Privacy Policy
Effective August 28, 2026 · STRATOSIA DIGITAL PRIVATE LIMITED
STRATOSIA DIGITAL PRIVATE LIMITED (“Company”, “we”, “us”) operates Zennor, a cloud-based operating system for aesthetic clinics, dermatology clinics, and med spas in India. This Privacy Policy explains how we collect, use, and protect information when clinics and their patients use Zennor. It is designed to align with the IT Act 2000, IT (SPDI) Rules 2011, and the Digital Personal Data Protection Act, 2023 (DPDPA 2023).
1. Who This Policy Applies To
This policy covers:
- Clinic Administrators & Staff — registered business users on the Zennor admin dashboard.
- Patients / End-Users — individuals interacting with clinics via Zennor (loyalty, memberships, bookings, QR redemption).
Important: For clinic operational and patient data, the clinic determines the purposes of processing and is responsible for obtaining valid patient consent before entering data into Zennor. Zennor processes that data to provide the platform. Zennor is separately responsible for its website, business-account, security, support, and platform-administration data.
2. Information We Collect
Clinic Account Information
- Clinic name, owner name, email, phone number, business address, GSTIN, billing details
- Login credentials (passwords are securely hashed by our authentication provider and never stored in plain text)
Clinic Operational & Patient Data
- Patient names, phone numbers, appointment history, treatment records
- Membership status, loyalty points, wallet balances, order history, invoices
- Before/after media and educational content uploaded by clinics
Clinics own all their operational and patient data. Zennor processes it solely to deliver platform services and does not sell or exploit this data.
Technical & Usage Data
- IP address, device type, browser, session logs, cookies, analytics identifiers, and diagnostic crash data
- Push notification tokens (where permission is granted)
Payment Information
Payments are processed by third-party gateways including Razorpay. Zennor does not store full payment-card credentials. Where a clinic uses platform-managed payouts, Zennor may store and transmit the clinic’s business, KYC, and settlement-bank details to Razorpay to set up and operate those payouts.
3. Health & Sensitive Personal Data
Treatment history and health-adjacent data constitutes Sensitive Personal Data under Indian law. We apply heightened safeguards including role-based access controls, encryption in transit and at rest, and no sharing with third parties beyond infrastructure providers.
Medical Disclaimer: Zennor is a clinic management platform. It does not provide medical advice, diagnosis, or treatment recommendations, and does not create a doctor-patient relationship. All clinical decisions are the sole responsibility of the clinic and its licensed practitioners.
4. How We Use Information
- Provide, maintain, and improve the Zennor platform
- Enable loyalty programs, memberships, bookings, and QR-based redemption
- Process payments and issue invoices
- Send service-related communications and push notifications
- Provide customer support, monitor security, and prevent fraud
- Comply with applicable Indian laws and regulatory obligations
5. Data Sharing & Service Providers
We share information only as needed to provide Zennor, meet legal obligations, protect the platform, or process a request you initiate.
| Provider | Purpose and data involved | Provider privacy information |
|---|---|---|
| Google Firebase | Authentication, database, Storage, Cloud Functions, push notifications, and crash diagnostics; this can include account, clinic, patient, device, and application data. | Firebase privacy and security |
| Razorpay | Payment processing and, where enabled, clinic payout/KYC services; this can include transaction, business, KYC, and settlement information. | Razorpay Privacy Policy |
| Meta WhatsApp Business Platform | Clinic communications where the clinic enables WhatsApp; this can include phone numbers and message content. | Meta Privacy Policy |
| Formspree | Website contact-form delivery; this receives the name, clinic name, email address, phone number, and message submitted through that form. | Formspree Privacy Policy |
| Sentry | Error monitoring for the website and administration tools. Browser error diagnostics are enabled only after the visitor accepts optional diagnostics. | Sentry Privacy Policy |
| Google Gemini API | Optional admin-only brand extraction from a submitted public website URL and a limited excerpt of its page content. Administrators must not submit patient, health, payment, or other confidential information to this feature. | Google Privacy Policy |
We may also disclose information to professional advisers, authorities, or other recipients where required by Indian law, court order, or a valid legal process. We do not sell data to advertisers or data brokers.
6. AI-Assisted Brand Extraction
Zennor offers an optional admin tool that uses the Google Gemini API to extract branding information from a submitted public website. The tool sends the URL and a limited, filtered excerpt of public page content to Google. It is not intended for patient, treatment, payment, or other confidential data. Zennor does not use patient data to train its own AI models.
7. Data Security
- HTTPS/TLS encryption for all data in transit
- Secure cloud infrastructure with role-based access controls
- Regular security monitoring and incident response processes
No system can guarantee absolute security. In the event of a data breach, we will notify affected parties as required under applicable law.
8. Data Retention
- Clinic data is retained while the account is active and for a reasonable period thereafter as required by law.
- Clinics may request a data export upon account termination.
- Financial and legal records may be retained for the statutory period under Indian law.
9. Your Rights & Data Subject Requests
If you are a patient or end-user of a Clinic utilizing the Zennor platform, your primary relationship for clinic-held records is with that Clinic. Requests about those records may need to be handled by the Clinic, and Zennor will provide reasonable technical assistance where it processes the data for the Clinic. You may contact Zennor directly for requests concerning Zennor’s own website, account, security, support, or platform-administration data.
Any requests to exercise your rights as a Data Principal—including requests for data access, correction, or permanent deletion—must be directed to your respective Clinic. Zennor will provide the necessary technological assistance to the Clinic to fulfill these requests within statutory timelines. However, Zennor cannot unilaterally delete your medical records, as such actions are subject to the Clinic’s mandatory medical record retention obligations under Indian healthcare and taxation laws.
Account Deletion
App users can initiate account deletion in the app under Profile → Privacy & Data → Delete Account, or submit an external request at Data Deletion Request. We delete account and personal profile data and may retain legally required financial, fraud-prevention, audit, or clinic records only in anonymized form.
10. Cookies
Zennor uses essential browser storage for authentication and security. With your consent, our website sends browser error diagnostics to help us improve reliability. We do not use advertising cookies or cross-site tracking. You can accept or decline optional diagnostics in the cookie banner, or clear your browser storage to reset that choice.
| Storage | Purpose | Duration and control |
|---|---|---|
cookie_consent browser storage | Records whether optional browser error diagnostics were accepted or declined. | Retained until you clear browser storage; use the cookie banner or clear browser storage to change it. |
| Firebase Authentication session storage | Keeps an authenticated administrator signed in during an active browser session. | Session-only; sign out or close the browser session to remove it. |
11. Cross-Border Processing
Data may be processed on cloud servers located outside India where appropriate safeguards are in place as required under applicable law.
12. Grievance Officer
- Name: Siddhesh Zagade
- Role: Grievance Officer / Director
- Email: support@zennor.app
- Address: 202 MSCB Emps Yogesh CHS, Kasturpark, Borivali West, Mumbai – 400092, Maharashtra, India
Grievances will be acknowledged within 48 hours and resolved within 30 days.
13. Changes to This Policy
Material changes will be notified to registered clinic administrators via email or in-platform notification. Continued use after updates constitutes acceptance.