This Policy explains how Zyposoft collects, uses, shares, retains and protects personal data submitted through its corporate website.
This Privacy Policy describes how Zyposoft Technologies Private Limited, Corporate Identity Number U62099KA2026PTC215058 (“Zyposoft”, “we”, “us” or “our”), collects, uses, discloses, retains and protects personal data through the Zyposoft corporate website.
For personal data collected directly through this website, Zyposoft determines the purpose and means of processing and acts as the data fiduciary or equivalent responsible organisation under applicable data protection law.
This Policy applies to website visitors, persons who submit enquiries, prospective customers, prospective partners, suppliers, professional advisers and other business contacts who interact with this website.
This Policy does not govern patient, clinical, employee or hospital operational data processed within Zypocare or another Zyposoft product on behalf of a hospital or enterprise customer. Such processing is governed by the applicable customer agreement, data-processing terms and product-specific privacy documentation.
We collect personal data that you voluntarily provide through the website, together with limited technical information required to operate and protect the website.
The information collected depends on the form or interaction you choose. It may include the categories listed below.
We collect personal data directly from you when you complete a contact form, submit a partner application, correspond with us or otherwise provide information through the website.
The website server also processes limited technical information automatically when it receives a request. The IP address used for form rate limiting is held in server memory for up to ten minutes and is not retained after that period or after a server restart.
Please provide only information that is relevant to your business enquiry. Website forms must not be used to submit patient data, personal health information, access credentials or information that you are required to transmit through a specially protected channel.
We process personal data only for lawful and specified purposes connected with our website, products, services, business relationships and legal obligations.
Depending on the circumstances and the law applicable to the processing, we rely on your consent, steps requested by you before entering into a contract, performance of a contract, compliance with law, or another lawful use recognised by applicable data protection legislation.
Access to personal data is limited to Zyposoft personnel and service providers who require it for the purposes described in this Policy and who are subject to appropriate confidentiality and security obligations.
Website form submissions are transmitted to a company-controlled Zoho Mail account. Our website-hosting provider processes technical requests necessary to deliver and secure the website.
We do not sell personal data and do not disclose it for third-party advertising.
Our service providers may operate infrastructure or support functions in more than one jurisdiction. Personal data may therefore be processed outside the jurisdiction in which it was collected.
Where personal data is transferred or made accessible across borders, we apply contractual, organisational and technical safeguards required by applicable law and observe any transfer restrictions notified by the Government of India.
We retain personal data only for as long as it is reasonably required for the purpose for which it was collected, for a continuing business relationship, or to comply with legal, accounting, security and record-keeping obligations.
Subject to applicable law, you may request information about personal data we process about you and ask us to correct, complete, update or erase it. You may also withdraw consent where processing is based on consent, object to or restrict processing where the law provides that right, and raise a grievance about our handling of personal data.
Withdrawal of consent does not affect processing lawfully carried out before withdrawal. We may retain information where continued retention is required by law or necessary for the establishment, exercise or defence of legal claims.
To protect personal data, we may ask for information reasonably necessary to verify your identity and authority before acting on a request. We will respond within the period prescribed by applicable law.
You may withdraw from optional marketing communications at any time by using the unsubscribe method provided in the communication or by contacting our Privacy and Grievance Officer.
We maintain reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, disclosure, alteration, loss, misuse and unlawful processing.
These safeguards include encrypted transmission, access controls, authentication, least-privilege access, secure credential handling, service-provider controls, rate limiting, logging, monitoring, vulnerability management and incident-response procedures appropriate to the nature of the data and the processing.
Where a personal-data breach requires notification under applicable law, we will notify the competent authority and affected individuals in the manner and within the period required by that law.
This website is intended for business and professional users and is not directed to children.
We do not knowingly solicit or process personal data from a child through this website. If we learn that a child has submitted personal data without the legally required authorisation, we will take appropriate steps to delete it.
The corporate website does not use personal data to make solely automated decisions that produce legal or similarly significant effects.
Partner applications, sales enquiries and other business submissions are reviewed by authorised personnel. Automated controls may be used for spam prevention, rate limiting, routing and security, but they do not determine whether Zyposoft will enter into a commercial or partnership relationship.
Where a hospital or enterprise customer uses Zypocare or another Zyposoft product, that customer ordinarily determines the purposes for which patient, clinical, employee or operational data is processed. Zyposoft processes such data in accordance with the customer agreement, documented instructions, applicable law and the security and privacy terms governing the deployment.
Requests concerning data held in a customer-controlled Zypocare deployment should ordinarily be directed to the relevant hospital or enterprise, which is responsible for determining and responding to the request. We will assist the customer where required by contract or law.
Patient or clinical information must not be submitted through the corporate website’s contact or partnership forms.
We may update this Policy to reflect changes in law, technology, our website, our processing activities or our service providers.
The effective date displayed at the top identifies the current version. Material changes will be communicated through an appropriate notice on the website or by another method where required by law.
Privacy enquiries, rights requests and grievances may be sent to Vikram, Data Protection and Grievance Officer, at vikram@zyposoft.com.
Please describe your request clearly and provide sufficient information for us to identify the relevant interaction or record. Do not send identity documents, patient information, passwords or other highly sensitive material unless we have first provided an appropriate secure method.
We will acknowledge and address privacy grievances in accordance with applicable law. If you are not satisfied with our response, you may pursue any remedy available to you before the competent data-protection authority or court.
This Privacy Policy is governed by the laws of India.
Our processing of personal data is subject to applicable Indian law, including the Information Technology Act, 2000 and, as the relevant provisions become applicable, the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
Subject to any mandatory right to approach a competent regulatory or adjudicatory authority, the courts at Bengaluru, Karnataka shall have jurisdiction over disputes arising from this Policy.