Gatekeeper
Privacy Policy
1. Scope of This Policy
The Zen India Therapeutics Private Limited (CIN U62013DL2024PTC429803) ("The Zen India," "Company," "we," "us," or "our") operates Gatekeeper, an AI-assisted practice-management toolkit for mental health practitioners and facilities — covering client records, curated clinical resources, scheduling, practitioner collaboration, and practice insights. This Policy explains how we handle personal data when you use Gatekeeper as a registered practitioner or facility ("Provider," "Facility," "you"). Our other products, including Sleepy Orange (our consumer companion app), are covered by their own privacy policies. Where a client of yours uses Sleepy Orange, Section 7.3 explains what that involves.
2. Definitions
- "Personal Data" — any data about an identifiable individual, per the Digital Personal Data Protection Act, 2023 ("DPDPA").
- "Data Fiduciary" — the entity that determines the purpose and means of processing; "Data Processor" — an entity that processes data on a Data Fiduciary's behalf and instructions. Section 6 explains which role we play for which data on Gatekeeper.
- "Client Data" — information about your patients/clients that you or your Facility enter into Gatekeeper (records, notes, assessments, scheduling details).
- "Sensitive/Health-Related Information" — data revealing physical or mental health status, diagnosis, treatment, or history — yours or your clients'.
3. Information We Collect
3.1 Your account and credentialing information
- Name, email, phone number, date of birth, gender, password, and profile photo.
- Professional licence/registration numbers and issuing authority (e.g., State Medical Council registration for psychiatrists, Rehabilitation Council of India registration for clinical psychologists, or the relevant certifying body for counsellors/therapists — see Gatekeeper Terms of Use Section 3 for why this varies by profession), educational qualifications, therapy modalities, specializations, resume/CV, and identity/verification documents.
- Facility registration details, business documents, and staff/practitioner affiliations, if you register a Facility.
- Billing details for your Gatekeeper subscription. Card/payment instrument data is handled by our payment processor, Razorpay, not stored on our servers.
3.2 Client Data you input
Records, intake notes, assessment results, session summaries, scheduling details, and communications you or your staff enter about your clients, to the extent you choose to use Gatekeeper for this purpose.
3.3 Usage and device data
- Device model, OS, app version, crash logs, IP address, and in-app interaction data, via in-house analytics tooling operated by The Zen India rather than a third-party analytics vendor.
- Approximate location derived from IP address only — Gatekeeper does not request precise device/GPS location.
4. How We Use Information
- Operate Gatekeeper's core features: records, scheduling, curated clinical resources, collaboration/network features, and practice insights.
- Verify practitioner credentials and facility registrations.
- Where a client of yours uses Sleepy Orange, your practice-management activity there (Section 7.3) — assigning care-plan tasks and seeing whether they're completed.
- Process your subscription billing.
- Maintain security, debug issues, and improve the product.
- Comply with legal, regulatory, and professional record-keeping obligations.
5. Legal Basis and Consent
We rely on your consent, given affirmatively at signup (not inferred from continued use), and on the limited "legitimate uses" the DPDPA permits for data you voluntarily provide us for a stated purpose. You may withdraw consent at any time (Section 11); this does not affect earlier processing and may limit features that depend on that data.
6. Fiduciary vs. Processor — Who Controls Client Data
For a Provider's/Facility's own account data (name, credentials, billing), we are the Data Fiduciary. For Client Data you enter about your patients, you are the Data Fiduciary — you decide what to record and why — and we act solely as a Data Processor, processing that data only on your instructions and for the purpose of operating Gatekeeper. We do not use Client Data for our own independent purposes beyond operating Gatekeeper, including for AI/product-analytics training across practitioners' data, except as separately disclosed to and agreed with you. As a Data Processor, we apply confidentiality and security obligations to our staff and sub-processors that are consistent with your own obligations as the treating practitioner.
7. How We Share Information
We do not sell personal data. We share it only as follows:
7.1 Service providers
| Recipient category | Data shared | Purpose | Location |
|---|---|---|---|
| Cloud hosting | Account, credentialing, and Client Data | Application hosting and storage | India |
| Analytics | Device/usage data (Section 3.3) | Product usage analytics | India — handled in-house by The Zen India, not a third-party vendor |
| Payment processor (Razorpay) | Billing details | Subscription billing | India |
| Email delivery (Hostinger) | Email, OTP and notification content | Account verification (OTP), appointment reminders, service and promotional notifications | India |
| Credential verification | Licence/registration details | Confirming professional credentials | India |
Publishing a specific, named list — rather than "various service providers" — is stronger practice than most competitor policies in this category default to. We'll keep this table current as any new vendor is added.
7.2 Legal and corporate
- Regulators, courts, or law enforcement where legally required.
- In connection with a merger, financing, or asset sale, subject to continued protection under this Policy or a comparable one.
7.3 Data Flow With Sleepy Orange
Sleepy Orange is a companion app for your clients, not a marketplace — clients don't discover or book you there independently of your existing relationship with them (a self-serve booking path may exist separately; see Sleepy Orange's own Privacy Policy). For a client using Sleepy Orange, the tasks you assign them in Gatekeeper appear as their care plan in Sleepy Orange, and you can see whether they've completed those tasks. Their mood check-ins, journal entries, and tracker data in Sleepy Orange are private to them and are not shared into your Gatekeeper account. This minimal-sharing design is a deliberate product commitment on the Sleepy Orange side, described in detail in its Privacy Policy.
8. Cross-Border Data Transfers
Our infrastructure is located in India. The DPDPA permits transfers outside India except to countries the Central Government restricts by notification; we monitor for such restrictions.
9. HIPAA and U.S. Health Data
Gatekeeper's Provider and Facility base is India-licensed only. HIPAA does not apply to our processing as a matter of law. If that changes — for example, if we onboard a U.S.-licensed Provider in the future — we will put a Business Associate Agreement in place with them as a standalone signable document, consistent with how mature practice-management platforms like SimplePractice handle it, rather than folding it into this Policy.
10. Data Retention
- Account/credentialing data: retained while your account is active, plus 3 years after closure for legal, tax, and dispute-resolution purposes.
- Client Data: since you are the Data Fiduciary for this data (Section 6), you control its retention and deletion within Gatekeeper's tools; we retain it only as long as your account instructs, subject to a 90-day backup cycle after deletion.
- We give a specific number here deliberately — vague retention language ("as long as necessary") is a documented weak point in comparable apps' privacy policies and something DPDPA reviewers flag.
11. Your Rights
11.1 Under the DPDPA
- Access a summary of personal data we hold about you and how we process it.
- Correction and updating of your personal data.
- Erasure of personal data no longer necessary for its purpose, subject to our legal retention obligations.
- Grievance redressal through our Grievance Officer (Section 17) before escalating to the Data Protection Board of India.
- Nominate another individual to exercise these rights on your behalf in case of death or incapacity.
- Withdraw consent at any time, as easily as it was given.
- Object to or pause non-essential processing (e.g., product analytics) without affecting your core access to Gatekeeper.
We will acknowledge rights requests within 7 days and substantively respond within 30 days — a concrete commitment, not an open-ended one.
11.2 GDPR/CCPA (if applicable)
EEA/UK Users additionally have rights to portability, restriction, and objection under GDPR; California residents have rights under CCPA/CPRA. We do not sell personal data.
12. Children's Privacy
Gatekeeper accounts are for adult practitioners and facility administrators (18+). Client Data you enter may relate to minor clients if your own practice serves minors; you remain responsible for obtaining any consent required from a minor client's parent/guardian under applicable law before recording their data in Gatekeeper.
13. Email Communications
We send OTP codes, appointment reminders, and service notifications by email only — we do not use SMS or WhatsApp for Gatekeeper. We also send promotional messages to Providers and Facilities by email — product updates, feature announcements, and similar communications. Transactional messages (OTPs, security alerts) don't require separate opt-in beyond your account consent. Promotional messages require their own opt-in and a working unsubscribe link in every message, consistent with TRAI's commercial-communication consent framework, in addition to the DPDPA's consent requirements. You can opt out of promotional messages at any time without affecting transactional messages tied to your account or your clients' care.
14. Cookies and Similar Technologies
Gatekeeper the app uses cookies/SDKs to keep you signed in, remember preferences, and understand usage, as described in Section 3.3. Our marketing website, thezenindia.in, is a separate property with its own cookie banner and cookie policy; this section covers the app only.
15. Data Security
We apply administrative, technical, and physical safeguards, including encryption in transit and at rest, and access controls limiting Client Data visibility to your own account and authorized Facility staff on a role-based basis. We are not currently pursuing ISO 27001 certification; we may revisit this as the product and client base grow. No system is completely secure; we will notify you and the Data Protection Board of India of any breach affecting your data without undue delay, per DPDPA requirements.
16. Confidentiality Under the Mental Healthcare Act, 2017
Section 23 of the Mental Healthcare Act, 2017 requires mental health professionals and establishments to keep a person's mental health information confidential, subject to narrow statutory exceptions. Gatekeeper is a tool that helps you meet that obligation; the underlying confidentiality duty toward your clients remains yours as the treating practitioner, independent of how the platform is built.
17. Grievance Officer
Grievance Officer / Privacy Contact: Somil Garg
Email: admin@thezenindia.in
Correspondence address: 565, Kasturba Gandhi Marg, Niti Khand-1, Indirapuram, Uttar Pradesh 201014, India
Registered office: P.No. 934, KH N-115, Gali-1, Mala Devi School Marg, Shahdara, Delhi, India 110032
If unsatisfied with our response, you may escalate to the Data Protection Board of India once operational.
18. Contact Us
Email: connect@thezenindia.in
Phone: (India) +91 98992 99775, (US) +1 347 879 5210
19. Changes to This Policy
We'll notify you in-app or by email of material changes before they take effect. Continued use after that constitutes acceptance.