1. Overview & Applicability
ZettaHealth Solutions Inc. ("ZettaHealth", "we", "us", or "our") respects your privacy and is committed to safeguarding personal information collected through our commercial website located at zettahealth.ai (the "Site").
ZettaHealth maintains technical, operational, and policy controls designed to support applicable U.S. privacy, commercial communications, accessibility, web security, cookie-consent, and healthcare-data obligations. These controls are enforced through automated testing, deployment safeguards, data-retention controls, and periodic applicability review.
This Privacy Policy describes our practices regarding the collection, processing, storage, disclosure, and protection of information gathered when you visit, browse, or submit commercial inquiries through this Site.
Website-Only Scope: This Privacy Policy applies strictly to interactions with this public marketing and informational website. Any procurement, subscription, access to, or use of separate enterprise environments designed to support HIPAA-regulated workflows where ZettaHealth acts as a business associate or otherwise has applicable HIPAA obligations is governed by separate, formally executed written Master Services Agreements (MSAs), Business Associate Agreements (BAAs), or commercial licensing agreements entered into directly with our enterprise clients.
This Site is operated exclusively as a commercial business-to-business (B2B) informational and marketing website. ZettaHealth Solutions Inc. is a commercial technology vendor and is not a healthcare provider, covered entity, medical practice, or emergency medical dispatch service. We do not provide clinical medical care, diagnosis, or patient services via this Site. We do not collect, solicit, or process Protected Health Information (PHI) governed by the Health Insurance Portability and Accountability Act (HIPAA) on zettahealth.ai. Visitors, prospective clients, and partners should not submit patient medical records, diagnostic imaging, or clinical PHI through this Site.
California Notice at Collection
Pursuant to the California Consumer Privacy Act (as amended by the California Privacy Rights Act, "CCPA/CPRA") and applicable U.S. state privacy laws, this Notice at Collection informs you of the categories of personal information collected through our public website, the business or commercial purposes for collection, whether each category is sold or shared, retention periods, and your rights:
| Category of Personal Information | Business Purpose | Sold / Shared Status | Retention Period |
|---|---|---|---|
| Identifiers (Name, Work Email, Phone, Organization Name) | To respond to inquiries, schedule product demonstrations, and communicate regarding requested services. |
Sold: No.
Shared for cross-context behavioral advertising: ZettaHealth does not intentionally use form-submission information for cross-context behavioral advertising. Certain analytics technologies applied to general browsing data may constitute "sharing" or targeted advertising under some state privacy laws as described in the Cookies and Tracking Technologies section.
|
90 days from inquiry receipt (organizational data minimization baseline) |
| Commercial Information (Inquiry Details, Solutions of Interest) | To qualify prospective enterprise customer requests and route to product specialists. |
Sold: No.
Shared for cross-context behavioral advertising: No. Commercial inquiry information submitted through forms is used exclusively for prospective customer qualification and service delivery.
|
90 days from inquiry receipt |
| Internet / Network Activity (Pseudonymized IP Hash, User Agent, Referrals, Analytics Telemetry) | To maintain cybersecurity, prevent automated form abuse, and analyze aggregated website traffic patterns. |
Sold: No.
Shared for cross-context behavioral advertising: Standard web measurement tags (Google Analytics) on general browsing sessions may be classified as "sharing" or targeted advertising under broad state privacy law definitions. Deployed only after affirmative consent and strictly honors Global Privacy Control (GPC) signals.
|
IP hashes rotate daily; Google Analytics aggregated telemetry expires per 14-month retention settings |
| DSAR & Privacy Compliance Records | To document consumer privacy requests and substantiate statutory compliance with legal obligations (11 CCR § 7101). |
Sold: No.
Shared for cross-context behavioral advertising: No. Stored strictly in isolated, pseudonymized compliance audit records.
|
Retained for at least 24 calendar months pursuant to 11 CCR § 7101 |
ZettaHealth maintains a strict operational and technical boundary between directly submitted B2B webform information and passive website browsing telemetry. Personal data submitted through webforms (such as your name, work email, organization, and inquiry text) is transmitted directly to our secure database and is never shared with third-party advertising networks, data brokers, or profiling engines. Passive website telemetry (such as cookies or Google Analytics measurement) applies exclusively to general website navigation, operates only after affirmative cookie consent, and is immediately suppressed when a Global Privacy Control (GPC) signal is detected.
To exercise your privacy rights, click or view our U.S. State Privacy Rights section below.
2. Information We Collect
We collect information directly from you when you provide it, as well as automatically through your navigation of our Site:
A. Directly Provided Contact Data
- Contact Details: Full name, business email address, direct telephone number, organization/practice name.
- Commercial Inquiries: Inquiries, consultation topics, or demonstration requests voluntarily submitted through website contact and inquiry forms.
B. Automatically Collected Technical Data
- Server & Network Logs: Client IP address, browser user-agent, operating system, timestamp, HTTP request headers, and routing latency.
- Aggregated Usage Metrics: Pages visited, duration of visit, referral URLs, and performance telemetry via Google Analytics, subject to your cookie preferences.
- Local Storage State: User interface preferences, session state, and your recorded cookie consent choices.
3. How We Use Personal Information
We process your personal information only for legitimate operational and business purposes:
- To respond to your inquiries, schedule demonstrations, and facilitate business communications.
- To transmit automated confirmation emails and notifications regarding your contact form submissions.
- To diagnose technical errors, optimize page load speed, and protect our infrastructure from automated spam, security breaches, or unauthorized access attempts.
- To fulfill legal, audit, regulatory, and compliance obligations under applicable law.
5. Global Privacy Control (GPC)
We recognize and automatically honor the Global Privacy Control (GPC) signal broadcasted by modern web browsers and privacy extensions. When our website detects an active GPC signal (navigator.globalPrivacyControl === true), our tracking management system immediately:
- Opts you out of optional analytics tracking (Google Analytics).
- Opts you out of third-party advertising cookies and cross-context behavioral tracking.
- Treats your session as a request to opt out of the sale or sharing of personal data under applicable state statutes.
6. U.S. State Privacy Rights & Consumer Controls
ZettaHealth implements privacy controls designed to support applicable U.S. state privacy requirements (including California CCPA/CPRA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and Utah UCPA). While ZettaHealth operates primarily as a specialized B2B healthcare technology vendor and may fall below certain statutory revenue or data volume thresholds, we voluntarily extend robust consumer privacy choices to all visitors:
When you submit a consumer privacy request (Access, Correct, Delete, or Opt-Out), our compliance team executes the following documented operational workflow:
- Intake & Verification: We verify the requestor's identity or authorized agent credentials to prevent unauthorized data exposure.
- Operational Action: Active inquiry records are exported, updated with recalculated integrity signatures, or permanently purged.
- Downstream Notification: Where applicable under statute, downstream service providers and contractors are instructed to mirror the action.
- Response & Explanation: The consumer receives a written confirmation of the action taken (or an explanation if a statutory exception applies).
- 24-Month Compliance Log: A minimal, pseudonymized audit record of the request, timestamp, and disposition is preserved in our dedicated compliance log for at least twenty-four (24) months to satisfy statutory recordkeeping requirements under California regulations, completely separate from our 90-day operational inquiry retention schedule.
To submit a verified consumer request (Access, Correct, Delete, or Opt-Out), click , visit our Communication Preferences page, or email our compliance team at legal@zettahealth.co.
7. Security Standards and Engineering Controls
Our security architecture is informed by OWASP application-security guidance and applicable NIST security-control principles. Technical safeguards include TLS 1.3 in-transit encryption, strict Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), automated rate limiting, and HMAC-SHA256 authenticated tokens.
ZettaHealth does not retain visitor IP addresses in plaintext. IP addresses used for abuse prevention and rate-limiting are pseudonymized using a salted cryptographic hash with daily rotating salts.
As an organizational retention decision supporting data minimization principles, commercial inquiry submissions received through our public website contact forms are automatically purged after ninety (90) days unless active business or contractual negotiations are underway. Aggregated, non-identifying telemetry logs in Google Analytics expire according to standard 14-month retention settings.
This public marketing website (zettahealth.ai) maintains a strict architectural boundary separating it from separate enterprise environments designed to support HIPAA-regulated workflows where ZettaHealth acts as a business associate or otherwise has applicable HIPAA obligations. The public website is not designed to receive or process Protected Health Information (PHI) under HIPAA, and no Business Associate Agreement (BAA) applies to submissions made through public website contact forms.
ZettaHealth maintains a recurring compliance protocol to re-evaluate CCPA applicability, cybersecurity-audit thresholds, and other state privacy-law thresholds annually based on the prior year's revenue and processing volumes.
8. Cross-Border Data Transfers (GDPR / International Visitors)
The Site at zettahealth.ai is hosted, administered, and operated within the United States. If you visit or interact with this Site from the European Economic Area (EEA), the United Kingdom, Switzerland, or any other jurisdiction outside the United States, please be aware that personal information you voluntarily submit will be transferred to, stored, and processed in the United States where data protection standards may differ from those in your home jurisdiction. By submitting inquiries or browsing this Site, you acknowledge this transfer, storage, and processing in accordance with this Privacy Policy.
9. Children's Privacy (COPPA)
The Site at zettahealth.ai is an enterprise B2B website designed exclusively for commercial business professionals and is intended for use by individuals aged 18 and older. We do not knowingly solicit, collect, or maintain personal information from individuals under 18 years of age. If we learn that personal data of a minor under 18 has been collected on the Site, we will promptly delete that information.
10. Contact Our Privacy Officer
If you have questions, comments, or requests regarding this Privacy Policy or your data protection rights, please contact our compliance department:
ZettaHealth Solutions Inc.
Attention: Legal & Compliance Department
Toll-Free Phone: (877) 380-6499
Email: legal@zettahealth.co
Business Hours: Monday – Friday 9:00 AM – 5:00 PM EST