Data processing agreement (template)
DRAFT — requires legal review
This document is a working draft prepared by the engineering team to describe how the platform is designed to support compliance. It is not legal advice and has not yet been reviewed by counsel. Do not rely on it as a final policy until this banner is removed.
This template sets out the key terms. Placeholders are in square brackets.
Parties: [Healthcare provider legal name, GSTIN, address] (“Data Fiduciary”) and Achal Technology [legal entity, address] (“Data Processor”).
- Subject matter and duration — processing of personal data to provide Achal Technology Healthcare Management Software for the term of the subscription and the post-termination period in clause 10.
- Nature and purpose — hosting, storage, retrieval, display, transmission (WhatsApp/email/SMS), rendering of documents, backups and support, solely to provide the service.
- Categories of data principals — patients (including children and their guardians), provider staff, referring practitioners.
- Categories of data — identity and contact data; health data; financial data; technical and log data.
- Instructions — the Processor processes only on documented instructions of the Fiduciary (the service configuration and this DPA), unless required by law, in which case it informs the Fiduciary unless prohibited.
- Confidentiality — personnel with access are bound by confidentiality and trained.
- Security — technical and organisational measures described in the security overview, including tenant isolation, encryption in transit and at rest, access control, logging, backups and incident response.
- Subprocessors — general authorisation for the subprocessors listed; [30] days' prior notice of changes with a right to object.
- Assistance — with data-principal requests, breach notification (notice to the Fiduciary within [24] hours of becoming aware), and records of processing.
- Return and deletion — on termination, the Processor makes a full export available for [90] days, then deletes or anonymises the data (backups expire within [8 weeks]), and certifies deletion on request.
- Data location — India (asia-south1 / asia-south2); any transfer outside India only as listed for specific subprocessors and permitted by law.
- Audit — the Processor provides information necessary to demonstrate compliance, including third-party audit or VAPT summaries, [annually].
- Liability and governing law — [as per the master subscription agreement]; courts at [city], India.