How KHAN Solutions processes data on behalf of veterinary clinics using VETEK.
Effective Date: August 5, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between KHAN Solutions ("Processor") and the veterinary clinic or organization that subscribes to VETEK ("Controller"). The Controller determines the purposes and means of processing personal data entered into the VETEK platform; the Processor processes that data solely on documented instructions from the Controller. This DPA applies to all personal data processed in connection with the VETEK service and is governed by the applicable data protection law of the Controller's jurisdiction, including the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") where it applies.
The Processor processes the following categories of personal data on behalf of the Controller: (a) account and authentication data of clinic staff (names, work email addresses, roles, credentials), (b) client data (names, identification numbers, phone numbers, countries), (c) pet and patient data (species, breed, sex, color, birth dates, photographs), (d) clinical records (consultation notes, diagnoses, treatments, surgical documentation, hospitalization records, vaccination histories, laboratory results, emergency triage data), and (e) financial and transaction data generated by cash register operations. The Controller confirms that it is authorized to provide this data to the Processor.
The Processor processes personal data only to: (a) provide, operate, maintain, and secure the VETEK service, including multi-branch inventory tracking, cash register operations, and clinical record storage and retrieval, (b) provide support and maintenance, (c) comply with legal obligations applicable to the Processor, and (d) fulfill documented instructions of the Controller. The Processor will never sell personal data and will not use it for its own independent purposes, advertising, or profiling.
The Processor processes personal data for the duration of the Controller's subscription. Upon termination or expiry of the agreement, the Processor will, at the Controller's election, return or securely delete all personal data within thirty (30) days, except where applicable law requires continued retention. Backup copies are deleted according to the retention schedule in Section 9.
The Controller authorizes the Processor to engage the following subprocessors for the provision of the Service: (a) database infrastructure provider — managed PostgreSQL hosting, (b) object storage provider — encrypted storage of clinical evidence files and photographs, (c) email delivery provider — service and support communications, (d) content delivery network — static asset delivery for the web application, and (e) payment processing provider — processing of subscription payments (payment data never includes clinical data). Each subprocessor is bound by a written contract imposing data protection obligations at least as protective as this DPA. The Processor will notify the Controller of any new or replaced subprocessors at least thirty (30) days in advance; the Controller may object in writing, and if the objection is not resolved within thirty (30) days, the Controller may terminate the affected services without penalty.
The Controller is responsible for responding to requests from data subjects exercising their rights under the GDPR or other applicable law, including the rights of access, rectification, erasure, restriction of processing, data portability, and objection. Where a data subject submits such a request directly to the Processor, the Processor will promptly forward it to the Controller and provide reasonable technical assistance to enable the Controller to fulfill it, including access to, or rectification or deletion of, the relevant data through the Service's administrative tools. The Processor may charge a reasonable fee for assistance that is demonstrably excessive or repetitive.
The Processor will notify the Controller without undue delay and in any event within seventy-two (72) hours of becoming aware of a personal data breach affecting data processed under this DPA. The notification will include: (a) the nature of the breach, including the categories and approximate number of data subjects and records concerned, (b) the likely consequences, (c) the measures taken or proposed to address the breach and mitigate its effects, and (d) a point of contact for further information. The Processor will cooperate with the Controller's notifications to supervisory authorities and data subjects and will document all breaches, their effects, and remedial measures. The Processor will not publish or disclose a breach notification before the Controller has had a reasonable opportunity to comply with its own notification obligations, unless required by law.
The Controller's data is retained while the subscription is active. After termination: account and authentication data is deleted within thirty (30) days; client, patient, and clinical records are deleted or returned at the Controller's election within thirty (30) days unless a longer retention period is required by applicable veterinary record-keeping or tax law; financial records are retained for the period required by applicable tax law; and technical logs are retained for up to twelve (12) months. Rotating backup copies are deleted within thirty (30) days of the underlying data's deletion.
The Processor may store and process data in countries other than the Controller's own. Where the GDPR or equivalent law applies, transfers of personal data to third countries are made only on the basis of an adequacy decision or appropriate safeguards, including the European Commission's Standard Contractual Clauses (2021/914). A copy of the relevant safeguards is available on request. The Processor maintains a record of all transfers and the safeguards applicable to each.
Taking into account the state of the art, the cost of implementation, and the risk to data subjects, the Processor implements the following measures: (a) pseudonymization of personal data where feasible, (b) encryption of personal data in transit (TLS 1.2 or higher) and at rest (AES-256), (c) role-based access control with least-privilege principles and per-user credentials, (d) continuous logging and audit trails of access to data, (e) a formal access management process including revocation of access when staff depart, (f) secure development practices including code review and dependency vulnerability scanning, (g) regular testing of security measures, (h) business continuity and backup procedures with tested restoration, and (i) confidentiality obligations on all personnel, backed by internal security policies and training.
The Processor will make available to the Controller, upon request, information necessary to demonstrate compliance with this DPA, including audit reports of its infrastructure providers where contractually available, and will participate in audits or inspections conducted by the Controller or the Controller's auditor where such audits are required by applicable law. Audits that are unreasonably frequent, disruptive, or duplicative may be subject to a reasonable fee. On-site inspections will be coordinated in advance and limited to the facilities and records necessary to verify compliance.
Questions about this DPA or data protection matters should be addressed to our Data Protection Officer at dpo@khan-solutions.com or to administration@khan-solutions.com.