Legal
Data Processing Agreement
A summary of what our data processing agreement covers, published so a compliance team can assess us before there is a contract to read.
This is a plain-language summary provided for transparency. The binding document is finalized and reviewed by legal counsel before general availability. It is not legal advice.
Who is who
Your hospital is the controller of its patients' health data. Takoriya Technology LLP is a processor: we hold and process that data on your instructions so that you can run your hospital on the platform.
That distinction decides most of the rest. You decide what is collected and why; we decide nothing about your patients, and we do not use their data for any purpose of our own.
What we will and will not do with your data
We process it to provide the service, to keep it secure, to support you when you ask, and to meet a legal obligation where one applies. Nothing else.
We do not sell it, share it, mine it, or use it to train anything. We do not send patient, staff or hospital-identifying data to an analytics or advertising vendor. There is no analytics vendor on the Portal at all.
Sub-processors
We use a small number of providers to run the platform: hosting and the managed database, transactional email and SMS, and object storage for documents. Where a hospital enables online payments, the payment gateway is the hospital’s own merchant account and we are not in the funds flow.
The current list, with what each one handles, is published on our security page. The binding list forms part of the agreement, and we tell you before it changes. A sub-processor you learn about afterwards is not one you agreed to.
Where the data lives
In India. The database runs in an India region; object storage is set to an India jurisdiction per environment at deployment. Development, staging and production are separate, with their own databases and their own storage, and a credential from one cannot be used in another.
Security measures
Tenant isolation enforced by the database rather than by application code, role-based access with per-user overrides, an append-only audit trail, encryption in transit and at rest, and least-privilege access for our own staff.
These are described in more detail, with what is enforced today separated from what is a deployment commitment, on our security page.
Breach notification
If we become aware of a personal data breach affecting your data, we notify you without undue delay, with what we know, what we are doing, and what we recommend you do. Your own notification obligations to patients and to the authority remain yours as controller, and we support them.
Patient rights
Requests from patients come to you, not to us, because you are the controller. We assist you in responding: retrieving what is held, correcting it and, subject to the statutory retention that applies to clinical records, deleting it.
A self-service rights workflow inside the product is scheduled rather than built. Today these are handled as a process, with our support, and we would rather say that than imply a screen exists.
When the contract ends
You take your data. We do not charge an exit fee, in any form, at any time. Report export to CSV works today and broader export is scheduled scope. Whichever exists when you leave, it is not billed.
After an agreed period, and once you confirm you have what you need, we delete our copy other than what a legal obligation requires us to retain.
Status of this page
This is a summary so that your compliance team can assess us before a contract exists. The binding data processing agreement is issued with your contract and is reviewed by counsel before general availability.
If your team needs the full document during evaluation, ask and we will send the current draft with its status clearly marked.