Data processing addendum

How we handle patient data on your behalf, in the language your own compliance review will ask for. It applies to every account automatically — there is nothing to sign.

Last updated: 3 August 2026

1. Parties and precedence

This addendum is between you — the registered practitioner or clinic using HomeoRep (the Data Fiduciary) — and [your registered legal name] (the Data Processor). It forms part of the Terms of Service and, on any question about the processing of personal data, takes precedence over them.

It applies automatically to every account. You do not need to request or sign it.

2. Roles

  • You are the Data Fiduciary for patient data. You decide what is recorded, you hold the clinical relationship, and the duties owed to the patient under the Digital Personal Data Protection Act, 2023 are yours.
  • We are the Data Processor. We process patient data only to provide HomeoRep to you, and only on your instructions — your use of the product being those instructions.
  • For your own account data (name, email, registration number, billing details) we are the Data Fiduciary, and the privacy policy governs.

3. Scope of processing

Subject matter: provision of repertorization and practice-management software.
Duration: for as long as your account is open, plus the deletion window in §8.
Nature and purpose: storing, organising, retrieving, displaying and printing the records you create; and no other purpose.
Categories of data subject: your patients, and your reception staff if you create logins for them.
Categories of personal data: patient demographics and contact details, case histories, symptoms, investigations and attached reports, prescriptions, appointments and fees — which include health data, and are treated accordingly.

4. What we undertake

  • Process only on your instructions, and not for any purpose of our own. We do not sell patient data, share it for advertising, or use it to train models — not in aggregate and not anonymised.
  • Confidentiality: anyone with access is bound by a duty of confidence, and access is limited to those who need it to operate or support the service.
  • Security: the measures described on the security page — database-level tenant isolation, encrypted transport, hashed credentials, and logged access.
  • Assistance with rights requests: if a patient exercises a right against you, we will help you locate, correct, export or erase their record within a reasonable time. Because you are the Fiduciary, we act through you and do not respond to your patients directly.
  • Assistance with security obligations: including breach notification (§6) and reasonable support for any impact assessment you carry out.

5. Where processing happens

Patient records are stored and processed in Mumbai, India. Keeping clinical data in India is a deliberate choice, not an accident of hosting.

That includes the backups. A backup is a complete copy of the record set, so the nightly off-server copies are held in the same country as the primary server rather than wherever storage happened to be cheapest.

Two of our sub-processors operate outside India — the transactional email provider and, if you switch the AI assists on, the model provider. Neither receives patient records: email carries only your own account details, and the AI assist sends only the symptom text of the case open at that moment, never patient names or identifiers. The current position for each is on the sub-processor page.

6. Personal data breach

If we become aware of a breach affecting your data we will notify you without undue delay, with what we know: what happened, which categories of data and roughly how many records are involved, the likely consequences, and what we are doing about it. We will keep updating you as we learn more rather than waiting for a complete picture.

We will also make the notification the DPDP Rules require of us to the Data Protection Board, and support any notification you must make.

7. Sub-processors

You give general authorisation for us to engage sub-processors, on the terms here. The current list — what each does, what data reaches them, and where they operate — is published at homeorep.com/legal/subprocessors.

We will give you at least 30days' notice by email before a new sub-processor begins processing your data. If you object on reasonable data-protection grounds, tell us and we will either not proceed, offer an alternative, or let you terminate and receive a pro-rata refund. Each sub-processor is bound to obligations no weaker than these, and we remain responsible to you for what they do.

8. Return and deletion

You can export your data at any time while the account is open. On closure we delete patient records within 90 days, except where we must retain something to meet a legal obligation or to defend a legal claim.

Two deliberate exceptions: access-log entries are retained even after the record they describe is deleted — an audit trail that could be erased would not be an audit trail — and they record only that a record was accessed, never its clinical content.

Non-payment never triggers deletion. A lapsed subscription downgrades the account and limits what you can add; it does not remove your ability to read, print or export anything you already have.

9. Information and audit

On reasonable written request, and no more than once a year unless a breach or a regulator requires otherwise, we will provide the information needed to demonstrate compliance with this addendum. We are a small operation: we will answer a security questionnaire and describe our controls honestly, including what we have not done — we have not completed an independent audit, and the security page says so.

10. Liability and law

The liability limits in the Terms of Service apply to this addendum. It is governed by the laws of India, with the courts at [city] having exclusive jurisdiction.

Questions, or a countersigned copy for your records: support@sabkacare.com.