Scope and obligations for personal data processed on clinic instructions.
This Data Processing Agreement (DPA), to the extent incorporated into the service agreement, governs processing where the customer clinic is controller and US-based Vetigen Incorporation is processor. Visiting the website alone does not establish this agreement or data subject consent. Separately signed specific processing terms apply within their relevant scope.
Vetigen’s account, billing, security and website processing for which it determines purposes and means is separate from this processor role and is explained in the Privacy Notice.
The subject matter is provision of the selected veterinary software and support service. Processing may include collection, organization, storage, authorized access, message delivery, requested AI operations, transfer, export and deletion. Duration depends on the service agreement, necessary return/deletion after termination and legal retention obligations.
The clinic is responsible for determining legal bases for collection and transfer, providing required notices, obtaining separate consent where required, applying communication preferences and managing permissions. The service agreement, enabled features, authorized user actions and documented support requests define the instruction scope.
Vetigen processes data only on documented instructions and for agreed purposes, and informs the clinic of legally required processing unless prohibited by law. It informs the clinic if it considers an instruction to infringe data protection law, and the affected operation may be suspended pending clarification. This DPA does not authorize general-purpose model training on clinic data.
Vetigen must ensure that authorized people accessing data are bound by confidentiality and that technical/organizational measures are proportionate to risk. Relevant controls include authorization, clinic access boundaries and operation records. Measures are assessed against the service and processing risk.
Subprocessors used for the service must be subject to arrangements carrying the relevant data protection obligations. Vetigen remains responsible for their performance as required by law and contract. Under this DPA, the clinic gives general authorization for listed subprocessors necessary for the service; additions or replacements require advance information and an opportunity to object on data protection grounds.
For an objection, the parties assess solutions such as an alternative provider or restricting the affected processing. If unresolved, continuation or termination of the affected service is addressed under the service agreement. Website advertising providers are not necessarily clinic-data subprocessors.
Considering the nature of processing and information available, Vetigen assists the clinic with data subject requests, security, breach notification, data protection impact assessments and consultation with authorities. Requests received directly about clinic data are referred to the relevant controller; except where legally required, Vetigen does not independently decide on the clinic’s behalf.
Vetigen provides information necessary to demonstrate compliance with this DPA and contributes to audits by the clinic or its authorized independent auditor. The parties arrange scope, notice, confidentiality and methods protecting other customers; these arrangements do not remove statutory audit rights.
As processor, Vetigen notifies the clinic of a personal data breach without undue delay after becoming aware of it. Available information includes the nature of the breach, affected data/subject categories, likely effects, measures taken/proposed and a contact point, supplemented in stages if needed. The clinic retains its duties to notify authorities and affected individuals.
International processing requires a valid transfer mechanism under applicable law. This DPA does not itself substitute for a KVKK standard contract, EU standard contractual clauses or a UK transfer document. Providers, countries, data types and applicable safeguards are determined for the service; required documents are part of the transfer conditions.
At service end, personal data is returned or deleted at the clinic’s choice and existing copies deleted, except where retention is required by law. Scope and timing account for data ownership, the export request and necessary technical steps. Access to legally retained data remains limited to that purpose.
Deleting a personal account is separate from ending the clinic agreement. Neither constitutes an instruction to erase unrelated clinics’ or other controllers’ records wholesale. Automatic blanket deletion after 90 days or generation of a deletion certificate is not the default process under this agreement.
Send privacy and data requests to Vetigen Incorporation at hello@vetigen.com. Describe your request, the relevant account or clinic, and how to contact you. We may request proportionate information to verify your identity; do not send passwords or verification codes.
For any questions or concerns regarding this policy, please contact us at legal@vetigen.com