Legal
Compliance
Last reviewed: May 2026
Zelnoo is a health-tech marketplace — a technology platform that connects users with independent, accredited diagnostic partners. We are not a clinical establishment, hospital, or healthcare provider, and the medical regulations that govern those entities do not apply to us. The frameworks below are the ones that actually apply to Zelnoo as a consumer technology platform handling personal data in India.
DPDP Act, 2023 — Digital Personal Data Protection
India's Digital Personal Data Protection Act, 2023 is the primary law governing how digital businesses collect, process, store, and transfer personal data. Zelnoo operates as a Data Fiduciary — we hold your data in trust, process it only with consent, and enable data principals (you) to exercise rights of access, correction, and erasure.
- Granular consent captured at each data collection point
- Data stored within India (AWS ap-south-1)
- Data minimisation — we collect only what is necessary
- Users can correct or delete personal data at any time
- Breach reporting to the Data Protection Board as required
IT Act, 2000 + Intermediary Guidelines, 2021
Zelnoo is an "intermediary" under the Information Technology Act, 2000 — a technology platform that connects users with independent third-party service providers. We comply with the Intermediary Guidelines, 2021 covering due diligence, grievance redressal, takedown obligations, and published terms of use.
- Grievance Officer appointed and contactable on the platform
- Published terms of use and privacy policy
- Takedown response within statutory timelines
- Due diligence on third-party content and listings
Consumer Protection (E-Commerce) Rules, 2020
As a marketplace e-commerce entity, Zelnoo follows the Consumer Protection (E-Commerce) Rules, 2020. We disclose the identity of the diagnostic partner fulfilling each order, publish transparent pricing, and provide a clear refund, cancellation, and grievance redressal mechanism.
- Partner lab clearly identified at the point of purchase
- Transparent, all-inclusive pricing — no hidden fees
- Published refund and cancellation policy
- Consumer grievance channel with defined response SLAs
- No manipulated ratings or fake reviews
SOC 2 Type II
We are preparing for a SOC 2 Type II audit covering the Security, Availability, and Confidentiality trust service criteria. This is a voluntary, internationally recognised attestation of our internal controls. Our current security controls already align with SOC 2 — the audit formalises and certifies them.
- Scope: Security, Availability, Confidentiality TSCs
- Expected completion: Q4 2026
- Current controls audited internally against SOC 2 criteria
ISO 27001 — Information Security Management
ISO 27001 certification formalises our Information Security Management System (ISMS). It is a voluntary standard we are pursuing alongside SOC 2 to give partners and enterprise customers an independent assurance of how we operate.
- ISMS scope: all production systems and data stores
- Risk assessment framework in place
- Target: Q4 2026
What applies to our partners, not to Zelnoo
Tests and reports are produced by independent diagnostic laboratories. The medical and clinical-establishment regulations below are obligations on those partners. Zelnoo verifies them at onboarding, but we do not perform diagnostics ourselves.
NABL accreditation (ISO 15189)
Diagnostic services are delivered by independent partner laboratories. We require every partner to hold current NABL accreditation against ISO 15189 medical laboratory standards. We verify accreditation at onboarding and re-verify annually.
Clinical Establishments Act, 2010
Where applicable in a partner's state, we require a valid Clinical Establishments Act registration certificate. Sample collection, testing, and reporting remain the regulatory responsibility of the registered clinical establishment.
Report retention and complaint handling
Partners retain diagnostic reports for the minimum period mandated under applicable law and operate their own complaint resolution processes for clinical matters. Zelnoo handles platform-level grievances; clinical disputes are escalated to the issuing lab.
Compliance or audit enquiries: compliance@zelnoo.com
