Skip to content

Legal

Data Processing Addendum

Last updated: August 9, 2026 · Eskaris LLC, Florida, United States

The processing terms between your practice and VetVero — part of the Terms of Service, formalizing the roles our Privacy Policy describes.

1. Parties & incorporation

This Data Processing Addendum (“DPA”) is between Eskaris LLC, the Florida limited liability company operating VetVero (“we,” “us”), and the veterinary practice that has accepted the Terms of Service (the “Customer,” “you”). It is incorporated into the Terms by reference and applies whenever we process Customer Data in providing the Service.

Order of precedence: if this DPA and the Terms conflict on the processing of personal data, this DPA prevails; for everything else, the Terms govern.

The Service is offered to practices in the United States and Canada only. It is not offered to practices subject to the GDPR or UK GDPR, and this DPA deliberately contains no EU or UK transfer mechanisms.

2. Definitions

  • “Customer Data” has the meaning given in Terms §7: patient and medical records, client information, financial records, and everything else your practice enters into VetVero.
  • “Practice Records” means the subset of Customer Data consisting of patient records, pet-owner personal information, and clinical records — the data our Privacy Policy §2 places under your practice’s control.
  • “Applicable Privacy Laws” means the California Consumer Privacy Act as amended by the CPRA, comparable US state privacy laws, and Canada’s PIPEDA, in each case as they apply to the parties.
  • “Personal information” takes its meaning from the Applicable Privacy Laws.

3. Roles

The roles described in Privacy Policy §2 apply as contractual allocations:

  • for Practice Records, your practice is the business (controller) and Eskaris LLC is your service provider (processor), acting only on your instructions as expressed in the Terms, this DPA, and your use of the Service;
  • for account, billing, and technical data about your practice and staff, Eskaris LLC is the business (controller), as described in the Privacy Policy.

4. CCPA service-provider terms

With respect to Practice Records, we certify that we will:

  • process personal information solely to provide and support the Service for your practice — the business purpose — under the Terms and your documented instructions;
  • not sell personal information;
  • not share personal information for cross-context behavioral advertising;
  • not retain, use, or disclose personal information outside our direct business relationship with your practice or for any purpose other than the business purpose, except as Applicable Privacy Laws permit;
  • notify you if we determine we can no longer meet our obligations under Applicable Privacy Laws, and permit you to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.

5. PIPEDA processing terms

For Canadian practices, we provide a comparable level of protection for Practice Records while they are processed by us in the United States, using the safeguards in Section 7. As Privacy Policy §10 explains, processing happens in the United States, and your practice is responsible for its own transparency to its clients about that.

We assist your practice with access and correction requests concerning Practice Records as described in Section 9.

6. Confidentiality

We ensure that personnel authorized to process Customer Data are bound by written or statutory confidentiality obligations before they process it.

7. Security

The safeguards described in Privacy Policy §7 — tenant isolation enforced at the database level, encryption in transit and at rest, private file storage behind short-lived signed URLs, role-based access, and audit logging — are the security baseline for processing under this DPA.

We may evolve individual measures as the Service develops, but we will not materially degrade the overall security of the Service during the term of this DPA.

8. Sub-processors

Your practice authorizes the sub-processors listed in Privacy Policy §5, for the purposes stated there. We may update that list with notice as described in the Privacy Policy.

We remain responsible for our sub-processors’ performance under this DPA to the same standard as our own.

9. Assistance

Privacy requests are routed as Privacy Policy §2 describes: pet owners direct requests about Practice Records to your practice, and we assist you in fulfilling them — access, correction, deletion, and portability — taking into account the nature of the processing and the information available to us.

We provide reasonable cooperation with your practice’s own compliance obligations under Applicable Privacy Laws to the extent they concern our processing of Practice Records.

10. Breach notification

If we confirm a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data, we will notify the affected practice without undue delay. The notice will describe, to the extent known, the nature and scope of the breach, the categories of data affected, and the remediation measures taken or planned, and we will provide updates as our investigation progresses.

11. Return & deletion

You can export your Customer Data as CSV files at any time — during the term and throughout the retention window that follows it. After your subscription or trial ends, Customer Data is retained for 90 days and then permanently deleted, as stated in Terms §7 and Privacy Policy §8 (including the encrypted-backup rotation caveat described there).

12. Audit & information rights

On written request, no more than once per year, we will provide documentation describing our processing and security practices and written responses to your practice’s reasonable questions, sufficient to demonstrate compliance with this DPA. This DPA does not grant on-site audit rights.

13. Liability

Liability arising under this DPA is subject to the limitations and the cap in Terms §12. This DPA creates no separate or additional cap and no liability beyond what the Terms allow.

14. Term & survival

This DPA takes effect when the Terms do. It does not lapse while we still hold Customer Data: every obligation in this DPA — including Sections 4, 6, 7, 8, and 10 — continues to apply throughout the post-termination retention window described in Section 11, until Customer Data is deleted. Return and deletion (Section 11) and liability (Section 13) survive until fulfilled.

15. Contact

Questions about this DPA:

Eskaris LLC — VetVero

Florida, United States

legal@vetvero.com · Contact form