Armidus Data Processing Addendum
Effective date: July 22, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Armidus, Inc. ("Armidus") and the customer using the Armidus Service ("Customer"), including the Armidus Terms of Service, any applicable Order Form, and any other written agreement governing Customer's use of the Service, collectively the "Agreement."
This DPA automatically applies whenever and to the extent Armidus processes Customer Personal Data on behalf of Customer in providing the Service. It is incorporated into the Agreement by reference. No separate signature is required, and Customer's acceptance of the Agreement constitutes acceptance of this DPA.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
If the parties require a separately signed version, they may sign a counterpart, Order Form, or negotiated data processing addendum that expressly incorporates, amends, or replaces this DPA. A negotiated amendment or replacement is effective only if it expressly identifies the affected provisions and is signed by authorized representatives of both parties.
1. Definitions
"Applicable Data Protection Law" means a law or regulation applicable to a party's processing of Customer Personal Data under the Agreement, including, as applicable, Singapore's Personal Data Protection Act 2012 and regulations, Australia's Privacy Act 1988 and Australian Privacy Principles, and U.S. state privacy laws such as the California Consumer Privacy Act as amended.
"Authorized Subprocessor" means a third party appointed by Armidus to process Customer Personal Data on behalf of Customer in providing the Service.
"Customer Personal Data" means personal information or personal data contained in Clinic Data that Armidus processes on Customer's behalf under the Agreement. It does not include information for which Armidus independently determines the purposes and means of processing, such as Armidus's own account, billing, security, and business-relationship information.
"Data Subject" means the identified or identifiable individual to whom Customer Personal Data relates, including an owner, Customer personnel member, or another person whose information appears in Clinic Data.
"Personal Data Breach" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Armidus. It does not include an unsuccessful attempt or event that does not compromise Customer Personal Data, such as a blocked probe or failed sign-in attempt.
"Restricted Transfer" means a transfer of Customer Personal Data that requires a recognized transfer mechanism or comparable-protection arrangement under Applicable Data Protection Law.
"process," "processor," "controller," "business," "service provider," and similar terms have the meanings given in Applicable Data Protection Law. If a law does not define a term, it will be interpreted consistently with the closest equivalent concept under that law.
2. Scope, roles, and compliance
2.1 Roles
For Customer Personal Data, Customer is a controller, business, or organization and Armidus is its processor, service provider, or data intermediary. If Customer processes personal data for another controller, Customer appoints Armidus as a subprocessor and represents that it has authority to do so.
The parties acknowledge that Armidus acts independently for limited processing described in the Privacy Policy, including administration of its customer relationship, billing and tax compliance, Service security, legal compliance, and establishment or defense of legal claims. This DPA does not convert that independent processing into processing on Customer's behalf.
2.2 Compliance
Each party will comply with Applicable Data Protection Law in performing its obligations under the Agreement and this DPA.
Customer is responsible for:
- determining that its instructions and use of the Service are lawful;
- providing required notices and obtaining required consents, permissions, or other lawful authority;
- the accuracy, quality, and legality of Customer Personal Data;
- deciding which Authorized Users receive access and assigning accurate roles;
- responding to Data Subjects except to the extent Armidus must assist under this DPA; and
- complying with veterinary, professional, medical-record, communications, and record-retention obligations applicable to Customer.
Armidus will process Customer Personal Data only as stated in this DPA and the Agreement, on Customer's documented instructions, or as required by law.
3. Customer instructions
3.1 Documented instructions
The Agreement, this DPA, Customer's use and configuration of the Service, and lawful instructions submitted through authorized support channels constitute Customer's documented instructions. Those instructions include processing Customer Personal Data to:
- host and maintain Clinic, owner, animal patient, care-plan, task, interaction, and audit records;
- authenticate users and enforce Clinic, owner, and role-based access;
- enable Customer-authorized communication and record sharing with owners;
- structure Clinic-authored content through AI-assisted features when invoked;
- send transactional notifications;
- monitor, secure, troubleshoot, support, and improve the operation of the Service for Customer; and
- delete, return, or de-identify data as required by the Agreement and this DPA.
Customer will not instruct Armidus to process Customer Personal Data in violation of law. If Armidus reasonably believes an instruction violates Applicable Data Protection Law, it will notify Customer unless prohibited by law and may suspend the affected processing until the parties resolve the issue.
3.2 Required processing
If law requires Armidus to process Customer Personal Data beyond Customer's instructions, Armidus will notify Customer of the legal requirement before processing unless the law prohibits notice.
4. Processing details
The subject matter, duration, nature, purpose, Data Subjects, and categories of Customer Personal Data are described in Schedule 1.
Armidus will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as necessary for their role.
5. Security
5.1 Security program
Armidus will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and access. The current measures are described in Schedule 2.
Armidus may update those measures as technology and the Service evolve, provided that the updates do not materially decrease the overall protection of Customer Personal Data during a paid Subscription.
5.2 Customer responsibilities
Customer is responsible for using available security features appropriately, protecting credentials and devices, limiting user access, maintaining accurate Clinic roles, promptly removing users who no longer require access, and notifying Armidus of suspected unauthorized access.
No security measure eliminates all risk. The parties will cooperate in good faith to address security risks within their respective control.
6. Personal Data Breaches
6.1 Notice
Armidus will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data. Notice may be delivered to Customer's account administrator, designated security contact, or another operational contact provided by Customer.
To the extent known and legally permitted, the notice will describe:
- the nature of the Personal Data Breach;
- the categories of affected Customer Personal Data and Data Subjects;
- the likely consequences;
- measures taken or proposed to contain, investigate, and remediate it; and
- a contact point for follow-up.
Information may be provided in phases as the investigation develops. Armidus's notice is not an admission of fault or liability.
6.2 Response and cooperation
Armidus will take reasonable steps to contain, investigate, and remediate a Personal Data Breach within its control and will provide reasonable information needed for Customer to meet applicable notification obligations.
Customer is responsible for deciding whether to notify Data Subjects, regulators, Clinics, insurers, or others unless Applicable Data Protection Law places that obligation directly on Armidus. Armidus will not notify a Data Subject on Customer's behalf without Customer's instruction unless law requires it.
7. Data Subject requests
Taking into account the nature of processing, Armidus will provide reasonable assistance through available technical and organizational measures for Customer to respond to a verified request to access, correct, delete, restrict, object to, or obtain a copy of Customer Personal Data.
If Armidus receives a request concerning Customer Personal Data directly from a Data Subject, Armidus may direct the person to Customer and notify Customer. It will not independently fulfill the request unless Customer instructs it, the request concerns information for which Armidus acts independently, or law requires a response.
Customer must not give Armidus a copy of unnecessary identity documents through a general contact form. The parties will agree on a secure verification method where additional information is needed.
8. Assistance with compliance
Taking into account the nature of processing and information available to it, Armidus will provide reasonable assistance with Customer's obligations relating to processing security, breach assessment, data-protection impact assessments, and prior consultation with a regulator.
If Customer's request requires material custom work beyond standard Service functionality or ordinary compliance support, Armidus may charge reasonable fees disclosed in advance, except to the extent the work is required because of Armidus's breach of this DPA.
9. Subprocessors
9.1 General authorization
Customer gives Armidus general written authorization to appoint the Authorized Subprocessors listed at https://armidus.com/subprocessors and to replace or add Authorized Subprocessors subject to this Section.
Armidus will:
- conduct reasonable privacy and security diligence appropriate to the processing;
- enter into a written agreement requiring the Authorized Subprocessor to protect Customer Personal Data to the extent applicable to its services;
- limit access to what is reasonably necessary for the subprocessor's role; and
- remain responsible for the Authorized Subprocessor's performance of its data-protection obligations to the extent required by Applicable Data Protection Law.
9.2 Changes and objections
Armidus will post changes to the Subprocessors and Service Providers page and provide at least 30 days' advance notice of a new Authorized Subprocessor that will materially process Customer Personal Data, where reasonably practicable. Customer may object during that period through the Privacy or Legal option at https://armidus.com/submit-request, stating reasonable, documented grounds related to protection of Customer Personal Data.
The parties will work in good faith to address a valid objection, which may include providing more information, using a commercially reasonable alternative, or allowing Customer to discontinue the affected feature. If no reasonable alternative is available, either party may terminate the affected portion of the Service. Any refund is governed by the Agreement and applies only where Armidus cannot continue the affected Service lawfully or in accordance with this DPA.
Customer may not object based solely on generalized preference, competitive considerations, or grounds unrelated to personal-data protection.
9.3 Provider classification
The public provider page may also identify vendors that are not Authorized Subprocessors, such as Stripe when it acts independently for payment processing or HubSpot and Microsoft 365 when they process Armidus's own prospect and business-communication information. Listing those vendors for transparency does not make all of their processing subject to this DPA.
10. Regional processing and Restricted Transfers
10.1 Regional Service environments
Where Armidus offers a country-specific production environment, core regional application records are hosted in the region stated in the Service documentation or Order Form. For the Singapore Service, the application, database, and secrets are hosted in a dedicated Google Cloud project configured for Singapore.
Regional hosting does not apply to every category of processing. For the Singapore Service, supported Vertex AI processing of Clinic Data is configured through a Singapore regional endpoint. Providers for authentication, transactional email, support, and related functions may process limited Customer Personal Data outside the country environment as stated on the Subprocessors and Service Providers page. Google Cloud service metadata that is outside a data-location commitment may be processed as described in Google's applicable terms.
10.2 Transfer protection
Armidus will not make a Restricted Transfer unless it uses a mechanism or contractual arrangement recognized by Applicable Data Protection Law. For Singapore personal data transferred outside Singapore, Armidus will take steps designed to ensure that the recipient is bound to provide a standard of protection comparable to that required by the Personal Data Protection Act 2012.
For Australian personal information, if applicable, Armidus will provide reasonable information to support Customer's assessment under Australian Privacy Principle 8 and will impose appropriate contractual protection on its processors.
If the European Economic Area, United Kingdom, Switzerland, or another jurisdiction requiring standard contractual clauses later becomes applicable, the parties will execute or incorporate the then-current legally required transfer terms before the Restricted Transfer. This DPA does not itself attach European standard contractual clauses.
11. Return and deletion
During the Subscription, Customer may use available Service functionality to retrieve Customer Personal Data. For 30 days after termination or expiration, Customer may request a reasonable export as described in the Agreement.
After that period, Armidus will delete or de-identify Customer Personal Data from active systems in accordance with Customer's instructions, the Agreement, and Armidus's documented retention process, unless law requires or permits continued retention. Armidus may also retain information reasonably necessary to establish or defend legal claims.
Customer Personal Data may remain temporarily in protected backups until the backups expire through their ordinary lifecycle. While retained, backup data remains protected and is not restored except for disaster recovery, security, or legal necessity.
If law prevents deletion, Armidus will isolate the retained information from further processing except for the required purpose and will delete it when the retention obligation ends.
12. Information and audits
12.1 Compliance information
Armidus will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, privilege, and third-party restrictions. This may include current security documentation, architecture descriptions, subprocessor information, and independent reports when available.
Armidus is not currently ISO/IEC 27001 certified and has not completed a SOC 2 examination. A roadmap statement is not a certification or audit report.
12.2 Customer audits
If the information made available under Section 12.1 is not reasonably sufficient, Customer may request an audit no more than once in a 12-month period, except after a Personal Data Breach affecting Customer Personal Data or where a regulator requires a further audit.
The audit must:
- be limited to processing relevant to Customer;
- occur during normal business hours on reasonable advance notice;
- avoid access to another customer's data, source code, vulnerability details, or information that would create a security risk;
- be performed by Customer or an independent auditor that is not Armidus's competitor and is bound by confidentiality; and
- minimize disruption to Armidus and its providers.
Customer bears its audit costs and Armidus's reasonable costs for material custom assistance, unless the audit identifies a material breach of this DPA by Armidus. The parties may agree that a remote review, questionnaire, or independent report satisfies the request.
13. Government and third-party requests
If Armidus receives a legally binding demand for Customer Personal Data, it will, where lawful:
- review the demand for facial validity;
- direct the requester to Customer where appropriate;
- notify Customer before disclosure;
- challenge or narrow an overbroad demand where reasonably appropriate; and
- disclose only the information legally required.
Armidus may disclose information without advance notice where prohibited by law or where an emergency involving serious risk requires immediate action. It will seek permission to notify Customer when a legal restriction expires where appropriate.
14. U.S. service-provider terms
To the extent a U.S. state privacy law applies and Armidus processes Customer Personal Data as Customer's processor, contractor, or service provider, Armidus will:
- process the information only for the limited and specified purposes stated in the Agreement, this DPA, and Customer's lawful instructions;
- not sell the information or share it for cross-context behavioral advertising;
- not retain, use, or disclose it outside the direct business relationship with Customer or for a commercial purpose other than the specified purposes, except as permitted by applicable law;
- not combine it with personal information received from another person or collected through Armidus's independent consumer interactions, except as permitted by applicable law;
- provide the same level of privacy protection required of Customer for the processing delegated to Armidus;
- notify Customer if Armidus determines it can no longer meet an applicable obligation; and
- allow Customer to take reasonable and appropriate steps to help ensure compliant processing and to stop and remediate unauthorized use.
Customer may monitor compliance through the information and audit mechanisms in Section 12. The parties agree that Customer Personal Data is disclosed for the business purposes in Schedule 1 and not as consideration for money or another commercial benefit.
15. Singapore data-intermediary terms
To the extent Armidus acts as a data intermediary for Customer under Singapore's Personal Data Protection Act 2012, Armidus will comply with the obligations applicable to it in that role, including applicable protection, retention-limitation, and data-breach notification obligations. Armidus will assist Customer with information reasonably required for Customer's own obligations under the Act.
Customer remains responsible for obligations that apply to the organization that determines the purposes and means of collection, use, or disclosure, including notice, consent or another legal authority, purpose limitation, accuracy, access and correction, and accountability, except to the extent the Act places an obligation directly on Armidus.
16. Liability and order of precedence
Each party's liability arising from this DPA is subject to the exclusions and limitations of liability in the Agreement, to the maximum extent permitted by law. Nothing in this DPA limits a liability that cannot lawfully be limited.
If documents conflict regarding the processing of Customer Personal Data, the following order controls:
- any mandatory data-transfer terms required by applicable law;
- a written amendment to this DPA that expressly identifies the provisions being amended and is signed by authorized representatives of both parties;
- this DPA; and
- the remainder of the Agreement.
An Order Form or other agreement does not amend this DPA merely because it contains different or additional terms. The Privacy Policy does not reduce Armidus's contractual obligations under this DPA.
17. Duration and termination
This DPA becomes binding when Customer accepts or enters into the Agreement and applies from the time Armidus first processes Customer Personal Data on behalf of Customer. It continues until Armidus no longer processes Customer Personal Data, subject to legally permitted retention. Provisions that must remain effective to protect retained Customer Personal Data survive termination of the Agreement.
18. Changes
Armidus may update this DPA prospectively to reflect changes in law or the Service. An update will not materially reduce protection of Customer Personal Data during a current paid Subscription. If an update materially affects Customer's rights, Armidus will provide advance notice and any objection or termination right required by law or the Agreement.
19. Contact
Use the Privacy or Legal option at https://armidus.com/submit-request for DPA requests, subprocessor objections, or data-protection questions. Do not include patient records, passwords, payment-card information, or claim links in the general form. Armidus will provide a secure channel if supporting data is needed.
Privacy and data-protection requests may also be sent to Armidus's Data Protection Officer at privacy@armidus.com.
Legal notices may also be sent by tracked post to:
Armidus, Inc. 1111B South Governors Avenue #49736 Dover, DE 19904 United States
Schedule 1: Details of processing
A. Subject matter
Provision, security, maintenance, and support of Armidus's veterinary post-visit care and operations platform for Customer.
B. Duration
The Subscription term plus the return, deletion, backup, legal-hold, and other limited retention periods described in the Agreement and this DPA.
C. Nature and purposes
- collection and import of Clinic, owner, animal patient, and care information;
- organization, structuring, validation, storage, retrieval, display, and Customer-authorized amendment of care content;
- creation and administration of owner claim links and account connections;
- generation, scheduling, and recording of care tasks and owner interactions;
- transmission of transactional messages and high-severity owner reports to the relevant Clinic;
- user authentication, authorization, Clinic separation, and account security;
- AI-assisted organization of Clinic-authored text when Customer invokes the feature;
- operation, monitoring, backup, recovery, troubleshooting, and support; and
- return, deletion, and de-identification as instructed and legally permitted.
D. Data Subjects
- Customer's veterinarians, administrators, staff, contractors, and authorized representatives;
- pet owners and other adult caregivers or contacts;
- treating clinicians and other professionals identified in care records;
- individuals appearing in communications, owner submissions, audit records, or support material; and
- other individuals whose personal data Customer lawfully submits.
Animal patients are not Data Subjects, but their records can contain personal data relating to owners and Clinic personnel.
E. Categories of Customer Personal Data
- identity and contact information, including names, emails, phone numbers, account IDs, Clinic affiliations, and professional roles;
- Clinic profile and business-contact information;
- authentication, organization-membership, role, claim, and access information;
- owner contact information copied into an animal patient record;
- Clinic-authored care-plan source text, guidance, schedules, and educational content that identifies or can be linked to an individual;
- treating-clinician identity and activity history;
- owner-submitted text, forms, symptom descriptions, photos or links, and task completion information;
- event, audit, timestamp, device, security, and usage information connected to an individual; and
- support and operational communications containing Customer Personal Data.
F. Sensitive or special-category data
The Service is designed for animal care and does not require human medical records, government identifiers, biometric data, payment-card numbers, or precise financial-account credentials. Customer must not submit those data types unless Armidus has expressly documented support and the parties have agreed on appropriate safeguards.
Owner text, photos, or other free-form material may incidentally contain sensitive information. Customer is responsible for data minimization and for instructing its users not to submit unnecessary human-sensitive information.
G. Frequency
Continuous and event-driven during the Subscription, based on Customer and Authorized User activity, scheduled tasks, notifications, and Service operations.
Schedule 2: Technical and organizational measures
Armidus currently maintains the following measures for the production Service.
1. Regional and tenant separation
- A separate Google Cloud project, application stack, database, and secrets for each launched production country.
- Regional owner and patient application records are not automatically merged or synchronized across countries.
- Each animal patient record belongs to a Clinic, and service queries scope access to the authenticated Clinic or linked owner.
2. Identity and access management
- Clerk-based identity and organization membership.
- Layered authorization through same-origin backend-for-frontend routes, API token validation, route guards, and service-layer database scoping.
- Clinic access based on authenticated organization membership and role.
- Owner access only after verified-email linking, valid claim, or another explicit enrollment path.
- Internal administrative access restricted to a separately configured Armidus administration organization.
- Access removal and role management available to Customer administrators.
3. Application and API protection
- Protected browser requests use same-origin server routes that attach verified bearer tokens to API requests.
- Backend validation of request payloads and resource ownership.
- Customer-supplied identifiers are not treated as authorization proof.
- Production services use managed HTTPS endpoints and restricted load-balancer ingress.
4. Encryption and secrets
- Encryption of customer content at rest through Google Cloud infrastructure.
- Encryption of Service traffic in transit through HTTPS or provider-secured connections.
- Production secrets held in Google Secret Manager rather than application source code.
- Environment-specific credentials for databases, authentication, email, payments, and AI providers.
5. Data and token protection
- Raw owner claim tokens are not stored. Only cryptographic hashes are retained in the application database.
- Owner linking requires a verified primary email and server-side validation.
- Payment-card numbers and security codes are collected on Stripe-hosted surfaces and do not pass through Armidus application servers.
- AI output is treated as untrusted, validated against application schemas, and subject to Clinic review.
6. Logging and monitoring
- Logging rules prohibit raw authentication tokens, claim tokens, secrets, database credentials, and complete owner or patient payloads.
- Production monitoring for availability, application errors, latency, database capacity, provider failures, and certificate expiry.
- Production default log retention currently configured for up to 180 days.
- Alerts routed to restricted operational contacts.
7. Availability and recovery
- Automated database backups, point-in-time recovery, retained transaction logs, storage growth controls, and deletion protection in production.
- Regional high-availability configuration for the production database.
- Recovery points before production database migrations.
- Health checks and controlled deployment workflows.
8. Organizational safeguards
- Confidentiality obligations for personnel and contractors with access.
- Least-privilege access appropriate to job responsibility.
- Environment separation and fail-fast handling of missing security-critical configuration.
- Security incident investigation and customer-notification obligations.
- Vendor contracts and diligence appropriate to processing risk.
Schedule 3: Authorized Subprocessors
The current Authorized Subprocessors and processing details are maintained at:
https://armidus.com/subprocessors
That page distinguishes Authorized Subprocessors that process Customer Personal Data under this DPA from payment providers and Armidus business-system providers used for Armidus's independent processing.