Data Processing Agreement

v1.1First published: 15 October 2025Last updated: 1 September 2026Effective: 1 October 2026

This Data Processing Agreement (DPA) establishes the terms under which Narra Technologies Private Limited ("Narra", "Data Processor") processes personal data on behalf of a data controller ("Client"). This DPA is drafted to meet the EU and UK GDPR and applicable local data protection law, including India's DPDP Act 2023.

Parties & Roles

Data Controller (Client)

Determines the purposes and means of data processing.

  • Determine what data to process and why
  • Collect data with proper consent
  • Ensure legal basis for processing
  • Respond to data subject requests
  • Report breaches to authorities

Data Processor (Narra)

Processes data on behalf of the Controller.

  • Process only on the Controller's documented instructions
  • Implement security safeguards
  • Maintain audit trails
  • Notify the Controller of breaches
  • Assist with data subject requests
  • Comply with data protection laws

Narra IS NOT

  • A joint controller
  • An independent data handler
  • A data owner
  • A data broker

Narra IS

  • A data custodian
  • A service provider
  • Your data processor
  • Your compliance partner

Where Narra is a Controller instead

For a limited set of activities Narra determines its own purposes and is a Controller, not a Processor: its own website analytics, its billing and tax records, its account security and fraud prevention, and its direct marketing to your administrators. Those activities are governed by our Privacy Policy, not by this DPA. This division is stated here so it does not conflict with the Privacy Policy, which describes Narra as a Controller for those purposes.

Unlawful instructions

If Narra considers that an instruction from the Controller infringes applicable data protection law, Narra will inform the Controller without undue delay and may suspend that instruction until it is confirmed or withdrawn.

Subject Matter & Duration

Processing Services Provided

  • Data Storage and Management: secure storage, version control, backup
  • Data Access and Sharing: authentication, granular access controls, logging
  • Data Portability: export in PDF, CSV, JSON, HL7, FHIR
  • Compliance and Audit: audit trails, access logging
  • Security and Protection: encryption, intrusion detection

Nature and purpose of processing

Hosting, storage, transmission, and retrieval of personal data so that the Controller can operate the service it has subscribed to. Narra does not determine the purpose of the processing and does not process the data for any purpose of its own beyond those listed in "Where Narra is a Controller instead" above.

Categories of data subject

Patients and their authorised representatives; the Controller's staff and administrators; in a commerce deployment, the Controller's customers and suppliers.

Duration

This DPA takes effect on execution and continues for the term of the service agreement, and thereafter for as long as Narra processes personal data on the Controller's behalf.

After termination: data is retained for 30 days so the Controller can export it, and is then deleted. The Controller may request earlier deletion at any time within that window. A certificate of deletion is provided. Backups containing the data are overwritten on their normal cycle and in any event within 30 days of primary deletion. This 30-day period is the same in the Terms of Service, the Privacy Policy, and the Business Associate Agreement.

Authorised Processing Activities

The Controller Authorises Narra To

  • Store personal data on encrypted servers
  • Create backup copies for disaster recovery
  • Authenticate users (password verification, MFA)
  • Authorise access per the Controller's instructions
  • Allow data subjects to correct and update data
  • Maintain version history
  • Log all data access (who, what, when)
  • Maintain audit trails for 5 years, or the longer period required by applicable law
  • Monitor for unauthorised activity
  • Export data in standard formats
  • Maintain processing documentation
  • Cooperate with regulatory inspections

Prohibited Processing

  • Process data for Narra's own purposes, beyond those declared in Parties & Roles
  • Use for marketing or advertising
  • Sell or share data with third parties
  • Combine with other customers' data
  • Train, fine-tune, or evaluate machine-learning models on identifiable personal data without the Controller's separate, explicit, written consent
  • Make automated decisions affecting individuals
  • Retain longer than necessary
  • Disclose without authorisation

Confidentiality of personnel

Every Narra employee and contractor with access to personal data is bound by a written confidentiality obligation that survives the end of their engagement, has passed a background check, and receives annual data protection training.

Data Categories Processed

Demographic data
Name, email, phone, address, date of birth, gender, nationality
Health data, if applicable
Medical history, diagnoses, medications, test results, clinical notes, allergies, vaccination records
Commercial data, if applicable
Orders, invoices, catalogue and pricing records, delivery addresses, supplier and customer contact records
Authentication data
Usernames, password hashes, MFA tokens, session tokens, device identifiers
Activity data
Login and logout timestamps, access logs, modification history, API calls
Metadata
Timestamps, anonymised IP addresses, device types

Special category and sensitive personal data

Enhanced security applies to health, financial, biometric, and genetic data, which are special category data under GDPR Article 9 and sensitive personal data under India's DPDP Act 2023. Additional measures include:

  • Enhanced encryption
  • Stricter access controls
  • Limited retention
  • Explicit consent verification

Data Subject Rights

Right to Access
Data subjects can access all personal data and obtain copies in portable format within 30 days.
Right to Correction
Correct inaccurate data; maintain version history; respond within 30 days.
Right to Erasure
Request deletion; primary data deleted within 30 days; backups deleted within 30 days of primary deletion.
Right to Data Portability
Receive data in portable format (PDF, CSV, JSON, HL7, FHIR).
Right to Restrict
Limit how data is processed; restrict sharing for specific purposes.
Right to Object
Object to marketing uses, profiling, or automated decisions.

How Narra Assists

Narra assists the Controller by:

  • Receiving Data Subject Access Requests (DSARs) and forwarding them to the Controller without undue delay
  • Not responding to a data subject directly unless the Controller instructs it to
  • Compiling requested data using the platform's export tooling
  • Responding within 30 days in total

Assistance with Articles 32 to 36

Taking into account the nature of the processing and the information available to it, Narra assists the Controller in ensuring compliance with its obligations on security of processing, breach notification to authorities and to data subjects, data protection impact assessments, and prior consultation with a supervisory authority.

Security & Confidentiality

Technical Security

  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • MFA and RBAC
  • 24/7 intrusion detection
  • Weekly vulnerability scanning
  • Quarterly penetration testing
  • Encrypted backups with tested recovery
  • Pseudonymisation where the processing purpose allows it

Physical Security

  • Biometric access and 24/7 security at Google Cloud data centres
  • Fire suppression and environmental controls
  • Encrypted storage media

Administrative Security

  • Background checks and confidentiality agreements
  • Least privilege access controls
  • Documented incident response procedures
  • Audit logging retained 5 years, or the longer period required by applicable law
  • Disaster recovery plan with regular drills

Security Controls Schedule

Control Frequency Verification
Access Logging Continuous Daily review
Vulnerability Scanning Weekly Report generation
Penetration Testing Quarterly Report and remediation
Backup Testing Monthly Restoration time logged
Disaster Recovery Quarterly Drill report

Audit Rights

This section gives effect to GDPR Article 28(3)(h).

Information on request

Narra makes available to the Controller all information necessary to demonstrate compliance with the obligations in this DPA. That includes the current sub-processor list, the security controls schedule above, our penetration test summaries, and our transfer impact assessment. These are provided under NDA on written request, within 30 days.

Reports

Where Narra holds a current third-party audit report covering the services (for example a SOC 2 Type II report or an ISO/IEC 27001 certificate), it will provide that report to satisfy an audit request. Narra does not hold such a report today. Our current certification status is stated in the Data Security Statement, and until a report exists the audit routes below apply instead.

Controller audits

The Controller, or an independent auditor it mandates who is not a competitor of Narra, may audit Narra's processing of the Controller's personal data. Conditions:

  • Not more than once in any 12-month period, except after a personal data breach affecting the Controller's data or where a supervisory authority requires it, in which case there is no frequency limit
  • On at least 30 days written notice
  • During business hours, without unreasonable disruption to Narra's operations
  • Subject to confidentiality obligations, and without access to another customer's data
  • Each party bears its own costs for the first audit in any 12-month period. Narra may charge its reasonable costs for additional audits it is not otherwise required to bear.

Sub-processor audits

Narra's contracts with its sub-processors give Narra audit and information rights equivalent to those above. On the Controller's written request, Narra will exercise those rights on the Controller's behalf and share the outcome, or, where the sub-processor permits it, arrange for the Controller to audit directly.

Security questionnaires

Narra will complete a reasonable number of the Controller's security questionnaires each year, and will respond to a standard industry questionnaire within 30 days of request.

Sub-processors

General authorisation

The Controller gives Narra a general written authorisation to engage sub-processors, subject to the notice and objection rights below. Narra remains fully liable to the Controller for the performance of each sub-processor's obligations.

Approval Process

  1. Assessment: evaluate security and compliance
  2. Documentation: collect certifications and audit reports
  3. Written contract: the sub-processor must sign a data processing agreement imposing the same data protection obligations as this DPA
  4. Notice: notify the Controller, as described below
  5. Objection period: 30 days
  6. Implementation
  7. Monitoring: ongoing compliance

Current Sub-processors

This list is current as at the "Last updated" date at the top of this page. It reflects the services actually in production. Every entry processes data in, or is contractually restricted to, the residency region described in the International Data Transfers section.

Vendor Purpose Processing region Certification
Google Cloud Platform (Google Cloud EMEA Ltd / Google LLC) Application hosting, compute, storage, key management, logging asia-south1 (Mumbai, India) ISO/IEC 27001, ISO/IEC 27018, SOC 2 Type II
Firebase (Google) Authentication, static web hosting, push and email delivery for sign-in Global control plane; identity records in the Google Cloud region for the project ISO/IEC 27001, SOC 2 Type II
MongoDB Atlas (MongoDB, Inc.) Managed application database Google Cloud asia-south1 (Mumbai, India) ISO/IEC 27001, SOC 2 Type II
Razorpay Payment processing (India) India PCI DSS, ISO/IEC 27001
Stripe Payment processing (international) United States and EU, under Stripe's own transfer safeguards PCI DSS, SOC 2 Type II

Payment processors act as independent controllers for the payment data they collect, under their own terms. Narra does not store full card numbers.

Not used: Narra does not currently use Amazon Web Services, and does not run a third-party website analytics or error-tracking service that processes customer personal data. Earlier versions of this document listed vendors that are not in production. They have been removed.

Change notice

  • Narra gives the Controller at least 30 days written notice before adding or replacing a sub-processor, or changing the purpose or processing region of an existing one.
  • Notice is given by email to the Controller's nominated data protection contact, and by updating this page. Controllers may subscribe to change notifications by emailing dpo@narrahealthcare.com with the subject "Subscribe: sub-processor changes".
  • The Controller may object on reasonable data protection grounds within those 30 days. The parties will work in good faith to find an alternative, for example a different region or a configuration that excludes the sub-processor.
  • If no resolution is reached within 30 days of the objection, the Controller may terminate the affected services without penalty, with a pro-rata refund of prepaid fees for the unused term.
  • Where an urgent change is required to preserve security or continuity of the service, Narra may make it immediately and will give notice as soon as possible, together with the objection and termination rights above.

Sub-processor Requirements

  • ISO/IEC 27001 or an equivalent independently assessed control framework
  • Annual security audits
  • Breach reports to Narra within 24 hours
  • Data residency compliance
  • Security controls at least equivalent to those in this DPA
  • Audit and information rights that Narra can exercise on the Controller's behalf

International Data Transfers

Data Residency

Personal data is stored and processed in Google Cloud asia-south1 (Mumbai, India), which is the primary hosting region for all customers today. Backups are replicated within India.

Additional residency regions, including the EU, the UK, and the United States, are on the roadmap and are not available today. Narra does not currently offer a contractual residency commitment outside India. Where regional residency is required, it must be agreed and recorded in an Order Form before the subscription starts; nothing in this DPA implies it is available.

Narra will not move personal data outside the agreed residency region without a lawful transfer mechanism and the Controller's prior approval, other than the transfers to payment processors listed in the sub-processor table, which the Controller authorises by entering into this DPA.

Transfer Mechanisms

EU and EEA transfers
The Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, incorporated into this DPA by reference. Module Two (controller to processor) applies between the Controller and Narra. Module Three (processor to processor) applies to onward transfers to sub-processors. The optional docking clause applies. For Clause 17, the governing law is the law of Ireland; for Clause 18, the forum is the courts of Ireland.
UK transfers
The International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
Swiss transfers
The EU SCCs as amended by the addendum published by the Swiss Federal Data Protection and Information Commissioner, with references to the GDPR read as references to the Swiss FADP.
Adequacy
India has not received an adequacy decision from the European Commission or the UK government. Narra does not rely on adequacy for any transfer into India.
Transfer impact assessment
Narra maintains a transfer impact assessment covering Indian law on government access to data, and the supplementary technical and organisational measures applied. It is provided under NDA on request.
Other jurisdictions
A lawful basis is required (court order, regulatory requirement, or explicit consent), with notification to the Controller.

Government access requests

If Narra receives a legally binding request from a public authority for personal data it processes for the Controller, it will notify the Controller unless legally prohibited, challenge the request where there are reasonable grounds to consider it unlawful, and disclose only the minimum permissible. Narra publishes the number of such requests received on request from the Controller.

Narra will NOT transfer data to:

  • A jurisdiction with no applicable data protection framework, absent a valid transfer mechanism
  • A party subject to a restriction under applicable data protection law
  • Any party without adequate safeguards

Breach Notification

Definition

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This definition is used consistently across the Terms of Service, Privacy Policy, this DPA, and the Business Associate Agreement.

Response Timeline

  • Detection, isolation, containment: without undue delay, and in any event within 1 hour of detection
  • Investigation: scope, impact, and root cause established within 24 hours
  • Notification: as set out below

Notification Schedule

Controller notification
Without undue delay after Narra becomes aware of the breach, and in any event within 24 hours. For a breach assessed as critical, within 1 hour. This is the GDPR Article 33(2) obligation.
Supervisory authority
The Controller notifies its supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (GDPR Article 33(1)). Narra provides the information the Controller needs to do so.
Data subject notification
Where the breach is likely to result in a high risk to data subjects, the Controller notifies them without undue delay (GDPR Article 34), and in any event within 72 hours where India's DPDP Act applies. Narra supports this notification.
Where HIPAA applies
Narra notifies the covered entity so that individual notice can be given without unreasonable delay and no later than 60 calendar days from discovery, with notice to the US Department of Health and Human Services, and to prominent media where 500 or more residents of a state or jurisdiction are affected. See the Business Associate Agreement.

Content of the notification

Each notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the contact point for more information. Where the full detail is not available at once, Narra provides it in phases without further undue delay.

Breach Support

Narra provides notification templates, media response assistance, and regulatory communication support, and maintains a record of every breach and the remedial action taken.

Term & Termination

Effective upon execution; continues for the term of the service agreement.

Termination by the Controller

  • Convenience (any reason)
  • Material breach uncured within 30 days
  • Regulatory requirement
  • An unresolved sub-processor objection, as set out in the Sub-processors section
  • A Force Majeure event continuing for more than 30 consecutive days

Termination by Narra

  • Material breach uncured within 30 days
  • Non-payment
  • A Force Majeure event continuing for more than 30 consecutive days

Force Majeure is defined in the Terms of Service and applies equally to both parties, with the same notice and mitigation duties.

Effect of Termination

No new data is accepted; existing data is retained for 30 days so the Controller can export it; processing during that window is limited to export and deletion; confidentiality obligations continue indefinitely.

Data Deletion

At the Controller's election, Narra returns or deletes all personal data at the end of the retention window. Deletion uses overwrite, crypto-erase, or physical destruction for decommissioned media. A certificate of deletion is provided. Audit logs are retained for 5 years, or the longer period required by applicable law, and this is the same figure used throughout the corpus.

Liability, Disputes & Contact

Liability Cap

Narra's total aggregate liability under this DPA is subject to, and forms part of, the single liability cap stated in the Terms of Service. This DPA does not create a separate cap and does not raise the cap in the Terms. There is no minimum liability floor.

Basis
The lesser of the fees paid to Narra in the 12 months preceding the claim, or ₹100,000 or its equivalent in your billing currency, as stated in the Terms of Service.
A different cap
Applies only where expressly stated in an Order Form or signed master agreement, which takes precedence over both this DPA and the Terms.
Exceptions
Gross negligence, wilful misconduct, fraud, death or personal injury caused by negligence, and any liability that cannot be limited by law.

Nothing in this section limits a data subject's rights against either party under GDPR Article 82, or either party's liability to a supervisory authority.

Excluded Damages

  • Lost profits
  • Indirect or consequential damages
  • Regulatory fines imposed for the Controller's own violations

Indemnification

Narra indemnifies the Controller for: data breaches caused by Narra, unauthorised disclosure by Narra, and failure by Narra to implement the security measures in this DPA.

The Controller indemnifies Narra for: claims arising from unauthorised data uploads, intellectual property infringement in Controller data, and regulatory violations by the Controller.

Dispute Resolution

  • Negotiation: 15 days
  • Executive review: 30 days
  • Mediation: 30 days
  • Arbitration: seat at Hyderabad, Telangana, India

Governing law: India. Jurisdiction: the exclusive jurisdiction of the courts in Hyderabad, Telangana, India. These are the same governing law and venue as the Terms of Service, which govern the whole relationship unless an Order Form states otherwise.

Contact

Entity
Narra Technologies Private Limited, Hyderabad, Telangana, India
DPA questions and contract notices
legal@narrahealthcare.com
Data protection and the Data Protection Officer
dpo@narrahealthcare.com
Security concerns and breach reports
security@narrahealthcare.com
EU / UK representative
Appointment under GDPR Article 27 is in progress. Until it is complete, contact the Data Protection Officer above.