Legal
Data Processing Addendum
Last updated: July 2026
This addendum supplements the Terms of Service and applies where a facility (“controller”) uses Kennelio to process personal data of its owners, staff, or dogs' contact details, and Provada (“processor”) processes that data on the facility's behalf.
1. Subject matter
Provada processes personal data solely to provide, secure, and support the Kennelio service, and only on documented instructions from the controller, unless required otherwise by law.
2. Categories of data
Owner names, phone numbers, and payment records; dog names and vaccination records; staff account details. Each record is scoped to a single tenant and isolated with Postgres Row-Level Security.
3. Sub-processors
A current list of sub-processors (database/auth hosting, payments) is available on request. We will notify controllers of any new sub-processor with an opportunity to object.
4. Security measures
Encryption in transit and at rest, per-tenant Row-Level Security, role-based access control, and an audit trail of data-changing actions, as described in our security overview.
5. Data subject requests
We will assist the controller in responding to data subject access, correction, or deletion requests to the extent required by applicable law.
6. Deletion on termination
On termination, tenant data is retained for 30 days for recovery purposes and then permanently deleted, unless a longer retention period is required by law.
This page is a working template provided as a starting point and has not been reviewed by a lawyer. If you serve customers under GDPR or similar regimes, have this reviewed and formally executed rather than relied on as-is.