Data Processing Agreement
Version 2026-09-25 · Effective 25 September 2026
1. Parties and scope
This DPA is between the clinic that accepted it at sign-up (the “Clinic”, as Data Fiduciary) and [Kliniq Technologies Private Limited] (“Kliniq”, as Data Processor). It applies to all personal data Kliniq processes on the Clinic's behalf through the Service (“Clinic Personal Data”).
Terms such as “personal data”, “data principal”, “data fiduciary”, “data processor”, “processing” and “personal data breach” have the meanings given in the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the DPDP Rules, 2025 (“Rules”). This DPA also meets section 8 of the DPDP Act, which requires a valid contract for engaging a data processor.
2. Details of the processing
| Item | Description |
|---|---|
| Subject matter | Providing Kliniq: booking, queue, reminders, billing, records, reports and data-protection tools |
| Duration | For the term of the Clinic's subscription, plus the return and deletion period in section 11 |
| Nature | Collecting, recording, storing, organising, retrieving, using, transmitting (messages) and erasing |
| Data principals | Patients, their family members and guardians, and the Clinic's staff and doctors |
| Categories of data | Identity and contact details, age and sex, family links, appointments and visits, queue tokens, clinical notes and follow-ups the Clinic enters, invoices and payment references, consent records, messages sent, privacy requests |
| Excluded | Card numbers, UPI PINs and bank credentials are never processed by Kliniq |
3. Processing only on the Clinic's instructions
- Kliniq processes Clinic Personal Data only to provide the Service, following the Clinic's documented instructions. Those instructions are the Terms, this DPA, and the Clinic's settings and actions in the Service.
- Kliniq will not use Clinic Personal Data for its own purposes, sell it, use it for advertising, or use it to train AI models.
- If Kliniq believes an instruction breaks the law, it will tell the Clinic and may decline to follow it.
- Kliniq may process data where Indian law requires it. Unless the law forbids, Kliniq tells the Clinic first.
4. The Clinic's responsibilities
- Give data principals a notice and get consent (or rely on another lawful ground) as the DPDP Act requires. Kliniq's booking page shows a notice in English and Hindi, records separate consents, and keeps a consent ledger the Clinic can export.
- Publish a contact for questions and complaints. Kliniq shows it on the booking page once the Clinic enters it in Settings → Data and privacy.
- Answer requests to access, correct or erase data, and grievances, within the time allowed. Kliniq's rights inbox tracks each request and its due date.
- Set retention periods that meet the Clinic's legal obligations, including those for medical records.
- Keep the data it enters accurate, and control who on its staff has access.
5. Security safeguards
Kliniq maintains reasonable security safeguards to prevent personal data breaches, as section 8(5) of the DPDP Act and the Rules require. These include:
- encryption at rest (AES-256, keys managed in a key management service) and in transit (TLS 1.2 or later);
- logical separation of every clinic's data, enforced in code and verified by automated cross-clinic tests before each release;
- role-based access for Clinic staff, with one-time-code sign-in and a second factor for owners and doctors;
- a tamper-evident log of access and changes, kept for at least one year;
- continuous backups with point-in-time restore, stored in India;
- least-privilege access for Kliniq personnel, confidentiality obligations in their contracts, and security training;
- WhatsApp and SMS templates that never contain diagnoses or test results, only a secure link;
- a yearly external penetration test.
6. Where data is kept
Clinic Personal Data and its backups are stored in India (AWS ap-south-1 Mumbai, with backup copies in ap-south-2 Hyderabad). Only the limited data needed to deliver a message or payment passes to the providers listed on the service providers page, and never to a country restricted by the Government of India.
7. Sub-processors
- The Clinic authorises Kliniq to use the sub-processors listed on our service providers page.
- Kliniq binds each sub-processor to data-protection terms at least as protective as this DPA, and remains responsible for their work.
- Kliniq gives at least 30 days' notice by email before adding or replacing a sub-processor. If the Clinic objects on reasonable data-protection grounds and we cannot resolve it, the Clinic may cancel and receive a pro-rata refund of prepaid fees for the unused period.
8. Helping with data principals' rights
Kliniq provides tools to find, export, correct and lawfully erase a patient's data, and to log and answer requests. If a data principal contacts Kliniq directly about Clinic Personal Data, Kliniq passes the request to the Clinic without undue delay and does not answer it on the Clinic's behalf unless instructed.
9. Personal data breaches
- Kliniq notifies the Clinic without undue delay, and in any case within 24 hours of becoming aware of a breach affecting Clinic Personal Data. The notice covers what happened, when, the data and patients affected, likely consequences and the steps taken.
- Kliniq reports cyber-security incidents to CERT-In within 6 hours, as the CERT-In Directions of April 2022 require.
- Kliniq helps the Clinic inform the Data Protection Board of India and affected data principals as the Rules require, including the detailed report due within 72 hours. It provides notice templates and lists of affected patients.
- Kliniq takes immediate steps to contain the breach and prevent it recurring.
10. Kliniq staff access to Clinic data
Kliniq support staff can view Clinic Personal Data only when the Clinic's owner approves a time-limited access request, for example to investigate a problem the Clinic reported. Each access is recorded in the Clinic's own audit log. Automated systems process data only to run the Service.
11. Return and deletion
- The Clinic can export all Clinic Personal Data at any time, including while the account is read-only or paused.
- When the subscription ends, the Clinic has 30 days of read-only access to export. Kliniq then deletes Clinic Personal Data from live systems. Backups expire within 35 days, and Kliniq confirms deletion in writing on request.
- Kliniq keeps data longer only where Indian law requires it, and then only for that purpose.
- The Clinic is responsible for keeping any medical records it must retain by law. Kliniq does not keep them for the Clinic after deletion.
12. Information and audits
On request, Kliniq provides the information reasonably needed to show that it complies with this DPA, including a summary of its latest penetration test and security policies. Clinics on Private hosting, or where a regulator requires it, may audit Kliniq once a year with 30 days' notice, during business hours, under confidentiality, and at the Clinic's cost.
13. Liability, term and contact
The limits of liability in the Terms apply to this DPA. This DPA lasts as long as Kliniq processes Clinic Personal Data. If it conflicts with the Terms on personal data, this DPA wins. It is governed by Indian law, and disputes are resolved as the Terms describe.
Contact about this DPA: privacy@kliniq.in, [Data Protection Officer name], Data Protection Officer.
Questions about this document? Write to hello@kliniq.in or use our contact form.