Data Processing Addendum
Last updated: August 27, 2026
This addendum sets out the terms on which VetFlow processes data on behalf of a subscribing practice: who acts as controller and who as processor, exactly what categories of data are involved, which sub-processors are used, how the service is secured, and what happens to your data when you leave.
1. Scope and roles
This addendum applies whenever VetFlow processes data on behalf of a subscribing practice. It forms part of the Terms of Service and takes precedence over those terms for anything specifically about processing on your behalf.
Your practice is the controller: you decide which appointments exist, which staff get logins, and what the board is used for. VetFlow is the processor: we handle that data only to provide the service and only on your instructions. Your instructions are the configuration you set — your locations, your staff, your shift setups, your connected scheduler — together with the Terms of Service.
For our own customer records — your account, contact details and billing — we act as a controller, and the Privacy Policy governs that.
2. Subject matter and duration
The subject matter of processing is the operation of the VetFlow clinical workflow and treatment board service for your licensed locations. Processing begins when your practice is provisioned and continues for as long as your subscription is active, plus the short deletion window described below.
3. Categories of data subject
- Your staff — owners, practice managers, doctors, nurses and receptionists who hold or share a login.
- Your clients — the pet owners named on the appointments read from your scheduler.
- Your patients — the animals themselves, whose data is not personal data but is processed alongside it.
4. Categories of data processed
- Staff identifiers — name, work email, role, and the practice and location their login is scoped to.
- Client identifiers — the client (owner) name as it appears on the appointment.
- Patient and visit details — patient name, species, reason for visit, appointment time and status, assigned doctor and nurse, room placement, visit start and discharge times.
- Workflow content your staff create — checklist completions, help call notes, patient alerts, broadcast alerts and staff chat messages.
- Operational records — sync heartbeats, reconcile and quarantine logs, and extension version information.
5. No special category or human health data
VetFlow is designed for veterinary workflow. It does not require special category personal data, and it must not be used to process human patient health information. Please keep clinical notes about people out of free-text fields such as help notes, patient alerts and staff chat.
6. Our obligations as processor
- Process your data only to provide the service, and only on your documented instructions — never for our own unrelated purposes and never to build a product from your clinical data.
- Keep your data confidential, and limit access to the personnel who need it to run and support the service.
- Maintain appropriate technical and organisational security measures, described below.
- Assist you, so far as we reasonably can, with data subject requests, impact assessments and regulator enquiries relating to data we hold for you.
- Notify you without undue delay if we become aware of a personal data breach affecting your data, with the information we have at the time.
- Delete or return your data at the end of the engagement, as set out below.
7. Your obligations as controller
- Make sure you have a lawful basis for the appointment and client data your scheduler exposes to VetFlow, and that your own privacy notices cover its use in a floor board.
- Confirm that connecting your practice management system to VetFlow is permitted under your agreement with that vendor.
- Issue, scope and revoke logins responsibly — including deciding whether to use shared per-clinic logins, and removing access when someone leaves.
- Keep out of VetFlow any data the service is not intended to hold, including human health information and payment card details.
8. Sub-processors
We use a small number of sub-processors to deliver the service. Each is bound to data protection obligations no less protective than these, and each receives only what it needs:
- Application hosting and database platform — hosts the application and stores your workflow data.
- Payment processing — handles subscription checkout and recurring billing. Card data goes to the processor, not to us.
- Transactional email delivery — sends invitations, password resets and notification emails.
9. Adding or changing sub-processors
You give general authorisation for the sub-processors above. If we intend to add or replace one in a way that affects your data, we will give you reasonable notice. If you have a legitimate data protection objection, tell us and we will work with you in good faith; if we cannot resolve it, you may cancel the affected subscription without further charge for periods not yet begun.
10. Security measures
- Encryption of data in transit.
- Tenant isolation enforced at the data layer — every record carries its owning practice and location, and access rules are applied to reads and writes rather than only in the interface.
- Role-scoped access, so a login only reaches the practice, location and operations it was issued for.
- Per-device keys for the browser extension, so machine access can be rotated or retired individually without disrupting other installations.
- Validation of outbound integration endpoints, so a connection cannot be pointed at internal infrastructure.
- A quarantine step that withholds a batch of scheduler data that appears to have come from the wrong clinic until a person reviews it, preventing cross-clinic exposure.
- Least-privilege access to production data by our personnel, limited to service operation and support.
11. International transfers
Our infrastructure and sub-processors may process data outside your own country. Where data protection law requires a transfer mechanism, we rely on an appropriate one — such as standard contractual clauses — together with the security measures above.
12. Audits and information
On reasonable written request, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably needed to demonstrate our compliance with this addendum. We may satisfy such a request with written responses and available documentation rather than on-site access, so that other practices' data and the security of the service are not put at risk.
13. Return and deletion of data
You can export your own data while your subscription is active, and we will help if you need assistance. On termination, we delete or de-identify your practice's clinical workflow data within a reasonable period, and we do not retain it for our own use.
We keep only the minimum account, billing and audit records we are legally required to keep, and those remain subject to the confidentiality and security obligations described here.
14. Liability and precedence
The limitation of liability in the Terms of Service applies to this addendum. Where this addendum conflicts with the Terms of Service on the processing of data on your behalf, this addendum governs.
If your practice needs a countersigned data processing agreement on your own template, tell us — we are happy to work through it.
Related documents
