Data Processing Agreement
This Data Processing Agreement (DPA) forms part of the Aethis Terms of Service and governs the processing of Personal Data by Aethis on behalf of the Controller.
Last updated: July 2026
Parties & Effective Date
Data Controller: The Clinic (you) — the legal entity that determines the purposes and means of processing Personal Data.
Data Processor: Aethis — the provider of the Aethis clinic management SaaS platform, which processes Personal Data on behalf of the Controller.
Effective Date: The date on which the Controller accepts the Aethis Terms of Service.
1. Subject Matter & Duration
This DPA governs the processing of Personal Data in connection with the Controller's use of the Aethis SaaS platform (the "Services"). The duration of this DPA shall be for the term of the Controller's subscription agreement with Aethis, including any period of data retention required by law.
2. Nature & Purpose of Processing
The processing activities performed by the Processor on behalf of the Controller include:
All processing is carried out to provide the Services as described in the Aethis Terms of Service.
3. Categories of Data Subjects
The Personal Data processed under this DPA relates to the following categories of data subjects:
4. Categories of Personal Data
The Processor may process the following categories of Personal Data on behalf of the Controller:
5. Special Category Data (UK GDPR Art 9 / DPDP Act 2023)
The Processor processes Special Category Personal Data, specifically data concerning health (medical records, clinical notes, treatment histories, photographs used for clinical purposes).
The Controller warrants and represents that it has obtained valid, explicit consent from each Data Subject for the processing of their Special Category Personal Data, or that another lawful basis under applicable data protection law applies. The Controller shall maintain records of such consents and provide evidence to the Processor upon reasonable request.
6. Processing Instructions
The Processor shall process Personal Data only in accordance with the Controller's documented instructions, including:
The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction infringes applicable data protection law. The Processor shall not process Personal Data for any purpose other than as instructed by the Controller, unless required to do so by applicable law (in which case the Processor shall notify the Controller before processing, unless prohibited by law).
7. Technical & Organisational Measures (TOMs)
The Processor implements and maintains the following technical and organisational measures to protect Personal Data:
Encryption:
Access Control:
Audit & Monitoring:
Data Lifecycle:
Organisational:
8. Sub-processors
The Controller authorises the Processor to engage the following sub-processors for the purposes described below:
Cloud Infrastructure:
Communications:
Payments:
Analytics:
The Processor shall:
9. Data Subject Rights Assistance
The Processor shall assist the Controller in fulfilling its obligations to respond to requests by Data Subjects exercising their rights under applicable data protection law, including:
The Aethis platform provides self-service capabilities for the Controller to:
The Processor shall notify the Controller within 5 business days of receiving a Data Subject request directly and shall not respond to such request unless authorised by the Controller.
10. Data Breach Notification
The Processor shall notify the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach affecting the Controller's data.
The notification shall include:
The Processor shall cooperate with and assist the Controller in complying with the Controller's notification obligations to supervisory authorities and Data Subjects under applicable data protection law.
Under the Digital Personal Data Protection Act, 2023 (DPDP Act) §8(6), the Processor is obligated to notify the Data Protection Board of India (DPBI) and each affected Data Principal of a Personal Data breach. The Processor maintains an India-specific breach notification runbook (docs/compliance/india-breach-runbook.md) detailing the DPBI notification procedure, timelines, and escalation contacts.
11. Deletion & Return of Data
Upon termination of the Controller's subscription, the following shall apply:
Notwithstanding the foregoing, the Processor may retain Personal Data to the extent required by applicable law (including, for India clinics, the DPDP Act §8(7) which permits retention where required by law, and applicable Clinical Establishments Act / NMC record-keeping requirements), provided that such retention is limited to the minimum necessary and subject to continued confidentiality and security obligations.
Under DPDP Act §12(3) and §6(5), the Processor shall erase Personal Data upon withdrawal of consent by the Data Principal, unless retention is required by law. The Processor's erasure pipeline (integrated with the consent withdrawal mechanism) flags and evaluates patient records for erasure upon consent withdrawal, anonymising or securely deleting data in accordance with the Controller's instructions.
12. Audit Rights
The Controller may, no more than once per calendar year and upon 30 days' written notice, request information to verify the Processor's compliance with this DPA. The Processor shall respond to such requests within 30 days by providing:
Any on-site audit shall be subject to mutual agreement on scope, timing, and duration, and shall be at the Controller's expense. The Processor may satisfy audit requests by providing an independent third-party audit report where available.
13. International Data Transfers
Primary Hosting: All Personal Data under this DPA — including patient records, clinical notes, treatment plans, photographs, billing data, and consent records — is stored and processed at rest within India (AWS Mumbai region, ap-south-1).
Notification Delivery: The following sub-processor activities involve the transmission of limited Personal Data outside India for the purpose of delivering notifications to patients:
No other Personal Data categories are transferred outside India.
Transfer Basis: As of the effective date, the Central Government has not yet notified any countries or territories to which data transfers are restricted under §16(1) of the DPDP Act, 2023. Until such notification is published, cross-border data transfers are not restricted by the DPDP Act. The Processor monitors the DPDP Rules rulemaking process and will promptly notify the Controller of any restricted-territory notification that impacts these data flows.
Safeguards: All sub-processors engaged in cross-border data transmission are bound by contractual obligations that are no less protective than this DPA. Where applicable, the Processor shall implement Standard Contractual Clauses or equivalent transfer mechanisms once the DPDP cross-border transfer framework is finalised.
A detailed cross-border transfer map is maintained at docs/compliance/india-transfer-map.md.
14. Liability
The Processor's liability under this DPA shall be subject to the limitations of liability set out in the Aethis Terms of Service. Nothing in this DPA shall exclude or limit either party's liability for matters that cannot be excluded or limited under applicable law.
Each party's liability for data protection breaches shall be assessed taking into account the party's respective responsibilities and obligations under applicable data protection law.
15. Data Principal Rights & Grievance Redressal (DPDP Act 2023)
In compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Processor supports the Controller in fulfilling the following obligations towards Data Principals:
Data Principal Rights:
The Aethis platform provides the Controller with self-service capabilities to:
Grievance Officer:
The Processor has appointed a Grievance Officer as required under DPDP Act §8(9) and §8(10):
<b>Grievance Officer, Aethis Health Pvt Ltd</b>
Email: grievance@aethis.in
Postal Address: Aethis Health Pvt Ltd, Haridwar, Uttarakhand — 249401, India
Grievance Handling SLA (per Draft DPDP Rules 2025 Rule 9):
If a Data Principal is not satisfied with the resolution, they have the right to file a complaint with the Data Protection Board of India under §5(2)(c) of the DPDP Act, 2023. The Processor shall cooperate with the Controller in responding to any such complaints.
16. Governing Law
This DPA is governed by the laws of India. Any disputes arising out of or relating to this DPA shall be resolved in accordance with the dispute resolution provisions of the Aethis Terms of Service.