Data Processing Agreement (DPDP)

AI clinical documentation SaaS — pay per report.

Version 2026-07-in-v2 · Last updated: July 2026

Draft — pending counsel review. Cleannote may replace this text with counsel-approved wording; you may be asked to re-accept a new version. Acceptance in the Cleannote application (clickwrap) is the intended binding method.

Parties and effective acceptance

This Data Processing Agreement (“DPA”) is entered into between the practice or organization accepting it (the “Data Fiduciary” — the entity that determines the purpose and means of processing personal data you upload) and Cleannote (the “Data Processor” — the service provider that processes that data on your instructions). This DPA becomes effective when an authorized individual accepts it in the Cleannote application by providing their name and confirming authority to bind the Data Fiduciary (electronic / clickwrap acceptance). Cleannote records the agreement type, version, acceptance timestamp, IP address, user agent, signer name, and a cryptographic hash of the accepted text as evidence of assent.

Scope and applicable law

This DPA applies when Cleannote processes personal data on your documented instructions to deliver Cleannote’s clinical documentation services for accounts associated with India, under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and rules issued thereunder, together with any other Indian privacy laws that mandatorily apply to that processing. “Personal data” has the meaning given in the DPDP Act.

Purpose limitation and instructions

Cleannote will process personal data only to provide the Cleannote medical documentation service (audio or text processing, drafting and formatting, style learning from samples you upload, secure delivery of outputs, and related support) and not for unrelated purposes. Processing described in Cleannote’s product documentation and your in-product configuration constitutes your instructions. Cleannote will not sell personal data or use it for third-party advertising.

Security safeguards

Cleannote will implement reasonable security safeguards designed to prevent unauthorized access, disclosure, alteration, or loss of personal data, including encryption of finished clinical outputs at rest using AES-256-GCM (or equivalent or stronger), transmission over HTTPS/TLS, and workforce access limited to personnel who need access to operate or support the service.

Retention and deletion

Session audio and generated reports are retained for a limited operational window (currently about six (6) days) and then deleted under Cleannote’s retention policy, except where longer retention is required by law or a documented legal hold. Samples, letterhead, and feedback you choose to keep remain until you remove them or close the account. After account closure, or upon your documented written request, Cleannote will delete remaining personal data it holds as processor, subject to legal exceptions and backup/deletion cycle limitations reasonably disclosed in product documentation.

Cross-border processing

Cleannote may use infrastructure or subprocessors that process personal data outside India where needed to operate the service, subject to applicable DPDP transfer requirements and contractual safeguards with those providers. By accepting this DPA and using the service, you instruct Cleannote to undertake such transfers as necessary to deliver the service.

Assistance with data principal requests

Taking into account the nature of processing, Cleannote will provide reasonable assistance to help you respond to data principal requests under the DPDP Act regarding personal data Cleannote processes for you, within timelines you and Cleannote agree after a documented request. You remain responsible for verifying the requestor’s identity and for the substantive response.

Personal data breaches

Cleannote will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, and will provide information reasonably available to help you meet any notification duties you may have under applicable law, including a description of the incident, likely impact, and mitigation steps, supplemented as more information becomes available.

Subprocessors

Cleannote may engage subprocessors (including cloud and AI providers) under written terms requiring appropriate protection of personal data. Cleannote remains responsible to you for subprocessors’ processing of personal data under this DPA.

Term, amendments, and miscellaneous

This DPA is effective upon clickwrap acceptance in the Cleannote application and continues while Cleannote processes personal data for your account. Either party may terminate for material breach not cured within thirty (30) days after written notice. Confidentiality, deletion, and incident-notification duties survive as applicable. Cleannote may publish updated versions when law or operations require; continued paid use may require re-acceptance of the current version. This DPA, with Cleannote’s applicable terms of service, is the agreement on processor handling of personal data for the service; on that subject this DPA controls over conflicting informal discussions. This DPA is not legal advice; you remain responsible for DPDP Act and professional compliance applicable to your practice.

Document type: DPA · Region: IN · Review & accept in your account