Data Processing Agreement
Last updated: September 18, 2026
This Data Processing Agreement ("DPA") forms part of the MyKaya Terms & Conditions("Terms") between MyKaya ("MyKaya", "we", "us") and the practitioner or practice that holds a MyKaya account ("you"). It applies automatically to every account from the date you accept the Terms, and needs no separate signature. If you need a signed copy for your records, email team@mykaya.app.
1. Definitions and roles
- Client Personal Data means personal data about your clients, or other individuals, that you upload to or create in MyKaya — including session audio, transcripts, notes, assessment responses and scores, and client records.
- DPDP Actmeans India's Digital Personal Data Protection Act, 2023 and the rules made under it. Terms such as Data Fiduciary, Data Processor, Data Principal, Personal Data Breach and Board have the meanings given in the DPDP Act.
- For Client Personal Data, you are the Data Fiduciary and MyKaya is your Data Processor. This DPA covers only Client Personal Data. Our handling of your own account data, where we are the Data Fiduciary, is described in our Privacy Policy.
2. Scope of processing
- Subject matter: providing the MyKaya service — recording, transcription, translation, note drafting, assessments, insights and storage.
- Duration: for as long as you use MyKaya, and then until deletion under section 11.
- Nature and purpose: collection, storage, transcription, analysis, structuring, retrieval and deletion, solely to provide the service to you.
- Data Principals: your clients (including children under 18, where you work with them) and other individuals who are recorded or mentioned in sessions.
- Categories of data: client identity and contact details; session audio; transcripts; clinical notes; assessment responses and scores; any other content you add. This includes health and mental-health information.
3. Your instructions
- We process Client Personal Data only on your documented instructions. The Terms, this DPA, and your use and configuration of the service are your complete instructions. Any other instruction requires our written agreement.
- We will tell you if we believe an instruction breaks applicable law, and we may decline to follow it.
- We do not sell Client Personal Data, or use it for advertising. We may use aggregated, de-identified usage information, to operate and improve the service.
4. Your responsibilities
As the Data Fiduciary, you are responsible for:
- giving your clients the notice the DPDP Act requires and obtaining their valid consent before recording or processing their sessions through MyKaya — including telling them that an AI documentation tool is used and which providers process their data (see our sub-processors);
- obtaining verifiable consent from a parent or lawful guardian before processing the data of a client who is under 18, or of a person with a disability who has a lawful guardian;
- the accuracy and lawfulness of the data you upload and of your instructions to us;
- responding to your clients' requests to access, correct or erase their data, with our help under section 7;
- keeping your account secure — protecting your login credentials, turning on multi-factor authentication, and removing access for anyone who should no longer have it; and
- your own professional, ethical and record-keeping obligations.
5. Confidentiality
Anyone at MyKaya who can access Client Personal Data is bound by confidentiality obligations, and accesses it only as needed to provide, support or secure the service, or when you ask us to.
6. Security
We maintain reasonable security safeguards to protect Client Personal Data, as the DPDP Act requires, including:
- encryption in transit (TLS 1.2 or higher) and at rest (AES-256), with sensitive clinical fields additionally encrypted by our application;
- per-practice access checks on every request for clinical records;
- authenticated access, with multi-factor authentication available to every account and enforced once enabled;
- logging of access to session and client records, kept for at least one year, and alerting on attempts to access data across practices;
- automated backups with 35-day retention; and
- a published channel for reporting security vulnerabilities.
We may update these measures over time, provided the overall level of protection is not materially reduced.
7. Assistance
- MyKaya lets you view and correct client records and delete sessions yourself, so you can respond to most of your clients' requests directly. To delete a client record or assessment, or where you need more help, email us and we will provide reasonable assistance.
- If one of your clients contacts us directly about their data, we will refer them to you and will not respond ourselves unless the law requires us to.
- We will give you information reasonably available to us to help you meet your obligations under the DPDP Act, including for breach reporting and inquiries from the Board.
- Assistance that goes beyond reasonable effort, or that is needed because of your own acts or omissions, may be charged at a reasonable cost, which we will agree with you in advance.
8. Personal Data Breaches
- We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting your Client Personal Data. We will send the notice to your account email.
- The notice will describe, as far as we know at the time: what happened and when; the categories and approximate number of people and records affected; the likely consequences; what we have done and propose to do; and who to contact. Where we don't yet have all of this, we will send what we have and follow up as we learn more.
- We will take reasonable steps to contain, investigate and mitigate the breach.
- As the Data Fiduciary, you are responsible for notifying your clients and the Board. We will support you, including with a notice you can adapt. We will make any reports that the law requires of us directly.
- Notifying you of a breach is not an admission of fault or liability.
9. Sub-processors
- You authorise us to engage sub-processors to provide the service. The current list, with what each does and where, is published at mykaya.app/subprocessors.
- We engage sub-processors under written terms that require them to protect the data — for major cloud providers, their standard data processing terms — and we remain responsible to you for their performance of our obligations under this DPA, subject to section 13.
- We will email account owners at least 30 days before a new sub-processor starts processing Client Personal Data. Where a change is urgently needed to keep the service secure or running, we may give shorter notice and will tell you as soon as we can.
- You may object in writing within the notice period on reasonable data-protection grounds. We will work with you in good faith to address the objection. If we cannot, your sole remedy is to stop using the affected service and close your account, and we will refund any prepaid fees for the unused period.
10. Processing outside India
You authorise processing in the locations shown on our sub-processors page, including outside India, as the DPDP Act permits. If the Government restricts transfers to a country we use, we will move that processing or take the other steps the law requires.
11. Deletion and return
- While you use MyKaya, you can delete sessions yourself at any time, and we will delete client records and assessments on your request.
- When you close your account, or ask us in writing to delete your data, you have 30 days to export it (we will provide reasonable help on request). We then delete Client Personal Data within 90 days of closure, unless the law requires us to keep it. Backups expire on their 35-day cycle. Access logs, which contain record IDs but no session content, are kept for up to 13 months for security.
- A lapsed or expired paid plan does not close your account. Your records remain available to you until you close the account or ask us to delete them.
12. Information and audits
- On request, we will give you a description of our security measures and our current sub-processor list, and answer one written security questionnaire in any 12-month period.
- Any further audit, including an on-site audit, will take place only where the law or a regulator requires it. It will be at your cost, with at least 30 days' written notice, during business hours, under confidentiality, no more than once in any 12-month period, and without access to other customers' data or to systems whose exposure would put security at risk.
13. Liability
To the maximum extent permitted by law, MyKaya's total aggregate liability arising out of or relating to this DPA and the processing of Client Personal Data is limited to the greater of (a) the fees you paid MyKaya in the 12 months before the event giving rise to the claim and (b) ₹5,000. MyKaya is not liable for any indirect, incidental, special or consequential loss, or for loss of profits, revenue, goodwill or data. Nothing in this DPA excludes or limits liability to the extent such exclusion or limitation is prohibited by applicable law. This section applies in addition to the limitations in the Terms.
14. HIPAA and other laws
This DPA is made under India's DPDP Act. It is not a HIPAA Business Associate Agreement, and MyKaya does not currently sign Business Associate Agreements. If your practice is subject to HIPAA, GDPR or other data protection laws, confirm that MyKaya meets your requirements before you use it for data those laws govern.
15. General
- If this DPA conflicts with the Terms on the protection of Client Personal Data, this DPA prevails. On all other matters, the Terms prevail.
- We may update this DPA. We will email account owners at least 30 days before a material change takes effect, and no change will materially reduce the protection of Client Personal Data unless the law requires it. Continuing to use MyKaya after a change takes effect means you accept it.
- This DPA is governed by the laws of India, and the courts in Mumbai have jurisdiction over any dispute.