ZEPHYRx PRIVACY POLICY
ZEPHYRx Privacy Notice
As of April 30, 2026
At a Glance
ZEPHYRx provides technology used in healthcare and clinical research. We do not provide medical care. Your privacy rights and how your data is handled depend on your relationship with ZEPHYRx.
If you are a patient or research participant
· Your healthcare provider or study sponsor controls your data
· ZEPHYRx processes your information on their behalf
· Please contact your provider or sponsor for questions about your health data
If you are a healthcare provider or customer
· We provide services as your vendor (Business Associate / Processor)
· You determine how personal and health information is used
If you are a website visitor or business contact
· We process your information for our own business purposes (Controller)
· This includes operating our website, managing relationships, and communications
ZEPHYRx is established in the United States and has appointed a representative in the European Union and the United Kingdom. Contact details are provided in the “Contact Us” section below.
1. Introduction and Scope
ZEPHYRx, LLC (“ZEPHYRx,” “we,” “us,” or “our”) provides cloud-based respiratory monitoring solutions used in healthcare delivery and decentralized or hybrid clinical trials, including patient-facing applications, provider dashboards, device-enabled testing workflows, and related support services.
This Privacy Notice explains how we collect, use, disclose, and otherwise process personal information in connection with:
· Our website and related online services
· Our respiratory monitoring platform and related software, applications, dashboards, integrations, and support services
· Our interactions with healthcare providers, research organizations, sponsors, sites, vendors, partners, and other business contacts
Our role in processing personal information depends on how you interact with us.
· In some cases, we act on behalf of healthcare providers, research sponsors, or other customers
· In other cases, we process personal information for our own business purposes
For purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA), ZEPHYRx may act as a controller, processor, or business associate, depending on the circumstances described in this Privacy Notice.
Important Information About Health Data
ZEPHYRx provides technology services but does not provide medical care directly to patients.
If you are a patient or research participant whose information is processed through our platform:
· Your healthcare provider or study sponsor determines how your information is used
· They are responsible for providing applicable privacy notices
· They are responsible for responding to your requests regarding your health information
Please contact your healthcare provider or study sponsor directly for questions about your health data.
2. Our Role in Processing Personal Information
ZEPHYRx operates in different roles depending on the context in which personal information is processed. The distinctions below apply throughout this Privacy Notice.
We do not engage in automated decision-making that produces legal or similarly significant effects.
When we act as a Processor (GDPR)
We process personal information on behalf of our customers, including healthcare providers, pharmaceutical companies, and research organizations.
· Our customers determine the purposes and means of processing
· We process data only in accordance with their instructions
When we act as a Business Associate (HIPAA)
We may create, receive, maintain, or transmit Protected Health Information (PHI) on behalf of healthcare providers.
· Our use and disclosure of PHI is governed by Business Associate Agreements (BAAs) and applicable law
· We do not independently determine how PHI is used beyond our contractual obligations
When we act as a Controller
We act as a controller when we process personal information for our own purposes, including:
· Operating and securing our website
· Managing relationships with customers and partners
· Marketing and promoting our services
· Improving and developing our services
3. Categories of Individuals Covered by This Notice
Categories of individuals we engage with as a Controller:
· Website Visitors – individuals who visit or interact with our website
· Business Contacts – representatives of customers, partners, and vendors
Categories of individuals we engage with as a Processor / Business Associate
· Healthcare Providers and Staff – users of our platform
· Patients – individuals whose respiratory data is collected through our platform
· Research Participants – individuals participating in clinical trials or studies using our services
In many cases, particularly for patients and research participants, ZEPHYRx receives personal information indirectly from our customers, sites, providers, study teams, connected devices, or integrated systems, rather than directly from the individual.
4. Personal Information We Collect
We collect personal information as a Controller either directly from you or automatically via our website; and as a Processor from our healthcare customers, depending on how you interact with ZEPHYRx and the role we play in the processing.
If you do not provide certain personal information, we may not be able to respond to inquiries or to provide requested services.
Information You Provide Directly (Controller)
· Name, email, phone number, organization, and role
· Communications and inquiries (e.g., demo requests, contact forms)
Information Collected Automatically (Controller)
· IP address, device and browser information
· Website usage data (pages viewed, interactions, timestamps)
· Cookie and tracking data (see below)
Information Received from Customers and Systems (Processor / Business Associate)
· Patient identifiers and demographic data
· Provider and user account information
· Respiratory measurements
· Symptom, adherence, and survey data
· Clinical, operational, and workflow data
· Data from connected devices and integrations
Special Category Data
ZEPHYRx does not process health data as a Controller. Some data processed through our platform may include health data and we do so only as a HIPAA Business Associate or a Processor.
Cookies and Tracking Technologies
We use cookies and similar technologies to collect information about how you interact with our website. Cookies are small text files stored on your device that help the site function and improve user experience.
We use:
· Strictly necessary cookies to operate the website (e.g., security and session management)
· Analytics cookies to understand and improve website performance
· Functional cookies to enable enhanced features and personalization
· Marketing cookies to deliver relevant content and measure effectiveness
You can withdraw your consent and manage your preferences at any time through our cookie banner or your browser settings. Disabling certain cookies may affect website functionality.
5. How We Use Personal Information
As a Controller:
· Operate and maintain our website
· Respond to inquiries and manage business relationships
· Provide requested information or communications
· Improve, secure, and analyze our services
· Prevent fraud and ensure system integrity
· Comply with legal obligations
As a Processor / Business Associate:
· Provide and maintain our platform and services
· Enable respiratory monitoring and data collection
· Support healthcare delivery and research activities
· Provide onboarding, integration, and support services
· Ensure system performance and security
6. Legal Bases for Processing
Where ZEPHYRx acts as a Controller, we rely on the following legal bases depending on the purpose of processing:
· Providing and responding to requests and business relationships - Contractual necessity and legitimate interests in managing and developing our business relationships
· Operating, maintaining, and securing our website and services - Legitimate interests in operating, securing, and maintaining a reliable platform
· Improving and developing our services - Legitimate interests in analyzing usage and improving our services
· Marketing and communications - Consent, where required and withdrawable at any time, and otherwise legitimate interests in promoting our services to business contacts, subject to applicable law
· Cookies and tracking technologies - Consent for non-essential cookies and legitimate interests for strictly necessary cookies
· Compliance with legal obligations - Processing necessary to comply with applicable laws and regulations
Where we act as a Processor or Business Associate, processing is carried out on documented instructions from our customers, and the applicable legal basis is determined by the customer.
7. How We Share Personal Information
We may share personal information with the following categories of recipients, depending on our role and the context of processing:
· Service Providers – vendors supporting hosting, infrastructure, analytics, security, and operations, who process data on our behalf under contractual safeguards
· Customers and Customer-Directed Recipients – including healthcare providers, research organizations, sponsors, clinical sites, and study teams, where we process and disclose data on behalf of and at the direction of our customers
· Healthcare and Research Systems and Integrations – including electronic medical record (EMR/EHR) systems, connected devices, and integration partners, where necessary to provide services or enable customer-configured workflows
· Professional Advisors – legal, audit, and compliance advisors, subject to confidentiality obligations
· Authorities and Legal Recipients – where required by law, regulation, legal process, or to protect rights, safety, or security
Where ZEPHYRx acts as a Processor or Business Associate, we share personal information only:
· On documented instructions from our customer.
· As necessary to provide the services under our agreements
We implement appropriate contractual safeguards, including data processing agreements and business associate agreements, as applicable.
8. Your Rights
Your rights depend on the context in which your personal information is processed.
When We Act as a Controller
· Right of Access – to obtain confirmation of whether we process your personal information and access to that data
· Right to Rectification – to request correction of inaccurate or incomplete personal information
· Right to Erasure – to request deletion of your personal information in certain circumstances
· Right to Restriction of Processing – to request that we limit how we use your personal information
· Right to Data Portability – to receive your personal information in a structured, commonly used, and machine-readable format, where applicable
· Right to Object – to object to processing based on our legitimate interests
· Right to Withdraw Consent – where processing is based on consent, you may withdraw consent at any time
When We Act as a Processor or Business Associate
If your personal information is processed on behalf of a healthcare provider or research sponsor:
· That organization is responsible for responding to your requests
· ZEPHYRx does not independently control how your data is used
· We support Covered Entities in fulfilling their obligations under HIPAA, including access, amendment, and accounting of disclosures
Please contact your healthcare provider or study sponsor directly.
Additional Information for EEA/UK Users
You have the right to lodge a complaint with a supervisory authority and to request information about safeguards used for international data transfers.
Exercising Your Rights
To exercise your rights where ZEPHYRx acts as a Controller, please contact us using the details below. We may need to verify your identity before responding to your request. We will respond in accordance with applicable data protection laws and may decline or limit requests where permitted by law.
9. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected.
· As a Controller: based on purpose, nature of data, and legal requirements - business and customer data for the duration of the relationship and a limited period thereafter; marketing data until you opt out or withdraw consent.
· As a Processor or Business Associate: based on customer instructions, Business Associate Agreements and contractual obligations, and applicable law
We may retain certain information longer where required to comply with legal obligations, resolve disputes, or defend legal claims.
10. Data Security and Breach Notification
We implement technical and organizational measures designed to protect personal information, including access controls, encryption, monitoring, audit logging, workforce training, and incident response procedures.
When acting as a Processor or Business Associate, we implement safeguards in accordance with our contractual obligations and applicable law, including the HIPAA Security Rule.
While we maintain these safeguards, no system can be completely secure.
In the event of a breach of unsecured PHI, ZEPHYRx will notify the controller or Covered Entity in accordance with applicable law and contractual obligations. When ZEPHYRx acts as a Controller, we will respond to and notify individuals and regulators of personal data breaches as required under applicable data protection laws.
11. International Transfer
ZEPHYRx is headquartered in the United States and may process personal information in the United States and other countries where ZEPHYRx, its affiliates, service providers, partners, or customer-directed recipients operate.
Where personal information is transferred outside of the European Economic Area (EEA), the United Kingdom, or Switzerland, we ensure that appropriate safeguards are in place in accordance with applicable data protection laws. These safeguards include:
· The European Commission’s Standard Contractual Clauses (2021/914), as applicable to our role as a processor
· The UK International Data Transfer Addendum, where required
· Supplementary technical, contractual, and organizational safeguards where appropriate
We conduct transfer impact assessments and implement supplementary technical and organizational measures, where necessary, to ensure that transferred personal information remains protected to a standard essentially equivalent to that provided in the EEA. These measures may include encryption, access controls, and contractual commitments.
Where we engage subprocessors located outside of the EEA, we ensure that such subprocessors are subject to equivalent data protection obligations and transfer safeguards. A list of subprocessors is available upon request.
Further information regarding these safeguards, including a copy of relevant contractual protections, may be requested by contacting us at legal@zephyrx.com.
12. Changes to This Privacy Notice
We may update this Privacy Notice from time to time. We will post the updated version on this page with a revised effective date.
13. Contact Us
If you have questions about this Privacy Notice or wish to exercise your rights where ZEPHYRx acts as a Controller, please contact us:
ZEPHYRx, LLC
Email: legal@zephyrx.com
Address: 433 River Street, Suite 6004, Troy, New York 12180
EU and UK Representative
General Data Protection Regulation (GDPR) – European Representative
Pursuant to Article 27 of the General Data Protection Regulation (GDPR), ZEPHYRx has appointed European Data Protection Office (EDPO) as its GDPR Representative in the EU. You can contact EDPO regarding matters pertaining to the GDPR:
· by using EDPO’s online request form: https://edpo.com/gdpr-data-request/
· by writing to EDPO at Avenue Huart Hamoir 71, 1030 Brussels, Belgium
UK General Data Protection Regulation (GDPR) - UK Representative
Pursuant to Article 27 of the UK GDPR, ZEPHYRx has appointed EDPO UK Ltd as its UK GDPR representative in the UK. You can contact EDPO UK regarding matters pertaining to the UK GDPR:
· by using EDPO’s online request form: https://edpo.com/uk-gdpr-data-request/
· by writing to EDPO UK Ltd, Unit 33, Waterside, Schooner Court, 44-48 Wharf Road, London, N1 7UX, United Kingdom
