Document contents
PetSpot Data Processing Agreement for Clinics
Version 1.0 Last updated: 10 September 2026
1. Parties and formation
These data-processing terms apply between PetSpot Technologies LLC, Georgia, identification number 422961637, and the clinic whose legal entity is identified in a services contract or order entered into with PetSpot, the “Clinic”.
PetSpot Technologies LLC was registered on 7 September 2026. Registered address: Georgia, Ambrolauri Municipality, Khvanchkara village, block N001, plot N047 Namosakhlevi. Agreement contact: support@petspot.love; additional contact: petspot@petspot.love.
This Agreement becomes part of the parties’ relationship when expressly incorporated into a signed contract, agreed order or another valid written/electronic instrument recording the parties, representative’s authority and accepted version. Publication, creation of a staff account or silence does not replace this process.
The contract or order records the Clinic’s legal name and ID, address, authorised representative, data contact, branches and service scope. The information and permissions required by the annexes are agreed before the relevant processing starts.
2. Roles and boundaries
The Clinic is the controller of its clients’, representatives’, workers’ and other individuals’ data in organising and providing its services. PetSpot is the processor of these data on the Clinic’s instructions.
PetSpot separately determines processing for its own platform accounts, security, contractual contacts and requests addressed directly to PetSpot. The Privacy Policy applies to those purposes. Independent-controller status does not allow PetSpot to use the clinical database for unagreed purposes of its own.
A clinic’s access to information from a user’s personal pet record requires an appropriate basis and access grant. Where a specific process involves jointly determined purposes, the parties allocate duties separately in writing; this Agreement does not automatically designate all processes as joint processing.
3. Subject matter, duration and instructions
PetSpot processes entrusted data to provide agreed cabinet features: client records, scheduling, bookings, queues, the practitioner workspace, documentation, laboratory management, communications, notifications, team administration, records and operational reporting within the connected service scope.
Processing lasts for the relevant instruction and lawful completion of return/deletion, subject to mandatory deadlines. An indefinitely existing account does not itself establish a retention period for clinical records.
Documented instructions include the contract, order, this Agreement, confirmed directions from authorised representatives and cabinet actions within their permissions. Instructions must not concern other clinics or users beyond lawful authority. PetSpot informs the Clinic of a suspected unlawful instruction and does not implement it until the issue is resolved; mandatory legal duties remain applicable.
4. Clinic obligations
The Clinic determines and records lawful purposes, grounds, necessary data categories, retention periods and staff permissions. It provides timely notices, including where an administrator enters a person’s information before that person creates a PetSpot account, and obtains consent where necessary.
The Clinic is responsible for lawful professional-document content and grounds for disclosure to an owner, another clinic or a laboratory. Record access does not replace consent to treatment. The Clinic must not instruct PetSpot to collect unnecessary identity documents or excessive sensitive information.
The Clinic keeps memberships and access rights current, ends access for departing or blocked staff, and avoids shared accounts where individual accountability is required. It informs PetSpot of requirements affecting lawful processing and retention.
5. PetSpot obligations
PetSpot processes data only for agreed purposes and documented instructions, except for processing expressly required by law. In that case, it informs the Clinic unless notification is prohibited.
PetSpot ensures confidentiality commitments for persons admitted to the data, proportionate technical and organisational safeguards, assistance with data-subject rights and information for verifying performance. Data is not used for sale, advertising, training publicly available AI models or creating an unagreed cross-clinic database.
Transfers between veterinary clinics, external AI and content-bearing Telegram integrations are not automatically authorised by this Agreement. They require separate instructions, notices, a legal basis and necessary approvals.
6. Other processors
Engaging another processor to assume processing duties requires the Clinic’s prior written consent in accordance with applicable law. An agreed named list forms part of the contract/order or its annex. Lack of objection or updating a webpage is not itself written consent.
PetSpot provides the supplier’s legal identity, function, data and countries, imposes necessary contractual obligations and remains responsible for its entrusted processing. A new supplier or material change in approved scope receives the necessary approval before data is transferred.
Where lawful approval is unavailable, the parties address an alternative, restriction of the affected feature or ending its use, without unlawfully withholding data.
7. International transfers
Before a relevant transfer, the parties determine recipients, countries, grounds and safeguards. Locating one server function in Europe is not evidence that all data is located there.
This Agreement is not itself a supervisory-authority permit, a client’s consent or a universal guarantee that any transfer is lawful. Where a mechanism under Georgian law requires a permit, it must be obtained before transfer. Onward transfers must also meet the applicable grounds and safeguards.
Additional contractual mechanisms required by another applicable jurisdiction are arranged separately. This text is not automatically designated as EU Standard Contractual Clauses.
8. Security and incidents
Minimum security obligations are in Annex 2. The parties take account of scope, context, risks, the public nature of particular material and access needs. A cloud supplier’s certification does not certify the entire PetSpot platform.
PetSpot informs the Clinic immediately upon identifying an incident affecting entrusted data. Initial notice is not delayed until the investigation ends. Available information includes the incident’s nature, affected categories, likely consequences, measures and a contact; further facts are supplied as established.
The Clinic assesses subject and authority notification requirements and deadlines for processing for which it is responsible. PetSpot assists the investigation and fulfilment of those obligations and performs its own controller duties for its own processes. This Agreement does not extend statutory deadlines.
9. Requests from individuals and authorities
PetSpot forwards requests relating to entrusted data to the Clinic without unjustified delay. PetSpot assists in locating data, access/copies, rectification, restriction and deletion within law and instruction. Individuals’ rights to approach responsible parties are not restricted.
The parties respond to lawful authority requests within their powers. Only necessary information is disclosed. PetSpot informs the Clinic of demands concerning its data where legally permitted. A Clinic’s refusal to cooperate does not authorise PetSpot to breach an independent legal duty.
10. Verification
PetSpot provides necessary information concerning performance and permits proportionate verification by the Clinic or an agreed independent reviewer, subject to confidentiality and other clients’ security.
The procedure is arranged to avoid excessive risk without obstructing lawful oversight, incident investigation or an authority’s demand. Verification must not require access secrets or unrelated clinics’ personal information. Costs must not be used to obstruct mandatory review or the exercise of data-subject rights.
11. Return, deletion and termination
When entrusted processing ends, PetSpot stops the relevant processing and immediately returns the entrusted data to the Clinic in full as required by law; subsequent deletion or transfer follows lawful instructions and mandatory rules. Return includes an agreed structured export and related files, not merely screenshots. This Agreement does not promise a self-service export button.
Copies are deleted except where a specific legal obligation requires retention. An exception identifies data, grounds, duration and use restrictions. Backups are not used to continue ordinary processing after termination or bypass rights. Statutory rules requiring cessation of processing and return of data in a processing dispute remain applicable.
Data is not withheld as security for payment or as leverage. Ending a Clinic contract does not entitle it to erase independent user accounts or original personal pet records outside the Clinic’s entrusted database. Shared records and lawful obligations are distinguished.
On completion, PetSpot confirms the actions and justified exceptions. Confidentiality and protection duties continue while data is lawfully retained.
12. Priority and responsibility
For entrusted processing, this Agreement prevails over conflicting general Terms. Mandatory law prevails over any contract. Responsibility follows actual roles and law; the parties cannot contract away mandatory individual rights.
Material changes to processing scope or permissions require appropriate documentation and consents, not merely a website change. The main contract determines governing law and commercial-dispute arrangements, preserving mandatory Georgian rules. Translations do not limit individual rights.
Annex 1. Description of entrusted processing
Individuals: clients and representatives; Clinic workers, practitioners and contacts; message participants; supplier contacts where entered in the cabinet.
Data: names, contacts and identifiers; roles and work schedules; animal information associated with a person; bookings, visits, queues, complaints, examinations, prescriptions, results, documents and attachments; messages and service markers; creation/modification information; minimal technical data for relevant features.
Operations: collection, recording, organisation, storage, retrieval, display to authorised persons, updating, document preparation, agreed disclosure, restriction, return, erasure and anonymisation.
Scale and frequency: within branches and features connected by the Clinic; user actions, agreed background processes and the duration of the instruction. The Clinic specifies category details and periods in its retention instructions.
Exclusions: human health data and other special categories are not entrusted as a standalone feature without separate assessment and written agreement. Veterinary information does not automatically become human health information, but owner links are protected. Advertising, AI training and automatic disclosure to unrelated clinics are excluded.
Annex 2. Minimum security obligations
Entrusted processing requires secure transmission; authentication and permission management; separation of clinics’ and branches’ data within authorised access; staff confidentiality; privileged server-operation controls; secret protection; records of material operations and incidents; proportionate vulnerability management; and documented retention, return and deletion.
Local caches and backups in use require access controls and clearing/restoration procedures consistent with individual rights. Link-based access takes account of validity, forwarding and data sensitivity. Public avatars and images are not treated as restricted clinical files.
These are contractual requirements, not a promise of end-to-end encryption, a round-the-clock response team, a particular recovery time or certification. Separate availability and backup guarantees exist only where expressly agreed.
Annex 3. Supplier approval
The technology arrangement may include Google/Firebase/Google Cloud for infrastructure and server operations, Vercel for the web cabinet and Resend for service emails. Before entrusting data, a named register of the actual contracting legal entities is approved, stating functions, data categories, countries and transfer mechanisms.
Google Analytics is not automatically treated as the clinical database’s cloud processor. Apple/APNs and other delivery channels are assessed according to the actual process and recipient role. OpenAI and Telegram are not automatically approved recipients of clinical documents. Connecting them requires a separate description, legal grounds and approval.
Where the register and necessary grounds are not yet agreed, publication of this text does not authorise the relevant transfer. The approved register and retention instructions form part of the written arrangements with the specific Clinic.