This agreement sets out how Bitkosh processes personal data on a customer’s behalf and the obligations Bitkosh accepts when it does. It supplements the applicable service agreement rather than replacing it, and covers only processing carried out on the customer’s documented instructions.
Purpose and scope
This Data Processing Agreement (“DPA”) applies where Bitkosh Technologies Private Limited (“Processor”) processes personal data for a customer (“Controller”) in connection with an applicable service agreement. It forms part of that agreement and applies only to personal data processed on the customer’s documented instructions.
Applicable data-protection laws
This DPA is intended to meet the processor terms required by Article 28 of the EU and UK General Data Protection Regulation, the obligations of a Data Processor under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), and equivalent requirements under other applicable data-protection law. Where a particular law imposes a stricter or additional requirement on a processing activity, that requirement applies to that activity.
Under the GDPR the customer is the controller and Bitkosh is the processor. Under the DPDP Act the customer is the Data Fiduciary and Bitkosh is a Data Processor engaged under a valid contract. Bitkosh does not sell or share personal data as those terms are defined by the California Consumer Privacy Act, and processes personal data only for the limited purposes set out in this DPA and the service agreement.
Roles and instructions
The customer determines the purposes and means of processing and remains responsible for lawfulness, accuracy and collection. Bitkosh processes personal data only to provide, secure, maintain and support the service, or as otherwise documented by the customer or required by applicable law.
If Bitkosh considers that an instruction infringes applicable data-protection law, it will inform the customer and may pause the affected processing until the instruction is confirmed, amended or withdrawn. Where Bitkosh is required by law to process personal data beyond the customer’s instructions, it will inform the customer of that requirement before processing unless the law prohibits it.
Special categories and sensitive personal data
Special categories of personal data include data concerning health, genetic and biometric data, financial account data, government-issued identifiers, precise location, children’s data, and data revealing racial or ethnic origin, religious or philosophical belief, political opinion, trade-union membership, sex life or sexual orientation.
Bitkosh processes such data only where the customer has instructed it in writing, has established a lawful basis and any further condition its own law requires for that category, and the service concerned has been agreed in writing to receive it. The customer must not place special-category data into a service that has not been agreed to receive it. Where such data is in scope, the parties will record the categories, purposes, retention period and any additional safeguards in the applicable service schedule, and Bitkosh will apply access restriction, encryption and logging proportionate to the sensitivity of the data.
Health data, HIPAA and clinical records
Where the customer is a Covered Entity or a Business Associate as defined by the U.S. Health Insurance Portability and Accountability Act (“HIPAA”), and Bitkosh will create, receive, maintain or transmit Protected Health Information on the customer’s behalf, the parties will execute a separate Business Associate Agreement before that processing begins.
This DPA is not a Business Associate Agreement and does not on its own satisfy 45 CFR §164.502(e) or §164.308(b). Where a Business Associate Agreement is in place, it controls for Protected Health Information to the extent of any conflict with this DPA. No entity holds a HIPAA “certification”, because the statute provides for none; the obligations Bitkosh accepts in relation to Protected Health Information are contractual and are set out in the Business Associate Agreement.
Health and clinical data originating outside the United States, including data processed through the Bitkosh Healthcare EHR, is handled under the special-categories section above together with the applicable local law, and under any sector-specific rules the customer identifies in writing.
Confidentiality
Bitkosh will ensure that personnel authorized to process personal data are bound by confidentiality obligations and receive appropriate instructions. Access is limited to personnel with a legitimate need to perform the service, and confidentiality obligations survive the end of the engagement.
Security measures
Bitkosh maintains reasonable technical and organizational measures appropriate to the risks of processing. Depending on the service, these may include access control, authentication, encryption in transit, secure development, logging, backup and recovery, vulnerability management, incident response and personnel awareness. Where special-category data is in scope, the parties will record any additional measures in the applicable service schedule.
Subprocessors
The customer gives general written authorization for Bitkosh to engage subprocessors for infrastructure, communications, monitoring, support or other service functions. Bitkosh will impose data-protection obligations on each subprocessor that are no less protective than those in this DPA, and remains fully liable to the customer for a subprocessor’s performance of those obligations.
Bitkosh will give the customer at least 30 days’ notice before adding or replacing a subprocessor that processes the customer’s personal data. The customer may object on reasonable data-protection grounds within that period. If the parties cannot agree a resolution, the customer may terminate the affected service without penalty and receive a refund of fees prepaid for the unused term. A current subprocessor list is available through the applicable service documentation or on request.
Assistance and data-subject requests
Taking into account the nature of processing, Bitkosh will provide reasonable assistance with requests to access, correct, delete, restrict or export personal data, and with data-protection impact assessments, prior consultations and other documented assessments required by applicable law. The customer remains responsible for responding to data subjects unless otherwise agreed. Where Bitkosh receives a request directly from a data subject relating to the customer’s data, it will not respond on the merits and will refer the request to the customer.
Personal-data breaches
Bitkosh will notify the customer without undue delay, and in any event within 48 hours, after becoming aware of a personal-data breach affecting the customer’s personal data. Notice will not be withheld pending a complete investigation; Bitkosh will report what is known and supplement it as the picture develops.
The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed. This is intended to leave the customer enough time to meet its own deadlines, including the 72-hour supervisory-authority notification under the GDPR and the obligation to report a personal data breach to the Data Protection Board of India under the DPDP Act. The parties will cooperate in good faith on containment, investigation, communications and remediation.
International transfers
Where personal data is transferred across borders, the parties will use a lawful transfer mechanism and the safeguards required by applicable law, including Standard Contractual Clauses or the UK International Data Transfer Agreement where these apply. Locations, transfer mechanisms and supplementary measures should be documented in the applicable service schedule or order form. Where the DPDP Act applies, transfers are additionally subject to any restriction the Central Government notifies in respect of particular territories.
Audits, records and information
Bitkosh will make available information reasonably necessary to demonstrate compliance with this DPA and support reasonable audits or assessments subject to confidentiality, security, scope and cost controls. Audits must not unreasonably disrupt other customers or the service. Bitkosh maintains a record of the categories of processing carried out on behalf of the customer and will make it available on request.
Return and deletion
At the end of the applicable service, Bitkosh will return or delete personal data in accordance with the customer’s documented instruction and the service’s retention and backup processes, unless applicable law requires continued retention. The customer is responsible for exporting required data before the agreed transition period ends.
On written request Bitkosh will confirm in writing once deletion is complete. Personal data held in routine encrypted backups is deleted on the ordinary backup expiry cycle and remains subject to this DPA until it is.
Liability and precedence
The parties’ liability, indemnity and commercial obligations are governed by the applicable service agreement. If this DPA conflicts with another data-processing term, this DPA controls for personal-data processing unless the parties expressly agree otherwise in writing. A Business Associate Agreement, where executed, controls for Protected Health Information.
Contact legal@bitkoshtechnologies.com or use our contact page.