Legal · Enterprise

Data Processing & Business Associate Agreements

Effective: 1 June 2026 · Anxya Tech Private Limited (CIN: U62099PN2024PTC230490) · Pune, Maharashtra, India

For pharma, hospital, payer, provider and other enterprise customers processing personal or health data through Anxya Health. Download or print this document, then contact privacy@anxya.health to execute a countersigned copy for your organisation.

Part A — Data Processing Agreement (DPA)

This DPA forms part of the agreement between the customer (“Controller”) and Anxya Tech Private Limited (“Processor”) and reflects GDPR Article 28 and the India DPDP Act, 2023.

1. Roles & subject matter

The Controller determines the purposes and means of processing personal data; Anxya processes it only to provide the Service and on the Controller’s documented instructions. Subject matter and duration follow the underlying subscription.

2. Nature & purpose of processing

Hosting, generating, storing and returning outputs from Controller data (including uploaded documents and queries) via the Service and its AI sub-processors, solely to deliver the requested functionality.

3. Categories of data & data subjects

Account users, and any personal data the Controller chooses to submit (e.g., patient, employee or research-subject data). The Controller is responsible for the lawful basis of any special-category/health data it submits.

4. Sub-processors

The Controller authorises the sub-processors listed in our Privacy Policy (cloud/hosting, AI model providers, email and payment providers). We impose data-protection terms on each and remain liable for their performance, and will give notice of material changes with a right to object.

5. Security (Art. 32)

We maintain encryption in transit, hashed credentials, access controls, de-identification for research cohorts, logging and least-privilege administration appropriate to the risk.

6. Data-subject requests & assistance

We will, taking into account the nature of processing, assist the Controller with data-subject rights, DPIAs and consultations by appropriate technical and organisational measures.

7. Personal-data breach

We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data, with information reasonably available to support the Controller’s own notification obligations.

8. International transfers

Where data leaves its region, we rely on Standard Contractual Clauses, adequacy decisions or equivalent safeguards.

9. Return & deletion

On termination, we will delete or return Controller personal data within a commercially reasonable period, subject to legal retention requirements, and delete residual copies on backup rotation.

10. Audits

We will make available information necessary to demonstrate compliance and allow for reasonable audits, on notice and subject to confidentiality.

Part B — HIPAA Business Associate Agreement (BAA)

Applies where the customer is a HIPAA Covered Entity (or Business Associate) and Protected Health Information (“PHI”) is processed. Anxya acts as Business Associate.

1. Permitted uses & disclosures

The Business Associate may use or disclose PHI only to perform the Service, as permitted by this BAA, or as required by law, and will not use PHI for any purpose the Covered Entity could not.

2. Safeguards

We implement administrative, physical and technical safeguards (consistent with the HIPAA Security Rule) to protect the confidentiality, integrity and availability of electronic PHI.

3. Reporting

We will report to the Covered Entity any use or disclosure not permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI, without unreasonable delay.

4. Subcontractors

We will ensure that subcontractors that create, receive, maintain or transmit PHI on our behalf agree to the same restrictions and conditions.

5. Individual rights

We will make PHI available for access, amendment and an accounting of disclosures, and cooperate with the Covered Entity to satisfy its obligations under 45 CFR §§164.524, 164.526 and 164.528.

6. Return or destruction

On termination, we will return or destroy all PHI where feasible; where not feasible, protections continue for as long as PHI is retained.

7. Governing terms

This BAA supplements the DPA and the main agreement. In case of conflict regarding PHI, this BAA controls.

Note: This page is a standard template for review. A signed, negotiated agreement is executed per customer. Anxya Health holds no organizational certifications (no SOC 2, no ISO/IEC 42001); these agreements describe contractual data-protection commitments, not a certification. Contact privacy@anxya.health.

We use cookies to run Anxya Health and improve your experience. Choose how we may use them. Read our Cookie Policy, Privacy Policy and Terms.