TERMS OF SERVICE AND PRIVACY POLICY

RecSoon Tx — operated by CareSutra Technologies Private Limited

TERMS OF SERVICE AND PRIVACY POLICY

RecSoon Tx — Therapist Practice Management Platform

Issued by: CareSutra Technologies Private Limited
Document Reference: CSTPL-LEGAL-001
Version: 1.0
Effective Date: 20 June 2026
Applicable Jurisdiction: Republic of India
Governing Legislation: Information Technology Act 2000; Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021; Digital Personal Data Protection Act 2023; Indian Contract Act 1872; Rehabilitation Council of India Act 1992; Indian Medical Council Act 1956 (as applicable)

Definitions

For the purposes of this Agreement, the following terms shall have the meanings ascribed to them below:

"Agreement" means these Terms of Service and Privacy Policy, as amended from time to time, which constitutes a legally binding contract between CareSutra Technologies Private Limited and the User.

"Applicable Law" means all laws, statutes, regulations, rules, orders, notifications, and judicial or quasi-judicial decisions in force in the Republic of India that are applicable to the subject matter of this Agreement, including without limitation the DPDPA 2023, the IT Act 2000, and applicable professional regulations governing the practice of healthcare professionals.

"Company", "CareSutra", "we", "us", "our" means CareSutra Technologies Private Limited, a company incorporated under the Companies Act 2013, bearing Corporate Identification Number U62090KA2026PTC219233, with its registered office at Kanadal Street, Near Water Tank, Kote, Chickmagalur, Karnataka – 577101, India.

"Confidential Information" means any non-public information relating to the business, operations, technology, patient data, or proprietary processes of either party, disclosed in connection with this Agreement.

"Data Fiduciary" has the meaning ascribed to it under Section 2(i) of the DPDPA 2023.

"Data Principal" has the meaning ascribed to it under Section 2(j) of the DPDPA 2023.

"Data Processor" has the meaning ascribed to it under Section 2(k) of the DPDPA 2023.

"DPDPA 2023" means the Digital Personal Data Protection Act 2023 (No. 22 of 2023), as amended, and any rules or regulations made thereunder.

"IT Act 2000" means the Information Technology Act 2000 (No. 21 of 2000), as amended, and any rules made thereunder.

"Patient" means any individual in respect of whom a User creates or maintains a clinical record on the Platform.

"Patient Data" means Personal Data relating to a Patient created or maintained by a User on the Platform in the course of that User's clinical practice, including identity data (name, date of birth, gender, contact details), clinical baseline data, treatment records (session notes, exercise logs, parameter measurements, assessment scores), progress records (trend data, goal attainment, reports), and any session media. Patient Data excludes the User's own Personal Data and the Company's Platform Data.

"Personal Data" has the meaning ascribed to it under Section 2(t) of the DPDPA 2023.

"Platform" means the RecSoon Tx mobile application (iOS and Android), any associated web interfaces, APIs, and backend systems operated by the Company, and all updates, upgrades, and new versions thereof.

"Platform Data" means (i) aggregated, de-identified operational, usage, and performance metrics derived from the Platform that do not allow identification of any individual User or Patient, and (ii) data created by the Company in the course of operating the Platform (such as system logs, error records, access audit entries) that is not Patient Data.

"RecSoon Tx" means the therapist-facing practice management platform operated by the Company under this Agreement. Any other applications the Company may operate are separate products governed by their respective terms.

"Sensitive Personal Data" means Personal Data that includes health data, biometric data, or any other category designated as sensitive under DPDPA 2023 and rules thereunder.

"Therapist Data" means Personal Data relating to a User in that User's capacity as an account holder, including identity (name, profile photograph), authentication credentials, professional registration data, contact details, device identifiers, Platform-usage telemetry, and consent records. Therapist Data excludes Patient Data.

"User", "you", "your" means the licensed healthcare professional who has accepted this Agreement and holds a registered account on RecSoon Tx.

Part I — Terms of Service

1. Formation and Acceptance of Agreement

1.1 This Agreement is entered into between CareSutra Technologies Private Limited and the User upon the User's affirmative action of tapping "I Agree — Activate Account" during the RecSoon Tx registration process.

1.2 Such affirmative action constitutes a valid, binding, and enforceable electronic contract within the meaning of Section 10A of the IT Act 2000. The Company's servers shall maintain an irrebuttable audit record of each User's acceptance, comprising the timestamp (UTC), device identifier, IP address (if available), and the version number of this Agreement accepted.

1.3 If you do not agree to this Agreement in its entirety, you must not create an account, must not access the Platform, and must immediately cease any existing use.

1.4 This Agreement governs your use of RecSoon Tx only. Any other applications the Company may operate are distinct products subject to their own terms and are not governed by this Agreement.

2. Eligibility Requirements

2.1 Access to RecSoon Tx is restricted exclusively to licensed or registered healthcare professionals. You represent and warrant that at all times during your use of the Platform:

(a) you hold a valid, subsisting, and unsuspended licence or registration to practise in your clinical discipline — including physiotherapy, speech-language pathology, occupational therapy, respiratory therapy, swallow therapy, or a substantially similar clinical discipline — under the Rehabilitation Council of India Act 1992, the Indian Medical Council Act 1956, or any applicable state or central legislation;

(b) you are a natural person of at least eighteen (18) years of age;

(c) you are not subject to any court order, disciplinary order, regulatory directive, or professional body ruling that restricts or prohibits you from treating patients or accessing patient health records;

(d) you are using the Platform exclusively for bona fide clinical practice in connection with Patients under your active professional care; and

(e) all information provided by you during registration is accurate, complete, and current.

2.2 The Company reserves the right, at its sole discretion, to verify the credentials of any User at any time. The Company may require you to submit documentary evidence of your professional registration upon request. Failure to provide such evidence within ten (10) business days of a request shall be grounds for suspension of your account.

2.3 In the event any of the representations in Clause 2.1 ceases to be true, you must immediately notify the Company at legal@caresutra-tech.com and suspend your use of the Platform pending resolution.

3. Account Registration and Security

3.1 You are solely responsible for maintaining the confidentiality and security of your account credentials, including your password, PIN, and any biometric authentication enrolled on your device.

3.2 You must:

(a) enable biometric lock or PIN authentication on RecSoon Tx at all times when Patient Data is accessible through your account;

(b) log out or engage the app lock when leaving a shared or unattended device;

(c) use unique, strong credentials not shared with any other service; and

(d) report any known or suspected unauthorised access to your account to security@caresutra-tech.com without undue delay, and in any event within twenty-four (24) hours of becoming aware.

3.3 You shall not permit any other person — including colleagues, assistants, trainees, or family members — to access the Platform using your credentials, whether or not such person is themselves a healthcare professional.

3.4 The Company shall not be liable for any loss, damage, or breach arising from your failure to comply with this Clause 3.

3.5 The Company may suspend your account without prior notice if automated systems or security personnel detect access patterns consistent with a credential compromise or unauthorised use.

4. Conduct Obligations

4.1 Restriction to Patients Under Active Care. You shall create and maintain Patient records on the Platform only in respect of individuals with whom you have an active, bona fide therapeutic relationship at the time of record creation. For the avoidance of doubt:

(a) you shall not create records for prospective patients prior to the commencement of a therapeutic relationship;

(b) you shall not create or access records for Patients assigned to other healthcare professionals unless you are a formally constituted member of that Patient's care team with the Patient's knowledge and consent;

(c) you shall not create test, demonstration, or fictitious Patient profiles using real personal data; and

(d) you shall not use the Platform to manage Patient records on behalf of a third party who is not themselves a registered User.

4.2 Accuracy of Clinical Records. All clinical data — including session notes, exercise records, parameter measurements, assessment scores, and progress entries — entered by you into the Platform must accurately reflect your clinical observations, assessments, and interventions to the best of your professional knowledge at the time of entry. You shall not:

(a) create or alter records so as to misrepresent the date, content, or circumstances of any clinical session;

(b) enter fabricated, estimated, or speculative data as if it were directly observed;

(c) delete or modify records for the purpose of concealing adverse events, missed appointments, or contraindicated interventions; or

(d) reproduce another Patient's records in a different Patient's file without a documented clinical basis.

4.3 Prior Patient Consent. Before creating any Patient record on the Platform, you must have obtained the Patient's (or, in the case of a minor, the parent's or legal guardian's) informed consent in accordance with Clause 11.3 of this Agreement and applicable law. The use of RecSoon Tx's integrated digital consent flow (as specified in the applicable product documentation) shall constitute prima facie evidence of consent collection. Where consent is obtained through an alternative documented process, you must retain evidence of such consent.

4.4 Scope of Practice. You shall not use the Platform to document, manage, or provide services outside your licensed scope of clinical practice. Any notes or records entered outside your licensed scope are your sole professional and legal responsibility.

5. Permitted and Prohibited Uses

5.1 Permitted Uses. Subject to the terms of this Agreement, you are licensed to use the Platform to:

(a) create, document, and maintain clinical records for Patients under your active care;

(b) design and manage care plans, exercise protocols, and rehabilitation programmes;

(c) record session notes, parameter measurements, exercise completions, and audio notes;

(d) generate progress reports and discharge summaries for Patients, their families, and treating clinicians;

(e) schedule and manage your clinical appointments; and

(f) communicate clinical information to other members of a Patient's care team through the Platform's designated functionality.

5.2 Prohibited Uses. You shall not:

(a) share, transfer, sell, sublicense, or otherwise make available your account or any access credentials to any third party;

(b) use the Platform for any purpose that is unlawful, harmful, or contrary to applicable professional ethics;

(c) access, copy, download, or export Patient Data for use on any third-party platform without the explicit, documented consent of the Patient;

(d) attempt to gain access to accounts, records, or data that you are not authorised to access;

(e) reverse-engineer, decompile, disassemble, or extract any portion of the Platform's software, source code, algorithms, or proprietary exercise content;

(f) introduce any virus, malware, or other harmful code into the Platform;

(g) use the Platform in any manner that places an unreasonable or disproportionate load on the Company's infrastructure;

(h) frame, mirror, or scrape content from the Platform without the Company's prior written consent; or

(i) remove, alter, or obscure any proprietary notices, labels, or branding on the Platform.

6. Intellectual Property Rights

6.1 The Company is and shall remain the exclusive owner of all right, title, and interest in and to the Platform, including all software (source code and object code), design elements, user interface components, exercise libraries, protocol templates, algorithm logic, and any derivative works or improvements thereto, whether or not patentable or registerable ("Company IP"). Nothing in this Agreement transfers or licenses any Company IP to you except the limited, non-exclusive, non-transferable, revocable licence granted in Clause 6.3.

6.2 You retain ownership of the clinical data, session notes, and Patient records you create through the Platform ("User Content"). User Content is Patient Data in respect of which you are the Data Fiduciary (see Clause 15). You grant the Company a limited, non-exclusive, royalty-free licence to host, store, transmit, process, and display User Content solely to the extent necessary to provide the services contemplated by this Agreement, in the Company's capacity as your Data Processor. The Company makes no claim to ownership of User Content.

6.3 Subject to your compliance with this Agreement, the Company grants you a limited, personal, non-exclusive, non-transferable, revocable licence to access and use the Platform solely for the purposes set out in Clause 5.1 during the term of this Agreement.

6.4 Any feedback, suggestions, or ideas you submit to the Company regarding the Platform may be used by the Company freely, without attribution or compensation, and shall not be treated as confidential.

7. Clinical Decision Disclaimer

7.1 RecSoon Tx is a clinical documentation and practice management tool. It is not a medical device, diagnostic system, clinical decision support system, or electronic health record (EHR) within the meaning of any applicable regulatory framework.

7.2 The Platform does not:

(a) diagnose, screen for, or rule out any clinical condition;

(b) prescribe, recommend, or validate the clinical appropriateness of any treatment, exercise, parameter threshold, or intervention; or

(c) replace the independent professional judgement of the treating therapist.

7.3 All clinical decisions — including the selection of protocols, the setting of parameter targets, the interpretation of progress data, and the determination of treatment endpoints — remain entirely within your professional judgement and responsibility. Protocol templates and exercise libraries available on the Platform are provided as documentation aids only. They are not clinical guidelines and have not been reviewed or endorsed by the Rehabilitation Council of India or any other regulatory body.

7.4 You acknowledge that you have the training, licensure, and clinical competence to use the Platform in connection with your Patients, and that you will exercise your independent professional judgement at all times.

8. Limitation of Liability

8.1 To the fullest extent permitted by Applicable Law, the Company shall not be liable for:

(a) any indirect, special, incidental, consequential, or punitive damages arising out of or in connection with your use of, or inability to use, the Platform;

(b) any clinical adverse event, patient harm, or malpractice claim arising from clinical decisions made by you in connection with your use of the Platform;

(c) loss of or corruption to Patient Data resulting from your failure to comply with the security obligations in Clause 3 or your Fiduciary obligations in Clauses 11 and 15;

(d) any loss arising from your use of the Platform outside the scope of your professional licence; or

(e) any loss arising from force majeure events, including without limitation natural disasters, acts of government, pandemic, cyberattacks, or failure of third-party telecommunications infrastructure.

8.2 Nothing in this Clause 8 shall exclude or limit the Company's liability for:

(a) death or personal injury caused by the Company's gross negligence or wilful misconduct;

(b) fraud or fraudulent misrepresentation by the Company; or

(c) any liability that cannot be excluded or limited under Applicable Law.

9. Pricing and Subscription

9.1 Current Pricing — Free Access. As at the Effective Date of this Agreement, RecSoon Tx is made available to registered Users at no charge ("Free Tier"). No subscription fee, licence fee, or any other monetary consideration is payable by you for access to the Platform during the Free Tier period.

9.2 Right to Introduce Fees. The Company reserves the right, at its sole discretion, to introduce subscription fees or other charges for access to the Platform or for specific features thereof at any future date. The introduction of fees shall not be treated as a material change that takes effect automatically — it shall be subject to the notice and consent obligations in Clause 9.3 below.

9.3 Notice Before Any Fee Introduction. If the Company decides to introduce fees, the Company shall:

(a) notify you via in-app notification and to your registered email address at least thirty (30) days before any fee becomes payable;

(b) clearly specify in that notice: the fee amount or structure, the features it applies to, the billing frequency, and the date from which the fee will apply; and

(c) give you the option to close your account before the fee commencement date, at no cost and without penalty, with your Patient records handled in accordance with Clause 12.4.

Your continued use of the Platform after the fee commencement date constitutes your acceptance of the applicable fees. If you do not accept the fees, you must close your account before that date.

9.4 No Retroactive Fees. The Company shall not charge fees for any period during which you used the Platform under the Free Tier. Fees, if introduced, will apply only from the date specified in the notice under Clause 9.3.

9.5 Grandfathering. At the Company's discretion, Users who were registered prior to the introduction of fees may be offered continued free access or preferential pricing. Any such arrangement will be communicated in the fee introduction notice under Clause 9.3 and will constitute a separate offer that may be accepted or declined independently.

10. Platform Availability, Modifications, and Updates

10.1 The Company shall use commercially reasonable efforts to maintain Platform availability. The Company does not warrant uninterrupted, error-free, or secure access to the Platform.

10.2 Planned maintenance shall be communicated via in-app notice at least forty-eight (48) hours in advance, except in cases of emergency maintenance required to prevent a security incident or data breach.

10.3 The Company may at any time modify, add, or remove features from the Platform. Where a modification materially reduces the functionality available to you, the Company shall provide at least fourteen (14) days' prior notice via in-app notification and registered email.

10.4 The Company may amend this Agreement at any time. Where an amendment is material, the Company shall notify you via in-app notification and registered email at least fourteen (14) days before the amendment takes effect. Your continued use of the Platform after the effective date of an amendment constitutes your acceptance of the amended Agreement. If you do not accept the amendment, you may close your account in accordance with Clause 12.1 before the effective date.

11. Data Roles, Therapist's Instructions, and the Therapist–Company DPA

11.1 Data-role declaration. In respect of Patient Data processed through the Platform, the roles of the parties under DPDPA 2023 are as follows:

(a) the User (Therapist) is the Data Fiduciary, as the User alone determines the purposes and essential means of processing Patient Data — namely, the clinical purpose, the scope of data collected, the duration of care, and the persons with whom data is to be shared as part of the Patient's care;

(b) the Company is a Data Processor, acting on the User's documented instructions (comprising this Agreement together with the User's actions within the Platform) to host, store, transmit, display, and — where activated by the User — generate AI-assisted summaries from Patient Data; and

(c) the Patient is the Data Principal, to whom all Data Principal rights under Chapter III of the DPDPA 2023 accrue.

11.2 Data Processing Agreement (DPA). This Clause 11, read together with Clauses 15 to 20, constitutes a written Data Processing Agreement between the User (as Data Fiduciary) and the Company (as Data Processor) in respect of Patient Data, satisfying the requirements for processor engagement under DPDPA 2023. By accepting this Agreement, you expressly instruct the Company to process Patient Data on your behalf for the purposes and on the terms set out herein.

11.3 Patient consent (obtained by the User as Data Fiduciary). Before creating a Patient record, you must have obtained the Patient's (or, for a minor, the parent's or legal guardian's) free, specific, informed, and unambiguous consent to:

(a) digital storage and processing of their health data by the User in the course of the User's clinical practice;

(b) the User's engagement of the Company as Data Processor for such processing, including sub-processing by the Company's service providers listed in Clause 18;

(c) AI-assisted summary generation as described in Clause 18.3, where the User intends to make use of that feature; and

(d) sharing of the Patient's data with other members of the Patient's care team as configured by the User in RecSoon Tx.

The digital consent flow embedded in the Patient add workflow constitutes a compliant consent mechanism under DPDPA 2023 §6. Where you use an alternative consent method, you must retain contemporaneous documentation of such consent.

11.4 User's Fiduciary obligations. As the Data Fiduciary for Patient Data, you shall:

(a) process Patient Data only for the clinical purposes for which the Patient has consented;

(b) implement appropriate device-side technical and organisational measures (including those in Clause 3.2) to protect Patient Data that is accessible through your device;

(c) promptly (within twenty-four (24) hours) notify the Company at security@caresutra-tech.com of any actual or suspected breach of Patient Data affecting data held on the Platform, so the Company may perform its Processor obligations under Clauses 18 and 20;

(d) respond to Patient requests under Chapter III of the DPDPA 2023 in the first instance (see Clause 19), calling on the Company as Processor to facilitate such responses; and

(e) not disclose Patient Data to third parties except as expressly permitted by this Agreement, by the Patient's consent, or by Applicable Law.

11.5 Company's Processor obligations (cross-reference). The Company's obligations as Processor — including security, sub-processing, cross-border processing, and assistance with Data Principal requests — are set out in Clauses 15 to 20.

11.6 Withdrawal of consent by a Patient. If a Patient withdraws consent while under your active care, the Company shall notify you in-app. You remain solely responsible for transitioning that Patient's records to an alternative lawful system in compliance with your professional record-keeping obligations.

12. Termination

12.1 Termination by User. You may terminate this Agreement and request closure and deletion of your account at any time by emailing dpo@caresutra-tech.com from your registered address, or by using Settings → Request Delete Account in the app, which sends us the same request by email. The Company verifies and actions such requests as set out in Clause 17.9. Patient record handling following termination shall be governed by Clause 12.4.

12.2 Termination by the Company. The Company may immediately suspend or terminate your account, without prior notice, upon:

(a) material breach of any provision of this Agreement, including the conduct obligations in Clause 4 or the Fiduciary obligations in Clause 11.4;

(b) revocation, suspension, or lapse of your professional licence or registration;

(c) receipt of a court order, regulatory direction, or law enforcement request requiring such action;

(d) reasonable determination by the Company that continued access poses a risk to Patient data security or safety; or

(e) abandonment of the account (no login activity for twenty-four (24) consecutive months), following thirty (30) days' notice.

12.3 Where grounds for termination exist but are capable of remedy, the Company may (at its discretion, not as an obligation) provide notice and a reasonable opportunity to cure before effecting termination.

12.4 Effect of Termination on Patient Data. Upon termination of your account, the Company, as your former Data Processor, shall:

(a) continue to store identifiable Patient records for the statutory minimum retention period of seven (7) years from the date of last session, as imposed by the Medical Council of India guidelines on medical record retention, so that the records remain available in the event of medicolegal proceedings affecting you or the Patient;

(b) on expiry of that period, anonymise the records (removing Patient identifiers while retaining a record skeleton for audit) or delete them, as your written instructions direct;

(c) retain no live access to the records on your behalf; and

(d) provide you, on request made before termination, with a structured export of your Patient records in accordance with Clause 19.1(e).

The seven-year retention is a legal obligation on you as Data Fiduciary, supported by the Company's infrastructure as Processor. The Company has no discretion to delete identifiable Patient records earlier if such deletion would breach this obligation.

12.5 Surviving Clauses. Upon termination, your licence to use the Platform ceases immediately. The following clauses survive termination: Clause 6.1 (Company IP), Clause 7 (Clinical Decision Disclaimer), Clause 8 (Limitation of Liability), Clause 13 (Governing Law), Clause 17 (Privacy Policy in full), this Clause 12, and any other clause that by its nature is intended to survive.

13. Governing Law, Jurisdiction, and Dispute Resolution

13.1 This Agreement is governed by and shall be construed in accordance with the laws of the Republic of India, without regard to its conflict-of-laws provisions.

13.2 Any dispute, controversy, or claim arising out of or in connection with this Agreement, including any question regarding its existence, validity, breach, or termination, shall first be subjected to good-faith negotiation between the parties for a period of thirty (30) days from the date of written notice of the dispute.

13.3 If the dispute is not resolved within the negotiation period, it shall be referred to and finally resolved by binding arbitration conducted under the Arbitration and Conciliation Act 1996, as amended. The arbitral tribunal shall consist of a sole arbitrator appointed by mutual agreement or, failing agreement within fifteen (15) days, appointed by the High Court of Karnataka under Section 11 of the Act. The seat and venue of arbitration shall be Bengaluru, Karnataka. The language of arbitration shall be English. The award shall be final and binding.

13.4 Nothing in this Clause 13 shall prevent either party from seeking urgent or interim injunctive or equitable relief from a competent court to prevent irreparable harm, preserve the status quo, or protect Confidential Information, pending resolution of the dispute.

13.5 For the purposes of any court proceedings not subject to Clause 13.3, the parties submit to the exclusive jurisdiction of the courts at Bengaluru, Karnataka.

14. General Provisions

14.1 Entire Agreement. This Agreement constitutes the entire agreement between the parties with respect to RecSoon Tx and supersedes all prior negotiations, representations, warranties, and agreements (whether written or oral) relating thereto.

14.2 Severability. If any provision of this Agreement is found by a competent court or arbitrator to be invalid, illegal, or unenforceable, such provision shall be modified to the minimum extent necessary to make it enforceable, or if modification is not possible, severed, and the remaining provisions shall continue in full force and effect.

14.3 Waiver. No failure or delay by either party in exercising any right under this Agreement shall constitute a waiver of that right. No single or partial exercise of any right shall preclude any other or future exercise of such right.

14.4 Assignment. You may not assign or transfer your rights or obligations under this Agreement without the prior written consent of the Company. The Company may assign this Agreement to a successor entity in connection with a merger, acquisition, or sale of substantially all of its assets, upon thirty (30) days' written notice to you.

14.5 Relationship of the Parties. Nothing in this Agreement creates a partnership, joint venture, agency, franchise, employment, or fiduciary relationship between the parties (other than the specific Data-role relationship described in Clause 11). You are an independent professional and not an employee, agent, or representative of the Company.

14.6 Notices. Notices under this Agreement shall be in writing and delivered by email to legal@caresutra-tech.com (for the Company) or to your registered email address (for you), and shall be deemed received upon confirmation of delivery.

14.7 Force Majeure. Neither party shall be in breach of this Agreement to the extent that performance is prevented or delayed by circumstances beyond that party's reasonable control, including acts of God, epidemic or pandemic, war, civil unrest, government action, or failure of third-party communications infrastructure. The affected party shall notify the other promptly and take reasonable steps to mitigate the effect.

Part II — Privacy Policy

15. Data Roles and Controllership

15.1 Company's Fiduciary role. CareSutra Technologies Private Limited is the Data Fiduciary under the DPDPA 2023 in respect of:

(a) Therapist Data — Personal Data collected from the User during registration, account management, billing (if and when activated), and Platform usage; and

(b) Platform Data — aggregated, de-identified operational, usage, and performance metrics that do not permit identification of any individual User or Patient.

15.2 Company's Processor role. In respect of Patient Data, the Company acts as a Data Processor on the User's instructions, as declared and agreed in Clause 11. The User is the Data Fiduciary for Patient Data; the Patient is the Data Principal. Clause 11.2 establishes the Data Processing Agreement between the User and the Company for this purpose.

15.3 Data Protection Officer. The Company has appointed a Data Protection Officer ("DPO") who is the primary point of contact for:

(a) matters relating to the Company's Fiduciary role (Therapist Data, Platform Data); and

(b) requests by Users for the Company's assistance in the User's Fiduciary role (Patient Data).

The DPO may be contacted at:

Name: Data Protection Officer, CareSutra Technologies Private Limited
Email: dpo@caresutra-tech.com
Postal address: Kanadal Street, Near Water Tank, Kote, Chickmagalur, Karnataka – 577101, India

16. Personal Data Collected

16.1 Therapist Data — collected by the Company in its Fiduciary capacity.

CategorySpecific Data ElementsPurpose
IdentityFull name, profile photograph (optional)Account creation, in-app display
AuthenticationEmail address (via Google OAuth token), hashed PIN or biometric hash (device-stored only)Secure account access
ProfessionalDiscipline (PT/SLP/OT/RT/SWT), registration number (optional), employment contextProtocol personalisation, eligibility verification
ContactMobile numberSecurity alerts, critical communications
DeviceDevice model, OS version, app version, installation IDCrash diagnostics, compatibility management
LocationApproximate device location — latitude/longitude and the city derived from it — captured in the foreground, with your permission, at registration and at the start and end of each therapy visitSetting your practice city; verifying your practice location; recording each therapy visit's location for clinical-record integrity and fraud prevention
UsageFeature interaction logs, session duration, error eventsPlatform performance, product improvement
ConsentAcceptance timestamp, Agreement version, device IDLegal audit record

16.2 Patient Data — processed by the Company on the User's instructions.

The Company processes the following categories of Patient Data solely on the User's written instructions (this Agreement and the User's actions within the Platform), in its capacity as Processor. The User collects and determines the scope of Patient Data; the Company does not directly solicit Patient Data from Patients except via the Platform under the User's configuration.

CategoryExamples
IdentityFull name, date of birth, age, gender, phone number
Clinical — BaselineDiagnosis, condition, primary complaints, comorbidities
Clinical — TreatmentCare plan, assigned protocol, exercise records, parameter measurements (ROM, MMT, pain scores, vital signs, functional scores), session notes, audio notes
Clinical — ProgressAssessment scores, trend data, goal attainment records, discharge summaries, progress reports
MediaPhotographs and short videos recorded during sessions (where User activates this feature)
ConsentPatient consent timestamp, version accepted, method of collection

16.3 What the Company does not collect. The Company does not collect:

(a) your device's contact list, call logs, or SMS content;

(b) location data while the app is in the background, or any continuous or real-time location tracking — the Company collects approximate location only in the foreground, with your permission, and only at the moments described in Clause 16.1 (at registration, and at the start and end of a therapy visit);

(c) camera or microphone input other than during explicit in-session audio note or media capture features, which require your active initiation; or

(d) any data for the purpose of advertising profiling, whether of Users or Patients.

17. Legal Bases, Purposes, and Retention

17.1 Legal bases.

Data CategoryLegal BasisStatutory Reference
Therapist Data — identity, professional, contactContract performance (this Agreement)DPDPA 2023 §4; IT Act 2000 §10A
Therapist Data — device, usageLegitimate interest (platform security, product improvement); contract performanceDPDPA 2023 §§4, 7(g)
Therapist Data — locationContract performance (practice setup) and legitimate interest (visit-record integrity, fraud prevention)DPDPA 2023 §§4, 7(g)
Patient Data — processing by the CompanyProcessing on the instructions of the User (Data Fiduciary), grounded in the Patient's consent obtained per Clause 11.3DPDPA 2023 §6; User's DPA (Clause 11.2)
Platform audit logs (access, consent records)Legal obligation and legitimate interest (platform security; medicolegal compliance)DPDPA 2023 §§7(c), 7(g)
Platform Data (anonymised analytics)Legitimate interest (product development); data is de-identified and outside the DPDPA's definition of Personal DataDPDPA 2023 §7(g); §3(x)

The Company does not rely on the Patient's legitimate interest or any other legal basis other than the Patient's consent (obtained by the User) for processing Patient Sensitive Personal Data.

17.2 Purposes of processing Therapist Data.

The Company processes Therapist Data for the following purposes, and no others:

(a) operating, maintaining, and improving the Platform and its features;

(b) verifying User eligibility and compliance with Clause 2;

(c) providing customer and technical support;

(d) detecting, investigating, and preventing security incidents and fraud;

(e) generating anonymised, aggregated insights (Platform Data) for product analytics;

(f) complying with obligations under Applicable Law; and

(g) verifying your practice location at registration and recording the approximate location of each therapy visit, captured in the foreground with your permission, to maintain the integrity of clinical records and to help prevent fraudulent or mislogged visits.

17.3 Purposes of processing Patient Data (as Processor).

The Company processes Patient Data only for the following purposes, and only on the User's instructions:

(a) storing and retrieving Patient records on behalf of the User;

(b) rendering Patient records to the User through the Platform interface;

(c) generating clinical documentation outputs (session recaps, progress reports, discharge summaries, exported records) at the User's request;

(d) generating AI-assisted summary drafts in accordance with Clause 18.3, when the User activates that feature; and

(e) enabling the User's configured sharing of records with other members of the Patient's care team.

17.4 Data minimisation. The Company collects and processes only such Personal Data as is necessary for the stated purposes. The User is not required to provide optional Therapist Data fields (such as professional registration number or profile photograph) to use the core features of the Platform.

17.5 Automated decision-making. The Platform does not make automated decisions with legal or similarly significant effects on Patients or Users. Any algorithmic suggestions (such as protocol recommendations or AI-generated summary drafts) are presentational aids only and are subject to the User's clinical review and override before any use.

17.6 Data storage (at rest).

All User and Patient data is stored at rest exclusively on servers located within the Republic of India, on AWS Mumbai (ap-south-1) infrastructure, in compliance with applicable data localisation expectations. Limited, transient processing outside India occurs as described in Clause 18.3 (AI-assisted summaries) and is subject to the safeguards set out therein.

17.7 Security measures.

The Company implements the following technical and organisational measures to protect Personal Data:

(a) encryption of all data in transit using TLS 1.3 (minimum);

(b) encryption of all data at rest using AES-256;

(c) field-level encryption of Patient health data fields (diagnosis, session notes, measurement records) using separate encryption keys;

(d) access controls restricting database access to authorised personnel only, with multi-factor authentication and full access audit logging;

(e) data masking in development and staging environments;

(f) implementation of FLAG_SECURE on all app screens displaying Patient Data, preventing screenshots and screen capture;

(g) background app masking to prevent Patient Data from appearing in the device's app-switcher;

(h) automated redaction of direct identifiers (patient name, phone numbers, email addresses) from free-text clinical notes before any transmission to AI sub-processors under Clause 18.3; and

(i) annual penetration testing and security audits by an independent third-party assessor.

17.8 Retention and deletion.

Data CategoryRetention PeriodPost-Period Action
Active User account (Therapist Data)Duration of the accountDeleted upon account closure
Therapist practice / registration locationDuration of the accountDeleted upon account closure
Patient clinical records (identifiable, incl. any per-visit location captured as part of the record)7 years from date of last session (statutory minimum)Anonymised (patient identifiers removed, record skeleton retained for medicolegal purposes) — on the User's documented instruction
Anonymised clinical records / Platform DataUntil the anonymised record loses research or compliance utilityDeleted
Platform audit logs (consent, access)5 years from the date of the triggering eventDeleted
Crash and error logs90 daysAutomatically purged
Data export requests24 hours from generationExport file deleted from Company servers

The 7-year retention of identifiable Patient records is a legal obligation on the User as Data Fiduciary (imposed by the Medical Council of India guidelines on medical record retention), which the Company supports in its Processor capacity. Neither the User nor the Company has discretion to delete identifiable Patient records earlier if such deletion would breach this obligation.

17.9 Account and data deletion — how to request.

You may request deletion of your account and the Personal Data the Company holds about you, as the account holder, at any time, by either of the following methods:

(a) by email, sent from your registered email address to dpo@caresutra-tech.com with the subject "Delete my account", including the registered email or mobile number on your account so the Company can verify your identity; or

(b) in the app, via Settings → Request Delete Account, which opens a pre-filled email request to the same address.

To protect health data, the Company verifies that a deletion request genuinely originates from the account holder before acting on it.

What is deleted. On a verified request, the Company deletes the Therapist Data it holds about you, including: your identity data (name, profile photograph); your authentication identity (Google sign-in association) and any device-stored credentials; your professional and contact details (discipline, registration number, mobile number); your approximate practice / registration location; your device identifiers and push-notification tokens; and your app-usage telemetry linked to your account.

What is retained, and why. Certain data is retained after a deletion request because it is subject to mandatory medical record-retention obligations, or is required for security and legal-audit purposes, as set out in the retention table in Clause 17.8. In summary: identifiable Patient clinical records — including any per-visit location captured as part of those records — are retained for seven (7) years from the date of last session before anonymisation or deletion; consent and access audit logs for five (5) years; and crash and error logs for ninety (90) days. Where data is retained for these reasons, access to it through your account is removed.

Timeframe. The Company acknowledges deletion requests within forty-eight (48) hours and completes deletion of all data not subject to mandatory retention within thirty (30) days of verifying the request.

Patients. If you are a Patient whose records were created by a therapist using RecSoon Tx, the therapist is the Data Fiduciary for your records. Direct deletion requests to your treating therapist in the first instance, or contact the Company at privacy@caresutra-tech.com, which will acknowledge within forty-eight (48) hours and pass the request to the relevant therapist, subject to the retention obligations above. See Clause 19.2.

A standalone summary of this deletion process is also published at caresutra-tech.com/legal/data-deletion.

18. Data Sharing and Third-Party Processors

18.1 The Company does not sell Personal Data. The Company does not share Personal Data with advertisers, data brokers, or marketing platforms.

18.2 The Company engages the following sub-processors, each bound by a written data-processing addendum. Where the Company is a Processor (for Patient Data), these recipients act as sub-processors under the User's DPA (Clause 11.2):

Sub-processorData SharedPurposeAgreement
Amazon Web Services India (ap-south-1)Therapist Data and Patient Data, encrypted at rest and in transitCloud hosting, primary database, file storageAWS Data Processing Addendum
Amazon Web Services — Bedrock (multi-region, see Clause 18.3)Redacted clinical note text only — see Clause 18.3AI-assisted summary generationAWS Bedrock Terms; AWS DPA
Google LLC (OAuth)OAuth token only — no clinical or Personal DataUser sign-in via Google accountGoogle OAuth Terms
Sentry (Crash Analytics)Anonymised crash logs, device model, OS version — no PHI, no Patient DataApplication stability monitoringSentry DPA (India data residency configured)
Firebase Cloud Messaging (Google LLC)Push notification tokens and metadata — no clinical contentDelivery of push notificationsGoogle Cloud DPA
Patient's care team membersClinical data the User explicitly shares via RecSoon TxCare coordination under the User's directionThe User's action as Data Fiduciary constitutes the disclosure
Law enforcement / courts / regulatory bodiesAs specified by a valid legal orderCompliance with Applicable LawN/A

18.3 AI-assisted clinical summaries.

When a User generates a session or case summary on the Platform, the following processing occurs:

(a) the User's clinical notes relating to the relevant session(s) are first processed by the Company to remove direct identifiers — the Patient's name, phone numbers, and email addresses are replaced with placeholder tokens before transmission;

(b) the redacted notes are then sent to Amazon Web Services (AWS), acting as the Company's sub-processor under Clause 18.2, for processing by third-party large-language-model (LLM) services hosted on AWS Bedrock, solely for the purpose of drafting the summary text requested by the User;

(c) the User reviews the draft and may edit any field before the draft is rendered, saved, or shared. No automated share or retention occurs without the User's explicit action.

The redaction described in (a) removes direct identifiers but does not amount to legal anonymisation under DPDPA 2023 — the remaining clinical content may still constitute Personal Data. Consent for AI-assisted summaries is therefore obtained from the Patient (by the User, under Clause 11.3) on that basis.

The specific LLM model used in Clause 18.3(b) may change over time as newer models become available on AWS Bedrock. The Patient's consent to AI-assisted summaries, obtained under Clause 11.3(c), covers any such model operated under AWS Bedrock on substantively equivalent terms.

Cross-border processing. AWS Bedrock may route the inference request to AWS data centres outside the Republic of India under its cross-region inference infrastructure. AWS is contractually bound under its Bedrock terms and the Company's data processing addendum with AWS not to (i) retain prompt content or responses beyond the duration of the request, (ii) use the content to train its own or third-party models, or (iii) make the content available to any other AWS customer. These contractual safeguards, together with the pre-transmission redaction under Clause 18.3(a), are the basis on which the Company effects transfer of Personal Data outside India under DPDPA 2023 §16.

18.4 Government and law enforcement requests. In respect of any government or law enforcement request for Therapist Data or Patient Data, the Company shall:

(a) verify the legal validity of the request before complying;

(b) provide only the minimum data required by the order;

(c) notify the affected User of the request, unless legally prohibited from doing so or unless notification would compromise an active law enforcement investigation; and

(d) maintain an internal record of all such requests.

Where the Company is a Processor (for Patient Data) and the request is not directed at the Company on a standalone basis, the Company will refer the request to the User (as Data Fiduciary) for response, unless Applicable Law requires the Company to respond directly.

19. Rights of Data Principals

19.1 Your rights as a User (in respect of your own Therapist Data).

Under Chapter III of the DPDPA 2023, you have the following rights in respect of Therapist Data, exercisable by contacting dpo@caresutra-tech.com or through the designated in-app controls. The Company, as Data Fiduciary for Therapist Data, is the responder.

(a) Right to Access Information about Processing (§11): You may request a summary of the categories of Therapist Data processed about you, the purposes of processing, and the identities of any sub-processors with whom your data has been shared. We will respond within fifteen (15) business days.

(b) Right to Correction and Erasure (§12): You may request correction of inaccurate Therapist Data or erasure of Therapist Data where it is no longer necessary for the purpose for which it was collected. Erasure requests in respect of Therapist Data are processed upon account closure. Patient Data erasure is governed by Clause 19.2.

(c) Right to Grievance Redressal (§13): You may submit a complaint regarding processing of your Therapist Data to our DPO at dpo@caresutra-tech.com. We will acknowledge within forty-eight (48) hours and provide a substantive response within thirty (30) days. Unresolved complaints may be escalated to the Data Protection Board of India, upon its constitution under DPDPA 2023.

(d) Right to Nominate (§14): You may nominate a person to exercise your data rights in the event of your death or incapacitation by contacting dpo@caresutra-tech.com with the nominee's name, relationship, and contact details. Nominations are confirmed in writing by the Company.

(e) Right to Data Portability: You may request an export of your Therapist Data and — acting in your own capacity as Data Fiduciary for your Patient records — your Patient records at any time by emailing dpo@caresutra-tech.com. Data is provided in a structured, machine-readable format within a reasonable period of the request.

19.2 Rights of Patients (as Data Principals in respect of Patient Data).

Patients hold the full suite of Data Principal rights under Chapter III of the DPDPA 2023 in respect of Patient Data. Because the User (Therapist) is the Data Fiduciary for Patient Data and the Company is a Processor, Patient rights requests are handled as follows:

(a) First point of contact. Patient requests should be directed, in the first instance, to the treating Therapist, who retains primary responsibility for the clinical relationship. The Therapist is obligated under Clause 11.4(d) to respond to such requests.

(b) Company-facilitation channel. Where a Patient contacts the Company directly at privacy@caresutra-tech.com, the Company will, subject to verification of the Patient's identity: (i) acknowledge the request within forty-eight (48) hours; (ii) identify the relevant Therapist(s) and pass the request to them; and (iii) take any action within its Processor capacity that the relevant Therapist instructs or that is required by Applicable Law. The Company will not take substantive action on Patient Data (such as rectification or deletion) without the Therapist's instruction, save where the Company is compelled to do so by Applicable Law or a valid order of a competent authority.

(c) Withdrawal of consent. A Patient may withdraw consent for processing of their data. The Company will notify the Therapist in-app of any withdrawal received through its facilitation channel and restrict further processing of that Patient's record pending the Therapist's transition of care. Historical records remain subject to mandatory retention under Clause 17.8.

(d) Access requests. Patient requests for a copy of their clinical records are fulfilled by the Therapist. The Company will, on the Therapist's instruction, assist by generating an export in the format specified in Clause 19.1(e).

(e) Correction requests. Clinical record correction requires the Therapist's professional review and authorisation. Identity-data corrections (name, date of birth, contact details) may be effected by the Company on the Therapist's instruction.

(f) Erasure requests. Subject to the mandatory retention obligations under Clause 17.8, the Company will anonymise a Patient's data upon receipt of a valid erasure request from the Patient with the Therapist's concurrence, or upon the expiry of the statutory retention period — whichever is later.

19.3 Escalation to the Data Protection Board. Where a Patient is dissatisfied with the response of either the Therapist or the Company in respect of the above rights, the Patient may escalate the matter to the Data Protection Board of India under DPDPA 2023 §13.

20. Breach Notification

20.1 In the event of a personal data breach that is likely to result in risk to the rights of Users or Patients, the Company shall:

(a) notify the Data Protection Board of India within such period as may be prescribed under DPDPA 2023 §8(6) and any rules thereunder;

(b) where the breach affects Therapist Data, notify affected Users within seventy-two (72) hours of the Company becoming aware of the breach, via a mandatory blocking in-app notification and registered email;

(c) where the breach affects Patient Data, notify the relevant Users within seventy-two (72) hours so that those Users, as Data Fiduciaries, may fulfil their own notification obligations to the affected Patients. The Company will, on the User's instruction or where required by Applicable Law, assist with Patient notifications;

(d) provide affected individuals with a clear description of the breach, the categories of data affected, the likely consequences, and the measures taken or proposed to address the breach.

20.2 Breach notifications to Users are implemented as a blocking in-app alert (governed by SCR-ALERT-001-BreachNotification) that cannot be dismissed without acknowledgement.

21. Children's Data

21.1 RecSoon Tx permits Users to create Patient records for minor patients (persons under 18 years of age). In respect of minor Patients:

(a) consent must be obtained by the User from the parent or lawful guardian of the minor, not from the minor;

(b) RecSoon Tx's patient consent flow prompts for guardian-provided consent when the Patient's age is recorded as under 18 years;

(c) minor Patient data is subject to the same security, retention, and deletion provisions as adult Patient Data; and

(d) the Company does not knowingly process data of minors as Users or account holders.

21.2 The Company does not knowingly permit persons under 18 to register as Users of RecSoon Tx.

22. Cookies and Device Tracking

22.1 The RecSoon Tx mobile application does not use advertising cookies, third-party tracking SDKs, or behavioural analytics platforms.

22.2 The application uses the following limited device-side storage:

(a) Secure session tokens (stored in the device's secure enclave via expo-secure-store): required for authentication. Not transmitted to third parties.

(b) Anonymous crash identifiers (Sentry): a randomly generated, non-persistent device identifier, reset on app reinstall, containing no Personal Data.

(c) Local data cache (React Query persistence via AsyncStorage): encrypted clinical and schedule data cached for offline functionality. Not shared with third parties.

22.3 The Company does not use Firebase Analytics, Facebook SDK, AppsFlyer, Amplitude, or any advertising or user-tracking network. Firebase Cloud Messaging is used solely for push-notification delivery (see Clause 18.2) and not for analytics.

23. Changes to this Privacy Policy

23.1 The Company may amend this Privacy Policy at any time. Material changes shall be communicated via in-app notification and registered email at least fourteen (14) days before the effective date of the change. A change to the data-role model (e.g., moving the Company from Processor to Fiduciary for any category of data) shall always be treated as a material change requiring fresh consent.

23.2 The authoritative version of this Policy is the version currently published at caresutra-tech.com/legal/privacy-policy. Previous versions are archived at caresutra-tech.com/legal/archive and are available upon request.

Part III — Product Scope

This Agreement governs RecSoon Tx, the therapist-facing application operated by CareSutra Technologies Private Limited. Any other applications the Company may operate, now or in the future, are separate products governed by their own terms and are not covered by this Agreement.

Data processed within RecSoon Tx is not commingled with data processed within any other application operated by the Company without the informed consent of the relevant Data Principals and, where applicable, your explicit action as the treating therapist and Data Fiduciary.

Contact Directory

PurposeContact
General supportsupport@caresutra-tech.com
Data Protection Officerdpo@caresutra-tech.com
Legal and compliancelegal@caresutra-tech.com
Security incidents and breach reportssecurity@caresutra-tech.com
Patient data rights requests (facilitation)privacy@caresutra-tech.com
Registered officeCareSutra Technologies Private Limited, Kanadal Street, Near Water Tank, Kote, Chickmagalur, Karnataka – 577101, India

Annexure A — Summary of Key User Obligations

The following is a non-exhaustive summary for quick reference. The full obligations are set out in Part I and Part II above and shall govern in the event of any conflict with this summary.

ObligationClause
Hold a valid professional licence at all times2.1(a)
Use RecSoon Tx for bona fide clinical practice only2.1(d)
Maintain account security; do not share credentials3.1–3.3
Create Patient records only for Patients under active care4.1
Enter accurate clinical data; do not falsify records4.2
Obtain Patient consent before creating a record (as Data Fiduciary)4.3, 11.3
Act as Data Fiduciary for Patient Data, with the Company as your Data Processor11.1–11.4
Respond in the first instance to Patient rights requests11.4(d), 19.2
Notify the Company within 24 hours of any Patient-Data security incident11.4(c), 3.2(d)
Do not use the Platform outside your licensed scope of practice4.4
Do not export Patient Data to third-party platforms without consent5.2(c)

Annexure B — Summary of Company's Processor Obligations (informational)

The following is a non-exhaustive summary of the Company's obligations when acting as Data Processor for Patient Data, for the User's reference. The full obligations are set out in Clauses 15 to 20.

ObligationClause
Process Patient Data only on the User's instructions (this Agreement + User's actions in the Platform)11.1, 11.2
Implement technical and organisational security measures to protect Patient Data at rest and in transit17.6–17.7
Redact direct identifiers from clinical notes before transmission to AI sub-processors17.7(h), 18.3
Maintain a current list of sub-processors and bind each by written data-processing terms18.2
Notify the User of any Personal Data breach affecting Patient Data within 72 hours20.1(c)
Assist the User in responding to Patient rights requests19.2
On termination, continue statutory retention and anonymise or delete as the User instructs on expiry12.4
Respect cross-border transfer safeguards under DPDPA §1617.6, 18.3

This Agreement was prepared for CareSutra Technologies Private Limited and reflects applicable Indian law as of the Effective Date. This document constitutes an internal product-legal draft. It must be reviewed and approved by qualified Indian legal counsel admitted to the Bar Council of India before the Platform is made available to Users with real Patient data. The Company makes no representation that this document is complete, exhaustive, or free from error.

End of CSTPL-LEGAL-001 v1.0