Skip to main content
Privacy Policy

How we collect, process, and protect data.

Built for GDPR, India's DPDP Act 2023, and CCPA/CPRA compliance. Effective 13 May 2026.

Policy version

v1.0 — May 2026

Covers consent, retention, data rights, international transfers, and AI processing disclosures.

1. Identity and contact information

ZoetiCoach is operated by Balaji Enterprises (referred to as "we", "us", or "our"), registered in India. We act as the data controller for coach account data and as a data processor for client personal data uploaded or submitted by coaches. For all privacy matters, contact us via the contact form on this website or by writing to our registered address. We will respond to all verifiable requests within 30 days.

2. Scope and applicability

This Privacy Policy applies to all personal data processed through the ZoetiCoach platform, including our web application, WhatsApp messaging integrations, and any associated APIs. It applies to coaches (account holders), their clients (end-users who interact via WhatsApp), and visitors to our marketing website. This policy is effective as of 13 May 2026 and supersedes all prior privacy notices.

3. Data we collect

We collect and process the following categories of personal data:

  • Coach account data: name, email address, mobile number, business name, time zone, and subscription tier.
  • Client contact data: name, WhatsApp phone number, and any profile information provided by the coach during onboarding.
  • Plan content: fitness, nutrition, wellness, or coaching plans uploaded by coaches as PDF or text documents.
  • Check-in interaction data: message content, timestamps, and session identifiers for WhatsApp conversations.
  • Usage and analytics data: page visits, feature interactions, session durations, and browser/device metadata.
  • Billing data: subscription tier, billing cycle, and payment transaction metadata (we do not store sensitive card or banking credentials; payments are securely processed by Razorpay).
  • Support communications: messages sent to us via contact forms, email, or in-app support channels.
  • Safety and crisis audit logs: timestamped, append-only records of intercepted off-plan, supplement, medication, clinical, or crisis queries routed to the human coach for verification.

4. Purposes and lawful bases for processing

We process personal data only where we have a valid lawful basis. The primary purposes and corresponding lawful bases are:

  • Service delivery — running messaging schedules, processing WhatsApp check-ins, and generating AI-assisted responses. Lawful basis: performance of a contract (GDPR Art. 6(1)(b)); legitimate business purpose (DPDP Act 2023 §7).
  • Coach dashboard analytics — computing adherence scores, streak metrics, and intervention signals. Lawful basis: contract performance and legitimate interests (GDPR Art. 6(1)(f)).
  • Plan ingestion and AI processing — chunking, embedding, and indexing uploaded plan documents for retrieval-augmented generation. Lawful basis: contract performance; explicit consent where plans contain health data (GDPR Art. 9(2)(a)).
  • Safety escalation and audit logging — intercepting medication, clinical, acute distress, or off-plan exceptions to halt automated AI generation and alert the human coach with an audit trail. Lawful basis: vital interests of data principals (GDPR Art. 6(1)(d)) and legitimate safety compliance (DPDP Act 2023 §7).
  • Billing and subscription management — invoicing, failed payment handling, and subscription lifecycle events. Lawful basis: contract performance and legal obligation.
  • Security and fraud prevention — detecting misuse, rate-limiting, and access control enforcement. Lawful basis: legitimate interests (GDPR Art. 6(1)(f)).
  • Legal compliance — responding to lawful requests from regulators, courts, or law enforcement. Lawful basis: legal obligation (GDPR Art. 6(1)(c)).
  • Marketing communications to coaches — product updates, feature announcements, and usage tips. Lawful basis: consent or legitimate interests with opt-out.

5. Data sharing and disclosure

We do not sell personal data. We share data only in the following circumstances:

  • Sub-processors: Meta Cloud API (WhatsApp messaging), OpenAI Enterprise (AI response generation under no-training agreement), Razorpay (payment processing & subscriptions), Cloudflare & AWS (cloud infrastructure, CDN & encrypted storage), Resend (transactional email), Google Cloud (authentication & anonymous telemetry), and Fitbit Web API (optional wearable sync). Each sub-processor is bound by an executed Data Processing Agreement (DPA) and enterprise security standards.
  • Coaches: Coaches have access to their own clients' check-in data, adherence metrics, and interaction logs through the coach dashboard. Coaches are independently responsible for handling this data in accordance with their own privacy obligations to clients.
  • Legal disclosure: We may disclose data where required by applicable law, court order, or to protect the rights, property, or safety of ZoetiCoach, our users, or the public.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction, subject to equivalent privacy protections.

6. International data transfers

ZoetiCoach is operated from India. Client and coach data may be transferred to and processed in countries outside the European Economic Area (EEA) and India, including the United States, where our sub-processors operate. For transfers from the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. For transfers under the DPDP Act 2023, we comply with cross-border transfer restrictions as notified by the Government of India. We maintain a current list of sub-processors and the countries where they process data, available on request.

7. Retention periods

We retain personal data only for as long as necessary for the stated purpose or as required by law:

  • Active coach accounts: data retained for the lifetime of the account plus 90 days post-closure for dispute resolution.
  • Client check-in and interaction data: retained for 24 months from the date of the last interaction, or until the coach deletes the client record.
  • Plan content (embeddings and source files): retained for the lifetime of the coach account; deleted within 30 days of account closure.
  • Billing records: retained for 7 years to comply with Indian accounting standards and GST requirements.
  • Support communications: retained for 3 years from resolution.
  • Usage analytics: aggregated and anonymised after 13 months; raw event logs deleted within 90 days.

8. Your rights under GDPR (EEA users)

If you are located in the European Economic Area, you have the following rights under the General Data Protection Regulation:

  • Right of access (Art. 15): request a copy of personal data we hold about you.
  • Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): request deletion of your data where there is no overriding legal ground for retention.
  • Right to restriction of processing (Art. 18): request that we limit processing in certain circumstances.
  • Right to data portability (Art. 20): receive your data in a structured, machine-readable format.
  • Right to object (Art. 21): object to processing based on legitimate interests, including profiling.
  • Rights related to automated decision-making (Art. 22): you will not be subject to decisions based solely on automated processing that produce significant legal effects without human review.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint with a supervisory authority: you may contact your local data protection authority if you believe your rights have been violated.

9. Your rights under DPDP Act 2023 (Indian users)

If you are located in India, the Digital Personal Data Protection Act 2023 grants you specific statutory rights as a Data Principal:

  • Right to information (§11): obtain a summary of the personal data processed and processing activities undertaken.
  • Right to correction and erasure (§12): request correction of inaccurate data, and erasure of data no longer necessary for coaching workflows.
  • Right of grievance redressal (§13): reach our designated Data Protection & Grievance Officer directly (details below) for prompt resolution.
  • Right to nominate (§14): nominate another individual to exercise rights in the event of death or incapacity.
  • Right to withdraw consent (§6): withdraw consent at any time; active messaging schedules will cease within 24 hours.
  • Designated Grievance Officer: Ashish Gupta, Grievance Officer, Balaji Enterprises, India. Email: grievance@zoeticoach.com (Full contact & postal details in Section 17). All grievances are acknowledged within 24 hours and redressed within 15 working days.

10. Your rights under CCPA/CPRA (California users)

If you are a California resident, the California Consumer Privacy Act (as amended by CPRA) provides the following rights:

  • Right to know: request disclosure of the categories and specific pieces of personal information collected, the sources, the business purpose, and third parties with whom it is shared.
  • Right to delete: request deletion of personal information, subject to certain exceptions.
  • Right to correct: request correction of inaccurate personal information.
  • Right to opt out of sale or sharing: we do not sell or share personal information for cross-context behavioural advertising.
  • Right to limit use of sensitive personal information: you may direct us to limit use of sensitive personal information to necessary service purposes.
  • Right to non-discrimination: exercising your CCPA rights will not result in discriminatory treatment.
  • To submit a verifiable consumer request, use the contact form and include "CCPA Request" in your message.

12. Strictly adult-only (18+ policy)

ZoetiCoach is strictly an adult-only platform for individuals aged 18 and older. We do not provide services to, onboard, or knowingly collect personal data from minors (anyone under 18 years of age). Coaches are strictly prohibited from onboarding clients under 18 onto ZoetiCoach. The Platform does not support verifiable parental consent mechanisms because minors are completely prohibited from using the service. If we discover or are notified that personal data belonging to an individual under 18 has been collected or processed, we will immediately terminate the associated client profile and permanently delete all related records. If you suspect an individual under 18 has been onboarded, please contact our Grievance Officer immediately at grievance@zoeticoach.com.

13. Security measures

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our measures include:

  • Encryption in transit (TLS 1.3) for all data exchanged between clients, coaches, WhatsApp, and our servers.
  • Encryption at rest for all stored personal data and plan embeddings.
  • Tenant isolation: each coach's data is scoped to their tenant context; cross-tenant access is prevented at the application and database level.
  • Role-based access control (RBAC) limiting internal team access to personal data on a need-to-know basis.
  • Webhook signature verification for all inbound WhatsApp messages.
  • Automated vulnerability scanning and dependency updates.
  • We will notify affected parties and relevant supervisory authorities of a personal data breach within 72 hours of becoming aware of it, where required by law.

14. Cookies and tracking technologies

Our marketing website uses cookies and similar tracking technologies. Strictly necessary cookies are set automatically for authentication and security. Analytics cookies require your consent and collect anonymised usage statistics. You can manage or customize your cookie preferences at any time via the Cookie Preferences link in our website footer. We do not use third-party advertising cookies or cross-site tracking.

15. AI-assisted processing

ZoetiCoach uses large language models (LLMs) provided by OpenAI and/or Anthropic to generate check-in responses grounded in uploaded plan content. The following disclosures apply:

  • Client messages and relevant plan fragments are transmitted to the LLM provider's API for response generation. These transmissions are governed by the provider's data processing agreements, which prohibit training on API-submitted data.
  • Non-Clinical Boundary & SaMD Disclaimer: ZoetiCoach is non-clinical software and is not Software as a Medical Device (SaMD) or telemedicine under India's Telemedicine Practice Guidelines 2020. The Platform never diagnoses, prescribes, or alters clinical parameters.
  • Mandatory Human Oversight & Audit Logging: Any inquiries concerning prescription medications, anabolic substances, clinical symptoms, physical injuries, or off-plan deviations automatically halt AI generation and route to the human coach with audit logging.
  • AI-generated responses are reviewed against guardrails before delivery and are intended as administrative habit accountability only. They do not constitute medical, nutritional, psychological, or professional advice.
  • Coaches remain responsible for the appropriateness and accuracy of all communications sent to their clients.
  • Clients are informed at onboarding that responses may be AI-assisted.
  • We do not use client data to train or fine-tune AI models without explicit, separate consent.

16. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. We will notify coaches of material changes by email at least 14 days before the change takes effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy. The current version and effective date are displayed at the top of this page. For historical versions, contact us.

17. Grievance redressal and statutory contact details

In accordance with the Digital Personal Data Protection Act 2023 and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the contact details of the designated Grievance & Data Protection Officer are provided below:

  • Name & Designation: Ashish Gupta, Grievance Officer & Data Protection Lead
  • Entity: Balaji Enterprises
  • Postal Address: Balaji Enterprises, First Floor, Shop No. 15, Guru Nanak Colony, B/S Mirado, Near Gill Nehar, Ludhiana, Punjab - 141006, India
  • Email: grievance@zoeticoach.com (Support inquiries: support@zoeticoach.com)
  • Response SLA: Acknowledgment within 24 hours; resolution within 15 working days from receipt.

Need help with a data request, consent withdrawal, or a rights exercise? Contact our privacy team.