Version dpa-v1.2-2026-09 · Effective 26 September 2026
This Data Processing Agreement ("DPA") forms part of the CollegioDx Platform Terms of Service between Trustqed Social Private Limited ("CollegioDx") and the Organisation. It applies to all Patient Data that CollegioDx processes on the Organisation's behalf.
1.1 For Patient Data, the Organisation is the Data Fiduciary and CollegioDx is the Data Processor within the meaning of the Digital Personal Data Protection Act, 2023 ("DPDP Act").
1.2 For Account Data of Authorised Users, CollegioDx is itself a Data Fiduciary, and its processing is described in the CollegioDx Privacy Policy.
1.3 Where the Organisation uses ABDM features, the Organisation is the Health Information Provider and, where applicable, Health Information User, registered in the Health Facility Registry, and CollegioDx operates the technical integration on its behalf.
2.1 CollegioDx shall process Patient Data only for the purpose of providing the Service and only in accordance with the Organisation's documented instructions. The functions of the Service as documented and configured by the Organisation constitute those instructions.
2.2 CollegioDx shall not process Patient Data for any other purpose, except as permitted by clause 9 or required by law, in which case CollegioDx will inform the Organisation unless the law prohibits it.
CollegioDx shall implement and maintain appropriate technical and organisational measures to protect Patient Data, including:
(a) storage and processing in Microsoft Azure data centres located in India (Central India and South India regions), with encryption in transit and at rest; traffic in transit passes through Microsoft's global edge network (Azure Front Door) for firewalling and delivery; (b) private network endpoints and denial of public network access to data stores; (c) application access through managed identities, with no shared secrets in application code; (d) storage partitioned by organisation so that one Organisation's data is never returned to another; (e) role-based access control with least privilege, and an append-only audit log of access to Patient Data; (f) a web application firewall and rate limiting at the network edge; (g) regular backups; and (h) periodic security testing.
4.1 The Organisation authorises CollegioDx to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure (Microsoft Corporation and affiliates) | Compute, database, storage, key management, monitoring, edge firewall, and Azure OpenAI language models | Data at rest and compute in India (Central India; AI models in South India); edge network global |
| Sarvam AI | Speech-to-text for voice dictation | India |
| Gupshup, and Meta Platforms (WhatsApp Business Platform) | WhatsApp message delivery to patients who have given a WhatsApp number | India (Gupshup); global (Meta) |
| Fast2SMS | SMS delivery (message templates are registered with a DLT registrar, which holds no message content) | India |
| National Health Authority (ABDM gateway) | Health-information exchange under ABDM, where enabled | India |
| Google LLC (Firebase Authentication) | Patient-portal sign-in | Global |
4.2 Artificial-intelligence sub-processors are engaged on terms under which they do not retain Patient Data beyond the request and do not use it to train models.
4.3 CollegioDx will give at least thirty (30) days' notice in the Service before adding a sub-processor that processes Patient Data. The Organisation may object on reasonable data-protection grounds, in which case the parties will discuss in good faith and the Organisation may terminate if no resolution is reached.
CollegioDx shall ensure that persons authorised to process Patient Data are bound by confidentiality obligations and receive appropriate training, and shall limit access to those who need it to provide or support the Service.
CollegioDx shall, taking into account the nature of the processing, assist the Organisation:
(a) in responding to requests from patients to access, correct, update or erase their personal data, or to nominate a person, and in handling grievances; (b) in meeting its obligations under the ABDM Health Data Management Policy, including consent-based sharing, care-context linking and erasure on expiry of consent; and (c) with information reasonably required for a data protection impact assessment.
7.1 CollegioDx shall notify the Organisation without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Patient Data, and shall provide the information the Organisation needs to meet its own notification obligations to the Data Protection Board of India and to affected patients under the DPDP Act and the rules made under it.
7.2 CollegioDx shall take reasonable steps to contain and remediate the breach and shall keep the Organisation informed.
8.1 CollegioDx retains Patient Data for as long as the Organisation uses the Service.
8.2 On termination, the Organisation may export its Patient Data for thirty (30) days as set out in the Terms. Within ninety (90) days after that period CollegioDx will delete Patient Data, except where a law requires retention, including the medical-record retention rules applicable to registered medical practitioners and ABDM obligations, in which case the data is retained only for that purpose and for that period. CollegioDx may retain a record that data existed and was deleted, containing no clinical content.
8.3 Where a patient withdraws consent or requests erasure and the Organisation instructs CollegioDx to erase, CollegioDx will erase the data unless retention is required by law, and will record the erasure.
9.1 The Organisation authorises CollegioDx to derive de-identified, aggregated datasets from Patient Data and from the Organisation's use of the Service, and to use and commercially license such datasets to healthcare industry participants (such as pharmaceutical, medical-device and diagnostics companies), research and public-health bodies, and other organisations working in healthcare, for product improvement, quality assurance and evaluation, benchmarking, market and epidemiological insight, public-health reporting, and to support sponsored content. This authorisation is part of what the Organisation gives in return for the Service being free of charge, and it continues for as long as the Organisation uses the Service.
9.2 CollegioDx commits that:
(a) no dataset released to any third party will identify, or be reasonably capable of being re-linked to, any patient, healthcare professional or Organisation; (b) every released statistic will be drawn from not fewer than ten (10) organisations and fifty (50) patients, and any cell that falls below these thresholds will be suppressed; (c) no output relating to a single Organisation or a single healthcare professional will be released to a third party without that Organisation's or professional's separate written consent; (d) health information received from other providers through ABDM consent artefacts is excluded from every such dataset and is used only for the purpose for which the patient gave consent; (e) CollegioDx will not attempt to re-identify any person from a de-identified dataset and will contractually prohibit every licensee from doing so; and (f) CollegioDx will not use Patient Data to train or fine-tune machine-learning models.
9.3 The Organisation shall include in its patient notice a statement that de-identified statistics may be derived from patient records.
Health information that the Organisation receives from other health information providers through ABDM is processed by CollegioDx solely to display it to the Organisation's Authorised Users for the consented purpose and period, is erased when the consent expires or is revoked, and is never included in any aggregate, licensed dataset, sponsored content or other commercial use.
11.1 CollegioDx will make available in the Service the Organisation's access-audit log and the record of acceptances of these Terms and this DPA.
11.2 On reasonable written request, not more than once a year unless required by a regulator or following a breach, CollegioDx will provide information reasonably necessary to demonstrate compliance with this DPA.
The limits and exclusions of liability in the Terms apply to this DPA.
This DPA remains in force for as long as CollegioDx processes Patient Data on the Organisation's behalf, including any retention period under clause 8.