Data processing agreement
This agreement applies between each organization using Petdocus (a rescue or a vet clinic — the controller) and the operator of Petdocus (the processor), for the personal data the organization enters about other people. An organization's admin accepts it in the app.
1. Parties
Processor: Condria Eduard-Dragos, Romania, operator of Petdocus during the free pilot (contact: condriaeduarddragos@gmail.com). Controller: the organization whose admin accepted this agreement in Petdocus.
2. Subject, duration, nature and purpose
The processor stores and processes personal data on the controller's behalf to provide Petdocus: keeping pet records, managing the organization's members, adoption transfers, sharing with partner rescues and vet clinics, and the change history. The agreement lasts as long as the organization uses Petdocus.
3. Types of data and data subjects
- Members of the organization: name, email, role, permissions; for clinics, vets' licence numbers.
- Adopters and owners: name and email; any contact data the organization records.
- Fosters and other people named in records or documents (for example on pet passports).
- Change history entries relating to these people.
No special categories of data are intended; the controller does not enter them.
4. Processor's obligations
- Process the data only on the controller's documented instructions — the use of Petdocus' features is the instruction — unless the law requires otherwise.
- Ensure that anyone authorised to process the data is bound to confidentiality.
- Implement appropriate technical and organisational measures (Art. 32): encryption in transit, secure password hashing, two-step verification for admins, server-side permission checks on every request, private file storage with logged views, append-only hash-chained audit log, EU-jurisdiction storage, point-in-time recovery.
- Engage sub-processors only as listed on the sub-processor page; inform controllers of intended changes so they can object; impose the same data protection obligations on them.
- Assist the controller with data subject requests (self-service export and erasure in the app; further help on request) and with Articles 32–36.
- Notify the controller without undue delay after becoming aware of a personal data breach, with the information available.
- At the end of the service, delete or return the data at the controller's choice (the organization export in Settings gives a full copy), unless the law requires storage.
- Make available the information needed to demonstrate compliance and allow for audits in a reasonable way.
5. Controller's obligations
- Have a legal basis for the data it records and inform the people concerned (for example adopters).
- Record only what is needed; keep notes free of unnecessary personal details.
- Give members only the permissions they need; keep two-step verification on for admins.
6. International transfers
Data is stored with EU jurisdiction. Sub-processors in the US are covered by the EU–US Data Privacy Framework and/or standard contractual clauses. Transfers to the United Kingdom rely on the EU adequacy decision for the UK.
7. Liability and law
Liability follows Art. 82 GDPR. Romanian law applies. This template will be reviewed by a lawyer before paid plans start; controllers will be asked to accept the reviewed version.