Vetspeaking

Data Processing Agreement

Last updated: 2026-08-16

This data processing agreement (the DPA) is entered into under Article 28 of the UK GDPR where the Customer is established in the United Kingdom, and under Article 28 of the EU GDPR where the Customer is established in Ireland or elsewhere in the EEA. It forms an integral part of the Terms of Use and governs the processing of personal data where Frominbox, MB (Vetspeaking) processes data on behalf of the Customer (a veterinary practice).

1. Parties and roles

  1. 1.1Data controller - the Customer (the veterinary practice) using the service, who determines the purposes and means of processing the data of people calling them.
  2. 1.2Data processor - Frominbox, MB, company code 307162506, registered at A. Juozapavičiaus g. 28, LT-09311 Vilnius, Lithuania, who processes that data on the Customer’s behalf and on their instructions.

The Processor is established outside the United Kingdom. Where the Processor is required to designate a representative in the UK under Article 27 of the UK GDPR, it will do so and will notify the Customer of the representative’s details.

This DPA applies only to processing we carry out as processor. For data where we are the controller ourselves, the Privacy Policy applies.

2. Subject matter, nature and purpose of processing

  1. 2.1Subject matter: processing callers’ personal data while providing the AI phone-answering service to a veterinary practice.
  2. 2.2Purpose: answering calls, taking enquiries and bookings, collecting contact details, recording and transcribing calls, providing summaries, forwarding calls, and escalating urgent calls.
  3. 2.3Nature: collection, recording, transcription, storage, structuring, use, disclosure to sub-processors, transfer to integrations the Customer chooses (calendar, practice-management or CRM system) on their instructions, and deletion.
  4. 2.4Duration: for as long as the service is provided, for the term of the Terms of Use.
  5. 2.5A detailed description is given in the annexes to section 12.

3. Processor obligations

Vetspeaking agrees to:

  1. 3.1process personal data only on the Customer’s documented instructions, including this DPA, except where required by law;
  2. 3.2inform the Customer without delay if, in our view, an instruction infringes applicable data protection law;
  3. 3.3process data only for the purposes set out in this DPA and not use it for our own purposes, including not using it to train AI models;
  4. 3.4ensure data is processed only by authorised staff who are bound by confidentiality;
  5. 3.5assist the Customer in fulfilling their obligations under applicable data protection law;
  6. 3.6while providing technical support, maintaining the service, or, at the Customer’s request, setting up or configuring the agent, allow our authorised staff to access the Customer’s account and manage the data in it; this is treated as processing on the Customer’s documented instructions (this DPA, the Terms of Use, and the Customer’s own support requests);
  7. 3.7design and operate the service so that callers are told they are speaking with an AI assistant, and so that calls cannot be recorded without the greeting saying so - see Annex A.

4. Confidentiality

We treat all data processed on the Customer’s behalf as strictly confidential.
  1. 4.1Only authorised staff who need access to perform their duties have it, and they are bound by a written or statutory confidentiality obligation.
  2. 4.2We do not disclose data to third parties, except approved sub-processors or where required by law.
  3. 4.3Every access by an authorised staff member to the Customer’s account is logged (who accessed which practice, and when), as set out in section 5; we provide these logs to the Customer on request.
  4. 4.4The confidentiality obligation continues indefinitely, including after the service ends.
Veterinary client confidentiality.We understand that the RCVS Code of Professional Conduct requires a practice not to disclose information about a client or a client’s animals to a third party without permission, and to limit any disclosure to the minimum necessary. Engaging us as a processor is consistent with that: we act only on the practice’s instructions, we do not become a recipient entitled to use the information for our own purposes, and the practice remains in control of what is collected and for how long. A fuller note is available on request.

5. Security measures

In line with Article 32, we implement appropriate technical and organisational measures, including:

  1. 5.1encrypting data in transit (TLS) and at rest;
  2. 5.2access control, authentication and the principle of least privilege;
  3. 5.3activity logging and monitoring;
  4. 5.4backups and the ability to restore data availability;
  5. 5.5regular review of how effective these measures are.

A fuller description of these measures is in Annex B (section 12).

6. Sub-processors

  1. 6.1The Customer gives general authorisation for us to engage sub-processors to provide the service.
  2. 6.2We provide the Customer with the current sub-processor list - including each provider’s role, location and applicable transfer safeguard - within 5 working days of a request to paul@vetspeaking.com. The list forms an integral part of this DPA; it is not published publicly, since it is the Processor’s commercial information, and is provided under confidentiality.
  3. 6.3We engage sub-processors who process personal data under their own published data processing terms and apply safeguards meeting the requirements of applicable data protection law; we choose providers offering a level of protection consistent with this DPA.
  4. 6.4We notify the Customer, at the email address on their account, of any intended change or new sub-processor at least 30 days before the change. Within that period the Customer may reasonably object; if no resolution is reached, the Customer has the right to terminate the service without further penalty.
  5. 6.5We remain responsible to the Customer for a sub-processor’s compliance with data protection obligations to the same extent we are responsible for our own actions.
Integrations the Customer connects themselves.When the Customer connects a third-party system themselves (a calendar, practice-management or CRM system), we only send data to it on the Customer’s instruction and within the scope they configure. Such systems act as independent recipients chosen by the Customer, not as our sub-processors; the Customer is responsible for choosing them, for their lawful basis, and for their agreements with them. The list of systems that can be connected is in section 7.1 of the Privacy Policy.

7. Assistance with data subject rights

Taking into account the nature of the processing, we use appropriate technical and organisational measures to help the Customer fulfil their obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). The Customer can view, export and delete calls, transcripts and contacts directly in their account. If a caller contacts us directly, we refer them to the Customer as data controller and let the Customer know.

8. Breach notification and assistance

  1. 8.1On becoming aware of a personal data breach, we notify the Customer without undue delay and provide the information available to us that they need to meet their own obligations. This applies to every breach, not only serious ones - the assessment of whether it is reportable is the Customer’s to make, as controller.
  2. 8.2The Customer, as controller, decides whether to report to their supervisory authority - the Information Commissioner’s Office in the UK, or the Data Protection Commission in Ireland - and does so within 72 hours of becoming aware where the breach is reportable.
  3. 8.3We help the Customer carry out a data protection impact assessment (DPIA) and, where needed, consult the supervisory authority in advance. A pre-filled DPIA template for veterinary practices is available on request.

9. International data transfers

Our database, call recordings and transcripts are stored in the United Kingdom (London). For a Customer established in the UK, this is domestic processing, not a restricted transfer, so no additional safeguard is required for that storage. Other legs of the processing do involve a transfer, and each has a lawful route:

  1. 9.1To the European Economic Area - the Processor is established in Lithuania, and payment and sign-in providers process some data in Ireland. These transfers are covered by the UK adequacy regulations for the EEA, so no additional safeguard is required.
  2. 9.2To the United States - covered by the UK Extension to the EU-US Data Privacy Framework where the provider holds an active certification covering the UK Extension. Where a provider is not so certified, we put in place the International Data Transfer Agreement issued by the Information Commissioner, or the UK Addendumto the European Commission’s Standard Contractual Clauses, and complete and record a transfer risk assessment (the “data protection test” under the Data (Use and Access) Act 2025).

Where the Customer is established in Ireland or elsewhere in the EEA, the position is different: because the Processor is established in the EU (Lithuania), it remains subject to the EU GDPR for everything it processes, wherever that happens. Storing the Customer’s data on UK-based infrastructure is therefore an international transfer from the Processor’s own perspective - covered by the European Commission’s adequacy decision for the United Kingdom (renewed December 2025, valid to December 2031), so no further safeguard is needed for that leg either. Transfers to the United States rely on the EU-US Data Privacy Frameworkwhere the provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses with supplementary measures.

The route applied to each individual provider is set out in the sub-processor list provided under section 6.

10. Return and deletion of data

Once the service ends, the data is gone. When the Customer ends the service, we permanently removeall personal data processed on their behalf from our database and audio storage; before doing so, at the Customer’s request, we give them the opportunity to take a copy. Some sub-processors may retain data briefly under their own retention schedules, after which it is deleted.
  1. 10.1We carry out deletion without undue delay, and in backups through the normal rotation cycle.
  2. 10.2Before deletion, the Customer is given the opportunity to take their data.
  3. 10.3We may retain only the data we are required to keep under applicable law, and only for the applicable period.
  4. 10.4At the Customer’s request, we provide confirmation that deletion has taken place.

11. Audits and inspections

We provide the Customer with the information needed to demonstrate compliance with the obligations of Article 28, and allow for audits carried out by the Customer or their authorised auditor, at a reasonable time and scope agreed in advance and subject to confidentiality.

12. Annexes (description of processing)

Annex A. Processing details

  • Categories of data subjects: people calling the practice - clients, prospective clients, and other callers.
  • Categories of personal data: first and last name, phone number, call audio recording and transcript, the content of the enquiry, booking details, and other information given during the call. Information about the caller’s animal (name, species, symptoms, treatment history) is processed where the caller provides it.
  • Special category data: the service is not expected to process special category data. Information about an animal’s health is not health data about a personand does not fall within Article 9. A caller may nonetheless volunteer information about their own health or circumstances while explaining their situation. The Processor does not solicit, extract, analyse or use such information for any purpose other than providing the service on the Customer’s instructions, and it is deleted with the rest of the call. Where it occurs, the Customer remains the controller and is responsible for its own lawful basis. The Customer can reduce what is collected in their settings, or turn off transcript storage.
  • Retention period:call recordings, transcripts, caller name and phone number, call summaries and any bookings created from the call are kept for the period the Customer chooses - 30, 90, 180 or 365 days (90 by default). Once that period ends, this personal data is deleted automatically, both in our systems and on the voice-technology provider’s side. Only the call’s date and duration remain, for billing. There is no unlimited-retention option. Contacts are not deleted automatically, since they are the Customer’s own business records.
  • Transparency to callers: the greeting discloses that the caller is speaking with an AI assistant, and, where recording is enabled, that the call is recorded. The service will not save a greeting that omits the AI disclosure, and disables recording if the greeting stops mentioning it. For new accounts, recording is off by default.
  • Processing operations: collection, recording, transcription, storage, use, disclosure to sub-processors, transfer to integrations the Customer chooses on their instructions, and deletion.

Annex B. Security measures

Encryption in transit and at rest; call audio held in private storage reachable only through short-lived signed links after an entitlement check; access control, authentication and least privilege; two-factor authentication on all staff accounts with system access; activity and access logging; signature verification on inbound webhooks; exclusion of personal data from system logs; daily backups with a tested recovery process; a written breach management process; staff confidentiality obligations.

Annex C. Sub-processors

The current list of approved sub-processors forms an integral part of this DPA and is provided to the Customer under the process in section 6 - within 5 working days of a request to paul@vetspeaking.com. It names each provider, what it is used for, where it processes data, and the transfer safeguard relied on.