This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer”, the Data Fiduciary) and TechForBharat.com (“TechForBharat.com”, the Data Processor) for the Customer’s use of the BharatConnector services (the “Services”). It reflects the parties’ obligations under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and other applicable data-protection law. If there is a conflict on data-protection matters between this DPA and the main agreement, this DPA prevails.
How to use this DPA: complete the details in Annex A, review Annexes B and C, and execute it alongside your services agreement. To have it countersigned, contact hello@techforbharat.com.
Contents
1. Definitions
Capitalised terms not defined here have the meaning given in the DPDP Act or the main agreement. “Data Principal”, “Data Fiduciary”, “Data Processor”, “Personal Data” and “Processing” have the meanings given in the DPDP Act. “Personal Data Breach” means any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to Personal Data that compromises its confidentiality, integrity or availability. “Sub-processor” means any third party engaged by TechForBharat.com to process Personal Data on the Customer’s behalf.
2. Roles of the parties
The Customer is the Data Fiduciary and determines the purposes and means of Processing. TechForBharat.com acts as a Data Processor and processes Personal Data only on the Customer’s documented instructions — including as set out in this DPA, Annex A and the main agreement — except where required to act by applicable law. TechForBharat.com will inform the Customer if, in its reasonable opinion, an instruction infringes applicable data-protection law.
3. Scope & instructions
Processing is limited to what is necessary to provide the Services and to the details described in Annex A. TechForBharat.com will not use Personal Data for its own purposes and will not sell Personal Data.
4. Confidentiality
TechForBharat.com ensures that personnel authorised to process Personal Data are bound by appropriate confidentiality obligations and access it only on a need-to-know basis.
5. Security measures
TechForBharat.com implements and maintains appropriate technical and organisational measures to protect Personal Data, as described in Annex B, and takes reasonable steps to ensure the reliability of personnel with access to it.
6. Sub-processors
The Customer grants a general authorisation for TechForBharat.com to engage the Sub-processors listed in Annex C. TechForBharat.com imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA and remains responsible for their performance. TechForBharat.com will give the Customer reasonable notice of any intended addition or replacement of a Sub-processor, and the Customer may object on reasonable data-protection grounds.
7. Assistance to the Data Fiduciary
Taking into account the nature of Processing and the information available to it, TechForBharat.com will provide reasonable assistance to help the Customer meet its own obligations under the DPDP Act, including in relation to security, Personal Data Breaches, and responding to Data Principals.
8. Personal data breach
TechForBharat.com will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer’s Personal Data, provide information reasonably required for the Customer to meet its notification obligations, and take reasonable steps to mitigate and remediate the breach.
9. Data Principal requests
If TechForBharat.com receives a request from a Data Principal relating to the Customer’s Personal Data, it will promptly inform the Customer and will not respond to the request itself except on the Customer’s instructions or as required by law. TechForBharat.com will assist the Customer in responding to such requests.
10. International transfers
TechForBharat.com processes and transfers Personal Data only in accordance with the Customer’s instructions and applicable law, and will not transfer Personal Data outside India except as permitted under the DPDP Act and with appropriate safeguards.
11. Health & claims data
Where the Services route clinical or insurance-claims data (for example, to enable interoperability with ABDM, NHCX, insurers, providers or third-party administrators), such data is processed only in transit as directed by the Customer and is not retained by TechForBharat.com beyond what is necessary to complete the relevant transaction.
12. Return & deletion
On expiry or termination of the Services, at the Customer’s choice, TechForBharat.com will delete or return the Personal Data it processes on the Customer’s behalf and delete existing copies, unless retention is required by applicable law.
13. Audits & information
TechForBharat.com will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, subject to reasonable notice, frequency, confidentiality and security requirements.
14. Liability
Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the main agreement.
15. Term
This DPA takes effect on the effective date in Annex A and remains in force for as long as TechForBharat.com processes Personal Data on the Customer’s behalf under the Services.
16. Governing law
This DPA is governed by the laws of India and by the governing-law and jurisdiction terms of the main agreement.
Annex A — Details of processing
| Customer (Data Fiduciary) | [Customer legal name] |
|---|---|
| Effective date | [Effective date] |
| Subject matter | Provision of the BharatConnector connector and integration services. |
| Duration | The term of the Services and any period required to return or delete Personal Data. |
| Nature & purpose | Facilitating interoperability and exchange of data between the Customer’s systems and national digital public infrastructure (e.g., ABDM, NHCX) and authorised third parties, to deliver the Services requested by the Customer. |
| Categories of Data Principals | Patients / beneficiaries, insured members, and the Customer’s staff and authorised users, as applicable. |
| Types of Personal Data | Identifiers and contact details, health identifiers (e.g., ABHA), and health or insurance-claims information routed through the Services as configured by the Customer. |
| Special considerations | May include health data; processed in transit only and not warehoused by TechForBharat.com. |
Annex B — Security measures
- Encryption of Personal Data in transit (TLS 1.3).
- Authenticated access using OAuth 2.0 and JWT within the platform.
- Role-based access control and least-privilege access.
- Network security, logging and monitoring of access and activity.
- Secure development practices and change management.
- Personnel confidentiality obligations and security awareness.
- Incident detection and response procedures.
- Governance consistent with ISO 27001 practices.
- Data minimisation and no retention of pass-through clinical or claims payloads.
Annex C — Sub-processors
TechForBharat.com may engage the following categories of Sub-processors to support the Services. The current list is available on request.
| Hosting / infrastructure | [Cloud / hosting provider], for secure hosting of the platform. |
|---|---|
| Communications | [Email / form-delivery provider], to deliver enquiry submissions and notifications. |
| Analytics (optional) | [Analytics provider], where enabled with consent, for aggregated usage statistics. |
Execution
| For the Customer (Data Fiduciary) | Name: __________________ Title: __________________ Date: __________ Signature: __________________ |
|---|---|
| For TechForBharat.com (Data Processor) | Name: __________________ Title: __________________ Date: __________ Signature: __________________ |