This Data Processing Addendum (“DPA”) forms part of the Terms of Service between RAKT INNOVATIONS (OPC) PVT. LTD., CIN U72900DL2020OPC360414, registered office AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India (“RAKT”, “Processor”) and the customer organisation subscribing to the Service (“Customer”, “Data Fiduciary”).
It applies automatically and requires no separate signature. It is the contract required by Section 8(2) of the Digital Personal Data Protection Act, 2023, under which a Data Fiduciary may engage a Data Processor only under a valid contract. A counterpart for signature, and a version on Customer letterhead for tender or accreditation purposes, is available on request to support@rakt.in.
1.1 In respect of Customer Data processed through the Service, Customer is the Data Fiduciary and determines the purposes and means of processing. RAKT is the Data Processor and processes that data only on Customer’s behalf.
1.2 Customer is responsible for establishing a lawful basis for the processing, for giving notice to data principals, for obtaining and maintaining records of any consent required, and for the accuracy and lawfulness of the data it enters into the Service.
1.3 This DPA does not apply to data for which RAKT is itself the Data Fiduciary, such as Customer’s billing and administrative contact details. That processing is governed by the Privacy Policy.
1.4 Capitalised terms not defined here have the meaning given in the Terms of Service. “Personal Data” includes sensitive personal data or information under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
RAKT shall:
Personal Data is Confidential Information of Customer for the purposes of the Terms of Service. RAKT shall not disclose it to any third party except as permitted by this DPA, on Customer’s instruction, or where required by law. Where a disclosure is compelled by law, RAKT shall, unless legally prohibited, notify Customer before disclosing, and shall disclose only the minimum required.
4.1 RAKT shall maintain reasonable security safeguards appropriate to the nature of the data, as required by Section 8(5) of the Digital Personal Data Protection Act, 2023 and Rule 8 of the SPDI Rules. Annex 2 describes the measures in force.
4.2 RAKT does not hold an ISO/IEC 27001 certification and does not represent that it does. Annex 2 states what is actually operated.
4.3 Customer is responsible for the security measures within its own control, including the management of Authorised Users and permissions, the security of its endpoints and networks, and not sharing credentials.
5.1 Customer authorises RAKT to engage the sub-processors listed at rakt.in/subprocessors/ for the purposes stated there.
5.2 RAKT shall impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains responsible to Customer for a sub-processor’s performance.
5.3 RAKT shall update that page and notify Customer by email or through the Service before a new sub-processor begins processing Personal Data. Customer may object on reasonable data protection grounds within fourteen days of the notice, and the parties shall work in good faith towards an alternative. If none is available, Customer may terminate the affected part of the Subscription without penalty and receive a pro-rata refund of any unused prepaid fees for that part.
5.4 The optional artificial intelligence features described in Section 5 of the Privacy Policy involve a sub-processor outside India. They are not enabled by operation of this DPA alone: Customer chooses whether to use them, and may ask RAKT to disable them for its account.
6.1 The Service provides Customer with the functionality to access, correct, update, export, and delete the records it holds, so that Customer can respond to a data principal’s request directly.
6.2 Where a data principal contacts RAKT directly about data RAKT processes for Customer, RAKT shall not respond substantively but shall refer the person to Customer and inform Customer without undue delay.
6.3 Where Customer cannot fulfil a request using the Service, RAKT shall provide reasonable assistance at no charge for a proportionate volume of requests.
7.1 RAKT shall notify Customer of a Personal Data breach affecting Customer Data without undue delay after becoming aware of it, and in any event within twenty-four hours of confirming it.
7.2 RAKT shall send an initial alert as soon as practicable, ahead of any complete assessment, so that Customer can meet its own six-hour reporting obligation to CERT-In under the directions dated 28 April 2022.
7.3 The notification shall include, to the extent known and updated as the investigation proceeds: the nature and extent of the breach, the categories and approximate volume of data and data principals affected, the likely consequences, the measures taken or proposed to mitigate it, and a contact point at RAKT.
7.4 RAKT shall provide the information reasonably required for Customer to notify the Data Protection Board of India, without delay and with detailed particulars within seventy-two hours, and to notify affected data principals.
7.5 RAKT shall take reasonable steps to contain and remediate the breach, and shall preserve relevant logs and evidence.
7.6 Notification is not an admission of fault or liability by RAKT.
8.1 On reasonable written request, and no more than once in any twelve-month period unless a breach or a regulator requires otherwise, RAKT shall provide the information reasonably necessary to demonstrate compliance with this DPA, including a description of its security measures, its sub-processor list, and responses to a reasonable security questionnaire.
8.2 Where that is insufficient for Customer to meet a documented statutory or accreditation obligation, including a NABH assessment, the parties shall agree an audit of scope, timing, and duration that does not compromise the security or confidentiality of other customers’ data. Customer bears its own costs, and RAKT’s reasonable costs where an audit exceeds one working day.
8.3 RAKT may satisfy an audit request by providing the report of an independent assessment covering the relevant controls.
9.1 Customer Data is stored and backed up on infrastructure located in India.
9.2 Certain sub-processors process limited Personal Data outside India, as identified with their locations at rakt.in/subprocessors/ and explained in Sections 5 and 6 of the Privacy Policy.
9.3 RAKT shall not transfer Personal Data to a country in respect of which such transfer is restricted by the Central Government under Section 16 of the Digital Personal Data Protection Act, 2023.
9.4 If Customer requires processing to be confined to India, it must tell RAKT in writing. RAKT will identify which features can be provided on that basis and which must be disabled.
10.1 On request made within thirty days after termination of the Subscription, RAKT shall make available an export of Customer Data in a standard machine-readable format at no additional charge.
10.2 After that window, RAKT shall delete Customer Data from its live systems.
10.3 Encrypted backups are retained on a defined lifecycle for up to twelve months and then expire and are destroyed. RAKT shall not restore expired Customer Data from backup except in the course of recovering the Service as a whole.
10.4 RAKT may retain Personal Data where a law requires it, for so long as that requirement lasts, and shall continue to protect it in accordance with this DPA.
10.5 RAKT shall confirm deletion in writing on request.
Customer shall:
Each party’s liability under this DPA is subject to the exclusions and the aggregate cap in Section 15 of the Terms of Service, save that nothing in this DPA or those Terms limits any liability that cannot lawfully be limited, including a monetary penalty imposed on a party by the Data Protection Board of India in respect of its own default.
13.1 This DPA takes effect when Customer begins using the Service and continues for as long as RAKT processes Personal Data for Customer.
13.2 If there is a conflict between this DPA and the Terms of Service in relation to the processing of Personal Data, this DPA prevails. A separately negotiated and signed data processing agreement between the parties prevails over this DPA.
13.3 This DPA is governed by the laws of India, and Section 21 of the Terms of Service applies to any dispute under it.
Subject matter. Provision of the RAKT blood centre management platform to Customer.
Duration. The term of the Subscription, plus the export and deletion periods in Section 10.
Nature of processing. Collection, recording, organisation, structuring, storage, retrieval, use, transmission, display, export, backup, erasure, and destruction, carried out by automated means for the purpose of operating the Service.
Purpose. Enabling Customer to manage donor registration and screening, blood collection and component preparation, testing records, inventory and issue, camps, recipients and requisitions, staff activity, statutory and internal reporting, and communications with donors, and to provide support, security, and continuity for those functions.
Categories of data principals. Blood donors and prospective donors; recipients and patients; camp organisers and volunteers; Customer’s staff and Authorised Users; and Customer’s institutional contacts.
Categories of Personal Data. Identity and contact data, including name, age or date of birth, sex, address, phone number, and email address; identifiers recorded by Customer; blood group and component data; donation, deferral, and transfusion history; screening and laboratory results, including for transfusion-transmissible infections; vitals and eligibility assessments; camp participation; staff role, credentials, and activity logs; and technical data such as IP address and device information.
Sensitive Personal Data. Health data, including medical history and test results, constitutes sensitive personal data or information under Rule 3 of the SPDI Rules and is processed subject to the measures in Annex 2.
Frequency. Continuous, for the duration of the Subscription.
These are the measures RAKT operates. They are described in the same terms in Section 7 of the Privacy Policy, and are stated as what is in force rather than as an aspiration.
RAKT may update these measures to maintain or improve the level of protection, and shall not materially reduce them during the term.
Grievance Officer
RAKT INNOVATIONS (OPC) PVT. LTD.
AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India
CIN: U72900DL2020OPC360414 | GSTIN: 07AAKCR0304B1Z0
Phone: +91 70427 21037, +91 99539 94941
Email: support@rakt.in — please put “DPA” or “Grievance” in the subject line
Ready to revolutionize your blood bank operations? Get started today!