Zyposoft
Data Privacy

Most privacy problems are justdata nobody needed to hold.

So the work is mostly subtraction: fewer fields collected, fewer sent back, changed before they leave, and gone when you said they would be.

Collect lessShow lessKeep it shorterChange it before it leavesRecord who looked
One record — what each person actually gets backIllustrative
Caring for this patient today. Everything clinical, because she is treating her.
NameMeera NairShown
Date of birth14 March 1958Shown
Hospital numberH-4471902Shown
Ward and bedWard B · Bed 12Shown
DiagnosisCommunity-acquired pneumoniaShown
MedicationsAmoxicillin · SalbutamolShown
AllergiesPenicillin — documentedShown
Next of kinR. Nair · 07700 900411Shown
Billing accountnot includedNever sent
ShownChanged firstNever sentBeing allowed in is not the same as being shown everything.
Thesafestdataisthedatayounevercollected.Thenextsafestisthedatayoudidnotsend.Thenthedatayouchangedbeforeitleft.Thenthedatayoudeletedwhenyousaidyouwould.Everythingafterthatisjusthoping.
How we work

Six habits, applied before anyone writes a line of code.

1

Ask for less in the first place

Every field on a form is a field somebody has to protect for years. If a workflow does not genuinely need a piece of information, the honest answer is to stop asking for it.

In practiceFewer fields, deliberately
Justify each fieldOptional stays optionalRemove what is unused
2

Send back only what was asked for

Being allowed into a record is not the same as being handed all of it. A pharmacist checking a prescription does not need the family's phone number, so it does not travel.

In practiceField-level, per role
Per rolePer situationNothing extra in the response
3

Change it before it leaves

Some things do not need to be exact. A research extract can use a year of birth instead of a date, and a subject number instead of a name — the clinical picture survives, the person is not identifiable from it.

In practiceMasked, coded or pseudonymised
MaskingCodingPseudonymsAggregates
4

Keep it for as long as agreed, then stop

Retention is a decision, not an accident. How long each kind of record lives is agreed with you up front and then actually enforced, rather than everything living forever because nobody chose.

In practiceRetention you set
Agreed per record typeEnforced, not aspirationalDeletion is recorded too
5

Be careful about what leaves the building

Integrations are where privacy quietly leaks. Every connection has an agreed set of fields, and adding one is a decision someone makes on purpose rather than a side effect.

In practiceAgreed field by field
Explicit contractsNo convenience payloadsReviewed when changed
6

Be able to show who looked

When a patient asks who has seen their record, that should be a query rather than an investigation. The same trail that supports security supports answering them honestly.

In practiceQueryable access records
WhoWhenWhyExportable
Straight answers

What we do, and what we will not.

We do
Hold the minimum a workflow actually needs
Keep clinical data inside the environment you approved
Let you set retention per record type
Record every access, including refused ones
Tell you what a connected system will receive, field by field
We will not
Sell or broker anyone's data
Use patient data to train models without an explicit, separate agreement
Copy production data into test environments as a matter of convenience
Add fields to an integration because they were easy to include
Keep records past the retention you set
That second one matters more each year. If AI features ever draw on your data beyond serving your own workflow, that is a separate conversation and a separate agreement not something buried in a change log.
Where this page stops

The questions that belong in a contract, not on a website.

Is this your privacy policy?

No. This page describes how the software is built to handle personal data. The privacy policy is a separate legal document covering what Zyposoft itself collects and why — it is linked in the footer.

Which regulations does this satisfy?

That depends on where you operate and what you are processing, and it is not something a web page should answer for you. Bring your obligations to us and we will go through them properly, in writing.

Who is the data controller?

In a hospital deployment that is normally you, and we are processing on your behalf. The specifics belong in the contract rather than here, because they change the answer to several other questions.

A patient wants to know who accessed their record.

The access records are queryable and exportable, so this is a report rather than a forensic exercise. Who is permitted to run that query is something you decide during setup.

This page is about engineering practice, not legal position. What any deployment ends up doing — which data is held, for how long, on what legal basis, in which jurisdiction, and who controls it — is settled in your contract and your own data-protection assessment. We are happy to be specific in that setting; we are not going to be specific here, where it could be read as a promise nobody has checked against your circumstances.
Setting it up

Six things to settle before launch.

The first one is the one people skip. Going field by field through what you actually need is tedious, and it removes more risk than anything that comes after it.

01
Work out what is actually needed
Every fieldWho needs itWhat breaks without itWhat can go
02
Classify it
What is sensitiveWhat is identifyingWhat is clinicalWhat is administrative
03
Decide what each role sees
Per rolePer situationWhat gets maskedWhat is never sent
04
Set retention, and mean it
Per record typeWho approves itHow deletion is provedLegal holds
05
Go through the integrations
What each one sendsField by fieldWho signed it offWhat happens when it changes
06
Check it, then keep checking
Review who has accessSample the recordsRe-check after changesHandle requests
Zyposoft Technologies is a product engineering company based in Bangalore, building software for healthcare and enterprise operations. Our products are Zypocare One, the connected hospital platform; Zypo Clinical AI, which adds intelligence a clinician can overrule; and the Integration Platform that keeps them working with the systems already in place.
Products
Zypocare OneZypo Clinical AIIntegration Platform
Solutions
Healthcare TransformationEnterprise Product EngineeringAI and AutomationCloud, Data and Integration
Company
About ZyposoftLeadershipPartnersCareersContact
Get in touch
Bangalore, IN
#7, Nisarga Layout
Chikkalsandra
Bangalore 560061
India
info@zyposoft.com
Security & GovernanceIdentity & AccessData PrivacyData Security
© 2026 Zyposoft Technologies. All rights reserved.
Privacy PolicyTerms of UseSitemap