Zuredex LLC ("Zuredex," "we," "us") operates the Zuredex operational intelligence platform (the "Service"), used by medical device sales organizations, surgical distributors, and sales operations teams to reconcile surgical case sheets against purchase orders. This policy describes how data is handled when you or your organization use the Service.
Account credentials are managed securely via Google Firebase Authentication with multi-factor authentication (MFA). We do not store raw passwords; authentication is delegated to Firebase's managed identity infrastructure.
Uploaded documents (case sheets, purchase orders) are processed and stored using Google Cloud Storage and BigQuery for reconciliation. Documents are processed within your organization's isolated tenant and are not accessible to other tenants.
Where documents contain Protected Health Information ("PHI"), Zuredex acts as a Business Associate under a HIPAA Business Associate Agreement (BAA) with its customers. Zuredex minimizes PHI exposure — patient identifiers are not required for reconciliation and are not extracted into structured records. Document access is access-controlled and audit-logged.
Zuredex uses Google Cloud Platform and Firebase as infrastructure sub-processors. Business Associate Agreements and data processing terms are maintained with sub-processors that handle PHI.
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Tenant data is isolated at the query layer, and access controls are enforced fail-closed.
Customer data is retained or disposed of in accordance with the applicable Business Associate Agreement and customer agreements.
This policy may be updated from time to time. Material changes will be reflected by updating the effective date below.
Questions about this policy can be directed to analytics@zuredex.com.
Questions about this policy? Contact us at analytics@zuredex.com.