LEGAL

Privacy Policy

Last updated: June 2025

Information We Collect

Zonov.ai collects information necessary to provide our AI-powered hospital management services. We collect three categories of data:

Service data, Information generated during use of the platform, including patient registration details, appointment records, clinical documentation, billing data, and diagnostic reports. This data is owned by the hospital and processed by Zonov.ai as a data processor under applicable law.

Account data, Names, email addresses, role designations, and login credentials for hospital administrators and clinical staff accessing the platform.

Usage data, Anonymised telemetry about how features are used, error logs, and performance metrics. This data does not contain patient-identifiable information and is used solely to improve the platform.

We do not collect:

  • Personal data beyond what is necessary for service delivery
  • Payment card information (handled by certified payment processors)
  • Data from minors under 18 without hospital-verified consent

How We Use It

We use the data we collect for the following purposes:

  • Delivering and improving the Zonov.ai platform and its AI agents
  • Generating clinical documentation, billing codes, and operational reports on behalf of the hospital
  • Sending operational notifications, alerts, and scheduled digests to authorised hospital staff
  • Fulfilling legal obligations under applicable data protection law, including the EU GDPR, and applicable healthcare regulations
  • Conducting anonymised research to improve AI model accuracy, with hospital consent

We do not use patient data for advertising, third-party profiling, or any purpose outside the contracted service scope.

Data Security

HIPAA and GDPR alignment: Zonov.ai is designed to meet the requirements of both the US Health Insurance Portability and Accountability Act (HIPAA) and the EU General Data Protection Regulation (GDPR). We implement administrative, technical, and physical safeguards to protect health information.

Key controls:

  • AES-256 encryption at rest; TLS 1.3 in transit
  • Role-based access controls with audit trails for all data access
  • Flexible data residency in your chosen region (AWS / Azure)
  • Annual third-party penetration testing and SOC 2 Type II audit in progress
  • Incident response SLA: notification within 72 hours of confirmed breach

Third-Party Sharing

Zonov.ai does not sell patient data. We share data only in the following circumstances:

  • With sub-processors (cloud infrastructure, analytics providers) under data processing agreements that enforce equivalent security standards
  • With the hospital's own HIS, EMR, or third-party diagnostic systems as directed by the hospital
  • When required by law, regulation, court order, or government authority
  • With your consent, for purposes clearly disclosed at the time of consent

A current list of sub-processors is available on request at privacy@zonov.ai.

Your Rights

Under applicable data protection law, individuals whose data is processed through the Zonov.ai platform may have the following rights:

  • Right to access: request a copy of personal data held about you
  • Right to correction: request correction of inaccurate or incomplete data
  • Right to erasure: request deletion of data, subject to legal retention obligations
  • Right to grievance redressal: file a complaint with the relevant data protection authority

Note: Most rights are exercised through the hospital (the data controller), not directly with Zonov.ai (the data processor). Contact your hospital's data protection officer in the first instance.

Contact Us

For privacy-related queries, data subject requests, or to report a concern:

Email: privacy@zonov.ai

Address: Zonov.ai Technologies Pvt. Ltd., Jaipur, India

We aim to respond to all privacy requests within 30 days.