How we collect, use, and protect your information.
Plain English summary: Zoonex AI collects only what is needed to provide the service. We never sell your data, run ads, or share it for marketing. Health-related query data is treated as equivalent to Protected Health Information under HIPAA. We comply with Maryland, federal US, and international privacy law.
Zoonex AI LLC ("Zoonex AI", "we", "us", "our") is a limited liability company registered in the State of Maryland, USA, with its principal office in Silver Spring, MD 20906.
We operate zoonexai.com — a One Health intelligence platform that synthesises evidence from 23 live biomedical databases for veterinary and public health professionals using AI.
Zoonex AI LLC is the data controller for personal data processed through our platform. Where applicable under HIPAA, we are prepared to enter into a Business Associate Agreement (BAA) with covered entities upon request.
Zoonex AI operates in compliance with the following laws and regulations. This policy is designed to satisfy all applicable requirements:
| Law / Regulation | Applicability to Zoonex AI |
|---|---|
| Federal HIPAA / HITECH (45 CFR Parts 160, 164) | Query data treated as PHI equivalent. Audit logging, encryption, access controls per § 164.312. |
| Federal FTC Act § 5 (15 U.S.C. § 45) | We do not engage in unfair or deceptive practices. AI outputs are clearly labelled as research tools, not medical advice. |
| Federal FTC Health Breach Notification Rule (16 CFR Part 318) | We notify consumers and the FTC within required timeframes of any health data breach. |
| Federal ACA § 1557 (Non-Discrimination) | Our AI systems do not use discriminatory clinical algorithms. No bias based on race, sex, age, disability, or national origin. |
| Federal COPPA (15 U.S.C. § 6501) | Platform is restricted to users 18+. We do not knowingly collect data from minors. |
| Federal FERPA | We do not process student education records. |
| Federal DOJ Data Security Rule (28 CFR Part 202) | We do not engage in bulk data transactions with foreign adversaries. Health data is not transferred to restricted countries. |
| Federal HHS AI Strategy 2025 | We align with HHS OneHHS AI principles: patient privacy, civil rights, civil liberties, and transparency in AI use. |
| Law | Applicability |
|---|---|
| Maryland Maryland Online Data Privacy Act (MODPA) — SB 541, effective Oct 1, 2025 | Full compliance. We do not sell sensitive data, we collect only data strictly necessary for the service, and we provide opt-out rights. |
| Maryland Maryland Personal Information Protection Act (PIPA) | Data breach notification within required timeframes to affected individuals and the Maryland AG. |
| Maryland Maryland Medical Records Act (Health-Gen. § 4-301) | Medical records processed through the platform are handled in compliance with Maryland medical records law. |
Name, email address, hashed password, and optional professional details (profession, specialty, institution, licence number, country). Collected at registration.
A SHA-256 hash of each query submitted, a 120-character preview for admin support, source count, and response latency. Raw query text is never stored long-term and is treated as equivalent to PHI under HIPAA.
We store your full query history per user in our Neon Postgres database to provide the query history feature. This data is private to your account and never shared.
Server logs including anonymised IP address (last octet masked), browser user agent, session identifiers, and timestamps. Used for security and rate limiting only.
All platform actions are recorded in a tamper-evident audit log as required by HIPAA § 164.312(b). This includes logins, queries, exports, and admin actions.
If you apply for verified professional status, credential documents are stored encrypted, reviewed, and deleted within 30 days of the verification decision.
| Category | Examples | Retention | Legal basis |
|---|---|---|---|
| Account data | Name, email, role | Until deletion | Contract |
| Query hashes | SHA-256 of query | 2 years | Contract |
| Query history | Full query history | 90 days rolling | Contract / Consent |
| Audit logs | Event type, actor, timestamp | 7 years (HIPAA min. 6) | Legal obligation |
| Session data | Auth0 session token | Session lifetime | Contract |
| Credential docs | Licence upload | 30 days post-decision | Contract |
We never sell your data, use it for advertising, use query content to train AI models, or share it with third parties for marketing purposes. This applies to sensitive health data under MODPA and PHI under HIPAA.
We treat all query-related data as potentially constituting Protected Health Information (PHI) and apply HIPAA-equivalent safeguards universally.
In the event of a breach involving unsecured PHI, we will notify affected individuals, the Secretary of HHS, and where required, prominent media outlets, within the timeframes required by the HITECH Breach Notification Rule (45 CFR §§ 164.400–414).
Business Associate Agreements (BAA): If you are a HIPAA covered entity requiring a BAA, contact support@zoonexai.com.
The Maryland Online Data Privacy Act (MODPA), Senate Bill 541, became effective October 1, 2025 and applies to personal data processing activities from April 1, 2026. Zoonex AI is fully compliant.
We collect only personal data that is reasonably necessary and proportionate to provide the Zoonex AI service, consistent with MODPA's strict data minimisation requirements.
Under MODPA, health-related query data constitutes sensitive data and consumer health data. We:
We use AI (Claude by Anthropic) to synthesise responses from evidence sources. This is a research support tool only and does not constitute automated decision-making that produces legal or similarly significant effects. We conduct Data Protection Impact Assessments (DPIAs) on all AI processing activities as required by MODPA.
We honour Global Privacy Control (GPC) signals and Do Not Track (DNT) headers. Maryland residents may opt out of any data processing beyond what is strictly necessary for the service via Settings → Privacy or by emailing support@zoonexai.com.
MODPA is enforced exclusively by the Maryland Attorney General. Civil penalties may be up to $10,000 per violation (first offence) and $25,000 for repeat violations. We maintain compliance to protect our users and our business.
We clearly label all AI-generated content as research and informational support tools. We do not make false, inaccurate, or misleading statements about the accuracy or capabilities of our AI. All responses include a disclaimer that they are not a substitute for clinical judgment.
As a platform that handles health-related information outside of HIPAA covered entity status (for general users), we comply with the FTC's Health Breach Notification Rule (16 CFR Part 318). In the event of a breach of personally identifiable health information, we will:
Our AI systems are designed not to produce outputs that discriminate on the basis of race, colour, national origin, sex, age, or disability. We conduct bias assessments on AI outputs and do not use clinical decision-support algorithms that produce discriminatory results.
In alignment with the HHS AI Strategy 2025 and FDA guidance on AI in health services, we maintain the following transparency practices:
Zoonex AI is NOT a diagnostic tool, a prescribing tool, or a replacement for professional clinical judgment. It is a research literature synthesis tool for use by qualified professionals.
We do not sell, rent, or trade your personal data. We share data only with the following processors under binding data processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting and edge delivery | US |
| Neon Inc. | PostgreSQL database hosting | US East (AWS) |
| Auth0 (Okta) | Authentication and identity management | US |
| Anthropic PBC | AI synthesis (Claude) | US |
| Resend Inc. | Transactional email delivery | US |
| Upstash Inc. | Redis rate limiting | US |
Anthropic note: Query text sent to Anthropic is processed per their API data processing terms. API inputs are not used to train models by default. We send only the minimum necessary context.
Foreign adversary restriction: Consistent with the DOJ Data Security Rule and BIOSECURE Act, we do not transfer bulk health data to restricted countries (China, Cuba, Iran, North Korea, Russia, Venezuela).
We may disclose data if required by lawful legal process. Where legally permitted, we will notify you before complying.
We retain personal data for as long as necessary to provide the service and comply with legal obligations. On account deletion:
Request deletion at any time: support@zoonexai.com. We respond within 30 days.
| Right | What it means |
|---|---|
| Access | Receive a copy of personal data we hold about you. |
| Correction | Correct inaccurate personal data. |
| Deletion | Request deletion of your personal data. |
| Portability | Receive your data in a machine-readable format. |
| Opt-out of sale | We do not sell data. No opt-out needed. |
| Opt-out of targeted advertising | We do not serve ads. No opt-out needed. |
| Opt-out of profiling | We do not profile users. No opt-out needed. |
| Appeal | Appeal any decision we make about your data rights within 60 days. |
To exercise rights: support@zoonexai.com. We respond within 45 days (extendable by 45 days with notice). Complaints to the Maryland Attorney General at marylandattorneygeneral.gov.
California residents have additional rights under the CCPA/CPRA including the right to know, delete, correct, and opt-out of sale (we do not sell data). Contact support@zoonexai.com to exercise these rights.
See Section 14 for GDPR-specific rights including Arts. 15–21. Complaints to your local supervisory authority or the FTC for US-based matters.
We implement technical and organisational measures appropriate to the risk:
In the event of a personal data breach we will notify affected users and relevant authorities within required timeframes (72 hours for GDPR; 60 days for FTC HBNR; immediately for HIPAA where required).
Zoonex AI is intended solely for use by health professionals and researchers aged 18 or over. We do not knowingly collect personal data from anyone under 18, consistent with COPPA requirements and MODPA's prohibition on processing sensitive data of consumers under 18. If you believe a minor has provided data to us, contact support@zoonexai.com immediately.
For users in the EEA or UK, we process personal data under the following legal bases (GDPR Art. 6):
| Processing activity | Legal basis |
|---|---|
| Account creation and authentication | Contract (Art. 6(1)(b)) |
| Audit logging | Legal obligation (Art. 6(1)(c)) |
| Transactional email | Contract (Art. 6(1)(b)) |
| Weekly digest emails | Consent (Art. 6(1)(a)) — opt-out any time |
| Anonymised analytics | Legitimate interest (Art. 6(1)(f)) |
International data transfers to the US are covered by EU Standard Contractual Clauses (SCCs). EEA users have rights under Arts. 15–21 GDPR. Complaints to your local supervisory authority. Contact: support@zoonexai.com.
We will notify registered users by email at least 14 days before material changes take effect. The "last updated" date at the top reflects the most recent revision. Continued use constitutes acceptance.
Zoonex AI LLC
📧 Privacy enquiries: support@zoonexai.com
📧 HIPAA BAA requests: support@zoonexai.com
📧 Security incidents: support@zoonexai.com
📮 Silver Spring, MD 20906, USA
Response within 5 business days · Subject access requests completed within 45 days · Maryland AG: marylandattorneygeneral.gov
This policy was last reviewed by legal counsel in March 2026. It should not be construed as legal advice. Consult a qualified US attorney for specific compliance questions.