This Data Processing Agreement (DPA) establishes the terms under which Narra Technologies Private Limited ("Narra", "Data Processor") processes personal data on behalf of a data controller ("Client"). This DPA is drafted to meet the EU and UK GDPR and applicable local data protection law, including India's DPDP Act 2023.
This DPA governs how Narra Technologies Private Limited ("Narra", the "Data Processor") processes personal data on behalf of a controller ("Client", the "Controller").
This DPA applies to both. In a healthcare deployment it operates alongside the Business Associate Agreement, which governs Protected Health Information specifically. In a commerce deployment no PHI is processed, the BAA is not required, and the health-data provisions of this DPA have no subject matter.
This DPA is part of the agreement described in the Order of Precedence section of the Terms of Service. Where this DPA and the Terms conflict, the Terms govern, except that where this DPA imposes a stricter obligation on Narra it is the stricter obligation that applies. An Order Form or signed master agreement overrides both.
Determines the purposes and means of data processing.
Processes data on behalf of the Controller.
For a limited set of activities Narra determines its own purposes and is a Controller, not a Processor: its own website analytics, its billing and tax records, its account security and fraud prevention, and its direct marketing to your administrators. Those activities are governed by our Privacy Policy, not by this DPA. This division is stated here so it does not conflict with the Privacy Policy, which describes Narra as a Controller for those purposes.
If Narra considers that an instruction from the Controller infringes applicable data protection law, Narra will inform the Controller without undue delay and may suspend that instruction until it is confirmed or withdrawn.
Hosting, storage, transmission, and retrieval of personal data so that the Controller can operate the service it has subscribed to. Narra does not determine the purpose of the processing and does not process the data for any purpose of its own beyond those listed in "Where Narra is a Controller instead" above.
Patients and their authorised representatives; the Controller's staff and administrators; in a commerce deployment, the Controller's customers and suppliers.
This DPA takes effect on execution and continues for the term of the service agreement, and thereafter for as long as Narra processes personal data on the Controller's behalf.
After termination: data is retained for 30 days so the Controller can export it, and is then deleted. The Controller may request earlier deletion at any time within that window. A certificate of deletion is provided. Backups containing the data are overwritten on their normal cycle and in any event within 30 days of primary deletion. This 30-day period is the same in the Terms of Service, the Privacy Policy, and the Business Associate Agreement.
Every Narra employee and contractor with access to personal data is bound by a written confidentiality obligation that survives the end of their engagement, has passed a background check, and receives annual data protection training.
Enhanced security applies to health, financial, biometric, and genetic data, which are special category data under GDPR Article 9 and sensitive personal data under India's DPDP Act 2023. Additional measures include:
Narra assists the Controller by:
Taking into account the nature of the processing and the information available to it, Narra assists the Controller in ensuring compliance with its obligations on security of processing, breach notification to authorities and to data subjects, data protection impact assessments, and prior consultation with a supervisory authority.
| Control | Frequency | Verification |
|---|---|---|
| Access Logging | Continuous | Daily review |
| Vulnerability Scanning | Weekly | Report generation |
| Penetration Testing | Quarterly | Report and remediation |
| Backup Testing | Monthly | Restoration time logged |
| Disaster Recovery | Quarterly | Drill report |
This section gives effect to GDPR Article 28(3)(h).
Narra makes available to the Controller all information necessary to demonstrate compliance with the obligations in this DPA. That includes the current sub-processor list, the security controls schedule above, our penetration test summaries, and our transfer impact assessment. These are provided under NDA on written request, within 30 days.
Where Narra holds a current third-party audit report covering the services (for example a SOC 2 Type II report or an ISO/IEC 27001 certificate), it will provide that report to satisfy an audit request. Narra does not hold such a report today. Our current certification status is stated in the Data Security Statement, and until a report exists the audit routes below apply instead.
The Controller, or an independent auditor it mandates who is not a competitor of Narra, may audit Narra's processing of the Controller's personal data. Conditions:
Narra's contracts with its sub-processors give Narra audit and information rights equivalent to those above. On the Controller's written request, Narra will exercise those rights on the Controller's behalf and share the outcome, or, where the sub-processor permits it, arrange for the Controller to audit directly.
Narra will complete a reasonable number of the Controller's security questionnaires each year, and will respond to a standard industry questionnaire within 30 days of request.
The Controller gives Narra a general written authorisation to engage sub-processors, subject to the notice and objection rights below. Narra remains fully liable to the Controller for the performance of each sub-processor's obligations.
This list is current as at the "Last updated" date at the top of this page. It reflects the services actually in production. Every entry processes data in, or is contractually restricted to, the residency region described in the International Data Transfers section.
| Vendor | Purpose | Processing region | Certification |
|---|---|---|---|
| Google Cloud Platform (Google Cloud EMEA Ltd / Google LLC) | Application hosting, compute, storage, key management, logging | asia-south1 (Mumbai, India) | ISO/IEC 27001, ISO/IEC 27018, SOC 2 Type II |
| Firebase (Google) | Authentication, static web hosting, push and email delivery for sign-in | Global control plane; identity records in the Google Cloud region for the project | ISO/IEC 27001, SOC 2 Type II |
| MongoDB Atlas (MongoDB, Inc.) | Managed application database | Google Cloud asia-south1 (Mumbai, India) | ISO/IEC 27001, SOC 2 Type II |
| Razorpay | Payment processing (India) | India | PCI DSS, ISO/IEC 27001 |
| Stripe | Payment processing (international) | United States and EU, under Stripe's own transfer safeguards | PCI DSS, SOC 2 Type II |
Payment processors act as independent controllers for the payment data they collect, under their own terms. Narra does not store full card numbers.
Not used: Narra does not currently use Amazon Web Services, and does not run a third-party website analytics or error-tracking service that processes customer personal data. Earlier versions of this document listed vendors that are not in production. They have been removed.
Personal data is stored and processed in Google Cloud asia-south1 (Mumbai, India), which is the primary hosting region for all customers today. Backups are replicated within India.
Additional residency regions, including the EU, the UK, and the United States, are on the roadmap and are not available today. Narra does not currently offer a contractual residency commitment outside India. Where regional residency is required, it must be agreed and recorded in an Order Form before the subscription starts; nothing in this DPA implies it is available.
Narra will not move personal data outside the agreed residency region without a lawful transfer mechanism and the Controller's prior approval, other than the transfers to payment processors listed in the sub-processor table, which the Controller authorises by entering into this DPA.
If Narra receives a legally binding request from a public authority for personal data it processes for the Controller, it will notify the Controller unless legally prohibited, challenge the request where there are reasonable grounds to consider it unlawful, and disclose only the minimum permissible. Narra publishes the number of such requests received on request from the Controller.
Narra will NOT transfer data to:
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This definition is used consistently across the Terms of Service, Privacy Policy, this DPA, and the Business Associate Agreement.
Each notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the contact point for more information. Where the full detail is not available at once, Narra provides it in phases without further undue delay.
Narra provides notification templates, media response assistance, and regulatory communication support, and maintains a record of every breach and the remedial action taken.
Effective upon execution; continues for the term of the service agreement.
Force Majeure is defined in the Terms of Service and applies equally to both parties, with the same notice and mitigation duties.
No new data is accepted; existing data is retained for 30 days so the Controller can export it; processing during that window is limited to export and deletion; confidentiality obligations continue indefinitely.
At the Controller's election, Narra returns or deletes all personal data at the end of the retention window. Deletion uses overwrite, crypto-erase, or physical destruction for decommissioned media. A certificate of deletion is provided. Audit logs are retained for 5 years, or the longer period required by applicable law, and this is the same figure used throughout the corpus.
Narra's total aggregate liability under this DPA is subject to, and forms part of, the single liability cap stated in the Terms of Service. This DPA does not create a separate cap and does not raise the cap in the Terms. There is no minimum liability floor.
Nothing in this section limits a data subject's rights against either party under GDPR Article 82, or either party's liability to a supervisory authority.
Narra indemnifies the Controller for: data breaches caused by Narra, unauthorised disclosure by Narra, and failure by Narra to implement the security measures in this DPA.
The Controller indemnifies Narra for: claims arising from unauthorised data uploads, intellectual property infringement in Controller data, and regulatory violations by the Controller.
Governing law: India. Jurisdiction: the exclusive jurisdiction of the courts in Hyderabad, Telangana, India. These are the same governing law and venue as the Terms of Service, which govern the whole relationship unless an Order Form states otherwise.