Data Processing Agreement
Last updated: June 17, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the veterinary practice (“Practice,” the data controller) and Chartling, operated by Cladeworks LLC (“Chartling,” the data processor), and governs Chartling’s processing of personal data on the Practice’s behalf. It supplements our Terms of Service and Privacy Policy. Where this DPA conflicts with the Terms on data protection, this DPA controls.
1. Roles
The Practice is the controller of the personal data it submits to Chartling — including its team members’ details and its clients’ contact and animal records. Chartling is the processor and acts only on the Practice’s documented instructions, which include the use of the platform as configured by the Practice.
2. Scope and purpose of processing
Chartling processes personal data solely to provide and support the service: clinical record-keeping, scheduling, billing, client communications, AI-assisted documentation, and related features the Practice enables. We do not process the data for our own purposes, and we do not sell it.
3. Categories of data and data subjects
- Data subjects: Practice staff, and the Practice’s clients (animal owners).
- Personal data: names, contact details, account credentials, and the contents of clinical and billing records the Practice creates.
4. Confidentiality
Personnel authorized to process personal data are bound by confidentiality obligations and access data only as needed to deliver and support the service.
5. Security
Chartling maintains technical and organizational measures appropriate to the risk, including encryption in transit, access controls and per-clinic isolation, role-based permissions, and tamper-evident audit logging of sensitive actions.
6. Sub-processors
The Practice authorizes Chartling to engage sub-processors to deliver the service. We impose data-protection terms on each sub-processor no less protective than this DPA. Our principal sub-processors are Supabase (authentication, database, and storage), Cloudflare (hosting, content delivery, and security), and Google (via the Lovable AI Gateway) for AI-assisted features. We will give notice of material changes to this list and a chance to object.
7. International transfers
Where personal data is transferred across borders, we rely on an appropriate transfer mechanism (such as Standard Contractual Clauses) with the relevant sub-processor.
8. Assistance to the Practice
Taking into account the nature of processing, Chartling assists the Practice in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations.
9. Personal data breaches
Chartling will notify the Practice without undue delay after becoming aware of a personal data breach affecting the Practice’s data, with the information reasonably available to help the Practice meet its own notification duties.
10. Return and deletion
On termination, and at the Practice’s choice, Chartling will return or delete the Practice’s personal data, except where retention is required by law. Some records (for example controlled-substance logs) carry mandatory legal retention periods and are retained accordingly.
11. Audits
Chartling will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with audits on reasonable notice, subject to confidentiality.
Contact
To request a signed copy of this DPA or to raise a data-protection question, email support@chartling.io.