MedPresto

Data Processing Agreement

Effective date: 25 August 2026 · Version 1.0.0

1. Roles & Definitions

Under this agreement and the Digital Personal Data Protection (DPDP) Act, 2023:

  • Data Fiduciary: The Clinic that registers on MedPresto and determines the purposes and means of processing patient data.
  • Data Processor: CLINZO Technologies Private Limited (“MedPresto”), which processes clinic-controlled patient data on behalf of the Clinic.
  • Data Principal: The patient whose personal data is being processed.

2. Scope of Processing

MedPresto processes the following data on behalf of the Clinic:

  • Patient names and phone numbers for queue token issuance.
  • Queue token data (position, status, timestamps).
  • Prescription data (medication details, diagnoses) created by clinic doctors.
  • WhatsApp notification delivery for queue updates.
  • Clinic operational data (doctor schedules, sessions, subscription billing).

3. MedPresto's Obligations (Data Processor)

  • Process personal data only as instructed by the Clinic and as necessary to provide the MedPresto platform services.
  • Implement appropriate technical and organizational security measures, including encryption in transit (TLS) and at rest, access controls, and regular security audits.
  • Notify the Clinic of any personal data breach within 72 hours of becoming aware of it.
  • Assist the Clinic in responding to data subject (patient) requests for access, correction, or erasure.
  • Not engage additional sub-processors without informing the Clinic (see Section 5).
  • Delete or return all personal data upon termination of the agreement, subject to legal retention requirements.

4. Clinic's Obligations (Data Fiduciary)

  • Ensure a lawful basis exists for collecting and processing patient data (e.g., consent, legitimate medical interest).
  • Inform patients about how their data is processed, including directing them to MedPresto's Privacy Policy.
  • Obtain appropriate consent from patients before processing their data through MedPresto, particularly for WhatsApp notifications.
  • Not upload or process data that is unlawfully obtained.
  • Respond to data subject requests in a timely manner, with MedPresto's assistance.

5. Sub-processors

MedPresto uses the following sub-processors:

Sub-processorPurposeLocation
Amazon Web Services (AWS)PostgreSQL database, application infrastructure, and private document storageMumbai, India
RazorpayPayment processing for subscriptionsIndia
MetaWhatsApp Business Platform for enabled service communicationsUnder Meta's terms and privacy practices

Google provides enabled Maps and Places services. Limited location and place-search data may be processed under Google's terms and privacy practices.

MedPresto will notify clinics of any changes to this sub-processor list at least 30 days in advance.

6. Data Return & Deletion on Termination

Upon termination of the clinic's subscription or account:

  • Clinics may request an export of their data before deletion.
  • MedPresto will delete all clinic and associated patient data within 90 days of termination, except where retention is required by law (e.g., prescriptions for 7 years, payment records for 7 years).
  • Anonymized and aggregated data may be retained for analytics purposes.

7. Contact

For questions about this agreement, contact us at grievance@medpresto.com.