Armidus Data Processing Addendum

Effective date: July 22, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Armidus, Inc. ("Armidus") and the customer using the Armidus Service ("Customer"), including the Armidus Terms of Service, any applicable Order Form, and any other written agreement governing Customer's use of the Service, collectively the "Agreement."

This DPA automatically applies whenever and to the extent Armidus processes Customer Personal Data on behalf of Customer in providing the Service. It is incorporated into the Agreement by reference. No separate signature is required, and Customer's acceptance of the Agreement constitutes acceptance of this DPA.

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

If the parties require a separately signed version, they may sign a counterpart, Order Form, or negotiated data processing addendum that expressly incorporates, amends, or replaces this DPA. A negotiated amendment or replacement is effective only if it expressly identifies the affected provisions and is signed by authorized representatives of both parties.

1. Definitions

"Applicable Data Protection Law" means a law or regulation applicable to a party's processing of Customer Personal Data under the Agreement, including, as applicable, Singapore's Personal Data Protection Act 2012 and regulations, Australia's Privacy Act 1988 and Australian Privacy Principles, and U.S. state privacy laws such as the California Consumer Privacy Act as amended.

"Authorized Subprocessor" means a third party appointed by Armidus to process Customer Personal Data on behalf of Customer in providing the Service.

"Customer Personal Data" means personal information or personal data contained in Clinic Data that Armidus processes on Customer's behalf under the Agreement. It does not include information for which Armidus independently determines the purposes and means of processing, such as Armidus's own account, billing, security, and business-relationship information.

"Data Subject" means the identified or identifiable individual to whom Customer Personal Data relates, including an owner, Customer personnel member, or another person whose information appears in Clinic Data.

"Personal Data Breach" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Armidus. It does not include an unsuccessful attempt or event that does not compromise Customer Personal Data, such as a blocked probe or failed sign-in attempt.

"Restricted Transfer" means a transfer of Customer Personal Data that requires a recognized transfer mechanism or comparable-protection arrangement under Applicable Data Protection Law.

"process," "processor," "controller," "business," "service provider," and similar terms have the meanings given in Applicable Data Protection Law. If a law does not define a term, it will be interpreted consistently with the closest equivalent concept under that law.

2. Scope, roles, and compliance

2.1 Roles

For Customer Personal Data, Customer is a controller, business, or organization and Armidus is its processor, service provider, or data intermediary. If Customer processes personal data for another controller, Customer appoints Armidus as a subprocessor and represents that it has authority to do so.

The parties acknowledge that Armidus acts independently for limited processing described in the Privacy Policy, including administration of its customer relationship, billing and tax compliance, Service security, legal compliance, and establishment or defense of legal claims. This DPA does not convert that independent processing into processing on Customer's behalf.

2.2 Compliance

Each party will comply with Applicable Data Protection Law in performing its obligations under the Agreement and this DPA.

Customer is responsible for:

Armidus will process Customer Personal Data only as stated in this DPA and the Agreement, on Customer's documented instructions, or as required by law.

3. Customer instructions

3.1 Documented instructions

The Agreement, this DPA, Customer's use and configuration of the Service, and lawful instructions submitted through authorized support channels constitute Customer's documented instructions. Those instructions include processing Customer Personal Data to:

Customer will not instruct Armidus to process Customer Personal Data in violation of law. If Armidus reasonably believes an instruction violates Applicable Data Protection Law, it will notify Customer unless prohibited by law and may suspend the affected processing until the parties resolve the issue.

3.2 Required processing

If law requires Armidus to process Customer Personal Data beyond Customer's instructions, Armidus will notify Customer of the legal requirement before processing unless the law prohibits notice.

4. Processing details

The subject matter, duration, nature, purpose, Data Subjects, and categories of Customer Personal Data are described in Schedule 1.

Armidus will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as necessary for their role.

5. Security

5.1 Security program

Armidus will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and access. The current measures are described in Schedule 2.

Armidus may update those measures as technology and the Service evolve, provided that the updates do not materially decrease the overall protection of Customer Personal Data during a paid Subscription.

5.2 Customer responsibilities

Customer is responsible for using available security features appropriately, protecting credentials and devices, limiting user access, maintaining accurate Clinic roles, promptly removing users who no longer require access, and notifying Armidus of suspected unauthorized access.

No security measure eliminates all risk. The parties will cooperate in good faith to address security risks within their respective control.

6. Personal Data Breaches

6.1 Notice

Armidus will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data. Notice may be delivered to Customer's account administrator, designated security contact, or another operational contact provided by Customer.

To the extent known and legally permitted, the notice will describe:

Information may be provided in phases as the investigation develops. Armidus's notice is not an admission of fault or liability.

6.2 Response and cooperation

Armidus will take reasonable steps to contain, investigate, and remediate a Personal Data Breach within its control and will provide reasonable information needed for Customer to meet applicable notification obligations.

Customer is responsible for deciding whether to notify Data Subjects, regulators, Clinics, insurers, or others unless Applicable Data Protection Law places that obligation directly on Armidus. Armidus will not notify a Data Subject on Customer's behalf without Customer's instruction unless law requires it.

7. Data Subject requests

Taking into account the nature of processing, Armidus will provide reasonable assistance through available technical and organizational measures for Customer to respond to a verified request to access, correct, delete, restrict, object to, or obtain a copy of Customer Personal Data.

If Armidus receives a request concerning Customer Personal Data directly from a Data Subject, Armidus may direct the person to Customer and notify Customer. It will not independently fulfill the request unless Customer instructs it, the request concerns information for which Armidus acts independently, or law requires a response.

Customer must not give Armidus a copy of unnecessary identity documents through a general contact form. The parties will agree on a secure verification method where additional information is needed.

8. Assistance with compliance

Taking into account the nature of processing and information available to it, Armidus will provide reasonable assistance with Customer's obligations relating to processing security, breach assessment, data-protection impact assessments, and prior consultation with a regulator.

If Customer's request requires material custom work beyond standard Service functionality or ordinary compliance support, Armidus may charge reasonable fees disclosed in advance, except to the extent the work is required because of Armidus's breach of this DPA.

9. Subprocessors

9.1 General authorization

Customer gives Armidus general written authorization to appoint the Authorized Subprocessors listed at https://armidus.com/subprocessors and to replace or add Authorized Subprocessors subject to this Section.

Armidus will:

9.2 Changes and objections

Armidus will post changes to the Subprocessors and Service Providers page and provide at least 30 days' advance notice of a new Authorized Subprocessor that will materially process Customer Personal Data, where reasonably practicable. Customer may object during that period through the Privacy or Legal option at https://armidus.com/submit-request, stating reasonable, documented grounds related to protection of Customer Personal Data.

The parties will work in good faith to address a valid objection, which may include providing more information, using a commercially reasonable alternative, or allowing Customer to discontinue the affected feature. If no reasonable alternative is available, either party may terminate the affected portion of the Service. Any refund is governed by the Agreement and applies only where Armidus cannot continue the affected Service lawfully or in accordance with this DPA.

Customer may not object based solely on generalized preference, competitive considerations, or grounds unrelated to personal-data protection.

9.3 Provider classification

The public provider page may also identify vendors that are not Authorized Subprocessors, such as Stripe when it acts independently for payment processing or HubSpot and Microsoft 365 when they process Armidus's own prospect and business-communication information. Listing those vendors for transparency does not make all of their processing subject to this DPA.

10. Regional processing and Restricted Transfers

10.1 Regional Service environments

Where Armidus offers a country-specific production environment, core regional application records are hosted in the region stated in the Service documentation or Order Form. For the Singapore Service, the application, database, and secrets are hosted in a dedicated Google Cloud project configured for Singapore.

Regional hosting does not apply to every category of processing. For the Singapore Service, supported Vertex AI processing of Clinic Data is configured through a Singapore regional endpoint. Providers for authentication, transactional email, support, and related functions may process limited Customer Personal Data outside the country environment as stated on the Subprocessors and Service Providers page. Google Cloud service metadata that is outside a data-location commitment may be processed as described in Google's applicable terms.

10.2 Transfer protection

Armidus will not make a Restricted Transfer unless it uses a mechanism or contractual arrangement recognized by Applicable Data Protection Law. For Singapore personal data transferred outside Singapore, Armidus will take steps designed to ensure that the recipient is bound to provide a standard of protection comparable to that required by the Personal Data Protection Act 2012.

For Australian personal information, if applicable, Armidus will provide reasonable information to support Customer's assessment under Australian Privacy Principle 8 and will impose appropriate contractual protection on its processors.

If the European Economic Area, United Kingdom, Switzerland, or another jurisdiction requiring standard contractual clauses later becomes applicable, the parties will execute or incorporate the then-current legally required transfer terms before the Restricted Transfer. This DPA does not itself attach European standard contractual clauses.

11. Return and deletion

During the Subscription, Customer may use available Service functionality to retrieve Customer Personal Data. For 30 days after termination or expiration, Customer may request a reasonable export as described in the Agreement.

After that period, Armidus will delete or de-identify Customer Personal Data from active systems in accordance with Customer's instructions, the Agreement, and Armidus's documented retention process, unless law requires or permits continued retention. Armidus may also retain information reasonably necessary to establish or defend legal claims.

Customer Personal Data may remain temporarily in protected backups until the backups expire through their ordinary lifecycle. While retained, backup data remains protected and is not restored except for disaster recovery, security, or legal necessity.

If law prevents deletion, Armidus will isolate the retained information from further processing except for the required purpose and will delete it when the retention obligation ends.

12. Information and audits

12.1 Compliance information

Armidus will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, privilege, and third-party restrictions. This may include current security documentation, architecture descriptions, subprocessor information, and independent reports when available.

Armidus is not currently ISO/IEC 27001 certified and has not completed a SOC 2 examination. A roadmap statement is not a certification or audit report.

12.2 Customer audits

If the information made available under Section 12.1 is not reasonably sufficient, Customer may request an audit no more than once in a 12-month period, except after a Personal Data Breach affecting Customer Personal Data or where a regulator requires a further audit.

The audit must:

Customer bears its audit costs and Armidus's reasonable costs for material custom assistance, unless the audit identifies a material breach of this DPA by Armidus. The parties may agree that a remote review, questionnaire, or independent report satisfies the request.

13. Government and third-party requests

If Armidus receives a legally binding demand for Customer Personal Data, it will, where lawful:

Armidus may disclose information without advance notice where prohibited by law or where an emergency involving serious risk requires immediate action. It will seek permission to notify Customer when a legal restriction expires where appropriate.

14. U.S. service-provider terms

To the extent a U.S. state privacy law applies and Armidus processes Customer Personal Data as Customer's processor, contractor, or service provider, Armidus will:

Customer may monitor compliance through the information and audit mechanisms in Section 12. The parties agree that Customer Personal Data is disclosed for the business purposes in Schedule 1 and not as consideration for money or another commercial benefit.

15. Singapore data-intermediary terms

To the extent Armidus acts as a data intermediary for Customer under Singapore's Personal Data Protection Act 2012, Armidus will comply with the obligations applicable to it in that role, including applicable protection, retention-limitation, and data-breach notification obligations. Armidus will assist Customer with information reasonably required for Customer's own obligations under the Act.

Customer remains responsible for obligations that apply to the organization that determines the purposes and means of collection, use, or disclosure, including notice, consent or another legal authority, purpose limitation, accuracy, access and correction, and accountability, except to the extent the Act places an obligation directly on Armidus.

16. Liability and order of precedence

Each party's liability arising from this DPA is subject to the exclusions and limitations of liability in the Agreement, to the maximum extent permitted by law. Nothing in this DPA limits a liability that cannot lawfully be limited.

If documents conflict regarding the processing of Customer Personal Data, the following order controls:

  1. any mandatory data-transfer terms required by applicable law;
  2. a written amendment to this DPA that expressly identifies the provisions being amended and is signed by authorized representatives of both parties;
  3. this DPA; and
  4. the remainder of the Agreement.

An Order Form or other agreement does not amend this DPA merely because it contains different or additional terms. The Privacy Policy does not reduce Armidus's contractual obligations under this DPA.

17. Duration and termination

This DPA becomes binding when Customer accepts or enters into the Agreement and applies from the time Armidus first processes Customer Personal Data on behalf of Customer. It continues until Armidus no longer processes Customer Personal Data, subject to legally permitted retention. Provisions that must remain effective to protect retained Customer Personal Data survive termination of the Agreement.

18. Changes

Armidus may update this DPA prospectively to reflect changes in law or the Service. An update will not materially reduce protection of Customer Personal Data during a current paid Subscription. If an update materially affects Customer's rights, Armidus will provide advance notice and any objection or termination right required by law or the Agreement.

19. Contact

Use the Privacy or Legal option at https://armidus.com/submit-request for DPA requests, subprocessor objections, or data-protection questions. Do not include patient records, passwords, payment-card information, or claim links in the general form. Armidus will provide a secure channel if supporting data is needed.

Privacy and data-protection requests may also be sent to Armidus's Data Protection Officer at privacy@armidus.com.

Legal notices may also be sent by tracked post to:

Armidus, Inc. 1111B South Governors Avenue #49736 Dover, DE 19904 United States

Schedule 1: Details of processing

A. Subject matter

Provision, security, maintenance, and support of Armidus's veterinary post-visit care and operations platform for Customer.

B. Duration

The Subscription term plus the return, deletion, backup, legal-hold, and other limited retention periods described in the Agreement and this DPA.

C. Nature and purposes

D. Data Subjects

Animal patients are not Data Subjects, but their records can contain personal data relating to owners and Clinic personnel.

E. Categories of Customer Personal Data

F. Sensitive or special-category data

The Service is designed for animal care and does not require human medical records, government identifiers, biometric data, payment-card numbers, or precise financial-account credentials. Customer must not submit those data types unless Armidus has expressly documented support and the parties have agreed on appropriate safeguards.

Owner text, photos, or other free-form material may incidentally contain sensitive information. Customer is responsible for data minimization and for instructing its users not to submit unnecessary human-sensitive information.

G. Frequency

Continuous and event-driven during the Subscription, based on Customer and Authorized User activity, scheduled tasks, notifications, and Service operations.

Schedule 2: Technical and organizational measures

Armidus currently maintains the following measures for the production Service.

1. Regional and tenant separation

2. Identity and access management

3. Application and API protection

4. Encryption and secrets

5. Data and token protection

6. Logging and monitoring

7. Availability and recovery

8. Organizational safeguards

Schedule 3: Authorized Subprocessors

The current Authorized Subprocessors and processing details are maintained at:

https://armidus.com/subprocessors

That page distinguishes Authorized Subprocessors that process Customer Personal Data under this DPA from payment providers and Armidus business-system providers used for Armidus's independent processing.