Data Processing Addendum
Effective 2026-05-28
This Data Processing Addendum ("DPA") forms part of the Terms of Servicebetween the clinic or chain ("Controller") and Proxie Innovations Labs Private Limited ("Processor") and governs the processing of personal data on the Vetra platform under the Digital Personal Data Protection Act, 2023 ("DPDPA").
1. Roles
The Controller is the data fiduciary for pet-parent and patient data entered into Vetra. The Processor (Proxie) is a data processor acting on the Controller's instructions, except where law requires otherwise.
2. Scope of processing
- Subject matter: provision of the Vetra clinic operating system to the Controller.
- Duration: the term of the subscription plus the 30-day export window.
- Nature & purpose: hosting, storing, indexing, searching, reporting, exporting and billing on Customer Data; sending transactional and operational communications.
- Categories of data subjects: pet parents, patients (pets), clinic staff, doctors, suppliers, employees.
- Categories of personal data: contact details, identity documents (where uploaded), clinical observations, prescriptions, payment records, attendance, payroll.
3. Processor obligations
- Process Customer Data only on documented instructions from the Controller, including the configuration of Vetra features.
- Ensure persons authorised to process Customer Data are bound by confidentiality obligations.
- Implement the technical and organisational measures described in the Security Statement.
- Assist the Controller, taking into account the nature of the processing, in responding to data-subject requests received via the Service.
- Notify the Controller without undue delay after becoming aware of a confirmed personal-data breach affecting their Customer Data.
4. Sub-processors
The Controller authorises the engagement of the sub-processors listed in the Privacy Policy. Proxie remains responsible for the acts and omissions of its sub-processors as if they were its own. New sub-processors are announced at least 30 days in advance; the Controller may object on reasonable grounds.
5. International transfers
Customer Data is primarily processed in Southeast Asia. Where data is transferred outside India by a sub-processor, that sub-processor's contractual safeguards (e.g. standard contractual clauses, certified practices) apply.
6. Audits
On reasonable prior notice and not more than once per twelve months (unless required by a data-protection authority), the Controller may request a copy of the latest available third-party audit report or independent assessment relevant to the Processor's security controls. On-site audits may be agreed in writing and at the requesting party's cost.
7. Return and deletion
At the choice of the Controller, the Processor will return or delete Customer Data at the end of the engagement, except where retention is required by law. The default behaviour is described in the Privacy Policy.
8. Liability
Liability under this DPA is subject to the limitations in the Terms of Service.
9. Governing law
This DPA is governed by the laws of India. Courts at Ludhiana, Punjab have exclusive jurisdiction.
10. Order of precedence
In case of conflict, this DPA prevails over the general Terms of Service with respect to the processing of personal data.