Clinic VoiceOps by FreeFast Back to home

Legal

Data Processing & Sub-processors

This page describes how FreeFast processes personal data on behalf of clinics, the sub-processors we rely on, and our security and breach-notification commitments under the DPDP Act.

Effective date: 24 June 2026 · Applies to freefast.co and the Clinic VoiceOps service.

1. Roles

For patient data, the Clinic is the Data Fiduciary and FreeFast is the Data Processor, processing personal data only on the clinic’s documented instructions and to provide the service described in our Terms of Service.

2. Scope of processing

  • Subject matter: operating patient communications and appointment workflows.
  • Categories of data principals: the clinic’s patients and staff.
  • Categories of data: contact details, appointment and report metadata, communication and consent records, and staff account data. See the Privacy Policy for detail.

3. Sub-processors

We engage the following sub-processors under contract, solely to operate the service:

Sub-processorPurposeData involved
Meta Platforms (WhatsApp Business Cloud API)Delivering WhatsApp confirmations, reminders, report links, and feedback requests.Patient mobile number, message content/template variables, delivery status.
Cloud hosting / infrastructure providerHosting the application, database, and worker; storage and compute.All service data at rest and in transit (encrypted).
Voice provider (enabled per clinic, when configured)Placing/receiving AI voice calls a clinic enables. Disabled by default.Patient mobile number, call metadata, and call context the clinic configures.

We will give clinics reasonable notice of new or replacement sub-processors so they may object on reasonable data-protection grounds.

4. Security measures

  • Encryption in transit; access restricted by role and tenant isolation between clinics.
  • Staff passwords stored only as salted hashes; signed, expiring sessions.
  • Login rate-limiting and audit logging of sensitive actions.
  • Messaging stays off until your provider confirms they're ready to use it.

5. Assisting with data-principal requests

We assist clinics in responding to data-principal requests (access, correction, erasure, consent withdrawal). Patients should raise requests with their clinic; we provide the tooling and support to act on them.

6. Personal data breach

If we become aware of a personal-data breach affecting a clinic’s data, we will notify the affected clinic(s) without undue delay and provide the information needed for the clinic to meet its obligations to the Data Protection Board and affected data principals.

7. Return and deletion

On termination, or on a clinic’s instruction, we will return and/or delete the clinic’s personal data, except where retention is required by law.

8. Contact

Data-protection questions: [email protected] or our Grievance Officer at [[email protected]].

Privacy PolicyTerms of Service[email protected]