Skip to content
Klaro Care
Back to home
DPDP · DPA §5

Subprocessor list

Every third party Klaro Care uses to deliver the service.

Last updated: 22 April 2026

1. What this list is

Under the Data Processing Agreement we maintain a public register of every party that processes personal data on our behalf. Each entry below shows the function, what data is shared, where it is stored, and the compliance posture. Customers and partners can subscribe to change-notifications via dpo@klarocare.in.

2. Hosting & infrastructure

SubprocessorData regionPurposeCompliance
Amazon Web Servicesap-south-1 (Mumbai)Application hosting, RDS PostgreSQL, S3 document vault, KMS-managed encryption keysISO 27001 · SOC 2 · CSA STAR · IRDAI ISNP-empanelled
CloudflareGlobal edgeEdge CDN, DDoS protection, WAF for static + cached responsesISO 27001 · SOC 2 · IS 700 (CERT-In)
DatadogEU + IN regionsApplication performance monitoring, log search (PII-masked at source)ISO 27001 · SOC 2 · HIPAA
SentryEUFrontend / backend error reporting; PII scrubbing applied client-sideISO 27001 · SOC 2

3. Payments & finance

SubprocessorData regionPurposeCompliance
Cashfree PaymentsIndiaActive payment gateway: card / UPI / netbanking · auto-debit mandates · refundsPCI-DSS 4.0 · RBI-licensed Payment Aggregator
RazorpayIndiaLegacy payment gateway · maintained for in-flight policies bought before Cashfree migrationPCI-DSS 4.0 · RBI PA
Tally SolutionsIndiaReconciliation & GST filings; only aggregated transaction data, no policy detailGST-suvidha-provider empanelled

4. Communications

SubprocessorData regionPurposeCompliance
MSG91IndiaTransactional SMS · OTP · DLT-registered template deliveryISO 27001 · TRAI-registered
WATIIndia + SingaporeWhatsApp Business API for transactional + opt-in marketing messagesMeta-approved BSP · ISO 27001
SendGrid (Twilio)US + EUTransactional email; suppressions list + bounce management. Marketing emails opt-in only.ISO 27001 · SOC 2
ExotelIndiaVoice OTP fallback + outbound advisor calls (consent-recorded)TRAI · DoT-registered cloud telephony

5. KYC, identity, document verification

SubprocessorData regionPurposeCompliance
NSDL e-GovernanceIndiaCKYC lookup · PAN verificationIRDAI / SEBI authorised KUA
UIDAIIndiaAadhaar e-KYC via authorised AUA (used only with explicit consent)UIDAI Authorised AUA
DigiLockerIndiaDocument fetch with consent: driving licence, vehicle RC, education proofsMEITY / NeGD
IDfyIndiaOCR + face-match + liveness for video-KYC (used at agent-onboarding only)ISO 27001 · ISO 27018 · SOC 2

6. Insurer integrations

Klaro Care passes minimum-necessary data to insurers when you request a quote, submit a proposal, or file a claim. Each insurer is an independent controller for the data they receive (per IRDAI composite-broker rules) and is governed by their own privacy policy + our master service agreement. The current insurer panel is at klarocare.in/insurers. No insurer receives data for a quote you didn't ask for.

7. Analytics & marketing

SubprocessorData regionPurposeCompliance
Google Analytics 4US + EUAnonymised page-level analytics; IP-anonymised; cookie consent gatedISO 27001 · SOC 2
MixpanelUSFunnel analytics; only product events, never PIIISO 27001 · SOC 2 Type II · GDPR DPA
HotjarEUSession-replay on opted-in users only; PII auto-redacted; off by defaultISO 27001 · DPF

8. Change control

  • New subprocessors are reviewed by the Privacy & Security council before contracting.
  • Standard Contractual Clauses are signed with every cross-border processor.
  • Customers are notified 30 days in advance of any addition; objections can be raised to dpo@klarocare.in.
  • Removed subprocessors are listed for one full quarter after exit, with a strikethrough, before being archived.

9. Reporting concerns

Data Protection Officer: dpo@klarocare.in.
For specific concerns about any subprocessor on this list, write to the DPO and reference the subprocessor name. We respond within 7 working days.

This is a legal document. Contact our DPO at dpo@klarocare.in for questions.

IRDAI Licence WA/1234/2024