Data Processing Agreement
Last updated: 20 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between you and your organization ("Customer", the controller) and Anutosh Chaudhuri, an individual carrying on business as a sole proprietor in Karnataka, India ("DravyaOS", "we", "us", the processor). It applies whenever you enable sync or the AI add-on and we therefore process personal data on your behalf. Where this DPA conflicts with the Terms on data protection, this DPA prevails.
1. Definitions
"Applicable data protection law" means the data protection and privacy laws that apply to the Customer's processing, which may include India's Digital Personal Data Protection Act, Singapore's PDPA, the EU/UK GDPR, and comparable laws. "Controller", "processor", "personal data", "processing", "data subject", and "personal data breach" have the meanings given in that law. "Sub-processor" means a third party we engage to process personal data on our behalf.
2. Roles of the parties
The Customer is the controller of the personal data it records in and syncs through DravyaOS — including its own customers' and patients' details — and is responsible for having a lawful basis and any consent required to process that data. We are the processor and process that personal data only to provide the service. Annex C describes the processing.
3. Our obligations as processor
- Instructions. We process personal data only on the Customer's documented instructions. The Customer's configuration and use of the service (enabling sync, using the AI add-on) are such instructions. We will tell the Customer if we believe an instruction breaches applicable data protection law.
- Confidentiality. Anyone we authorize to process the data is bound by confidentiality.
- Security. We maintain the technical and organizational measures in Annex B.
- Sub-processors. We use the sub-processors in Annex A under Section 4.
- Data subject requests. Taking into account the nature of the processing, we assist the Customer with appropriate measures to respond to data subjects exercising their rights.
- Assistance. We assist the Customer, to the extent reasonable, with security, breach notification, and data protection impact assessments.
- Return or deletion. On termination, or on the Customer's request, we delete or return the personal data as set out in Section 7, unless the law requires us to retain it.
- Records and audits. We make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits by the Customer or an auditor it mandates, on reasonable notice, not more than once a year unless required by a regulator, and subject to confidentiality.
4. Sub-processors
The Customer gives general authorization for us to engage the sub-processors listed in Annex A. We impose data protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. If we add or replace a sub-processor, we will update Annex A and give the Customer a reasonable opportunity to object on reasonable data protection grounds; if an objection cannot be resolved, the Customer may stop using the affected feature.
5. International transfers
The Customer acknowledges that personal data it syncs is stored and processed in Singapore, and that the AI add-on may transfer data to the locations of the sub-processors in Annex A. We rely on appropriate safeguards required by applicable data protection law for any such transfer.
6. Personal data breach
We notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with the information the Customer reasonably needs to meet its own notification obligations. Our notice is not an acknowledgment of fault.
7. Return or deletion of data
On termination of the service, or on the Customer's written request, we delete the Customer's synced personal data from our active systems within a reasonable period, subject to any data we are required by law to retain and to routine backup cycles after which backups are overwritten. The Customer's local database remains under the Customer's sole control.
8. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms & Conditions.
9. Term and governing law
This DPA lasts for as long as we process personal data for the Customer. It is governed by the laws of India, and the courts at Bengaluru, Karnataka, India have exclusive jurisdiction, consistent with the Terms.
Annex A — Sub-processors
- Railway — hosting of the application and the managed Postgres database that holds synced data. Hosting region: Singapore.
- Cloudflare R2 — object storage for scanned images and attachments, where used.
- OpenRouter, routing to the underlying model provider (currently Google, Gemini models) — processing of images or text you submit to the AI add-on, to return structured data. Used only when the AI add-on is enabled.
Annex B — Technical and organizational security measures
- Encryption of personal data in transit (TLS).
- Per-device authentication; access to synced data scoped to the Customer's organization.
- Protection of sensitive records at rest, with an audit trail for sensitive actions.
- Access to production systems limited to authorized personnel on a need-to-know basis.
- Use of reputable managed infrastructure providers (Annex A) with their own security programs.
Annex C — Details of processing
- Subject matter and duration. Provision of the DravyaOS sync and AI features, for as long as the Customer uses them.
- Nature and purpose. Storing, syncing, restoring, and (for the AI add-on) extracting structured data from, the Customer's pharmacy records.
- Categories of data subjects. The Customer's own customers and patients, and the Customer's staff who use the app.
- Categories of personal data. Names and contact details; purchase, sales, and payment records; and, where the Customer records them, prescription and schedule-drug details.
- Special-category data. Prescription and patient details may reveal health information; the Customer decides what to record and must limit it to what it is permitted to keep.
Acceptance
By enabling sync or the AI add-on, the Customer accepts this DPA. A Customer that needs a countersigned copy for its records can request one at help@dravyaos.com.