Legal
Data Processing
How data processing is approached for the ZenOptix website today, and for customer practices as they onboard.
This page describes our intended approach and should be reviewed before full commercial launch. Formal data processing agreements are put in place as part of customer onboarding, not through this website.
Website enquiries
Enquiries submitted through this website are processed as described in our Privacy Policy: stored securely, forwarded to our enquiries inbox, and used only to respond to you.
Customer practice data
Practices using the ZenOptix application entrust it with patient and operational data. That data is processed under the agreements entered into when a practice becomes a customer, not under these website pages. ZenOptix is designed around role-based access, audit-focused workflows and GDPR-aware handling of sensitive practice data.
Data processing agreements
Appropriate data processing terms are agreed with customer practices as part of onboarding, covering roles and responsibilities, the scope of processing, and the safeguards applied.
Security and access controls
ZenOptix is designed around least-privilege access, organisation and branch context, auditability of sensitive actions and controlled support access. More detail is on our Security & GDPR page.
Subprocessors
For the public website, enquiry notification emails are delivered via Postmark, a transactional email provider, and website analytics are processed by Google (Google Analytics 4) only where a visitor has accepted analytics cookies. A full subprocessor list for the ZenOptix application will be published as part of customer onboarding documentation.
Production onboarding
As practices join ZenOptix, onboarding covers data migration, access setup, and the agreements described above, so responsibilities are clear before any practice data is processed.