Skip to content

Compliance & data protection

One page for the questions procurement, legal, and security teams actually ask before signing off. GDPR, HIPAA scope, sub-processors, retention, breach notification, and how to reach us for a DPA. The web version — with the same content, better navigation — lives at zellbox.com/compliance.

Last reviewed: 2026-07-27

At a glance

ControlStatus
GDPRCompliant — DPA on request, EU/UK data-subject rights supported end-to-end.
HIPAANot a Business Associate today — see the HIPAA section below for what US healthcare practices can and can't route through Zellbox.
Google CASATier 2 — independent-lab audit passed July 2026, covers our Gmail + Calendar restricted OAuth scopes.
Encryption in transitTLS 1.2+ end-to-end, HSTS enforced.
Encryption at restAES-256 via AWS-managed keys. Google OAuth refresh tokens use a dedicated, rotation-enabled AWS KMS key.
Cascade delete30 days after account deletion.
Breach notification72 hours (matching GDPR Article 33) — offered universally, not just where legally required.

GDPR / LOPDGDD

Zellbox is GDPR-compliant. Product behaviour, contractual commitments, and technical safeguards line up with what the regulation asks of a processor.

Our role. You are the controller of the customer records in your workspace. Zellbox is the processor. That distinction shapes the DPA and everything below it.

Data Processing Agreement. Signed on request. Email hello@support.zellbox.com with your legal entity name — turnaround is one business day.

Data-subject rights. Access, rectification, erasure, restriction, portability, and objection — exercisable from Settings, or via support. Response window: 30 days.

Send-and-sign consent workflow. Send a consent PDF via WhatsApp or email → the customer signs on their phone → the signed document is stored on their record with a full audit trail. Real evidence, not a checkbox.

LOPDGDD, DSGVO, LGPD, RGPD. The regional GDPR-equivalents are covered by the same technical + organisational measures. AEPD (Spain) inspections have specific expectations around the signed-consent evidence — the workflow above is designed to meet them.

HIPAA — not a Business Associate today

We won't dodge this one. Zellbox is not a HIPAA Business Associate. We do not sign BAAs, and Meta's WhatsApp Business API cannot back a BAA for the WhatsApp channel anyway.

If a signed BAA is a hard requirement for your practice, Zellbox is not the right fit today. We track BAA requests — email hi@zellbox.com and we'll update this page when the position changes.

What US healthcare practices can do with Zellbox

Appointment logistics — time, location, chair, generic confirm / cancel prompts. This falls within the limited-disclosure scope permitted for appointment-reminder communications under 45 CFR 164 without triggering a BAA requirement.

What US healthcare practices should not do with Zellbox

Route Protected Health Information — clinical notes, diagnoses, test results, treatment specifics, medication names — through message bodies. Keep clinical detail inside your PMS or an EHR-integrated messaging solution.

Full context in our GDPR + HIPAA checklist for clinics (see point 5 in particular).

Google CASA Tier 2

Independent-lab security assessment of the Google restricted OAuth scopes Zellbox uses (Gmail send + read, Calendar events). Passed July 2026 — covered by our Limited Use commitment.

What it covers. Application security controls (auth, session management, input validation, cryptography, secure coding), infrastructure controls (patch cadence, least-privilege IAM, encryption at rest), and operational controls (incident response, secrets management, dependency vulnerability tracking).

Why it matters. Google requires CASA on file for any app using restricted scopes; Zellbox's Gmail + Calendar integrations are core product surface. Read the announcement post for the specifics.

Sub-processors

The named third parties that touch data on Zellbox's behalf. If we add or remove one, this list changes.

ProviderPurposeRegion
Amazon Web ServicesHosting, database (DynamoDB), auth (Cognito), transactional email (SES)us-east-1
Meta PlatformsWhatsApp Business Cloud API — message delivery + webhook receiptUS / EU
GoogleOAuth sign-in, Google Calendar API, Gmail send/read APIsGlobal
StripePayment processing (card data never touches Zellbox servers)US / EU
Anthropic (Claude API)Content generation for our own marketing surfaces — does NOT process customer dataUS

Data retention & deletion

Data categoryRetention window
Account + workspace metadataLife of the account · 30-day cascade delete on request
Customer records (name, phone, custom fields)Life of the account · 30-day cascade delete
Signed consent PDFs + audit trailLife of the customer record · deleted with cascade
WhatsApp conversation historyLife of the account · 30-day cascade delete
Google refresh tokensUntil you disconnect Google Sync (revokes at Google)
Operational logs (CloudWatch, billing)Up to 90 days after account deletion

Cancelling your subscription drops the account to free-tier limits — no data is deleted until you explicitly request account deletion or the account goes dormant per the Terms of Service.

Security controls

  • Encryption in transit — TLS 1.2+ end to end. HSTS enforced on the marketing + app surface.
  • Encryption at rest — AES-256 via AWS-managed keys. Google OAuth refresh tokens live in a dedicated, rotation-enabled AWS KMS key.
  • Auth + session — Cognito-issued JWTs, signed + time-limited. API requests require a valid JWT or scoped API key.
  • Workspace isolation — Every workspace is isolated from every other — no cross-tenant reads at the query layer.

More detail (vulnerability disclosure, security.txt, CASA Tier 2 attestation) at zellbox.com/security.

Breach notification

If personal data on Zellbox is compromised, notification runs on the timelines regulators expect.

GDPR (EU + UK). Article 33: supervisory-authority notification within 72 hours of becoming aware. Where the breach materially affects data subjects, controllers (you) are notified with the detail needed to fulfil Article 34.

US state laws + sector rules. We notify affected accounts on the shortest window applicable to their jurisdiction (30-day floor for most state breach laws). Because we are not a HIPAA Business Associate today (see above), the HHS Breach Notification Rule does not attach — but we commit to notifying you within the same 72-hour window even where not legally required.

Cookies & local storage

Zellbox uses a minimal cookie footprint — no advertising trackers, no cross-site remarketing pixels.

  • Authentication session cookie — set after sign-in so the app remembers you.
  • i18nextLng in localStorage — remembers the language you picked.
  • CloudFront cache cookies — set by the CDN in front of Zellbox for cache-key routing.

A per-category cookie consent banner is on the roadmap and will ship before we introduce any analytics or marketing cookies that would require it. Full detail in the Privacy Policy §9.

Data protection contact

One inbox for DPAs, data-subject requests, sub-processor questions, and security disclosures.

Zellbox by Blockchain Web Services 2055 Limestone Rd Ste 200C, Wilmington, DE 19808, United States

Full contractual terms in the Privacy Policy and Terms of Service. This page summarises the compliance-adjacent parts of both plus the additional commitments Zellbox makes as a processor.

Zellbox documentation