Data Processing Agreement
Effective date: 25 August 2026 · Version 1.0.0
1. Roles & Definitions
Under this agreement and the Digital Personal Data Protection (DPDP) Act, 2023:
- Data Fiduciary: The Clinic that registers on MedPresto and determines the purposes and means of processing patient data.
- Data Processor: CLINZO Technologies Private Limited (“MedPresto”), which processes clinic-controlled patient data on behalf of the Clinic.
- Data Principal: The patient whose personal data is being processed.
2. Scope of Processing
MedPresto processes the following data on behalf of the Clinic:
- Patient names and phone numbers for queue token issuance.
- Queue token data (position, status, timestamps).
- Prescription data (medication details, diagnoses) created by clinic doctors.
- WhatsApp notification delivery for queue updates.
- Clinic operational data (doctor schedules, sessions, subscription billing).
3. MedPresto's Obligations (Data Processor)
- Process personal data only as instructed by the Clinic and as necessary to provide the MedPresto platform services.
- Implement appropriate technical and organizational security measures, including encryption in transit (TLS) and at rest, access controls, and regular security audits.
- Notify the Clinic of any personal data breach within 72 hours of becoming aware of it.
- Assist the Clinic in responding to data subject (patient) requests for access, correction, or erasure.
- Not engage additional sub-processors without informing the Clinic (see Section 5).
- Delete or return all personal data upon termination of the agreement, subject to legal retention requirements.
4. Clinic's Obligations (Data Fiduciary)
- Ensure a lawful basis exists for collecting and processing patient data (e.g., consent, legitimate medical interest).
- Inform patients about how their data is processed, including directing them to MedPresto's Privacy Policy.
- Obtain appropriate consent from patients before processing their data through MedPresto, particularly for WhatsApp notifications.
- Not upload or process data that is unlawfully obtained.
- Respond to data subject requests in a timely manner, with MedPresto's assistance.
5. Sub-processors
MedPresto uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | PostgreSQL database, application infrastructure, and private document storage | Mumbai, India |
| Razorpay | Payment processing for subscriptions | India |
| Meta | WhatsApp Business Platform for enabled service communications | Under Meta's terms and privacy practices |
Google provides enabled Maps and Places services. Limited location and place-search data may be processed under Google's terms and privacy practices.
MedPresto will notify clinics of any changes to this sub-processor list at least 30 days in advance.
6. Data Return & Deletion on Termination
Upon termination of the clinic's subscription or account:
- Clinics may request an export of their data before deletion.
- MedPresto will delete all clinic and associated patient data within 90 days of termination, except where retention is required by law (e.g., prescriptions for 7 years, payment records for 7 years).
- Anonymized and aggregated data may be retained for analytics purposes.
7. Contact
For questions about this agreement, contact us at grievance@medpresto.com.