Your clients' data is sacred.
We treat it that way.
ZoetiCoach is engineered consent-first under India’s Digital Personal Data Protection (DPDP) Act 2023 principles, featuring strict tenant isolation, zero AI model training, and industry-standard TLS 1.3 in transit and AES-256 encryption at rest.
Tenant UUID schema & vector partition
No-training policy with AI providers
TLS 1.3 with Perfect Forward Secrecy
Security incident response & notification commitment
How Client Data Travels Securely
From WhatsApp message to plan-grounded AI guidance: every step is cryptographically verified, isolated by tenant, and guarded by human signoff.
WhatsApp Inbound
Client check-in, meal photo, or question arrives over TLS 1.3 with cryptographic HMAC-SHA256 signature verification.
Tenant Isolation Gate
Routing middleware authenticates coach tenant UUID. Cross-tenant access is architecturally impossible at the database layer.
Plan-Grounded RAG
Vector retrieval queries strictly the coach’s verified protocols. Public internet search and unverified data are disabled.
Safety Guardrail Gate
Prescription drugs, injury keywords, or off-plan queries trigger an instant safety hold and route to coach WhatsApp for signoff.
Audited Delivery
Plan-cited reply delivers to client WhatsApp. An immutable, append-only consent and interaction log is updated.
WhatsApp Inbound
Client check-in, meal photo, or question arrives over TLS 1.3 with cryptographic HMAC-SHA256 signature verification.
8 Pillars of Data Protection & AI Safety
Built specifically for high-touch coaches and wellness practices holding confidential health, diet, and lifestyle information.
We Never Train AI on Your Data
Client conversations and uploaded plans are processed strictly in real time under no-training policies with AI providers. Your data never enters public LLM training weights.
Consent-First (DPDP Act 2023)
Every client explicitly confirms opt-in on WhatsApp before automated daily check-ins begin, with timestamped consent logs and 1-tap instant revocation via STOP.
Your Data, Your Control
Full data sovereignty. Download a standardized JSON/CSV export of all client records, check-in histories, and adherence logs anytime, or permanently wipe your account in 1 click.
Your Rights Under the DPDP Act 2023
Every client and coach on ZoetiCoach possesses direct, enforceable statutory rights under Indian personal data protection law:
Right to Access & Portability
Section 11Right to obtain a summary of personal health and interaction data being processed by ZoetiCoach on behalf of your practice.
Right to Correction & Updating
Section 12(1)Right to rectify, correct, and update inaccurate, incomplete, or outdated personal health, macro, and workout metrics.
Right to Complete Erasure
Section 12(3)Right to complete cryptographic erasure of personal data that is no longer necessary for coaching services.
Right to Grievance Redressal
Section 13Right to readily available means of grievance redressal in respect of any personal data processing or privacy matter.
Authorized Sub-Processors
We maintain executed Data Processing Agreements (DPAs) with enterprise infrastructure providers meeting ISO 27001, SOC 2, or RBI requirements:
Enterprise WhatsApp message delivery, template triggers & webhook ingress
Plan-grounded semantic reasoning under enterprise zero-data-retention & no-training policy
PCI-DSS Level 1 payment gateway & subscription billing management
DDoS mitigation, edge CDN, SSL termination, compute & encrypted PostgreSQL storage
Transactional email delivery for account verifications, password resets & billing receipts
OAuth sign-in authentication & privacy-preserving anonymous telemetry
Optional client wearable biometric synchronization (steps, sleep, heart rate) upon explicit client OAuth consent
Frequently Asked Security Questions
Straightforward answers regarding client confidentiality, AI safety boundaries, and compliance.
Never. ZoetiCoach uses AI providers under no-training policies. Your uploaded documents, client check-in messages, and photos are processed in real time to generate replies. They are never stored for model fine-tuning, training, or shared across any other accounts.
ZoetiCoach enforces strict tenant isolation across all layers: database tables, vector indices, and API middleware. Every query is partitioned by your unique tenant UUID. It is architecturally impossible for another coach to query, view, or reference your plans or client data.
Our multi-stage safety guardrail immediately intercepts clinical queries, prescription drugs, anabolic substances, and acute injury keywords. The assistant refuses to diagnose or recommend unauthorized substances, sends a courteous holding message to the client, and notifies you directly via WhatsApp with an editable approval draft.
No. ZoetiCoach is administrative habit accountability and client communication software. It is explicitly not a medical device (SaMD) and does not provide telemedicine under India’s Telemedicine Practice Guidelines 2020. The system never diagnoses diseases, never alters clinical parameters, and automatically escalates all medical, supplement, medication, and off-plan inquiries to the human coach with audit logging.
Before any automated check-in begins, clients receive an official WhatsApp opt-in utility template explaining what data is logged and how their coach uses it. The client explicitly agrees before automation begins. Clients can reply STOP at any moment to immediately withdraw consent and halt all messaging.
Yes. You maintain 100% data sovereignty. You can generate and download a comprehensive export of all your client records, check-in histories, and adherence scores in CSV or JSON at any time from your Settings dashboard.
We publish an RFC 9116 compliant security disclosure policy at /.well-known/security.txt. Security researchers and compliance auditors can reach our security response team directly at security@zoeticoach.com.
Authorized Sub-Processors
We engage the following sub-processors under executed Data Processing Agreements (DPAs). Each is bound by enterprise-grade security and data minimization obligations.
| Processor | DPA Status |
|---|---|
| Meta / WhatsApp Cloud APIEnterprise WhatsApp message delivery, template triggers & webhook ingress | Executed (Meta Business DPA) |
| OpenAI EnterprisePlan-grounded semantic reasoning under enterprise zero-data-retention & no-training policy | Executed (OpenAI Business DPA) |
| Razorpay SoftwarePCI-DSS Level 1 payment gateway & subscription billing management | Executed (Razorpay Merchant Terms & DPA) |
| Cloudflare & AWSDDoS mitigation, edge CDN, SSL termination, compute & encrypted PostgreSQL storage | Executed (Cloudflare & AWS DPAs) |
| ResendTransactional email delivery for account verifications, password resets & billing receipts | Executed (Resend DPA) |
| Google Cloud & Google IdentityOAuth sign-in authentication & privacy-preserving anonymous telemetry | Executed (Google Cloud DPA) |
| Fitbit Web APIOptional client wearable biometric synchronization (steps, sleep, heart rate) upon explicit client OAuth consent | Executed (Fitbit Platform Agreement) |
Data Protection & Grievance Officer
Operated by Balaji Enterprises (Ludhiana, Punjab, India). In accordance with the Digital Personal Data Protection Act 2023, our designated Grievance Officer handles privacy audits, DPA requests, and subject rights inquiries.
