invoicing and security.

We do not train third party AI models on your conversations, and we do not sell personal data. AI features use your content only to serve you within your own session and care context.

6. What your employer can and cannot see

This is the question employees ask most, so the answer is explicit.

Your employer seesYour employer never sees
Engagement and usage rates for groups and departmentsWhether you personally registered, logged in, or used anything
Aggregated mood and wellbeing trends over timeYour mood entries, scores, journal or history
Themes across the workforce, such as workload or sleepThe content of any conversation with ai or a therapist
Total counselling credits usedWho booked a session, or that you did
Assessment results at work unit levelAny individual's questionnaire answers

No result is reported for any group too small to protect anonymity. If a department or work unit falls below our minimum group size, its data is merged into a larger unit or withheld entirely.

Kai is different and simpler: no employer receives any individual data at all. An Employer Partner sees only how many redemption places have been taken up in total, never who took them.

Where an employer instructs us to run an assessment, we act as a data processor for the resulting work unit level records, and as controller for the individual responses that we never disclose to them.

7. When we share data, and with whom

  • Care providers. Therapists and counsellors in our care network see what you share with them, and only for your care.
  • Service providers. Cloud hosting, communications and analytics vendors acting on our instructions under written contracts, with no right to use your data for their own purposes.
  • Crisis and emergency situations. Where there is a serious and imminent risk to life, we may contact emergency services or a nominated contact. We tell you this before you use the service, and it is the only situation in which individual content may leave our care team without your instruction.
  • Legal requirements. Where we are compelled by a valid legal order.
  • Corporate transactions. If our business is reorganised, data may transfer under equivalent protections and we will notify you.

We do not share individual data with your employer, your insurer, or advertisers.

8. Where data is stored and transferred

Personal data is stored on cloud infrastructure hosted in the Asia Pacific region, encrypted in transit and at rest. Some service providers may process data in other countries; where they do, we rely on appropriate safeguards such as standard contractual clauses and equivalent protection commitments.

9. How long we keep it

DataRetention
Account and wellbeing contentWhile your account is active, then deleted within 30 days of closure unless you ask sooner
Care recordsAs required by professional and clinical record keeping standards, then deleted
Aggregated, anonymised insightsRetained indefinitely; these contain no personal data
Assessment records (work unit level)Seven years, where the applicable guideline requires it
Business contact and contract recordsFor the contract term plus the period required by tax and company law

10. Your rights, and how to use them

Depending on where you live, you have rights to access your data, correct it, delete it, restrict or object to processing, withdraw consent, and receive a copy in a portable format. Under Malaysia's Personal Data Protection Act 2010 and Singapore's Personal Data Protection Act 2012 you have access and correction rights; under the GDPR you have the fuller set listed above. We apply the same core rights to everyone, wherever you are.

To use any of them, write to hello@eveand.ai from any address, or use the in app request. Deletion requests are completed within seven days. Your employer cannot make or block these requests on your behalf.

11. Children

eve & ai and Kai are for adults aged 18 and over. We do not knowingly collect data from children through these services. Our sister platform Zoala serves schools under separate terms and consent arrangements.

12. Security

We apply encryption in transit and at rest, role based access control, least privilege for our own staff, audit logging, background checked and credential verified care providers, and regular review of our controls. No system is perfectly secure, but we treat this data as the most sensitive we handle. If a breach affects you, we will notify you and the relevant regulator as required by law.

13. Cookies and our websites

Our website uses only what is needed to serve pages and understand aggregate traffic. We do not use advertising trackers or sell website data. Tools such as the PRisMA readiness check keep your answers to produce your result, and we delete them on request within seven days.

14. Changes to this policy

If we make a material change, we will tell you in the app or by email before it takes effect. The date at the top of this page always shows the current version.

15. Contact and complaints

Write to hello@eveand.ai. If you are not satisfied with our response, you may complain to your data protection authority: the Personal Data Protection Commissioner in Malaysia, the Personal Data Protection Commission in Singapore, or your local supervisory authority elsewhere.