Data Processing Addendum
Last updated: August 3, 2026
This Addendum applies whenever we process personal data about your patients on your behalf. It forms part of our Terms of Service and takes precedence over them on data protection. It is written to be read, not to be survived; where a control is weaker than you would like, it says so plainly so you can decide with your eyes open.
1. Roles
For patient data, you are the Data Fiduciary and we are your Data Processor under the Digital Personal Data Protection Act 2023. You decide which patients are recorded, what is recorded, and why. We process only to provide the service.
For your own account — staff identities, billing, invoices and audit records — we act as Data Fiduciary and our Privacy Policy governs.
2. Scope of processing
Subject matter: providing an AI receptionist, appointment booking and a patient records portal. Duration: for as long as your subscription is active, plus the deletion period in section 8. Data subjects: your patients, their guardians and dependants, and people who call or message you. Categories: contact details, date of birth and sex, appointment history, call and message content including transcripts, and health data — diagnoses, prescriptions, allergies, clinical notes and uploaded documents.
3. Our obligations
We will: process patient data only to provide the service and on your documented instructions, including your configuration of it; not sell it, and not use it to train AI models; keep it confidential and limit access to personnel who need it; assist you with your patients’ requests as set out in section 6; notify you of a breach as set out in section 7; and delete or return data as set out in section 8.
If we believe an instruction from you breaches the law, we will tell you rather than quietly comply.
4. Your obligations
You will: hold a lawful basis for the data you put into the service and for our processing of it; give your patients the notice the law requires, including that an AI agent handles their calls and messages and that their data is processed by our providers, some outside India; obtain any consent required, including for a child; keep your own access controls sound, including who on your staff can see records; and answer your patients’ requests, with our help.
5. Security measures, as implemented
In place:encryption in transit; provider credentials and uploaded patient documents encrypted at rest with AES-256-GCM under a key held outside the database; per-organisation isolation; role-based access control on every route; an audit log of administrative and clinical write actions; patient portal access only after one-time-code verification of the patient’s mobile number, with rate limits and hashed codes; clinician-controlled release of a diagnosis, with private clinical notes never exposed on a patient-facing path; the ability to revoke a patient’s portal access immediately; encrypted nightly database backups; and monitored uptime alerting.
Limits you should know before signing:
Clinical free text — diagnoses, typed prescriptions, allergies, call transcripts and chat messages — is stored without a second, application-level layer of encryption. It is protected by access control, network isolation and encrypted backups.
Data is hosted in the United States, and our AI and most carrier providers are reached on global endpoints. We do not currently offer India-resident processing.
Reads of a patient record are not individually audited; write actions are. There is no customer-managed encryption key, no SSO/SAML, and no independent security certification such as ISO 27001 or SOC 2.
6. Assisting with data-principal requests
If a patient contacts us directly we will not act on their record ourselves — we will route the request to you, because you control it. On your written request we will help you locate, correct, export or delete a patient’s data.
Honestly stated: some of this is manual today. Deleting a single patient’s record and producing a complete export of everything held about one person are performed by our team rather than a button in the dashboard, within 30 days of your request. Plan your own response times accordingly.
7. Breach notification
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 72 hours, with what happened, the categories and approximate volume affected, the likely consequences, and what we are doing. We will report to the Data Protection Board of India as required of us. As Data Fiduciary, deciding whether and how to inform your patients is yours, and we will give you what you need.
8. Deletion and return
You can delete agents, knowledge documents, consultations and connections yourself at any time, and set a retention window after which call transcripts and analysis are purged automatically. That window is off unless you set it.
On termination, we will delete your organisation’s data within 30 days of your written request, except records we must keep by law, such as invoices, for the statutory period. Before you close the account, export what you need — reports and patient lists export as CSV, and clinical records are available through the API.
9. Sub-processors
You authorise the sub-processors listed on our sub-processor page, which names what each receives and where it processes. We remain responsible for their performance. We will update that page before a new sub-processor begins handling customer data and notify you of material additions; if you object, your remedy is to stop using the affected feature or to terminate.
10. Cross-border transfer
You acknowledge that providing the service involves processing patient data outside India, as described in section 5 and on the sub-processor page. You confirm you have the lawful basis for that transfer and have told your patients about it.
11. Audit
On reasonable written notice, no more than once a year, we will answer a security questionnaire and provide the documentation we hold. We do not currently hold a third-party audit report, and we will not claim otherwise. On-site audits are by agreement.
12. Signing this
This Addendum applies automatically to every customer processing patient data — you do not need to sign it for it to bind us. If your procurement process needs a countersigned copy, or terms specific to your institution, write to info@vaaniyantra.com and we will work through it.
Questions about how we handle data, or a complaint, go to the Grievance Officer named in our Privacy Policy.