DATA PROCESSING AGREEMENT
This Data Processing Agreement with its Schedules (“DPA”) forms part of the agreement between FydoDx and the Customer for the use by the Customer of FydoDx products and services. FydoDx provides quality of care and data analytics, clinical workflow automation solutions and clinical decision support tools (together, the “Services”).
Where there is any conflict between the terms of this DPA and any other part of the Terms of Service (the “Agreement”), the DPA prevails for the protection of Personal Information.
1. DEFINITIONS AND INTERPRETATION
1.1 The following words and phrases used in this DPA and the appendices shall have the following meanings, except where the context otherwise requires:
“Applicable Privacy Laws” means, all applicable legislation and regulations governing the collection, use and disclosure of Personal Information in the jurisdictions where Customer has subscribed to use the Services, in particular where applicable, the Act Respecting the protection of personal information in the private sector - the “Québec Act”; the Personal Information Protection and Electronic Documents Act – “PIPEDA”; the Personal Information Protection Act of British Columbia – PIPA BC; the Personal Information Protection Act of Alberta – PIPA AB; the EU General Data Protection Regulation - the “GDPR”, the UK General Data Protection Regulation – the UK-GDPR as well as any other applicable legislation, regulation, recommendation or opinion replacing, adding to or amending, extending, reconstituting or consolidating the Applicable Privacy Laws.
“Data Controller” refers to the party who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any Personal Information are or are to be processed, i.e. the Customer.
“Data Processor” means a person or entity who processes Personal Information on behalf of the Customer on the basis of a formal written contract, but who is not an employee of the Customer, i.e. the Service Provider, FydoDx.
“Personal Information” or “Personal Data” means information which relates to a living individual who can be identified either directly from that data, or indirectly in conjunction with other data which is likely to come into the legitimate possession of the Customer or Service Provider.
“Confidentiality Incident” means any (i) access; (ii) use; (iii) communication not authorized by law of Personal Information; or (iv) loss of Personal Information or any other breach of the protection of such information or any other breach of Personal Information as defined under Applicable Privacy Laws.
“Services” has the meaning defined in the recitals
2. CAPACITY OF THE PARTIES
2.1 FydoDx processes Personal Information in its capacity as a Data Processor, acting under the documented instructions and on behalf of the Customer, acting as the Data Controller under the GDPR and the UK GDPR. The DPA and its appendices form the Customer’s instructions to FydoDx.
3. SCOPE OF THE DATA PROCESSING AGREEMENT
3.1 The purpose of these clauses is to define the conditions under which FydoDx undertakes to carry out the Personal Information processing operations defined below on behalf of the Customer. In the context of their contractual relations, the Parties undertake to comply with Applicable Privacy Laws.
3.2 Unless otherwise agreed upon in writing by the Parties, the provisions of this Data Processing Agreement are applicable on each processing operation of FydoDx based on the Agreement.
3.3 In the event of any inconsistency between this DPA and the Agreement, this DPA shall prevail.
3.4 This DPA may be modified only in writing and must be signed by the Parties.
4. OBLIGATIONS OF THE CUSTOMER
4.1 The Customer represents and warrants that all Personal Information has been, and will continue to be, collected, used, disclosed and more generally processed in compliance with Applicable Privacy Laws, and, where required, that all necessary and valid consents or authorizations have been obtained. The Customer shall provide the Personal Information to FydoDx together with such other information as FydoDx may reasonably require in order for FydoDx to provide the Services.
4.2 The instructions given by the Customer to FydoDx in respect of the Personal Information shall at all times be in accordance with Applicable Privacy Laws and shall be in a written and duly documented form.
4.3 The Customer shall determine the retention period of Personal Information in relation to the purposes for which they were collected and in accordance with the Applicable Privacy Laws.
4.4 The Customer will retain control and responsibility for all Personal Information and will have immediate access to it at all times.
5. OBLIGATIONS OF FYDODX
5.1 FydoDx undertakes to process the Personal Information only in accordance with this agreement or the Customer’s documented instructions for the processing of that Personal Information.
5.2 If FydoDx considers that an instruction from the Customer constitutes a violation of the Applicable Privacy Laws, it shall inform the Customer as soon as possible.
5.3 FydoDx will process the Personal Information only for the purposes of the performance of the Services, i.e. only for the purpose of providing the FydoDx software, analytics, reporting, and related services. For the sake of clarity, the Parties expressly agree that FydoDx is authorized to generate and use aggregated, statistical, and anonymized information derived from client data for purposes including: product improvement; benchmarking; quality analysis; clinical trend identification; model evaluation; operational insights; development of industry-level analytics; and improvement of FydoDx software, reporting, and analytics services. For greater certainty, such information will be processed and maintained in a manner that does not permit the identification or re-identification of any individual, clinic or group.
5.4 FydoDx will not store Personal Information beyond the retention period fixed by the Customer in relation to the purposes for which they were collected and, in any event, will not store them after the expiration of the DPA, except in the event of any legislative or regulatory provision or any administrative or judicial decision stating the contrary.
6. COOPERATION AND ASSISTANCE
6.1 FydoDx endeavours to collaborate with the Customer, in particular by providing it with the necessary documentation to demonstrate compliance with all of its obligations, in particular the protection impact assessment and the performance of audits, including inspections, subject to at least one month’s written notice prior to the date of the audit and within normal business hours, by the Customer or another auditor (that is independent and not a competitor of FydoDx) that the Customer has mandated and contribute to such audits.
6.2 Unless an audit, inspection, or review is required by applicable law or requested by a competent supervisory authority, the Customer shall be responsible for its own costs and expenses in connection with any audit, inspection, or review of the Processor’s compliance with this Agreement. The Processor shall provide reasonable cooperation in connection with such audit at its own internal cost. However, the Customer shall reimburse the Processor for any reasonable, documented out-of-pocket costs and for any audit support that requires material time, resources, or third-party assistance, provided that the Processor notifies the Customer of such anticipated costs in advance where practicable. If such audit identifies a material breach of this Agreement by the Processor, the Processor shall promptly remediate the breach at its own cost.
6.3 If an audit, inspection, or review identifies that the Processor is in material breach of this Agreement or applicable Data Protection Laws, the Processor shall promptly remediate such breach at its own cost and shall reimburse the Customer for its reasonable, documented audit costs directly related to confirming such breach, subject to any liability limitations set out in the Agreement.
6.4 FydoDx will inform, without undue delay, the Customer in case of a request from an administrative or judiciary authority received by FydoDx related to the Processing of Personal Information made in respect of Services.
7. SUB-PROCESSORS
7.1 FydoDx will not disclose the Personal Information to a third party in any circumstances other than at the specific written request of the Customer, unless the disclosure is required by law.
7.2 The Customer agrees that FydoDx may engage sub-processors to process Personal Information. The sub-processors currently engaged by FydoDx and authorized by the Customer are listed in Appendix 3 “List of Sub-Processors”.
7.3 FydoDx will notify in writing the Customer of any changes to the list of Sub-Processors authorized to process Personal Information (“List of Sub-Processors”), provide the Customer with such information regarding the sub-processor as the Customer may reasonably require, and provide the Customer with a mechanism to obtain notice of any updates to the List of Sub-Processors. Notification of a new sub-processor shall be issued ten (10) days prior to such new sub-processor being authorised to process Personal Information in connection with the Agreement.
7.4 The Customer may object to the Service Provider’s use of a new sub-processor where there are reasonable grounds to believe that the new sub-processor will be unable to comply with the terms of this Data Processing Agreement or the Agreement. If the Customer objects to the Service Provider’s use of a new sub-processor, the Customer shall notify FydoDx promptly in writing within ten (10) working days after notification regarding such sub-processor. Customer’s failure to object in writing within such time period shall constitute approval to use the new sub-processor. If the Customer objects to the use of a third party or refuses to grant permission for the use of a third party by the Service Provider, FydoDx shall suggest another third party. If it is not possible, and insofar as the refusal reasonably justifies this, both Parties have the right to terminate the Data Processing Agreement without being liable to pay any damages to the other Party, with a notice period of one (1) month.
7.5 FydoDx shall ensure that all of its obligations under the DPA and its appendices are respected by any sub-contractors replacing FydoDx, regardless of its rank or method of intervention, by expressly providing for these same obligations in the contract binding FydoDx to the said sub-contractor and to any subsequent sub-contractor, so that they undertake to respect the DPA. FydoDx shall be liable for the acts and omissions of any sub-contractor to the same extent as if the acts or omissions were performed by the Service Provider.
8. INTERNATIONAL TRANSFERS OF PERSONAL INFORMATION
8.1 For European clients, FydoDx hosts and processes Personal Information within the European Union using Google Cloud Platform EU regions. Where EU data residency is required, FydoDx is designed so that client Personal Information, report data, authentication data, encryption keys, backups, and audit logs remain within the EU. FydoDx does not transfer Personal Information outside the EEA to deliver the service; each region is isolated, with no cross-border replication of Personal Information.
8.2 FydoDx may also process Personal Information in Canada and the country where the Customer is operating. FydoDx may also transfer Personal Information to a third country, where it has service providers or where it operates, recognized by an adequacy decision of the European Commission as providing an adequate level of protection for Personal Information or by using adequate safeguards as required under Applicable Privacy Laws governing cross-border data transfers, such as conducting a privacy impact assessment and, where required under Applicable Privacy Laws, entering Standard Contractual Clauses attached in Appendix 4.
8.3 Where FydoDx appoints an affiliate or a third party Sub-Contractor to process Personal Information in a third country, FydoDx must ensure that such processing takes place in accordance with the requirements of Applicable Privacy Laws.
8.4 If a governmental authority in the recipient country sends the Service Provider a request to access Personal Information relating to the Customer, the Service Provider will inform the Customer as soon as possible. The Service Provider will redirect the governmental authority to request Personal Information directly from the Customer, in which case the Service Provider can provide the governmental authority with its basic contact details.
8.5 If compelled to disclose the Customer’s Personal Information to a governmental authority, the Service Provider will give the governmental authority reasonable notice to enable Customer to seek a protective order or other appropriate remedy, unless prohibited from doing so by law.
9. CONFIDENTIALITY
9.1 FydoDx endeavours to ensure that only such of its employees who need to have access to enable FydoDx to meet its obligations under the DPA shall have access to the Personal Information.
9.2 FydoDx endeavours that all such employees have undergone training in the law of data protection and are bound by a duty of confidentiality under the Agreement.
10. INDIVIDUALS’ RIGHTS
10.1 The Customer will inform and assist individuals when they have requests, questions, complaints or any other form of announcement. If the individual contacts FydoDx, FydoDx shall refer the Data Subject to the Customer, unless otherwise provided for in this Data Processing Agreement.
10.2 FydoDx assists the Customer with all individuals’ requests which may be received from individuals to whom the Personal Information refers.
11. SECURITY MEASURES
11.1 FydoDx uses appropriate organizational and technological processes and procedures to guarantee the security of its premises and to keep the Personal Information safe from unauthorized use, disclosure or access, loss, accidental or unlawful destruction, theft, alteration, distortion or any other modification, such as the de-identification and encryption of Personal Information; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; the ability to restore the availability and access to Personal Information in a timely manner in the event of an incident and a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
11.2 The technical and organizational security measures, which FydoDx shall have in place, are set out at Appendix 2 to this DPA. In case of modification of the implemented technical and organizational security measures related to the Personal Information subject to this DPA, FydoDx shall notify the Customer. If the Customer objects to the Service Provider’s use of a new technical and organizational security measure, the Customer shall notify FydoDx promptly in writing within thirty (30) days of notification regarding such security measures.
12. CONFIDENTIALITY INCIDENT
12.1 FydoDx will notify the Customer of any Confidentiality Incident, or attempted Confidentiality Incident, which may impact the processing of the Personal Information covered by this DPA without undue delay after becoming aware of any such incident.
12.2 This notification will be accompanied by all relevant documentation to enable the Customer, if necessary, to notify the Confidentiality Incident to the competent supervisory authority.
12.3 Where, and insofar as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
12.4 Only upon the Customer’s prior approval, FydoDx will, in the name and on behalf of the Customer, communicate the Confidentiality Incident to the Individuals without undue delay, when the Personal Information Incident is likely to result in a serious injury.
12.5 FydoDx endeavours to co-operate with the Customer in implementing any required corrective action agreed between the Parties.
12.6 The Parties acknowledge and agree that this Section 12.6 constitutes notice by FydoDx to the Customer of the ongoing existence and occurrence or attempts of unsuccessful security incidents for which no additional notice to the Customer shall be required. "Unsuccessful security incidents" means, without limitation, pings and other broadcast attacks on Service Provider's firewall, port scans, unsuccessful log-on attempts, denial of service attacks, and any combination of the above, so long as no such incident results in unauthorized access, use or disclosure of Personal Information.
13. NULLITY
13.1 If any provision of this Data Processing Agreement is null and void or otherwise unenforceable, the remaining provisions will remain in full force.
14. DURATION AND TERMINATION
14.1 At the termination of the DPA, FydoDx will retained Personal Information for a maximum of 30 days for billing and operational purposes. After such period, FydoDx will delete or return all the Personal Information to the Customer at the Customer’s choice and delete existing copies unless the law requires storage of the Personal Information.
14.2 The provisions in this DPA shall remain in effect as long as FydoDx has the instruction of the Customer to process Personal Information on the basis of the Agreement between the Customer and FydoDx.
14.3 The provisions in this DPA relating to the protection of Personal Information shall survive the termination of the Agreement.
15. APPLICABLE LAWS.
15.1 This DPA shall be governed by and construed in accordance with the applicable laws of British-Columbia (Canada) and each Party hereby submits to the non-exclusive jurisdiction of the appropriate courts.
APPENDIX 1
PROCESSING OF PERSONAL INFORMATION
PERSONAL INFORMATION AND PURPOSES
The Customer tasks FydoDx with the processing of the following Personal Information:
• DxCore App and Spotlight Analytics:
Patient ID
Name
Breed
Sex
Age
Current medications
Current Vaccinations
Current and Past Conditions
Medical Record Notes
Surgical Notes
Callback notes
Dental Records
Wellness plan enrollment and compliance
Laboratory Reports
Imaging results
Dispensed prescriptions
Vitals
Invoice code and price per item
Estimates
De-identified analytics (to identify trends that can be shared with customers, by region, without being possible to be identified back to the client/practitioner/ clinic or group) for FydoDx’s own processing
• Dx Core App only:
Client ID
Client Name
Client Email
Client Telephone
ACCESS
FydoDx will store and process all Personal Information strictly separate from Personal Information that it processes on its own behalf or on behalf of third parties. In addition, and for greater certainty, each customer’s data is segregated and maintained separately from the data of other clients.
Only the following group of people within FydoDx will have access to the Personal Information:
Consulting DVMs, system developers, account managers, support service engineers, administrators, IT experts of the Sub-Processor engaged by FydoDx, exclusively on a ‘need-to-know’ basis to support the technical operation, hosting and, if necessary, development of the application;
Access to reports and client data is logged and auditable.
DURATION
The Personal Information processed by FydoDx will be retained for the duration of the contractual arrangement and for a period of 30 days thereafter, unless applicable legal requirements mandate a longer retention period.
INDIVIDUALS
The Personal Information processed by FydoDx concerns the following categories of Individuals:
Customer’s end Users such as employees and clinicians
APPENDIX 2
SECURITY MEASURES
Processor maintains governance practices designed to support compliance with EU and UK data, including:
• records of processing activities;
• data minimization controls;
• retention and deletion procedures;
• access management reviews;
• vendor and sub-processor oversight;
• security monitoring;
• audit logging;
• encryption controls to protect client data both in transit and at rest. Data is encrypted in transit using modern transport security protocols, including TLS 1.2 or higher. Data at rest is encrypted using enterprise-grade encryption controls. Where applicable, FydoDx supports customer-managed encryption keys held in EU-based key management services. This allows for enhanced client control over key access, key rotation, and, where required, cryptographic revocation of access
• internal confidentiality obligations;
• anonymization and aggregation controls; and
• documented technical and organizational security measures.
FydoDx aligns its security practices with recognized industry standards and continuously reviews its controls as the product, regulatory environment, and client requirements evolve.
APPENDIX 3
SUB-PROCESSORS
The following Sub-processors have already been engaged by FydoDx at the time of the conclusion of the Data Processing Agreement.
By signing this Data Processing Agreement, the Customer has given permission for the engagement of these Sub-processors.
Name of the Sub-processors Activity of the Sub-processor Location of the Sub-processor
Google Cloud Platform Canada, US, EU depending on relevant client location(s)
OpenAi Limited de-identified LLM Calls for data processing. 30 data retention policy, data training not allowed. California
HuggingFace Limited de-identified LLM Calls for data processing. Zero data retention policy. Data training not allowed . New York
APPENDIX 4
STANDARD CONTRACTUAL CLAUSES
TRANSFERS FROM DATA CONTROLLER TO DATA PROCESSOR
The Parties agree Module 2 of the EU Standard Contractual Clauses applies, as well as the UK Addendum the EU Standard Contractual Clauses in particular the following terms and conditions apply to Module:
EU SCCs
Module 2 – Transfers from a Data Controller to a Data Processor Selected option / Applicable conditions
Clause 7
Docking clause The docking clause is not applicable to the EU SCCs.
Clause 9
Use of Sub-Processor Option 2 (general written authorization) is applicable.
Clause 11
Redress The Independent Dispute Resolution Body option is not applicable.
Clause 13
Supervision The competent supervisory authority shall be the supervisory authority of: (a) the EU member state in which the data exporter is established; (b) if the data exporter does not have an EU establishment, the EU member state in which the data exporter’s representative is established; or (c) if the data exporter does not have an EU establishment and is not required to appoint a representative, one of the member states in which the relevant individuals are located
Clause 17
Governing law British Columbia, Canada
Clause 18
Choice of forum and jurisdiction British Columbia, Canada