Data Processing Agreement (DPA)
This Data Processing Agreement governs the processing of personal data by Oden on behalf of our business customers, in accordance with GDPR and other applicable data protection laws.
Last updated: June 1, 2025
1. Roles and parties
This DPA is between Oden Inc. ("Processor") and the business customer who uses Oden to process personal data ("Controller"). The Processor processes personal data only on behalf of, and on the documented instructions of, the Controller.
2. Categories of data
The Processor may process the following categories of personal data on behalf of the Controller: customer contact information (name, email, phone, address), pet information, appointment and session history, billing information, and any other data the Controller enters into the platform. The Processor does not process special categories of personal data unless specifically directed by the Controller.
3. Purpose of processing
The Processor processes personal data solely to provide the Oden platform as described in the Terms & Conditions, including providing scheduling, customer management, billing, and related features.
4. Sub-processors
The Processor engages sub-processors to deliver the service, including cloud hosting, email delivery, payment processing, and analytics. A current list of sub-processors is available on request. The Processor remains liable for the acts and omissions of its sub-processors.
5. Security measures
The Processor implements industry-standard security measures as described on our Security page, including encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access controls, and activity monitoring. The Processor is working toward SOC 2 alignment as it scales.
6. International data transfers
The Processor may transfer personal data outside the European Economic Area. Such transfers are governed by Standard Contractual Clauses or other appropriate safeguards as required by applicable law.
7. Data subject rights
The Processor will assist the Controller in responding to data subject requests where reasonably possible. The Processor will not respond directly to data subject requests without the Controller's authorization, except where required by law.
8. Breach notification
The Processor will notify the Controller of a personal data breach without undue delay and in any case within 72 hours of becoming aware of the breach, providing all information reasonably necessary for the Controller to meet its own breach notification obligations.
9. Data return and deletion
Upon termination of the service, the Processor will, at the Controller's choice, return or delete all personal data, except where retention is required by law. The Controller may export their data at any time during the term of the service.
10. Audit rights
The Controller may audit the Processor's compliance with this DPA once per year, with reasonable notice, and subject to confidentiality obligations. The Processor will provide relevant documentation, including third-party audit reports, to demonstrate compliance.
11. Contact
For questions about this DPA or to request execution of a signed copy, contact us at legal@oden.pet.