Data & Privacy

Data Processing Agreement

Scope and obligations for personal data processed on clinic instructions.

Effective Date: September 14, 2026
Last Updated: September 14, 2026
Version: 2.3.0

Parties and application

This Data Processing Agreement (DPA), to the extent incorporated into the service agreement, governs processing where the customer clinic is controller and US-based Vetigen Incorporation is processor. Visiting the website alone does not establish this agreement or data subject consent. Separately signed specific processing terms apply within their relevant scope.

Vetigen’s account, billing, security and website processing for which it determines purposes and means is separate from this processor role and is explained in the Privacy Notice.

Subject matter and duration

The subject matter is provision of the selected veterinary software and support service. Processing may include collection, organization, storage, authorized access, message delivery, requested AI operations, transfer, export and deletion. Duration depends on the service agreement, necessary return/deletion after termination and legal retention obligations.

  • Data subjects: clinic staff and users, customers/pet owners, contacts and other individuals whose information appears in records.
  • Data types: identity/contact details, clinic relationships, information linked to animals and care records, appointment and communication records, transaction/financial data and uploaded attachments.
  • Veti, SOAP, voice and document processing: content and clinic context needed for the enabled feature. Unnecessary human health data or other sensitive personal data should not be uploaded.

Clinic instructions and responsibilities

The clinic is responsible for determining legal bases for collection and transfer, providing required notices, obtaining separate consent where required, applying communication preferences and managing permissions. The service agreement, enabled features, authorized user actions and documented support requests define the instruction scope.

Vetigen processes data only on documented instructions and for agreed purposes, and informs the clinic of legally required processing unless prohibited by law. It informs the clinic if it considers an instruction to infringe data protection law, and the affected operation may be suspended pending clarification. This DPA does not authorize general-purpose model training on clinic data.

Confidentiality and security obligations

Vetigen must ensure that authorized people accessing data are bound by confidentiality and that technical/organizational measures are proportionate to risk. Relevant controls include authorization, clinic access boundaries and operation records. Measures are assessed against the service and processing risk.

Subprocessors

Subprocessors used for the service must be subject to arrangements carrying the relevant data protection obligations. Vetigen remains responsible for their performance as required by law and contract. Under this DPA, the clinic gives general authorization for listed subprocessors necessary for the service; additions or replacements require advance information and an opportunity to object on data protection grounds.

For an objection, the parties assess solutions such as an alternative provider or restricting the affected processing. If unresolved, continuation or termination of the affected service is addressed under the service agreement. Website advertising providers are not necessarily clinic-data subprocessors.

Rights requests, assistance and audit

Considering the nature of processing and information available, Vetigen assists the clinic with data subject requests, security, breach notification, data protection impact assessments and consultation with authorities. Requests received directly about clinic data are referred to the relevant controller; except where legally required, Vetigen does not independently decide on the clinic’s behalf.

Vetigen provides information necessary to demonstrate compliance with this DPA and contributes to audits by the clinic or its authorized independent auditor. The parties arrange scope, notice, confidentiality and methods protecting other customers; these arrangements do not remove statutory audit rights.

Personal data breaches

As processor, Vetigen notifies the clinic of a personal data breach without undue delay after becoming aware of it. Available information includes the nature of the breach, affected data/subject categories, likely effects, measures taken/proposed and a contact point, supplemented in stages if needed. The clinic retains its duties to notify authorities and affected individuals.

Transfer requirements

International processing requires a valid transfer mechanism under applicable law. This DPA does not itself substitute for a KVKK standard contract, EU standard contractual clauses or a UK transfer document. Providers, countries, data types and applicable safeguards are determined for the service; required documents are part of the transfer conditions.

Termination, return and deletion

At service end, personal data is returned or deleted at the clinic’s choice and existing copies deleted, except where retention is required by law. Scope and timing account for data ownership, the export request and necessary technical steps. Access to legally retained data remains limited to that purpose.

Deleting a personal account is separate from ending the clinic agreement. Neither constitutes an instruction to erase unrelated clinics’ or other controllers’ records wholesale. Automatic blanket deletion after 90 days or generation of a deletion certificate is not the default process under this agreement.

DPA contact

Send privacy and data requests to Vetigen Incorporation at hello@vetigen.com. Describe your request, the relevant account or clinic, and how to contact you. We may request proportionate information to verify your identity; do not send passwords or verification codes.

For any questions or concerns regarding this policy, please contact us at legal@vetigen.com