Back to Home

Data Processing Agreement

This Data Processing Agreement (DPA) forms part of the Aethis Terms of Service and governs the processing of Personal Data by Aethis on behalf of the Controller.

Last updated: July 2026

Parties & Effective Date

Data Controller: The Clinic (you) — the legal entity that determines the purposes and means of processing Personal Data.

Data Processor: Aethis — the provider of the Aethis clinic management SaaS platform, which processes Personal Data on behalf of the Controller.

Effective Date: The date on which the Controller accepts the Aethis Terms of Service.

1. Subject Matter & Duration

This DPA governs the processing of Personal Data in connection with the Controller's use of the Aethis SaaS platform (the "Services"). The duration of this DPA shall be for the term of the Controller's subscription agreement with Aethis, including any period of data retention required by law.

2. Nature & Purpose of Processing

The processing activities performed by the Processor on behalf of the Controller include:

  • Clinic management and administration
  • Patient records management (creation, storage, retrieval)
  • Appointment scheduling and management
  • Treatment plan tracking
  • Billing and invoicing
  • Consent form management and storage
  • Clinical photography storage and management
  • Appointment reminder notifications (WhatsApp, SMS, email)
  • Analytics and reporting for clinic operations
  • Data export and erasure as instructed by the Controller
  • All processing is carried out to provide the Services as described in the Aethis Terms of Service.

    3. Categories of Data Subjects

    The Personal Data processed under this DPA relates to the following categories of data subjects:

  • Patients of the Controller (the clinic's patients)
  • Staff members of the Controller (clinic practitioners, administrators)
  • Users authorised by the Controller to access the Services
  • 4. Categories of Personal Data

    The Processor may process the following categories of Personal Data on behalf of the Controller:

  • Identity data: name, date of birth, gender
  • Contact data: phone number, email address, postal address
  • Health data: medical history, clinical notes, treatment records, diagnoses, prescriptions, allergies
  • Photographic data: clinical before/after photographs, patient profile photos
  • Financial data: billing information, payment records (processed via third-party payment processors)
  • Consent data: consent form records, consent status, withdrawal history
  • Usage data: appointment history, visit records, notification logs
  • Communication data: SMS, WhatsApp, and email notification content and delivery status
  • 5. Special Category Data (UK GDPR Art 9 / DPDP Act 2023)

    The Processor processes Special Category Personal Data, specifically data concerning health (medical records, clinical notes, treatment histories, photographs used for clinical purposes).

    The Controller warrants and represents that it has obtained valid, explicit consent from each Data Subject for the processing of their Special Category Personal Data, or that another lawful basis under applicable data protection law applies. The Controller shall maintain records of such consents and provide evidence to the Processor upon reasonable request.

    6. Processing Instructions

    The Processor shall process Personal Data only in accordance with the Controller's documented instructions, including:

  • These terms set out in this DPA
  • Any configuration settings selected by the Controller within the Aethis platform
  • Any specific written instructions issued by the Controller from time to time
  • The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction infringes applicable data protection law. The Processor shall not process Personal Data for any purpose other than as instructed by the Controller, unless required to do so by applicable law (in which case the Processor shall notify the Controller before processing, unless prohibited by law).

    7. Technical & Organisational Measures (TOMs)

    The Processor implements and maintains the following technical and organisational measures to protect Personal Data:

    Encryption:

  • AES-256 encryption at rest for all stored data (databases, file storage, backups)
  • TLS 1.3 encryption in transit for all network communications
  • Encrypted backup storage with access controls
  • Access Control:

  • Role-based access control (RBAC) with granular permission levels
  • Multi-tenancy isolation — each clinic's data is logically separated
  • Unique user accounts with strong password requirements
  • Session timeouts and automatic logout
  • Two-factor authentication (2FA) support
  • Audit & Monitoring:

  • Comprehensive audit logging of all data access and modifications
  • PII redaction in logs — personal identifiers are masked in application logs
  • Real-time monitoring and alerting for suspicious activity
  • Regular security vulnerability scanning
  • Data Lifecycle:

  • 30-day retention enforcement — data is permanently deleted 30 days after account cancellation
  • Secure deletion procedures using cryptographic erasure
  • Automated backup rotation and secure disposal of expired backups
  • Organisational:

  • ISO-aligned information security management processes
  • Regular security awareness training for all personnel
  • Incident response plan with defined roles and escalation procedures
  • Vendor security assessment programme for all sub-processors
  • 8. Sub-processors

    The Controller authorises the Processor to engage the following sub-processors for the purposes described below:

    Cloud Infrastructure:

  • Amazon Web Services (AWS) — Cloud hosting and data storage; Data hosted in Mumbai (ap-south-1) region
  • Communications:

  • Twilio — WhatsApp and SMS notification delivery
  • SMTP providers (e.g., SendGrid) — Email notification delivery
  • Payments:

  • Razorpay — Subscription payment processing
  • Analytics:

  • Plausible Analytics — Privacy-focused, self-hosted analytics (no personal data shared)
  • The Processor shall:

  • Notify the Controller of any intended changes concerning the addition or replacement of sub-processors at least 14 days in advance
  • Ensure all sub-processors are bound by data protection obligations no less protective than those in this DPA
  • Remain fully liable to the Controller for the performance of each sub-processor's obligations
  • 9. Data Subject Rights Assistance

    The Processor shall assist the Controller in fulfilling its obligations to respond to requests by Data Subjects exercising their rights under applicable data protection law, including:

  • Right of access (Subject Access Requests)
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • The Aethis platform provides self-service capabilities for the Controller to:

  • Export patient data in machine-readable format (data portability)
  • Initiate patient data erasure requests (right to erasure)
  • Update and correct patient records (right to rectification)
  • The Processor shall notify the Controller within 5 business days of receiving a Data Subject request directly and shall not respond to such request unless authorised by the Controller.

    10. Data Breach Notification

    The Processor shall notify the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach affecting the Controller's data.

    The notification shall include:

  • A description of the nature of the breach
  • The categories and approximate number of Data Subjects and Personal Data records affected
  • The likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate its effects
  • The name and contact details of the Processor's data protection contact
  • The Processor shall cooperate with and assist the Controller in complying with the Controller's notification obligations to supervisory authorities and Data Subjects under applicable data protection law.

    Under the Digital Personal Data Protection Act, 2023 (DPDP Act) §8(6), the Processor is obligated to notify the Data Protection Board of India (DPBI) and each affected Data Principal of a Personal Data breach. The Processor maintains an India-specific breach notification runbook (docs/compliance/india-breach-runbook.md) detailing the DPBI notification procedure, timelines, and escalation contacts.

    11. Deletion & Return of Data

    Upon termination of the Controller's subscription, the following shall apply:

  • The Controller may export all Personal Data from the Aethis platform within 30 days of termination
  • After 30 days, the Processor shall securely delete all Personal Data processed on behalf of the Controller from its systems, including backups
  • Deletion shall be performed using industry-standard secure deletion methods
  • At the Controller's written request, the Processor shall provide written confirmation of deletion
  • Notwithstanding the foregoing, the Processor may retain Personal Data to the extent required by applicable law (including, for India clinics, the DPDP Act §8(7) which permits retention where required by law, and applicable Clinical Establishments Act / NMC record-keeping requirements), provided that such retention is limited to the minimum necessary and subject to continued confidentiality and security obligations.

    Under DPDP Act §12(3) and §6(5), the Processor shall erase Personal Data upon withdrawal of consent by the Data Principal, unless retention is required by law. The Processor's erasure pipeline (integrated with the consent withdrawal mechanism) flags and evaluates patient records for erasure upon consent withdrawal, anonymising or securely deleting data in accordance with the Controller's instructions.

    12. Audit Rights

    The Controller may, no more than once per calendar year and upon 30 days' written notice, request information to verify the Processor's compliance with this DPA. The Processor shall respond to such requests within 30 days by providing:

  • Responses to a written security questionnaire or assessment
  • Copies of relevant certifications, audit reports, or attestations (e.g., SOC 2, ISO 27001)
  • A summary of the technical and organisational measures in place
  • Any on-site audit shall be subject to mutual agreement on scope, timing, and duration, and shall be at the Controller's expense. The Processor may satisfy audit requests by providing an independent third-party audit report where available.

    13. International Data Transfers

    Primary Hosting: All Personal Data under this DPA — including patient records, clinical notes, treatment plans, photographs, billing data, and consent records — is stored and processed at rest within India (AWS Mumbai region, ap-south-1).

    Notification Delivery: The following sub-processor activities involve the transmission of limited Personal Data outside India for the purpose of delivering notifications to patients:

  • Twilio (WhatsApp & SMS): Patient phone numbers and notification content may transit through or be processed in Twilio's infrastructure located in the United States. Twilio is contractually bound by DPDP-compliant data processing terms.
  • SMTP Providers (e.g., SendGrid): Patient email addresses and notification content may transit through or be processed in infrastructure located outside India, including the United States.
  • No other Personal Data categories are transferred outside India.

    Transfer Basis: As of the effective date, the Central Government has not yet notified any countries or territories to which data transfers are restricted under §16(1) of the DPDP Act, 2023. Until such notification is published, cross-border data transfers are not restricted by the DPDP Act. The Processor monitors the DPDP Rules rulemaking process and will promptly notify the Controller of any restricted-territory notification that impacts these data flows.

    Safeguards: All sub-processors engaged in cross-border data transmission are bound by contractual obligations that are no less protective than this DPA. Where applicable, the Processor shall implement Standard Contractual Clauses or equivalent transfer mechanisms once the DPDP cross-border transfer framework is finalised.

    A detailed cross-border transfer map is maintained at docs/compliance/india-transfer-map.md.

    14. Liability

    The Processor's liability under this DPA shall be subject to the limitations of liability set out in the Aethis Terms of Service. Nothing in this DPA shall exclude or limit either party's liability for matters that cannot be excluded or limited under applicable law.

    Each party's liability for data protection breaches shall be assessed taking into account the party's respective responsibilities and obligations under applicable data protection law.

    15. Data Principal Rights & Grievance Redressal (DPDP Act 2023)

    In compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Processor supports the Controller in fulfilling the following obligations towards Data Principals:

    Data Principal Rights:

  • Right to access — Data Principals may request a summary of their personal data being processed (DPDP Act §11)
  • Right to correction, completion, updating, and erasure — Data Principals may request correction of inaccurate data or erasure of their personal data (DPDP Act §12)
  • Right to grievance redressal — Data Principals may file a complaint with the Grievance Officer (DPDP Act §13)
  • Right to nominate — Data Principals may nominate another individual to exercise their rights in the event of death or incapacity (DPDP Act §14)
  • Right to withdraw consent — Data Principals may withdraw previously given consent at any time (DPDP Act §6(4)), following which the Processor shall cease processing for that purpose (§6(5)) and trigger the erasure/anonymization pipeline (§12(3)/§6(5))
  • Right to complain to the Data Protection Board of India — Data Principals may file a complaint with the DPBI if they believe their rights have been infringed (DPDP Act §5(2)(c))
  • The Aethis platform provides the Controller with self-service capabilities to:

  • Export patient data in machine-readable format (supporting access and portability rights)
  • Initiate patient data erasure (supporting the right to erasure)
  • Record and process consent withdrawals
  • Update and correct patient records
  • Grievance Officer:

    The Processor has appointed a Grievance Officer as required under DPDP Act §8(9) and §8(10):

    <b>Grievance Officer, Aethis Health Pvt Ltd</b>

    Email: grievance@aethis.in

    Postal Address: Aethis Health Pvt Ltd, Haridwar, Uttarakhand — 249401, India

    Grievance Handling SLA (per Draft DPDP Rules 2025 Rule 9):

  • Acknowledgement: within 24 hours of receipt
  • Resolution: within 7 calendar days of receipt
  • If a Data Principal is not satisfied with the resolution, they have the right to file a complaint with the Data Protection Board of India under §5(2)(c) of the DPDP Act, 2023. The Processor shall cooperate with the Controller in responding to any such complaints.

    16. Governing Law

    This DPA is governed by the laws of India. Any disputes arising out of or relating to this DPA shall be resolved in accordance with the dispute resolution provisions of the Aethis Terms of Service.