Legal
Data Processing Agreement
- Effective date
- the date the Practice Administrator accepts this Agreement in the sign-up flow
- Last updated
- 27 May 2026
Working draft
This document is a working draft and has not been reviewed by a qualified solicitor. Before relying on it for live regulatory work it should be reviewed by a UK data protection lawyer.
Between
Josh Human trading as Human Builds, a sole trader established in the United Kingdom, providing the AHC Companion service at vetforms.co.uk(“Processor”, “we”, “us”, “our”)
and
The veterinary practice on whose behalf the Practice Administrator accepts this Agreement when creating an account on VetForms (“Controller”, “you”, “your”, the “Practice”)
(each a “Party”, together the “Parties”).
1. How this Agreement is entered into
This Agreement is accepted electronically by tick-box by the Practice Administrator at the point of creating the Practice’s account on VetForms. The Practice Administrator confirms that they have authority to bind the Practice. Acceptance is recorded in the audit log (Clerk organisation ID, user ID, IP address and timestamp) and a copy of the Agreement at the version current at acceptance is retained.
If your Practice requires a wet-signature DPA, an MSA, or any amendments, contact vetforms@humanbuilds.dev before accepting this Agreement in the product.
2. Scope, structure and order of precedence
This Agreement governs our processing of personal data on your behalf in connection with the Terms of Service(the “Principal Agreement”). It is entered into to satisfy the requirements of Article 28 of the UK GDPR.
If there is a conflict between this Agreement and the Principal Agreement on a matter of data protection, this Agreement prevails to the extent of the conflict. The Schedules form part of this Agreement.
3. Definitions
Terms in bold capitalsthat are not otherwise defined have the meanings given to them in the UK GDPR or the Data Protection Act 2018. “Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any successor or related UK legislation. “Personal Data”, “Process”, “Controller”, “Processor” and “Data Subject” have the meanings given to them in the UK GDPR. “Sub-Processor” means any third party we engage to Process Personal Data on your behalf.
4. Roles
You are the Controllerof the Personal Data set out in Schedule 1 (“Customer Personal Data”). We are the Processor of that Personal Data. Each Party is responsible for its own compliance with Data Protection Law in respect of its role.
You confirm that:
- you have a lawful basis under Article 6 of the UK GDPR for the Processing you instruct us to carry out;
- where required, you have given Data Subjects all information required by Articles 13 and 14 of the UK GDPR;
- your instructions to us comply with Data Protection Law; and
- you have authority to enter into this Agreement on behalf of the Practice.
5. Our processing obligations
We will Process Customer Personal Data only:
- in accordance with the documented instructions in this Agreement, the Principal Agreement, and the configuration choices you make in the AHC Companion product;
- as permitted or required by UK or EU law to which we are subject (and where we are required by law to Process Customer Personal Data on a basis other than your instruction, we will tell you of that requirement before Processing, unless the law prohibits us from doing so on important grounds of public interest); and
- to the extent reasonably necessary to provide, secure, debug, and support the VetForms service.
We will:
- ensure that personnel authorised to Process Customer Personal Data are bound by appropriate confidentiality obligations;
- implement the technical and organisational measures set out in Schedule 3 to ensure a level of security appropriate to the risk;
- assist you, taking into account the nature of the Processing and the information available to us, in your obligations to respond to Data Subject requests (Article 12–22), to keep Customer Personal Data secure (Article 32), to deal with personal data breaches (Articles 33–34), to carry out data protection impact assessments (Article 35), and to consult with the ICO where required (Article 36);
- make available to you all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR; and
- notify you promptly if, in our opinion, an instruction infringes Data Protection Law.
6. Sub-Processors
You consent to our use of the Sub-Processors listed in Schedule 2 for the Processing of Customer Personal Data.
We will:
- impose data protection obligations on each Sub-Processor that are no less protective than those in this Agreement;
- remain liable to you for the acts and omissions of each Sub-Processor as if they were our own;
- give you at least 30 days’ notice of any change to the list of Sub-Processors (by updating Schedule 2 at vetforms.co.uk/sub-processors and notifying the Practice Administrator by in-product notice or email); and
- give you a reasonable opportunity to object on legitimate data-protection grounds. If you object and the objection cannot be resolved within 30 days, either Party may terminate the affected part of the Principal Agreement without penalty (your sole remedy in respect of the objection).
7. International transfers
Some Sub-Processors are established outside the United Kingdom. Where Customer Personal Data is transferred from the UK to a country that the UK government has not declared to provide an adequate level of protection, we ensure that one of the following safeguards is in place:
- the UK International Data Transfer Agreement (IDTA) signed with the receiving party;
- the EU Standard Contractual Clauses as supplemented by the UK Addendum; or
- the UK Extension to the EU–US Data Privacy Framework, where the receiving party is certified under it.
You authorise us to enter into these instruments with Sub-Processors on your behalf where they are required.
8. Data Subject requests
If we receive a request from a Data Subject relating to Customer Personal Data, we will not respond directly (other than to confirm receipt or to direct them to you). We will tell you about the request within 5 working days and provide reasonable assistance to enable you to respond, including by providing access to or export of the relevant Personal Data through standard product functionality where available.
9. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and in any event no later than 48 hours after we become aware of it. The notification will include the information we are able to provide at that time, in the form required by Article 33(3) of the UK GDPR, and we will follow up with further information as it becomes available.
You are responsible for any notification to the ICO and to affected Data Subjects, as you are the Controller.
10. Audit
You may, no more than once in any 12-month period (unless required more frequently by the ICO or by Data Protection Law) and on reasonable prior written notice, request information reasonably necessary to demonstrate our compliance with this Agreement. We may satisfy that request by providing:
- a current SOC 2 or ISO 27001 report (our own or that of a relevant Sub-Processor);
- written responses to a reasonable security questionnaire; or
- a video call with the Processor to discuss the responses.
Any on-site audit is by mutual agreement and at your cost. You must keep all information disclosed under this clause confidential.
11. Return and deletion
On termination of the Principal Agreement, and at any point during it on your written request, we will (at your choice) return Customer Personal Data to you in a structured, commonly-used machine-readable format, or delete it, except where:
- we are required by law to retain the data (in which case we will tell you what we are retaining, why, and for how long); or
- the retention is necessary for regulatory recordkeeping required of a UK OV — in particular, the at least 3-year retention of issued AHCs — in which case we will retain it for that period only and only for that purpose.
Routine backups may continue to contain Customer Personal Data for up to 30 days after deletion from the live system, after which they expire. Backup copies are not accessed except for disaster recovery.
12. Liability
The liability of each Party under this Agreement is subject to the limitations and exclusions in the Principal Agreement, including the liability cap in section 13 of the Principal Agreement, which applies on an aggregate basis across both agreements. Nothing in this Agreement increases or decreases a Party’s statutory liability to Data Subjects under Article 82 of the UK GDPR.
13. Term and termination
This Agreement starts on the Effective Date and continues for as long as we Process Customer Personal Data for you. It terminates automatically on termination of the Principal Agreement. Clauses that by their nature should survive termination (in particular sections 9, 10, 11 and 12) survive.
14. General
- Governing law. This Agreement is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction.
- Notices. Notices to us go to vetforms@humanbuilds.dev. Notices to you go to the Practice Administrator email recorded in VetForms at the time the notice is sent.
- Changes. We may amend this Agreement on at least 30 days’ notice where the change is required to keep the Agreement compliant with Data Protection Law, or where the change does not materially reduce the protection afforded to Data Subjects. Other changes require your acceptance (which can be given by clicking through an updated version of this Agreement in-product).
- Entire agreement. This Agreement and the Principal Agreement are the entire agreement between the Parties on this subject and supersede any prior agreement on it.
Schedule 1 — Subject matter and details of Processing
| Subject matter | Preparation, validation and issue of UK-to-EU Animal Health Certificates (AHCs) for companion animals (dogs, cats, ferrets) by UK Official Veterinarians. |
| Duration | The term of the Principal Agreement, plus the retention period in section 11. |
| Nature and purpose | Collection, storage, structured retrieval, validation, PDF generation, and transmission of Customer Personal Data to enable the OV to certify and issue an AHC, and to maintain the regulatory audit trail. |
| Categories of Data Subject | Pet owners; authorised persons accompanying an animal on the owner’s behalf; named carriers; the Practice’s own OVs and staff (to the extent they appear on a certificate, e.g. the administering veterinarian for tapeworm treatment). |
| Categories of Personal Data | Owner / authorised person / carrier: full name, postal address, telephone number, email address, relationship to owner (where applicable), carrier name. Animal-linked data tied to an identifiable owner: species, breed, sex, name, date of birth, colour markings, microchip number and implant date and location, rabies vaccination history, tapeworm treatment history. Travel data: planned travel date, EU point of entry, scheduled arrival. Audit and technical: IP address used when submitting an owner-collection form, timestamps of certificate actions. |
| Special category data | None intended. Animal health data is not special category data under the UK GDPR. If special category data of a human is inadvertently entered into a free-text field, both Parties will treat it as such and we will assist you with removal on request. |
| Frequency | Continuous, on demand, for the duration of the Principal Agreement. |
Schedule 2 — Authorised Sub-Processors
The current list of Sub-Processors is maintained at vetforms.co.uk/sub-processors. At the Effective Date the list is:
| Sub-Processor | Service | Location of processing | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Application hosting, server-side PDF generation, file storage (Vercel Blob) for generated PDFs and stamp images | United States, with UK/EU edge regions where available | UK IDTA / SCCs + UK Addendum |
| Neon Inc. | Managed PostgreSQL database | UK/EU region selected for the VetForms project | Where any access from outside the UK occurs (e.g. operational support), UK IDTA / SCCs + UK Addendum |
| Clerk Inc. | Authentication, organisation management, user identity | United States | UK IDTA / SCCs + UK Addendum |
We may also use sub-processors for transactional email delivery and error monitoring. These will be listed at the URL above before they Process Customer Personal Data.
Schedule 3 — Technical and organisational measures
We maintain measures appropriate to the risk, including:
- Encryption in transit. All connections to the AHC Companion service use TLS 1.2 or higher.
- Encryption at rest. Provided by Neon (AES-256) and Vercel Blob.
- Access control. Role-based access control (OV, admin, support) enforced server-side. Multi-tenant isolation by
practiceId/ Clerk organisation ID; queries are scoped to a single Practice and there is no UI or API route that crosses tenants. - Authentication. Single sign-on via Clerk. Multi-factor authentication available; the Practice may enforce it for its members through the Clerk organisation.
- Tokenisation. Owner-collection forms are reached through single-use, time-limited tokens (currently 14 days) tied to a single certificate.
- Audit logging. Every state change on a certificate is recorded in an append-only audit log with user ID, action, and IP address.
- Least privilege. Production access is limited to the sole proprietor (Josh Human) and any documented support personnel. Access is via SSO and is logged.
- Backups. Routine database backups via Neon, with retention up to 30 days, after which backups expire.
- Patching. Dependencies are kept on supported versions. Critical security patches are applied within 7 days of release where the service is impacted.
- Personnel. Anyone with access to Customer Personal Data is bound by written confidentiality obligations.
- Sub-processor management. Each Sub-Processor is required by contract to apply measures no less protective than those above.
