Compliance
How Zellbox handles data — the honest version
One page for the questions procurement, legal, and security teams actually ask. GDPR posture, HIPAA scope, sub-processors, retention, breach notification, and how to reach us for a Data Processing Agreement. No overclaims, no hedging, one source of truth.
Last updated: 2026-07-27
At a glance
Six controls we can hand to a security reviewer today. Every item on this page is either backed by product behaviour, a signed agreement we can produce, or an independent audit report we can share on request.
- GDPR-compliant
- DPA on request
- Google CASA Tier 2
- Independent-lab audit (Jul 2026)
- TLS 1.2+ in transit
- AES-256 at rest
- Send-and-sign consent
- Signed PDF on record + audit trail
- 30-day cascade delete
- On account deletion
- 72-hour breach notice
- Where required by law
EU + UK
GDPR / LOPDGDD
Zellbox is GDPR-compliant. Product behaviour, contractual commitments, and technical safeguards line up with what the regulation asks of a processor.
Our role
You are the controller of the customer records in your workspace. Zellbox is the processor. That distinction shapes the DPA and everything below it.
Data Processing Agreement
Signed on request. Email hello@support.zellbox.com with your legal entity name — turnaround is one business day.
Data-subject rights
Access, rectification, erasure, restriction, portability, and objection — exercisable from Settings, or via support. Response window: 30 days.
Send-and-sign consent
Consent PDF → sent via WhatsApp or email → signed on the customer's phone → stored on the record with a full audit trail. Real evidence, not a checkbox.
US healthcare
HIPAA — not a Business Associate today
We won't dodge this one. Zellbox is not a HIPAA Business Associate. We do not sign BAAs, and Meta's WhatsApp Business API cannot back a BAA for the WhatsApp channel anyway.
If a signed BAA is a hard requirement for your practice, Zellbox is not the right fit today.
We track BAA requests — email hi@zellbox.com and we'll update this page when the position changes.
What US healthcare practices can do with Zellbox: appointment logistics — time, location, chair, generic confirm / cancel prompts. This falls within the limited-disclosure scope permitted for appointment-reminder communications under 45 CFR 164 without triggering a BAA requirement.
What US healthcare practices should not do with Zellbox: route Protected Health Information — clinical notes, diagnoses, test results, treatment specifics, medication names — through message bodies. Keep clinical detail inside your PMS or an EHR-integrated messaging solution.
Full context in our GDPR + HIPAA checklist for clinics (see point 5 in particular).
Third-party audit
Google CASA Tier 2
Independent-lab security assessment of the Google restricted OAuth scopes Zellbox uses (Gmail send + read, Calendar events). Passed July 2026 — covered by our Limited Use commitment.
What it covers
Application security controls (auth, session management, input validation, cryptography, secure coding), infrastructure controls (patch cadence, least-privilege IAM, encryption at rest), and operational controls (incident response, secrets management, dependency vulnerability tracking).
Why it matters
Google requires CASA on file for any app using restricted scopes; Zellbox's Gmail + Calendar integrations are core product surface. Read the announcement post for the specifics.
Supply chain
Sub-processors
The named third parties that touch data on Zellbox's behalf. If we add or remove one, this list changes.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting, database (DynamoDB), auth (Cognito), transactional email (SES) | us-east-1 |
| Meta Platforms | WhatsApp Business Cloud API — message delivery + webhook receipt | US / EU |
| OAuth sign-in, Google Calendar API, Gmail send/read APIs | Global | |
| Stripe | Payment processing (card data never touches Zellbox servers) | US / EU |
| Anthropic (Claude API) | Content generation for our own marketing surfaces — does NOT process customer data | US |
Retention
Data retention + deletion
How long we keep each category of data, and what happens when you delete your account. Cascade delete is 30 days end-to-end.
| Data category | Retention window |
|---|---|
| Account + workspace metadata | Life of the account · 30-day cascade delete on request |
| Customer records (name, phone, custom fields) | Life of the account · 30-day cascade delete |
| Signed consent PDFs + audit trail | Life of the customer record · deleted with cascade |
| WhatsApp conversation history | Life of the account · 30-day cascade delete |
| Google refresh tokens | Until you disconnect Google Sync (revokes at Google) |
| Operational logs (CloudWatch, billing) | Up to 90 days after account deletion |
Safeguards
Security controls
The technical safeguards that back everything above.
Encryption in transit
TLS 1.2+ end to end. HSTS enforced on the marketing + app surface.
Encryption at rest
AES-256 via AWS-managed keys. Google OAuth refresh tokens live in a dedicated, rotation-enabled AWS KMS key.
Auth + session
Cognito-issued JWTs, signed + time-limited. API requests require a valid JWT or scoped API key.
Workspace isolation
Every workspace is isolated from every other — no cross-tenant reads at the query layer.
A more detailed security page (vulnerability disclosure, security.txt, CASA Tier 2 attestation) lives at /security.
Incident response
Breach notification
If personal data on Zellbox is compromised, notification runs on the timelines regulators expect.
GDPR (EU + UK)
Article 33: supervisory-authority notification within 72 hours of becoming aware. Where the breach materially affects data subjects, controllers (you) are notified with the detail needed to fulfil Article 34.
US state laws + sector rules
We notify affected accounts on the shortest window applicable to their jurisdiction (30-day floor for most state breach laws). Because we are not a HIPAA Business Associate today (see above), the HHS Breach Notification Rule does not attach — but we commit to notifying you within the same 72-hour window even where not legally required.
- Authentication session cookie — set after sign-in so the app remembers you.
i18nextLnginlocalStorage— remembers the language you picked.- CloudFront cache cookies — set by the CDN in front of Zellbox for cache-key routing.
A per-category cookie consent banner is on the roadmap and will ship before we introduce any analytics or marketing cookies that would require it. Full detail in Privacy Policy §9.
Contact
Data protection contact
One inbox for DPAs, data-subject requests, sub-processor questions, and security disclosures.
Zellbox by Blockchain Web Services
2055 Limestone Rd Ste 200C, Wilmington, DE 19808, United States
Data-protection + DPA requests: hello@support.zellbox.com
Security disclosures: security@zellbox.com — see also /security and security.txt.
Full contractual terms in the Privacy Policy and Terms of Service. This page summarises the compliance-adjacent parts of both plus the additional commitments Zellbox makes as a processor.