Privacy and consent
Privacy Policy and DPDP-ready Notice.
A clean view of how Zoechéa collects, uses, protects, and gives you control over account, community, learning, access, and historical payment data.
Plain-language view
Privacy notice, organized for quick review.
Only needed data
Zoechéa collects data needed to create accounts, run community and learning areas, assign tier access, retain required historical payment records, and keep the portal secure.
Clear tool boundaries
Invoice, focus, learning, and community data stay tied to the purpose users expect when they use each area.
Requests stay simple
Members can ask for access, correction, export, deletion, consent withdrawal, and grievance review.
Who and what is covered
- Account data: name, email, phone number, login/session information, and account settings.
- Community and learning: posts, replies, bookmarks, progress, attendance-related records, and Knowledge Hub activity.
- Invoice data: practice profile, client billing details, invoice items, GST/TDS settings, payment status, and invoice records.
- Historical payment data: earlier membership transactions, payment status, and provider identifiers retained for support, accounting, refunds, and legal obligations.
- Usage and security: IP/device/browser information, feature usage, error logs, and security events.
- Service purposes: account support, legal compliance, abuse prevention, debugging, and platform protection.
Feature-level data use
Before you use sensitive account features, the portal gives feature-level notice wherever practical. Consent records may include the notice version, timestamp, consent type, and limited device/security metadata so we can show what notice was given.
Account creation
Data: Name, email address, phone number, password hash, login/session details, and basic account settings.
Purpose: To create your account, verify access, keep the portal secure, provide support, and communicate service updates.
Storage: Stored in your Zoechéa account until you delete the account or request deletion, except where records must be retained for legal, security, billing, or dispute purposes.
Choice: Required to use the portal. You can request account deletion from Settings or Support.
Terms and privacy acceptance
Data: Your acceptance status, notice version, timestamp, and limited device/security metadata.
Purpose: To record that you understood the platform terms and privacy notice at the time of signup.
Storage: Retained as an account and compliance record while your account exists and for a reasonable period after closure if needed for legal or dispute purposes.
Choice: Required to create an account.
Google Sign-In
Data: Google account ID, name, email address, email verification status, and profile picture if provided by Google.
Purpose: To let you sign in securely with Google and maintain your Zoechéa account access.
Storage: Stored only as needed for account login and authentication. Google access can be revoked from your Google Account permissions.
Choice: Optional. You can use email/password login instead if available.
Membership access and historical payments
Data: Membership tier, permanent access status, earlier Razorpay payment/order identifiers, payment dates, and limited support records.
Purpose: To manage admin-assigned access and support historical refunds, accounting, disputes, and legal obligations.
Storage: Zoechéa retains only the historical transaction records needed for support and compliance. No new self-service tier checkout is offered.
Choice: Practitioner Membership is reviewed and assigned manually. Membership arrangements are completed outside this website.
Service and support communication
Data: Email address, support messages, ticket details, service alerts, and limited delivery logs.
Purpose: To respond to support requests, send security/account messages, and provide service-related updates.
Storage: Stored as part of support and account records.
Choice: Service messages are required for account operation. Marketing messages should stay optional.
Sensitive information
Do not enter more data than needed. Avoid putting diagnosis, case notes, therapy content, or sensitive mental health details into invoices, journals, community posts, or other tools that do not require them.
Zoechéa tools support community learning, billing, focus, and professional growth. They do not replace clinical judgment, supervision, diagnosis, emergency care, legal advice, or a qualified professional's responsibility.
How data is protected
- We use HTTPS/TLS for data in transit.
- Passwords are stored using secure password hashing.
- Sensitive tools use access controls, restricted private storage, and activity logging.
- Trusted services receive only the data needed to perform their function.
- Admin impersonation is restricted from sensitive private areas.
- Access stays limited to authorised service operations and support needs.
How long records stay
- Account data: kept while your account exists and for a reasonable period after closure if needed for legal, billing, security, or dispute purposes.
- Client/practice data: kept under your account until you delete it or request deletion, unless legal/professional retention requirements apply.
- Invoices and payments: retained as needed for accounting, tax, fraud prevention, and legal obligations.
- Security logs: kept only as long as reasonably needed to protect the service and investigate abuse.
Member requests and breach communication
You may request access, correction, export, deletion, consent withdrawal where applicable, and grievance review. Some processing may continue if required for legal, billing, security, or completed service obligations.
Registered users can start privacy requests from Settings Privacy. You can also contact us using the details below.
If we become aware of a security incident affecting personal data, we will investigate, take reasonable containment steps, and notify affected users and/or authorities where required by applicable law.
08 / Contact and changes
Privacy questions, data requests, and grievance support.
Include your account email and request type so support can respond accurately. Significant updates can be shown in-platform or sent through account email where appropriate.