Legal

Privacy Policy

How we collect, use, and protect your information.

Plain English summary: Zoonex AI collects only what is needed to provide the service. We never sell your data, run ads, or share it for marketing. Health-related query data is treated as equivalent to Protected Health Information under HIPAA. We comply with Maryland, federal US, and international privacy law.

01 Who we are

Zoonex AI LLC ("Zoonex AI", "we", "us", "our") is a limited liability company registered in the State of Maryland, USA, with its principal office in Silver Spring, MD 20906.

We operate zoonexai.com — a One Health intelligence platform that synthesises evidence from 23 live biomedical databases for veterinary and public health professionals using AI.

Zoonex AI LLC is the data controller for personal data processed through our platform. Where applicable under HIPAA, we are prepared to enter into a Business Associate Agreement (BAA) with covered entities upon request.

02 Applicable laws

Zoonex AI operates in compliance with the following laws and regulations. This policy is designed to satisfy all applicable requirements:

Federal US law

Law / RegulationApplicability to Zoonex AI
Federal HIPAA / HITECH (45 CFR Parts 160, 164)Query data treated as PHI equivalent. Audit logging, encryption, access controls per § 164.312.
Federal FTC Act § 5 (15 U.S.C. § 45)We do not engage in unfair or deceptive practices. AI outputs are clearly labelled as research tools, not medical advice.
Federal FTC Health Breach Notification Rule (16 CFR Part 318)We notify consumers and the FTC within required timeframes of any health data breach.
Federal ACA § 1557 (Non-Discrimination)Our AI systems do not use discriminatory clinical algorithms. No bias based on race, sex, age, disability, or national origin.
Federal COPPA (15 U.S.C. § 6501)Platform is restricted to users 18+. We do not knowingly collect data from minors.
Federal FERPAWe do not process student education records.
Federal DOJ Data Security Rule (28 CFR Part 202)We do not engage in bulk data transactions with foreign adversaries. Health data is not transferred to restricted countries.
Federal HHS AI Strategy 2025We align with HHS OneHHS AI principles: patient privacy, civil rights, civil liberties, and transparency in AI use.

Maryland state law

LawApplicability
Maryland Maryland Online Data Privacy Act (MODPA) — SB 541, effective Oct 1, 2025Full compliance. We do not sell sensitive data, we collect only data strictly necessary for the service, and we provide opt-out rights.
Maryland Maryland Personal Information Protection Act (PIPA)Data breach notification within required timeframes to affected individuals and the Maryland AG.
Maryland Maryland Medical Records Act (Health-Gen. § 4-301)Medical records processed through the platform are handled in compliance with Maryland medical records law.

Other applicable law

  • CCPA / CPRA — California users have additional rights described in Section 11.
  • GDPR / UK GDPR — EEA and UK users have rights described in Section 14.
  • BIOSECURE Act (2025) — We do not use biotechnology equipment or services from entities linked to foreign adversaries.

03 Data we collect

3.1 Account data

Name, email address, hashed password, and optional professional details (profession, specialty, institution, licence number, country). Collected at registration.

3.2 Query data

A SHA-256 hash of each query submitted, a 120-character preview for admin support, source count, and response latency. Raw query text is never stored long-term and is treated as equivalent to PHI under HIPAA.

3.3 Query history

We store your full query history per user in our Neon Postgres database to provide the query history feature. This data is private to your account and never shared.

3.4 Usage data

Server logs including anonymised IP address (last octet masked), browser user agent, session identifiers, and timestamps. Used for security and rate limiting only.

3.5 Audit log data

All platform actions are recorded in a tamper-evident audit log as required by HIPAA § 164.312(b). This includes logins, queries, exports, and admin actions.

3.6 Credential documents

If you apply for verified professional status, credential documents are stored encrypted, reviewed, and deleted within 30 days of the verification decision.

CategoryExamplesRetentionLegal basis
Account dataName, email, roleUntil deletionContract
Query hashesSHA-256 of query2 yearsContract
Query historyFull query history90 days rollingContract / Consent
Audit logsEvent type, actor, timestamp7 years (HIPAA min. 6)Legal obligation
Session dataAuth0 session tokenSession lifetimeContract
Credential docsLicence upload30 days post-decisionContract

04 How we use your data

  • Service delivery — authenticating users, routing queries to 23 evidence APIs, returning AI-synthesised responses.
  • Professional verification — reviewing credentials to grant enhanced query access.
  • Safety and compliance — audit logging, abuse detection, HIPAA and MODPA obligations.
  • Transactional email — account, verification, security, and digest notifications via Resend.
  • Query history — showing users their query history for reference and convenience.
  • Platform improvement — aggregated, anonymised analytics only. No individual profiling.

We never sell your data, use it for advertising, use query content to train AI models, or share it with third parties for marketing purposes. This applies to sensitive health data under MODPA and PHI under HIPAA.

05 HIPAA compliance

We treat all query-related data as potentially constituting Protected Health Information (PHI) and apply HIPAA-equivalent safeguards universally.

Technical safeguards (§ 164.312)

  • Access controls — role-based access (viewer, professional, admin) with Auth0 MFA.
  • Audit controls — tamper-evident audit log for all data access and modification events.
  • Integrity controls — query data stored as SHA-256 hashes; databases encrypted at rest (AES-256).
  • Transmission security — all data in transit encrypted with TLS 1.3.

Administrative safeguards (§ 164.308)

  • Staff access to production data is logged and reviewed quarterly.
  • Data access is on a need-to-know basis only.
  • Incident response procedures are maintained and tested annually.
  • Risk analysis and risk management programme in place.

HITECH Act compliance

In the event of a breach involving unsecured PHI, we will notify affected individuals, the Secretary of HHS, and where required, prominent media outlets, within the timeframes required by the HITECH Breach Notification Rule (45 CFR §§ 164.400–414).

Business Associate Agreements (BAA): If you are a HIPAA covered entity requiring a BAA, contact support@zoonexai.com.

06 Maryland MODPA compliance

The Maryland Online Data Privacy Act (MODPA), Senate Bill 541, became effective October 1, 2025 and applies to personal data processing activities from April 1, 2026. Zoonex AI is fully compliant.

Data minimisation

We collect only personal data that is reasonably necessary and proportionate to provide the Zoonex AI service, consistent with MODPA's strict data minimisation requirements.

Sensitive data

Under MODPA, health-related query data constitutes sensitive data and consumer health data. We:

  • Do not sell sensitive data for monetary or other valuable consideration.
  • Collect and process sensitive data only when strictly necessary to provide the service you requested.
  • Require opt-in consent before processing any sensitive data beyond what is strictly necessary.

Automated decision-making

We use AI (Claude by Anthropic) to synthesise responses from evidence sources. This is a research support tool only and does not constitute automated decision-making that produces legal or similarly significant effects. We conduct Data Protection Impact Assessments (DPIAs) on all AI processing activities as required by MODPA.

Universal opt-out mechanism

We honour Global Privacy Control (GPC) signals and Do Not Track (DNT) headers. Maryland residents may opt out of any data processing beyond what is strictly necessary for the service via Settings → Privacy or by emailing support@zoonexai.com.

Enforcement

MODPA is enforced exclusively by the Maryland Attorney General. Civil penalties may be up to $10,000 per violation (first offence) and $25,000 for repeat violations. We maintain compliance to protect our users and our business.

07 FTC compliance

FTC Act § 5 — Unfair or deceptive practices

We clearly label all AI-generated content as research and informational support tools. We do not make false, inaccurate, or misleading statements about the accuracy or capabilities of our AI. All responses include a disclaimer that they are not a substitute for clinical judgment.

FTC Health Breach Notification Rule

As a platform that handles health-related information outside of HIPAA covered entity status (for general users), we comply with the FTC's Health Breach Notification Rule (16 CFR Part 318). In the event of a breach of personally identifiable health information, we will:

  • Notify affected consumers within 60 days of discovery.
  • Notify the FTC within 60 days (or simultaneously for breaches affecting 500+ people).
  • Notify prominent media outlets for breaches affecting 500+ residents of a state.

AI non-discrimination (ACA § 1557)

Our AI systems are designed not to produce outputs that discriminate on the basis of race, colour, national origin, sex, age, or disability. We conduct bias assessments on AI outputs and do not use clinical decision-support algorithms that produce discriminatory results.

08 AI transparency (FDA / HHS)

In alignment with the HHS AI Strategy 2025 and FDA guidance on AI in health services, we maintain the following transparency practices:

  • AI disclosure: All responses are clearly labelled as AI-generated. We identify the AI model used (Anthropic Claude).
  • Not a medical device: Zoonex AI is a research and clinical decision-support tool. It is not classified as a Software as a Medical Device (SaMD) under FDA regulations as it does not diagnose, treat, cure, or prevent disease.
  • Clinical judgment: All AI responses include a disclaimer requiring human professional review before clinical application.
  • Data sources: We disclose all 23 evidence databases used in synthesis. Source lists are shown with every response.
  • Limitations: AI synthesis may contain errors, be outdated, or miss relevant evidence. Users should verify critical information against primary sources.
  • Hallucination risk: AI-generated content may occasionally be inaccurate. We are not liable for clinical decisions based solely on AI output.

Zoonex AI is NOT a diagnostic tool, a prescribing tool, or a replacement for professional clinical judgment. It is a research literature synthesis tool for use by qualified professionals.

09 Data sharing

We do not sell, rent, or trade your personal data. We share data only with the following processors under binding data processing agreements:

ProcessorPurposeLocation
Vercel Inc.Application hosting and edge deliveryUS
Neon Inc.PostgreSQL database hostingUS East (AWS)
Auth0 (Okta)Authentication and identity managementUS
Anthropic PBCAI synthesis (Claude)US
Resend Inc.Transactional email deliveryUS
Upstash Inc.Redis rate limitingUS

Anthropic note: Query text sent to Anthropic is processed per their API data processing terms. API inputs are not used to train models by default. We send only the minimum necessary context.

Foreign adversary restriction: Consistent with the DOJ Data Security Rule and BIOSECURE Act, we do not transfer bulk health data to restricted countries (China, Cuba, Iran, North Korea, Russia, Venezuela).

We may disclose data if required by lawful legal process. Where legally permitted, we will notify you before complying.

10 Data retention

We retain personal data for as long as necessary to provide the service and comply with legal obligations. On account deletion:

  • Account profile data deleted within 30 days.
  • Query history deleted within 30 days.
  • Audit log PII anonymised (event records retained 7 years per HIPAA).
  • Credential documents deleted immediately.

Request deletion at any time: support@zoonexai.com. We respond within 30 days.

11 Your rights

Maryland residents (MODPA)

RightWhat it means
AccessReceive a copy of personal data we hold about you.
CorrectionCorrect inaccurate personal data.
DeletionRequest deletion of your personal data.
PortabilityReceive your data in a machine-readable format.
Opt-out of saleWe do not sell data. No opt-out needed.
Opt-out of targeted advertisingWe do not serve ads. No opt-out needed.
Opt-out of profilingWe do not profile users. No opt-out needed.
AppealAppeal any decision we make about your data rights within 60 days.

To exercise rights: support@zoonexai.com. We respond within 45 days (extendable by 45 days with notice). Complaints to the Maryland Attorney General at marylandattorneygeneral.gov.

California residents (CCPA / CPRA)

California residents have additional rights under the CCPA/CPRA including the right to know, delete, correct, and opt-out of sale (we do not sell data). Contact support@zoonexai.com to exercise these rights.

EEA / UK users (GDPR)

See Section 14 for GDPR-specific rights including Arts. 15–21. Complaints to your local supervisory authority or the FTC for US-based matters.

12 Security

We implement technical and organisational measures appropriate to the risk:

  • TLS 1.3 encryption for all data in transit.
  • AES-256 encryption for data at rest.
  • SHA-256 hashing of query text and IP addresses.
  • Role-based access control with principle of least privilege.
  • Multi-factor authentication required for all staff accessing production systems.
  • Automated vulnerability scanning and dependency auditing.
  • Annual penetration testing by an independent third party.
  • Tamper-evident audit logging per HIPAA § 164.312(b).

In the event of a personal data breach we will notify affected users and relevant authorities within required timeframes (72 hours for GDPR; 60 days for FTC HBNR; immediately for HIPAA where required).

13 Children

Zoonex AI is intended solely for use by health professionals and researchers aged 18 or over. We do not knowingly collect personal data from anyone under 18, consistent with COPPA requirements and MODPA's prohibition on processing sensitive data of consumers under 18. If you believe a minor has provided data to us, contact support@zoonexai.com immediately.

14 International users (GDPR)

For users in the EEA or UK, we process personal data under the following legal bases (GDPR Art. 6):

Processing activityLegal basis
Account creation and authenticationContract (Art. 6(1)(b))
Audit loggingLegal obligation (Art. 6(1)(c))
Transactional emailContract (Art. 6(1)(b))
Weekly digest emailsConsent (Art. 6(1)(a)) — opt-out any time
Anonymised analyticsLegitimate interest (Art. 6(1)(f))

International data transfers to the US are covered by EU Standard Contractual Clauses (SCCs). EEA users have rights under Arts. 15–21 GDPR. Complaints to your local supervisory authority. Contact: support@zoonexai.com.

15 Changes to this policy

We will notify registered users by email at least 14 days before material changes take effect. The "last updated" date at the top reflects the most recent revision. Continued use constitutes acceptance.

16 Contact

Privacy & Data Protection Contact

Zoonex AI LLC

📧 Privacy enquiries: support@zoonexai.com

📧 HIPAA BAA requests: support@zoonexai.com

📧 Security incidents: support@zoonexai.com

📮 Silver Spring, MD 20906, USA

Response within 5 business days · Subject access requests completed within 45 days · Maryland AG: marylandattorneygeneral.gov

This policy was last reviewed by legal counsel in March 2026. It should not be construed as legal advice. Consult a qualified US attorney for specific compliance questions.