Skip to main content
Built for DPDP (DPDP-Ready) · Zero AI Training

Your clients' data is sacred. We treat it that way.

ZoetiCoach is engineered consent-first under India’s Digital Personal Data Protection (DPDP) Act 2023 principles, featuring strict tenant isolation, zero AI model training, and industry-standard TLS 1.3 in transit and AES-256 encryption at rest.

100%
Isolated Tenancy

Tenant UUID schema & vector partition

0 Days
Zero Model Training

No-training policy with AI providers

TLS 1.3
Encrypted Transit

TLS 1.3 with Perfect Forward Secrecy

Rapid
Incident Notification

Security incident response & notification commitment

Zero-Trust Architecture

How Client Data Travels Securely

From WhatsApp message to plan-grounded AI guidance: every step is cryptographically verified, isolated by tenant, and guarded by human signoff.

STEP 01 OF 05

WhatsApp Inbound

Meta Cloud API

Client check-in, meal photo, or question arrives over TLS 1.3 with cryptographic HMAC-SHA256 signature verification.

Verified Meta signature prevents spoofed webhooks.
Security Pillars

8 Pillars of Data Protection & AI Safety

Built specifically for high-touch coaches and wellness practices holding confidential health, diet, and lifestyle information.

Zero Model Training

We Never Train AI on Your Data

Client conversations and uploaded plans are processed strictly in real time under no-training policies with AI providers. Your data never enters public LLM training weights.

No-training policy with AI providers
Statutory Opt-In

Consent-First (DPDP Act 2023)

Every client explicitly confirms opt-in on WhatsApp before automated daily check-ins begin, with timestamped consent logs and 1-tap instant revocation via STOP.

Verified WhatsApp template consent ledger
1-Click Export & Wipe

Your Data, Your Control

Full data sovereignty. Download a standardized JSON/CSV export of all client records, check-in histories, and adherence logs anytime, or permanently wipe your account in 1 click.

1-Click JSON/CSV export & permanent wipe
Statutory Framework

Your Rights Under the DPDP Act 2023

Every client and coach on ZoetiCoach possesses direct, enforceable statutory rights under Indian personal data protection law:

Right to Access & Portability

Section 11

Right to obtain a summary of personal health and interaction data being processed by ZoetiCoach on behalf of your practice.

Available in Settings → Export Data (Instant JSON/CSV download)

Right to Correction & Updating

Section 12(1)

Right to rectify, correct, and update inaccurate, incomplete, or outdated personal health, macro, and workout metrics.

Available in Client Profile → Instant real-time roster sync

Right to Complete Erasure

Section 12(3)

Right to complete cryptographic erasure of personal data that is no longer necessary for coaching services.

Available in Settings → Delete Account (Permanent cryptographic wipe)

Right to Grievance Redressal

Section 13

Right to readily available means of grievance redressal in respect of any personal data processing or privacy matter.

Direct contact with Data Protection Officer (24h SLA)
Verified Infrastructure

Authorized Sub-Processors

We maintain executed Data Processing Agreements (DPAs) with enterprise infrastructure providers meeting ISO 27001, SOC 2, or RBI requirements:

Meta / WhatsApp Cloud APISingapore / US

Enterprise WhatsApp message delivery, template triggers & webhook ingress

ISO 27001SOC 2 Type IISOC 3
OpenAI EnterpriseUS / Global

Plan-grounded semantic reasoning under enterprise zero-data-retention & no-training policy

SOC 2 Type IIGDPR / DPDP AlignedCCPA Compliant
Razorpay SoftwareMumbai, India

PCI-DSS Level 1 payment gateway & subscription billing management

PCI-DSS Level 1ISO 27001RBI Authorized
Cloudflare & AWSMumbai, India / Global

DDoS mitigation, edge CDN, SSL termination, compute & encrypted PostgreSQL storage

ISO 27001SOC 2 Type IIMeitY Empanelled
ResendUS / Global

Transactional email delivery for account verifications, password resets & billing receipts

SOC 2 Type IIGDPR Compliant
Google Cloud & Google IdentityGlobal / US / India

OAuth sign-in authentication & privacy-preserving anonymous telemetry

ISO 27001SOC 2 Type IISOC 3
Fitbit Web APIUS / Global

Optional client wearable biometric synchronization (steps, sleep, heart rate) upon explicit client OAuth consent

ISO 27001SOC 2 Type IIHIPAA / HITRUST
Clarifications

Frequently Asked Security Questions

Straightforward answers regarding client confidentiality, AI safety boundaries, and compliance.

Never. ZoetiCoach uses AI providers under no-training policies. Your uploaded documents, client check-in messages, and photos are processed in real time to generate replies. They are never stored for model fine-tuning, training, or shared across any other accounts.

ZoetiCoach enforces strict tenant isolation across all layers: database tables, vector indices, and API middleware. Every query is partitioned by your unique tenant UUID. It is architecturally impossible for another coach to query, view, or reference your plans or client data.

Our multi-stage safety guardrail immediately intercepts clinical queries, prescription drugs, anabolic substances, and acute injury keywords. The assistant refuses to diagnose or recommend unauthorized substances, sends a courteous holding message to the client, and notifies you directly via WhatsApp with an editable approval draft.

No. ZoetiCoach is administrative habit accountability and client communication software. It is explicitly not a medical device (SaMD) and does not provide telemedicine under India’s Telemedicine Practice Guidelines 2020. The system never diagnoses diseases, never alters clinical parameters, and automatically escalates all medical, supplement, medication, and off-plan inquiries to the human coach with audit logging.

Before any automated check-in begins, clients receive an official WhatsApp opt-in utility template explaining what data is logged and how their coach uses it. The client explicitly agrees before automation begins. Clients can reply STOP at any moment to immediately withdraw consent and halt all messaging.

Yes. You maintain 100% data sovereignty. You can generate and download a comprehensive export of all your client records, check-in histories, and adherence scores in CSV or JSON at any time from your Settings dashboard.

We publish an RFC 9116 compliant security disclosure policy at /.well-known/security.txt. Security researchers and compliance auditors can reach our security response team directly at security@zoeticoach.com.

Transparency · DPDP Act 2023

Authorized Sub-Processors

We engage the following sub-processors under executed Data Processing Agreements (DPAs). Each is bound by enterprise-grade security and data minimization obligations.

ProcessorDPA Status
Meta / WhatsApp Cloud APIEnterprise WhatsApp message delivery, template triggers & webhook ingressExecuted (Meta Business DPA)
OpenAI EnterprisePlan-grounded semantic reasoning under enterprise zero-data-retention & no-training policyExecuted (OpenAI Business DPA)
Razorpay SoftwarePCI-DSS Level 1 payment gateway & subscription billing managementExecuted (Razorpay Merchant Terms & DPA)
Cloudflare & AWSDDoS mitigation, edge CDN, SSL termination, compute & encrypted PostgreSQL storageExecuted (Cloudflare & AWS DPAs)
ResendTransactional email delivery for account verifications, password resets & billing receiptsExecuted (Resend DPA)
Google Cloud & Google IdentityOAuth sign-in authentication & privacy-preserving anonymous telemetryExecuted (Google Cloud DPA)
Fitbit Web APIOptional client wearable biometric synchronization (steps, sleep, heart rate) upon explicit client OAuth consentExecuted (Fitbit Platform Agreement)
Built for DPDP (DPDP-Ready) · Statutory Readiness

Data Protection & Grievance Officer

Operated by Balaji Enterprises (Ludhiana, Punjab, India). In accordance with the Digital Personal Data Protection Act 2023, our designated Grievance Officer handles privacy audits, DPA requests, and subject rights inquiries.