This Data Processing Agreement (DPA) establishes the terms under which NarraHealth Technologies Pvt. Ltd. ("Data Processor") processes personal data on behalf of a data controller ("Client"). This DPA complies with India's DPDP Act 2023 and GDPR.
This DPA governs how NarraHealth Technologies Pvt. Ltd. ("Data Processor") processes personal data on behalf of a controller ("Client").
This DPA complements the Business Associate Agreement (BAA), Privacy Policy, Terms of Service, and Data Security Statement.
Determines the purposes and means of data processing.
Processes data on behalf of Controller.
Effective upon execution, continues for service agreement term. Post-termination: data retained 30–90 days for transition; data available for download; deleted on request or per retention policy.
Enhanced security applies to health, financial, biometric, and genetic data. Additional measures include:
Narra Healthcare assists the Controller by:
| Control | Frequency | Verification |
|---|---|---|
| Access Logging | Continuous | Daily review |
| Vulnerability Scanning | Weekly | Report generation |
| Penetration Testing | Quarterly | Report and remediation |
| Backup Testing | Monthly | Restoration time logged |
| Disaster Recovery | Quarterly | Drill report |
| Vendor | Purpose | Location | Certification |
|---|---|---|---|
| Google Cloud Platform | Cloud infrastructure | Delhi and Mumbai, India | ISO 27001, SOC 2 |
| AWS | Cloud redundancy | Mumbai, India | ISO 27001, SOC 2 |
| Razorpay | Payment processing | India | PCI DSS, ISO 27001 |
| Stripe | Payment processing | US data in India | PCI DSS, SOC 2 |
| Google Analytics | Analytics | Global | ISO 27001, SOC 2, GDPR-ready |
| Sentry | Error tracking: anonymised data only | US | SOC 2 |
All personal data is stored in India (AWS ap-south-1 / Google Cloud asia-south1). No transfer outside India without explicit approval.
Narra Healthcare will NOT transfer data to:
Unauthorised access, disclosure, modification, loss, or corruption of personal data.
Narra Healthcare provides notification templates, media response assistance, and regulatory communication support.
Effective upon execution; continues for service agreement term.
No new data accepted; existing data retained 30–90 days; processing limited to export and deletion; confidentiality obligations continue indefinitely.
Deletion uses overwrite method, crypto-erase, or physical destruction for decommissioned servers. A certificate of deletion is provided. Audit logs are retained per legal requirements (5–7 years).
Narra Healthcare indemnifies Controller for: data breaches caused by Narra Healthcare, unauthorised disclosure, failure to implement security.
Controller indemnifies Narra Healthcare for: claims from unauthorised data uploads, IP infringement, regulatory violations by Controller.
Governing law: India. Jurisdiction: Hyderabad courts.