Security & Data Protection
Last updated: July 20, 2026 — Version 1.0
This page describes the technical and organizational measures Zero Headache uses to protect personal data processed through the Service. It forms part of our Data Processing Agreement and our HIPAA-aligned configuration.
1. Encryption
Personal data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Call audio and transcripts are encrypted in storage and during transmission to and from sub-processors.
2. Access control
Access to systems that process personal data is restricted to personnel who require it to operate the Service. Access is granted on a least-privilege basis, reviewed periodically, and revoked on role change or departure. All access to production systems is logged and auditable.
3. Hosting & region
The Service is hosted on cloud infrastructure with region-pinned storage for clients who require data residency. EU clients can have data processed and stored in the European Union. US healthcare clients can have PHI processed and stored in the United States. See the Sub-processor List for the hosting providers and their regions.
4. Sub-processors
Each sub-processor is bound by data-protection terms no less protective than our DPA. We do not engage a sub-processor that touches personal data without a signed agreement covering security, confidentiality, and breach notification. See the Sub-processor List for the current set and the DPA for the change-notification process.
5. Incident response
We maintain an incident-response process for security incidents involving personal data. On becoming aware of a confirmed breach, we notify affected clients without undue delay and in any event within 72 hours, consistent with GDPR Article 33. Where required, we notify the relevant supervisory authority or the Indian Data Protection Board, and we support clients in notifying affected individuals.
6. Retention & deletion
Call recordings and transcripts are retained for the period instructed by the client, or until the end of the service relationship. The default retention period for call recordings and transcripts is 6 months unless you instruct us otherwise, and the zero-data-retention option, available as a paid add-on, for healthcare clients purges them after CRM sync. On termination, client data is returned or deleted at the client's direction. Data and traffic logs are retained for at least one year, as required by India's DPDP Rules 2025.
7. No use of personal data for model training
We do not use client or end-customer personal data, call audio, or transcripts to train, improve, or fine-tune any AI model, ours or our sub-processors', without the client's explicit written authorization.
8. Certifications & roadmap
We are working toward SOC 2 Type II. Until that is achieved, we make our security documentation available to clients under NDA on reasonable request. Composio, one of our integration providers, holds SOC 2 and ISO 27001:2022.
9. Contact
Security questions and incident reports can be sent to legal@zeroheadache.co.













