Privacy Policy
How we handle information in a business-to-business engagement
Last updated: July 2026
1. Who this covers
ZIONN is a software engineering and AI company that operates from the United States and works with clients worldwide. We work business-to-business: our clients are organizations, and the people we deal with are acting on behalf of those organizations.
This policy covers two different things, and it is worth separating them:
- Information we collect for ourselves, through this website and in the ordinary course of a commercial relationship.
- Information we process on behalf of a client, inside systems we build or operate for them.
The second category is governed by the agreement with that client, not by this policy. In those engagements the client decides what is collected and why; we act on their instructions.
2. What we collect for ourselves
When you use this site or contact us, we may collect:
- Contact details you give us: name, work email, phone, company, and what you tell us about your systems.
- Records of our correspondence, including messages sent through the assistant on this site.
- Basic technical information from your browser, such as device type and general location, used to keep the site working.
We do not require personal information to browse this site.
3. Why we use it
We use the information above to respond to enquiries, scope and deliver work, meet our contractual and legal obligations, and keep our own systems secure.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
4. Client data and confidentiality
When an engagement gives us access to a client environment, we treat everything in it as confidential. Specifically:
- Access is limited to the engineers assigned to that engagement, and only for as long as they need it.
- We work in client-controlled environments wherever the client prefers that.
- We do not use client data to train models, benchmark, or build anything outside that engagement.
- On request or at the end of an engagement, we return or delete the data and confirm when it is done.
5. Protected Health Information (HIPAA)
Some of our clients are covered entities or business associates under the Health Insurance Portability and Accountability Act. Where an engagement involves Protected Health Information (PHI), ZIONN acts as a Business Associate.
In those engagements:
- We execute a Business Associate Agreement before any access to PHI is granted.
- We apply the administrative, physical, and technical safeguards required under the HIPAA Security Rule.
- PHI is accessed only by named personnel, on the minimum-necessary principle, with access logged.
- PHI is encrypted in transit and at rest, and is not moved outside environments agreed with the client.
- We do not use or disclose PHI other than as permitted by the BAA and by law.
- We notify the client of any suspected breach without unreasonable delay, and cooperate with their obligations.
Where our subcontractors touch PHI, they are bound by equivalent written terms.
6. Sharing
We share information only where it is needed to do the work or required by law:
- Service providers that support our own operations, under written terms.
- Professional advisers, where they are bound by confidentiality.
- Authorities, where we are legally compelled. We tell the client unless prohibited from doing so.
7. Retention
We keep commercial correspondence for as long as the relationship is active and for the period we are required to retain records afterwards. Data held on behalf of a client is retained under that client’s instructions and returned or deleted at the end of the engagement.
8. Your choices
You can ask us what information we hold about you, ask us to correct it, ask us to delete it, or unsubscribe from anything you have signed up for. Write to privacy@zionn.io.
If your organization is our client and the request concerns data inside a system we run for them, we will forward the request to them, because they decide how it is answered.
9. California residents
If you are a California resident, you have the right to know what personal information we collect, to request its deletion or correction, and to be free from discrimination for exercising those rights.
ZIONN does not sell or share personal information as those terms are used in the California Consumer Privacy Act. To exercise a right, write to privacy@zionn.io.
10. Contact
ZIONN. 4909 Webbed Foot Way, Ellicott City, MD 21043, United States. Privacy questions: privacy@zionn.io.