Compliance

How Zellbox handles data — the honest version

One page for the questions procurement, legal, and security teams actually ask. GDPR posture, HIPAA scope, sub-processors, retention, breach notification, and how to reach us for a Data Processing Agreement. No overclaims, no hedging, one source of truth.

Last updated: 2026-07-27

At a glance

Six controls we can hand to a security reviewer today. Every item on this page is either backed by product behaviour, a signed agreement we can produce, or an independent audit report we can share on request.

GDPR-compliant
DPA on request
Google CASA Tier 2
Independent-lab audit (Jul 2026)
TLS 1.2+ in transit
AES-256 at rest
Send-and-sign consent
Signed PDF on record + audit trail
30-day cascade delete
On account deletion
72-hour breach notice
Where required by law

EU + UK

GDPR / LOPDGDD

Zellbox is GDPR-compliant. Product behaviour, contractual commitments, and technical safeguards line up with what the regulation asks of a processor.

Our role

You are the controller of the customer records in your workspace. Zellbox is the processor. That distinction shapes the DPA and everything below it.

Data Processing Agreement

Signed on request. Email hello@support.zellbox.com with your legal entity name — turnaround is one business day.

Data-subject rights

Access, rectification, erasure, restriction, portability, and objection — exercisable from Settings, or via support. Response window: 30 days.

Send-and-sign consent

Consent PDF → sent via WhatsApp or email → signed on the customer's phone → stored on the record with a full audit trail. Real evidence, not a checkbox.

US healthcare

HIPAA — not a Business Associate today

We won't dodge this one. Zellbox is not a HIPAA Business Associate. We do not sign BAAs, and Meta's WhatsApp Business API cannot back a BAA for the WhatsApp channel anyway.

If a signed BAA is a hard requirement for your practice, Zellbox is not the right fit today.

We track BAA requests — email hi@zellbox.com and we'll update this page when the position changes.

What US healthcare practices can do with Zellbox: appointment logistics — time, location, chair, generic confirm / cancel prompts. This falls within the limited-disclosure scope permitted for appointment-reminder communications under 45 CFR 164 without triggering a BAA requirement.

What US healthcare practices should not do with Zellbox: route Protected Health Information — clinical notes, diagnoses, test results, treatment specifics, medication names — through message bodies. Keep clinical detail inside your PMS or an EHR-integrated messaging solution.

Full context in our GDPR + HIPAA checklist for clinics (see point 5 in particular).

Third-party audit

Google CASA Tier 2

Independent-lab security assessment of the Google restricted OAuth scopes Zellbox uses (Gmail send + read, Calendar events). Passed July 2026 — covered by our Limited Use commitment.

What it covers

Application security controls (auth, session management, input validation, cryptography, secure coding), infrastructure controls (patch cadence, least-privilege IAM, encryption at rest), and operational controls (incident response, secrets management, dependency vulnerability tracking).

Why it matters

Google requires CASA on file for any app using restricted scopes; Zellbox's Gmail + Calendar integrations are core product surface. Read the announcement post for the specifics.

Supply chain

Sub-processors

The named third parties that touch data on Zellbox's behalf. If we add or remove one, this list changes.

ProviderPurposeRegion
Amazon Web ServicesHosting, database (DynamoDB), auth (Cognito), transactional email (SES)us-east-1
Meta PlatformsWhatsApp Business Cloud API — message delivery + webhook receiptUS / EU
GoogleOAuth sign-in, Google Calendar API, Gmail send/read APIsGlobal
StripePayment processing (card data never touches Zellbox servers)US / EU
Anthropic (Claude API)Content generation for our own marketing surfaces — does NOT process customer dataUS

Retention

Data retention + deletion

How long we keep each category of data, and what happens when you delete your account. Cascade delete is 30 days end-to-end.

Data categoryRetention window
Account + workspace metadataLife of the account · 30-day cascade delete on request
Customer records (name, phone, custom fields)Life of the account · 30-day cascade delete
Signed consent PDFs + audit trailLife of the customer record · deleted with cascade
WhatsApp conversation historyLife of the account · 30-day cascade delete
Google refresh tokensUntil you disconnect Google Sync (revokes at Google)
Operational logs (CloudWatch, billing)Up to 90 days after account deletion

Safeguards

Security controls

The technical safeguards that back everything above.

  • Encryption in transit

    TLS 1.2+ end to end. HSTS enforced on the marketing + app surface.

  • Encryption at rest

    AES-256 via AWS-managed keys. Google OAuth refresh tokens live in a dedicated, rotation-enabled AWS KMS key.

  • Auth + session

    Cognito-issued JWTs, signed + time-limited. API requests require a valid JWT or scoped API key.

  • Workspace isolation

    Every workspace is isolated from every other — no cross-tenant reads at the query layer.

A more detailed security page (vulnerability disclosure, security.txt, CASA Tier 2 attestation) lives at /security.

Incident response

Breach notification

If personal data on Zellbox is compromised, notification runs on the timelines regulators expect.

GDPR (EU + UK)

Article 33: supervisory-authority notification within 72 hours of becoming aware. Where the breach materially affects data subjects, controllers (you) are notified with the detail needed to fulfil Article 34.

US state laws + sector rules

We notify affected accounts on the shortest window applicable to their jurisdiction (30-day floor for most state breach laws). Because we are not a HIPAA Business Associate today (see above), the HHS Breach Notification Rule does not attach — but we commit to notifying you within the same 72-hour window even where not legally required.

Browser storage

Cookies + local storage

Zellbox uses a minimal cookie footprint — no advertising trackers, no cross-site remarketing pixels.

  • Authentication session cookie — set after sign-in so the app remembers you.
  • i18nextLng in localStorage — remembers the language you picked.
  • CloudFront cache cookies — set by the CDN in front of Zellbox for cache-key routing.

A per-category cookie consent banner is on the roadmap and will ship before we introduce any analytics or marketing cookies that would require it. Full detail in Privacy Policy §9.

Contact

Data protection contact

One inbox for DPAs, data-subject requests, sub-processor questions, and security disclosures.

Zellbox by Blockchain Web Services

2055 Limestone Rd Ste 200C, Wilmington, DE 19808, United States

Data-protection + DPA requests: hello@support.zellbox.com

Security disclosures: security@zellbox.com — see also /security and security.txt.

Full contractual terms in the Privacy Policy and Terms of Service. This page summarises the compliance-adjacent parts of both plus the additional commitments Zellbox makes as a processor.