Skip to main content
Compliance & Governance

Data Processing Addendum (DPA)

Effective Date: 26 April 2026  ·  Last Updated: 26 April 2026

Technical & Organizational Measures (TOMs), Sub-Processor Registry, and GDPR Article 28 / HIPAA / DPDP Act compliance commitments.

Security Rule Safeguards

TLS 1.3 in-transit, AES-256 rest encryption, role-based multi-tenant partitioning, and immutable audit logs (§ 164.312(b)).

Cross-Border Transfers

All non-EEA/India data processing governed under EU Standard Contractual Clauses (SCCs) with verified zero-retention policies.

Medical Record Retention

Statutory 3-year clinical archiving under NMC Telemedicine Guidelines (exempt from immediate erasure under GDPR Art. 17(3)(b)).

Authorised Sub-Processors

Homeo AI Clinic engages the following third-party infrastructure providers to support platform reliability, AI clinical decision support, and payment execution.

Sub-ProcessorCategoryScope of DataLocation & MechanismCompliance
OpenRouter / Google Gemini APIAI Clinical InferenceAnonymized symptoms & clinical rubrics (Zero-Retention configuration)US / EU (SCCs)SOC 2 Type II, ISO 27001
Stripe Inc.Payment GatewayBilling transactions & receipts (Zero raw card numbers stored)Global EdgePCI-DSS Level 1
PayU Payments Private Ltd.Payment Gateway (India)UPI, NetBanking & domestic rupee transactionsIndia (RBI Regulated)PCI-DSS, ISO 27001
Cashfree Payments IndiaSecondary Gateway & PayoutsDoctor consultation disbursements and fallback billingIndiaPCI-DSS, ISO 27001
Resend / PostmarkTransactional MessagingPrescription delivery & case intake email notificationsUS / EU (SCCs)SOC 2 Type II, GDPR Compliant
Cloudflare Inc.Edge CDN & SecurityEncrypted packet delivery, DDoS mitigation & WAF shieldingGlobal EdgeSOC 2, ISO 27001, PCI-DSS

Incident Response & 72-Hour Breach Notification

In accordance with GDPR Article 33 and DPDPA 2023, if a security incident occurs that poses a risk to the rights and freedoms of data subjects or impacts confidential patient records, Homeo AI Clinic will:

  • Notify the relevant supervisory authority and affected individuals within 72 hours of confirming the incident.
  • Promptly provide a comprehensive summary of the affected data categories, nature of the vulnerability, and immediate remediation actions taken.
  • Publish an incident post-mortem in coordination with our designated Data Protection Officer.

Exercising Your Right to Data Portability (GDPR Art. 20)

Patients can at any time generate and download an authentic, machine-readable JSON export of all their submitted symptoms, vitals, medical history, and clinical consultations directly from their Patient Dashboard using the “Export My Data” button.

Homeo AI Clinic — homeoaiclinic.com  ·  Governed by the laws of India & International Standards

← Back to Home