ConnectAI

Clinic, Lab & Hospital Privacy Notice

Applies to organisations that subscribe to ConnectAI. Last updated 11 August 2026.

Are you a patient? This notice is written for our business customers. Read the Patient Privacy Policy instead.

Short version: patient data you put into ConnectAI belongs to you. We process it only to run the services you have subscribed to, on your instructions. We do not sell it, we do not use it to train our own AI models, and we do not share it with other clinics.

1. Who this notice is for

ConnectAI is operated by ZODIX HEALTH Pvt. Ltd. ("ConnectAI", "we"). This notice explains how we handle data when a clinic, diagnostic laboratory, hospital, polyclinic, dental practice or other healthcare provider ("you", "Customer") uses ConnectAI — including the clinic portal, website builder, WhatsApp automation, AI voice receptionist, CRM, billing, lab and pharmacy modules, Google Business Profile management, and ad management.

It sits alongside our Terms & Conditions. Where you have signed a separate data processing agreement (DPA) or master services agreement with us, that document prevails over this notice.

2. Two different roles — and why it matters

We handle two distinct categories of data, and our legal responsibility differs for each.

CategoryExamplesOur role
Customer DataYour patients' and enquirers' personal and health data — records, appointments, prescriptions, lab reports, WhatsApp threads, call recordings and transcripts, invoicesData Processor. You are the Data Fiduciary (controller). You decide what is collected and why; we act on your instructions.
Account DataYour organisation details, staff logins and roles, subscription and payment records, support conversations, product usage and audit logsData Fiduciary. We determine how this is used, to operate, bill for, secure and support the service.

This split is what the Digital Personal Data Protection Act, 2023 (DPDP Act) expects. Practically: consent, notices, purpose limitation and patient-facing obligations for Customer Data sit with you. Security, confidentiality, sub-processor control and acting only on your instructions sit with us.

3. Your responsibilities as Data Fiduciary

By using ConnectAI you confirm that you will:

  • Give your patients the notice required by law about how their data is used, and obtain any consent needed — including for WhatsApp messaging, marketing messages, and recording of calls handled by the AI receptionist.
  • Only upload patient data you are lawfully entitled to process, and keep it accurate.
  • Manage your own staff access — create, review and revoke logins promptly, and not share credentials. Access you grant inside your account is your decision, not ours.
  • Follow WhatsApp Business Platform and Google policies for any template, campaign or listing content you publish through us.
  • Use clinical outputs — AI summaries, drafted replies, suggested content — as assistance only. A qualified clinician remains responsible for every clinical decision.

4. What we do with Customer Data

We process Customer Data only to:

  • Deliver the modules you have subscribed to — answer calls and WhatsApp messages, book and remind about appointments, store records, generate reports and invoices, publish your portal.
  • Provide support you request, and investigate faults you report.
  • Keep the service secure, prevent abuse, and maintain backups.
  • Comply with a legal obligation binding on us.

We do not sell Customer Data, rent it, share it with other clinics, use it to advertise to your patients on our own behalf, or use it to train our own or any third party's AI models. Aggregated, de-identified statistics that cannot be linked back to you or any individual may be used to improve the product.

5. Account Data we collect about you and your staff

  • Registration and business details: clinic name, speciality, addresses, phone numbers, email addresses, registration or licence numbers you provide, GSTIN where applicable.
  • Staff accounts: name, role, contact details, login and activity logs.
  • Subscription and billing: plan, invoices, payment status and references. Card details are handled by our payment gateways — we do not store full card numbers.
  • Usage and diagnostics: features used, error logs, IP address, device and browser information.
  • Sales and support communication: demo bookings, enquiry forms, WhatsApp and email threads with our team, and recordings or notes of demo calls where you have been told they are recorded.

We use Account Data to onboard you, operate and bill the service, provide support, and — for our own customers and enquirers — send service and marketing communications. You can opt out of marketing at any time; service and billing notices continue while your subscription is active.

6. Where your data is stored

Customer Data is stored in India, on Amazon Web Services infrastructure in the Mumbai region (ap-south-1), including backups.

Some processing necessarily leaves India: WhatsApp message delivery, telephony, and the large language models behind our AI features run on providers hosted outside India. Those transfers are limited to the data needed for that specific function, are made to the sub-processors listed in section 8 under contract, and only to countries not restricted by the Central Government under the DPDP Act. If your policy requires all processing to stay within India, tell us before onboarding — some AI features cannot be delivered under that constraint.

7. AI processing, in plain terms

  • Call audio and WhatsApp messages are converted to text and sent to the AI providers in section 8 to generate a reply, summary or suggested action.
  • We use these providers through their business or API offerings, under terms that do not permit them to train their models on your content.
  • Transcripts, recordings and AI outputs are Customer Data. They live in your account, are visible to the staff you authorise, and are deleted with the rest of your data (section 10).
  • AI output can be wrong. It is drafted assistance for your team, not a medical or legal decision, and it is not a substitute for clinician review.

8. Sub-processors

We use the third parties below to run the service. Each is engaged under a contract that limits them to processing for the stated purpose. Which of them touch your data depends on the modules you subscribe to.

Sub-processorPurposeData involvedProcessing location
Amazon Web Services (AWS)Application hosting, database, file and backup storageAll Customer DataIndia (ap-south-1, Mumbai)
Meta Platforms (WhatsApp Business Platform)Sending and receiving WhatsApp messages on your behalfPatient name, phone number, message contentUnited States / global
TwilioVoice calling and SMS for the AI receptionistPhone numbers, call audio, call metadataUnited States / global
Anthropic (Claude)AI conversation, summarisation and content generationMessage and call transcripts, clinic content submitted for generationUnited States
OpenAIAI conversation and document/text processingMessage and call transcripts, uploaded document textUnited States
Google (Gemini, Google Ads API, Google Business Profile API)AI processing, and — where you subscribe to those modules — managing your ad campaigns and Google Business ProfileTranscripts, campaign and listing data, aggregate enquiry countsUnited States / global
Sarvam AIIndian-language speech-to-text and text-to-speechCall audio and transcriptsIndia
SendGrid (Twilio)Transactional email deliveryRecipient name, email address, message contentUnited States / global
Google FirebasePush notifications to your staff appDevice tokens, notification contentUnited States / global
Razorpay / PaytmCollecting your subscription paymentsBilling contact and payment detailsIndia

Analytics and advertising tools on our public marketing website (Google Tag Manager, Google Analytics, Meta Pixel, Microsoft Clarity) are used for that website only. They are not embedded in your clinic account and never receive patient data. Where you subscribe to our ad management module, we share only campaign and aggregate enquiry data with the ad platform on your behalf.

We will notify you at the email address on your account before adding a sub-processor that materially changes how Customer Data is handled.

9. Security

  • Data encrypted in transit over TLS; storage and backups encrypted at rest.
  • Every account is isolated by clinic identifier, and every API request is authenticated and scoped to that clinic.
  • Role-based permissions inside your account, so receptionists, doctors, lab staff and owners see only what their role allows.
  • Access by our staff is limited to the people who need it for support, operations or debugging, and is logged.
  • Backups taken on a regular schedule.

No system is perfectly secure. We do not currently hold ISO 27001 or SOC 2 certification; if your procurement process requires one, raise it with us before signing so we can tell you honestly where we stand.

10. Retention, export and deletion

  • While your subscription is active we retain Customer Data so your team can use it.
  • You can export your data at any time from your account, or ask us for an export.
  • On written request, or within 30 days of your subscription ending, we delete Customer Data from live systems. Copies in encrypted backups age out within a further 35 days.
  • We retain Account Data — invoices, tax records, contracts — for as long as Indian tax and company law require, after your account closes.
  • Where you are legally obliged to keep medical records for a set period, that obligation is yours. Export before you ask us to delete.

11. Patient requests and Data Principal rights

If a patient asks us directly to access, correct or erase their data, we will not act on it ourselves — we will point them to you and, if we can identify your clinic, tell you. Because you are the Data Fiduciary, the decision is yours.

We will give you reasonable assistance to answer such a request, including locating, exporting, correcting or deleting the data in question, at no extra charge for ordinary volumes.

For your own Account Data — yours and your staff's — you can ask us directly to access, correct, or delete it, or to withdraw consent for marketing, by writing to hello@connectai.care.

12. Security incidents

If we become aware of a personal data breach affecting your Customer Data, we will notify you without undue delay at the contact on your account, with what we know: what happened, which data and how many individuals appear affected, what we are doing about it. As Data Fiduciary, notifying the Data Protection Board and affected patients is your call and your obligation; we will give you the information you need to make it.

13. Confidentiality and no lock-in

Your patient lists, pricing, referral sources and clinical content are confidential to you. Our staff are bound by confidentiality obligations. We do not use one customer's data to benefit another, and we will not obstruct your move to another vendor — your data comes with you.

14. Changes to this notice

We may update this notice as the product or the law changes. Material changes affecting how Customer Data is handled will be notified to the email on your account before they take effect. The "last updated" date above always reflects the current version.

15. Contact and grievances

ZODIX HEALTH Pvt. Ltd. (ConnectAI)
J-101 SDS NRI Residency Omega-2,
Greater Noida, UP, India
PIN - 201310
CIN available on request.

  • Privacy and data protection queries: hello@connectai.care
  • Grievances, including a request for our data processing agreement or a security questionnaire: hello@connectai.care with "Grievance" in the subject line. We acknowledge within 3 working days.
  • Or use the contact form.