Data Processing Agreement

Last updated: June 9, 2026

This Data Processing Agreement ("DPA") governs how AesthOS Clinic Suite ("Processor", "we") processes Personal Data on behalf of subscribing clinics ("Controller", "you") under the Digital Personal Data Protection Act, 2023 of India ("DPDP Act") and applicable data protection law.

1. Roles

The clinic is the Data Fiduciary (controller) of patient, staff, and operational data captured in the platform. AesthOS is the Data Processor acting on the clinic's documented instructions through the use of the software.

2. Categories of data processed

3. Purpose & limitation

AesthOS processes Personal Data only to deliver the contracted service: appointment scheduling, billing, EMR, marketing automation, accounting, and reporting requested by the Controller. We do not use clinic or patient data for advertising, resale, or model training.

4. Security measures

5. Sub-processors

We use vetted infrastructure sub-processors (managed database, edge compute, email delivery, WhatsApp Business API gateway, payments). A current list is available on request. We notify Controllers of material changes.

6. Data Principal rights

The Controller is responsible for responding to Data Principal (patient/staff) requests for access, correction, erasure, and grievance redressal. AesthOS provides export and deletion tooling in the admin area to assist.

7. Data location & transfers

Primary storage is in India / Asia-Pacific regions. Cross-border processing, where required for service delivery, is restricted to jurisdictions permitted by Indian law and the DPDP Act notifications.

8. Breach notification

We notify the Controller without undue delay (and in any case within 72 hours of confirmation) of any Personal Data Breach affecting clinic data, with sufficient information for the Controller to meet its own obligations to the Data Protection Board.

9. Return & deletion

On termination, the Controller may export all clinic data through the admin area. AesthOS deletes Personal Data from active systems within 30 days and from backups within 90 days, except where retention is required by law.

10. Audit & cooperation

AesthOS makes available the information necessary to demonstrate compliance with this DPA and reasonably cooperates with audits requested by the Controller, subject to confidentiality and proportionality.

11. Contact

For DPA, security, or DPDP-related questions, contact customercare@dtaniqueahmedabad.com.

See also: Privacy Policy · Terms of Service