Data Processing Addendum
The UK GDPR processor terms that apply when PawPlanner handles personal data for a subscribing care business.
1. Scope and roles
This Data Processing Addendum (DPA) forms part of the Business Subscription Terms. It applies to Customer Personal Data processed by PawPlanner on the Customer's behalf. The Customer is the controller and PawPlanner is the processor, unless the parties' actual use of the data legally requires a different role.
The Customer instructs PawPlanner to process Customer Personal Data to provide, secure, support, maintain and improve the configured Service; to operate requested integrations; and to follow other documented lawful instructions consistent with the Agreement. The details of processing are in the Annex below.
2. Customer obligations
The Customer must comply with applicable Data Protection Law, give required privacy information, have a lawful basis for every processing purpose, minimise and keep data accurate, set retention rules, respond to individuals, and give PawPlanner lawful instructions. The Customer must not instruct PawPlanner to process data unlawfully.
Animal health information is not automatically special-category personal data, but linked records, messages or uploads can contain information about identifiable people. The Customer must avoid entering human health or other special-category data unless it is necessary, lawful and appropriately protected.
3. PawPlanner processor obligations
PawPlanner will process Customer Personal Data only on documented instructions, including for international transfers, unless UK law requires otherwise. Where permitted, we will tell the Customer before legally required processing. We will immediately inform the Customer if, in our opinion, an instruction infringes Data Protection Law and may pause the affected processing.
We will ensure that people authorised to process Customer Personal Data are bound by confidentiality, implement appropriate technical and organisational security measures, and make available information reasonably necessary to demonstrate compliance with Article 28 UK GDPR.
4. Security measures
Taking account of the state of the art, implementation cost, processing context and risks to people, PawPlanner will maintain measures designed to protect confidentiality, integrity, availability and resilience. Measures must be reviewed and tested and will include, as appropriate:
- encrypted HTTPS/TLS connections for production traffic and provider-managed encryption at rest where supported and configured;
- unique accounts, role-based access, tenant and client scoping, strong password hashing, session controls and multi-factor authentication for privileged platform administration;
- separation of production and test environments, secrets management, security updates, dependency review and least-privilege operational access;
- audit and security logging designed to avoid storing credentials, full payment-card data or unnecessary care content;
- backups, recovery procedures, monitoring and periodic restore tests appropriate to the assessed risk; and
- incident response, access removal, vulnerability handling and secure deletion procedures.
5. Personal data breaches
PawPlanner will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, likely consequences, affected data and people where known, and measures taken or proposed. PawPlanner may provide information in phases and will take reasonable steps to contain, investigate and remediate the incident.
The Customer is responsible as controller for deciding whether to notify the ICO or individuals. PawPlanner will provide reasonable assistance, taking account of the nature of processing and information available. Notification is not an admission of fault or liability.
6. Rights requests and compliance assistance
Taking account of the nature of processing, PawPlanner will provide reasonable technical and organisational assistance for access, correction, erasure, restriction, objection and portability requests. If we receive a request relating to Customer Personal Data, we will direct the person to the Customer unless law requires otherwise.
We will provide reasonable assistance with security obligations, breach assessment and notification, data-protection impact assessments and prior consultation. Bespoke or unusually extensive assistance may be charged at a reasonable rate agreed in advance unless required because of PawPlanner's breach.
7. Sub-processors
The Customer gives general written authorisation for the sub-processors listed in the Sub-processor List. PawPlanner will impose materially equivalent data-protection obligations on each sub-processor and remains responsible for its performance as required by Data Protection Law.
We will give at least 14 days' notice before a new sub-processor starts materially processing Customer Personal Data. The Customer may object during that period on reasonable, documented data-protection grounds. The parties will try in good faith to resolve the concern; if no reasonable alternative is available, either party may end the affected Service without penalty for the unused prepaid period.
8. International transfers
PawPlanner will not make a restricted transfer of Customer Personal Data unless it is covered by UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, another lawful safeguard, or a valid exception. Where required, PawPlanner will complete the applicable transfer assessment and implement supplementary measures.
The Customer authorises transfers made through the listed sub-processors subject to these safeguards. Data-region selection alone does not mean that support, telemetry or provider sub-processing never occurs outside that region.
9. Return, deletion and backups
At the end of the services involving processing, PawPlanner will, at the Customer's choice, return or delete Customer Personal Data unless UK law requires retention. The Customer must request and complete any available export during the stated export window. Deletion will be carried out under the published retention schedule.
Where immediate deletion from protected backups is not technically practicable, affected data will be put beyond ordinary use, protected under this DPA and overwritten through the established backup cycle. It will not be restored except for disaster recovery, and any restored deleted data will be removed again before ordinary use.
10. Audits
PawPlanner will provide relevant policies, summaries, certifications or questionnaire responses reasonably needed to demonstrate Article 28 compliance. If that is insufficient, the Customer may request one audit in a 12-month period by an independent auditor bound by confidentiality, on at least 30 days' notice, during normal hours and without access to another customer's data or to systems in a way that creates security risk.
The Customer pays its audit costs and PawPlanner's reasonable assistance costs unless the audit identifies a material breach by PawPlanner. More frequent audits are permitted where required by a regulator or following a relevant Personal Data Breach.
11. Annex: processing details
Subject matter and purpose: hosting and operation of PawPlanner's dog-care business-management functions and requested integrations. Duration: the subscription plus the export, deletion and backup-overwrite periods. Frequency: continuous and as initiated by authorised users.
Data subjects may include the Customer's owners, administrators, staff and contractors; clients and prospective clients; household or emergency contacts; veterinary contacts; invoice recipients; and people appearing in messages, photographs, documents or audit records.
Personal data may include names, contact and account information; addresses and access instructions; booking and service information; communications, photographs and documents; invoice and payment-status records; staff activity and audit information; technical identifiers; and dog/care information linked to an identifiable person. Full payment-card details are not intended to be processed by PawPlanner.
Processing operations may include collection, recording, organisation, storage, retrieval, consultation, display, transmission, synchronisation, export, backup, restriction, deletion and other operations necessary to provide the Service.
12. Governing terms and contact
The liability, governing-law and dispute terms in the Business Subscription Terms apply to this DPA only to the extent permitted by Data Protection Law. Nothing relieves either party of its direct statutory obligations or prevents an individual or regulator from exercising legal rights.
Data-protection and DPA questions may be sent to daniel@jenkinsinteractive.com.