Data Processing Addendum

Master DPA — Caresoft Systems Private Limited • Version: [v1.0] • Effective: 01/04/2026
Structure. Clauses 1–22 apply to every Caresoft product. Annex A is completed per customer. Annex B (security measures) applies to all. Annex C contains the product-specific schedule — find your product and read that section together with the main body. Where Annex C differs from the main body, Annex C prevails for that product.

This Data Processing Addendum ("DPA") forms part of the agreement (the "Agreement") between Caresoft Systems Private Limited, CIN U72900MH2022PTC387875, registered office 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107 ("Processor", "Caresoft"), and the customer identified in the Order ("Controller", "you"), and governs Caresoft's processing of Personal Data on your behalf.

Four commitments that apply across every Caresoft product:

1. Personal Data is stored and processed within India.
2. We never sell your data, share it between customers, or use it for our own commercial purposes.
3. We never use it to train artificial intelligence models.
4. Every access by Caresoft personnel is logged with a stated reason, available to you on request.

1. Definitions

  • "Applicable Law" — the Digital Personal Data Protection Act, 2023 and rules; the Information Technology Act, 2000 and the SPDI Rules, 2011; directions issued by CERT-In; and, where relevant, the EU and UK GDPR and the Swiss FADP.
  • "Personal Data" — personal data processed by Caresoft on your behalf under the Agreement, as described in Annex A and the applicable product schedule.
  • "Controller" / "Data Fiduciary", "Processor" / "Data Processor", "Data Subject" / "Data Principal", "Personal Data Breach" — as defined in Applicable Law. Under the DPDP Act, Controller means Data Fiduciary, Processor means Data Processor, and Data Subject means Data Principal.
  • "Sub-processor" — a third party engaged by Caresoft to process Personal Data.
  • "SCCs" — the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
  • "Product Schedule" — the relevant section of Annex C.

2. Roles

DataYouCaresoft
Personal Data you or your users place in, or generate through, the productControllerProcessor
Your user accounts and audit logs within the productControllerProcessor
Your account, billing, contract and support recordsCounterpartyController
Caresoft website and enquiry data—Controller
System logs Caresoft must retain by law—Controller
Aggregated, irreversibly de-identified operational metrics—Controller (subject to §17)

Where you are yourself a processor for another controller, you warrant that you have authority to appoint Caresoft as sub-processor on these terms, and references to "Controller" apply to you as if you were the controller.

Significant Data Fiduciary. A customer processing personal data at volume or of a sensitive nature may be notified as a Significant Data Fiduciary under the DPDP Act, with additional obligations including a Data Protection Officer, independent audit and periodic impact assessment. Determining that is your responsibility; we will provide the information reasonably required to support it.

3. Scope and instructions

  • Caresoft processes Personal Data only on your documented instructions. The Agreement, this DPA, your configuration of the product, and your support requests together constitute your complete instructions.
  • We will inform you if, in our opinion, an instruction infringes Applicable Law, and may decline to act on an instruction that would.
  • Processing required by law to which Caresoft is subject is permitted; where legally allowed, we will inform you before doing so. See §13 and §15.
  • Details of processing are in Annex A and the applicable Product Schedule.

4. Your obligations

  • Establish and maintain a lawful basis for the Personal Data you place in the product.
  • Give the notices, and obtain and manage the consents, that Applicable Law requires of you.
  • Not place in the product any category of Personal Data outside Annex A and the Product Schedule without our written agreement.
  • Configure the product appropriately — retention, access, visibility and any product-specific control identified in the Product Schedule.
  • Provision, review at least [quarterly], and revoke user access within [24] hours of a person leaving or changing role. We cannot know when your people change.
  • Handle Data Principal requests as Controller (§11).
  • Conduct any required data protection impact assessment.
  • Notify us immediately of any incident on your side affecting Personal Data or the product (§12).

5. Our obligations

Caresoft will: process only on your instructions; ensure personnel are bound by confidentiality (§7); implement and maintain the measures in Annex B; engage Sub-processors only under §9; assist you under §11, §12 and §18; make available the information and access in §14; and return or delete Personal Data under §16.

6. Our access to your data

Caresoft personnel access Personal Data only where necessary to: resolve a support request you raised; investigate a security incident or suspected misuse; perform contracted managed services; or comply with valid legal process.

  • Access is on a least-privilege, minimum-necessary basis, individually authenticated, never through shared accounts, and requires multi-factor authentication.
  • Every access is logged with identity, timestamp, record accessed and stated reason. The log is available to you on request.
  • We notify you of access made for reasons other than a request you raised, unless legally prohibited.
  • Production Personal Data is never copied into development, test, training or demonstration environments. Those use synthetic or irreversibly anonymised data only.
  • Caresoft personnel must not download, export, photograph or retain Personal Data on personal devices or accounts.

7. Personnel

  • All personnel with potential access are bound by written confidentiality obligations surviving employment, subject to background verification appropriate to the role, and trained on data protection at induction and at least [annually].
  • Access is provisioned by role, reviewed at least [quarterly], and revoked within [24] hours of role change or exit.
  • We maintain a current list of roles with access to Personal Data and provide it on request.

8. Security measures

Caresoft implements and maintains the technical and organisational measures in Annex B, together with any additional measures in the Product Schedule, appropriate to the risk.

We may update these measures provided the overall level of security is not reduced. Reduction of any measure requires your written agreement. Material changes are notified.

Security is shared. You are responsible for your network, endpoints, credentials, user access hygiene, and any component running on your own infrastructure (agents, edge devices, gate hardware) as identified in the Product Schedule.

9. Sub-processors

  • You give general written authorisation for Caresoft to engage Sub-processors. The current list per product is at [https://caresoft.co.in/subprocessors] and summarised in the Product Schedule.
  • Each is engaged under a written contract imposing obligations materially equivalent to this DPA, including access logging and the localisation requirement in §10.
  • Caresoft remains fully liable to you for its Sub-processors' acts and omissions.
  • Notice. At least [30] days before a new Sub-processor begins processing Personal Data, by email to your named data protection contact.
  • Objection. You may object within [15] days on reasonable, documented data protection grounds. We will propose an alternative; if none is agreed within [30] days, you may terminate the affected scope without penalty and receive a pro-rata refund of prepaid unused fees. That is your sole remedy for an objection.
  • Emergency substitution. Where necessary for continuity or security, we may engage a replacement without prior notice and will inform you as soon as practicable.

For products processing health or financial data, we will not engage a Sub-processor located outside India for that data without your prior written consent. See the Product Schedule.

10. Location and transfers

  • Personal Data is stored and processed within India, including production, backups and disaster recovery, unless the Product Schedule states otherwise.
  • Caresoft support and engineering access is from India. Access from outside India is not permitted without your prior written consent.
  • Transfers outside India are made only where permitted under Section 16 of the DPDP Act and any restriction notified by the Central Government, and only on your written instruction or as stated in the Product Schedule.
  • EEA transfers. Where we process Personal Data subject to the GDPR and transfer it outside the EEA without an adequacy decision, the SCCs are incorporated, with Module Two (controller to processor) where you are a controller and Module Three (processor to processor) where you are a processor. Annex A and Annex B populate the corresponding SCC annexes. Clause 7 (docking) applies; Clause 9 option 2 (general authorisation, [30] days' notice) applies; Clause 11 optional redress body does not apply; Clause 17 governing law is the law of [Ireland]; Clause 18 forum is the courts of [Ireland].
  • UK transfers. The UK International Data Transfer Addendum applies, with the SCCs as its Approved EU SCCs, Tables 1–3 populated by this DPA and its Annexes, and Table 4 "neither party".
  • Swiss transfers. The SCCs apply with references to the GDPR read as references to the Swiss FADP, and the FDPIC as supervisory authority.

11. Data principal requests

  • You have direct access to Personal Data in the product and can respond to requests yourself. That is the expected route.
  • If we receive a request directly from a Data Principal relating to your Personal Data, we will not respond substantively, will refer them to you, and will inform you within [2] working days unless legally prohibited.
  • Where you cannot fulfil a request through the product, we will provide reasonable assistance, at your cost where more than trivial, taking into account what is technically feasible.
  • Erasure may be constrained by mandatory retention (§13), by immutable audit trails maintained for evidential and safety reasons, and by records you are separately required to keep. We will identify specifically what cannot be erased and why.

12. Breach notification

Caresoft will notify you of any Personal Data Breach affecting Personal Data we process for you without undue delay, and in any event within the period stated in your Product Schedule — 6, 24 or 48 hours depending on the sensitivity of the data concerned.

  • Initial notification is in writing and, for the shorter windows, by phone to your named contact. Information is supplemented as the investigation proceeds.
  • Notification will describe: the nature of the breach; categories and approximate numbers of Data Principals and records affected; likely consequences; measures taken and proposed; and a named contact.
  • We preserve all evidence and will not alter or delete logs relating to the breach until the investigation is closed.
  • You are responsible for notifying the Data Protection Board of India, any other regulator, and affected Data Principals. We provide the information and support required and will not communicate with your Data Principals without your written instruction.
  • We provide a written root cause analysis with corrective and preventive actions within [10] working days.
  • Notification is not an acknowledgement of fault or liability.
  • You must notify us within [6] hours of any breach on your side affecting Personal Data or capable of affecting the product or other customers.

13. Mandatory Indian retention and reporting

As an Indian service provider, Caresoft is subject to directions issued by CERT-In. These are legal obligations that override conflicting instructions, including erasure instructions under §16.

  • ICT system logs are retained for a minimum of 180 days within India and produced to CERT-In or another lawful authority on demand. These record activity about systems, not the contents of your data.
  • Specified cyber incidents must be reported to CERT-In within 6 hours of our becoming aware. You must report qualifying incidents to us immediately.
  • System clocks are synchronised to NPL or NIC network time servers.
  • Where a product falls within the CERT-In direction on virtual server, cloud or VPN services, validated customer registration records are retained for at least 5 years after termination, as stated in the Product Schedule.

Where an instruction cannot be followed because of these obligations, we will tell you which obligation applies and precisely what is retained.

14. Audit and information

  • On request we provide: our security documentation and completed due-diligence questionnaire; penetration test and vulnerability assessment summaries; access logs relating to your data; restore test and DR evidence; the current Sub-processor list; and any certification reports we hold.
  • You may audit our processing of your Personal Data once per twelve months, and additionally following a Personal Data Breach or where required by a regulator or accreditation body.
  • Audits require [30] days' notice (less following an incident or on regulatory direction), are conducted during business hours, are subject to confidentiality, and must not access other customers' data.
  • You may use an independent auditor who is not a competitor of Caresoft and who signs a confidentiality undertaking.
  • You bear your own audit costs; we bear ours for the annual audit and for any audit following a breach attributable to us.
  • We cannot grant physical access to data centres we do not own. Facility assurance is provided through the hosting provider's published certifications.

15. Government access

If we receive a legally binding request from a public authority for Personal Data we process for you, we will assess its validity, challenge it where there are reasonable grounds, disclose only the minimum required, and notify you promptly unless legally prohibited — in which case we will seek a waiver and notify as soon as the prohibition lapses. Where feasible we will direct the authority to request the data from you directly. We maintain records of such requests to the extent lawful.

16. Return and deletion

  • You may export Personal Data at any time during the term.
  • On termination, Personal Data remains available for export for the period in your Product Schedule, after which it is deleted.
  • Backups are deleted on their normal rotation, within [35] days.
  • Deletion is subject to §13 and to records we must retain as Controller. Retained copies remain protected by this DPA and are processed only for the purpose requiring retention.
  • Data relating to an open safety, security or fraud investigation is preserved until closure regardless of any deletion instruction.
  • On written request we certify deletion once completed.

17. Secondary use and artificial intelligence

Caresoft will not: use your Personal Data for its own purposes; sell, licence or share it; use it for marketing or research; share it between customers; benchmark it in identifiable form; or use it to train, fine-tune, evaluate or improve any artificial intelligence or machine learning model, whether ours or a third party's.

  • Aggregated operational metrics (usage counts, error rates, performance) may be used for capacity planning and product improvement only where irreversibly de-identified such that no Data Principal, user or customer can be identified or re-identified.
  • Where a product feature uses a third-party AI service, it is disclosed in the Product Schedule, our contract with that provider prohibits training on submitted data, and — where the Product Schedule so states — the feature can be disabled entirely for your account.
  • Any proposal to use Personal Data for research, benchmarking, publication or model development requires a separate written agreement and is outside this DPA.

18. Assistance

Taking into account the nature of processing and the information available to us, we will assist you — at your cost where the assistance is more than trivial — with your security obligations, breach notification, data protection impact assessments, and prior consultation with a supervisory authority. Because we do not have visibility into the substance of what you place in the product, much of this assistance takes the form of documentation, configuration information and platform-level records.

19. Liability

Liability under this DPA is subject to the limitations in the Agreement, save that the general cap does not apply to breach of data protection obligations where the Agreement so provides. Caps apply in the aggregate across the Agreement and this DPA, not separately. Nothing limits liability that cannot lawfully be limited, or a Data Principal's rights. Where the SCCs apply, nothing limits any liability that cannot be limited under them.

20. Term, precedence and changes

  • This DPA takes effect with the Agreement and continues while Caresoft processes Personal Data for you.
  • Precedence: any clinical-safety document identified in the Product Schedule → SCCs where applicable → Product Schedule → this DPA main body → the Agreement → other policies.
  • We may update this DPA where required by a change in Applicable Law, a supervisory authority decision, or a change in approved transfer mechanisms, on [30] days' notice. Changes reducing protection require your written agreement.
  • If any provision is invalid, it is modified to the minimum extent necessary and the remainder continues.
  • Governed by the law of the Agreement, except that the SCCs are governed as stated in §10.
  • No signature is required where you accept the Agreement online — this DPA applies automatically. A countersigned copy is available on request.

Annex A — Details of processing

A. Parties

Data exporterData importer
NameThe Customer in the OrderCaresoft Systems Private Limited
AddressAs stated in the Order311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
ContactCustomer's data protection contact[[email protected]]
RoleController (or processor, where applicable)Processor

B. Description

ItemDetail
Subject matterProvision of the Caresoft product named in the Order
DurationTerm of the Agreement, plus the deletion periods in §16 and mandatory retention under §13
Nature and purposeAs set out in the applicable Product Schedule
Categories of Data PrincipalsAs set out in the applicable Product Schedule
Categories of Personal DataAs set out in the applicable Product Schedule
Special categoriesAs set out in the applicable Product Schedule
FrequencyContinuous for the duration of the Agreement
RetentionAs instructed by you, within the product's configuration; defaults in the Product Schedule
Competent Supervisory Authority (SCC Annex I.C)[The authority of the EEA member state where your EU representative is established, or where Data Principals are located]

Annex B — Technical and organisational measures

Applies to all products. Additional or stricter measures per product are in Annex C.

AreaMeasures
EncryptionTLS 1.2+ in transit; encryption at rest for databases and backups; passwords stored using a modern one-way hash with a per-install pepper in addition to a per-user salt; secrets, API keys and third-party credentials stored encrypted with restricted retrieval
Access controlRole-based access; multi-factor authentication for all administrative access; least privilege; no shared accounts; server-side enforcement of portal and tenant separation; access reviewed [quarterly]; revocation within [24] hours of exit
Tenant isolationEnforced at the data layer; no customer can reach another customer's data by any interface
AuditImmutable logging of authentication, data access, record changes, configuration changes and exports, with identity, timestamp and reason; available to the customer
Environment separationProduction separated from development, test and training. No production Personal Data in non-production environments
AvailabilityEncrypted backups held in India in a separate failure domain; restore testing [quarterly]; DR exercise [annually]; recovery objectives per the applicable SLA
Vulnerability managementRegular patching; dependency and vulnerability scanning; penetration testing [annually] with summary available; documented remediation timelines by severity
Secure developmentPeer-reviewed changes; version control; separated environments; release and rollback procedures; defect tracking; documented pre-release testing
Logging and monitoringAuthentication, error and integrity telemetry; alerting on anomalous access; ICT system logs retained ≥180 days in India; clocks synchronised to NPL/NIC
Incident responseDocumented plan with defined severities and escalation; on-call coverage; customer notification per §12; CERT-In reporting within 6 hours; evidence preservation; root cause analysis within [10] working days
PersonnelBackground verification; confidentiality agreements surviving employment; data protection training at induction and [annually]; documented joiner-mover-leaver process
Sub-processor governancePre-engagement assessment on security, certifications, jurisdiction and incident history; equivalent contractual obligations; annual review; public disclosure
PhysicalHosting in access-controlled facilities within India under published certifications; media decommissioning by the hosting provider under its certified procedures
DeletionSecure deletion on instruction with written certification; backup expiry within [35] days

Annex C — Product schedules

Find your product. Read it with the main body; where they differ, this schedule prevails.

C1 Sloto — scheduling

ItemDetail
Nature and purposePublishing availability, accepting and managing bookings, creating calendar events, sending confirmations and reminders
Data PrincipalsHosts (your users); Invitees (people who book with them); guests added to invitations
Personal DataName, email, phone, time zone, job title, organisation, booking form responses, meeting date/time/type, reschedule and cancellation records, calendar free/busy and event data from connected accounts
Special categoriesNot permitted. Health, financial account, biometric or government-identifier data must not be collected through booking forms without written agreement
Third-party servicesCalendar and conferencing providers connected by the Host act as independent controllers once data reaches them. Google user data is handled under the Limited Use requirements
Breach notification[48] hours
Export window on termination30 days
Sub-processorsAWS India (hosting); Twilio / MSG91 (SMS notifications); SendGrid / Postmark (transactional email)

C2 CareHMS — Healthcare Management System

ItemDetail
Nature and purposeElectronic health records (EHR), patient registration, clinical documentation, billing, lab management, and telemedicine
Data PrincipalsPatients, next of kin, emergency contacts, attending doctors, nurses, and administrative staff
Personal DataDemographics, contact details, national health IDs (ABHA), insurance numbers, billing/payment records
Special categoriesPermitted. Medical history, diagnoses, prescriptions, lab results, genomic data, biometric identifiers
Breach notification[6] hours (critical clinical data)
Export window on termination60 days
Sub-processorsAWS India (Healthcare Zone); NIC / ABDM Gateway (health ID resolution); Razorpay (payments)

C3 CarePay — Billing & Financial Gateway

ItemDetail
Nature and purposeInvoicing, payment processing, subscription management, tax calculation, and financial reconciliation
Data PrincipalsPayer (customers/patients), account holders, billing administrators
Personal DataBilling address, transaction histories, masked payment tokens, GSTIN, invoice details
Special categoriesNot permitted. Raw PCI-DSS card data is tokenised directly via PCI-certified payment gateways
Breach notification[24] hours
Export window on termination30 days (financial logs retained per statutory accounting requirements)
Sub-processorsStripe India / Razorpay (payment processing); ClearTax (tax compliance)