Zen Health Logo
LEGAL & GOVERNANCE

Privacy Policy

This Privacy Policy explains how Zen Health collects, processes, and protects clinical trial data, patient observations, and health information when you interact with our website, platform, and safety governance services.

Last Updated: August 2026

01

Information We Collect & Ingest

We collect information submitted voluntarily through briefing requests, contact forms, and partnership inquiries (including your name, work email address, organization type, and message details). For biopharma sponsors, CROs, and clinical trial sites using the Zen Health Safety Governance Platform, clinical data—including adverse event reports, vital signs, lab trends, and encounter records—is ingested strictly via authorized FHIR R4 API connectors, EDC integrations, or encrypted flat-file uploads.
02

How We Use Information & Zero-AI-Training Guarantee

We use submitted contact information to respond to inquiries, execute clinical partnerships, and provide safety governance updates. Within the platform, clinical observations are processed to generate AI-assisted predictive risk scores and draft SAE narratives for physician review. Zero-AI-Training Guarantee: Protected Health Information (PHI) and proprietary clinical data are processed exclusively in tenant-isolated enterprise environments. Patient data is never used to train third-party, commercial, or foundation AI models.
03

Patient Identity Resolution & De-Identification

Clinical data ingested from connected EHR/EDC systems undergoes automatic pseudonymization at the Master Patient Index (MPI) boundary. Direct patient identifiers (MRNs, names, addresses) are encrypted and isolated. AI triage modules operate solely on pseudonymized patient keys. Unmasked identity access is restricted to credentialed physician reviewers of record and authorized site staff under strict role-based access controls (RBAC).
04

21 CFR Part 11 Audit Trail Integrity & Data Retention

In compliance with 21 CFR Part 11 and EU Annex 11, every physician sign-off, decision confirmation, or override rationale creates an immutable, tamper-evident audit record. Clinical trial audit trails are retained in accordance with FDA GCP recordkeeping requirements (or sponsor-defined retention schedules) and are exported on demand.
05

Data Security, Encryption & Compliance Standards

Zen Health enforces rigorous physical, technical, and administrative security controls. All data at rest is encrypted using AES-256, and data in transit is protected using TLS 1.3 encryption. Platform infrastructure operates under HIPAA Business Associate Agreements (BAAs) and GDPR Data Processing Agreements (DPAs).
06

Cookies & Website Analytics

Our marketing website uses essential cookies solely to support basic navigation and secure form processing. We do not sell user data, nor do we employ cross-site tracking cookies or third-party behavioral profiling.
07

Contact Information

For questions regarding this Privacy Policy, data privacy rights, or clinical compliance documentation, please contact our team.

Have questions about our data security architecture?

Schedule a technical deep-dive with our compliance and engineering team.