Data Processing Agreement
This DPA governs how Tokenn processes personal data on behalf of clinics as a Data Processor under India's Digital Personal Data Protection Act 2023.
Last updated 19 May 2026
This DPA is incorporated into the Tokenn Terms of Service and applies automatically to all clinic accounts. No separate signature is required.
1. Definitions
| Term | Meaning |
|---|---|
| Data Fiduciary (Controller) | The clinic that determines the purpose and means of processing patient personal data |
| Data Processor | Cyberzio Innovations Pvt Ltd, which processes data on behalf of the Data Fiduciary |
| Data Principal (Data Subject) | The patient whose personal data is processed |
| Personal Data | Any data relating to an identified or identifiable patient, including name and phone number |
| Processing | Any operation on personal data — collection, storage, use, transmission, deletion |
| DPDP Act | Digital Personal Data Protection Act 2023 (India) |
2. Scope and relationship
The clinic ("Data Fiduciary") engages Cyberzio Innovations Pvt Ltd ("Data Processor") to process personal data of patients for the purpose of managing outpatient queues and sending WhatsApp notifications.
Tokenn processes personal data only on documented instructions from the clinic and does not process data for any other purpose.
3. Categories of personal data processed
| Category | Data elements | Data subjects |
|---|---|---|
| Patient contact data | Name, phone number | Clinic patients |
| Queue data | Token number, timestamp, queue position, estimated wait time | Clinic patients |
| Visit reason | Short free-text reason and category entered by staff at token issue (e.g. "fever", "follow-up") — encrypted at rest | Clinic patients |
| Communication data | Inbound WhatsApp message content (for AI queue status queries) | Clinic patients |
| Staff identity data | Name, mobile number, email, hashed MPIN, role | Clinic staff |
Tokenn does not process medical records, lab results, diagnostic reports, scan images, clinical photographs, prescriptions or treatment notes. The product has no facility to upload or store them.
4. Obligations of Tokenn as Data Processor
4.1 Lawful processing
Tokenn will:
- Process personal data only on the clinic's documented instructions.
- Not process data for any purpose other than providing the Tokenn service.
- Implement appropriate technical and organisational measures to protect personal data.
- Assist the clinic in responding to data principal rights requests (access, correction, erasure) within 72 hours of the clinic's request to us.
- Delete or return all personal data upon termination of the service agreement, within 30 days.
- Maintain records of processing activities as required by the DPDP Act.
4.2 Confidentiality
Tokenn ensures that all personnel with access to clinic personal data are bound by confidentiality obligations.
4.3 Security measures
Tokenn implements the following controls (see Security page for full detail):
- AES-256 encryption of WhatsApp credentials at rest.
- AES-256 encryption of patient phone numbers and visit reasons at rest.
- TLS 1.2+ encryption in transit for all data flows.
- Role-based access control and JWT authentication.
- Clinic-level data isolation — no cross-clinic data access.
- Daily automated database backups with 7-day retention.
5. Sub-processors
Tokenn engages a small set of sub-processors, by category, to provide the service. The clinic authorises them by accepting the Terms of Service. A current list naming the specific providers, with their locations, is available to the clinic on request.
| Category | Purpose | Data transferred | Location |
|---|---|---|---|
| Managed database | Database storage | All clinic and patient data | India |
| Application hosting | Compute / processing | Data in transit during processing | Germany (EU) |
| WhatsApp messaging | Deliver messages to patients | Patient phone number, message content | USA / Global |
| AI provider | AI replies to patient messages | The patient's own message text (may contain personal data they share) + queue/clinic context; no stored identifiers | USA / Global |
| Website analytics | Usage analytics (marketing pages, with consent) | Anonymised IP, page views — no patient or clinic account data | USA / Global |
| Payment processing | Subscription billing | Billing contact info (no card data) | India |
| Real-time queue store | Queue state / pub-sub | Queue state, token counts | India |
Tokenn will notify the clinic at least 14 days before engaging any new sub-processor. The clinic may object within 14 days; if no resolution is reached, either party may terminate the agreement.
6. International data transfers
Some sub-processors — application hosting (Germany / EU) and the WhatsApp messaging, AI, and analytics providers — are located outside India. Tokenn ensures such transfers occur only where:
- The receiving country is notified by the Indian Government as having adequate data protection, or
- Appropriate standard contractual clauses or equivalent safeguards are in place.
7. Data retention and deletion
| Data type | Retention | Deletion |
|---|---|---|
| Patient tokens | 90 days from creation | Auto-deleted after retention period |
| Queue state | Resets daily at midnight | Auto-cleared |
| Staff accounts | Duration of active subscription | Deleted 30 days after cancellation |
| Clinic data | Duration of active subscription | Deleted within 30 days of written request or cancellation |
| Server logs | 30 days | Auto-deleted |
8. Obligations of the clinic as Data Fiduciary
The clinic undertakes to:
- Obtain appropriate consent from patients before collecting their personal data for queue management.
- Have a lawful basis under the DPDP Act for processing patient data.
- Provide patients with a notice explaining that their phone number will be used to send WhatsApp queue notifications.
- Not instruct Tokenn to process personal data in a manner that would violate applicable law.
- Promptly inform Tokenn of any data principal rights requests that require Tokenn's assistance.
9. Breach notification
Tokenn will notify the clinic within 72 hours of becoming aware of a personal data breach that affects clinic data. The notification will include:
- Nature of the breach and categories of data affected.
- Approximate number of data principals affected.
- Likely consequences of the breach.
- Measures taken or proposed to address the breach.
10. Audit rights
The clinic may request a written summary of Tokenn's data protection practices once per calendar year, at no charge. Requests can be made on WhatsApp +91 86674 52543. Tokenn will respond within 30 days.
11. Term and termination
This DPA is effective for the duration of the clinic's subscription. On termination:
- Tokenn will cease all processing of clinic personal data.
- The clinic may request a data export within 30 days of termination date.
- All personal data will be permanently deleted within 30 days of termination, unless legal retention obligations apply.
12. Contact
Data Protection Officer — WhatsApp +91 86674 52543
Cyberzio Innovations Pvt Ltd, Tamil Nadu, India
Operated by Cyberzio Innovations Pvt Ltd for TOKENN — WhatsApp queue and token management for clinics in India. See also Privacy Policy, Terms of Service, Security and Data Processing Agreement.