Last updated August 5, 2026.
Scope and our role
This policy applies to Zenthea's public website and cloud-based EHR services. A healthcare practice generally determines why and how its patient information is used. When Zenthea processes protected health information (PHI) for that practice, Zenthea acts as its business associate under a Business Associate Agreement (BAA) and follows the practice's lawful instructions. Questions about a provider's care or medical record should normally be directed to that provider first.
Information we collect
Depending on how you interact with Zenthea, we may collect:
- Contact and account information, such as name, work email, telephone number, organization, role, and login or authentication details.
- Practice and subscription information, including configuration, support requests, contracts, and billing administration details.
- Patient and clinical information entered by or for a healthcare practice, which may include PHI such as demographics, appointments, clinical documentation, orders, prescriptions, and billing records.
- Website and service usage data, including device, browser, IP address, timestamps, security events, and interactions needed to operate, secure, and improve the service.
- Communications and feedback you choose to send to us. Please do not send PHI through the public website or ordinary email.
Website analytics and advertising measurement
With your permission, our public website may use Google Analytics to understand visits and interactions, and the LinkedIn Insight Tag when enabled to measure campaign performance. These tools may process online identifiers and information about the page, device, browser, and campaign link. We do not send form contact details or PHI to these analytics tools.
Optional measurement is off until you choose to allow it. You can review or change that choice at any time using the Privacy choices control on the website. Please do not send patient information through public website forms or campaign pages.
How we use and disclose information
We use information to provide, support, secure, and maintain Zenthea; authenticate users; process authorized transactions; communicate about the service; meet legal obligations; and improve reliability and usability. We disclose information only as needed to provide the services, to vendors bound by appropriate contractual safeguards, at a customer's direction, during a lawful corporate transaction, or when required by law. Uses and disclosures of PHI are limited by the applicable BAA and HIPAA.
Zenthea does not sell personal data or PHI. We do not use PHI for targeted advertising. We do not disclose PHI except as permitted by the relevant BAA, customer instructions, and applicable law.
PHI and healthcare customers
Healthcare practices remain responsible for their privacy notices, patient authorizations, record-access decisions, and other duties as covered entities. Zenthea maintains safeguards required of a business associate, reports qualifying incidents as required by contract and law, supports customers in responding to patient requests, and returns or destroys PHI at the end of services when required and feasible. We apply minimum-necessary access controls and maintain audit records for security and compliance purposes.
Security and encryption
Zenthea uses administrative, technical, and physical safeguards designed for healthcare data. These include role-based and least-privilege access, authentication controls, monitoring, workforce controls, backups, and incident-response procedures. Data is encrypted in transit using industry-standard transport encryption and encrypted at rest. No security program can guarantee absolute security, but we regularly assess and improve these safeguards.
Retention and international privacy
We retain information only for as long as necessary to provide the services, satisfy customer instructions, preserve required healthcare and security records, resolve disputes, and meet legal obligations. Where GDPR or similar laws apply, processing may rely on performance of a contract, legal obligations, legitimate interests, consent, or other lawful bases. Cross-border transfers use safeguards required by applicable law.
Your privacy and patient rights
Depending on your location and relationship with Zenthea, you may have rights to request access, correction, deletion, restriction, portability, or objection, and to withdraw consent or appeal a denied request. These rights may be limited by healthcare-record retention, legal, security, or other permitted exceptions. Patients seeking PHI should contact their healthcare practice, which controls the medical record; Zenthea will assist the practice as required by the BAA. You may also have the right to complain to a privacy or data-protection authority without retaliation.
Requests and contact
To make a privacy request or ask a question, email info@zenthea.ai. Describe the request and your relationship to Zenthea, but do not include clinical details or other PHI in ordinary email. We may need to verify your identity and authority before responding. If Zenthea processes the data for a healthcare practice, we may direct the request to that practice.
Changes to this policy
We may update this policy as our services or legal obligations change. We will post the revised version here with a new effective date and provide additional notice when required.