fwfwef
ZYVO Daily Check-In
Email Support
fwfwef
ZYVO Privacy Policy
Effective on: June 30, 2026
Last update: June 30, 2026
By using ZYVO (“ZYVO” or the “App”), you acknowledge that you have read and understood this Privacy Policy. Where we process health-related information, AI wellness assistant conversations, or other sensitive personal information, we will rely on your explicit consent or another lawful basis required by applicable law.

This Privacy Policy (“Policy”) explains how WowSuite Software Ltd. ("Company", "we,""us," or "our") collects, uses, discloses, and safeguards your personal information when you visit our website or use our services. This Policy forms part of and is incorporated by reference into our Terms and Conditions.

I. Your Agreement

This Policy applies to the ZYVO mobile application, its associated websites, and any services offered through them. By creating an account or using ZYVO, you acknowledge that we act as the data controller for the collection and processing of your personal information, including certain health-related data, as described in this Policy and in accordance with applicable law. 

For users located in the European Economic Area (EEA) and the United Kingdom (UK), this Policy also explains how we comply with the General Data Protection Regulation (GDPR) and the UK-GDPR.

II. Data We Collect

When you create an account or use the App, we collect the information you voluntarily provide, such as your name, email address, and other details needed to operate your account and the service. You may also provide daily wellness check-in information through the App, including daily health check-in responses, user-reported inputs, notes, journal entries, wellbeing status, wellness check-in data, and other information you choose to enter. Where such information constitutes special category personal data (such as health data under applicable law), we process it only where necessary to provide the App and in accordance with applicable legal safeguards, including your explicit consent where required. We do not require submission of medical or diagnostic information.

If you interact with the AI-powered wellness assistant, we may collect your prompts, questions, user messages entered into the AI wellness assistant, limited to non-sensitive content required to provide the feature, and basic technical logs for security and performance. AI wellness assistant conversations are processed solely to provide the requested functionality, maintain conversation history, and ensure safety, security, and performance of the service.

If you enable missed check-in notifications, we may collect information about scheduled check-ins, completed check-ins, missed check-ins, reminder history, trusted-contact notification history, and delivery status where available. A trusted-contact notification may indicate activity related to your ZYVO account. Trusted-contact notifications are informational, user-initiated or system-triggered alerts and are not emergency, medical, or crisis-response services.

We automatically collect certain technical and usage data from your device, such as device type, operating system, IP address, and App interaction metrics. We do not collect web-browsing history outside the App. 

III. How We Use Your Data

We use your personal and health information to operate and improve the App and to provide you with the services you request. Specifically, we process information to provide daily health check-ins, store and display your health tracking history, operate the AI-powered wellness assistant, generate general wellness summaries based on user-provided check-in information and educational information, send reminders, notify trusted contacts according to your selected settings, personalize your user experience, and maintain your account. We also use information to troubleshoot issues, measure usage, enhance features, and ensure platform security. We do not use wellness or health-related data for advertising, profiling, or automated decision-making.

Certain processing is required for legal and regulatory compliance, such as responding to lawful requests, maintaining audit logs, or protecting against misuse. We may send you administrative notices, respond to inquiries, and provide customer support. 

We only process de-identified or aggregated data solely for feature improvement, where permitted by law. We do not use health-related data or AI health conversations to make automated decisions with legal or similarly significant effects. We do not use personal data, including health data or AI conversations, to train general-purpose AI models.

ZYVO is intended for wellness tracking, personal reflection only and educational purposes only. It does not provide medical diagnosis, medical treatment, emergency services, clinical evaluation or professional healthcare advice. Users should consult qualified healthcare professionals for medical concerns. AI outputs must not be used for medical decision-making.

Wellness Assistant Data Sharing

This section applies only when the AI Wellness Assistant feature is actively used. AI processing occurs only when the user actively enables the AI Wellness Assistant feature for a given session.

When the AI Wellness Assistant feature is used, certain personal information is transmitted to OpenAI, Inc. (United States) for the purpose of generating AI-powered responses.

Data is only transmitted when BOTH conditions are met:
(1) the user actively uses the AI Wellness Assistant feature, and
(2) the user has provided explicit consent within the App interface prior to use.

The types of data transmitted may include:
  • User prompts, messages, and questions entered into AI chat
  • Recent user messages required to maintain session continuity
  • Non-sensitive user check-in messages entered into the AI wellness assistant
  • Technical logs required to operate, secure, and maintain the feature
By using the AI wellness assistant after providing consent in the App interface, you authorize this transmission of data to OpenAI, Inc. solely for AI response generation. AI responses should not be relied upon as a substitute for professional medical advice, diagnosis, or treatment.

No personal data is transmitted unless both activation and consent conditions are met.

IV. Consumer Health Data and Privacy

ZYVO is not a HIPAA-covered entity. Where required under a written agreement with a healthcare provider, we may process limited health data as a Business Associate. We apply appropriate security measures to protect personal data as required by applicable law, including Federal Trade Commission’s Health Breach Notification Rule and with applicable state consumer health data and privacy laws. We provide legally required breach notifications where applicable law requires it.

We do not analyze, infer, or diagnose medical conditions based on user-submitted wellness or health-related information.

Payments are processed by third-party providers (e.g., Apple App Store, Google Play). We do not store full payment card details.

Personal data may be processed outside your country of residence, including the United States. Where required by law, we use appropriate safeguards for international data transfers.

If you suspect a data security incident, please contact the Company at support@zyvohealth.com. Do not include sensitive data in such emails.

V. California Notice at Collection

This Notice is provided pursuant to the California Consumer Privacy Act (as amended by the CPRA). It explains the categories of personal information we collect, the purposes for which we use it, our retention practices, and your rights to opt out.

We use this information to operate and improve our services, communicate with you, fulfill transactions, personalize your experience, and comply with legal and security obligations. We retain information only as long as reasonably necessary for the purposes described in this Policy.

We share limited user data with OpenAI, Inc. only when the AI Wellness Assistant feature is actively used by the user.

Sale or Sharing of Personal Information

We do not sell or share consumer health data, health check-in responses, wellness check-in data, AI wellness assistant conversations, trusted-contact data, or missed check-in notification data for cross-context behavioral advertising. We do not use these categories of information for targeted advertising. California residents may exercise rights to access, correct, delete, or limit the use of sensitive information by contacting support@zyvohealth.com or by using the “Do Not Sell or Share My Personal Information” link in the App. We honor Global Privacy Control (GPC) signals.

VI. Cookies

The App may use cookies and similar technologies (e.g., functional tokens, analytics SDKs, crash-reporting tools) for authentication, security, performance, diagnostics, fraud prevention, and App improvement. These tools may collect limited technical and usage information, such as device information, error logs, crash reports, performance metrics, and App interactions. We do not use these technologies to track your activity outside the App. Where analytics or tracking involves consumer health data, sensitive personal information, or similar protected data, we will obtain consent or use another lawful basis where required and will apply appropriate contractual and technical safeguards. Analytics and diagnostic tools do not access wellness check-in content or AI wellness assistant messages.

VII. Retention

We retain personal information only as long as reasonably necessary to provide services, meet legal obligations, resolve disputes, and enforce our agreements. Retention periods vary depending on the category of information and applicable laws.

Health check-ins, notes, journal entries, optional wellness tracking inputs, wellness check-in data, and tracking history: These records are stored while your account is active or until you delete them, request deletion, or close your account, subject to legal, security, backup, dispute-resolution, and compliance requirements.

AI wellness assistant conversations: AI conversation logs are retained only for security monitoring, abuse prevention, system integrity, and providing user-requested conversation history, where permitted by applicable law.

Trusted contact information: Trusted contact information is stored while the contact remains active in your account or until you remove the contact, request deletion, or close your account, subject to legal, security, backup, dispute-resolution, and compliance requirements. Missed check-in notifications are reminder-based and do not represent emergency monitoring or safety surveillance.

Missed check-in and notification logs: These records may be retained for a limited period to verify notification delivery, maintain security, resolve disputes, and comply with legal obligations.

If we are required by law or contract to retain certain records, we will do so securely and limit access to those records until destruction is permitted.

VIII. Third-Party Services

Generally, the third-party providers we use will only collect, use, and disclose your information as necessary to perform specific services they provide to us. These providers are bound by written agreements requiring confidentiality and data-processing terms consistent with GDPR and U.S. privacy laws, appropriate safeguards consistent with applicable healthcare data protection standards where relevant, and compliance with Standard Contractual Clauses (SCCs) or other approved transfer mechanisms for data exported outside the EEA or UK. 

These providers may include cloud hosting providers, AI technology providers, analytics providers, customer support providers, payment processors, security providers, email or SMS providers, and push notification providers.

Where trusted-contact notifications are enabled, notification providers may process limited information necessary to send the notification. Trusted contacts do not receive health information.

We may disclose information to comply with laws, regulations, or legal processes, or to protect the rights, property, or safety of users and the public.

Subprocessors

As part of providing our services, we may engage third parties (subprocessors) to process your personal data. All subprocessors are bound by written data-processing agreements with us in accordance with GDPR and applicable US law. Subprocessors perform technical processing only; they do not provide medical advice or diagnosis.

We use the following subprocessors to process your personal data:

(i) Microsoft Azure

Location: United States (Microsoft Azure)
Processing Purpose: Cloud infrastructure, secure data storage, App hosting, system logs, security monitoring, backup support, and related technical processing
Data Types:
  • Account information
  • Daily health check-in responses
  • User-reported inputs, notes, journal entries, optional wellness metrics, wellness check-in data, and other wellness information entered by users
  • Health tracking history
  • Trusted-contact information
  • Missed check-in and notification logs
  • Technical, usage, security, and system log data
Microsoft Azure provides cloud infrastructure and related technical processing services used to host, store, secure, and operate the App. Microsoft Azure does not provide medical advice, diagnosis, treatment recommendations, prescriptions, emergency support, or healthcare services through the App.

(ii) OpenAI
Location: United States (OpenAI, Inc.)
Processing Purpose: AI-powered wellness assistant, chat interactions, wellness insights, and AI feature support
Data Types:
  • User queries
  • User-entered wellness check-in messages that do not include medical or diagnostic data
  • AI-generated responses
  • Feedback and related technical logs
OpenAI, Inc. acts solely as a data processor and service provider processing information on behalf of Zyvo for the purpose of generating AI-powered responses within the AI wellness assistant feature. OpenAI does not determine the purposes or means of processing and does not use this data for advertising, profiling, or any unrelated commercial purpose. AI-generated content may contain errors and is provided for general informational and wellness purposes only. Users should not rely on AI-generated responses as a substitute for professional medical advice.

Third-party providers and subprocessors process personal data only to support App functionality and only under written agreements requiring confidentiality, security, and processing in accordance with our instructions and applicable law, unless a provider is separately identified as an independent controller for a specific processing activity. Unless stated in this policy, third-party providers do not receive or process medical, diagnostic, or clinical information.

IX. Your Rights

Depending on your location, you may have rights to access, correct, delete, or export your personal data. You can exercise these rights by contacting support@zyvohealth.com. We verify each request and respond within legally required timeframes. 

You may request access to, correction of, deletion of, or a copy of your personal information in a commonly used and machine-readable format where required by law.

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing that occurred before withdrawal.

California residents may have additional rights regarding sensitive personal information, including the right to limit certain uses where required by law.

Users may delete their account and associated personal data through the App or by contacting us. 

X. Age of Consent
The App is designed for adults and is not directed to children under 13 in the United States, under the applicable age of digital consent in the EEA/UK, or under the minimum age required by local law in any other jurisdiction.

We do not knowingly collect personal data from children under applicable age limits. If we learn that we have collected personal information from a child without required consent, we will delete it promptly unless retention is legally required.

We do not use children’s data for advertising, profiling, general-purpose AI model training, or any commercial purpose unrelated to providing the requested App functionality.

If you believe that we may have collected a child’s personal information in error or without proper authorization, please contact us immediately at support@zyvohealth.com so that we can investigate and take appropriate action.

XI. Changes to this Policy

We reserve the right to modify this Policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the App. Material changes will be announced via an in-App banner or notification at least 30 days before the new Policy takes effect. Where required by applicable law, we will obtain your consent before applying material changes that affect how we process sensitive personal data. Continued use of the App after changes take effect may constitute acceptance of the revised Policy to the extent permitted by applicable law. This Policy is an integral part of our Terms of Use.

In the event of a merger, acquisition, or sale of assets, we may transfer personal data as part of that transaction, subject to appropriate safeguards and applicable law.

Residents of the European Economic Area: Our disclosure is limited to situations where we are permitted to do so under applicable European and national data protection laws and regulations.

XII. Questions and Contact Information

If you would like to access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information, contact us at email address support@zyvohealth.com.
For privacy questions, contact us at: support@zyvohealth.com.


NL - EN speaking only: 085 4001159