Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement (the "Agreement") between Caresoft Systems Private Limited, CIN [ U72900MH2022PTC387875], registered office [311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107] ("Processor", "Caresoft"), and the customer identified in the Order ("Controller", "you"), and governs Caresoft's processing of Personal Data on your behalf.
Four commitments that apply across every Caresoft product:
1. Personal Data is stored and processed within India.
2. We never sell your data, share it between customers, or use it for our own commercial purposes.
3. We never use it to train artificial intelligence models.
4. Every access by Caresoft personnel is logged with a stated reason, available to you on request.
1. Definitions
- "Applicable Law" — the Digital Personal Data Protection Act, 2023 and rules; the Information Technology Act, 2000 and the SPDI Rules, 2011; directions issued by CERT-In; and, where relevant, the EU and UK GDPR and the Swiss FADP.
- "Personal Data" — personal data processed by Caresoft on your behalf under the Agreement, as described in Annex A and the applicable product schedule.
- "Controller" / "Data Fiduciary", "Processor" / "Data Processor", "Data Subject" / "Data Principal", "Personal Data Breach" — as defined in Applicable Law. Under the DPDP Act, Controller means Data Fiduciary, Processor means Data Processor, and Data Subject means Data Principal.
- "Sub-processor" — a third party engaged by Caresoft to process Personal Data.
- "SCCs" — the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
- "Product Schedule" — the relevant section of Annex C.
2. Roles
| Data | You | Caresoft |
|---|---|---|
| Personal Data you or your users place in, or generate through, the product | Controller | Processor |
| Your user accounts and audit logs within the product | Controller | Processor |
| Your account, billing, contract and support records | Counterparty | Controller |
| Caresoft website and enquiry data | — | Controller |
| System logs Caresoft must retain by law | — | Controller |
| Aggregated, irreversibly de-identified operational metrics | — | Controller (subject to §17) |
Where you are yourself a processor for another controller, you warrant that you have authority to appoint Caresoft as sub-processor on these terms, and references to "Controller" apply to you as if you were the controller.
Significant Data Fiduciary. A customer processing personal data at volume or of a sensitive nature may be notified as a Significant Data Fiduciary under the DPDP Act, with additional obligations including a Data Protection Officer, independent audit and periodic impact assessment. Determining that is your responsibility; we will provide the information reasonably required to support it.
3. Scope and instructions
- Caresoft processes Personal Data only on your documented instructions. The Agreement, this DPA, your configuration of the product, and your support requests together constitute your complete instructions.
- We will inform you if, in our opinion, an instruction infringes Applicable Law, and may decline to act on an instruction that would.
- Processing required by law to which Caresoft is subject is permitted; where legally allowed, we will inform you before doing so. See §13 and §15.
- Details of processing are in Annex A and the applicable Product Schedule.
4. Your obligations
- Establish and maintain a lawful basis for the Personal Data you place in the product.
- Give the notices, and obtain and manage the consents, that Applicable Law requires of you.
- Not place in the product any category of Personal Data outside Annex A and the Product Schedule without our written agreement.
- Configure the product appropriately — retention, access, visibility and any product-specific control identified in the Product Schedule.
- Provision, review at least [quarterly], and revoke user access within [24] hours of a person leaving or changing role. We cannot know when your people change.
- Handle Data Principal requests as Controller (§11).
- Conduct any required data protection impact assessment.
- Notify us immediately of any incident on your side affecting Personal Data or the product (§12).
5. Our obligations
Caresoft will: process only on your instructions; ensure personnel are bound by confidentiality (§7); implement and maintain the measures in Annex B; engage Sub-processors only under §9; assist you under §11, §12 and §18; make available the information and access in §14; and return or delete Personal Data under §16.
6. Our access to your data
Caresoft personnel access Personal Data only where necessary to: resolve a support request you raised; investigate a security incident or suspected misuse; perform contracted managed services; or comply with valid legal process.
- Access is on a least-privilege, minimum-necessary basis, individually authenticated, never through shared accounts, and requires multi-factor authentication.
- Every access is logged with identity, timestamp, record accessed and stated reason. The log is available to you on request.
- We notify you of access made for reasons other than a request you raised, unless legally prohibited.
- Production Personal Data is never copied into development, test, training or demonstration environments. Those use synthetic or irreversibly anonymised data only.
- Caresoft personnel must not download, export, photograph or retain Personal Data on personal devices or accounts.
7. Personnel
- All personnel with potential access are bound by written confidentiality obligations surviving employment, subject to background verification appropriate to the role, and trained on data protection at induction and at least [annually].
- Access is provisioned by role, reviewed at least [quarterly], and revoked within [24] hours of role change or exit.
- We maintain a current list of roles with access to Personal Data and provide it on request.
8. Security measures
Caresoft implements and maintains the technical and organisational measures in Annex B, together with any additional measures in the Product Schedule, appropriate to the risk.
We may update these measures provided the overall level of security is not reduced. Reduction of any measure requires your written agreement. Material changes are notified.
Security is shared. You are responsible for your network, endpoints, credentials, user access hygiene, and any component running on your own infrastructure (agents, edge devices, gate hardware) as identified in the Product Schedule.
9. Sub-processors
- You give general written authorisation for Caresoft to engage Sub-processors.
- Each is engaged under a written contract imposing obligations materially equivalent to this DPA, including access logging and the localisation requirement in §10.
- Caresoft remains fully liable to you for its Sub-processors' acts and omissions.
- Notice. At least [30] days before a new Sub-processor begins processing Personal Data, by email to your named data protection contact.
- Objection. You may object within [15] days on reasonable, documented data protection grounds. We will propose an alternative; if none is agreed within [30] days, you may terminate the affected scope without penalty and receive a pro-rata refund of prepaid unused fees. That is your sole remedy for an objection.
- Emergency substitution. Where necessary for continuity or security, we may engage a replacement without prior notice and will inform you as soon as practicable.
For products processing health or financial data, we will not engage a Sub-processor located outside India for that data without your prior written consent. See the Product Schedule.
10. Location and transfers
- Personal Data is stored and processed within India, including production, backups and disaster recovery, unless the Product Schedule states otherwise.
- Caresoft support and engineering access is from India. Access from outside India is not permitted without your prior written consent.
- Transfers outside India are made only where permitted under Section 16 of the DPDP Act and any restriction notified by the Central Government, and only on your written instruction or as stated in the Product Schedule.
- EEA transfers. Where we process Personal Data subject to the GDPR and transfer it outside the EEA without an adequacy decision, the SCCs are incorporated, with Module Two (controller to processor) where you are a controller and Module Three (processor to processor) where you are a processor. Annex A and Annex B populate the corresponding SCC annexes. Clause 7 (docking) applies; Clause 9 option 2 (general authorisation, [30] days' notice) applies; Clause 11 optional redress body does not apply; Clause 17 governing law is the law of [Ireland]; Clause 18 forum is the courts of [Ireland].
- UK transfers. The UK International Data Transfer Addendum applies, with the SCCs as its Approved EU SCCs, Tables 1–3 populated by this DPA and its Annexes, and Table 4 "neither party".
- Swiss transfers. The SCCs apply with references to the GDPR read as references to the Swiss FADP, and the FDPIC as supervisory authority.
11. Data principal requests
- You have direct access to Personal Data in the product and can respond to requests yourself. That is the expected route.
- If we receive a request directly from a Data Principal relating to your Personal Data, we will not respond substantively, will refer them to you, and will inform you within [2] working days unless legally prohibited.
- Where you cannot fulfil a request through the product, we will provide reasonable assistance, at your cost where more than trivial, taking into account what is technically feasible.
- Erasure may be constrained by mandatory retention (§13), by immutable audit trails maintained for evidential and safety reasons, and by records you are separately required to keep. We will identify specifically what cannot be erased and why.
12. Breach notification
Caresoft will notify you of any Personal Data Breach affecting Personal Data we process for you without undue delay, and in any event within the period stated in your Product Schedule — 6, 24 or 48 hours depending on the sensitivity of the data concerned.
- Initial notification is in writing and, for the shorter windows, by phone to your named contact. Information is supplemented as the investigation proceeds.
- Notification will describe: the nature of the breach; categories and approximate numbers of Data Principals and records affected; likely consequences; measures taken and proposed; and a named contact.
- We preserve all evidence and will not alter or delete logs relating to the breach until the investigation is closed.
- You are responsible for notifying the Data Protection Board of India, any other regulator, and affected Data Principals. We provide the information and support required and will not communicate with your Data Principals without your written instruction.
- We provide a written root cause analysis with corrective and preventive actions within [10] working days.
- Notification is not an acknowledgement of fault or liability.
- You must notify us within [6] hours of any breach on your side affecting Personal Data or capable of affecting the product or other customers.
13. Mandatory Indian retention and reporting
As an Indian service provider, Caresoft is subject to directions issued by CERT-In. These are legal obligations that override conflicting instructions, including erasure instructions under §16.
- ICT system logs are retained for a minimum of 180 days within India and produced to CERT-In or another lawful authority on demand. These record activity about systems, not the contents of your data.
- Specified cyber incidents must be reported to CERT-In within 6 hours of our becoming aware. You must report qualifying incidents to us immediately.
- System clocks are synchronised to NPL or NIC network time servers.
- Where a product falls within the CERT-In direction on virtual server, cloud or VPN services, validated customer registration records are retained for at least 5 years after termination, as stated in the Product Schedule.
Where an instruction cannot be followed because of these obligations, we will tell you which obligation applies and precisely what is retained.
14. Audit and information
- On request we provide: our security documentation and completed due-diligence questionnaire; penetration test and vulnerability assessment summaries; access logs relating to your data; restore test and DR evidence; the current Sub-processor list; and any certification reports we hold.
- You may audit our processing of your Personal Data once per twelve months, and additionally following a Personal Data Breach or where required by a regulator or accreditation body.
- Audits require [30] days' notice (less following an incident or on regulatory direction), are conducted during business hours, are subject to confidentiality, and must not access other customers' data.
- You may use an independent auditor who is not a competitor of Caresoft and who signs a confidentiality undertaking.
- You bear your own audit costs; we bear ours for the annual audit and for any audit following a breach attributable to us.
- We cannot grant physical access to data centres we do not own. Facility assurance is provided through the hosting provider's published certifications.
15. Government access
If we receive a legally binding request from a public authority for Personal Data we process for you, we will assess its validity, challenge it where there are reasonable grounds, disclose only the minimum required, and notify you promptly unless legally prohibited — in which case we will seek a waiver and notify as soon as the prohibition lapses. Where feasible we will direct the authority to request the data from you directly. We maintain records of such requests to the extent lawful.
16. Return and deletion
- You may export Personal Data at any time during the term.
- On termination, Personal Data remains available for export for the period in your Product Schedule, after which it is deleted.
- Backups are deleted on their normal rotation, within [35] days.
- Deletion is subject to §13 and to records we must retain as Controller. Retained copies remain protected by this DPA and are processed only for the purpose requiring retention.
- Data relating to an open safety, security or fraud investigation is preserved until closure regardless of any deletion instruction.
- On written request we certify deletion once completed.
17. Secondary use and artificial intelligence
Caresoft will not: use your Personal Data for its own purposes; sell, licence or share it; use it for marketing or research; share it between customers; benchmark it in identifiable form; or use it to train, fine-tune, evaluate or improve any artificial intelligence or machine learning model, whether ours or a third party's.
- Aggregated operational metrics (usage counts, error rates, performance) may be used for capacity planning and product improvement only where irreversibly de-identified such that no Data Principal, user or customer can be identified or re-identified.
- Where a product feature uses a third-party AI service, it is disclosed in the Product Schedule, our contract with that provider prohibits training on submitted data, and — where the Product Schedule so states — the feature can be disabled entirely for your account.
- Any proposal to use Personal Data for research, benchmarking, publication or model development requires a separate written agreement and is outside this DPA.
18. Assistance
Taking into account the nature of processing and the information available to us, we will assist you — at your cost where the assistance is more than trivial — with your security obligations, breach notification, data protection impact assessments, and prior consultation with a supervisory authority. Because we do not have visibility into the substance of what you place in the product, much of this assistance takes the form of documentation, configuration information and platform-level records.
19. Liability
Liability under this DPA is subject to the limitations in the Agreement, save that the general cap does not apply to breach of data protection obligations where the Agreement so provides. Caps apply in the aggregate across the Agreement and this DPA, not separately. Nothing limits liability that cannot lawfully be limited, or a Data Principal's rights. Where the SCCs apply, nothing limits any liability that cannot be limited under them.
20. Term, precedence and changes
- This DPA takes effect with the Agreement and continues while Caresoft processes Personal Data for you.
- Precedence: any clinical-safety document identified in the Product Schedule → SCCs where applicable → Product Schedule → this DPA main body → the Agreement → other policies.
- We may update this DPA where required by a change in Applicable Law, a supervisory authority decision, or a change in approved transfer mechanisms, on [30] days' notice. Changes reducing protection require your written agreement.
- If any provision is invalid, it is modified to the minimum extent necessary and the remainder continues.
- Governed by the law of the Agreement, except that the SCCs are governed as stated in §10.
- No signature is required where you accept the Agreement online — this DPA applies automatically. A countersigned copy is available on request.
Annex A — Details of processing
A. Parties
| Data exporter | Data importer | |
|---|---|---|
| Name | The Customer in the Order | Caresoft Systems Private Limited |
| Address | As stated in the Order | 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107 |
| Contact | Customer's data protection contact | [email protected] |
| Role | Controller (or processor, where applicable) | Processor |
B. Description
| Item | Detail |
|---|---|
| Subject matter | Provision of the Caresoft product named in the Order |
| Duration | Term of the Agreement, plus the deletion periods in §16 and mandatory retention under §13 |
| Nature and purpose | As set out in the applicable Product Schedule |
| Categories of Data Principals | As set out in the applicable Product Schedule |
| Categories of Personal Data | As set out in the applicable Product Schedule |
| Special categories | As set out in the applicable Product Schedule |
| Frequency | Continuous for the duration of the Agreement |
| Retention | As instructed by you, within the product's configuration; defaults in the Product Schedule |
| Competent Supervisory Authority (SCC Annex I.C) | [The authority of the EEA member state where your EU representative is established, or where Data Principals are located] |
Annex B — Technical and organisational measures
Applies to all products. Additional or stricter measures per product are in Annex C.
| Area | Measures |
|---|---|
| Encryption | TLS 1.2+ in transit; encryption at rest for databases and backups; passwords stored using a modern one-way hash with a per-install pepper in addition to a per-user salt; secrets, API keys and third-party credentials stored encrypted with restricted retrieval |
| Access control | Role-based access; multi-factor authentication for all administrative access; least privilege; no shared accounts; server-side enforcement of portal and tenant separation; access reviewed [quarterly]; revocation within [24] hours of exit |
| Tenant isolation | Enforced at the data layer; no customer can reach another customer's data by any interface |
| Audit | Immutable logging of authentication, data access, record changes, configuration changes and exports, with identity, timestamp and reason; available to the customer |
| Environment separation | Production separated from development, test and training. No production Personal Data in non-production environments |
| Availability | Encrypted backups held in India in a separate failure domain; restore testing [quarterly]; DR exercise [annually]; recovery objectives per the applicable SLA |
| Vulnerability management | Regular patching; dependency and vulnerability scanning; penetration testing [annually] with summary available; documented remediation timelines by severity |
| Secure development | Peer-reviewed changes; version control; separated environments; release and rollback procedures; defect tracking; documented pre-release testing |
| Logging and monitoring | Authentication, error and integrity telemetry; alerting on anomalous access; ICT system logs retained ≥180 days in India; clocks synchronised to NPL/NIC |
| Incident response | Documented plan with defined severities and escalation; on-call coverage; customer notification per §12; CERT-In reporting within 6 hours; evidence preservation; root cause analysis within [10] working days |
| Personnel | Background verification; confidentiality agreements surviving employment; data protection training at induction and [annually]; documented joiner-mover-leaver process |
| Sub-processor governance | Pre-engagement assessment on security, certifications, jurisdiction and incident history; equivalent contractual obligations; annual review; public disclosure |
| Physical | Hosting in access-controlled facilities within India under published certifications; media decommissioning by the hosting provider under its certified procedures |
| Deletion | Secure deletion on instruction with written certification; backup expiry within [35] days |
Annex C — Product schedules
Find your product. Read it with the main body; where they differ, this schedule prevails.
C1 Sloto — scheduling
| Item | Detail |
|---|---|
| Nature and purpose | Publishing availability, accepting and managing bookings, creating calendar events, sending confirmations and reminders |
| Data Principals | Hosts (your users); Invitees (people who book with them); guests added to invitations |
| Personal Data | Name, email, phone, time zone, job title, organisation, booking form responses, meeting date/time/type, reschedule and cancellation records, calendar free/busy and event data from connected accounts |
| Special categories | Not permitted. Health, financial account, biometric or government-identifier data must not be collected through booking forms without written agreement |
| Third-party services | Calendar and conferencing providers connected by the Host act as independent controllers once data reaches them. Google user data is handled under the Limited Use requirements |
| Breach notification | [48] hours |
| Export window on termination | [30] days |
| Customer-side responsibility | Booking form design; notices to Invitees; recipient lists for notifications |
| AI features | None |
C2 ClaimX — cashless claims
| Item | Detail |
|---|---|
| Nature and purpose | Preparing, validating, assembling, transmitting and tracking the Hospital's claims to payers over NHCX, payer APIs and portals |
| Data Principals | Patients; the Hospital's staff users |
| Personal Data | Patient identifiers, policy and member details, diagnosis and procedure codes, admission and discharge details, clinical documents, bill line items, claim and query correspondence, transmission and acknowledgement records |
| Special categories | Yes — health data throughout. Processed under the additional safeguards in this schedule |
| Onward transmission | Payers become independent controllers on receipt. Caresoft cannot retrieve, correct or delete data from a payer's systems |
| Localisation | Data held in India. No Sub-processor outside India for claim data without prior written consent |
| Breach notification | [6] hours |
| Export window on termination | [30] days; in-flight claims accessible for a transition period of not less than [30] days |
| Retention | As instructed, consistent with medical-record, tax and payer-contract obligations. Claim records are frequently needed years later for disputes and audits — set retention accordingly |
| AI features | None. Any future AI feature requires prior written consent before claim data is sent to a provider |
C3 Screenify — hospital display and media
| Item | Detail |
|---|---|
| Nature and purpose | Scheduling and displaying queue information, hospital content and advertising; monitoring screens; proof-of-play reporting |
| Data Principals | Patients whose queue or appointment information is displayed; the Hospital's staff users; individuals appearing in content |
| Personal Data | Token and appointment identifiers, counter or room, doctor or department, and — only where the Hospital configures it — patient name or partial identifier; staff accounts and approval records |
| Special categories | Displaying a patient's identifier against a named ward can disclose a condition. Clinical information must never be displayed in any zone. Default is token-only |
| No audience measurement | No cameras, face detection, footfall sensors or mobile tracking. No audience data is collected or held. Any such capability requires prior written agreement and a separate privacy assessment |
| No targeting | Advertising is never selected on the basis of patient information or who is watching |
| Advertisers | Receive proof of play for their own campaigns only — no queue data, no patient data, no audience data |
| Breach notification | [24] hours |
| Retention defaults | Queue data [30] days; proof of play [24] months; content and approval records term plus [24] months |
| Customer-side responsibility | Screen placement and what is displayed on it; content approval; physical security of screens and players |
C4 Sahi — writing assistant
| Item | Detail |
|---|---|
| Nature and purpose | Checking text submitted for correction and returning suggestions; usage reporting |
| Data Principals | Your users; any individual mentioned in text they submit |
| Personal Data | The passage submitted for checking; user account details; usage counts and error categories |
| Text is not stored | Submitted text is held in memory for the duration of the check and discarded. Check results are cached against a hash of the passage for [7] days and pruned nightly; caching can be disabled for your organisation on request |
| Field exclusions | Password, payment and OTP fields are excluded on-device before processing. Organisations may extend exclusions by domain, URL or field |
| Administrator visibility | Usage counts and error categories only. Administrators cannot see the text, the recipient, or the site. Insights reporting is off by default and aggregates before any phrase appears |
| AI features | Where enabled, the passage is sent to our AI provider. Contractually prohibited from training on it. Can be disabled entirely per organisation or department; rule-based checking continues without it |
| On-premise deployment | Where installed on your infrastructure, no text, metadata or usage data reaches Caresoft and most of this DPA does not apply to that text |
| Breach notification | [24] hours |
| Customer-side responsibility | Deciding where Sahi is enabled; configuring exclusions for sensitive systems; notifying your people that it is deployed and what administrators can see |
C5 CareHire — healthcare jobs
| Item | Detail |
|---|---|
| Role note | CareHire is primarily a Controller in its own right for job seeker profiles. This schedule applies where Caresoft acts as processor for an Employer — for example in managing an Employer's applicant records |
| Nature and purpose | Hosting profiles, delivering applications, employer verification, fraud detection |
| Data Principals | Job seekers; employer staff users |
| Personal Data | Identity and contact details, qualifications, council registration, experience, employment history, resumes and certificates, application and message records |
| Employer as independent controller | On receiving an application, the Employer becomes an independent controller of its copy. Deleting a CareHire profile does not delete what an Employer already holds |
| Employer restrictions | Use only for the role applied to or a closely comparable one; no sale, publication or third-party sharing; no marketing; delete when no longer needed |
| Prohibited data | We do not require and ask users not to upload government identity numbers. Caste, religion, community and marital status are not collected and must not be used to filter |
| Breach notification | [24] hours |
| Retention | Profiles for account life plus [30] days; inactive accounts notified at [24] months; fraud investigation records [5] years |
| AI features | Matching uses structured fields only; no AI processing of resume content without prior notice |
C6 Caresoft VMS — visitor management
| Item | Detail |
|---|---|
| Nature and purpose | Verifying visitor mobile numbers, issuing gate passes, recording entry and exit, enforcing visiting limits, reporting |
| Data Principals | Visitors; patients named as the subject of a visit; the Hospital's staff users |
| Personal Data | Visitor name, mobile, optional email, who they are visiting, purpose, entry and exit times, pass tokens, device and IP data |
| Inference risk | A visitor record can reveal that a patient is admitted and to which ward — and therefore, by inference, their condition. Treated as sensitive throughout |
| Not collected | No photographs, no biometrics, no government identity numbers, no location tracking. Hospitals must not repurpose fields to capture them |
| Hospital system interface | Receives admission status, ward, doctor lists and visitor limits. No clinical data crosses this interface |
| OTP delivery | Via a WhatsApp Business Solution Provider as Sub-processor; number and OTP text only |
| Breach notification | [24] hours |
| Retention defaults | Visit records [90] days; OTP records [24] hours; pass tokens purged within [7] days; sync log [30] days |
| Customer-side responsibility | Displaying the visitor notice; form design and minimisation; keeping ward detail off passes; maintaining a manual alternative |
C7 Sales Sathi — accounting BI
| Item | Detail |
|---|---|
| Nature and purpose | Importing accounting data, storing it, computing dashboards and reports, scheduled delivery |
| Data Principals | Your customers, suppliers and employees named in your ledgers; your platform users |
| Personal Data | Party names and contact details, GSTIN, transaction records, and — where payroll ledgers are connected — employee names and salary information |
| Minimisation | Connect only the companies and periods you need. Exclude payroll ledgers where dashboards do not require them |
| Read-only | The agent reads only, through documented interfaces. It cannot write to, alter or delete anything in your accounting software |
| Not a backup | The Platform holds a working copy for reporting. It is not structured to restore your accounting system |
| Commercial sensitivity | Margins, customer lists, supplier terms and salaries are treated as your confidential information. Never benchmarked in identifiable form or shared between customers |
| AI features | Where the prompt bar is used, the prompt and the relevant schema and figures are sent to our AI provider, contractually prohibited from training on them. Can be disabled entirely |
| Breach notification | [24] hours |
| Retention | Imported data for the subscription term, deleted within [30] days of termination after the export window; prompt history [13] months; audit log [24] months |
| Customer-side responsibility | The agent machine; lawful basis for the personal data in your ledgers; scheduled report recipient lists |
C8 Caresoft eICU and Aura Cloud
These products have their own standalone DPAs, reflecting clinical-safety and infrastructure-reseller obligations that do not generalise. See the Caresoft eICU DPA and the Aura Cloud DPA. This master DPA does not apply to them.
Execution
Where the Agreement is accepted online, this DPA is incorporated automatically and no signature is required. Customers requiring a countersigned copy may complete the block below and send it to [email protected].
| Customer (Controller) | Caresoft Systems Private Limited (Processor) |
|---|---|
| Entity: ______________________ Product(s): ______________________ Name: ______________________ Title: ______________________ Data protection contact: ______________ Signature: __________________ Date: ______________________ |
Entity: Caresoft Systems Private Limited Name: ______________________ Title: ______________________ Signature: __________________ Date: ______________________ |
