ਡ੍ਰਾਫ਼ਟ – ਭਾਰਤੀ ਕਾਨੂੰਨੀ ਸਲਾਹਕਾਰ ਦੀ ਸਮੀਖਿਆ ਬਾਕੀ ਹੈ। ਅਜੇ ਲਾਗੂ ਨਹੀਂ।
ਕਾਨੂੰਨੀ ਦਸਤਾਵੇਜ਼ ਅਜੇ ਅੰਗਰੇਜ਼ੀ ਵਿੱਚ ਉਪਲਬਧ ਹਨ। ਅਨੁਵਾਦ ਜਲਦੀ ਆਉਣਗੇ।
1. Roles
The clinic (the customer) is the data fiduciary for patient data entered in SOTTO. SOTTO acts as data processor and processes that data only on the clinic's documented instructions.
2. Security measures
- Encryption in transit (TLS) and at rest.
- Role-based access control checked on the server.
- Audit logs of sign-ins and access to patient records.
- Remote sign-out of lost devices; short-lived access tokens.
- Backups in more than one cloud.
3. Personal data breaches
SOTTO notifies the clinic without undue delay after becoming aware of a breach affecting its data, with the information the clinic needs to meet its own obligations. [Timelines per DPDP Rules and CERT-In directions to be confirmed.]
4. Sub-processors
[List of hosting, backup, e-mail and payment sub-processors to be published.]
5. End of service
On termination, the clinic can export its data. SOTTO deletes it after the agreed retention period unless the law requires otherwise.
