Data Processing Addendum (DPA)
Effective date: 27 July 2026
This Addendum forms part of the Terms of Service between Ryan Murdoch Haste (ABN 93 739 849 070) trading as Wattle Veterinary Health (“Wattle”, “we”, “us”) and the customer clinic (“you”, “the clinic”). It governs our handling of personal information you provide or generate through the Service. It is drafted for the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs); “controller” and “processor” are used as convenient analogues, not as terms importing overseas law.
1. Roles
1.1 You (the clinic) decide what personal information is collected and why. For the client (pet-owner) and patient records you enter, you are the APP entity accountable under the Privacy Act (analogous to a “controller”), including for responding to pet-owner access, correction, and deletion requests.
1.2 Wattle handles that data only on your instructions to provide the Service (analogous to a “processor”). We do not service pet owners directly; we assist you as set out in clause 3.
1.3 Wattle is separately the APP entity for clinic-staff account data and for its own billing, support, and website-contact records. Those are covered by our Privacy Policy, not this Addendum.
2. Scope of processing
2.1 Categories of data: clinic details; staff accounts (name, email, role, professional title, vet registration number and state, hashed Schedule 8 PIN); client (pet-owner) contact and billing details, including ABN for organisational payers and insurance details; patient (animal) clinical records, including notes, treatments, prescriptions, laboratory results, documents, and photos; appointments; billing records (append-only ledger, invoices, payments, estimates, receipts); communications records and delivery status; files in private clinic-scoped storage; quick notes (private to their author); and, where enabled, Schedule 8 controlled-drug register entries in an isolated register schema, together with associated audit logs.
2.2 Purpose: solely to provide, secure, support, and maintain the Service, and to meet legal record-keeping obligations.
2.3 Duration: for the term of your subscription, then per clause 6 (Retention and deletion).
3. Wattle’s obligations
3.1 Instructions. We process your data only to provide the Service, on your instructions given through the Service or in writing, or as required by law (in which case we will tell you unless the law prevents it).
3.2 Security measures. We apply technical and organisational measures including:
- row-level security on every database table with per-clinic isolation;
- private, clinic-scoped file storage;
- least-privilege roles; privileged service credentials held server-side only;
- short-lived (15-minute) session tokens with verified identity-token signatures; suspension enforced at token exchange; Bearer-token authentication (no cookies), structurally mitigating cross-site request forgery;
- for Schedule 8 register surfaces, two-step verification — password sign-in plus a per-user, server-verified PIN with lockout and idle re-authentication (this is not multi-factor authentication and is not represented as such);
- TLS 1.2+ in transit; AES-256/provider-default encryption at rest;
- security headers (CSP, X-Frame-Options DENY, nosniff, Referrer-Policy, Permissions-Policy, HSTS);
- two independent, encrypted backups — our database provider’s managed daily backups (7-day retention) and a separate off-site backup held with a different provider (retained up to 45 days);
- append-only audit logs; the Schedule 8 register is append-only with a cryptographic hash chain and verification function.
Service targets (99.5% uptime, RPO under 24 hours, RTO under 4 hours) are operational targets, not contractual service levels.
3.3 Confidentiality. We ensure that any person we authorise to process your data is bound by confidentiality obligations.
3.4 Assistance. Taking into account the nature of the processing, we will assist you, so far as reasonable, with: (a) pet-owner access requests (APP 12) — we acknowledge assistance requests within 1 business day and help you deliver within the 30-day statutory maximum; (b) correction requests (APP 13) — in-app editing with a full audit trail is the correction mechanism; and (c) your obligations under the Notifiable Data Breaches (NDB) scheme (see clause 7).
3.5 No use for our own purposes. We do not use your clients’ or patients’ data for our own purposes. Sole carve-out: we may generate and use aggregated, de-identified service telemetry (for example, usage volumes and performance metrics that cannot identify any person, client, or patient) for the purpose of operating, securing, and improving the platform.
4. Sub-processors
4.1 You authorise us to engage third-party service providers (“sub-processors”) to deliver the Service, for functions including: hosting and database storage, identity and sign-in services, transactional email delivery, error monitoring and diagnostics, payment processing, and AI text-processing services used to extract or summarise information you submit. We remain responsible for their handling of your data and impose data-protection obligations on them consistent with this Addendum. A current list of our sub-processors, including where each is located, is available on request to [email protected].
4.2 Change notice. We will give you at least 14 days’ prior notice of any intended addition or replacement of a sub-processor that processes your data, by in-app notice or email.
4.3 Right to object. If you reasonably object on data-protection grounds within that notice period, we will discuss the concern in good faith. If we cannot resolve it, your remedy is to terminate the affected subscription and export your data (clauses 6 and 8) before the change takes effect — no termination fee applies.
5. Cross-border disclosure (APP 8)
5.1 Your primary record data — the database and stored files — remains in Australia.
5.2 Some sub-processors are located overseas and may process limited personal information outside Australia in the course of providing their services. Before using an overseas provider, we take reasonable steps — including contractual data-protection commitments — to satisfy ourselves it will handle personal information consistently with the Australian Privacy Principles, as required by APP 8.1.
6. Retention and deletion
6.1 During the term, your data is retained for as long as you keep it — you control your own records within the Service.
6.2 On cancellation or account deletion: if you hold a paid subscription, it is cancelled at the end of the billing period you have already paid for — you keep full access until then (use it to export your data), no further charges are made, and no partial-period refunds are given. If you do not hold a paid subscription, the clinic is soft-deleted immediately and access is revoked straight away. In both cases, once soft-deleted your data is retained for a 90-day restore window, after which it is permanently purged. Within the window, we can restore the account at your request via support; after purge, restoration is impossible — the data is gone from live systems, and it ages out of all backups within 45 days of that permanent deletion.
6.3 Immediate purge on request. Instead of the 90-day window, you may request in writing that we purge your data immediately. We will confirm before executing, because purging is irreversible.
6.4 Our own tax records. Wattle retains a minimal set of its own billing and tax records — who paid us and when — for 5 years, as required by Australian tax law (clinic legal name, ABN, billing address, subscription invoice numbers/amounts/dates, and payment-processor identifiers). These are held by our payment processor, not in a separate Wattle-side copy, and comprise transaction data only. No clinical, patient, or pet-owner data is included.
6.5 Your statutory retention duties. Statutory retention obligations for clinical records and the Schedule 8 controlled-drug register bind you, the clinic — not Wattle (register retention is, for example, 2 years in NSW and QLD, 3 years in VIC, and 5 years in WA). Wattle cannot retain records for you after purge. You must export your records before or at cancellation using the export tooling provided:
- Settings → Data export — full clinic export;
- Schedule 8 full export (
s8_export_all); - Register PDF/CSV reports for hard-copy retention.
A courtesy export reminder at cancellation is planned but not yet guaranteed; the obligation to export remains yours regardless.
6.6 Anonymisation of individual clients. Where a pet owner requests deletion, the default mechanism is the in-app anonymise action, which replaces the owner’s identifying details with placeholders while preserving the clinical record — satisfying APP 11.2 de-identification without breaching your retention duties. Hard deletion of individual clients is handled manually on written request and at your risk with respect to your retention obligations.
7. Data breaches
7.1 On becoming aware of a data breach (or suspected breach) affecting your data, we will notify you within 72 hours and provide reasonable information about the nature of the breach, the data affected, and the remediation steps taken or proposed.
7.2 We will provide reasonable assistance with your assessment and any notification obligations under the NDB scheme, and will not notify affected individuals on your behalf without your agreement unless the law requires us to.
8. Return and deletion on termination
8.1 On termination or expiry of your subscription, clause 6 applies: you may export your data via the tooling in clause 6.5 at any time before purge; data is purged after the 90-day window (or immediately on written request under clause 6.3), subject only to the clause 6.4 tax-record carve-out.
8.2 We have no obligation to retain, restore, or reproduce your data after purge.
9. Assignment
9.1 Wattle currently operates as a sole trader and intends to incorporate. We may assign this Addendum (together with the Terms of Service) to a successor entity that acquires or continues the Wattle Clinic business — including a company incorporated by or for Ryan Murdoch Haste — provided the successor assumes all obligations under this Addendum.
9.2 We will give you notice of any such assignment. Your continued use of the Service after that notice constitutes acceptance of the assignment; no re-signature is required. Your rights under this Addendum are unaffected by the assignment.
10. Precedence
If this Addendum conflicts with the Terms of Service on data-handling matters, this Addendum prevails to the extent of the inconsistency. This Addendum is governed by the laws of New South Wales, Australia.