Zoren AI
Data Policy
This Data Policy describes the technical and organizational measures Zoren, Inc. uses to classify, store, secure, and retain data processed through Zoren AI (the “Service”), including protected health information (“PHI”) processed as a HIPAA business associate. It supplements, and does not replace, our Privacy Policy and the Business Associate Agreement or other agreement in place with a Customer, which control in the event of any conflict.
1. Purpose & audience
This policy is written for Customer security and compliance reviewers, procurement teams, and auditors who need detail beyond what a consumer-facing privacy policy typically covers.
2. Data classification
| Category | Examples | Handling |
|---|---|---|
| Protected Health Information (PHI) | Patient demographics, insurance details, clinical/prescription data submitted for PA processing, and call recordings and transcripts from voice features | Governed by HIPAA and the applicable Customer BAA; encrypted in transit and at rest; access limited to authorized roles |
| Personally Identifiable Information (PII) — non-PHI | User account name, work email, organization | Governed by this policy and our Privacy Policy |
| Credentials & secrets | Passwords, integration API keys, session tokens | Stored using industry-standard hashing/encryption; never logged or displayed in plaintext |
| De-identified / aggregate data | Usage metrics, aggregated workflow statistics | De-identified to the HIPAA standard before use for analytics and product improvement; never re-identified |
3. Storage & encryption
- Data is encrypted in transit using TLS.
- Data at rest is encrypted using our infrastructure providers’ encryption-at-rest capabilities.
- Designated PHI fields and integration credentials are additionally encrypted at the application layer, using keys managed separately from the database.
- Our production environment is hosted in the United States on Microsoft Azure, and our primary database runs on Neon in the United States.
4. Access controls
Access to production systems and Customer Data is limited to authorized personnel on a least-privilege basis, role-based within the Service for Customer end users, and subject to authentication requirements, including multi-factor authentication available for user accounts. Administrative access to production infrastructure is logged and periodically reviewed.
5. Multi-tenant isolation
The Service is a multi-tenant platform operating on a shared database with organization-scoped isolation enforced in application logic, access-control checks, and database row-level security, so that one Customer organization’s data is not visible to another. Platform-level administrative roles that can span organizations are restricted and audited.
6. Sub-processors & integrations
We use the following sub-processors to provide the Service. The authoritative list is Exhibit A of our Business Associate Agreement.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google LLC (Google Cloud Vertex AI) | AI model inference through Vertex AI (primary provider; real-time voice agent) | United States |
| Anthropic, PBC | AI model inference (drafting, extraction, review; fallback provider) | United States |
| OpenAI, L.L.C. | AI model inference (document and fax OCR; voice transcription, speech, and embeddings) | United States |
| Microsoft Corporation (Azure) | Application hosting, document storage, and call recordings | United States |
| Neon (managed PostgreSQL) | Primary database | United States |
| Cloudflare, Inc. | DNS, CDN, WAF, TLS termination | Global edge network |
| Salesforce, Inc. | Customer relationship management synchronization, where enabled by a Customer | Customer's Salesforce instance |
| Twilio Inc. | SMS notifications and voice calling | United States |
| Cisco Systems, Inc. (Webex Calling) | Webex Calling interconnection for voice features | United States |
| MetroFax; iFax | Inbound and outbound fax | United States |
| Google LLC (Workspace) | Email transmission and platform mailbox | United States |
| Functional Software, Inc. (Sentry) | Error tracking and monitoring | United States |
| DigitalRx / DBS | Pharmacy dispense data synchronization | United States |
At a Customer’s direction, the Service also interacts with payer and utilization-management portals, such as CoverMyMeds, to submit and track prior-authorization requests. Voice calls are handled by Asterisk, open-source software we operate within our own hosting environment.
7. Retention
We retain Customer Data, including PHI, for as long as a Customer uses the Service, and we do not automatically delete it. Audit logs are retained for at least six (6) years.
When a Customer’s agreement ends, Customer Data remains available for export for thirty (30) days. After that, we keep the PHI we need to operate and administer our business — records of the services we provided, billing and financial records, audit and security logs, and records needed to handle complaints, claims, disputes, legal obligations, and regulatory inquiries — together with any PHI that cannot feasibly be returned or destroyed. That PHI stays protected under the Business Associate Agreement and is used only for those purposes; the rest is returned or destroyed. De-identified information is not PHI and may be retained indefinitely.
8. Audit logging
We maintain audit logs of access to and material changes affecting Customer Data and PHI, including authentication events and administrative actions, to support security monitoring and compliance obligations under HIPAA and applicable Customer agreements.
9. Breach notification
If we discover an impermissible use or disclosure of PHI or a successful security incident affecting PHI, we will report it to the affected Customer without unreasonable delay and within ten (10) business days of discovery, and supplement that report as our investigation continues, as set out in the Business Associate Agreement and as required by the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–414).
10. Data subject requests
Because Customers generally control the PHI and other personal information submitted to the Service, requests from patients or other individuals to access, correct, or delete their information should be directed to the relevant Customer (healthcare provider or pharmacy) in the first instance. We will support our Customers in fulfilling such requests as required by the applicable BAA or Customer agreement.
11. Security reporting
If you believe you have discovered a security vulnerability in the Service, please report it to [email protected]. Please do not access patient data, degrade the Service, or publicly disclose the issue before we have had a reasonable opportunity to address it.
12. Changes to this policy
We may update this Data Policy from time to time to reflect changes in our architecture, sub-processors, or legal obligations. Material changes will be reflected in the “Last updated” date above.
13. Contact us
Questions about this Data Policy can be sent to [email protected] or to Zoren, Inc., 2615 N. Greenbrier, Santa Ana, CA 92706.