Skip to content

Agilix Vet Data Processing Agreement

The data processing agreement (art. 28 GDPR) between a veterinary clinic and Agilix Vet: data covered, security, sub-processors, breaches, and the return and deletion of data.

Effective from 9 October 2026.

The parties

Controller - the veterinary clinic (a sole trader, a company or another entity) that created a clinic in Agilix Vet or whose Owner accepted this agreement in the Panel (the "Clinic").

Processor - the provider of Agilix Vet (the "Provider"):

  • Full company name: Hackerman Consulting - Adam Gajzlerowicz
  • Tax ID (NIP): 7772841677
  • REGON: 380997651
  • Registered address: Hebanowa 16E, 62-020 Zalasewo, woj. wielkopolskie
  • Email: adam@agilix.dog

This agreement is concluded together with accepting the Agilix Vet Terms of Service and forms part of them. See the Agilix Vet Terms of Service. The terms Panel, Owner, Employee, User and Clinic Data have the meaning given to them in the Terms of Service. GDPR means Regulation (EU) 2016/679.

  1. Subject matter and purpose of processing

    • The Clinic entrusts the Provider with processing the personal data that Users record in the Panel, to the extent and for the purpose of providing the Agilix Vet service described in the Terms of Service.
    • The Provider does not process this data for its own purposes, does not sell it and does not use it for advertising.
  2. Duration

    This agreement applies for the term of the Agilix Vet service agreement and, after it ends, until the data is returned and deleted under section 13.

  3. Nature of processing

    The Provider processes the data by automated means as part of running the Panel: it collects it from Users, stores, organises, searches and displays it, makes it available to the Clinic's team, creates suggestions from it with an AI model (Terms of Service, section 8), backs it up and deletes it.

  4. Types of data and categories of data subjects

    • Categories of data subjects: the Clinic's clients (animal owners), their contact persons and other people whose data Users record in the Panel, for example in notes or files.
    • Types of data: names, phone numbers, e-mail addresses, addresses, country, information on outstanding payments, signed documents and other files, animal data and records of their visits and preventive care, notes by the Clinic's team and suggestions created by the AI model. The full list is in the Agilix Vet Privacy Policy.
    • The Panel is not intended for special categories of data (art. 9 GDPR) or data relating to criminal convictions (art. 10 GDPR). If the Clinic enters such data, the Provider protects it in the same way as other data.
  5. The Clinic's instructions

    • The Provider processes the data only on the Clinic's documented instructions. The instructions are the Terms of Service, this agreement and Users' actions in the Panel. An Owner gives any other instructions by e-mail.
    • If the law requires the Provider to process the data otherwise, it informs the Clinic before doing so, unless the law prohibits that.
    • The Provider promptly informs the Clinic if, in its opinion, an instruction infringes data protection law.
  6. Confidentiality

    The Provider gives access to the data only to people who need it to provide the service, maintain and repair the Panel or handle the Clinic's requests. These people are bound to confidentiality, also after their engagement ends.

  7. Security of processing

    The Provider applies the measures of art. 32 GDPR, in particular:

    • connections to the Panel are encrypted (HTTPS);
    • the Clinic's data is visible in the Panel only to members of its team, and some actions are available to Owners only;
    • sign-in uses an Agilix Account, and a team invitation can be accepted only from a confirmed e-mail address;
    • the Panel records which team member saved a visit;
    • files are not publicly accessible - the Panel opens them through links valid for up to 3 days;
    • the Panel and the database run on a server in the European Union;
    • the database is backed up: point-in-time recovery copies for 40 days, daily copies in the European Union for 60 days and a daily copy in the United States for 2 months;
    • files deleted in the Panel are deleted from file storage;
    • application errors and server logs are monitored (Sentry, Google Cloud Logging);
    • private notes are not sent to the AI model.

    The Provider regularly evaluates the effectiveness of these measures and adjusts them to the risk.

  8. Sub-processors

    The Clinic gives the Provider general authorisation to engage sub-processors. They currently are:

    • Hetzner Online GmbH (Germany) - a server in the European Union that runs the Panel, the search and the database;
    • Google (Firebase, Google Cloud) - file storage in a United States region, database backups in Frankfurt and a daily copy in the United States, server logs (Google Cloud Logging), the Gemini model (Gemini API) and statistics (Google Analytics), which receive the addresses of Panel pages visited, including internal client and animal identifiers;
    • Mailgun Technologies, Inc. - delivery of messages from the Panel's contact form (servers in the European Union);
    • Functional Software, Inc. (Sentry) - application errors and performance measurements (United States);
    • Cloudflare, Inc. - all traffic to the Panel passes through its network.
    • The Provider informs the Owners by e-mail at least 14 days in advance of any intended addition or replacement of a sub-processor. The Clinic may object within that time and, if the Parties do not reach agreement, terminate the agreement without notice.
    • The Provider imposes on sub-processors data protection obligations no less protective than those in this agreement and is liable to the Clinic for their performance.
  9. Transfers outside the EEA

    Some data leaves the European Economic Area, in particular to the United States (section 8). The transfers rely on a European Commission adequacy decision (the Data Privacy Framework) or on Standard Contractual Clauses approved by the European Commission. The Provider gives the Clinic a copy of the safeguards on request.

  10. Data subjects' rights

    • The Clinic fulfils its clients' rights itself, using the Panel's features: viewing the data, correcting it, deleting files and archiving clients.
    • Where the Panel lacks the needed feature, an Owner asks the Provider by e-mail, and the Provider carries out the request within 14 days.
    • The Provider forwards to the Clinic any requests that individuals address to it directly, and does not answer them itself.
  11. Assistance to the Clinic

    Taking into account the nature of processing and the information available to it, the Provider assists the Clinic in meeting its obligations under arts. 32-36 GDPR: security, breach notification, data protection impact assessments and prior consultation with the supervisory authority.

  12. Personal data breaches

    • The Provider notifies the Clinic of a personal data breach affecting the Clinic's data within 48 hours of becoming aware of it, by e-mail to the Owners.
    • The notice includes, as far as available, the information listed in art. 33(3) GDPR: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken or proposed and a contact person. Information not available at once is provided without undue delay afterwards.
    • The Clinic notifies the supervisory authority and the data subjects.
  13. Return and deletion of data

    After the service ends, the Provider returns and deletes the data in the way and within the periods described in section 14 of the Terms of Service, unless the law requires it to be kept.

  14. Information and audits

    • The Provider makes available to the Clinic the information necessary to demonstrate compliance with art. 28 GDPR within 14 days of a request.
    • The Clinic or an auditor it authorises may carry out an audit after giving the Provider at least 14 days' notice, no more than once every 12 months unless the audit follows a personal data breach or a request by the supervisory authority. The audit is carried out at the Clinic's cost, without disrupting the Panel and under confidentiality.
    • For sub-processors, the Provider may provide their reports and certifications instead of an on-site audit.
  15. Liability

    Towards data subjects, the Parties are liable under art. 82 GDPR. Between the Parties, the liability provisions of section 10 of the Terms of Service apply, to the extent permitted by law.

  16. Final provisions

    • In matters of personal data, this agreement prevails over the Terms of Service.
    • This agreement is changed following the procedure in section 15 of the Terms of Service.
    • This agreement is governed by Polish law, and disputes are resolved by the court named in the Terms of Service.
    • The Polish version of this agreement is binding. Other language versions are translations.