Bilateral Enterprise Legal Instrument

Data Processing Agreement & BAA

Standard Contractual Terms for Healthcare Data Fiduciaries • Effective Date: June 5, 2026 • Version 2.4

Bilateral Legal Execution & Corporate Succession

This Data Processing Agreement ("DPA" or "Agreement") constitutes a legally binding contract entered into by and between the clinical subscriber, medical practice, healthcare organization, or licensed healthcare practitioner ("Customer", "Clinician", "Data Fiduciary", or "Covered Entity") and Eldovian Technologies (operating commercially as Eldovian, pending formal registration as Eldovian Technologies Private Limited under the Companies Act, 2013, India, and represented by its co-founders Vinay Singh B, Sureshwar Udayashankar, and Prem Kumar, who are bound jointly and severally; upon corporate incorporation, all rights, duties, and obligations herein shall novate and transfer automatically to the private limited entity, fully and irrevocably releasing the co-founders from personal liability) ("Eldovian", "Data Processor", or "Business Associate").

Preamble & Recitals

WHEREAS, Customer operates a medical practice or clinical healthcare facility and is a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act") and, where applicable, a Covered Entity under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA");

WHEREAS, Eldovian provides an AI clinical documentation and speech-to-text platform known as Eldovian Simplify ("Platform"), providing real-time audio transcription, clinical summary drafting (SOAP, H&P, consultation notes), ICD-10 coding assistance, and multi-lingual medical translation;

WHEREAS, the provision of the Platform requires the processing of Customer Personal Data, including sensitive health data and Protected Health Information (PHI) belonging to patients ("Data Principals"); and

WHEREAS, the parties desire to define their respective legal, regulatory, technical, and operational obligations pursuant to Section 8 of the DPDP Act 2023, the Information Technology Act, 2000, the National Medical Commission (NMC) Regulations, and HIPAA regulations (45 CFR Parts 160 and 164).

1. Definitions & Interpretation

  • "Applicable Data Protection Law" means all legislation and regulations governing privacy, data governance, and cybersecurity applicable to the processing of personal data under this Agreement, including the Digital Personal Data Protection Act, 2023 (India) and any rules notified thereunder, the Information Technology Act, 2000 and the SPDI Rules 2011, the CERT-In Cybersecurity Directions of April 2022, the National Medical Commission (Professional Conduct) Regulations, and HIPAA / HITECH Act (45 CFR Parts 160/164).
  • "Customer Personal Data" means any personal data, health metrics, consultation dialogues, medical audio, diagnostic references, or Protected Health Information (PHI) processed by Eldovian on behalf of Customer in connection with the Platform.
  • "Data Fiduciary" and "Data Processor" shall have the meanings ascribed to them under Section 2(i) and Section 2(k) of the DPDP Act 2023.
  • "Data Principal" means the individual (including patients, legal guardians, or healthcare recipients) to whom Customer Personal Data relates.
  • "Personal Data Breach" means any unauthorized or accidental processing, access, disclosure, acquisition, alteration, destruction, or loss of Customer Personal Data that compromises the confidentiality, integrity, or availability of such data.
  • "Sub-processor" means any third-party infrastructure provider, API service, or vendor engaged by Eldovian who handles or processes Customer Personal Data.
  • "Application-Level Encryption (ALE)" means the programmatic cryptographic transformation of plaintext data into ciphertext at the application layer prior to transmission across the internal network or persistence to the database, utilizing AES-256-GCM authenticated encryption.

2. Dual Commercial Scope & Licence Governance

2.1 Universal Applicability: This Agreement governs all processing of Customer Personal Data initiated through Eldovian Simplify, whether during an initial evaluation pilot ("Pilot Evaluation") or an ongoing commercial subscription ("Commercial Subscription").

2.2 Grant of Limited Licence: Subject to the terms and conditions herein, Eldovian grants Customer a limited, non-exclusive, non-sublicensable, non-transferable, revocable licence to access and utilize the Platform for clinical documentation within Customer's authorized clinical practice.

2.3 Strict Assistive Scope & Clinical Non-Liability: Customer acknowledges and expressly agrees that:

  • Eldovian Simplify is an administrative and assistive clinical documentation tool, not a medical device, diagnostic agent, or licensed medical practitioner.
  • AI-generated outputs (including transcriptions, draft clinical summaries, ICD-10 suggestions, and prescription drafts) are preliminary drafts generated by computational models and may contain omissions, hallucinations, or transcription inaccuracies.
  • Customer retains sole, exclusive, and final medical, diagnostic, and clinical responsibility for evaluating, confirming, modifying, approving, and signing all clinical notes, diagnoses, prescriptions, and patient management plans. Eldovian disclaims all liability for clinical care outcomes, diagnostic errors, or therapeutic decisions.

3. Statutory Roles & Relationship of the Parties

3.1 Data Fiduciary / Processor Relationship: Under the DPDP Act 2023, Customer is the Data Fiduciary who determines the purpose and lawful basis for collecting patient data. Eldovian acts strictly as a Data Processor, processing Customer Personal Data solely on the documented, lawful instructions of Customer as set forth in this DPA and the Platform configuration.

3.2 Express Exclusion of Joint Data Fiduciary Status: The parties explicitly stipulate that Eldovian does not act as a Joint Data Fiduciary under Section 2(i) or Section 8 of the DPDP Act. Eldovian does not determine the medical or organizational purposes of data collection. Customer shall indemnify, defend, and hold harmless Eldovian against any regulatory penalties, claims, or administrative actions arising from any determination by a regulatory authority or court that Eldovian is a Joint Data Fiduciary due to Customer's breach of its statutory consent or notice obligations.

3.3 Purpose Limitation: Eldovian covenants to process Customer Personal Data exclusively for: (a) generating real-time clinical transcripts and structured notes; (b) formatting ICD-10 diagnostic codes; (c) supporting clinical record retrieval by Customer; and (d) maintaining technical security, audit trails, and platform integrity.

4. Technical & Organizational Measures (TOMs) & Architecture

Eldovian covenants to implement and maintain rigorous technical and organizational security measures as detailed below and in Schedule B:

  • Zero Audio Storage Warranty: All acoustic consultation audio captured through the Platform is streamed ephemerally directly into volatile system memory (RAM). Audio data is transcribed in-flight and permanently and irreversibly discarded from memory immediately upon transcript completion. Audio recordings are never written to physical disk, non-volatile storage, local caches, or backup archives.
  • Zero Model Training on Protected Data: Eldovian guarantees that Customer Personal Data, patient consultations, acoustic recordings, and clinical transcripts are never utilized to train, re-train, fine-tune, or benchmark public foundation AI models or third-party artificial intelligence engines.
  • Application-Level Encryption (ALE): All clinical data stored at rest (including clinical notes, diagnostic summaries, demographic keys, and past visit logs) is protected by Application-Level Encryption utilizing AES-256-GCM. Encryption keys are securely managed outside the database layer, rendering persisted records cryptographically unreadable in the event of underlying database compromise.
  • Sovereign Data Localization: All persistent databases, authentication servers, and application clusters are hosted exclusively within the sovereign territory of the Republic of India at the AWS Asia Pacific (Mumbai) Region (ap-south-1).
  • ISO 27789 Audit Trails: Platform operations enforce granular, tamper-evident audit logging compliant with ISO 27789 standards, tracking all clinical note views, edits, exports, and identity authentications.

5. Customer Obligations, Patient Consent & Pediatric Governance (DPDP Act Sec. 9)

5.1 Verifiable Patient Consent: Customer warrants and covenants that prior to initiating any audio recording or clinical documentation session through the Platform, Customer has obtained valid, informed, verifiable consent (written or explicit verbal acknowledgement documented in clinical records) from the patient (Data Principal) in compliance with Section 6 of the DPDP Act 2023.

5.2 Pediatric & Minor Governance (DPDP Act Section 9): Where a clinical consultation involves a Data Principal who is a child (under 18 years of age) or a person with a disability under lawful guardianship:

  • Customer represents, warrants, and covenants that it has obtained verifiable consent from the parent or lawful guardian of the child prior to initiating any recording or data processing.
  • Customer acknowledges that Eldovian enforces an absolute prohibition against behavioral monitoring, tracking, or targeted profiling of children, and Customer agrees never to configure or utilize the Platform for any such purpose.

5.3 Suggested Verifiable Consent Script: Customer may fulfill its verbal disclosure duty by administering the following or substantially equivalent notice:

"I use an AI-assisted documentation system to transcribe our medical conversation today. The audio is processed temporarily in real-time memory and is deleted instantly after the notes are created. No audio is ever saved. Your notes are encrypted and accessible only to our clinic. You may decline at any time without affecting your medical treatment."

6. Sub-processors & Supply Chain Governance

6.1 Authorized Sub-processors: Customer provides prior general written authorization for Eldovian to engage the sub-processors set forth in Schedule C.

6.2 Pass-Through Contractual Covenants: Eldovian shall impose data protection and cybersecurity obligations on each sub-processor that are no less protective than those set forth in this Agreement, including data localization within India, zero model training on patient data, and encryption at rest and in transit.

6.3 Sub-processor Modification & Right to Object: Eldovian shall notify Customer of any planned addition, removal, or replacement of a sub-processor by updating its sub-processor registry or providing electronic notice at least fifteen (15) calendar days in advance. Customer may object to a new sub-processor on reasonable data protection grounds within ten (10) days of receiving notice. If the parties cannot resolve the objection, Customer may terminate the affected service without penalty upon written notice.

6.4 Primary Processor Liability: Eldovian remains fully liable to Customer for the acts and omissions of its sub-processors to the same extent as if performed directly by Eldovian.

7. Data Principal Rights Management

7.1 Fiduciary Responsibility: Customer, as Data Fiduciary, is primarily responsible for receiving, evaluating, and fulfilling Data Principal rights requests (including access, correction, completion, erasure, and grievance redressal under Sections 11–13 of the DPDP Act 2023).

7.2 Processor Assistance SLA: To the extent Customer cannot fulfill a Data Principal request through the Platform console, Eldovian shall, upon receipt of written notice at grievance@eldovian.com (or privacy@eldovian.com), provide commercially reasonable assistance within thirty (30) calendar days.

7.3 Harmonization with NMC Medical Archiving: If a Data Principal requests the erasure of clinical notes or consultation records, both parties recognize that Customer and Eldovian are subject to statutory medical record-retention mandates, including the National Medical Commission (NMC) requirement to retain clinical records for a minimum period of three (3) years. In such instances, Eldovian shall support Customer by quarantining and soft-deleting the active records, retaining them in an isolated, encrypted cold archive solely for statutory compliance.

7.4 Statutory Grievance Redressal Officer (DPDP Act Sec. 8(9)): Pursuant to Section 8(9) and Section 13 of the DPDP Act 2023, Eldovian has designated a Grievance Redressal Officer. Data Principals and Customers may lodge privacy complaints, rights requests, or audit queries directly:

Grievance Redressal Officer: Compliance & Legal Cell, Eldovian Technologies
Designated Email: grievance@eldovian.com
Jurisdiction / Seat: Bengaluru, Karnataka, India
Resolution SLA: Acknowledgment within forty-eight (48) hours; statutory resolution within thirty (30) calendar days.

8. Security Incidents & Breach Notification Protocol

8.1 Notification Timeline: In the event of a confirmed Personal Data Breach affecting Customer Personal Data within Eldovian's infrastructure, Eldovian shall notify Customer without undue delay and in any event within twenty-four to forty-eight (24–48) hours of verifying the incident.

8.2 Incident Documentation: Eldovian shall provide Customer with available details regarding: (a) the nature, timing, and extent of the breach; (b) the estimated categories and volume of affected Data Principals; (c) the likely consequences; and (d) mitigation and remediation measures taken or planned.

8.3 Regulatory Reporting & Cost Allocation:

  • Customer retains primary statutory responsibility for reporting the breach to the Data Protection Board of India (DPBI) under Section 8(6) of the DPDP Act and to affected Data Principals.
  • Where a breach is caused solely by Eldovian's breach of its security commitments, Eldovian shall remediate the breach and provide breach documentation at its own expense. Where a breach is caused by Customer's credential mismanagement, device compromise, or unauthorized user access, all remediation and notification expenses shall be borne solely by Customer.

9. Audit Rights & Compliance Attestations

9.1 Managed Security Evidence: Upon Customer's written request, Eldovian shall satisfy Customer's verification and audit rights under Applicable Data Protection Law by providing: (a) executive summaries of its annual Vulnerability Assessment and Penetration Testing (VAPT) conducted by an independent CERT-In empaneled security auditor; (b) technical architecture security attestations; and (c) completed standardized security questionnaires (SIG/CAIQ).

9.2 Restricted On-Site Audits: If Customer, as a regulated healthcare entity, is required by a competent regulatory authority (e.g., DPBI, NABH, or State Medical Council) to perform an on-site audit, Eldovian shall permit such inspection subject to: (a) at least thirty (30) business days' advance written notice; (b) conduct during normal business hours; (c) execution of a non-disclosure agreement; (d) strict non-interference with production operations and multi-tenant data boundaries; and (e) Customer bearing all out-of-pocket costs of such audit.

10. Confidentiality & Proprietary Rights

10.1 Bilateral Confidentiality: Each party covenants to protect the other party's Confidential Information with the same degree of care it uses for its own confidential records, but in no event less than a reasonable standard of care.

10.2 Customer Data Ownership: All clinical notes, patient summaries, consultation transcripts, ICD codes, and medical records generated through the Platform remain the sole and exclusive intellectual and proprietary property of Customer.

10.3 Platform Intellectual Property: Eldovian retains sole and exclusive ownership of all right, title, and interest in and to the Platform, including proprietary algorithms, prompt architectures, user interfaces, documentation, and technical enhancements.

11. Data Return, Transition & Cryptographic Erasure

11.1 Post-Termination Transition Window: Upon expiration or termination of the service relationship for any reason, Eldovian shall provide Customer with a thirty (30) calendar day read-only transition period, during which Customer may export all clinical notes, transcripts, and audit logs via standard JSON/PDF/CSV formats.

11.2 Certified Cryptographic Erasure: Following the expiry of the 30-day transition window, Eldovian shall, upon Customer's written confirmation or automatic expiry, permanently delete, overwrite, and cryptographically erase all active Customer Personal Data from its production database clusters within sixty (60) days, retaining only those archived records strictly mandated by applicable statutory laws (such as NMC archiving or taxation).

12. Limitation of Liability & Indemnification

12.1 Consequential Damages Exclusion: To the maximum extent permitted by applicable law, neither party shall be liable to the other for any indirect, incidental, punitive, special, or consequential damages, including loss of clinical revenue, loss of goodwill, or business interruption.

12.2 Aggregate Liability Ceiling:

  • Commercial Subscriptions: Eldovian's total aggregate liability arising out of or related to this Agreement shall be strictly capped at the total fees paid by Customer to Eldovian in the twelve (12) months preceding the incident.
  • Pilot Evaluations: For non-paying pilot users, Eldovian's aggregate liability shall not exceed INR 50,000 (Rupees Fifty Thousand).

12.3 Liability Carve-Outs: The liability limitations in Section 12.2 shall not apply to damages resulting from a party's gross negligence, willful misconduct, or breach of Section 10 (Confidentiality).

12.4 Customer Indemnity: Customer agrees to defend, indemnify, and hold Eldovian harmless against any third-party claims, liabilities, or regulatory fines arising out of: (a) failure to obtain valid informed patient consent; (b) clinical malpractice, patient misdiagnosis, or treatment decisions; or (c) Customer's breach of Section 5.2 (Pediatric Governance).

13. Term & Termination

13.1 Term: This Agreement takes effect upon account registration or signature and remains in effect co-terminously with Customer's active Pilot Evaluation or Commercial Subscription.

13.2 Termination for Convenience: Either party may terminate this Agreement without cause upon thirty (30) days' advance written notice.

13.3 Termination for Material Breach: Either party may terminate this Agreement immediately upon written notice if the other party materially breaches this Agreement and fails to cure such breach within fifteen (15) days of written notice.

14. Dispute Resolution & Governing Law

14.1 Governing Law: This Agreement shall be governed by, and construed in accordance with, the substantive laws of the Republic of India.

14.2 Amicable Resolution: In the event of any dispute arising out of this Agreement, the parties shall first attempt to resolve the dispute through good-faith negotiations between designated executive representatives for fifteen (15) business days.

14.3 Binding Arbitration: Any dispute not resolved through negotiation shall be referred to and finally resolved by binding arbitration under the Arbitration and Conciliation Act, 1996 (as amended). The arbitral tribunal shall consist of a sole arbitrator appointed by mutual agreement, or failing agreement within thirty (30) days, in accordance with the Act.

14.4 Seat, Venue & Language: The legal seat and venue of the arbitration shall be Bengaluru, Karnataka, India. The language of arbitration shall be English.

15. Corporate Succession & Founder Liability Novation

Customer acknowledges that Eldovian Technologies is in the process of formal corporate incorporation as Eldovian Technologies Private Limited. Upon issuance of the Certificate of Incorporation by the Ministry of Corporate Affairs (MCA), Government of India, all rights, covenants, and liabilities of Eldovian Technologies under this Agreement shall automatically novate and transfer to Eldovian Technologies Private Limited without requiring additional written consent, thereby completely and irrevocably releasing the individual co-founders from any personal, joint, or several liability hereunder.

16. Electronic Execution & Enforceability

Execution Clause: By registering a clinic account, checking the "Accept Terms & DPA" dialogue, deploying a pilot access code, or utilizing Eldovian Simplify, Customer and Eldovian digitally execute and accept all clauses in this Data Processing Agreement, establishing a valid, enforceable bilateral contract pursuant to the Information Technology Act, 2000 (India).
Schedule A

Specification of Processing Operations

Subject MatterReal-time clinical voice transcription, SOAP/H&P clinical summary drafting, ICD-10 coding formatting, and consultation record management.
Duration of ProcessingReal-time in-flight audio processing (transient RAM-only), with structured clinical note records retained throughout the Customer's active subscription plus 30-day transition period, subject to NMC archiving.
Categories of Data PrincipalsPatients, clinic visitors, consulting physicians, nurse practitioners, and clinical support staff.
Types of Personal DataPatient identifiers (name, age, gender), consultation dialogues, symptoms, vital signs, physical exam findings, clinical diagnoses, ICD-10 codes, and medication instructions.
Special Categories / Sensitive DataProtected Health Information (PHI) and Health Data under DPDP Act Section 2(t) and Section 9.
Schedule B

Technical and Organizational Security Measures (TOMs)

1. Cryptographic Safeguards

Application-Level Encryption (AES-256-GCM) for sensitive clinical payloads; TLS 1.3 encryption for all data in transit; zero plaintext persistence of clinical notes.

2. Ephemeral Audio Processing

Audio is processed strictly in volatile memory (RAM); zero audio disk persistence; permanent deletion immediately following note completion.

3. Multi-Tenant Logical Isolation

PostgreSQL Row Level Security (RLS) enforcing strict tenant scoping (`user_id = auth.uid()`); zero cross-tenant data leakage.

4. Audit Logging & Access Controls

Aggregated JSONB access ledgers compliant with ISO 27789; role-based access control (RBAC); strict credential hashing (Argon2/bcrypt).

Schedule C

Authorized Sub-processors Registry

Sub-processorActivityLocationData Safeguards
Supabase Inc. (AWS)Managed PostgreSQL, User Authentication, Application HostingMumbai, India (AWS ap-south-1)AES-256 at rest, SOC 2 Type II, ISO 27001
Sarvam AI Private LimitedReal-time Indic Speech-to-Text Transcription APIsBengaluru, IndiaIn-flight RAM-only processing; zero model training; zero disk persistence
Google LLC (Google Cloud / Google AI)Clinical Natural Language Structuring, SOAP Summarization & ICD-10 FormattingCloud / Global (Enterprise Zero-Retention Endpoints)In-flight transient processing; zero customer data model training; TLS 1.3 encrypted in transit; SOC 2 Type II, ISO 27001
Schedule D

HIPAA Business Associate Agreement (BAA) Addendum

This Schedule D applies solely where Customer is a Covered Entity or Business Associate subject to the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the HITECH Act.

1. Permitted Uses and Disclosures: Business Associate shall use or disclose Protected Health Information (PHI) only as permitted by this Agreement or as Required by Law, pursuant to 45 CFR § 164.504(e)(2)(i).

2. Statutory Safeguards: Business Associate agrees to implement administrative, physical, and technical safeguards that reasonably protect the confidentiality, integrity, and availability of electronic PHI that it creates, receives, maintains, or transmits on behalf of Covered Entity, compliant with 45 CFR Part 164, Subpart C.

3. Security Incident Reporting: Business Associate shall report to Covered Entity any Security Incident or Breach of Unsecured PHI of which it becomes aware within forty-eight (48) hours, compliant with 45 CFR § 164.410.

4. Access to Books and Records: Business Associate agrees to make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services (HHS) for purposes of determining Covered Entity's compliance with HIPAA.