Skip to content
Data Processing Addendum

How RAKT processes personal data on your behalf.

The processor contract required by Section 8(2) of the Digital Personal Data Protection Act, 2023. It applies automatically to every RAKT HMS subscription and needs no separate signature.

Version 1.0 · Effective 6 September 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between RAKT INNOVATIONS (OPC) PVT. LTD., CIN U72900DL2020OPC360414, registered office AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India (“RAKT”, “Processor”) and the customer organisation subscribing to the Service (“Customer”, “Data Fiduciary”).

It applies automatically and requires no separate signature. It is the contract required by Section 8(2) of the Digital Personal Data Protection Act, 2023, under which a Data Fiduciary may engage a Data Processor only under a valid contract. A counterpart for signature, and a version on Customer letterhead for tender or accreditation purposes, is available on request to support@rakt.in.

1. Roles and scope

1.1 In respect of Customer Data processed through the Service, Customer is the Data Fiduciary and determines the purposes and means of processing. RAKT is the Data Processor and processes that data only on Customer’s behalf.
1.2 Customer is responsible for establishing a lawful basis for the processing, for giving notice to data principals, for obtaining and maintaining records of any consent required, and for the accuracy and lawfulness of the data it enters into the Service.
1.3 This DPA does not apply to data for which RAKT is itself the Data Fiduciary, such as Customer’s billing and administrative contact details. That processing is governed by the Privacy Policy.
1.4 Capitalised terms not defined here have the meaning given in the Terms of Service. “Personal Data” includes sensitive personal data or information under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

2. RAKT’s obligations

RAKT shall:
2.1 process Personal Data only on Customer’s documented instructions, which comprise this DPA, the Terms of Service, the configuration Customer applies in the Service, and any further written instruction the parties agree;
2.2 not process Personal Data for its own purposes, and not sell, rent or disclose it for consideration;
2.3 not use Personal Data to train or improve any artificial-intelligence or machine-learning model, and require the same of its sub-processors;
2.4 inform Customer if, in RAKT’s opinion, an instruction would cause a breach of applicable law, and may suspend that instruction until resolved;
2.5 limit access to Personal Data to personnel who need it to deliver or support the Service, ensure those personnel are bound by written confidentiality obligations that survive the end of their engagement, and maintain access records;
2.6 implement and maintain the technical and organisational measures set out in Annex 2, and not materially reduce them during the term;
2.7 assist Customer, at Customer’s reasonable request, with data protection impact assessments, audits, and enquiries or investigations by a regulator or the Data Protection Board of India, so far as they relate to RAKT’s processing.

3. Confidentiality

Personal Data is Confidential Information of Customer for the purposes of the Terms of Service. RAKT shall not disclose it to any third party except as permitted by this DPA, on Customer’s instruction, or where required by law. Where a disclosure is compelled by law, RAKT shall, unless legally prohibited, notify Customer before disclosing, and shall disclose only the minimum required.

4. Security

4.1 RAKT shall maintain reasonable security safeguards appropriate to the nature of the data, as required by Section 8(5) of the Digital Personal Data Protection Act, 2023 and Rule 8 of the SPDI Rules. Annex 2 describes the measures in force.
4.2 RAKT does not hold an ISO/IEC 27001 or SOC 2 attestation and does not represent that it does. Annex 2 states what is actually operated.
4.3 Customer is responsible for the security measures within its own control, including the management of Authorised Users, roles and Department permissions, the security of its endpoints and networks, the safekeeping of API keys, and not sharing credentials.

5. Sub-processors

5.1 Customer authorises RAKT to engage the sub-processors listed in Annex 3 for the purposes stated there.
5.2 RAKT shall impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains responsible to Customer for a sub-processor’s performance.
5.3 RAKT shall update Annex 3 and notify Customer by email or through the Service before a new sub-processor begins processing Personal Data. Customer may object on reasonable data protection grounds within fourteen days of the notice, and the parties shall work in good faith towards an alternative. If none is available, Customer may terminate the affected part of the Subscription without penalty and receive a pro-rata refund of any unused prepaid fees for that part.
5.4 The optional artificial-intelligence assistant identified in Annex 3 involves a sub-processor outside India. It is not enabled by operation of this DPA alone: it is switched on only at Customer’s request, and Customer may ask RAKT to disable it at any time.
5.5 Where Customer connects its own systems or AI clients to the Service through the API or the MCP server using Customer’s keys, those clients are engaged by Customer, act on Customer’s instructions and are not sub-processors of RAKT.

6. Assisting data principals

6.1 The Service provides Customer with the functionality to access, correct, update, export and delete the records it holds, including a patient erasure workflow with a cooling-off window Customer sets, so that Customer can respond to a data principal’s request directly.
6.2 Where a data principal contacts RAKT directly about data RAKT processes for Customer, RAKT shall not respond substantively but shall refer the person to Customer and inform Customer without undue delay.
6.3 Where Customer cannot fulfil a request using the Service, RAKT shall provide reasonable assistance at no charge for a proportionate volume of requests.

7. Personal data breaches

7.1 RAKT shall notify Customer of a Personal Data breach affecting Customer Data without undue delay after becoming aware of it, and in any event within twenty-four hours of confirming it.
7.2 RAKT shall send an initial alert as soon as practicable, ahead of any complete assessment, so that Customer can meet its own six-hour reporting obligation to CERT-In under the directions dated 28 April 2022.
7.3 The notification shall include, to the extent known and updated as the investigation proceeds: the nature and extent of the breach, the categories and approximate volume of data and data principals affected, the likely consequences, the measures taken or proposed to mitigate it, and a contact point at RAKT.
7.4 RAKT shall provide the information reasonably required for Customer to notify the Data Protection Board of India, without delay and with detailed particulars within seventy-two hours, and to notify affected data principals.
7.5 RAKT shall take reasonable steps to contain and remediate the breach, and shall preserve relevant logs and evidence.
7.6 Notification is not an admission of fault or liability by RAKT.

8. Audit and information rights

8.1 On reasonable written request, and no more than once in any twelve-month period unless a breach or a regulator requires otherwise, RAKT shall provide the information reasonably necessary to demonstrate compliance with this DPA, including a description of its security measures, its sub-processor list, and responses to a reasonable security questionnaire.
8.2 Where that is insufficient for Customer to meet a documented statutory or accreditation obligation, including a NABH or equivalent assessment, the parties shall agree an audit of scope, timing and duration that does not compromise the security or confidentiality of other customers’ data. Customer bears its own costs, and RAKT’s reasonable costs where an audit exceeds one working day.
8.3 RAKT may satisfy an audit request by providing the report of an independent assessment covering the relevant controls.

9. Location of processing

9.1 Customer Data is stored and backed up on infrastructure located in India.
9.2 Certain sub-processors process limited Personal Data outside India, as identified with their locations in Annex 3.
9.3 RAKT shall not transfer Personal Data to a country in respect of which such transfer is restricted by the Central Government under Section 16 of the Digital Personal Data Protection Act, 2023.
9.4 If Customer requires processing to be confined to India, it must tell RAKT in writing. RAKT will identify which features can be provided on that basis and which must be disabled.

10. Return and deletion

10.1 On request made within thirty days after termination of the Subscription, RAKT shall make available an export of Customer Data in a standard machine-readable format at no additional charge.
10.2 After that window, RAKT shall delete Customer Data from its live systems.
10.3 Encrypted backups are retained on a defined lifecycle for up to twelve months and then expire and are destroyed. RAKT shall not restore expired Customer Data from backup except in the course of recovering the Service as a whole.
10.4 RAKT may retain Personal Data where a law requires it, for so long as that requirement lasts, and shall continue to protect it in accordance with this DPA.
10.5 RAKT shall confirm deletion in writing on request.

11. Customer’s obligations as Data Fiduciary

Customer shall:
11.1 give data principals the notice required by Section 5 of the Digital Personal Data Protection Act, 2023, and obtain and record any consent required, including for treatment records, test results, and any patient notifications Customer configures;
11.2 where it enables the optional AI assistant, ensure its notice and consent documentation covers the processing described in Annex 3;
11.3 not enter into the Service any category of data prohibited under Section 6.4 of the Terms of Service;
11.4 maintain its own statutory records and determine its own retention periods, including for medical records, dispensing registers and financial records;
11.5 administer Authorised Users, roles, Department permissions, API keys and offboarding promptly and accurately.

12. Liability

Each party’s liability under this DPA is subject to the exclusions and the aggregate cap in Section 15 of the Terms of Service, save that nothing in this DPA or those Terms limits any liability that cannot lawfully be limited, including a monetary penalty imposed on a party by the Data Protection Board of India in respect of its own default.

13. Term, conflict and governing law

13.1 This DPA takes effect when Customer begins using the Service and continues for as long as RAKT processes Personal Data for Customer.
13.2 If there is a conflict between this DPA and the Terms of Service in relation to the processing of Personal Data, this DPA prevails. A separately negotiated and signed data processing agreement between the parties prevails over this DPA.
13.3 This DPA is governed by the laws of India, and Section 21 of the Terms of Service applies to any dispute under it.

Annex 1 — Details of processing

Subject matter. Provision of the RAKT HMS hospital management platform to Customer.
Duration. The term of the Subscription, plus the export and deletion periods in Section 10.
Nature of processing. Collection, recording, organisation, structuring, storage, retrieval, use, transmission, display, export, backup, erasure and destruction, carried out by automated means for the purpose of operating the Service.
Purpose. Enabling Customer to register patients and manage appointments and outpatient visits; admissions, beds and inpatient care records; laboratory and radiology orders, results and reports; pharmacy stock and dispensing; emergency and operating-theatre records; billing, payers and claims; staff roles and activity; statutory and internal reporting; and communications with patients — and to provide support, security and continuity for those functions.
Categories of data principals. Patients and prospective patients; attendants and next of kin; referring doctors and external hospitals; Customer’s staff and Authorised Users; suppliers; and the contacts of insurers and other payers.
Categories of Personal Data. Identity and contact data, including name, age or date of birth, sex, address, phone number and email address; identifiers recorded by Customer, including government identity numbers and health-account numbers where captured; clinical data, including vitals, diagnoses, notes, prescriptions, orders, results, reports, admissions and discharge summaries; insurance and payer details; billing and payment records; staff role, credentials and activity logs; and technical data such as IP address and device information.
Sensitive Personal Data. Health data, including medical history, clinical notes and test results, constitutes sensitive personal data or information under Rule 3 of the SPDI Rules and is processed subject to the measures in Annex 2.
Frequency. Continuous, for the duration of the Subscription.

Annex 2 — Technical and organisational measures

These are the measures RAKT operates for RAKT HMS. They are described in plain language on the Security and data page, and are stated as what is in force rather than as an aspiration.

  • Encryption in transit. HTTPS for all access, with HTTP Strict Transport Security enforced for one year, including subdomains and preload, and plain HTTP redirected.
  • Encryption at rest and in backup. Government identity numbers on patient records encrypted at the application layer; object storage encrypted server-side; database backups encrypted and stored in India. Restores are periodically tested.
  • Authentication. Passwords of at least twelve characters, validated against common-password lists and stored only as salted cryptographic hashes; account lockout after five failed attempts, scoped to the address and username pair; secure, HTTPS-only session cookies; one-time codes for the patient portal.
  • Access control. Permission codes per department, module and action, evaluated by the server on every request; named default roles per department; organisation-scoped, user-bound API keys that are read-only by default; logical separation so that records are scoped to the organisation and branch that own them.
  • Accountability and logging. An append-only activity log attributing every change to a user, their role at the time and a structured before-and-after; edits to existing records routed through change requests; access, traffic and processing logs retained for one year.
  • Integrations. Outbound webhooks signed with a shared secret, retried and logged; per-key rate limits and per-origin CORS rules.
  • Personnel. Production access restricted to personnel who require it, over authenticated channels, under written confidentiality obligations.
  • Resilience. Managed database with provider backups, independent encrypted off-host backups taken nightly on a defined retention lifecycle, and documented restore procedures.
  • Incident response. Documented procedure for detection, containment, assessment, notification within the timelines in Section 7, and remediation; vulnerability reports handled through security@rakt.in.
  • Data minimisation in support and diagnostics. Support access to Customer Data only as required to resolve a reported issue; error monitoring configured not to send personal data; prohibitions on storing prohibited data categories under Section 6.4 of the Terms of Service.

RAKT may update these measures to maintain or improve the level of protection, and shall not materially reduce them during the term.

Annex 3 — Sub-processors

The third parties that process Personal Data on RAKT’s behalf to deliver RAKT HMS, what each does, and where it processes data. The list is kept short on purpose: every entry is a party that can technically see some Personal Data, and we would rather name them than describe them vaguely as “our service providers”. Patient records are stored and backed up in India; entries outside India handle delivery, diagnostics or the optional AI assistant, not the primary record store.

Sub-processorWhat it doesProcessing location
DigitalOcean, LLCApplication hosting and the managed PostgreSQL database. This is the primary store for Customer Data.India (Bengaluru)
Amazon Web Services, Inc.Object storage for uploaded files and generated documents, encrypted database backups, and content delivery for static assets.India (Mumbai). Content-delivery edge locations are global and serve static assets only.
Twilio SendGridTransactional and notification email. Processes recipient email addresses and message content.United States
MSG91 (Walkover Web Solutions Pvt. Ltd.) and TextlocalSMS and one-time passcode delivery on DLT-registered templates. Processes recipient phone numbers and template variables.India
Meta Platforms, Inc. (WhatsApp Business Cloud API)WhatsApp notifications where Customer enables them and records patient consent. Processes recipient phone numbers and template message contents, which can include a patient name, appointment details and report documents.United States and other locations operated by Meta
Razorpay Software Pvt. Ltd.Online payment for self-booked appointments and subscription fees. Card and bank details are entered directly with Razorpay and are never received or stored by RAKT.India
Functional Software, Inc. (Sentry)Application error and performance monitoring. Personal-data reporting is disabled; limited identifiers can appear incidentally within an error payload.United States
Google LLCreCAPTCHA on sign-up and public forms; website analytics on rakt.org only, subject to consent, as described in the Cookie Policy. Not present in the signed-in application.United States
Optional AI assistant providerOnly where RAKT enables the optional laboratory AI assistant for Customer’s account: an OpenAI-compatible model provider receives the staff member’s question and the records returned by the assistant’s permission-checked lookups. Disabled unless Customer asks for it; contractually prohibited from training on the data.United States

Contact

Grievance Officer
RAKT INNOVATIONS (OPC) PVT. LTD.
AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India
CIN: U72900DL2020OPC360414 · GSTIN: 07AAKCR0304B1Z0
Phone: +91 70427 21037, +91 99539 94941
Email: support@rakt.in — please put “DPA” or “Grievance” in the subject line