LEGAL
Privacy Policy
Last updated: June 2025
Information We Collect
Zonov.ai collects information necessary to provide our AI-powered hospital management services. We collect three categories of data:
Service data, Information generated during use of the platform, including patient registration details, appointment records, clinical documentation, billing data, and diagnostic reports. This data is owned by the hospital and processed by Zonov.ai as a data processor under applicable law.
Account data, Names, email addresses, role designations, and login credentials for hospital administrators and clinical staff accessing the platform.
Usage data, Anonymised telemetry about how features are used, error logs, and performance metrics. This data does not contain patient-identifiable information and is used solely to improve the platform.
We do not collect:
- Personal data beyond what is necessary for service delivery
- Payment card information (handled by certified payment processors)
- Data from minors under 18 without hospital-verified consent
How We Use It
We use the data we collect for the following purposes:
- Delivering and improving the Zonov.ai platform and its AI agents
- Generating clinical documentation, billing codes, and operational reports on behalf of the hospital
- Sending operational notifications, alerts, and scheduled digests to authorised hospital staff
- Fulfilling legal obligations under applicable data protection law, including the EU GDPR, and applicable healthcare regulations
- Conducting anonymised research to improve AI model accuracy, with hospital consent
We do not use patient data for advertising, third-party profiling, or any purpose outside the contracted service scope.
Data Security
HIPAA and GDPR alignment: Zonov.ai is designed to meet the requirements of both the US Health Insurance Portability and Accountability Act (HIPAA) and the EU General Data Protection Regulation (GDPR). We implement administrative, technical, and physical safeguards to protect health information.
Key controls:
- AES-256 encryption at rest; TLS 1.3 in transit
- Role-based access controls with audit trails for all data access
- Flexible data residency in your chosen region (AWS / Azure)
- Annual third-party penetration testing and SOC 2 Type II audit in progress
- Incident response SLA: notification within 72 hours of confirmed breach
Your Rights
Under applicable data protection law, individuals whose data is processed through the Zonov.ai platform may have the following rights:
- Right to access: request a copy of personal data held about you
- Right to correction: request correction of inaccurate or incomplete data
- Right to erasure: request deletion of data, subject to legal retention obligations
- Right to grievance redressal: file a complaint with the relevant data protection authority
Note: Most rights are exercised through the hospital (the data controller), not directly with Zonov.ai (the data processor). Contact your hospital's data protection officer in the first instance.
Contact Us
For privacy-related queries, data subject requests, or to report a concern:
Email: privacy@zonov.ai
Address: Zonov.ai Technologies Pvt. Ltd., Jaipur, India
We aim to respond to all privacy requests within 30 days.