

ZENOTI
By Zenoti
The typical implementation process for Zenoti software involves several key steps, each designed to ensure a smooth transition from the customer's existing system to Zenoti. Here's a brief overview of the process:
Data Collection and Site Preparation: This initial phase involves gathering all necessary master data from the customer's existing system. Zenoti's team works closely with the customer to prepare the site for the new system.
Configuration and Data Migration: Zenoti configures the system according to the customer's specific needs. This includes setting up features such as the webstore and migrating data from the old system to Zenoti. This step is guided by a Statement of Work (SOW) agreed upon by both parties.
Training: Zenoti provides training through Zenoti University, offering self-paced online courses tailored to the roles of the customer’s team members. Successful completion of this training is crucial for optimizing the use of Zenoti's services.
Branding and Customization
ZENOTI allows businesses to customize the look and feel of their consumer mobile app (CMA) according to their branding requirements. This includes adding custom logos, icons, background images, color schemes, and text labels for various elements like the navigation bar, action buttons, and more.
Service and Package Configurations
Businesses can define their own service categories, service sequences (order in which services are performed) and create tailored packages by bundling complementary services or multiple instances of a service. ZENOTI provides flexible options for pricing, discounts, and promotions for packages.
Business Rules and Settings
ZENOTI offers a wide range of configuration settings that allow businesses to customize various aspects like online booking rules, employee schedules, inventory management, marketing campaigns, and more to align with their specific processes and requirements.
Custom Forms and Templates
Zenoti University: An online learning platform with courses, videos, and training modules tailored for different roles like front desk, managers, service providers, etc. This is included in the subscription at no extra cost.
Live Virtual Training: ZENOTI provides live instructor-led virtual training sessions for new and existing users to learn about new features, best practices, and get their questions answered.
On-site Training: Businesses can opt for on-site training sessions from ZENOTI's team, which may incur additional charges.
24/7 Support: ZENOTI offers round-the-clock technical support via phone, email, and chat to assist customers with any queries or issues they may face.
Zenoti has a well-established Information Security Program with defined security policies and procedures.
The leadership team actively participates in security governance, supported by a dedicated team of security and privacy professionals.
Regular security audits are conducted to ensure compliance with security requirements.
Zenoti's platform is hosted on Amazon Web Services (AWS) and designed as a multi-tenant architecture.
Data at rest and in transit is encrypted to protect against unauthorized access.
The platform includes DDoS protection, API throttling, and threat detection capabilities.
All systems in the cloud are protected by antivirus software, and instances run on AWS Virtual Private Cloud (VPC).
Single Sign-On (SSO) is implemented, and servers are hardened based on CIS benchmark standards.
Zenoti has a Vulnerability Management Program, conducting regular vulnerability assessments and penetration testing.
Static code testing and application security testing are performed, following guidelines like OWASP Top 10 and PCI DSS Penetration Testing Guidelines.
The Zenoti platform provides roles and permissions to control user access based on roles.
Extensive product logging is available to meet compliance requirements.
Developer code undergoes review before commitment, and all changes are thoroughly tested by the Quality Assurance team.
Physical access to Zenoti premises and server rooms is controlled by proximity-based access systems and monitored by CCTV cameras.
Preventive measures are in place to protect against environmental hazards such as fire and power outages.
Zenoti complies with GDPR, CCPA, HIPAA, PIPEDA, and PCI DSS, ensuring protection of personal data and privacy rights.
GDPR compliance includes allowing guests to opt-in to marketing communications and ensuring minors' privacy rights are protected.
Zenoti releases updates almost every month. These updates include new features, enhancements, and security patches. The release notes for these updates are published regularly, detailing the changes and improvements made. For example, updates were released on May 21, April 30, April 16, April 03, March 20, and March 07 in 2024.
Data Ownership:
Customers retain sole and exclusive ownership of all their data, including all intellectual property rights related to it.
Zenoti is not responsible for the accuracy, integrity, completeness, or quality of the customer data. Customers are responsible for providing all necessary data for Zenoti to deliver its services.
Data Portability:
Customers have the right to access and use their data as needed. Zenoti provides tools and support to facilitate data portability, ensuring that customers can export their data if they decide to switch to another service provider.
Data Processing and Use:
Zenoti is granted a license to process customer data as necessary to provide its services. This includes modifying and creating derivative works from the data to improve service delivery.
Price Scaling: This allows businesses to charge different rates for services based on the skill level of the service provider or the specific room where the service is performed. For example, senior employees or specific rooms can have higher service rates configured as either a percentage or an absolute amount.
Employee Service Pricing: Businesses can set dynamic prices for services depending on the service provider's skill level and experience. This is managed through the Employee service pricing configuration.
Commission Configurations: Zenoti allows for the configuration of commissions based on a flat amount or a percentage of the sale amount for series packages. This can be set at the item level, employee level, or job level, providing flexibility in how commissions are awarded.
Cross-Center Redemption: This feature allows guests to redeem memberships, packages, prepaid cards, and gift cards across different centers. This can be enabled or disabled based on the organization's needs, especially if taxation laws or tiered pricing structures make cross-center redemptions complex.
Transactional Notifications in Preferred Languages: Zenoti supports sending transactional notifications in multiple languages, which can be set at the user, center, or organization level. This ensures that communication is consistent and tailored to the preferences of the guests.
Custom Packages and Payment Modes: Zenoti allows businesses to create custom packages and accept custom payment modes, providing flexibility in how services are bundled and paid for. This can help in scaling operations by offering tailored solutions to different customer segments.
Zenoti Wallet: This payment service allows service providers and employees to receive their tips faster and manage their finances more efficiently. It supports faster layouts and financial management, which can be crucial for scaling operations.
Contract Renewal
Automatic Renewal: The term of the agreement commences on the effective date and continues for the initial term as specified in the order form. After the initial term, the agreement automatically renews for successive one-year terms unless either party provides written notice of non-renewal at least 90 days before the expiration of the current term.
Fee Adjustments: At the conclusion of the initial term or any renewal term, Zenoti may increase the fees associated with the subscription by no more than 20% of the then-current fees for the subsequent renewal term.
Payment of Fees: Zenoti will renew the terms and conditions after the expiration of the initial term or a renewal term only after receiving payment of the applicable fees for the renewed services from the customer.
Notification of Changes: Zenoti will provide the customer with written notice of any changes to the current terms and conditions in compliance with the agreement.
Contract Cancellation
Termination by Customer: The customer can terminate the agreement by providing written notice to Zenoti. The specific terms for termination, including any potential fees or penalties, depend on the details outlined in the customer's contract.
Termination by Zenoti: Zenoti may suspend or terminate services if:
The customer fails to comply with any term of the agreement.
The customer or any authorized user is involved in fraudulent, misleading, or unlawful activities.
Zenoti receives a judicial or governmental demand or order requiring such action.
Cancellation of Memberships: Zenoti allows for the setup of rules for canceling and terminating memberships. This can include automatic termination after a set number of days post-cancellation or manual waivers on cancellation fees for classes and workshops.
No-Show and Cancellation Fees: Zenoti provides options to configure commissions for no-show and canceled invoices. This can be set as a flat amount or a percentage of the cancellation/no-show fee collected.
Scheduled Downtime and Service Levels: Zenoti schedules downtime for routine maintenance and provides at least eight hours' prior notice of all scheduled outages. The services are guaranteed to be available 99.9% of the time, excluding exceptions such as force majeure events or customer-related issues.
General Data Protection Regulation (GDPR)
Zenoti complies with GDPR by providing various settings and options to protect the privacy rights of guests. This includes allowing guests to explicitly opt-in to marketing communications, ensuring that minors' privacy rights are protected, and enabling businesses to manage guest consent for marketing communications.
Health Insurance Portability and Accountability Act (HIPAA)
Zenoti is HIPAA-compliant, which is crucial for medical spas and other healthcare-related businesses. This compliance ensures that Zenoti meets the necessary standards for protecting sensitive patient health information.
California Consumer Privacy Act (CCPA)
Zenoti complies with CCPA, which provides California residents with specific rights regarding their personal information, including the right to know what personal data is being collected and the right to request deletion of their data.
Payment Card Industry Data Security Standard (PCI DSS)
Zenoti is PCI DSS Level 1 compliant, ensuring that it meets the highest standards for securing credit card transactions and protecting cardholder data.
Personal Information Protection and Electronic Documents Act (PIPEDA)
Zenoti complies with PIPEDA, which governs how private sector organizations collect, use, and disclose personal information in the course of commercial business in Canada.
System and Organization Controls (SOC) Reports
Zenoti has obtained SOC 1 Type 2 and SOC 2 Type 2 reports, which demonstrate that it has the necessary controls in place to protect customer data and ensure the integrity and confidentiality of its services.
Additional Security Measures
Zenoti also implements various security measures, including:
Audit Logging: Extensive product logging to meet compliance requirements.
Data Masking: Protecting sensitive data by masking it.
Encryption: Encrypting data at rest and in transit.
Access Control: Implementing strict access control measures to ensure only authorized personnel can access sensitive data.
Endpoint Security: Including disk encryption, endpoint detection and response, and mobile device management.