menchipatient concierge

Menchi Privacy Policy

This Privacy Policy describes how Zalto Inc. (operating Menchi) handles personal health information (PHI) and other personal information collected through Menchi services. Menchi is offered to healthcare clinics in Canada (currently Ontario) as a digital concierge service.

This Policy is aligned with Ontario’s Personal Health Information Protection Act, 2004 (PHIPA) and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).

Effective date: 2026-04-30
Last reviewed: 2026-04-30

1. Who we are

Zalto Inc. is a federal Canadian-controlled private corporation incorporated under the Canada Business Corporations Act on March 25, 2026, with its registered office in Mississauga, Ontario. Zalto Inc. operates the Menchi product.

When a clinic uses Menchi to handle their phone calls, the clinic is the Health Information Custodian (HIC). They own the patient relationship and the legal duties under PHIPA. Zalto Inc. acts as the clinic’s Information Manager / Agent under PHIPA section 10, processing PHI strictly on the clinic’s behalf.

2. What information we collect

When a patient calls a clinic that uses Menchi, the following may be collected:

  • The patient’s name (if provided during the call)
  • The patient’s phone number (automatically captured by the phone system)
  • A written transcript of the call
  • The reason for the call and any appointment details discussed
  • The date and time of the call and any appointment booked
  • A record of which clinic staff members accessed the call data and when (audit log)

We do not collect data Menchi does not need to perform its function. We do not ask patients for medical history, social insurance numbers, or financial information.

3. How we use this information

We use the collected information only to:

  • Route the call between the patient and the clinic
  • Generate a transcript and booking record for the clinic
  • Maintain audit logs as required by PHIPA section 10.1 and our Information Manager Agreements with clinics
  • Respond to clinic-directed access, correction, or deletion requests
  • Comply with applicable Canadian law

We do not use any patient call data to train artificial intelligence systems. This applies to Menchi’s own systems and to all our service providers. Menchi’s product improvement is conducted on synthetic data, public sources, and direct feedback from clinic staff. Never on real patient calls.

We do not use patient information for marketing, profiling, or any purpose other than what the clinic has engaged us for.

4. Who we share this information with

We share patient call data only with our service providers (sub-processors) who help us deliver Menchi services. The full list, including each provider’s role, country, and data-handling tier, is published at trymenchi.com/sub-processors and updated whenever it changes.

In summary:

  • Real-time call processing is handled by US-based providers (Twilio, with Deepgram and ElevenLabs inside Twilio’s voice session, and Anthropic) under data protection addenda
  • Storage of transcripts and bookings is in Canada (Supabase, ca-central-1, Montréal)
  • Application runtime is on Vercel in a Canadian region

We do not sell patient information. We do not share it with advertisers, data brokers, or any third party other than our disclosed sub-processors.

We may disclose information when required by law (court order, lawful subpoena, or other legal process). Where lawful, we will notify the affected clinic before complying.

5. How long we keep this information

Type of dataRetention
Call audioNot applicable. Calls are not recorded
Transcripts1 year
Appointment booking detailsUntil appointment date + 1 year
Audit log entries7 years (records of access, never PHI itself)

After the retention window, the data is permanently deleted. Our sub-processors retain data only as their data protection addenda permit; Anthropic, which generates Menchi’s replies, deletes inputs and outputs within 30 days and is contractually prohibited from training its models on our data.

6. Where this information lives

  • In transit during a call: US-based sub-processors (Twilio, with Deepgram and ElevenLabs inside Twilio’s voice session, and Anthropic) under contractual safeguards
  • While the call is happening: Canada. Once your speech is text, the conversation is handled by Menchi’s own software running in Toronto
  • At rest, after the call: Canada (Supabase ca-central-1, Montréal). Calls are not recorded, so there is no audio to store

This split is a deliberate architectural choice. We acknowledge the cross-border processing during the call, and we use contractual and technical controls to limit US-based data exposure to the request lifetime only.

7. How we protect this information

  • Encryption at rest: AES-256, with keys managed by AWS KMS in Canada
  • Encryption in transit: TLS 1.2+ on all connections
  • Tenant isolation: Postgres Row-Level Security ensures clinics cannot access each other’s data
  • Audit log immutability: the audit log is enforced as append-only at the database grant layer. No Menchi or Zalto staff member can edit or delete an audit log entry
  • Access controls: least-privilege access for Zalto staff, multi-factor authentication required, all access logged
  • Sub-processor controls: Data Processing Addenda with our sub-processors, with the current status of each published at trymenchi.com/sub-processors

8. Patient rights

Under PHIPA, patients have the right to:

  • Access their personal health information (s.52)
  • Correct inaccurate information (s.55)
  • Withdraw consent to specific uses or disclosures, where consent is the basis (s.18)
  • File a complaint with the Information and Privacy Commissioner of Ontario (s.56)

These rights are exercised through the clinic where the patient is a patient. The clinic instructs Menchi to provide, correct, or delete data as required.

We respond to clinic-initiated requests within 5 business days.

9. Privacy contact

Privacy officer (PHIPA s.15 designated contact):

  • Name: Alejandro Zuluaga, Founder, Zalto Inc.
  • Email: menchi@zalto.live
  • Mail: Zalto Inc., Mississauga, Ontario, Canada

For complaints to the regulator:

10. Changes to this Policy

We will update this Policy as Menchi evolves. Material changes (new sub-processors, changes in country of processing, new categories of data collected) will be communicated to clinic customers at least 30 days in advance.

The current version, effective date, and last review date are listed at the top of this document.

11. Disclosed limitations

We are honest about where we are. As of the effective date of this Policy, Menchi operates under the following limitations:

  • Single-founder operation. No 24/7 Security Operations Center. Best-effort response within 15 minutes during business hours; out-of-business-hours response is best-effort within 1 business day.
  • No SOC 2 Type II audit yet. Planned for Gate 2 (broader market readiness).
  • No HITRUST certification yet. Evaluated post-Gate 2 based on market demand.
  • No independent privacy audit yet. Planned alongside SOC 2.
  • No cyber insurance policy yet. Planned alongside SOC 2.

We will update this Policy as each limitation is resolved.

12. Questions

Email menchi@zalto.live for any privacy questions.