Applies to organisations that subscribe to ConnectAI. Last updated 11 August 2026.
Are you a patient? This notice is written for our business customers. Read the Patient Privacy Policy instead.
Short version: patient data you put into ConnectAI belongs to you. We process it only to run the services you have subscribed to, on your instructions. We do not sell it, we do not use it to train our own AI models, and we do not share it with other clinics.
ConnectAI is operated by ZODIX HEALTH Pvt. Ltd. ("ConnectAI", "we"). This notice explains how we handle data when a clinic, diagnostic laboratory, hospital, polyclinic, dental practice or other healthcare provider ("you", "Customer") uses ConnectAI — including the clinic portal, website builder, WhatsApp automation, AI voice receptionist, CRM, billing, lab and pharmacy modules, Google Business Profile management, and ad management.
It sits alongside our Terms & Conditions. Where you have signed a separate data processing agreement (DPA) or master services agreement with us, that document prevails over this notice.
We handle two distinct categories of data, and our legal responsibility differs for each.
| Category | Examples | Our role |
|---|---|---|
| Customer Data | Your patients' and enquirers' personal and health data — records, appointments, prescriptions, lab reports, WhatsApp threads, call recordings and transcripts, invoices | Data Processor. You are the Data Fiduciary (controller). You decide what is collected and why; we act on your instructions. |
| Account Data | Your organisation details, staff logins and roles, subscription and payment records, support conversations, product usage and audit logs | Data Fiduciary. We determine how this is used, to operate, bill for, secure and support the service. |
This split is what the Digital Personal Data Protection Act, 2023 (DPDP Act) expects. Practically: consent, notices, purpose limitation and patient-facing obligations for Customer Data sit with you. Security, confidentiality, sub-processor control and acting only on your instructions sit with us.
By using ConnectAI you confirm that you will:
We process Customer Data only to:
We do not sell Customer Data, rent it, share it with other clinics, use it to advertise to your patients on our own behalf, or use it to train our own or any third party's AI models. Aggregated, de-identified statistics that cannot be linked back to you or any individual may be used to improve the product.
We use Account Data to onboard you, operate and bill the service, provide support, and — for our own customers and enquirers — send service and marketing communications. You can opt out of marketing at any time; service and billing notices continue while your subscription is active.
Customer Data is stored in India, on Amazon Web Services infrastructure in the Mumbai region (ap-south-1), including backups.
Some processing necessarily leaves India: WhatsApp message delivery, telephony, and the large language models behind our AI features run on providers hosted outside India. Those transfers are limited to the data needed for that specific function, are made to the sub-processors listed in section 8 under contract, and only to countries not restricted by the Central Government under the DPDP Act. If your policy requires all processing to stay within India, tell us before onboarding — some AI features cannot be delivered under that constraint.
We use the third parties below to run the service. Each is engaged under a contract that limits them to processing for the stated purpose. Which of them touch your data depends on the modules you subscribe to.
| Sub-processor | Purpose | Data involved | Processing location |
|---|---|---|---|
| Amazon Web Services (AWS) | Application hosting, database, file and backup storage | All Customer Data | India (ap-south-1, Mumbai) |
| Meta Platforms (WhatsApp Business Platform) | Sending and receiving WhatsApp messages on your behalf | Patient name, phone number, message content | United States / global |
| Twilio | Voice calling and SMS for the AI receptionist | Phone numbers, call audio, call metadata | United States / global |
| Anthropic (Claude) | AI conversation, summarisation and content generation | Message and call transcripts, clinic content submitted for generation | United States |
| OpenAI | AI conversation and document/text processing | Message and call transcripts, uploaded document text | United States |
| Google (Gemini, Google Ads API, Google Business Profile API) | AI processing, and — where you subscribe to those modules — managing your ad campaigns and Google Business Profile | Transcripts, campaign and listing data, aggregate enquiry counts | United States / global |
| Sarvam AI | Indian-language speech-to-text and text-to-speech | Call audio and transcripts | India |
| SendGrid (Twilio) | Transactional email delivery | Recipient name, email address, message content | United States / global |
| Google Firebase | Push notifications to your staff app | Device tokens, notification content | United States / global |
| Razorpay / Paytm | Collecting your subscription payments | Billing contact and payment details | India |
Analytics and advertising tools on our public marketing website (Google Tag Manager, Google Analytics, Meta Pixel, Microsoft Clarity) are used for that website only. They are not embedded in your clinic account and never receive patient data. Where you subscribe to our ad management module, we share only campaign and aggregate enquiry data with the ad platform on your behalf.
We will notify you at the email address on your account before adding a sub-processor that materially changes how Customer Data is handled.
No system is perfectly secure. We do not currently hold ISO 27001 or SOC 2 certification; if your procurement process requires one, raise it with us before signing so we can tell you honestly where we stand.
If a patient asks us directly to access, correct or erase their data, we will not act on it ourselves — we will point them to you and, if we can identify your clinic, tell you. Because you are the Data Fiduciary, the decision is yours.
We will give you reasonable assistance to answer such a request, including locating, exporting, correcting or deleting the data in question, at no extra charge for ordinary volumes.
For your own Account Data — yours and your staff's — you can ask us directly to access, correct, or delete it, or to withdraw consent for marketing, by writing to hello@connectai.care.
If we become aware of a personal data breach affecting your Customer Data, we will notify you without undue delay at the contact on your account, with what we know: what happened, which data and how many individuals appear affected, what we are doing about it. As Data Fiduciary, notifying the Data Protection Board and affected patients is your call and your obligation; we will give you the information you need to make it.
Your patient lists, pricing, referral sources and clinical content are confidential to you. Our staff are bound by confidentiality obligations. We do not use one customer's data to benefit another, and we will not obstruct your move to another vendor — your data comes with you.
We may update this notice as the product or the law changes. Material changes affecting how Customer Data is handled will be notified to the email on your account before they take effect. The "last updated" date above always reflects the current version.
ZODIX HEALTH Pvt. Ltd. (ConnectAI)
J-101 SDS NRI Residency Omega-2,
Greater Noida, UP, India
PIN - 201310
CIN available on request.