Free Health Assessment
Data Processing & Protection

Data Processing Agreement

Last Updated: February 12, 2026

Lawful Basis • Purpose Limitation • Data Minimization • Security & Accountability

Lawful Data Processing Commitment

SOBS Pets processes personal information only on lawful bases and in accordance with applicable US privacy laws. This Data Processing Agreement describes the categories of data we process, the purposes of processing, the lawful bases we rely upon, and our data protection practices.

7 Lawful Bases
12 Data Categories
15+ Processors
24/7 Security Monitoring
1

Introduction & Scope

This Data Processing Agreement ("DPA") describes how SOBS Pets ("Controller") processes personal information in connection with the operation of our website, products, and services.

Scope

This DPA applies to all personal information processed by SOBS Pets, including information collected from:

  • Website visitors — Individuals who browse our website sobspets.com
  • Customers — Individuals who purchase our products or create accounts
  • Health Assessment users — Individuals who complete our pet health assessment tool
  • Marketing recipients — Individuals who subscribe to our communications
  • Customer support contacts — Individuals who contact our support team
  • Veterinarians & Professionals — Veterinary professionals who interact with our services

Controller-Processor Relationship

SOBS Pets acts as a Controller for the personal information we collect directly from you. We determine the purposes and means of processing your personal information. When we engage third-party service providers, they act as Processors acting on our behalf and under our instructions.

SOBS Pets Controller
Third-Party Processors
Sub-Processors (with authorization)
Incorporation by Reference:

This DPA is incorporated into and forms part of our Privacy Policy and Terms of Service. Capitalized terms not defined herein shall have the meanings assigned in those documents.

2

Definitions

The following terms have the meanings set forth below when used in this DPA:

"Controller" CCPA/CPRA
The entity that determines the purposes and means of processing personal information. SOBS Pets is the Controller.
"Processor" CCPA/CPRA
A third-party entity that processes personal information on behalf of and under the instructions of the Controller.
"Personal Information" / "Personal Data" CCPA/GDPR
Any information relating to an identified or identifiable natural person. This includes information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household.
"Sensitive Personal Information" CPRA
Personal information that reveals: (1) social security, driver's license, or state ID number; (2) account login credentials; (3) financial account information; (4) precise geolocation; (5) racial or ethnic origin; (6) religious beliefs; (7) union membership; (8) genetic data; (9) health information; (10) sex life or sexual orientation.
"Processing" CCPA/GDPR
Any operation or set of operations performed on personal information, whether by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, or erasure.
"Data Subject" GDPR/CCPA
The identified or identifiable natural person to whom the personal information relates.
"Service Provider" CCPA
A entity that processes personal information on behalf of a business and receives a consumer's personal information from a business for a business purpose pursuant to a written contract.
"Third Party" CCPA
An entity that is not the business that collects personal information from consumers nor a person that the business discloses personal information to for a business purpose and that is permitted to use the personal information for its own commercial purposes.
"Business Purpose" CCPA
The use of personal information for the business's operational purposes, as defined in Cal. Civ. Code § 1798.140(d).
3

Processing Purposes

SOBS Pets processes personal information for the following specific, explicit, and legitimate purposes:

Order Processing & Fulfillment

Purpose: Process payments, ship products, manage orders, handle returns and refunds.

Categories: Identifiers, Customer Records, Commercial Information

Lawful Basis: Contract performance

Account Management

Purpose: Create and manage user accounts, authenticate users, maintain account preferences.

Categories: Identifiers, Customer Records, Inferences

Lawful Basis: Contract performance, Legitimate interests

Health Assessment Service

Purpose: Generate personalized pet health recommendations, track assessment history, improve algorithms.

Categories: Identifiers, Commercial Information, Inferences

Lawful Basis: Contract performance, Consent

Analytics & Improvement

Purpose: Analyze website usage, improve products and services, conduct market research, measure customer satisfaction.

Categories: Identifiers, Internet Activity, Geolocation Data

Lawful Basis: Legitimate interests, Consent (cookies)

Marketing & Communications

Purpose: Send promotional emails, product recommendations, newsletters, and special offers.

Categories: Identifiers, Commercial Information, Inferences

Lawful Basis: Consent, Legitimate interests (existing customers)

Customer Support

Purpose: Respond to inquiries, resolve issues, provide technical support, handle complaints.

Categories: Identifiers, Customer Records, Commercial Information

Lawful Basis: Contract performance, Legitimate interests

Security & Fraud Prevention

Purpose: Detect and prevent fraud, maintain website security, protect against unauthorized access.

Categories: Identifiers, Internet Activity, Geolocation Data

Lawful Basis: Legitimate interests, Legal obligation

Legal Compliance

Purpose: Comply with applicable laws, regulations, court orders, and legal processes.

Categories: All relevant categories

Lawful Basis: Legal obligation

4

Categories of Data Subjects

SOBS Pets processes personal information of the following categories of data subjects:

Customers

Individuals who have purchased products, created accounts, or otherwise engaged in commercial transactions with SOBS Pets.

~50,000+ active customers

Website Visitors

Individuals who browse our website, interact with our content, or use our free tools (Health Assessment) without creating an account.

~500,000+ annual visitors

Marketing Subscribers

Individuals who have opted in to receive promotional communications, newsletters, or product updates.

~125,000+ subscribers

Customer Support Contacts

Individuals who have contacted our customer support team via email, phone, chat, or other channels.

~15,000+ annual contacts

Veterinary Professionals

Licensed veterinarians and veterinary staff who interact with our professional services or partner programs.

~500+ professionals

Recipients & Gift Recipients

Individuals who receive products as gifts or shipments from our customers.

~10,000+ annual recipients
5

Categories of Personal Data

SOBS Pets processes the following categories of personal information, mapped to CCPA/CPRA categories and including specific data elements:

Category CCPA/CPRA Category Specific Data Elements Purpose Retention
Identity Information A. Identifiers Full name, username, date of birth (optional), profile photo Account creation, personalization Account + 2 yrs
Contact Information A. Identifiers, B. Customer Records Email address, phone number, shipping address, billing address Order fulfillment, communication Account + 2 yrs
Payment Information B. Customer Records, L. Sensitive Credit card details, PayPal account, billing information Transaction processing Not stored by SOBS Pets
Account Credentials L. Sensitive Personal Information Password (hashed), security questions, authentication tokens Account security, authentication Account deletion
Pet Information D. Commercial Information, K. Inferences Pet name, species, breed, age, weight, health conditions, symptoms, medications Health assessment, recommendations 3 years
Transaction History D. Commercial Information Order history, purchase amount, products purchased, subscription status Order management, recommendations 7 years
Website Activity F. Internet Activity Pages visited, time spent, clicks, navigation path, search queries Analytics, optimization 26 months
Device Information F. Internet Activity IP address, browser type, operating system, device type Analytics, security 30 days (logs)
Location Information G. Geolocation Data IP-based location (city/region), shipping address Regional compliance, fraud prevention 30 days (IP logs)
Communication Content B. Customer Records Emails to support, chat transcripts, call recordings (with notice) Customer service, quality assurance 3 years
Marketing Preferences D. Commercial Information Email opt-in status, subscription preferences, communication history Consent management Until consent withdrawn
Inferences K. Inferences Pet health profile, predicted needs, product recommendations, customer lifetime value Personalization, improvement 3 years
6

Lawful Basis for Processing

SOBS Pets relies on the following lawful bases for processing personal information:

Contract Performance

CCPA/CPRA: Performance of Services

Processing necessary to fulfill our contractual obligations to you, including:

  • Processing and delivering orders
  • Creating and managing your account
  • Providing health assessment results
  • Customer support related to your purchases

Consent

CCPA/CPRA: Explicit Consent

Processing based on your freely given, specific, informed, and unambiguous consent:

  • Marketing emails and newsletters
  • Non-essential cookies and tracking
  • Optional data collection for research

You may withdraw consent at any time.

Legitimate Interests

CCPA/CPRA: Business Purpose

Processing necessary for our legitimate interests, provided such interests are not overridden by your rights:

  • Website analytics and optimization
  • Fraud detection and prevention
  • Network and information security
  • Product improvement and development
  • Direct marketing to existing customers

Legal Obligation

CCPA/CPRA: Legal Compliance

Processing necessary to comply with applicable legal obligations:

  • Tax and accounting records (7 year retention)
  • Compliance with court orders and subpoenas
  • Consumer protection laws
  • Product safety and recall obligations

Vital Interests

CCPA/CPRA: Emergency Situations

Processing necessary to protect someone's life. In rare circumstances, we may process information to address an imminent threat to an individual's health or safety.

This basis is rarely invoked and only in genuine emergencies.

Public Interest

Not currently relied upon

SOBS Pets does not currently process personal information for the performance of a task carried out in the public interest.

Legitimate Interests Balancing Test

For processing based on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms. Our legitimate interests are:

  • Commercial interests: Understanding our customers to improve products and services
  • Security interests: Protecting our website, users, and data from threats
  • Efficiency interests: Operating our business effectively and sustainably

We have determined that these interests are necessary and proportionate, and we implement safeguards to minimize privacy impacts.

7

Sensitive Personal Information

Enhanced Protection for Sensitive Data

SOBS Pets collects limited categories of sensitive personal information as defined under CPRA and other applicable laws. We apply additional safeguards and strictly limit the use of sensitive information.

Sensitive Data Category Collected Purpose Disclosure Retention
Social Security, Driver's License, State ID NO
Account Login Credentials YES Authentication, account security Not disclosed (hashed) Until account deletion
Financial Account, Debit/Credit Card Number YES* Payment processing PCI-compliant processors Not stored by SOBS Pets
Precise Geolocation NO
Racial or Ethnic Origin NO
Religious or Philosophical Beliefs NO
Union Membership NO
Genetic Data NO
Health Information (Human) NO
Sex Life or Sexual Orientation NO

*Note on Payment Information: Credit card numbers are processed directly by our PCI DSS Level 1 compliant payment processors (Stripe, PayPal). SOBS Pets does not store full credit card numbers on our servers. We store only the last four digits and card type for reference.

Right to Limit Use of Sensitive Information

Under CPRA, California residents have the right to limit the use of their sensitive personal information to that which is necessary to perform the services requested. Because SOBS Pets ONLY uses sensitive information for the purposes of providing the requested services (authentication and payment processing), there is no additional use to limit. We do not use sensitive information for any secondary purpose.

8

Third-Party Processors

SOBS Pets engages trusted third-party processors to assist in providing our services. All processors are contractually bound to:

  • Process personal information only on our documented instructions
  • Implement appropriate technical and organizational security measures
  • Maintain confidentiality obligations for their personnel
  • Assist us in fulfilling data subject rights requests
  • Notify us of any personal data breaches
  • Return or delete personal information after service termination
  • Demonstrate compliance with applicable data protection laws

Authorized Third-Party Processors

Processor Service Provided Data Categories Location Security Certification
Stripe, Inc. Payment processing Payment information, billing contact USA PCI DSS Level 1, SOC 2
PayPal, Inc. Payment processing Payment information, billing contact USA PCI DSS Level 1, SOC 2
Shopify, Inc. E-commerce platform Customer information, order history USA/CAN PCI DSS Level 1, SOC 2
Google LLC Analytics, email (G Suite) Website activity, email communications USA SOC 2, ISO 27001
Microsoft Corporation Analytics (Clarity), cloud services Website activity, usage data USA ISO 27001, SOC 2
Amazon Web Services Cloud hosting, data storage All data categories USA ISO 27001, SOC 2, FedRAMP
Mailchimp (Intuit) Email marketing Email address, preferences USA SOC 2, ISO 27001
Zendesk, Inc. Customer support platform Support tickets, customer communications USA SOC 2, ISO 27001
ShipStation Shipping & fulfillment Name, address, phone, order details USA SOC 2, PCI DSS
Twilio Inc. SMS notifications Phone number, opt-in status USA SOC 2, ISO 27001
Processor Agreements:

All processors are subject to written data processing agreements that comply with applicable privacy laws. These agreements include obligations regarding data security, confidentiality, sub-processing, audit rights, and assistance with data subject requests.

9

International Data Transfers

SOBS Pets is based in the United States and primarily processes personal information within the United States. However, we may transfer personal information to processors located in other countries as necessary to provide our services.

Transfer Mechanisms

When we transfer personal information outside the United States, we rely on the following safeguards:

Adequacy Decisions

For transfers to countries recognized by applicable law as providing adequate data protection (where applicable).

Standard Contractual Clauses

We utilize European Commission approved Standard Contractual Clauses for transfers from the EU/EEA.

Binding Corporate Rules

Not currently applicable (we are a single entity).

Consent

With your explicit consent for specific transfers.

Data Transfer Locations

Our processors are primarily located in:

  • United States
  • Canada
  • Ireland (EU)
  • Germany (EU)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, your personal information may be transferred to the United States and other jurisdictions that may not provide the same level of data protection as your home country. We provide appropriate safeguards through Standard Contractual Clauses and other transfer mechanisms.

10

Data Retention & Deletion

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, including for the satisfaction of legal, accounting, or reporting requirements.

Data Category Retention Period Rationale Deletion Method
Account Information Duration of account + 2 years Service continuity, potential reactivation Secure deletion, anonymization
Order History 7 years Tax, warranty, legal compliance Archival, secure deletion
Payment Information Not stored by SOBS Pets PCI DSS compliance N/A (processed by payment processors)
Health Assessment Data 3 years from submission Service improvement, customer support Anonymization, secure deletion
Marketing Preferences Until consent withdrawn + 30 days Consent management, audit trail Secure deletion
Website Analytics 26 months Google Analytics retention policy Aggregation, anonymization
Server Logs 30 days Security monitoring, troubleshooting Overwrite, secure deletion
Customer Support Communications 3 years Quality assurance, dispute resolution Secure deletion
Abandoned Cart Data 30 days Recovery marketing (with consent) Secure deletion

Deletion Procedures

When personal information reaches the end of its retention period, or when we receive a verified deletion request, we implement one of the following:

  • Secure deletion: Permanently erase data from our production systems using secure deletion methods (ATA Secure Erase, cryptographic erasure).
  • Anonymization: Irreversibly remove identifying information so that data can no longer be linked to an individual.
  • Archival: For legal holds or litigation, data may be placed on legal hold with restricted access.
We review our retention periods annually to ensure they remain appropriate and necessary.
11

Technical & Organizational Security Measures

SOBS Pets implements comprehensive technical and organizational security measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

Technical Measures

  • Encryption at rest: AES-256 encryption for all databases containing personal information
  • Encryption in transit: TLS 1.2+ for all data transmitted over networks
  • Access controls: Role-based access control (RBAC), principle of least privilege
  • Authentication: Multi-factor authentication for all administrative access
  • Network security: Firewalls, intrusion detection/prevention systems (IDS/IPS)
  • Vulnerability management: Weekly vulnerability scanning, quarterly penetration testing
  • Patch management: Automated security patching within 48 hours of critical releases
  • Logging & monitoring: 24/7 security information and event management (SIEM)
  • Backup: Encrypted daily backups with geographic redundancy
  • Web application firewall: Protection against OWASP Top 10 vulnerabilities

Organizational Measures

  • Data protection training: Annual mandatory training for all employees
  • Confidentiality agreements: All personnel bound by confidentiality obligations
  • Access reviews: Quarterly review of system access rights
  • Incident response: Documented incident response plan, tested annually
  • Vendor management: Security assessments for all third-party processors
  • Data protection officer: Designated DPO overseeing compliance
  • Privacy by design: Data protection impact assessments for new processing activities
  • Policy framework: Documented information security policies
  • Background checks: Pre-employment screening for relevant positions
  • Physical security: Access controls at office locations

Security Certifications & Compliance

SOC 2 Type II (in progress) PCI DSS Compliant ISO 27001 (planned 2026) CCPA/CPRA Compliant
Report a Security Vulnerability:

If you have discovered a security vulnerability in our systems, please contact our security team at security@sobspets.com. We follow responsible disclosure practices.

12

Data Subject Rights

SOBS Pets respects and facilitates the exercise of data subject rights under applicable privacy laws, including CCPA/CPRA, GDPR, and other US state privacy laws.

Right to Know / Access

Data subjects have the right to confirm whether we process their personal information and to access that information, along with details about our processing activities.

CCPA §1798.110, §1798.115 • GDPR Art. 15

Right to Delete

Data subjects have the right to request deletion of their personal information, subject to certain exceptions.

CCPA §1798.105 • GDPR Art. 17

Right to Correct

Data subjects have the right to request correction of inaccurate personal information.

CPRA §1798.106 • GDPR Art. 16

Right to Opt-Out

Data subjects have the right to opt-out of the sale or sharing of personal information. SOBS Pets does not sell personal information.

CCPA §1798.120 • CPRA

Right to Limit

Data subjects have the right to limit the use of sensitive personal information. No limitation is necessary as we do not use sensitive information for secondary purposes.

CPRA §1798.121

Right to Non-Discrimination

Data subjects have the right not to receive discriminatory treatment for exercising their privacy rights.

CCPA §1798.125 • CPRA

Right to Data Portability

Data subjects have the right to receive their personal information in a structured, commonly used, machine-readable format.

GDPR Art. 20 • CPRA

Right to Appeal

Data subjects have the right to appeal any denial of their privacy rights requests.

CPRA §1798.130

How to Exercise Your Rights

To exercise your data subject rights, please submit a verifiable request through one of our designated methods:

We will respond to verifiable requests within 45 days (extendable by an additional 45 days with notice).

13

Data Breach Notification

In the event of a personal data breach, SOBS Pets has implemented the following procedures:

1

Detection & Containment

Immediately upon discovery, our security team initiates containment procedures to stop the breach and prevent further unauthorized access.

2

Assessment & Investigation

We assess the scope, nature, and impact of the breach, including categories of affected individuals, types of data involved, and probable consequences.

3

Notification

We notify affected individuals, relevant supervisory authorities, and other stakeholders as required by applicable law, without undue delay.

4

Remediation

We implement measures to address the breach and prevent future occurrences, including updates to policies, procedures, and technical controls.

Notification Timeline

  • Affected individuals: As soon as practicable, but no later than as required by applicable state laws (typically within 45 days of discovery).
  • California residents: In compliance with Cal. Civ. Code §1798.82, without unreasonable delay.
  • Other US states: In accordance with each state's specific data breach notification laws.
Suspected Breach Reporting:

If you suspect a data breach involving your personal information, please contact our security team immediately at security@sobspets.com.

14

Audit & Accountability

SOBS Pets maintains accountability for its data processing activities through the following measures:

Internal Audits

Quarterly internal audits of our data processing activities, security controls, and compliance with privacy policies.

Third-Party Audits

Annual independent third-party security assessments and penetration testing. SOC 2 Type II audit in progress.

Documentation

Maintenance of records of processing activities, data protection impact assessments, and lawful basis documentation.

Compliance Monitoring

Continuous monitoring of legal and regulatory developments to ensure ongoing compliance.

Customer Audit Rights

SOBS Pets does not currently offer individual customer audit rights due to the multi-tenant nature of our services and the confidentiality of our security practices. However, we provide:

  • Annual SOC 2 Type II reports upon request (when available)
  • PCI DSS Attestation of Compliance
  • Security summaries and certifications

For enterprise customers requiring additional audit rights, please contact our legal department to discuss specific arrangements.

15

Sub-Processor Engagement

Our authorized processors may engage sub-processors to assist in providing services. All sub-processors are subject to:

  • Written contract imposing the same data protection obligations as in our processor agreements
  • Requirement to implement appropriate technical and organizational security measures
  • Prohibition on engaging further sub-processors without prior authorization

Sub-Processor Notification & Objection

We maintain a current list of sub-processors on this page. If you are a customer, you may subscribe to notifications of sub-processor changes by emailing privacy@sobspets.com. You have the right to object to new sub-processors on reasonable grounds relating to data protection. If you object and we cannot provide a reasonable alternative, you may terminate your contract.

A complete and current list of sub-processors is available upon request by contacting privacy@sobspets.com.
16

Confidentiality

All SOBS Pets personnel with access to personal information are subject to strict confidentiality obligations:

  • Signed confidentiality agreements as a condition of employment
  • Annual data protection and security training
  • Access granted only on a need-to-know basis
  • Disciplinary actions for unauthorized access or disclosure
  • Confidentiality obligations survive termination of employment
We treat all personal information as confidential and do not disclose it except as described in our Privacy Policy or as required by law.
17

Liability & Indemnification

SOBS Pets accepts liability for our processing of personal information in accordance with applicable privacy laws. Our liability for data protection claims is subject to the limitation of liability provisions in our Terms of Service.

Data Protection Liability

  • We are liable for damages caused by our processing where we have failed to comply with our obligations under applicable privacy laws.
  • We are liable for the actions of our processors who act on our instructions.
  • We do not limit our liability for gross negligence, willful misconduct, or violations of law that cannot be limited by contract.

Indemnification

To the extent permitted by applicable law, you agree to indemnify and hold SOBS Pets harmless from any claims, damages, losses, liabilities, costs, and expenses arising out of or related to your violation of these terms or applicable law regarding your use of our services.

18
Privacy Inquiries privacy@sobspets.com General privacy questions, data subject requests
Security Team security@sobspets.com Vulnerability reporting, security incidents
Legal Department legal@sobspets.com DPA requests, legal process, compliance
Our DPO and privacy team aim to respond to all inquiries within 2 business days.

Lawful Processing Commitment

SOBS Pets is committed to processing personal information lawfully, fairly, and transparently. This Data Processing Agreement demonstrates our accountability and dedication to protecting your privacy rights.

Welcome to the S.O.B.S. Family!

Thank you for subscribing. Please check your email to verify your subscription and access exclusive content.

exit();