Zovera Back to site
Legal

Privacy Policy

Effective Date: April 30, 2026 · Last Updated: April 30, 2026

Zovera Inc. ("Zovera", "we", "us") is committed to protecting your privacy and handling your personal information responsibly, in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable Canadian laws. This Privacy Policy describes how we collect, use, disclose, and protect your information when you use our website and Services.

By using our Services, you expressly consent to the collection and use of your personal information as described in this Policy. Because we collect health-related information, we treat all personal data as sensitive and apply heightened safeguards accordingly.

Contents
  1. Information We Collect
  2. How We Use Your Information
  3. Legal Basis & Consent
  4. Data Sharing
  5. Automated Decision-Making
  6. Data Security
  7. Data Retention
  8. Your Rights
  9. Breach Notification
  10. Cookies & Tracking
  11. Third-Party Links
  12. International Users
  13. Children's Privacy
  14. Changes to This Policy
  15. Contact & Privacy Officer
Section 1

Information We Collect

a. Information You Provide

  • Name, email address, and contact details
  • Health, lifestyle, and supplement-related information submitted through our intake assessment
  • Medications, medical conditions, dietary habits, sleep patterns, and health goals
  • Payment information (processed by third-party payment providers — we do not store full payment card details)

b. Automatically Collected Data

  • IP address and approximate location
  • Device type, operating system, and browser information
  • Website usage data, including pages visited, time on site, and referral source
  • Cookies and similar tracking technologies (see Section 10)

Sensitive Data: Health and lifestyle information collected through our intake form is treated as sensitive personal information and is subject to heightened protection under PIPEDA.

Section 2

How We Use Your Information

We use your information to:

  • Generate your personalized supplement protocol report
  • Provide customer support and respond to inquiries
  • Process payments and manage transactions
  • Improve our Services, platform, and AI models (using de-identified or aggregated data where possible)
  • Communicate service updates, policy changes, or support-related information
  • Send marketing or promotional communications, only with your express consent
  • Comply with applicable legal obligations
Section 3

Legal Basis & Consent

By completing our intake assessment and using our Services, you provide express, informed consent to the collection, use, and disclosure of your personal information — including health information — for the purposes described in this Policy.

You may withdraw your consent at any time by contacting us at clientsupport@zovera.ai. Withdrawal of consent may affect our ability to provide the Services to you. We will process withdrawal requests within 30 days.

Section 4

Data Sharing

We do not sell your personal data.

We may share your data with trusted third-party service providers for operational purposes, including:

  • Cloud hosting providers — for secure data storage and infrastructure
  • AI processing services — to generate your personalized report (health intake data may be processed by AI providers under confidentiality agreements)
  • Payment processors — to securely handle transactions
  • Email and communication platforms — to deliver reports and support communications
  • Analytics providers — to understand website usage (using aggregated or anonymized data where possible)

All third-party providers are required to maintain appropriate confidentiality, security, and data protection obligations consistent with PIPEDA requirements. We do not authorize third parties to use your personal data for their own purposes.

We may also disclose your information if required by law, court order, or regulatory authority.

Section 5

Automated Decision-Making

Transparency Notice: Your supplement protocol report is generated through automated AI processing of your intake data, without individual human clinical review of each output. You have the right to request human review or to ask questions about how your report was generated by contacting us at clientsupport@zovera.ai.

Zovera's AI tools are not approved as regulated medical devices or clinical decision-support systems under Health Canada or any other regulatory framework. Automated outputs are intended for informational purposes only.

Section 6

Data Security

We implement industry-standard technical and organizational safeguards to protect your personal information, including:

  • Encryption in transit (TLS/HTTPS) and at rest
  • Secure data storage systems with access controls
  • Restricted internal access on a need-to-know basis
  • Regular review of security practices

However, no system is 100% secure. We cannot guarantee absolute security of information transmitted over the internet.

Section 7

Data Retention

We retain your personal information only as long as necessary to fulfill the purposes for which it was collected:

  • Account and report data — retained for up to 3 years after your last interaction with the Service, to support re-orders, revisions, and customer service
  • Legal and compliance records — retained for up to 7 years where required by applicable law (e.g., financial records under the Income Tax Act)
  • Aggregated / de-identified analytics data — may be retained indefinitely as it no longer constitutes personal information

When personal information is no longer required, we securely destroy or anonymize it.

Section 8

Your Rights

Under PIPEDA, you have the right to:

  • Access — request a copy of the personal information we hold about you
  • Correction — request correction of inaccurate or incomplete information
  • Deletion — request deletion of your personal information, subject to legal retention obligations
  • Withdraw consent — withdraw consent to the collection and use of your data at any time
  • Complain — file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca if you believe your privacy rights have been violated

To submit a request, contact us at: clientsupport@zovera.ai

We will acknowledge your request and respond within 30 days, subject to any applicable legal obligations.

Section 9

Breach Notification

In the event of a breach of security safeguards involving your personal information that poses a real risk of significant harm, we will:

  • Notify the Office of the Privacy Commissioner of Canada as required under PIPEDA's Breach of Security Safeguards Regulations
  • Notify affected individuals directly as soon as reasonably practicable
  • Maintain a record of all breaches for a minimum of 24 months
Section 10

Cookies & Tracking

We may use cookies and similar technologies for the following purposes:

  • Essential cookies — required for the Service to function (cannot be disabled)
  • Analytics cookies — to understand how visitors use our website (e.g., page visits, session duration)
  • Marketing cookies — only with your express consent, to deliver relevant advertising

You can manage your cookie preferences through your browser settings. Disabling non-essential cookies will not affect your ability to access the core Service. Where required, we will seek your consent before deploying non-essential tracking technologies.

Section 11

Third-Party Links

Our platform may contain links to third-party websites and retailers (such as supplement marketplaces or product pages). We are not responsible for the privacy practices, content, or data handling of those third-party sites. We encourage you to review the privacy policies of any external sites you visit.

Section 12

International Users

Zovera is operated from Ontario, Canada. If you access the Services from outside Canada, your personal information — including health intake data — may be transferred to and processed in Canada or by third-party service providers in other jurisdictions (such as the United States), where data protection laws may differ from those in your country.

By using the Services, you consent to this transfer and processing. We take reasonable steps to ensure that third-party processors in other jurisdictions maintain privacy protections consistent with PIPEDA.

Section 13

Children's Privacy

Zovera is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected information from a person under 18, we will promptly delete that information. If you believe a minor has submitted information through our Services, please contact us at clientsupport@zovera.ai.

Section 14

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. For material changes, we will provide reasonable advance notice by email or by posting a notice on our website, with the updated effective date. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

Section 15

Contact & Privacy Officer

Zovera Inc. has designated a Privacy Officer responsible for overseeing compliance with this Policy and applicable privacy legislation.

For privacy-related inquiries, access requests, or complaints:

Privacy Officer, Zovera Inc.
legal@zovera.ai

For client support requests:

clientsupport@zovera.ai

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada:
www.priv.gc.ca · 1-800-282-1376

© 2026 Zovera Inc. All rights reserved.  ·  Terms of Service  ·  Privacy Policy