1. Overview & Scope
This policy applies to MedZoa (medex.base44.app) — the personal health assistant platform for patients, families, and healthcare providers — and to this public website.
MedZoa is operated in India by Zoa Zone Services Pvt Ltd, 376, G3, Road No 82, Film Nagar, Jubilee Hills, Hyderabad, Telangana 500096, India. Global operations for customers outside India are handled by Zoa Zone Services LLC, 1770 Grand Concourse 12A, Bronx, NY 10457, USA. The data controller for your account is the entity you contracted with at sign-up (see our Terms & Conditions).
This policy applies to all visitors, registered users, and business account holders who interact with MedZoa. By creating an account or using the service, you agree to this policy.
2. Data We Collect
We collect the minimum data necessary to operate our services. Here's what we collect and why:
2.1 Account & Identity Data
| Data / Field | Purpose | Legal Basis |
|---|---|---|
| Full Name | Account creation, service personalization | Contract performance |
| Email Address | Account alerts, OTPs, billing receipts, login | Contract + Legitimate interest |
| Phone Number | SMS OTPs, account security, WhatsApp alerts | Consent + Contract |
| Company Name | Business account features, invoicing | Contract performance |
| Payment Information | Billing — processed by Cashfree Payments for Indian customers (INR); we never store card, UPI or bank credentials | Contract performance |
2.2 Platform Usage Data
| Data / Field | Purpose | Legal Basis |
|---|---|---|
| Call Transcripts & Recordings | AI training, quality review, compliance | Legitimate interest + Consent |
| Agent Configuration | Service delivery | Contract performance |
| Knowledge Base Content | AI voice agent responses | Contract performance |
| Login & Session Logs | Security, fraud detection | Legitimate interest |
| IP Address & Device Info | Security, geo-compliance | Legitimate interest |
2.3 Communications Data
| Data / Field | Purpose | Legal Basis |
|---|---|---|
| Messages sent/received via SMS | Delivery confirmation, compliance logging | Consent + Legal obligation |
| WhatsApp message logs | Support, compliance | Consent |
| Email open/click data | Service improvement (opt-out available) | Legitimate interest |
2.4 Health Data (MedZoa only)
⚕️ Health-related data processed through MedZoa is treated as PHI (Protected Health Information) under HIPAA. See Section 10 for full details.
3. Messaging Consent — SMS, WhatsApp & Email
3.1 How We Collect Consent
- ✓At account registration, via clearly labeled checkboxes for each communication channel (SMS, WhatsApp, Email).
- ✓Consent is not pre-checked and is not a condition of using core services.
- ✓Transactional messages (OTPs, billing alerts, security notices) require consent as part of service enrollment.
- ✓Marketing messages require separate, explicit opt-in.
- ✓We log the timestamp, IP address, and method of consent for every user.
3.2 Types of Messages We Send
🔐 Transactional / Account
- • One-time passcodes (OTP)
- • Login verification codes
- • Password reset links
- • Billing receipts & invoices
- • Payment confirmations
- • Subscription renewal reminders
- • Account suspension notices
- • Security alerts (unusual login, etc.)
⚙️ Service & Operations
- • Agent status updates
- • Call completion summaries
- • System outage notifications
- • Feature update announcements
- • Usage limit alerts
- • Support ticket updates
📢 Marketing (Opt-in Only)
- • New feature releases
- • Promotional offers
- • Partner announcements
- • Webinar & event invites
- • Monthly newsletters
🚫 We Will NEVER Send
- • Unsolicited cold messages
- • Third-party advertising without consent
- • Messages after opt-out
- • Misleading sender information
- • Affiliate spam
3.3 How to Opt Out
📵 SMS
Reply "STOP" to any message
You will receive one final confirmation. No further messages.
Message 'STOP' or go to Settings → Notifications
Opt-out processed within 24 hours.
Click "Unsubscribe" in any email footer
Mandatory transactional emails continue.
You may also manage all notification preferences in your account Settings → Notifications, or by emailing care@zoazoneservices.com.
4. A2P 10DLC & TCPA Compliance
MedZoa sends application-to-person (A2P) SMS messages through registered US carriers in compliance with A2P 10DLC (10-Digit Long Code) regulations enforced by The Campaign Registry (TCR) and US wireless carriers.
4.1 Our A2P Commitments
- ✓ All SMS campaigns are registered with The Campaign Registry (TCR) with declared use cases.
- ✓ We identify our brand name clearly in every message (e.g., 'MedZoa:').
- ✓ Message content is pre-approved and consistent with the registered campaign use case.
- ✓ We maintain a valid opt-out mechanism in EVERY message we send.
- ✓ We do not send messages between 9:00 PM and 8:00 AM local recipient time.
- ✓ We maintain consent records for a minimum of 5 years.
- ✓ We do not share or sell phone numbers to third-party marketers.
4.2 TCPA Compliance
Under the Telephone Consumer Protection Act (TCPA):
- ✓ We obtain prior express written consent before sending marketing SMS messages.
- ✓ We honor STOP requests immediately and keep suppression lists indefinitely.
- ✓ Our AI phone agents identify themselves as automated systems at the start of every call.
- ✓ We do not use auto-dialers to contact individuals who have not consented to receive calls.
- ✓ For healthcare-related calls via MedZoa, we follow additional FCC exemptions and HIPAA guidelines.
4.3 For Business Operators Using MedZoa
- Obtaining valid consent from your customers before initiating AI-assisted calls.
- Registering your own A2P campaigns if you send SMS through our platform.
- Ensuring your agent scripts comply with applicable telemarketing and robocall laws.
- Including disclosures that calls are AI-handled where required by state law (e.g., California AB 302).
5. WhatsApp Business Messaging Policy
MedZoa sends WhatsApp messages through the official WhatsApp Business API (Meta) and complies with WhatsApp's Business Messaging Policy and Commerce Policy.
5.1 WhatsApp Consent Rules
- ✓ You must explicitly opt in to receive WhatsApp messages from MedZoa.
- ✓ Opt-in is collected through our registration form or account settings — never assumed.
- ✓ We clearly state the types of messages you will receive at the time of opt-in.
- ✓ We include our business name in every WhatsApp message.
- ✓ You may opt out at any time by messaging 'STOP' or through your account settings.
- ✓ We do not send promotional WhatsApp messages without a prior opt-in.
- ✓ We only use approved WhatsApp Message Templates for regulated message categories.
5.2 WhatsApp Message Types We Use
| Category | Examples | Consent Required |
|---|---|---|
| Authentication | OTPs, verification codes | Transactional — requires service enrollment |
| Utility | Account alerts, billing receipts, subscription status | Transactional — requires service enrollment |
| Marketing | Promotions, offers, newsletters | Requires explicit marketing opt-in |
MedZoa does not use WhatsApp for spam, bulk cold outreach, or sharing user data with Meta beyond what is required for message delivery.
6. Email Communications Policy
All email communications from MedZoa comply with CAN-SPAM Act (US), CASL (Canada), GDPR (EU), and applicable international email marketing laws.
6.1 CAN-SPAM Compliance
- ✓ Every email clearly identifies Zoa Zone Services Pvt Ltd as the sender.
- ✓ Subject lines are never deceptive or misleading.
- ✓ Every marketing email includes a physical postal address.
- ✓ Every marketing email includes a clear, working unsubscribe link.
- ✓ Unsubscribe requests are honored within 10 business days.
- ✓ We do not use purchased email lists.
6.2 Transactional vs. Marketing Emails
Transactional emails (OTPs, billing receipts, security alerts, account notices) are sent based on your service enrollment. These cannot be fully opted out of while your account is active — they are essential to service delivery and account security.
Marketing emails require a separate opt-in and can be unsubscribed from at any time without affecting your account access.
7. Security Measures
We implement industry-standard security controls to protect your data:
🔒 Encryption
- ✓ TLS 1.2+ for all data in transit
- ✓ AES-256 encryption for data at rest
- ✓ End-to-end encryption for sensitive fields
- ✓ Call recordings encrypted in storage
🛡️ Access Control
- ✓ Role-based access control (RBAC)
- ✓ Multi-factor authentication (MFA) available
- ✓ Session timeout and token rotation
- ✓ Principle of least privilege enforced
🔍 Monitoring
- ✓ 24/7 infrastructure monitoring
- ✓ Anomaly detection & alerting
- ✓ Audit logs for all admin actions
- ✓ Automated threat scanning
📋 Compliance & Audits
- ✓ SOC 2 Type II aligned practices
- ✓ Regular penetration testing
- ✓ Vulnerability disclosure program
- ✓ Incident response plan (< 72hr notification)
🗝️ OTP & Passcode Security
- ✓ OTPs expire in 5 minutes
- ✓ OTPs are single-use only
- ✓ Failed OTP attempts locked after 5 tries
- ✓ OTPs never stored in plain text
🏢 Infrastructure
- ✓ Hosted on SOC 2 certified cloud providers
- ✓ Data residency in US (default)
- ✓ Automated backups with tested recovery
- ✓ No customer data used for AI model training without consent
7.1 Reporting a Security Issue
If you discover a security vulnerability, please report it responsibly to care@zoazoneservices.com. We commit to acknowledging your report within 48 hours and providing a remediation timeline within 7 business days. We do not pursue legal action against good-faith security researchers.
8. Your Privacy Rights
Depending on your location, you have the following rights regarding your personal data:
Right to Access
Request a copy of all personal data we hold about you.
📌 How: Email care@zoazoneservices.com or use Settings → Data Export
Right to Correction
Request correction of inaccurate or incomplete data.
📌 How: Update directly in Settings, or email us
Right to Deletion
Request deletion of your data ('Right to be Forgotten').
📌 How: Settings → Delete Account, or email us
Right to Portability
Receive your data in a machine-readable format.
📌 How: Email care@zoazoneservices.com with your request
Right to Object
Object to processing of your data for marketing purposes.
📌 How: Unsubscribe links in messages or Settings → Notifications
Right to Restrict
Request limitation of how we use your data.
📌 How: Email care@zoazoneservices.com with your request
Opt-Out of Sale (CCPA)
California residents: opt out of sale of personal information.
📌 How: We do not sell personal information. No action needed.
Withdraw Consent
Withdraw any consent given at any time.
📌 How: Settings → Notifications, or reply STOP to messages
We respond to all verified requests within 30 days. Complex requests may be extended by an additional 60 days with notice. Identity verification may be required before processing sensitive requests.
8.1 California Residents (CCPA / CPRA)
California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We do not sell or share personal information for cross-context behavioral advertising. You may submit a request to know, delete, or correct your data by emailing care@zoazoneservices.com.
8.2 EU / UK Residents (GDPR / UK GDPR)
EU and UK residents may lodge a complaint with their local supervisory authority if they believe their data rights have been violated. Our Data Protection Officer can be contacted at care@zoazoneservices.com.
9. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Duration of account + 2 years post-closure | Legal obligation, dispute resolution |
| Call recordings | 90 days (default) — configurable by operator | Quality review, compliance |
| Call transcripts | 12 months | AI improvement, compliance logging |
| Billing & transaction records | 7 years | Tax and accounting obligations |
| SMS / WhatsApp consent logs | 5 years | TCPA / A2P compliance |
| Email consent logs | 5 years | CAN-SPAM / GDPR compliance |
| Security & access logs | 12 months | Security incident investigation |
| OTPs / passcodes | Deleted immediately after use or 5-minute expiry | Security |
| Marketing analytics | 36 months | Service improvement |
| Health data (MedZoa) | Minimum 6 years — see HIPAA section | HIPAA compliance |
Upon account deletion, we anonymize or delete personal data within 30 days, except where retention is required by law. Anonymized, aggregated data may be retained indefinitely for platform analytics.
India — DPDP Act 2023
For users in India, we process personal data in compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act):
- ✓ We collect personal data only for a lawful purpose, with your informed consent or notice, or where processing is necessary for the service you have asked for.
- ✓ We collect only the data that is necessary — data minimisation by design.
- ✓ You may access, correct, complete, or erase your personal data, withdraw consent, and nominate another individual to exercise your rights if you are unable to.
- ✓ We take reasonable security safeguards to prevent personal data breaches and will notify affected users and the Data Protection Board as required by law.
- ✓ We do not process personal data in a manner likely to cause harm to a child, except as permitted by the DPDP Act.
- ✓ Upon request or withdrawal of consent, we cease processing and erase your data unless retention is required by law (see Data Retention above).
Grievance Redressal (India)
Under the IT Rules, 2021, grievances of users in India are handled by our Grievance Officer:
- Designation: Grievance Officer
- Entity: Zoa Zone Services Pvt Ltd, 376, G3, Road No 82, Film Nagar, Jubilee Hills, Hyderabad, Telangana 500096, India
- Email: care@zoazoneservices.com
- Phone: +1 256 699 8899 (Mon–Sat, 10:00–18:00 IST)
- Acknowledgement: within 48 hours
- Resolution: within 15 days of receipt
Data-related requests under the DPDP Act 2023 are honoured through the same contact.
10. HIPAA Compliance — MedZoa
medex.base44.app), where all health data is treated as sensitive and handled per this policy.- ✓ MedZoa enters into a Business Associate Agreement (BAA) with all covered entities using MedZoa.
- ✓ PHI is encrypted at rest (AES-256) and in transit (TLS 1.3).
- ✓ Access to PHI is strictly role-based and logged in immutable audit trails.
- ✓ PHI is never used to train AI models without explicit authorization.
- ✓ Call recording PHI redaction is available and enabled by default for healthcare accounts.
- ✓ Transcript PHI redaction removes names, SSNs, dates of birth, and other identifiers.
- ✓ Data is retained for a minimum of 6 years per HIPAA requirements.
- ✓ Breach notification is provided within 60 days of discovery per HIPAA Breach Notification Rule.
- ✓ De-identification of health data follows the HIPAA Safe Harbor method.
- ✓ HIPAA training is completed by all staff with access to PHI systems.
11. Children's Privacy
MedZoa services are intended for use by businesses and individuals aged 18 and older. We do not knowingly collect personal information from individuals under 18 years of age. If you believe a minor has provided us with personal information, please contact care@zoazoneservices.com and we will delete it promptly.
12. Policy Changes
We may update this policy periodically to reflect changes in our practices, technologies, or legal obligations. When we make material changes, we will:
- • Post the updated policy on this page with a new effective date.
- • Send an email notification to all registered account holders.
- • Display an in-app banner for 30 days after the update.
- • For material changes affecting messaging consent, we will re-collect your explicit consent.
Continued use of our services after the effective date of any updates constitutes acceptance of the revised policy.
13. Contact & Data Requests
📧 General Privacy Inquiries
care@zoazoneservices.com🏛️ Data Protection Officer (EU/UK)
care@zoazoneservices.com🔒 Security Vulnerability Reports
care@zoazoneservices.com📋 CCPA / CPRA Requests
care@zoazoneservices.comWe aim to respond to all inquiries within 5 business days. Data subject requests are handled within 30 days as required by applicable law.
Zoa Zone Services Pvt Ltd · Zoa Zone Services LLC · Last updated: 28 September 2026
Questions? care@zoazoneservices.com