Effective: 1 June 2026 · Anxya Tech Private Limited (CIN: U62099PN2024PTC230490) · Pune, Maharashtra, India
For pharma, hospital, payer, provider and other enterprise customers processing personal or health data through Anxya Health. Download or print this document, then contact privacy@anxya.health to execute a countersigned copy for your organisation.
This DPA forms part of the agreement between the customer (“Controller”) and Anxya Tech Private Limited (“Processor”) and reflects GDPR Article 28 and the India DPDP Act, 2023.
The Controller determines the purposes and means of processing personal data; Anxya processes it only to provide the Service and on the Controller’s documented instructions. Subject matter and duration follow the underlying subscription.
Hosting, generating, storing and returning outputs from Controller data (including uploaded documents and queries) via the Service and its AI sub-processors, solely to deliver the requested functionality.
Account users, and any personal data the Controller chooses to submit (e.g., patient, employee or research-subject data). The Controller is responsible for the lawful basis of any special-category/health data it submits.
The Controller authorises the sub-processors listed in our Privacy Policy (cloud/hosting, AI model providers, email and payment providers). We impose data-protection terms on each and remain liable for their performance, and will give notice of material changes with a right to object.
We maintain encryption in transit, hashed credentials, access controls, de-identification for research cohorts, logging and least-privilege administration appropriate to the risk.
We will, taking into account the nature of processing, assist the Controller with data-subject rights, DPIAs and consultations by appropriate technical and organisational measures.
We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data, with information reasonably available to support the Controller’s own notification obligations.
Where data leaves its region, we rely on Standard Contractual Clauses, adequacy decisions or equivalent safeguards.
On termination, we will delete or return Controller personal data within a commercially reasonable period, subject to legal retention requirements, and delete residual copies on backup rotation.
We will make available information necessary to demonstrate compliance and allow for reasonable audits, on notice and subject to confidentiality.
Applies where the customer is a HIPAA Covered Entity (or Business Associate) and Protected Health Information (“PHI”) is processed. Anxya acts as Business Associate.
The Business Associate may use or disclose PHI only to perform the Service, as permitted by this BAA, or as required by law, and will not use PHI for any purpose the Covered Entity could not.
We implement administrative, physical and technical safeguards (consistent with the HIPAA Security Rule) to protect the confidentiality, integrity and availability of electronic PHI.
We will report to the Covered Entity any use or disclosure not permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI, without unreasonable delay.
We will ensure that subcontractors that create, receive, maintain or transmit PHI on our behalf agree to the same restrictions and conditions.
We will make PHI available for access, amendment and an accounting of disclosures, and cooperate with the Covered Entity to satisfy its obligations under 45 CFR §§164.524, 164.526 and 164.528.
On termination, we will return or destroy all PHI where feasible; where not feasible, protections continue for as long as PHI is retained.
This BAA supplements the DPA and the main agreement. In case of conflict regarding PHI, this BAA controls.
We use cookies to run Anxya Health and improve your experience. Choose how we may use them. Read our Cookie Policy, Privacy Policy and Terms.