Legal
Data Processing Addendum
Version 1.0 · Last updated: 17-07-2026
This Data Processing Addendum (the “Addendum”) forms part of, and is incorporated into, the Terms & Conditions between MaxPet Limited (“MaxPet”, “we”, “us”) and the veterinary practice that holds a MaxVet Clinic account (the “Clinic”, “you”). It records how the parties handle personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and is written so a practice can hand it to its own data protection officer or adviser. Terms defined in the Terms & Conditions have the same meaning here.
1. Roles and scope
1.1 MaxVet involves two different flows of personal data, and a different data-protection role applies to each. This table is the single source of truth for which regime governs a given field; the rest of this Addendum follows it.
| Data flow | Examples | Our role | Governed by |
|---|---|---|---|
| Part A — Clinic-originated data | Your clinic and user accounts and identity data; documents your clinic uploads to a patient record; appointments and messages your clinic sends to clients; the name and email address you supply when you invite a client. | We act as your processor, processing this data on your documented instructions. | Clauses 2–10 (full Art 28(3) processor terms) + Annexes 1–3. |
| Part B — Owner-shared pet record | The health record a pet owner logs in the MaxPet app (weight, diet, symptoms, medication, activity, etc.) and chooses to share with your clinic by adding you to the pet’s care team, together with the owner’s own contact details. | You and MaxPet Limited are each an independent (separate) controller — we are not your processor for this data, and we are not joint controllers. | Clause 11. |
1.2 Role classification can be fact-sensitive. If your clinic uses the platform in a way not contemplated here, the roles may differ; you should take your own advice. Where a single item could fall under either flow, the classification above governs unless we agree otherwise in writing.
2. Part A — where we act as your processor
2.1 Clauses 3 to 10 set out our obligations under Article 28(3) of the UK GDPR and apply solely to Part A data — the personal data we process on your behalf as your processor. They do not apply to Part B (see clause 11).
2.2 The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex 1.
3. Processing on documented instructions
3.1 We will process Part A personal data only on your documented instructions, including as to any transfer to a country outside the UK, unless we are required to process it by law that applies to us; in that case we will inform you of that legal requirement before processing, unless the law prohibits us from doing so.
3.2 This Addendum, together with the settings you configure in the product and any written instructions you give us through the account, form your documented instructions. If, in our opinion, an instruction infringes the UK GDPR or other UK data protection law, we will inform you without undue delay.
4. Confidentiality
4.1 We ensure that any person authorised to process Part A personal data (including our staff and contractors) is bound by an appropriate obligation of confidentiality, whether contractual or statutory.
5. Security
5.1 Taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32. Our current measures are described in Annex 2.
6. Sub-processors
6.1 You give general written authorisation for us to engage the sub-processors listed in Annex 3 to process Part A personal data.
6.2 Before we add or replace a sub-processor that will process Part A personal data, we will give you at least 14 days’ prior notice, by email to your stated contact and/or by updating Annex 3 with a dated change note. You may object in writing within 14 days on reasonable data-protection grounds. We will work with you in good faith to address the objection; if it cannot be resolved, you may, as your sole remedy, terminate the affected part of the service. If you do not object within that period, the change is treated as authorised.
6.3 We impose on each sub-processor, by a written contract, data protection obligations equivalent to those in this Addendum, and we remain fully liable to you for each sub-processor’s performance of its obligations.
7. Assisting with data-subject rights
7.1 Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, to fulfil your obligation to respond to requests from individuals exercising their rights under Chapter III of the UK GDPR (such as access, rectification, erasure, restriction, portability and objection). If a data subject sends such a request directly to us in relation to Part A data, we will forward it to you without undue delay and will not respond ourselves except on your instruction or as required by law.
8. Breaches, DPIAs and other assistance
8.1 Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations under Articles 32 to 36 of the UK GDPR (security, personal data breach notification, data protection impact assessments and prior consultation).
8.2 Where we become aware of a personal data breach affecting Part A personal data, we will notify you without undue delay, and in any event within 48 hours of becoming aware. The notification will include, to the extent then known and on a phased basis where necessary: the nature of the breach and, where possible, the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a single named contact point. We will provide further information as it becomes available without undue further delay.
8.3 As your processor, we do not notify the Information Commissioner’s Office or affected individuals on your behalf; that remains your responsibility as controller. We will give you reasonable assistance to meet your own Article 33 and 34 obligations.
9. Return and deletion
9.1 On the end of the provision of services relating to processing, at your choice we will either return to you or delete all Part A personal data, and delete existing copies, unless UK law requires us to keep it. Unless you tell us otherwise, our default is to make the data available for you to export for 30 days after your account closes and then to delete it, and in any event to delete it within 90 days of account closure. Personal data held by our sub-processors is deleted in accordance with their standard deletion cycles.
10. Information and audit
10.1 We make available to you all information reasonably necessary to demonstrate our compliance with Article 28, and we allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
10.2 So that audits do not compromise the security of other customers, we may satisfy an audit request by providing our then-current security documentation and answering reasonable written questions; a physical inspection may take place on reasonable prior notice, no more than once a year (unless required by a regulator or following a breach), during business hours, subject to confidentiality, and without accessing other customers’ data. You bear your own costs of an audit.
11. Part B — where we are independent controllers
11.1 For the owner-shared pet record (Part B), your clinic and MaxPet Limited are each an independent controller. The owner and MaxPet operate the consumer MaxPet app under MaxPet’s own Privacy Notice; your clinic uses the shared record for your own clinical purposes. Neither party determines the other’s purposes or means, so we are not controller-and-processor and not joint controllers for this data, and no Article 28 processor contract governs it.
11.2 Each party is separately responsible for: its own lawful basis for processing; its own transparency to data subjects; responding to data-subject requests it receives; its own Article 32 security; and its own Article 33 and 34 breach reporting. Each party is responsible for its own compliance and answers for its own failures.
11.3 The parties will notify each other without undue delay of any personal data breach affecting the shared record, and will give each other reasonable assistance and information to meet their respective obligations. This clause reflects good practice under the ICO’s Data Sharing Code; it does not make the parties joint controllers.
11.4 Access to a pet’s record depends on the owner adding your clinic to the pet’s care team and continues only for as long as the owner allows; the owner may withdraw it at any time.
12. International transfers
12.1 Our hosting is UK/EU-based. Where a sub-processor processes personal data outside the UK, the transfer is protected by an appropriate safeguard recognised under UK law, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy regulation. Details are noted in Annex 3.
13. Liability and precedence
13.1 This Addendum is subject to the limitations and exclusions of liability in the Terms & Conditions, which apply to the parties’ total liability under the Terms and this Addendum together.
13.2 If there is any conflict between this Addendum and the rest of the Terms & Conditions on the handling of personal data, this Addendum prevails; on all other matters the Terms & Conditions prevail.
14. General
14.1 This Addendum is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, in line with the Terms & Conditions.
14.2 We may update this Addendum from time to time to reflect changes in the service, our sub-processors or the law. We will change the version and date above and, for material changes, take reasonable steps to bring them to your attention.
Annex 1 — Details of the processing (Part A)
| Subject-matter | Provision of the MaxVet clinic portal and related storage, display and transmission of clinic-originated data. |
|---|---|
| Duration | The term of your Clinic account, plus the return/deletion window in clause 9. |
| Nature & purpose | Hosting, storage, display and transmission of clinic accounts, uploaded clinical documents, and the appointments, messages and client invitations your clinic chooses to create and send — all on your instructions. |
| Types of personal data | Clinic staff account and identity data (name, work email, role, hashed credentials); the name and email address of clients your clinic invites; free-text clinical notes and documents your clinic uploads, which may contain a client’s identity and, incidentally, information about the client. Pet clinical data is not itself personal data, but the human identifiers linked to it are. |
| Categories of data subject | Your clinic’s personnel (owners, vets, nurses, reception), and the pet owners (clients) your clinic invites or contacts. |
Annex 2 — Technical and organisational security measures
We maintain measures appropriate to the risk, including:
- Encryption in transit — the service is served only over HTTPS with HTTP Strict Transport Security (HSTS).
- Access control — access to any pet’s record is enforced server-side by owner-granted care-team permissions and role-based access within a clinic; least-privilege administrative access.
- Authentication & sessions — passwords are stored only in hashed form; session cookies are marked Secure and HttpOnly; forms are protected against cross-site request forgery; sign-in via Apple or Google is supported.
- Application security — a strict Content Security Policy; signed, expiring URLs for stored images; per-IP rate limiting and a bot challenge on public forms.
- Infrastructure — hosting, database, object storage, content delivery and a web application firewall provided by Cloudflare, with access logging.
- Assurance — security testing (including dynamic application security testing) and vulnerability management; staff and contractor confidentiality undertakings; breach detection and response.
These measures are kept under review and may be improved over time; we will not reduce the overall level of security during your use of the service.
Annex 3 — Authorised sub-processors
We engage the following sub-processors to process Part A personal data. Each is bound by a written contract with data protection obligations equivalent to this Addendum, and any transfer outside the UK is covered by an appropriate safeguard (such as the UK IDTA / UK Addendum to the EU SCCs).
| Sub-processor | Service | Data it processes |
|---|---|---|
| Cloudflare, Inc. | Application & website hosting, database, object/file storage, content delivery, security/WAF, and text extraction (OCR) of uploaded documents. | All Part A data at rest and in transit. |
| Resend (Plusdocs, Inc.) | Delivery of transactional and notification email (team and client invitations, appointment and message emails, password resets). | Recipient name and email address, and the content of the email. |
| Apple Inc. | Delivery of push notifications to clinic devices (Apple Push Notification service), and Sign in with Apple where a user chooses it. | Device push tokens, notification content, and sign-in identifiers. |
| Google LLC | Delivery of certain outbound email, and Sign in with Google where a user chooses it. | Email content and recipient address, and sign-in identifiers. |
This Addendum is provided in good faith and is written to reflect the law of England and Wales. It is not legal advice; if you need advice on your specific circumstances you should consult a solicitor.