Plain English Verified

Data Processing Agreement (DPA)

Last updated: February 25, 2026

This Data Processing Agreement applies when BimaHaq acts as a Data Processor on behalf of a corporate client — for example, when we run a Group Insurance Claims Desk for your employees. It is entered into alongside the engagement letter for that service and reflects the roles and duties of the Digital Personal Data Protection Act, 2023 (the 'DPDP Act').

Roles

You (the corporate client) are the Data Fiduciary and determine the purposes and means of processing. BimaHaq is the Data Processor and processes personal data only on your documented, lawful instructions and for the engagement — never for our own purposes. If we believe an instruction breaches the law, we will tell you.

Subject matter, purpose, and duration

We process personal data to deliver the claims-desk / advisory service described in the engagement letter, for the duration of the engagement. After it ends, we return or delete the data as set out below, keeping only what a law requires us to retain.

Categories of data and data principals

Data principals: your employees and their dependents. Categories: identity and contact details, policy and claim details, claim files and correspondence, and health/medical information contained in claim documents. Health data is sensitive and is processed only where consent or another lawful basis exists.

Our obligations as processor

We will: process only on your instructions; keep the data confidential and limit access to personnel who need it and are under confidentiality obligations; apply the security measures below; assist you, so far as we can, to respond to data-principal requests and to meet your breach-notification and consultation duties; and make available the information you reasonably need to show compliance.

Security measures

We apply security appropriate to the sensitivity of the data — including encryption in transit, encryption at rest at the database layer, role-based and least-privilege access, hashed credentials, signed short-lived access tokens, strict file-type and size validation on uploads, rate limiting, and audit logging of security-relevant actions. Our broader security programme and regulatory alignment (IRDAI Information and Cyber Security Guidelines 2023 and BIS IS 19493:2025) are described on our Security page.

Sub-processors

We engage a small set of vetted sub-processors: Razorpay (payment processing), Resend (transactional email), and MongoDB Atlas (database hosting), with document storage on our own servers by default (and Cloudinary only if we enable it). Hosting is configured in India in line with IRDAI localisation principles. Each sub-processor is bound to data-protection obligations no less protective than these. We provide a current sub-processor list on request and give you at least 30 days' notice of any intended change so you can object.

Assisting with data-principal rights

If a data principal exercises a right (access, correction, erasure, or withdrawal of consent) directly with us, we will refer them to you and assist you to respond within the time the DPDP Act allows.

Personal data breach

We will notify you without undue delay — and in any event within 24 hours — of becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations. We also report cyber incidents to CERT-In within 6 hours as required by the CERT-In Directions (2022).

Audit, return, and deletion

You may audit our compliance with this DPA once a year on reasonable notice (or after a breach). On termination, at your choice we return or securely delete your personal data — and cause our sub-processors to delete their copies — within 30 days, retaining only what a specific law requires, under restricted access, until that period ends.

Precedence

Where this DPA conflicts with the general Terms of Use on the handling of your employees' personal data, this DPA prevails. Liability under the engagement is as set out in the engagement letter.

Questions about this page?

Write to info@bimahaq.com. We respond within one working day.