Data Processing Agreement

Last updated: June 17, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the veterinary practice (“Practice,” the data controller) and Chartling, operated by Cladeworks LLC (“Chartling,” the data processor), and governs Chartling’s processing of personal data on the Practice’s behalf. It supplements our Terms of Service and Privacy Policy. Where this DPA conflicts with the Terms on data protection, this DPA controls.

1. Roles

The Practice is the controller of the personal data it submits to Chartling — including its team members’ details and its clients’ contact and animal records. Chartling is the processor and acts only on the Practice’s documented instructions, which include the use of the platform as configured by the Practice.

2. Scope and purpose of processing

Chartling processes personal data solely to provide and support the service: clinical record-keeping, scheduling, billing, client communications, AI-assisted documentation, and related features the Practice enables. We do not process the data for our own purposes, and we do not sell it.

3. Categories of data and data subjects

4. Confidentiality

Personnel authorized to process personal data are bound by confidentiality obligations and access data only as needed to deliver and support the service.

5. Security

Chartling maintains technical and organizational measures appropriate to the risk, including encryption in transit, access controls and per-clinic isolation, role-based permissions, and tamper-evident audit logging of sensitive actions.

6. Sub-processors

The Practice authorizes Chartling to engage sub-processors to deliver the service. We impose data-protection terms on each sub-processor no less protective than this DPA. Our principal sub-processors are Supabase (authentication, database, and storage), Cloudflare (hosting, content delivery, and security), and Google (via the Lovable AI Gateway) for AI-assisted features. We will give notice of material changes to this list and a chance to object.

7. International transfers

Where personal data is transferred across borders, we rely on an appropriate transfer mechanism (such as Standard Contractual Clauses) with the relevant sub-processor.

8. Assistance to the Practice

Taking into account the nature of processing, Chartling assists the Practice in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations.

9. Personal data breaches

Chartling will notify the Practice without undue delay after becoming aware of a personal data breach affecting the Practice’s data, with the information reasonably available to help the Practice meet its own notification duties.

10. Return and deletion

On termination, and at the Practice’s choice, Chartling will return or delete the Practice’s personal data, except where retention is required by law. Some records (for example controlled-substance logs) carry mandatory legal retention periods and are retained accordingly.

11. Audits

Chartling will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with audits on reasonable notice, subject to confidentiality.

Contact

To request a signed copy of this DPA or to raise a data-protection question, email support@chartling.io.