Data Processing Agreement
Last updated: 1 July 2025
1. Definitions
"Controller" means the healthcare provider using Relaya's services. "Processor" means Relaya Health Technologies Pvt. Ltd. "Personal Data" includes patient health information, practitioner details, and any data processed through the platform. "Processing" means any operation performed on Personal Data including collection, storage, transcription, and deletion.
2. Scope of Processing
Relaya processes Personal Data solely to provide clinical documentation services as instructed by the Controller. This includes audio transcription, AI-generated note structuring, template application, and data storage. Processing occurs exclusively on infrastructure located within India.
3. Controller Obligations
The Controller shall ensure lawful basis for processing, obtain necessary patient consents, provide accurate instructions to the Processor, and notify the Processor of any data subject requests. The Controller remains responsible for the accuracy and completeness of all clinical documentation.
4. Processor Obligations
Relaya shall process data only on documented instructions from the Controller, ensure personnel are bound by confidentiality, implement appropriate technical and organisational security measures, assist the Controller with data subject requests, delete or return all data upon termination, and make available information necessary to demonstrate compliance.
5. Security Measures
Relaya implements the following technical and organisational measures:
- AES-256 encryption at rest, TLS 1.3 in transit
- Role-based access controls with audit logging
- Automated vulnerability scanning and annual penetration testing
- SOC 2 Type II certification
- 24/7 security monitoring
- Infrastructure hosted in AWS Mumbai (ap-south-1) with geographic redundancy within India
6. Sub-Processors
Relaya uses the following sub-processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Infrastructure and hosting | India (Mumbai) |
| Razorpay | Payment processing | India |
We will notify the Controller at least 30 days before engaging any new sub-processor. The Controller may object to new sub-processors within 14 days of notification.
7. Data Breach Notification
Relaya shall notify the Controller of any Personal Data breach within 72 hours of becoming aware of it. Notification shall include the nature of the breach, categories of data affected, approximate number of records, likely consequences, and measures taken to mitigate the breach.
8. Data Transfers
No Personal Data shall be transferred outside India without the Controller's explicit written consent. In the event such transfer becomes necessary, Relaya shall ensure compliance with the Digital Personal Data Protection Act, 2023 and any applicable cross-border transfer mechanisms.
9. Term and Termination
This DPA remains in effect for the duration of the service agreement. Upon termination, Relaya shall delete all Personal Data within 60 days unless retention is required by law. The Controller may request data export in standard formats (JSON, PDF) prior to deletion.
For a signed copy of this DPA, contact legal@relaya.one