QEMRA legal
Data Processing Addendum
This document explains the rules, responsibilities, and protections that apply when you use QEMRA.
1. Parties and roles
Customer means the business or professional using QEMRA.
For personal data relating to the Customer’s end users, contacts, patients, clients, prospects or other individuals, the Customer generally determines the purpose and means of processing and acts as the controller, Data Fiduciary or equivalent role under applicable law.
KRAVIA/QEMRA acts as the processor, Data Processor, service provider or equivalent role to the extent it processes that data on the Customer’s documented instructions.
For account administration, billing, security, fraud prevention, compliance and KRAVIA’s own service operations, KRAVIA may independently determine certain purposes and act in the role assigned by applicable law.
2. Subject matter and duration
QEMRA processes personal data to provide business messaging, automation, inbox, booking, analytics, AI assistance, workflow execution, support, security and related services.
Processing continues for the term of the customer relationship and applicable retention/deletion periods.
3. Categories of data
Depending on enabled features, data may include names/contact details, phone/WhatsApp identifiers, relationship data, message content/metadata, consent/opt-out records, bookings, uploaded files/media, workflow variables, tags/notes, support records and technical/audit/security data.
The Customer must not intentionally submit data it is not authorized to process.
4. Data subjects
Data subjects may include the Customer’s customers/prospects, staff/contractors, patients/clients where applicable, website visitors and other people with whom the Customer communicates.
5. Processing instructions
QEMRA processes Customer Personal Data only to provide the QEMRA service, according to Customer configuration and documented instructions, to protect service security/integrity, as required by law, or as otherwise agreed in writing.
If QEMRA reasonably believes an instruction violates applicable data-protection law, it may suspend the affected processing and notify the Customer where permitted.
6. Customer obligations
The Customer is responsible for having a lawful basis, providing required notices, obtaining required consent, ensuring message/contact-list compliance, configuring retention/access appropriately, responding to data-subject requests as the primary contact, avoiding unnecessary sensitive data and ensuring its instructions comply with law.
7. Confidentiality
Personnel authorized to process Customer Personal Data are subject to confidentiality obligations and access is limited according to role and need.
8. Security
QEMRA maintains reasonable technical and organizational measures designed to protect Customer Personal Data, including as applicable encryption in transit/at rest, access controls, tenant isolation, secure authentication/sessions, optional MFA, audit logging, backups, internal monitoring, vulnerability management and incident response.
No security program can eliminate all risk.
9. Subprocessors
The Customer gives general authorization for QEMRA to use subprocessors necessary to provide the service.
QEMRA maintains a public Subprocessor List and will notify customers of material new subprocessors that may process Customer Personal Data.
A Customer may object within 15 days of notice on legitimate data-protection grounds. QEMRA will attempt a reasonable alternative where practical. If no workable alternative exists, the Customer may terminate the affected service.
QEMRA requires subprocessors to protect data through contractual or equivalent safeguards appropriate to their role.
10. International transfers
Customer Personal Data may be processed outside the Customer’s country where needed for approved hosting, messaging, AI, payments, support, analytics or security services.
QEMRA uses legally required transfer safeguards where applicable. If an applicable jurisdiction requires specific transfer clauses, QEMRA may incorporate or execute those clauses as required.
11. Data-subject requests
The Customer is normally responsible for receiving requests from its end customers.
Taking into account the nature of processing, QEMRA will provide reasonable assistance with access, correction, deletion, export or other rights requests when technically possible and legally required.
QEMRA will not independently respond to an end-customer request on the Customer’s behalf unless required by law or authorized by the Customer.
12. Security incidents
QEMRA will notify the affected Customer without undue delay after becoming aware of a personal-data/security incident materially affecting Customer Personal Data, as required by law or contract.
Available notice may include the nature of the incident, affected data/systems, likely impact where known, mitigation taken and recommended customer actions.
13. Deletion and return
During the account relationship, QEMRA provides reasonable export tools.
Following account deletion or termination, Customer Personal Data is scheduled for deletion according to the Data Retention & Deletion Policy, subject to legal, tax, fraud, security and dispute-retention requirements.
Deleted data may remain temporarily in encrypted backups until scheduled rotation.
14. Audits and information
QEMRA will make reasonable compliance information available, including this DPA, the Security Policy and subprocessor information.
For enterprise customers, additional audit rights, certifications or onsite-review terms must be agreed separately and may be subject to reasonable confidentiality, scope, frequency and cost limits.
15. Government requests
Where QEMRA receives a legally valid demand for Customer Personal Data, it will seek to verify the request, disclose only what is legally required and notify the Customer where legally permitted.
16. AI providers
If the Customer enables AI features, limited Customer Personal Data may be processed by approved AI providers as necessary for those features.
QEMRA does not use Customer WhatsApp conversations or message content to train QEMRA’s own AI models by default.
17. Liability and precedence
Liability under this DPA is subject to the liability framework in the Terms or, where applicable, a signed Business Customer Agreement.
If this DPA directly conflicts with the Terms on data-processing obligations, this DPA controls for that issue. A separately signed Business Customer Agreement may control where expressly agreed.
18. Contact
Data-protection and DPA questions: noreply@qemra.vmnexa.co.in
Annex A — Processing details
Nature: collection, storage, organization, retrieval, transmission, message processing, automated workflow execution, AI-assisted processing, support and deletion. Purpose: to provide QEMRA according to Customer configuration. Frequency: continuous or event-driven while the service is used. Duration: account term plus applicable retention periods.
Annex B — Security measures
QEMRA’s current baseline is described in the public Security Policy. Controls may evolve as technology, risk and legal requirements change.
