🔒 MedZoa uses your contact details to send account alerts, OTPs, transaction receipts, and service updates. We require your explicit consent per TCPA / A2P 10DLC / GDPR / CCPA rules.

Learn more
Legal & ComplianceGDPR · CCPA · TCPA · A2P 10DLC · HIPAA · CAN-SPAM

Privacy, Security & Consent Policy

This policy governs how Zoa Zone Services Pvt Ltd (India) and Zoa Zone Services LLC (USA) collect, use, store, and protect your data through MedZoa, our personal health assistant platform.

Effective Date: 28 September 2026  |  Last Reviewed: 28 September 2026

1. Overview & Scope

This policy applies to MedZoa (medex.base44.app) — the personal health assistant platform for patients, families, and healthcare providers — and to this public website.

MedZoa is operated in India by Zoa Zone Services Pvt Ltd, 376, G3, Road No 82, Film Nagar, Jubilee Hills, Hyderabad, Telangana 500096, India. Global operations for customers outside India are handled by Zoa Zone Services LLC, 1770 Grand Concourse 12A, Bronx, NY 10457, USA. The data controller for your account is the entity you contracted with at sign-up (see our Terms & Conditions).

This policy applies to all visitors, registered users, and business account holders who interact with MedZoa. By creating an account or using the service, you agree to this policy.

ℹ️Healthcare Providers (Clinics & Hospitals): If you use MedZoa to serve your own patients, you are the data controller/fiduciary for your patients' data. MedZoa acts as a processor on your behalf. You must maintain your own privacy disclosures and ensure your patients consent to messaging and AI-assisted features.

2. Data We Collect

We collect the minimum data necessary to operate our services. Here's what we collect and why:

2.1 Account & Identity Data

Data / FieldPurposeLegal Basis
Full NameAccount creation, service personalizationContract performance
Email AddressAccount alerts, OTPs, billing receipts, loginContract + Legitimate interest
Phone NumberSMS OTPs, account security, WhatsApp alertsConsent + Contract
Company NameBusiness account features, invoicingContract performance
Payment InformationBilling — processed by Cashfree Payments for Indian customers (INR); we never store card, UPI or bank credentialsContract performance

2.2 Platform Usage Data

Data / FieldPurposeLegal Basis
Call Transcripts & RecordingsAI training, quality review, complianceLegitimate interest + Consent
Agent ConfigurationService deliveryContract performance
Knowledge Base ContentAI voice agent responsesContract performance
Login & Session LogsSecurity, fraud detectionLegitimate interest
IP Address & Device InfoSecurity, geo-complianceLegitimate interest

2.3 Communications Data

Data / FieldPurposeLegal Basis
Messages sent/received via SMSDelivery confirmation, compliance loggingConsent + Legal obligation
WhatsApp message logsSupport, complianceConsent
Email open/click dataService improvement (opt-out available)Legitimate interest

2.4 Health Data (MedZoa only)

⚕️ Health-related data processed through MedZoa is treated as PHI (Protected Health Information) under HIPAA. See Section 10 for full details.

4. A2P 10DLC & TCPA Compliance

MedZoa sends application-to-person (A2P) SMS messages through registered US carriers in compliance with A2P 10DLC (10-Digit Long Code) regulations enforced by The Campaign Registry (TCR) and US wireless carriers.

4.1 Our A2P Commitments

  • ✓ All SMS campaigns are registered with The Campaign Registry (TCR) with declared use cases.
  • ✓ We identify our brand name clearly in every message (e.g., 'MedZoa:').
  • ✓ Message content is pre-approved and consistent with the registered campaign use case.
  • ✓ We maintain a valid opt-out mechanism in EVERY message we send.
  • ✓ We do not send messages between 9:00 PM and 8:00 AM local recipient time.
  • ✓ We maintain consent records for a minimum of 5 years.
  • ✓ We do not share or sell phone numbers to third-party marketers.

4.2 TCPA Compliance

Under the Telephone Consumer Protection Act (TCPA):

  • ✓ We obtain prior express written consent before sending marketing SMS messages.
  • ✓ We honor STOP requests immediately and keep suppression lists indefinitely.
  • ✓ Our AI phone agents identify themselves as automated systems at the start of every call.
  • ✓ We do not use auto-dialers to contact individuals who have not consented to receive calls.
  • ✓ For healthcare-related calls via MedZoa, we follow additional FCC exemptions and HIPAA guidelines.

4.3 For Business Operators Using MedZoa

⚠️If you send messages to your own patients through MedZoa, you are legally responsible for:
  • Obtaining valid consent from your customers before initiating AI-assisted calls.
  • Registering your own A2P campaigns if you send SMS through our platform.
  • Ensuring your agent scripts comply with applicable telemarketing and robocall laws.
  • Including disclosures that calls are AI-handled where required by state law (e.g., California AB 302).
MedZoa provides compliance tools (consent toggles, call disclosures) but is not liable for operator misuse.

5. WhatsApp Business Messaging Policy

MedZoa sends WhatsApp messages through the official WhatsApp Business API (Meta) and complies with WhatsApp's Business Messaging Policy and Commerce Policy.

5.1 WhatsApp Consent Rules

  • ✓ You must explicitly opt in to receive WhatsApp messages from MedZoa.
  • ✓ Opt-in is collected through our registration form or account settings — never assumed.
  • ✓ We clearly state the types of messages you will receive at the time of opt-in.
  • ✓ We include our business name in every WhatsApp message.
  • ✓ You may opt out at any time by messaging 'STOP' or through your account settings.
  • ✓ We do not send promotional WhatsApp messages without a prior opt-in.
  • ✓ We only use approved WhatsApp Message Templates for regulated message categories.

5.2 WhatsApp Message Types We Use

CategoryExamplesConsent Required
AuthenticationOTPs, verification codesTransactional — requires service enrollment
UtilityAccount alerts, billing receipts, subscription statusTransactional — requires service enrollment
MarketingPromotions, offers, newslettersRequires explicit marketing opt-in

MedZoa does not use WhatsApp for spam, bulk cold outreach, or sharing user data with Meta beyond what is required for message delivery.

6. Email Communications Policy

All email communications from MedZoa comply with CAN-SPAM Act (US), CASL (Canada), GDPR (EU), and applicable international email marketing laws.

6.1 CAN-SPAM Compliance

  • ✓ Every email clearly identifies Zoa Zone Services Pvt Ltd as the sender.
  • ✓ Subject lines are never deceptive or misleading.
  • ✓ Every marketing email includes a physical postal address.
  • ✓ Every marketing email includes a clear, working unsubscribe link.
  • ✓ Unsubscribe requests are honored within 10 business days.
  • ✓ We do not use purchased email lists.

6.2 Transactional vs. Marketing Emails

Transactional emails (OTPs, billing receipts, security alerts, account notices) are sent based on your service enrollment. These cannot be fully opted out of while your account is active — they are essential to service delivery and account security.

Marketing emails require a separate opt-in and can be unsubscribed from at any time without affecting your account access.

7. Security Measures

We implement industry-standard security controls to protect your data:

🔒 Encryption

  • ✓ TLS 1.2+ for all data in transit
  • ✓ AES-256 encryption for data at rest
  • ✓ End-to-end encryption for sensitive fields
  • ✓ Call recordings encrypted in storage

🛡️ Access Control

  • ✓ Role-based access control (RBAC)
  • ✓ Multi-factor authentication (MFA) available
  • ✓ Session timeout and token rotation
  • ✓ Principle of least privilege enforced

🔍 Monitoring

  • ✓ 24/7 infrastructure monitoring
  • ✓ Anomaly detection & alerting
  • ✓ Audit logs for all admin actions
  • ✓ Automated threat scanning

📋 Compliance & Audits

  • ✓ SOC 2 Type II aligned practices
  • ✓ Regular penetration testing
  • ✓ Vulnerability disclosure program
  • ✓ Incident response plan (< 72hr notification)

🗝️ OTP & Passcode Security

  • ✓ OTPs expire in 5 minutes
  • ✓ OTPs are single-use only
  • ✓ Failed OTP attempts locked after 5 tries
  • ✓ OTPs never stored in plain text

🏢 Infrastructure

  • ✓ Hosted on SOC 2 certified cloud providers
  • ✓ Data residency in US (default)
  • ✓ Automated backups with tested recovery
  • ✓ No customer data used for AI model training without consent

7.1 Reporting a Security Issue

If you discover a security vulnerability, please report it responsibly to care@zoazoneservices.com. We commit to acknowledging your report within 48 hours and providing a remediation timeline within 7 business days. We do not pursue legal action against good-faith security researchers.

8. Your Privacy Rights

Depending on your location, you have the following rights regarding your personal data:

Right to Access

Request a copy of all personal data we hold about you.

📌 How: Email care@zoazoneservices.com or use Settings → Data Export

Right to Correction

Request correction of inaccurate or incomplete data.

📌 How: Update directly in Settings, or email us

Right to Deletion

Request deletion of your data ('Right to be Forgotten').

📌 How: Settings → Delete Account, or email us

Right to Portability

Receive your data in a machine-readable format.

📌 How: Email care@zoazoneservices.com with your request

Right to Object

Object to processing of your data for marketing purposes.

📌 How: Unsubscribe links in messages or Settings → Notifications

Right to Restrict

Request limitation of how we use your data.

📌 How: Email care@zoazoneservices.com with your request

Opt-Out of Sale (CCPA)

California residents: opt out of sale of personal information.

📌 How: We do not sell personal information. No action needed.

Withdraw Consent

Withdraw any consent given at any time.

📌 How: Settings → Notifications, or reply STOP to messages

We respond to all verified requests within 30 days. Complex requests may be extended by an additional 60 days with notice. Identity verification may be required before processing sensitive requests.

8.1 California Residents (CCPA / CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We do not sell or share personal information for cross-context behavioral advertising. You may submit a request to know, delete, or correct your data by emailing care@zoazoneservices.com.

8.2 EU / UK Residents (GDPR / UK GDPR)

EU and UK residents may lodge a complaint with their local supervisory authority if they believe their data rights have been violated. Our Data Protection Officer can be contacted at care@zoazoneservices.com.

9. Data Retention

Data TypeRetention PeriodReason
Account dataDuration of account + 2 years post-closureLegal obligation, dispute resolution
Call recordings90 days (default) — configurable by operatorQuality review, compliance
Call transcripts12 monthsAI improvement, compliance logging
Billing & transaction records7 yearsTax and accounting obligations
SMS / WhatsApp consent logs5 yearsTCPA / A2P compliance
Email consent logs5 yearsCAN-SPAM / GDPR compliance
Security & access logs12 monthsSecurity incident investigation
OTPs / passcodesDeleted immediately after use or 5-minute expirySecurity
Marketing analytics36 monthsService improvement
Health data (MedZoa)Minimum 6 years — see HIPAA sectionHIPAA compliance

Upon account deletion, we anonymize or delete personal data within 30 days, except where retention is required by law. Anonymized, aggregated data may be retained indefinitely for platform analytics.

India — DPDP Act 2023

For users in India, we process personal data in compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act):

  • ✓ We collect personal data only for a lawful purpose, with your informed consent or notice, or where processing is necessary for the service you have asked for.
  • ✓ We collect only the data that is necessary — data minimisation by design.
  • ✓ You may access, correct, complete, or erase your personal data, withdraw consent, and nominate another individual to exercise your rights if you are unable to.
  • ✓ We take reasonable security safeguards to prevent personal data breaches and will notify affected users and the Data Protection Board as required by law.
  • ✓ We do not process personal data in a manner likely to cause harm to a child, except as permitted by the DPDP Act.
  • ✓ Upon request or withdrawal of consent, we cease processing and erase your data unless retention is required by law (see Data Retention above).

Grievance Redressal (India)

Under the IT Rules, 2021, grievances of users in India are handled by our Grievance Officer:

  • Designation: Grievance Officer
  • Entity: Zoa Zone Services Pvt Ltd, 376, G3, Road No 82, Film Nagar, Jubilee Hills, Hyderabad, Telangana 500096, India
  • Email: care@zoazoneservices.com
  • Phone: +1 256 699 8899 (Mon–Sat, 10:00–18:00 IST)
  • Acknowledgement: within 48 hours
  • Resolution: within 15 days of receipt

Data-related requests under the DPDP Act 2023 are honoured through the same contact.

10. HIPAA Compliance — MedZoa

⚠️This section applies to the MedZoa platform (medex.base44.app), where all health data is treated as sensitive and handled per this policy.
  • ✓ MedZoa enters into a Business Associate Agreement (BAA) with all covered entities using MedZoa.
  • ✓ PHI is encrypted at rest (AES-256) and in transit (TLS 1.3).
  • ✓ Access to PHI is strictly role-based and logged in immutable audit trails.
  • ✓ PHI is never used to train AI models without explicit authorization.
  • ✓ Call recording PHI redaction is available and enabled by default for healthcare accounts.
  • ✓ Transcript PHI redaction removes names, SSNs, dates of birth, and other identifiers.
  • ✓ Data is retained for a minimum of 6 years per HIPAA requirements.
  • ✓ Breach notification is provided within 60 days of discovery per HIPAA Breach Notification Rule.
  • ✓ De-identification of health data follows the HIPAA Safe Harbor method.
  • ✓ HIPAA training is completed by all staff with access to PHI systems.

11. Children's Privacy

MedZoa services are intended for use by businesses and individuals aged 18 and older. We do not knowingly collect personal information from individuals under 18 years of age. If you believe a minor has provided us with personal information, please contact care@zoazoneservices.com and we will delete it promptly.

12. Policy Changes

We may update this policy periodically to reflect changes in our practices, technologies, or legal obligations. When we make material changes, we will:

  • • Post the updated policy on this page with a new effective date.
  • • Send an email notification to all registered account holders.
  • • Display an in-app banner for 30 days after the update.
  • • For material changes affecting messaging consent, we will re-collect your explicit consent.

Continued use of our services after the effective date of any updates constitutes acceptance of the revised policy.

13. Contact & Data Requests

📧 General Privacy Inquiries

care@zoazoneservices.com

🏛️ Data Protection Officer (EU/UK)

care@zoazoneservices.com

🔒 Security Vulnerability Reports

care@zoazoneservices.com

📋 CCPA / CPRA Requests

care@zoazoneservices.com

We aim to respond to all inquiries within 5 business days. Data subject requests are handled within 30 days as required by applicable law.

Zoa Zone Services Pvt Ltd · Zoa Zone Services LLC · Last updated: 28 September 2026

Questions? care@zoazoneservices.com

© 2026 MedZoa. Operated in India by Zoa Zone Services Pvt Ltd, 376, G3, Road No 82, Film Nagar, Jubilee Hills, Hyderabad, Telangana 500096, India. Global operations: Zoa Zone Services LLC, 1770 Grand Concourse 12A, Bronx, NY 10457, USA.