Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and Vansora Studio Private Limited, trading as Relaya ("Processor"), for the provision of the Relaya platform services.

This DPA applies where the Processor processes Personal Data on behalf of the Controller in the course of providing the Relaya service, and where such processing is subject to the UK GDPR, EU GDPR, or equivalent data protection legislation.

1. Definitions

  • Controller: The healthcare practice or organisation that determines the purposes and means of processing Personal Data through the Relaya platform.
  • Processor: Vansora Studio Private Limited (trading as Relaya), which processes Personal Data on behalf of the Controller.
  • Data Subjects: Patients, staff members, and other individuals whose Personal Data is processed through the Relaya platform.
  • Personal Data: Any information relating to an identified or identifiable natural person, including patient names, contact details, appointment records, communication records, and health-related data.
  • Processing: Any operation performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
  • Sub-processor: Any third party engaged by the Processor to process Personal Data on behalf of the Controller.

2. Scope and Purpose

The Processor processes Personal Data for the following purposes in connection with the Relaya platform:

  • Practice management (scheduling, patient records, workflow automation)
  • Clinical note generation and documentation (AI Scribe)
  • Patient communications (voice calls, SMS, email, WhatsApp messaging)
  • Payment processing and billing management
  • Analytics and reporting for practice operations
  • AI-powered voice handling and call management

The categories of Data Subjects include: patients of the Controller's practice, staff and practitioners of the Controller, and third parties communicating with the practice through the platform.

3. Data Processor Obligations

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law.
  • Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing.
  • Not engage another processor (sub-processor) without prior specific or general written authorisation of the Controller.
  • Assist the Controller in responding to requests from Data Subjects exercising their rights under applicable data protection law.
  • Assist the Controller in ensuring compliance with obligations related to security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
  • At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services, and delete existing copies unless storage is required by applicable law.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA, and allow for and contribute to audits and inspections.

4. Sub-processors

The Controller provides general authorisation for the Processor to engage sub-processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object.

Current sub-processors:

Sub-processorPurposeLocation
Oracle Cloud Infrastructure (OCI)Primary hosting and data storageIndia / UK (region-dependent)
Brevo / SendGridTransactional and marketing email deliveryEU / US
Stripe / RazorpayPayment processingUS / India
PaddleSubscription billing and merchant of recordUK / EU
Twilio / VapiVoice and SMS communications, AI voice processingUS / UK
AI Providers (OpenAI, Anthropic, Google)AI inference for clinical notes, voice, and communication assistanceUS

The Processor ensures that sub-processor agreements impose equivalent data protection obligations to those set out in this DPA.

5. Security Measures

The Processor implements the following technical and organisational measures:

  • Encryption at rest: AES-256-GCM for all stored Personal Data and database fields containing sensitive information.
  • Encryption in transit: TLS 1.3 for all data transmission between clients and servers.
  • Access control: Role-Based Access Control (RBAC) with principle of least privilege. Multi-factor authentication for administrative access.
  • Audit trails: Comprehensive logging of all access to and modifications of Personal Data, retained for 12 months.
  • Penetration testing: Annual third-party penetration testing with remediation of identified vulnerabilities.
  • Backup and recovery: Automated encrypted backups with tested recovery procedures.
  • Incident response: Documented incident response plan with defined roles, escalation procedures, and communication protocols.

6. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligation to respond to requests from Data Subjects exercising their rights under applicable data protection law, including:

  • Right of access (Subject Access Requests)
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object

The Processor shall respond to the Controller's assistance requests within 30 days of receipt. Where a Data Subject makes a request directly to the Processor, the Processor shall promptly redirect the request to the Controller.

7. Breach Notification

In the event of a Personal Data breach, the Processor shall:

  • Notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach.
  • Provide the Controller with sufficient information to meet its obligations to report the breach to the supervisory authority and affected Data Subjects.
  • Cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
  • Document all breaches, including the facts, effects, and remedial actions taken, regardless of whether notification to the supervisory authority is required.

8. International Transfers

Where Personal Data is transferred outside the United Kingdom or European Economic Area, the Processor shall ensure that appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs):Transfers are governed by the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) or the UK International Data Transfer Agreement / Addendum, as applicable.
  • Adequacy decisions: Where the destination country has received an adequacy decision from the European Commission or the UK Secretary of State, transfers may proceed on that basis.
  • Supplementary measures: Additional technical measures (encryption, pseudonymisation) are applied where required by the risk assessment.

9. Duration and Termination

This DPA shall remain in effect for the duration of the Processor's provision of services to the Controller under the main service agreement (Terms of Service).

Upon termination or expiry of the service agreement, the obligations in this DPA shall continue to apply to any Personal Data retained by the Processor until such data is deleted or returned.

10. Data Return and Deletion

Upon termination of the service agreement, the Processor shall, at the Controller's election:

  • Return: Provide a complete export of all Personal Data in a structured, commonly used, machine-readable format (JSON/CSV) within 30 days of the termination date.
  • Delete: Securely delete all Personal Data within 30 days of the termination date, and certify such deletion in writing.

Where applicable law requires retention of certain data beyond the termination date, the Processor shall inform the Controller of such requirement and limit processing to what is required by law.

11. Contact

For questions regarding this DPA or to execute a signed version:

Email: legal@relaya.one
Privacy: privacy@relaya.one
Company: Vansora Studio Private Limited (trading as Relaya)