Legal

Data Processing Agreement (Verwerkersovereenkomst)

Last updated: 19 July 2026 · Version 1.0

Zoravet company details are filled (Jensen Software, KvK 96526181). This is the standard template signed with every clinic; the clinic’s own details are completed at contract signing. This DPA sits under the main service agreement (Terms of Service / subscription contract) between Zoravet and the clinic; on data-protection matters this DPA prevails.

Parties

  • Processor (verwerker): Jensen Software, trading as Zoravet, KvK 96526181, Oanjelaan 32, 1421 AK Uithoorn, Netherlands (“Zoravet”).
  • Controller (verwerkingsverantwoordelijke): the veterinary clinic — legal entity name, address, KvK number and contact person are completed at contract signing (the “Clinic”).

Together the “Parties”. This DPA governs only the personal data that Zoravet processes on the Clinic’s instructions to provide the platform. It does not cover data for which Zoravet is itself controller (platform login accounts, security/operational data), which is governed by Zoravet’s own privacy policies.

1. Subject matter, nature, purpose and duration

  • Subject matter: processing of personal data through the Zoravet platform (pet-owner app + clinic portal + backend) to deliver hosted veterinary practice-management software to the Clinic.
  • Nature and purpose: storing and displaying client/pet/dossier data, managing appointments and messaging, invoicing and bookkeeping, sending transactional notifications, backups, security, and support — limited to what is necessary to provide the service.
  • Duration: for the term of the main service agreement. Obligations that by their nature survive — confidentiality, deletion/return, and liability — continue after termination.
  • Instructions: Zoravet processes personal data only on the Clinic’s documented instructions. The main service agreement, this DPA, and the Clinic’s configuration of the platform together constitute those documented instructions. Zoravet informs the Clinic if, in its opinion, an instruction infringes the AVG/GDPR or other applicable data-protection law.
  • Zoravet does not use the Clinic’s personal data for its own purposes.

2. Categories of data subjects and personal data

Matching the platform’s actual data inventory (see the app and portal privacy policies):

  • Data subjects:

    • the Clinic’s clients (pet owners);
    • the Clinic’s staff users of the portal.
  • Categories of personal data:

    • Owner identity and contact data (name, email, phone);
    • Pets and their animal medical dossiers (consultation notes, diagnoses, treatments, vaccinations, prescriptions, weight, lab results — data about the animal);
    • Appointments (requests, schedule, reason, status);
    • Messages exchanged between owner and clinic;
    • Invoices, payments and financial/bookkeeping records;
    • Bank transaction data: counterparty names, IBANs, and payment references of third parties (the Clinic’s suppliers and payers), imported from bank statements for bookkeeping and reconciliation;
    • Push-notification tokens and notification preferences/opt-ins;
    • Staff work-account data, roles/permissions, and audit records of actions taken.
  • Special-category (Art. 9) data: animal health data is not Art. 9 special-category data (which protects data about a human’s health and other sensitive categories about people). No human special-category data is intended to be processed. The Clinic must not enter human special-category data (e.g. an owner’s own health information) into free-text fields.

  • Payment-card data is not stored by the platform (confirmed 19 Jul 2026: no in-app card payments; pay-by-link is deferred). Should a payment provider be introduced, this section and the sub-processor list (Annex B) will be updated before activation.

3. Processor obligations

3.1 Instructions only

Zoravet processes personal data only as set out in section 1, on the Clinic’s documented instructions, and not for any other purpose.

3.2 Confidentiality

Personnel authorised to process the Clinic’s personal data are bound by an obligation of confidentiality (contractual or statutory) that survives the end of their engagement.

3.3 Security measures (technical and organisational)

Zoravet implements appropriate technical and organisational measures to protect the personal data, taking into account the state of the art, costs, and the nature/scope/context and risk of the processing (AVG/GDPR Art. 32). The measures are described in Zoravet’s Security Statement and summarised in Annex A to this DPA; they include at least:

  • Encryption in transit (TLS/HTTPS) and at rest (database, file storage and secrets encryption in the production environment);
  • Tenant isolation: strict, mechanism-enforced logical separation so one clinic cannot access another clinic’s data — enforced centrally in the application/data layer, failing closed. An independent three-reviewer isolation audit (July 2026) found zero confirmed cross-tenant data leaks;
  • Access control: role-based, least-privilege access; Zoravet staff access to production limited to operational/support need and logged;
  • Authentication via self-hosted Keycloak (OIDC), supporting strong credentials — MFA/TOTP is supported by Keycloak but not enforced by policy for staff or operators;
  • Audit logging of access and changes;
  • Backups: automated daily backups retained 7 days, with point-in-time recovery, stored in the EU;
  • Vulnerability and patch management, monitoring, and incident response.

The full, versioned measures are maintained in Annex A.

3.4 Sub-processors

  • The Clinic gives Zoravet general written authorisation to engage the sub-processors listed in Annex B (see the Subprocessors page for the current, full list):
Sub-processorPurposeLocation / transfer
Amazon Web Services (AWS)Hosting, compute, PostgreSQL database, file storage, backups, secretsEU region eu-central-1 (Frankfurt, Germany)
Amazon SESTransactional / notification emailEU region eu-central-1 (Frankfurt, Germany)
Google (Firebase Cloud Messaging)Push-notification deliveryUS-based; Google LLC certified under the EU–U.S. Data Privacy Framework, EU Standard Contractual Clauses as fallback under Google’s Data Processing Terms
  • Keycloak is self-hosted by Zoravet in the EU and is not a sub-processor.
  • Zoravet imposes on each sub-processor, by contract, data-protection obligations equivalent to those in this DPA (back-to-back). Zoravet remains fully liable to the Clinic for a sub-processor’s performance of those obligations.
  • Change notice: Zoravet informs the Clinic in advance of any intended addition or replacement of a sub-processor, giving the Clinic a reasonable period of 30 days to object on reasonable data-protection grounds. If the Parties cannot resolve a well-founded objection, the Clinic may terminate the affected service as its remedy.

3.5 International transfers

  • Primary storage and processing is in the EU (AWS eu-central-1, Frankfurt, Germany).
  • Push-notification delivery via Google may involve transfer outside the EEA; the transfer is covered by Google LLC’s EU–U.S. Data Privacy Framework certification, with EU Standard Contractual Clauses as fallback under Google’s Data Processing Terms.
  • Zoravet does not otherwise transfer the Clinic’s personal data outside the EEA without an appropriate Art. 44–49 transfer mechanism.

3.6 Assisting the Clinic

Taking into account the nature of processing and the information available to it, Zoravet assists the Clinic with:

  • Data-subject rights requests (access, rectification, erasure, restriction, portability, objection). The platform provides a synchronous data-export function for a pet owner’s own personal data (portability), exposed so the Clinic as controller can fulfil access/portability requests with Zoravet assisting. The self-service export deliberately excludes the animal’s clinical dossier and vet-authored content — that is the Clinic’s controller record and is provided via the Clinic. A deletion-request function routes an owner’s erasure request to the Clinic for controller decision; erasure itself is currently carried out as a manual staff action under the Clinic’s instruction, not a fully automated pipeline — stated honestly here rather than implied otherwise.
  • Security of processing (Art. 32);
  • Personal-data-breach notification (section 3.7);
  • Data protection impact assessments (DPIAs) and prior consultation where applicable.

Zoravet forwards any data-subject request it receives directly to the Clinic without undue delay and does not respond to it itself except on the Clinic’s instruction.

3.7 Personal data breach notification

  • Zoravet notifies the Clinic without undue delay and at the latest within 48 hours of becoming aware of a personal-data breach affecting the Clinic’s data. This is identical to the figure stated in the Security Statement.
  • The notice includes the information available: nature of the breach, categories and approximate numbers of data subjects and records affected, likely consequences, and the measures taken or proposed.
  • The Clinic, as controller, is responsible for notifying the Autoriteit Persoonsgegevens and, where required, the affected data subjects. Zoravet supports the Clinic but does not notify the AP on the Clinic’s behalf.

4. Deletion and return on termination

  • On termination of the service, at the Clinic’s choice, Zoravet returns the Clinic’s personal data in a usable export format and/or deletes it within 30–90 days of termination, unless EU or Dutch law requires continued retention.
  • Fiscal-retention carve-out: invoices and financial records subject to the Dutch fiscal retention obligation are retained for 7 years as required by law, even after termination; they are then deleted. Other legally mandated retention is likewise honoured, and the reason recorded. Automated enforcement of this retention floor is built and runs in dry-run mode today (counts only, no deletions); full, live enforcement is switched on at go-live, consistent with the Security Statement — today it is additionally applied manually where needed.
  • Backups containing the Clinic’s data are purged on the normal backup-rotation cycle (maximum 7-day retention window).
  • Zoravet confirms deletion in writing on the Clinic’s request.

5. Audit rights

  • The Clinic may audit Zoravet’s compliance with this DPA on reasonable prior notice, no more than once per year, and additionally after a personal-data breach affecting the Clinic or on a supervisory-authority request.
  • Zoravet may satisfy audits primarily by providing documentation — the Security Statement, the Annex A measures, and any third-party certifications or reports it holds (none exist today; no third-party security certification is on a committed roadmap — see the Security Statement, section 2). On-site or technical audits are reserved for where documentation is insufficient, are limited to the Clinic’s data and Zoravet’s own environment, must not compromise other clinics’ confidentiality or security, and are at the Clinic’s cost save where the audit reveals material non-compliance.

6. Liability

  • Liability under this DPA follows the limitations and allocations in the main service agreement, subject to the mandatory provisions of AVG/GDPR Art. 82. The precise liability position and any cap are finalised with the main service agreement as part of legal review; this DPA does not itself introduce a different position.
  • In case of conflict on data-protection matters, this DPA prevails over the main service agreement.

7. Governing law and jurisdiction

  • This DPA is governed by the law of the Netherlands.
  • Disputes are subject to the jurisdiction agreed in the main service agreement; absent such agreement, to the competent Dutch court.

Annexes

  • Annex A — Technical and organisational measures (full). The Security Statement constitutes Annex A in full.
  • Annex B — Sub-processor list (maintained and versioned). Current list reproduced in section 3.4 and on the Subprocessors page.
  • Annex C — Details of processing. Data subjects, personal-data categories, and purposes — captured in sections 1–2 above.

Signatures

This DPA is signed as part of the clinic onboarding process, alongside the main service agreement. For a copy of the signature page or to start onboarding, contact grc@zoravet.com.