Data Processing Addendum (DPA)
Effective Date: 26 April 2026 · Last Updated: 26 April 2026
Technical & Organizational Measures (TOMs), Sub-Processor Registry, and GDPR Article 28 / HIPAA / DPDP Act compliance commitments.
TLS 1.3 in-transit, AES-256 rest encryption, role-based multi-tenant partitioning, and immutable audit logs (§ 164.312(b)).
All non-EEA/India data processing governed under EU Standard Contractual Clauses (SCCs) with verified zero-retention policies.
Statutory 3-year clinical archiving under NMC Telemedicine Guidelines (exempt from immediate erasure under GDPR Art. 17(3)(b)).
Authorised Sub-Processors
Homeo AI Clinic engages the following third-party infrastructure providers to support platform reliability, AI clinical decision support, and payment execution.
| Sub-Processor | Category | Scope of Data | Location & Mechanism | Compliance |
|---|---|---|---|---|
| OpenRouter / Google Gemini API | AI Clinical Inference | Anonymized symptoms & clinical rubrics (Zero-Retention configuration) | US / EU (SCCs) | SOC 2 Type II, ISO 27001 |
| Stripe Inc. | Payment Gateway | Billing transactions & receipts (Zero raw card numbers stored) | Global Edge | PCI-DSS Level 1 |
| PayU Payments Private Ltd. | Payment Gateway (India) | UPI, NetBanking & domestic rupee transactions | India (RBI Regulated) | PCI-DSS, ISO 27001 |
| Cashfree Payments India | Secondary Gateway & Payouts | Doctor consultation disbursements and fallback billing | India | PCI-DSS, ISO 27001 |
| Resend / Postmark | Transactional Messaging | Prescription delivery & case intake email notifications | US / EU (SCCs) | SOC 2 Type II, GDPR Compliant |
| Cloudflare Inc. | Edge CDN & Security | Encrypted packet delivery, DDoS mitigation & WAF shielding | Global Edge | SOC 2, ISO 27001, PCI-DSS |
Incident Response & 72-Hour Breach Notification
In accordance with GDPR Article 33 and DPDPA 2023, if a security incident occurs that poses a risk to the rights and freedoms of data subjects or impacts confidential patient records, Homeo AI Clinic will:
- Notify the relevant supervisory authority and affected individuals within 72 hours of confirming the incident.
- Promptly provide a comprehensive summary of the affected data categories, nature of the vulnerability, and immediate remediation actions taken.
- Publish an incident post-mortem in coordination with our designated Data Protection Officer.
Exercising Your Right to Data Portability (GDPR Art. 20)
Patients can at any time generate and download an authentic, machine-readable JSON export of all their submitted symptoms, vitals, medical history, and clinical consultations directly from their Patient Dashboard using the “Export My Data” button.
Related Legal Documents
Homeo AI Clinic — homeoaiclinic.com · Governed by the laws of India & International Standards
← Back to Home