Privacy policy
ZenLocate is in early access. This policy describes how the service handles information as it works today, and we will update it as the product develops.
Who we are
ZenLocate is an indoor asset-tracking service for hospitals and senior care operators, built by ZenduIT / GoFleet. Your organisation — the hospital or care home that signs up — is our customer, and its administrators decide who is allowed to use the service.
What the WhatsApp service collects
When a member of your staff sends a message to the ZenLocate WhatsApp number, we receive two things:
- The phone number the message came from. We use it to check the sender against your organisation's list of authorised staff.
- The text of the message. We read it to work out what is being asked — which item, which zone, which kind of equipment.
We do not read WhatsApp profile names, contact lists, photos, or any other conversation on the phone.
What we do with it
The phone number authenticates the sender. If a number is not on your authorised list, the service replies to say so and does nothing else with the message.
The message text is used only to answer the question — locating a piece of tagged equipment, listing what has left its home zone, and similar. It is processed in memory to produce the reply, and the service does not write message content to storage. Message identifiers are held in memory for about ten minutes so that a retry from WhatsApp cannot produce a duplicate reply.
Messages travel through WhatsApp
The service is built on the WhatsApp Business Platform, which is operated by Meta. Messages between your staff and ZenLocate pass through Meta's systems, and Meta's own terms and privacy practices apply to that part of the journey. That leg is not under our control.
We do not send patient or resident names
This matters, so it is stated plainly: ZenLocate does not transmit the names of patients or residents over WhatsApp. People who are tracked wear a badge identified by a number — “Badge 118”, for example — and that number is what the service uses. Connecting a badge number to a person is something your organisation does in its own records, not something ZenLocate holds.
Location data
Location information in ZenLocate relates to tagged equipment — wheelchairs, beds, pumps — and to anonymous badge numbers. It records where a tag was detected and when. It is not a record of identified individuals.
How long we keep things
Location history is retained as part of your organisation's account, so your team can ask where something was last seen. We have not set a fixed retention period for early-access sites. If your organisation needs a defined retention or deletion schedule, tell us and we will agree it with you in writing.
Requests, questions and deletion
To ask what the service holds for your organisation, or to request that it be deleted, use the contact form on our main page and tell us what you need.
If you are a member of staff and want your phone number removed from the authorised list, your site administrator can remove it, or you can reach us with the same form.
This website
These marketing pages set no tracking or advertising cookies, and we run no analytics on them. The pages do load typefaces from Google Fonts, which means Google receives your IP address when a page loads.
What this policy does not claim
ZenLocate is a pre-launch product. We make no claim of HIPAA, PHIPA or any other regulatory certification, and nothing here should be read as one. If your organisation needs a data processing agreement or a security review before a pilot, ask and we will work through it with you.
Changes to this policy
When the service changes, this page changes with it. The date above shows the last revision.