Skip to content

Data Processing Addendum

Version 1.0  ·  Effective 31 July 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between RAKT INNOVATIONS (OPC) PVT. LTD., CIN U72900DL2020OPC360414, registered office AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India (“RAKT”, “Processor”) and the customer organisation subscribing to the Service (“Customer”, “Data Fiduciary”).

It applies automatically and requires no separate signature. It is the contract required by Section 8(2) of the Digital Personal Data Protection Act, 2023, under which a Data Fiduciary may engage a Data Processor only under a valid contract. A counterpart for signature, and a version on Customer letterhead for tender or accreditation purposes, is available on request to support@rakt.in.

1. Roles and scope

1.1 In respect of Customer Data processed through the Service, Customer is the Data Fiduciary and determines the purposes and means of processing. RAKT is the Data Processor and processes that data only on Customer’s behalf.

1.2 Customer is responsible for establishing a lawful basis for the processing, for giving notice to data principals, for obtaining and maintaining records of any consent required, and for the accuracy and lawfulness of the data it enters into the Service.

1.3 This DPA does not apply to data for which RAKT is itself the Data Fiduciary, such as Customer’s billing and administrative contact details. That processing is governed by the Privacy Policy.

1.4 Capitalised terms not defined here have the meaning given in the Terms of Service. “Personal Data” includes sensitive personal data or information under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

2. RAKT’s obligations

RAKT shall:

  • 2.1 process Personal Data only on Customer’s documented instructions, which comprise this DPA, the Terms of Service, the configuration Customer applies in the Service, and any further written instruction the parties agree;
  • 2.2 not process Personal Data for its own purposes, and not sell, rent, or disclose it for consideration;
  • 2.3 not use Personal Data to train or improve any artificial intelligence or machine learning model, and require the same of its sub-processors;
  • 2.4 inform Customer if, in RAKT’s opinion, an instruction would cause a breach of applicable law, and may suspend that instruction until resolved;
  • 2.5 limit access to Personal Data to personnel who need it to deliver or support the Service, ensure those personnel are bound by written confidentiality obligations that survive the end of their engagement, and maintain access records;
  • 2.6 implement and maintain the technical and organisational measures set out in Annex 2, and not materially reduce them during the term;
  • 2.7 assist Customer, at Customer’s reasonable request, with data protection impact assessments, audits, and enquiries or investigations by a regulator or the Data Protection Board of India, so far as they relate to RAKT’s processing.

3. Confidentiality

Personal Data is Confidential Information of Customer for the purposes of the Terms of Service. RAKT shall not disclose it to any third party except as permitted by this DPA, on Customer’s instruction, or where required by law. Where a disclosure is compelled by law, RAKT shall, unless legally prohibited, notify Customer before disclosing, and shall disclose only the minimum required.

4. Security

4.1 RAKT shall maintain reasonable security safeguards appropriate to the nature of the data, as required by Section 8(5) of the Digital Personal Data Protection Act, 2023 and Rule 8 of the SPDI Rules. Annex 2 describes the measures in force.

4.2 RAKT does not hold an ISO/IEC 27001 certification and does not represent that it does. Annex 2 states what is actually operated.

4.3 Customer is responsible for the security measures within its own control, including the management of Authorised Users and permissions, the security of its endpoints and networks, and not sharing credentials.

5. Sub-processors

5.1 Customer authorises RAKT to engage the sub-processors listed at rakt.in/subprocessors/ for the purposes stated there.

5.2 RAKT shall impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains responsible to Customer for a sub-processor’s performance.

5.3 RAKT shall update that page and notify Customer by email or through the Service before a new sub-processor begins processing Personal Data. Customer may object on reasonable data protection grounds within fourteen days of the notice, and the parties shall work in good faith towards an alternative. If none is available, Customer may terminate the affected part of the Subscription without penalty and receive a pro-rata refund of any unused prepaid fees for that part.

5.4 The optional artificial intelligence features described in Section 5 of the Privacy Policy involve a sub-processor outside India. They are not enabled by operation of this DPA alone: Customer chooses whether to use them, and may ask RAKT to disable them for its account.

6. Assisting data principals

6.1 The Service provides Customer with the functionality to access, correct, update, export, and delete the records it holds, so that Customer can respond to a data principal’s request directly.

6.2 Where a data principal contacts RAKT directly about data RAKT processes for Customer, RAKT shall not respond substantively but shall refer the person to Customer and inform Customer without undue delay.

6.3 Where Customer cannot fulfil a request using the Service, RAKT shall provide reasonable assistance at no charge for a proportionate volume of requests.

7. Personal data breaches

7.1 RAKT shall notify Customer of a Personal Data breach affecting Customer Data without undue delay after becoming aware of it, and in any event within twenty-four hours of confirming it.

7.2 RAKT shall send an initial alert as soon as practicable, ahead of any complete assessment, so that Customer can meet its own six-hour reporting obligation to CERT-In under the directions dated 28 April 2022.

7.3 The notification shall include, to the extent known and updated as the investigation proceeds: the nature and extent of the breach, the categories and approximate volume of data and data principals affected, the likely consequences, the measures taken or proposed to mitigate it, and a contact point at RAKT.

7.4 RAKT shall provide the information reasonably required for Customer to notify the Data Protection Board of India, without delay and with detailed particulars within seventy-two hours, and to notify affected data principals.

7.5 RAKT shall take reasonable steps to contain and remediate the breach, and shall preserve relevant logs and evidence.

7.6 Notification is not an admission of fault or liability by RAKT.

8. Audit and information rights

8.1 On reasonable written request, and no more than once in any twelve-month period unless a breach or a regulator requires otherwise, RAKT shall provide the information reasonably necessary to demonstrate compliance with this DPA, including a description of its security measures, its sub-processor list, and responses to a reasonable security questionnaire.

8.2 Where that is insufficient for Customer to meet a documented statutory or accreditation obligation, including a NABH assessment, the parties shall agree an audit of scope, timing, and duration that does not compromise the security or confidentiality of other customers’ data. Customer bears its own costs, and RAKT’s reasonable costs where an audit exceeds one working day.

8.3 RAKT may satisfy an audit request by providing the report of an independent assessment covering the relevant controls.

9. Location of processing

9.1 Customer Data is stored and backed up on infrastructure located in India.

9.2 Certain sub-processors process limited Personal Data outside India, as identified with their locations at rakt.in/subprocessors/ and explained in Sections 5 and 6 of the Privacy Policy.

9.3 RAKT shall not transfer Personal Data to a country in respect of which such transfer is restricted by the Central Government under Section 16 of the Digital Personal Data Protection Act, 2023.

9.4 If Customer requires processing to be confined to India, it must tell RAKT in writing. RAKT will identify which features can be provided on that basis and which must be disabled.

10. Return and deletion

10.1 On request made within thirty days after termination of the Subscription, RAKT shall make available an export of Customer Data in a standard machine-readable format at no additional charge.

10.2 After that window, RAKT shall delete Customer Data from its live systems.

10.3 Encrypted backups are retained on a defined lifecycle for up to twelve months and then expire and are destroyed. RAKT shall not restore expired Customer Data from backup except in the course of recovering the Service as a whole.

10.4 RAKT may retain Personal Data where a law requires it, for so long as that requirement lasts, and shall continue to protect it in accordance with this DPA.

10.5 RAKT shall confirm deletion in writing on request.

11. Customer’s obligations as Data Fiduciary

Customer shall:

  • 11.1 give data principals the notice required by Section 5 of the Digital Personal Data Protection Act, 2023, and obtain and record any consent required, including for donor screening and test results and for any notifications the Customer configures;
  • 11.2 where it enables the optional artificial intelligence features, ensure its notice and consent documentation covers the processing described in Section 5 of the Privacy Policy;
  • 11.3 not enter into the Service any category of data prohibited under Section 6.4 of the Terms of Service;
  • 11.4 maintain its own statutory records and determine its own retention periods, including under the Drugs and Cosmetics Rules, 1945;
  • 11.5 administer Authorised Users, permissions, and offboarding promptly and accurately.

12. Liability

Each party’s liability under this DPA is subject to the exclusions and the aggregate cap in Section 15 of the Terms of Service, save that nothing in this DPA or those Terms limits any liability that cannot lawfully be limited, including a monetary penalty imposed on a party by the Data Protection Board of India in respect of its own default.

13. Term, conflict, and governing law

13.1 This DPA takes effect when Customer begins using the Service and continues for as long as RAKT processes Personal Data for Customer.

13.2 If there is a conflict between this DPA and the Terms of Service in relation to the processing of Personal Data, this DPA prevails. A separately negotiated and signed data processing agreement between the parties prevails over this DPA.

13.3 This DPA is governed by the laws of India, and Section 21 of the Terms of Service applies to any dispute under it.

Annex 1 — Details of processing

Subject matter. Provision of the RAKT blood centre management platform to Customer.

Duration. The term of the Subscription, plus the export and deletion periods in Section 10.

Nature of processing. Collection, recording, organisation, structuring, storage, retrieval, use, transmission, display, export, backup, erasure, and destruction, carried out by automated means for the purpose of operating the Service.

Purpose. Enabling Customer to manage donor registration and screening, blood collection and component preparation, testing records, inventory and issue, camps, recipients and requisitions, staff activity, statutory and internal reporting, and communications with donors, and to provide support, security, and continuity for those functions.

Categories of data principals. Blood donors and prospective donors; recipients and patients; camp organisers and volunteers; Customer’s staff and Authorised Users; and Customer’s institutional contacts.

Categories of Personal Data. Identity and contact data, including name, age or date of birth, sex, address, phone number, and email address; identifiers recorded by Customer; blood group and component data; donation, deferral, and transfusion history; screening and laboratory results, including for transfusion-transmissible infections; vitals and eligibility assessments; camp participation; staff role, credentials, and activity logs; and technical data such as IP address and device information.

Sensitive Personal Data. Health data, including medical history and test results, constitutes sensitive personal data or information under Rule 3 of the SPDI Rules and is processed subject to the measures in Annex 2.

Frequency. Continuous, for the duration of the Subscription.

Annex 2 — Technical and organisational measures

These are the measures RAKT operates. They are described in the same terms in Section 7 of the Privacy Policy, and are stated as what is in force rather than as an aspiration.

  • Encryption in transit. HTTPS for all access, with HTTP Strict Transport Security enforced including on subdomains, and plain HTTP redirected.
  • Encryption at rest and in backup. Managed database storage with provider-level encryption; object storage encrypted server-side; system-state backups encrypted with AES-256 before upload to storage in India. Restores are periodically tested.
  • Authentication. Support for passkeys and WebAuthn; passwords stored only as salted cryptographic hashes; rate limiting on login; periodic re-authentication for sensitive operations; two-factor authentication on administrative interfaces.
  • Access control. Role-based permissions within each organisation, and logical separation so that records are scoped to the organisation that owns them.
  • Accountability and logging. Record-level change history and organisation activity logs attributing actions to a user and a time; access, traffic, and processing logs retained for one year.
  • Personnel. Production access restricted to personnel who require it, over authenticated channels, under written confidentiality obligations.
  • Resilience. Managed database with provider backups, independent encrypted off-host backups on a defined retention lifecycle, and documented restore procedures.
  • Incident response. Documented procedure for detection, containment, assessment, notification within the timelines in Section 7, and remediation.
  • Data minimisation in support. Support access to Customer Data only as required to resolve a reported issue, and prohibitions on storing prohibited data categories under Section 6.4 of the Terms of Service.

RAKT may update these measures to maintain or improve the level of protection, and shall not materially reduce them during the term.

Contact

Grievance Officer
RAKT INNOVATIONS (OPC) PVT. LTD.
AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India
CIN: U72900DL2020OPC360414  |  GSTIN: 07AAKCR0304B1Z0
Phone: +91 70427 21037, +91 99539 94941
Email: support@rakt.in — please put “DPA” or “Grievance” in the subject line