Data Processing Agreement
Last updated: June 9, 2026
This Data Processing Agreement ("DPA") governs how AesthOS Clinic Suite ("Processor", "we") processes Personal Data on behalf of subscribing clinics ("Controller", "you") under the Digital Personal Data Protection Act, 2023 of India ("DPDP Act") and applicable data protection law.
1. Roles
The clinic is the Data Fiduciary (controller) of patient, staff, and operational data captured in the platform. AesthOS is the Data Processor acting on the clinic's documented instructions through the use of the software.
2. Categories of data processed
- Patient identifiers — name, phone, email, address, gender, date of birth.
- Clinical data — diagnoses, allergies, medications, treatment notes, prescriptions, before/after photos, consent forms.
- Financial data — invoices, payments, refunds, GST identifiers.
- Staff data — employment, payroll, attendance, role assignments.
- Communications — appointment reminders, follow-ups, WhatsApp/email logs.
3. Purpose & limitation
AesthOS processes Personal Data only to deliver the contracted service: appointment scheduling, billing, EMR, marketing automation, accounting, and reporting requested by the Controller. We do not use clinic or patient data for advertising, resale, or model training.
4. Security measures
- Row-Level Security (RLS) on every table; role-scoped access via
has_role/is_staff. - TLS 1.2+ for data in transit and AES-256 for data at rest.
- Daily automated database backups with point-in-time recovery.
- Audit logging of administrative actions and data exports.
- Optional two-factor authentication (TOTP) for staff accounts.
- Principle of least privilege for AesthOS employees; production access is gated and logged.
5. Sub-processors
We use vetted infrastructure sub-processors (managed database, edge compute, email delivery, WhatsApp Business API gateway, payments). A current list is available on request. We notify Controllers of material changes.
6. Data Principal rights
The Controller is responsible for responding to Data Principal (patient/staff) requests for access, correction, erasure, and grievance redressal. AesthOS provides export and deletion tooling in the admin area to assist.
7. Data location & transfers
Primary storage is in India / Asia-Pacific regions. Cross-border processing, where required for service delivery, is restricted to jurisdictions permitted by Indian law and the DPDP Act notifications.
8. Breach notification
We notify the Controller without undue delay (and in any case within 72 hours of confirmation) of any Personal Data Breach affecting clinic data, with sufficient information for the Controller to meet its own obligations to the Data Protection Board.
9. Return & deletion
On termination, the Controller may export all clinic data through the admin area. AesthOS deletes Personal Data from active systems within 30 days and from backups within 90 days, except where retention is required by law.
10. Audit & cooperation
AesthOS makes available the information necessary to demonstrate compliance with this DPA and reasonably cooperates with audits requested by the Controller, subject to confidentiality and proportionality.
11. Contact
For DPA, security, or DPDP-related questions, contact customercare@dtaniqueahmedabad.com.