This Privacy Policy describes how zerodesk ("zerodesk," "we," "us") collects, uses, and shares information in connection with our front-office automation platform for healthcare practices (the "Service"). It applies to our marketing site and, where applicable, the Service itself.
Because the Service is designed to touch scheduling, intake, and other patient-facing workflows, it may process Protected Health Information ("PHI") on behalf of healthcare provider customers. Section 5 addresses that specifically.
We do not sell personal information, and we do not use PHI processed on behalf of provider customers for our own marketing purposes.
For marketing-site visitors, we act as the data controller for information submitted through this site (e.g. demo requests). For data processed through the Service on behalf of a healthcare practice customer, we act as a service provider / business associate, not a controller — the practice determines what data is collected and how it is used clinically.
This section requires legal verification before publication.
Where the Service processes PHI on behalf of a covered entity, we enter into a Business Associate Agreement ("BAA") with that customer governing our obligations under HIPAA, including permitted uses, safeguards, breach notification, and subcontractor flow-down requirements to any subprocessors (including any LLM or orchestration providers) in the data path.
Any claim of "HIPAA compliance" on our marketing site refers to our administrative, technical, and physical safeguards and our willingness to execute a BAA — it does not certify that any specific customer deployment is compliant, which depends on that customer's own configuration and use of the Service.
Update once analytics/tooling is finalized.
We may use cookies or similar technologies to understand site usage and improve the marketing site. We do not currently use third-party advertising cookies.
We share information with:
We use administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction. No system is perfectly secure, and we cannot guarantee absolute security.
[Define specific retention periods once determined — this is currently a placeholder.]
We retain information for as long as needed to provide the Service and fulfil the purposes described in this policy, or as required by law, our BAAs, or customer agreements.
Depending on your location, you may have rights to access, correct, or delete personal information we hold about you. If your data was submitted to us by a healthcare practice as part of their use of the Service, you should generally direct these requests to that practice, who controls the underlying data; we will assist them as required under our BAA.
To make a request regarding data submitted directly to us (e.g. through a demo request), contact us using the details in Section 13.
The marketing site is not directed to children, and we do not knowingly collect personal information from children through it.
We may update this policy from time to time. We will update the "Last updated" date above and, for material changes, provide additional notice as appropriate.
[Confirm final contact details before publishing.]
Questions about this policy can be sent to privacy@gozerodesk.com.