Terms of service
Effective date: 5 August 2026
Version 1.0
PLEASE READ THESE TERMS CAREFULLY.
These Terms govern the supply of the PetFlow HQ software platform by Education AI Group Co., Ltd. to a pet-care business. They are a business-to-business agreement. By creating a venue account, activating Live Mode, signing an Order, or otherwise using the Platform, the Venue agrees to them.
These Terms do not govern the relationship between a Venue and its own customers. A Venue contracts with its customers on the Venue's own terms and under the Venue's own privacy notice. Education AI Group is not a party to that contract. Clause 9 sets out, in itemised terms, what the Venue must tell its own customers about our involvement — including matters the Venue's customers cannot learn from any document we publish.
A Thai-language version of these Terms and of the PetFlow HQ Privacy Policy is issued alongside the English version. Clause 35.10 states which version governs which subject matter.
1. Who we are
1.1 PetFlow HQ is a software product brand operated by Education AI Group Co., Ltd. ("Education AI Group", "PetFlow HQ", "we", "us" or "our"), a company incorporated in Thailand with company registration number 0845568020186 and registered office at 2/1 Moo 6, Bophut, Ko Samui, Surat Thani, Thailand.
1.2 PetFlow HQ is management software for pet-care businesses. It is supplied as a hosted service comprising: the Venue's public website; a customer portal used by the Venue's own customers; a staff workspace; and the Venue's back office at app.petflowhq.com. We also operate an internal operator panel used by our own personnel to administer, support and maintain the service.
1.3 What is Venue-branded and what is not. The content of the Venue's public website, customer portal, documents and customer messages is presented under the Venue's own name and branding. However:
(a) transactional and notification email is sent by us, on the Venue's behalf, from a PetFlow HQ sending address and under our sending domain and signing keys, with the Venue's name in the message content;
(b) account, sign-in, password-reset and email-confirmation pages and the emails that carry them are ours, are hosted on PetFlow HQ domains and are sent from our authentication system; and
(c) while an account is in the Master Merchant State (clause 14), the payment descriptor shown to an End Customer is that of our master merchant account and not necessarily the Venue's trading name.
We therefore do have a technical channel to the Venue's End Customers. We do not use it to market to them, to contact them on our own account, or to hold ourselves out to them as the provider of the Venue's services, and clause 32 makes that a binding covenant. Clause 9.2 requires the Venue to disclose the matters in this clause 1.3 in its own privacy notice and customer terms.
1.4 There is no PetFlow HQ mobile application. The Platform is delivered through a web browser.
2. Definitions
In these Terms:
"Agreement" means these Terms, the Schedules to them, and the Order.
"Authorised User" means an individual to whom the Venue grants a named login to the Platform, including the Venue's owners, managers, staff and contractors.
"Business Day" means a day other than a Saturday, Sunday or public holiday in Thailand.
"Committed Change" means a change to the Platform listed in the table at clause 21.4.
"Confidential Information" has the meaning given in clause 18.1.
"Data Processing Schedule" means Schedule 1, which is the data processing agreement required by section 40 of the PDPA and governs our processing of personal data on the Venue's behalf.
"Documentation" means the user documentation and functional descriptions we make available for the Platform, and any written statement of functionality or capability given to the Venue before the Order was signed and annexed to the Order.
"End Customer" means a customer of the Venue, and any member of that customer's household, whose details are recorded in the Platform by or for the Venue.
"Fees" means the amounts payable by the Venue under clause 15 and the Order.
"Group" means, in relation to the Venue, the Venue and any company that controls it, is controlled by it, or is under common control with it, and any other entity identified as part of the Venue's group in the Order.
"Initial Term" means the initial subscription term stated in the Order.
"Live Mode" means the state of a venue account after activation under clause 7.3.
"Master Merchant State" means the payment configuration described in clause 14.2, in which charges are made on Education AI Group's own Omise merchant account.
"Order" means the written order form or subscription agreement, signed by both parties, under which the Venue subscribes to the Platform, together with any schedule annexed to it.
"PDPA" means the Personal Data Protection Act B.E. 2562 (2019) of Thailand.
"Platform" means the PetFlow HQ software service described in clause 1.2, together with petflowhq.com, app.petflowhq.com, and our support channels.
"Sub-merchant State" means the payment configuration described in clause 14.3, in which the Venue holds its own Omise merchant account.
"Sub-processor" means a third party engaged by us to process personal data on the Venue's behalf, as listed in clause 16.1 and in Annex 2 to Schedule 1.
"Test Mode" means the pre-activation setup state of a venue account, described in clause 7.
"Venue", "you" or "your" means the pet-care business that subscribes to the Platform, being our customer under this Agreement, and (for the purposes of the licence in clause 8 and the confidentiality obligations in clause 18) each member of its Group identified in the Order.
"Venue Data" means all data, content and records entered into, uploaded to or generated within the Venue's tenant on the Platform by the Venue, its Authorised Users or its End Customers, including End Customer records, animal records, health, behaviour and incident records, bookings, care records, documents, waivers, website content and configuration, and financial records.
"Venue Funds" means amounts collected from End Customers through the Platform in the Master Merchant State and not yet settled to the Venue.
3. Acceptance, electronic agreement and the Order
3.1 By accepting these Terms, creating a venue account or using the Platform, the person doing so confirms that they have read, understood and agree to be bound by these Terms and the Schedules to them, and that they have authority to bind the Venue. That person's acceptance binds the Venue.
3.2 Acceptance by conduct is limited. Creating an account, activating Live Mode or using the Platform binds the Venue to these Terms and the Schedules as published at that time. It does not bind the Venue to any Fee, rate, term length, service level, tenancy model or other commercial term unless that term is set out in an Order signed by both parties. No Fee is payable, and no minimum term applies, before an Order is signed.
3.3 These Terms and the Schedules contain no blank, bracketed or unresolved term. Every period, cap, rate mechanism and notice period they contain is fixed. Where a matter is left to the Order, clause 3.2 applies to it.
3.4 Acceptance may be recorded electronically. The Venue agrees that electronic records, confirmations, notices, click-through acceptances and communications may be used as evidence of the Venue's use of the Platform and of its acceptance of this Agreement, to the extent permitted by applicable law, including under the Electronic Transactions Act B.E. 2544 (2001).
3.5 Additional terms may apply to particular features, payment methods or integrations. Where they do, they will be presented before the relevant feature is enabled, and they do not vary this Agreement unless clause 33 is followed.
4. Documents forming the Agreement, and order of precedence
4.1 The Agreement comprises, in descending order of precedence:
(a) the Order, including any specification or functionality schedule annexed to it;
(b) Schedule 1 (Data Processing Schedule), which prevails on all matters concerning the processing of personal data;
(c) these Terms;
(d) Schedule 2 (Data Export Schedule) and Schedule 3 (Security Measures).
4.2 The Data Processing Schedule is annexed, not referenced. Schedule 1 in the form set out at the end of this document is the data processing agreement between the parties. No other version applies. Nothing in this Agreement incorporates by reference a data-protection document that has not been supplied to the Venue. If the Venue's own data-protection agreement is executed instead, it prevails only to the extent expressly agreed by us in writing.
4.3 The Privacy Policy is informational. The PetFlow HQ Privacy Policy explains our processing as controller. It is not a contract document, does not form part of this Agreement, and cannot vary it. Where the Privacy Policy and this Agreement differ on a period, figure or commitment, this Agreement governs, and we will correct the Privacy Policy.
4.4 Where there is a conflict, the higher-ranking document prevails, but only to the extent of the conflict and only on the subject matter it governs.
5. Our role
5.1 We supply software. We are a software provider only, save in respect of payment collection in the Master Merchant State, which clause 14 describes.
5.2 The Venue is solely the provider of pet-care services to its End Customers. The Venue contracts with its End Customers on the Venue's own terms of service and under the Venue's own privacy notice. We are not a party to any such contract and are not the provider of the Venue's services.
5.3 We do not board, day-care, walk, groom, train, transport, supervise, feed, medicate, examine, insure or otherwise handle any animal. We make no veterinary, behavioural or animal-welfare judgement of any kind. Any assessment, flag, alert, reminder or report generated by the Platform is a presentation of information the Venue has recorded, and is not advice. That does not relieve us of responsibility for storing, retaining, retrieving, displaying and alerting on that information as designed; clauses 29.6 and 30.6 allocate that risk.
5.4 Where the Platform processes a payment, sends a message on the Venue's behalf, produces a document, or assists with a refund, it does so as a tool operated on the Venue's instruction, and — in the Master Merchant State — as collection agent and merchant of record for the underlying transaction as described in clause 14.2.
5.5 We do not provide legal, tax, accounting, veterinary or insurance advice. Where we make a template document available, including the template customer privacy notice and template customer terms described in clause 9.2(f), we give no advice on and no assurance of its adequacy.
6. The venue account, Authorised Users and security
6.1 The Venue must nominate a responsible person who holds authority to act for the Venue, and must provide accurate, current and complete account information, including the Venue's legal name, trading name, company registration number, tax identification number, addresses, and the responsible person's name, date of birth, email address and telephone number. Clause 7.4 explains why the date of birth is required.
6.2 The Venue must keep that information up to date and must notify us promptly of any change to the responsible person.
6.3 Each Authorised User must have their own individual login. Credentials must not be shared, transferred, sold or rented, and a single login must not be used by more than one individual. The Venue is responsible for assigning appropriate permission levels and for removing access promptly when an Authorised User leaves or changes role.
6.4 Age of Authorised Users. The contracting party under this Agreement is the Venue, not the individual Authorised User. There is no minimum age for holding an Authorised User login. The Venue is responsible for its Authorised Users' use of the Platform regardless of their age, and for complying with employment and child-labour law in its own jurisdiction. The rules on the personal data of minors are dealt with separately at clause 9.11.
6.5 Responsibility for account activity. The Venue is responsible for activity carried out through its account and for the acts and omissions of its Authorised Users as if they were its own. The Venue is not responsible for unauthorised activity to the extent that it results from:
(a) a failure, defect, misconfiguration or vulnerability in the Platform or in a Sub-processor's systems;
(b) an act or omission of our personnel, including access through the operator panel; or
(c) a credential exposure caused by us.
The Venue must notify us of known or suspected unauthorised use within 5 Business Days of becoming aware of it. Failure to do so limits the Venue's protection under this clause only to the extent the delay increased the loss.
6.6 We may request reasonable information and documentation to verify the Venue's identity, business registration, ownership, the authority of the responsible person, payment details, and compliance with this Agreement. We may decline to activate or continue an account where verification is not completed.
6.7 The Venue must not create an account using false details, impersonate another person or business, or exceed any user, tenant or volume limit stated in the Order.
7. Test Mode, Live Mode and activation
7.1 Test Mode is a setup state, not a technical control. A venue account starts in Test Mode. Test Mode is a status recorded against the account. It is presently a self-declared state that we do not technically enforce: the Platform does not today refuse a payment, a payment-terminal provisioning request, an accounting posting, an invoice, a receipt or a tax document on the ground that an account is in Test Mode. The Venue must not take a real payment from an End Customer, and must not issue an invoice, receipt or other tax document, before activation under clause 7.3, and is contractually responsible for observing that restriction. We will introduce technical enforcement on the payment and document paths by the date stated in clause 21.4.
7.2 Real records may be entered during setup. The Venue may enter real End Customer and animal records, and may import its existing customer list, during Test Mode. That is how the Platform is designed to be set up. Records created in Test Mode are retained on activation and are not wiped, reset or migrated away. We will not delete or reset Venue Data created in Test Mode without the Venue's written instruction, except for sample or demonstration data that we clearly label as such and that the Venue asks us to remove.
7.3 Activation. To move to Live Mode, the Venue must:
(a) complete its account profile in full, including the responsible person's date of birth;
(b) supply a URL for its own customer-facing privacy notice and a URL for its own customer terms of service, which we will render on the Venue's public site, the customer portal and every Venue-branded collection form under clause 9.2(e);
(c) confirm in writing that its privacy notice covers each item itemised in clause 9.2(c), including the QuickBooks disclosure at clause 9.2(c)(iv) and the payment-collection and email disclosures at clause 9.2(c)(v) and (vi);
(d) confirm that it has a mechanism for obtaining the explicit consent required by clause 9.4 for health, behaviour and incident data;
(e) complete our payment onboarding under clause 14 where payment processing is enabled; and
(f) have a signed Order in place.
We may require further verification before activating Live Mode.
7.4 The responsible person's date of birth is a mandatory field. It is collected to activate Live Mode, to satisfy the customer due-diligence requirements applying to accounts through which payments are processed, to evidence legal capacity to contract, and for fraud prevention and accountability for the person behind a trading account. It is not collected on the basis of consent, and the account cannot trade without it. Retention of that data is described in Schedule 1.
7.5 Return to Test Mode. We may return an account to Test Mode where verification lapses, where information proves inaccurate, or where our payment provider requires it. A return to Test Mode:
(a) does not permit us to wipe, reset or reduce any warranty in respect of Venue Data created while the account was in Live Mode;
(b) preserves the Venue's full read access to, and export rights over, all Venue Data; and
(c) is subject to clause 24 as if it were a suspension of payment processing.
8. Licence to use the Platform
8.1 Subject to this Agreement and to payment of the Fees, we grant the Venue a limited, non-exclusive, non-transferable, non-sublicensable licence, during the term, to access and use the Platform through its Authorised Users for the internal business purposes of the Venue and its Group, being the operation of their own pet-care businesses.
8.2 Multi-site and multi-entity use is permitted. Use across all sites, trading entities and companies within the Venue's Group is within the licence. Where the Venue operates a franchise model, a management company that runs the back office for two or more trading entities, or a group structure with a separate company per site, the tenancy, user and Fee model for that structure is agreed in the Order. Adding a site or a Group company is not a breach of clause 8.3(a) or clause 17.1(h).
8.3 The licence does not permit the Venue to:
(a) use the Platform to operate the business of an undertaking outside its Group, or to provide a service bureau, managed service or outsourced service to a third party outside its Group;
(b) resell, sublicense, rent, lease or distribute the Platform to a third party outside its Group;
(c) copy, modify, translate, adapt, decompile, disassemble or reverse engineer any part of the Platform, or create a derivative work of it, except to the extent that applicable law expressly permits this notwithstanding this restriction;
(d) remove, obscure or alter any proprietary notice; or
(e) use our Confidential Information to build, train or market a product or service that competes with the Platform. This paragraph does not prevent the Venue from evaluating, procuring, commissioning or building software for its own business, from comparing the Platform with alternatives, or from describing its own experience of the Platform.
8.4 Except for the licence expressly granted in clause 8.1, no rights in the Platform are granted to the Venue.
9. Venue obligations
9.1 Its own customers. The Venue is solely responsible for its relationship with its End Customers, including service delivery, pricing, availability, communications, complaints, disputes, cancellations and refunds.
9.2 Its own terms and privacy notice.
(a) The Venue must publish and maintain its own customer terms of service and its own privacy notice, and must give its End Customers the information required by section 23 of the PDPA prior to or at the time of collection.
(b) The Venue must supply the URL of each document to us as a condition of activation under clause 7.3(b), and must keep both URLs current.
(c) The Venue's privacy notice must state, as a minimum:
(i) that the Venue is the controller, with its identity and contact details, and the purposes and lawful bases for each category of data it records, including animal health data, behaviour and bite-history data, and incident records;
(ii) that Education AI Group Co., Ltd. (trading as PetFlow HQ) processes that data on the Venue's behalf as processor, and the identity, purpose and country of each Sub-processor listed in clause 16.1;
(iii) the retention periods the Venue actually applies, which — unless the Venue has instructed otherwise in writing — are the Platform defaults recorded in clause 26.6, including a ten-year default retention for incident reports and five years for payment and accounting records, and the deletion timetable in clause 26.4;
(iv) the QuickBooks disclosure: that invoices, receipts and related financial documents bearing the End Customer's name are transmitted to Education AI Group Co., Ltd. and to Intuit Inc. in the United States; that Education AI Group holds those entries as a controller in its own right for its own statutory accounting purposes; that they are retained for at least five years and up to seven years under the Accounting Act B.E. 2543 (2000) and the Revenue Code; and that those entries are not deleted when the Venue's account closes;
(v) the payment disclosure: while the account is in the Master Merchant State, that payment is collected by Education AI Group Co., Ltd. as merchant of record on the Venue's behalf, that the card statement descriptor is ours, and that card data is handled by Omise (Opn) and never stored by the Venue or by PetFlow HQ;
(vi) the email and account disclosure: that transactional and notification email is sent by Education AI Group on the Venue's behalf from a PetFlow HQ address using Resend (United States), and that customer-portal account, sign-in and password pages and emails are operated by Education AI Group on PetFlow HQ domains;
(vii) that anonymised and aggregated statistics are derived from the records, on the Venue's documented instruction, for the purposes described in clause 10.3;
(viii) the cross-border transfers described in Annex 2 to Schedule 1 and the safeguards applied;
(ix) the End Customer's rights under sections 30 to 36 of the PDPA, how to exercise them, the 30-day statutory response period, and the right to complain to the Personal Data Protection Committee Office; and
(x) the cookie information required by clause 9.9.
(d) The Venue's customer terms of service must be consistent with clause 9.2(c)(v) as to who collects payment.
(e) What we do. We will render the Venue's privacy-notice link and customer-terms link on the Venue's public site, on the customer portal registration screen, and on every Venue-branded form through which End Customer or animal data is collected, at or before the point of collection, by the date stated in clause 21.4 and, from activation, on the surfaces on which that rendering is already available.
(f) The template. Until the Venue supplies its own documents, the Platform renders a template customer privacy notice and template customer terms that we have written, and the customer registration flow requires acceptance of them. Those templates are supplied for the Venue's convenience only. The Venue adopts them as its own documents, remains the controller and the contracting party, must review them and keep them accurate, and must amend them so that they contain the items in clause 9.2(c). We give no advice on and no assurance of their adequacy, and the Venue's obligation under clause 9.2(a) is not discharged by leaving a template in place unreviewed.
9.3 Lawful basis. The Venue must hold a lawful basis under the PDPA for every category of personal data it records in the Platform. Our provision of a field, form or module is not advice that the Venue may lawfully use it.
9.4 Explicit consent for sensitive data — must be standalone. For health data, and for any incident record describing injury to a person, the Venue must obtain explicit consent under section 26 of the PDPA or establish an applicable statutory exemption. That consent must be:
(a) requested in a standalone, separately presented form, clearly separated from the Venue's terms of service, registration terms, booking flow and waiver;
(b) expressed in clear, plain, easily accessible and readable language, per category of data;
(c) recorded with the date and time given, the identity of the person giving it, and the version of the wording used; and
(d) withdrawable as easily as it was given, with the consequences of withdrawal notified at the time consent is requested.
Consent bundled into terms of service, registration terms or a signed waiver will not satisfy section 19 paragraphs 2 and 3 of the PDPA. We will provide the per-category consent record and one-click withdrawal described in clause 21.4 by the date stated there; until then the Venue must obtain and hold that consent using its own separately presented forms and attach the record to the customer file in the Platform.
9.5 Animal welfare and safety. The Venue is solely responsible for the care, welfare, health, supervision, handling, housing, feeding, medication, transport and safety of every animal in its care, and for the safety of its staff, its End Customers and any third party at its premises. The Venue must maintain its own operational, safety, hygiene and emergency procedures independently of the Platform, and must not rely on the Platform as its only safety control.
9.6 Accuracy of records. The Venue is responsible for the accuracy, completeness, currency and lawfulness of the Venue Data it enters, including vaccination records and expiry dates, medication and dosage details, veterinary contacts, allergies, feeding instructions, behaviour flags, bite history and incident reports. We do not verify, validate or audit the content of Venue Data. This clause allocates to the Venue the risk of data entered incorrectly; it does not allocate to the Venue the risk of data the Platform failed to store, retain, retrieve, display or alert on as designed, which is dealt with at clauses 29.6 and 30.6.
9.7 Staff and access. The Venue must ensure its Authorised Users are trained in the use of the Platform, are bound by appropriate confidentiality obligations, and are granted only the permissions their role requires. The Venue must operate a prompt offboarding process.
9.8 Legal compliance. The Venue must comply with all laws applicable to its business, including animal-welfare, licensing, premises, employment, health-and-safety, consumer-protection, advertising, tax, accounting and data-protection law, and must hold all licences, registrations, permissions and consents its operations require.
9.9 Cookies on Venue-branded surfaces. On the Venue's public site and customer portal we set only strictly necessary cookies and equivalent storage: session and authentication tokens, security and anti-abuse tokens, and load-balancing identifiers set by Cloudflare. We do not set analytics, advertising or profiling cookies on those surfaces. The Venue must describe those cookies in its privacy notice. If the Venue adds any third-party tag, pixel, analytics or advertising script to its site, the Venue is responsible for obtaining any consent required for it. We will not introduce a non-essential cookie on a Venue-branded surface without first providing a configurable consent control and giving notice under clause 33.
9.10 Complaints, refunds and taxes. The Venue must handle its End Customers' complaints, disputes and refund requests fairly, promptly and in accordance with its own published terms and applicable law. The Venue is responsible for determining, declaring, collecting, reporting and paying all taxes and charges arising from its own business and its own receipts, including VAT, withholding tax and income tax, subject to clause 15.7.
9.11 Minors — section 20 of the PDPA. Where a data subject recorded in the Platform is a minor:
(a) if the minor is not sui juris and cannot give valid consent alone under section 19, consent must be given by the holder of parental responsibility who is entitled to act on the minor's behalf, or jointly with the minor, as section 20 requires; and
(b) if the minor is under 10 years of age, consent must in every case be obtained from the holder of parental responsibility.
The Venue captures and holds that consent record. It must be recorded against the customer or household record in the Platform, identifying the minor, the consenting adult, the date and the scope of consent, and must be retained for as long as the underlying record. This applies to any child recorded as a member of an End Customer's household, as a person present at a booking, or as a person named in an incident report.
9.12 Its own data-protection obligations. The Venue is a controller under the PDPA and carries the controller's obligations, including records of processing under section 39, responding to data-subject requests within the statutory period, and notifying the Personal Data Protection Committee Office of a personal-data breach within 72 hours under section 37(4) where required. Whether the Venue must appoint a data protection officer under section 41 is a matter for the Venue and its own advisers.
10. Venue Data: ownership and use
10.1 The Venue owns its data. As between the Venue and us, the Venue retains all right, title and interest in Venue Data. Nothing in this Agreement transfers ownership of Venue Data to us.
10.2 The Venue grants us a non-exclusive, worldwide, royalty-free licence to host, store, copy, transmit, display, back up and otherwise process Venue Data solely to the extent necessary to provide, secure, support and maintain the Platform for the Venue, to comply with law, and as otherwise instructed by the Venue. This licence is limited to those purposes, binds any assignee under clause 35.4, and ends in accordance with clause 26.
10.3 Aggregated and anonymised data.
(a) The Venue instructs us, as a documented processing instruction recorded in Annex 1 to Schedule 1, to derive aggregated and anonymised statistics from Venue Data. The derivation step operates on identifiable Venue Data and is performed on that instruction; it is not processing outside instruction for the purposes of section 40(1) of the PDPA.
(b) Once irreversibly aggregated or anonymised, we may use the resulting statistics to operate, secure, analyse and improve the Platform and to produce industry-level insights.
(c) Aggregation must be irreversible, so that neither the Venue, an Authorised User, an End Customer, a household member nor an animal can be identified from the output, alone or in combination with other information available to us. We will not attempt to re-identify it and will not publish or disclose it in a form that identifies the Venue without the Venue's written consent.
(d) Reciprocity. Where we produce benchmark or industry insight outputs derived in part from the Venue's data, we will make the same outputs available to the Venue at no charge.
(e) The Venue may withdraw the instruction in paragraph (a) at any time by written notice, in which case we will exclude the Venue's tenant from the derivation. Withdrawal does not affect outputs already produced.
10.4 Model training — prohibited. We will not use Venue Data, including End Customer personal data, animal records, incident records, images or documents, to train, fine-tune, evaluate or benchmark any machine-learning or artificial-intelligence model, and will not permit a Sub-processor to do so. This prohibition may be lifted only by the Venue's prior written opt-in, given per purpose and per model, and revocable. There is no notice-and-continue mechanism: silence, continued use, or a change to a published policy does not lift it.
10.5 The Venue warrants that it holds all rights necessary to provide Venue Data to us and that Venue Data does not breach any law or infringe the rights of any person. We may remove, restrict or disable content where we reasonably believe it is unlawful, infringing, or creates a safety, security or legal risk, and will tell the Venue where we lawfully can.
11. Data protection
11.1 In relation to End Customer, household and animal-linked personal data recorded in the Platform, the Venue is the controller and we are the processor. The Venue decides why and how that data is processed. We process it on the Venue's documented instructions, which are set out in Annex 1 to Schedule 1.
11.2 We are a controller in our own right only in respect of: the Venue's business and account details; the responsible person's contact details and date of birth; Authorised User accounts; billing and fee records; support correspondence; product telemetry; security records and audit logs; and our own statutory accounting records, including the ledger entries described in clause 16.4 which contain End Customer names.
11.3 Schedule 1 governs our processing as processor and prevails over these Terms on that subject. It records our documented instructions, the categories of data and data subjects, the named Sub-processors and the authorisation and objection process for them, cross-border transfers and the mechanism used for each destination, breach notification, assistance with data-subject requests, audit and documentation, and return and deletion on termination.
11.4 Breach notification — 24 hours from awareness.
(a) Where we become aware of, or reasonably suspect, a personal-data breach affecting Venue Data, we will notify the Venue without undue delay and in any event within 24 hours of becoming aware, whether or not the breach has by then been confirmed. The clock runs from awareness, not from confirmation or completion of an investigation. A suspected breach is notified on the same clock and updated as the investigation develops.
(b) The notification will contain, so far as known at the time and updated as it becomes known: the nature of the breach; the categories and approximate number of data subjects and records affected; whether the Venue's tenant is affected; the cause; the likely consequences; the containment and remediation measures taken and proposed; and a contact point. It will be in a form the Venue can file with the Personal Data Protection Committee Office without a second round-trip.
(c) We will preserve all logs, records and evidence relevant to the breach for at least three years and will make them available to the Venue and, at the Venue's direction, to its advisers and to the Personal Data Protection Committee Office.
(d) Where the breach arose from our act, omission or systems, we will bear the Venue's reasonable and documented costs of notifying the Personal Data Protection Committee Office and affected data subjects, including printing, postage, call-handling and reasonable external advice. This obligation sits outside the cap in clause 30.3 up to a maximum of THB 1,000,000 and within the cap in clause 30.4 above that.
(e) The same 24-hour figure appears in Schedule 1 and in the Privacy Policy. If any document states a different figure, 24 hours governs.
11.5 Data-subject requests from End Customers.
(a) An End Customer request that reaches support@petflowhq.com will be forwarded to the Venue within 3 Business Days, and we will tell the requester the date on which it was forwarded and that the Venue is the controller who will answer it.
(b) The Venue must respond as controller within the period fixed by the PDPA, which is 30 days from receipt of the request under sections 30, 31, 32, 33, 34, 35 and 36, subject to any permitted extension.
(c) We will provide the assistance and tooling described in Schedule 1, and will perform data-subject request actions on the Venue's written instruction under clause 26.5 where self-service tooling is not yet available.
(d) Fallback where the Venue does not respond. Where the Venue's account has been terminated, the Venue has ceased to trade, or the Venue has not responded within 30 days of our forwarding a request, we will answer the requester directly in respect of the records for which we are controller under clause 11.2 — in particular the accounting entries described in clause 16.4 and our security and access logs — and will tell the requester the identity and last known contact details of the controller that holds the remaining records.
11.6 Operator access log.
(a) We log each occasion on which our own personnel access a Venue's tenant, recording the identity of the operator, the time, the tenant, and the reason or ticket reference.
(b) The Venue may obtain the operator-access log for its own tenant on request, at any time, at no charge, in a machine-readable format, within 5 Business Days.
(c) Access to a tenant that is not initiated by a support request from that Venue is a break-glass access. Break-glass access requires an authorised approver, a recorded reason, and the narrowest scope necessary. We will notify the Venue of each break-glass access within 2 Business Days, with the reason and the scope of data accessed, unless a law or a live security investigation prevents it, in which case we will notify as soon as we lawfully can.
(d) Operator-access records are retained for 3 years, notwithstanding the shorter retention that applies to general technical logs.
11.7 Any limit of liability in clause 30 allocates risk between the Venue and us only. It does not limit, and cannot limit, a data subject's statutory rights or remedies under the PDPA, including under sections 77 and 78.
12. Security and tenant separation
12.1 Measures. We apply the technical, organisational and administrative measures set out in Schedule 3, which is mapped to the categories required by the Notification of the Personal Data Protection Committee on Security Measures of the Data Controller B.E. 2565 (2022). Schedule 3 forms part of this Agreement and may not be reduced without the Venue's agreement under clause 33.
12.2 Tenant separation warranty. We warrant that, in the application database and file storage used by the Platform:
(a) every record containing Venue Data is scoped to a single tenant;
(b) access is enforced at the database layer by row-level security policies, so that a query executed with one tenant's credentials cannot return another tenant's rows, and no application query path exists that bypasses that enforcement;
(c) role-based permissions further restrict access within a tenant; and
(d) operator access is separately gated and logged under clause 11.6.
We test cross-tenant isolation, including automated tests exercised on each release, and will provide the Venue with a summary of the most recent test results on request. Breach of this warranty is subject to the separate cap in clause 30.5.
12.3 The isolation disclaimer is limited to the accounting system. The statement that Venue records are not held in an environment separate from that of other customers applies only to the shared QuickBooks company described in clause 16.4. It does not apply to the application database, file storage, backups or any other part of the Platform.
12.4 What the Venue does. The Venue is responsible for credential hygiene and password strength; enabling and enforcing any multi-factor authentication we make available; assigning and reviewing Authorised User permissions; prompt offboarding; the security of the devices, networks and browsers its Authorised Users use; controlling who can physically see a screen showing End Customer data; and the accuracy and lawfulness of what it enters.
12.5 Assurance available to the Venue.
(a) We hold no security certification, accreditation or third-party audit attestation today, and we do not claim one.
(b) We will commission an independent penetration test at least annually, the first to be completed by the date in clause 21.4, and will share the executive summary and the remediation status with the Venue on request.
(c) We will respond to a written security questionnaire from the Venue within 20 Business Days.
(d) The Venue may appoint an independent auditor, bound by confidentiality and not a competitor of ours, to audit the systems and records used to process the Venue's data, once in any 12-month period and on 30 days' notice, or at any time following a personal-data breach affecting the Venue. The Venue bears the auditor's cost unless the audit identifies a material breach of this Agreement or of Schedule 3, in which case we bear it.
(e) For the shared QuickBooks company, where inspection is not possible because the file contains other venues' records, we will instead provide an independent accountant's written report on the access controls in place, on request and at our cost, once in any 12-month period.
12.6 No online service can guarantee absolute security.
13. Backup, restore and continuity
13.1 Backups. We take backups of the application database and file storage at least daily, encrypted at rest, retained for 30 days, and stored separately from the primary environment. Backups are not accessed except for disaster recovery, restore requests and integrity testing.
13.2 Recovery objectives. Our recovery point objective is 24 hours and our recovery time objective is 48 hours for a total loss of the primary environment. We test restoration at least annually and will share a summary of the test result with the Venue on request.
13.3 Restore on request. The Venue may request a restore, including a restore of data deleted or corrupted in error by its own staff, at any time within 30 days of the loss. We will use reasonable efforts to restore to the nearest available recovery point. A restore is at no charge where the loss was caused by us, by the Platform or by a Sub-processor; otherwise a reasonable charge, not exceeding THB 5,000 per restore, may apply.
13.4 Continuity snapshots. At the Venue's request we will deliver a monthly full encrypted export of the Venue's data, in the formats set out in Schedule 2, to storage the Venue nominates and controls, at no charge.
13.5 Insolvency and supplier failure.
(a) We will notify the Venue immediately, and in any event within 2 Business Days, of: any insolvency event affecting us, including a petition, resolution, moratorium or appointment of a receiver, administrator or liquidator; any cessation or proposed cessation of trading; and the loss, termination or material degradation of any Sub-processor listed in clause 16.1 that we cannot replace without interruption.
(b) On any such event the Venue may terminate this Agreement immediately by written notice, take an immediate full export under Schedule 2, and recover Fees paid in advance for the unused part of the current period.
(c) Clauses 13.4, 13.5, 14.5 (Venue Funds held on trust) and 26 (export and deletion) survive termination and are expressed to bind any receiver, administrator, liquidator, successor or assignee.
14. Payment processing and the handling of Venue funds
14.1 Two states. Payment processing operates in one of two states, which differ in who is the merchant of record and who receives the money. Every new venue account starts, and remains until we promote it, in the Master Merchant State.
14.2 Master Merchant State — this is the default.
(a) Charges are made on Education AI Group's own Omise (Opn) merchant account. Card and PromptPay payments are supported.
(b) Education AI Group is the merchant of record for those transactions and collects the payment from the End Customer as the Venue's collection agent. The card statement descriptor shown to the End Customer is ours.
(c) The money reaches us first. Funds settle into our Omise balance and our bank account, and are paid to the Venue later as a netted payout under clause 15.
(d) The Venue does not have an Omise merchant account in this state and is not onboarded with Omise. Our onboarding form is our form, not Omise's, and completing it creates nothing at Omise.
(e) The Venue remains the supplier of the underlying pet-care services, and remains responsible for the service supplied, for what it charges, and for its own pricing, VAT, invoicing and receipting obligations in respect of its own supply.
14.3 Sub-merchant State. Where we promote a Venue to the Sub-merchant State and the Venue holds its own Omise merchant account, the Venue is the merchant of record, is bound by Omise's merchant terms and the applicable card-scheme rules, and receives settlement directly from Omise. Promotion is at our discretion and is presently an operator-initiated step; no Venue is in this state at the date of these Terms. We will tell the Venue in writing which state its account is in at activation and on any change.
14.4 Card details. Card details are held by Omise and are never stored by PetFlow HQ. The Platform stores a payment-method reference only.
14.5 Venue Funds are held on trust.
(a) Venue Funds are received by us for the account of the Venue, are held on trust for the Venue, are not our property, are not available to our creditors, and do not form part of our estate on insolvency.
(b) We will hold Venue Funds separately from our own funds in a designated account, and will complete segregation into a designated client account by the date stated in clause 21.4. Until then we record Venue Funds as a distinct liability owing to the Venue in the finance ledger and will identify the balance to the Venue on request.
(c) We will tell the Venue the balance of its Venue Funds within 2 Business Days of a written request.
14.6 Refunds. Refunds are the Venue's decision, made under the Venue's own published policy and applicable law. A refund is funded from Venue Funds or from amounts otherwise due to the Venue, and reduces the amount settled in the cycle in which it is made. Where Venue Funds are insufficient, we will invoice the Venue under clause 15.4. We administer the mechanics only.
14.7 Chargebacks and disputed transactions. A chargeback, reversal or disputed transaction arising on a payment we collected is dealt with case by case, in writing, at the time. We do not operate an automatic deduction, negative-balance or reserve mechanism, and no such mechanism applies to the Venue unless and until it is built, notified under clause 33 and agreed in the Order. Where a chargeback is ultimately borne by the Venue, we will provide the underlying transaction evidence and reasonable assistance in defending it.
14.8 Payment-provider requirements. We may act on an instruction, restriction or requirement imposed by Omise or a card scheme, including suspending processing or requiring further information, subject to clause 24. The Venue must not use the Platform for any business category prohibited by the payment provider or the card schemes.
14.9 Currency conversion. Where currency conversion applies, the End Customer's card issuer, bank or payment provider applies its own exchange rate and charges. We are not responsible for those charges.
15. Fees, settlement and taxes
15.1 What the Venue pays. The Venue pays a subscription fee, a percentage of payments processed for it through the Platform, or both, at the rates stated in the Order. No rate binds the Venue unless it is stated in a signed Order (clause 3.2).
15.2 Settlement cycle — stated here, not deferred. In the Master Merchant State:
(a) a settlement invoice is raised for each Venue at 00:15 Asia/Bangkok time on the first day of each calendar month, in respect of the preceding calendar month;
(b) the amount settled is the gross payments we collected for the Venue in that month, less the payment provider's charges, less refunds made in that month, less the Fees due for that month; and
(c) the transfer is initiated approximately 3 Business Days after the invoice is raised.
Settlement runs are presently initiated manually by us on that cycle rather than by an automated scheduler. If we change the cycle we will give notice under clause 33.
15.3 Netting authority. The Venue authorises us to net the amounts in clause 15.2(b) from Venue Funds before settlement. That authority extends to those amounts only. It does not extend to set-off against any amount the Venue disputes in good faith and has notified in writing, and it does not extend to a reserve, holdback or negative-balance recovery.
15.4 Invoicing and card on file.
(a) Where Venue Funds are insufficient to cover the Fees, or where the Venue does not use payment processing, we will invoice the Venue. Invoices are payable within 30 days of the invoice date.
(b) Continuous payment authority. Where the Venue stores a payment card in the Platform for the payment of Fees, the Venue authorises us to charge that card on a recurring basis for Fees and other amounts properly due under this Agreement, on or after the due date, having given the Venue at least 3 Business Days' notice of the amount and date of each charge. The Venue may withdraw this authority at any time in writing, in which case clause 15.4(a) applies. We will not charge the card for a disputed amount.
15.5 Holds and withholding. We may withhold, delay or adjust a settlement only where reasonably required to deal with a refund, a suspected fraud, a legal or tax obligation, a technical error, or a payment-provider requirement, and subject to the following, which are conditions of the right:
(a) we will give the Venue written reasons within 3 Business Days of the hold;
(b) no hold may exceed 10 Business Days unless we give further written reasons and a date for release, and the Venue may escalate under clause 34.2 at any time;
(c) the amount held must not exceed the amount reasonably in issue;
(d) we will pay interest at 1% per month on any amount later shown to have been withheld without proper cause; and
(e) we may not suspend the account under clause 24.1(a) for non-payment while we hold Venue Funds exceeding the amount in dispute.
15.6 Taxes. Fees are stated exclusive of VAT and other applicable taxes, which are added where due. Each party is responsible for its own income and business taxes.
15.7 Withholding tax — resolved.
(a) Where we invoice the Venue, the Venue withholds Thai withholding tax on the service fee at the applicable rate, pays us the net amount, and delivers a valid withholding tax certificate within the period required by law. We will accept that certificate in satisfaction of the withheld amount.
(b) Where Fees are netted from settlement under clause 15.2, the Venue makes no payment from which it can withhold. In that case we treat the netted Fee as a gross amount, calculate the withholding on it, account for and remit the withholding to the Revenue Department for the Venue's account, and issue the Venue the withholding tax certificate and supporting statement it needs for its own filings, within the period required by law. We indemnify the Venue against any withholding tax, surcharge, fine or penalty assessed on the Venue that arises from the netting mechanism or from our failure to perform this paragraph. That indemnity is not subject to the cap in clause 30.3.
(c) The Venue must not deduct any amount from the Fees other than a deduction required by law. Nothing in this Agreement prevents or penalises a lawful statutory withholding.
15.8 Late payment. We may charge interest on undisputed overdue amounts at 1% per month, or the maximum permitted by law if lower.
15.9 Currency. Fees are charged in Thai Baht unless the Order states otherwise.
15.10 Fee changes.
(a) Fees are fixed for the Initial Term and may not be increased during it.
(b) After the Initial Term, we may increase Fees once in any 12-month period, on not less than 90 days' written notice, by no more than the lower of (i) the increase in the Thailand consumer price index published by the Ministry of Commerce over the preceding 12 months, and (ii) 5%.
(c) The percentage-of-payments Fee may not be increased at all during the Initial Term, and thereafter may not be increased by more than 0.25 percentage points in any 12-month period, subject to the same 90 days' notice.
(d) Any increase beyond paragraphs (b) or (c) requires the Venue's written agreement under clause 33.2.
(e) Pass-through charges. Where a payment provider or card scheme increases the charges we pass through to the Venue, we will notify the Venue as soon as we are notified. If the increase is material, the Venue may terminate under clause 25.2(c) with a pro-rata refund, on the same basis as for a Fee increase.
(f) If the Venue does not accept a change permitted by this clause, it may terminate under clause 25.2(c) by notice given before the change takes effect, and the existing Fees apply until termination.
16. Third-party services and Sub-processors
16.1 The Platform depends on the following third parties. This table is the Sub-processor list for the purposes of Schedule 1.
| Provider | Purpose | Data | Country |
|---|---|---|---|
| Supabase | Application database, authentication and file storage | All Venue Data, including End Customer, animal, health, behaviour and incident records | Hosting region as notified in the Order; Supabase Inc. is a United States company and administrative access may occur from the United States |
| Omise (Opn) | Card and PromptPay payment processing | Cardholder and transaction data; payment-method references | Thailand; group operations in Japan and Singapore |
| Resend | Transactional and notification email delivery | End Customer and Authorised User email addresses, subject lines and message content, including customer names, animal names, booking references, amounts and payment status | United States |
| Intuit QuickBooks | Accounting, invoicing and financial records | Invoice, receipt and ledger entries including End Customer names | United States |
| Cloudflare | DNS, content delivery and security | IP addresses, request metadata, security tokens | United States; global edge network |
16.2 Each provider operates under its own terms and privacy policy. We are not responsible for a third-party service's content, availability, acts or omissions, save for our own contractual obligations to the Venue in respect of Sub-processors under Schedule 1 and save that clause 35.6 (force majeure) does not excuse a Sub-processor failure.
16.3 Changes to the list in clause 16.1 are notified at least 30 days in advance and may be objected to under paragraph 6 of Schedule 1.
16.4 QuickBooks — disclosure and conditions.
(a) The design. Venue invoices, receipts and related financial documents, which include End Customer names, are written into a single QuickBooks company operated by Education AI Group, with venues distinguished by the QuickBooks Location field. Location is a reporting dimension and not an access boundary: a person with access to that company file can see records relating to more than one venue, including venues that may compete with one another.
(b) Current status — stated in the correct tense. At the date of these Terms, accounting posting operates against a test (sandbox) company only. No production connection exists, no Venue document has been posted to a production QuickBooks company, and Education AI Group's own company file has not been connected. The arrangement described in paragraph (a) is the design that will apply when posting moves to production. We will give the Venue at least 30 days' written notice before any Venue document is posted to a production QuickBooks company, and the Venue may object under paragraph 6 of Schedule 1 before that happens.
(c) Access control. Access to the QuickBooks company is limited to a named list of individuals — our finance personnel and our external accountants and bookkeepers. We will provide that list to the Venue on request and will notify the Venue of a change to it. The number of individuals with access will not exceed ten without notice to the Venue.
(d) Confidentiality undertakings enforceable by the Venue. We will obtain from each external accountant and bookkeeper with access a written confidentiality undertaking, expressed for the benefit of each Venue and enforceable by the Venue directly under section 374 of the Civil and Commercial Code, and will provide a copy on request.
(e) Restriction on use. Neither we nor any person with access may use venue-identifying information in that company file for the benefit of another venue, for our own commercial purposes beyond operating and accounting for the Platform, or for any benchmarking or competitive purpose. Clause 32 applies to it.
(f) Migration commitment. We will migrate to per-venue QuickBooks companies or per-venue sub-accounts, so that no venue's records are visible to a person accessing another venue's records, by 31 December 2027. If we miss that date by more than 30 days, the Venue may terminate under clause 25.2(c) with a pro-rata refund and the exit assistance in clause 25.7.
(g) Controller status and retention. The same ledger entries are also our own statutory accounting records, for which we are controller. They are retained for the periods in clause 26.5(a) and are not deleted when the Venue's account closes. The Venue must disclose this to its End Customers under clause 9.2(c)(iv).
(h) Liability. Breach of this clause 16.4 is subject to the separate cap in clause 30.5.
16.5 The Venue should read this clause before activating Live Mode.
17. Acceptable use
17.1 The Venue must not, and must not permit any Authorised User or third party to:
(a) break the law, infringe intellectual property rights, breach privacy or data-protection law, commit fraud, send unlawful marketing, or mislead any person;
(b) harass, threaten, abuse, discriminate against or endanger any person;
(c) upload malware, attempt to gain unauthorised access to the Platform or any system connected to it, interfere with its security, or disrupt its operation;
(d) attempt to access, view, extract or interfere with the tenant, data, configuration or records of any other venue, or with our operator panel or any administrative function not made available to the Venue;
(e) scrape, crawl or extract data or content from the Platform by automated means without our written permission, except that the Venue may extract its own Venue Data by any means at any time;
(f) reverse engineer, decompile or circumvent technical restrictions, except as clause 8.3(c) permits;
(g) exceed any user, tenant, storage or volume limit agreed in the Order;
(h) resell, sublicense or provide the Platform as a service bureau to a business outside the Venue's Group, or operate an unrelated business's operations on the account;
(i) use our Confidential Information to develop or assist a product that competes with the Platform, subject to the same qualification as clause 8.3(e); or
(j) upload or record content that is unlawful, defamatory, deceptive, infringing or otherwise inappropriate.
17.2 The Venue must not take a real payment from an End Customer or issue an invoice, receipt or other tax document before activation under clause 7.3. Entering real End Customer and animal records during Test Mode is permitted (clause 7.2).
18. Confidentiality
18.1 "Confidential Information" means non-public information disclosed by one party to the other that is identified as confidential or would reasonably be understood to be confidential. Ours includes non-public product information, roadmaps, pricing not publicly listed, security documentation and support materials. The Venue's includes Venue Data, its commercial terms, its customer lists, its pricing and its business records.
18.2 Each party must keep the other's Confidential Information confidential, use it only for the purposes of this Agreement, and disclose it only to personnel and advisers who need it and who are bound by equivalent obligations.
18.3 The QuickBooks exception. The disclosure of Venue invoice and receipt data within the shared QuickBooks company described in clause 16.4 is a permitted disclosure of the Venue's Confidential Information, but only for so long as every condition in clauses 16.4(c) to (f) is satisfied. If any of those conditions ceases to be satisfied, the disclosure is not permitted and clause 18.2 applies to it without qualification.
18.4 These obligations do not apply to information that is or becomes public without breach, was already lawfully known, is independently developed, or is required to be disclosed by law, a court or a regulator — in which case the disclosing party must, where lawful, give prompt notice.
18.5 These obligations survive termination for 5 years, and indefinitely in respect of personal data, which is also governed by Schedule 1.
19. Support
19.1 Support is provided by email to support@petflowhq.com and through any in-Platform support channel we make available.
19.2 We give no response-time or resolution-time commitment. We aim to respond promptly during Thai business hours, but no service level is offered or implied, and none may be inferred from past response times. Any service level must be expressly agreed in writing in the Order, and the Venue should not assume one exists.
19.3 We will keep the Venue informed during a material unplanned outage under clause 20.3.
20. Availability, maintenance and changes to the Platform
20.1 We aim to keep the Platform available and accurate, but it is provided on an "as is" and "as available" basis, subject to clause 21.
20.2 No uptime commitment. We give no uptime target, no availability commitment and no service credits. We do not warrant uninterrupted availability or that the Platform will meet the Venue's particular requirements. A Venue that requires a service level must agree one in the Order. The Venue should assess this before making the Platform operationally critical to its business.
20.3 What we do commit to.
(a) Planned maintenance that we expect to interrupt service will be notified at least 5 Business Days in advance and, wherever practicable, carried out between 00:00 and 05:00 Asia/Bangkok time.
(b) Unplanned outage. During a material unplanned outage we will publish status updates and keep the Venue informed of cause, progress and expected restoration, and will provide a written summary within 5 Business Days of restoration.
(c) Fee abatement. Where the Platform is materially unavailable for more than 8 consecutive hours, or for more than 24 hours in aggregate in a calendar month, the subscription Fee abates pro rata for the period of unavailability. Abatement is credited against the next invoice or settlement.
(d) Termination for repeated or extended outage. The Venue may terminate under clause 25.2(c), with a pro-rata refund and the exit assistance in clause 25.7, where the Platform is materially unavailable for a single continuous period exceeding 24 hours, or where fee abatement under paragraph (c) has been triggered in each of 3 consecutive months.
20.4 Changes to features. We may change, improve or discontinue features where reasonably necessary for operational, security, legal, technical or commercial reasons. Where we withdraw a material feature the Venue is actively using, we will give at least 60 days' notice, and if the withdrawal is materially adverse to the Venue, the Venue may terminate under clause 25.2(c).
20.5 Beta features. Features labelled beta, preview, trial or early access are supplied as-is, may be changed or withdrawn without notice, carry no warranty and no support commitment, and should not be relied upon for critical operations. Clause 21 does not apply to them.
21. Warranty, correction of defects and committed changes
21.1 Conformity warranty. We warrant that the Platform will materially conform to the Documentation and to the functionality described in the Order. This warranty is not disclaimed by clause 29 and is not excluded by clause 20.1.
21.2 Remedy for non-conformity. If the Platform does not materially conform, the Venue may notify us in writing. We will correct the non-conformity within 30 days of that notice, or within a longer period the parties agree in writing. If we do not, the Venue may terminate under clause 25.2(c) and recover the Fees paid for the affected part of the service for the period in which it did not conform.
21.3 Correction of defects. We will use reasonable efforts to correct material defects, and will prioritise by severity, treating as highest priority any defect that causes loss, corruption, non-retrieval or non-display of animal health, medication, behaviour, bite-history or incident data, or that prevents the Venue from operating a booking, check-in or medication workflow. We will keep the Venue informed of the status of a reported defect of that kind at least weekly until it is resolved.
21.4 Committed changes. We commit to make the following changes by the dates stated. Each date is a contractual commitment, not a forecast.
| Committed Change | By |
|---|---|
| Rendering of the Venue's own privacy-notice and customer-terms links on every Venue-branded collection surface and portal registration screen (clause 9.2(e)) | 31 October 2026 |
| Technical enforcement of Live Mode on the payment, terminal, accounting and document paths, failing closed where the mode is not set (clause 7.1) | 31 October 2026 |
| Per-category explicit-consent record with timestamp and wording version, and one-click withdrawal that flags the affected records to the Venue (clause 9.4) | 31 December 2026 |
| Self-service structured export of all data categories in Schedule 2, from the back office (clause 26.1) | 31 December 2026 |
| Read-only account mode, for graduated suspension and for the post-termination export window (clauses 24.2 and 26.3) | 31 December 2026 |
| First independent penetration test completed and executive summary available (clause 12.5(b)) | 31 December 2026 |
| Designated segregated client account for Venue Funds (clause 14.5(b)) | 31 December 2026 |
| Professional indemnity and cyber liability insurance in place (clause 27.2) | 31 December 2026 |
| Venue-configurable retention settings in the back office (clause 26.6) | 30 June 2027 |
| Migration to per-venue QuickBooks companies or sub-accounts (clause 16.4(f)) | 31 December 2027 |
If a Committed Change is more than 30 days late, the Venue may terminate under clause 25.2(c), with a pro-rata refund and the exit assistance in clause 25.7.
21.5 We do not claim what we have not built. Where this Agreement describes a capability as a Committed Change, that capability does not exist today, and the Venue must not rely on it before the stated date.
22. Intellectual property, domain names and DNS
22.1 The Platform, including our software, source code, designs, interfaces, branding, trademarks, service marks, logos, text, graphics, documentation and other proprietary materials, is owned by or licensed to Education AI Group and is protected by applicable intellectual property laws. All rights not expressly granted are reserved.
22.2 The Venue retains all rights in Venue Data and in its own name, branding and marks. The Venue grants us a licence to use its name, logo and brand assets solely to configure, host and display the Venue's own Platform surfaces and communications.
22.3 Domain names and DNS.
(a) The Venue owns its domain name and all DNS records for it. Where we register or hold a domain, or hold DNS control through Cloudflare, we do so as bare agent for the Venue and acquire no interest in it.
(b) We will transfer or release the domain registration, the authorisation code and full DNS control to the Venue or its nominee within 5 Business Days of a written request, at any time, including during a suspension and after termination, and without charge.
(c) The Venue's website content, images, copy, page structure and site configuration are Venue Data and form part of the standard export under Schedule 2.
22.4 Feedback. If the Venue gives us suggestions or feedback about the Platform, we may use them without restriction, attribution, confidentiality obligation or payment. This does not give us any right to Venue Data.
23. Term and renewal
23.1 This Agreement starts when the Venue first accepts it and continues for the Initial Term stated in the Order, or, if none is stated, on a rolling monthly basis.
23.2 Unless the Order says otherwise, the subscription renews automatically for successive periods of the same length. Either party may prevent renewal by giving written notice not less than 30 days before the end of the current period.
23.3 Fees already paid for a period are non-refundable except where clause 25 provides for a refund or where the law requires otherwise.
24. Suspension
24.1 Grounds. We may suspend or restrict access to the Platform, in whole or in part, where:
(a) undisputed Fees are overdue and remain unpaid after written notice;
(b) there is a material security risk, suspected compromise of an account, or suspected fraud;
(c) continued operation would expose us or the Venue to a legal or regulatory risk;
(d) our payment provider or a card scheme requires it;
(e) the Venue is in material breach of clause 17; or
(f) we are required to do so by law.
24.2 Measures available. Suspending a venue account affects End Customers who have bookings in place and animals in the Venue's care. We will act proportionately and use the least disruptive measure available. The measures available today are:
(a) restricting or disabling an individual Authorised User; and
(b) disabling payment processing.
A read-only account mode does not exist today. It will be available by the date in clause 21.4, and from then it must be used in preference to withdrawing access altogether. Until then, we will not withdraw the Venue's access to the Platform under clause 24.1(a) or (e) without first giving 10 Business Days' written notice and an opportunity to remedy.
24.3 Protections.
(a) Wherever practicable we will give prior notice and an opportunity to remedy, and we will always tell the Venue the reason unless the law prevents us.
(b) The Venue's export rights under clause 26 and Schedule 2 continue in full during any suspension.
(c) No suspension for a disputed invoice. We may not suspend or terminate for non-payment where the Venue has paid the undisputed portion and has raised the dispute in writing, pending completion of the escalation in clause 34.2.
(d) No suspension while we hold the Venue's money. We may not suspend under clause 24.1(a) while we hold Venue Funds exceeding the amount in dispute.
(e) Fee abatement. Fees abate for any period of suspension that is not caused by the Venue's proven breach.
(f) Unjustified suspension. Where a suspension is later shown to have been unjustified, we will reinstate immediately, refund all Fees for the period of suspension, and credit an additional amount equal to those Fees.
(g) Maximum duration. If a suspension continues for more than 30 days, the Venue may terminate under clause 25.2(c) with a pro-rata refund, a full export and the exit assistance in clause 25.7.
(h) We will lift a suspension promptly once its cause is resolved.
25. Termination
25.1 Either party may terminate as set out in this clause. Termination rights elsewhere in this Agreement (clauses 13.5, 20.3(d), 21.2, 21.4, 24.3(g), 33.3 and 35.4) are exercised as terminations under clause 25.2(c).
25.2 Termination by the Venue. The Venue may terminate:
(a) for convenience, on 30 days' written notice, effective at the end of the then-current billing period, with no refund of Fees already paid unless the Order says otherwise;
(b) immediately, if we are in material breach and have not remedied it within 30 days of written notice; or
(c) without penalty, in any of the cases identified in clause 25.1 or on a Fee or pass-through increase under clause 15.10, a materially adverse feature withdrawal under clause 20.4, a materially adverse change under clause 33, a Sub-processor objection that cannot be resolved under Schedule 1, or a change of control under clause 35.4 — in which case we will refund Fees paid in advance for the unused part of the current period.
25.3 Termination by us. We may terminate this Agreement:
(a) immediately, if the Venue is in material breach and has not remedied it within 30 days of written notice;
(b) if undisputed Fees remain unpaid 30 days after a written reminder, subject to clause 24.3(c) and (d);
(c) immediately, if the Venue becomes insolvent, enters liquidation, has a receiver appointed or ceases to trade;
(d) immediately, if required by law or by our payment provider; or
(e) for convenience, on 6 months' written notice, with a pro-rata refund of Fees paid in advance and the exit assistance in clause 25.7. We may not terminate for convenience during the Initial Term.
25.4 Effect of termination. On termination, the licence in clause 8 ends, access to the Platform ends at the end of the export window in clause 26.3, and all Fees accrued to the date of termination become due.
25.5 Survival. Termination does not affect accrued rights or any provision that by its nature should survive, including clauses 2, 10, 11, 12.5, 13.4, 13.5, 14.5, 15.7, 18, 22.3, 25.7, 26, 29, 30, 31, 32, 34 and 35, and Schedules 1 and 2.
25.6 Fees paid in advance. Where this Agreement provides for a pro-rata refund, we will pay it within 30 days of termination, together with the balance of any Venue Funds we hold.
25.7 Exit assistance. Where clause 25.2(c) or clause 25.3(e) applies, we will, at our own cost:
(a) agree a written migration plan with the Venue within 15 Business Days of the notice;
(b) deliver the Venue's data in the formats set out in Schedule 2, including all binary attachments, as often as the Venue reasonably requests during the notice period and the export window;
(c) maintain the Venue's access to the Platform on the existing terms for the remainder of the notice period and for the export window;
(d) co-operate reasonably with the Venue's replacement supplier, including answering schema and mapping questions, for up to 20 hours at no charge; and
(e) where we terminated for convenience under clause 25.3(e), reimburse the Venue's reasonable and documented migration costs up to an amount equal to 12 months' Fees.
26. Export and deletion of Venue Data
26.1 During the term. The Venue may obtain a full export of its Venue Data at any time, covering every category and format listed in Schedule 2. The Venue may request an export in writing and we will deliver it within 10 Business Days, at no charge. Self-service export tools do not exist in the back office today; they will be available by the date in clause 21.4, after which the Venue may export at any time without asking us. The finance report download presently available in the back office is not an export for the purposes of this clause.
26.2 Charges. A standard export under Schedule 2 is free of charge, however often it is requested. A charge may apply only to a genuinely non-standard export — one that requires bespoke transformation, a format not listed in Schedule 2, or reconstruction of data not held — and any such charge must be quoted and agreed in advance and may not exceed THB 20,000.
26.3 Export window after termination. For 90 days after termination or expiry, the Venue may continue to obtain exports under clause 26.1, and we will maintain the Venue's data intact throughout. From the date in clause 21.4 the account will also remain accessible in read-only mode during that window. Export rights also continue in full during any suspension.
26.4 Deletion — one set of figures. After the export window closes, we will delete or irreversibly anonymise Venue Data held in live systems within 60 days. Copies held in encrypted backups are overwritten on the ordinary backup rotation cycle, which is 90 days, during which they are not accessed except for disaster recovery. The same figures — 60 days for live systems and 90 days for backups — are stated in Schedule 1 and in the Privacy Policy. If any document states a different figure, this clause governs. We will provide a written certificate of deletion, covering live systems and backups with the dates on which each was completed, on request.
26.5 How deletion is performed today, and statutory carve-outs.
(a) Deletion and anonymisation are performed manually by us on the Venue's written instruction. There is no self-service tenant, customer or animal deletion or anonymisation function in the back office today. We will act on a written deletion or anonymisation instruction from the Venue within 30 days, and will confirm in writing what was deleted. Venue-configurable retention and deletion tooling is a Committed Change (clause 21.4).
(b) Clause 26.4 does not apply to:
(i) accounting records, invoices, receipts and transaction records, including entries in the QuickBooks company described in clause 16.4, which we must retain as our own statutory accounting records for at least five years under the Accounting Act B.E. 2543 (2000), extendable to seven years at the direction of the Director-General, and for the periods required by the Revenue Code. We are controller of those records for that purpose, and they are not deleted when the Venue's account closes;
(ii) records reasonably required to establish, exercise or defend a legal claim, or to comply with a legal or regulatory obligation or a lawful request;
(iii) operator-access records retained for 3 years under clause 11.6(d) and breach evidence retained under clause 11.4(c); and
(iv) aggregated and anonymised data produced under clause 10.3, which contains no personal data.
26.6 Retention defaults during the term.
(a) The following are our defaults, applied by us. There is no retention configuration screen in the back office today; the Venue may change a default by written instruction and we will apply it. Configurable retention is a Committed Change (clause 21.4).
(b) Defaults: incident reports involving injury to a person — 10 years, reflecting the prescription periods in section 448 of the Civil and Commercial Code; payment, invoice and accounting records — 5 years; other End Customer and animal records — for the life of the account and the periods in clause 26.4 thereafter.
(c) Log retention. Operator-access records are retained for 3 years (clause 11.6(d)). General audit logs and technical and security logs are retained for as long as they are needed for security, accountability and the investigation of incidents, and are then deleted. We do not today operate an automated log-purge schedule, and we do not claim a fixed log-deletion period beyond the operator-access commitment.
(d) The Venue should not shorten the 10-year incident-report default without advice, and must state the periods it actually applies in its own privacy notice under clause 9.2(c)(iii).
26.7 This clause is to be read consistently with Schedule 1. If they conflict, Schedule 1 prevails, and no figure in Schedule 1 differs from a figure in this clause.
27. Insurance
27.1 The Venue. The Venue must hold and maintain, at its own cost, insurance appropriate to its business, including public liability and, where available and appropriate, professional or care, custody and control cover for the animals in its care. We do not insure the Venue, its premises, its staff, its End Customers or any animal, and the Platform is not a substitute for insurance.
27.2 Us. We will maintain, from the date stated in clause 21.4 and for the term and for 3 years afterwards, professional indemnity insurance and cyber and data-breach liability insurance with a limit of indemnity of not less than THB 10,000,000 in the aggregate. We will provide a certificate of currency on request, not more than once a year, and will notify the Venue if the cover lapses, is cancelled or is materially reduced.
28. Publicity
We will not use the Venue's name, logo or a description of its business in our marketing, on our website or in a case study without the Venue's prior written consent. Consent is sought separately, in a standalone written request at the time we wish to use the material. It is not sought or given at account creation, and it is not bundled into acceptance of these Terms. Consent may be withdrawn on 30 days' written notice, after which we will remove the material from our own channels.
29. Disclaimers
29.1 Subject to clause 21 and to the warranties expressly given in clauses 12.2 and 21.1, and to the maximum extent permitted by law, the Platform is provided without warranty of any kind, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, accuracy or non-infringement.
29.2 We do not warrant that the Platform will be uninterrupted, secure or error-free.
29.3 We do not warrant that Venue Data entered by the Venue is accurate, complete or lawfully held.
29.4 We do not warrant that the Platform will prevent, detect or mitigate any risk to an animal or a person, except to the extent that a risk materialises because of a defect, failure or error in the Platform — including a failure to store, retain, retrieve, display or alert on data as designed and as described in the Documentation.
29.5 Nothing in this Agreement excludes or limits liability that cannot lawfully be excluded or limited, including liability for fraud, wilful misconduct, gross negligence, or death or personal injury where liability cannot be excluded under applicable law.
29.6 The line between Venue risk and Platform risk. Data that the Venue or its End Customer entered incorrectly, incompletely or late is the Venue's risk. Data that the Platform failed to store, retain, retrieve, display, transmit or alert on as designed is our risk. Every exclusion and limitation in clauses 29 to 31 is to be read subject to that distinction.
30. Limitation of liability
30.1 Excluded loss. To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, punitive or consequential loss, loss of profits, loss of revenue, loss of opportunity, loss of goodwill or loss of anticipated savings arising from or connected with this Agreement or the Platform.
30.2 What is not excluded. Clause 30.1 does not exclude, and the following are recoverable as direct loss:
(a) the Venue's reasonable costs of recovering, reconstructing, re-keying or re-collecting Venue Data that has been lost, corrupted, wrongly deleted or rendered unusable;
(b) the Venue's reasonable costs of procuring a substitute service, including migration and implementation costs, following our material breach; and
(c) the Venue's reasonable costs of notifying regulators and data subjects, to the extent clause 11.4(d) applies.
30.3 Mutual cap. Subject to clauses 30.4 to 30.6, neither party's total aggregate liability to the other for all claims arising from or connected with this Agreement will exceed the greater of (a) the total Fees paid or payable under this Agreement in the 12 months immediately preceding the first event giving rise to the claim, and (b) THB 2,000,000.
30.4 Data-protection super-cap. Our total aggregate liability for claims arising from a breach by us of Schedule 1 or of our obligations as processor under the PDPA will not exceed the greater of (a) two times the Fees paid in the preceding 12 months, and (b) THB 5,000,000. This is a separate cap and is not aggregated with clause 30.3.
30.5 Confidentiality and cross-tenant super-cap. Our total aggregate liability for (a) breach of clause 18 (confidentiality), (b) breach of the tenant-separation warranty in clause 12.2, (c) disclosure of Venue Data to another venue, and (d) breach of clause 16.4 or clause 32, will not exceed the greater of (i) three times the Fees paid in the preceding 12 months, and (ii) THB 5,000,000. This is a separate cap and is not aggregated with clauses 30.3 or 30.4.
30.6 Uncapped and excluded matters. No cap in this clause applies to: the Venue's obligation to pay Fees and other amounts properly due; either party's liability for fraud, fraudulent misrepresentation or wilful misconduct; our indemnity for withholding tax under clause 15.7(b); our intellectual-property indemnity under clause 31.5; or any liability that cannot lawfully be limited.
30.7 Exclusions of our liability, subject to the defect carve-out. We are not liable for loss arising from the Venue's own services, its handling or care of any animal, an incident at its premises, a decision made by the Venue or its staff, the inaccuracy or incompleteness of Venue Data entered by the Venue, the Venue's failure to publish its own terms or privacy notice or to hold a lawful basis, or the act or omission of an End Customer — in each case except to the extent that the loss was caused or contributed to by a defect, failure or error in the Platform, including a failure to store, retain, retrieve, display or alert on data as designed.
30.8 Third-party services. We are not liable for the failure, act or omission of a third-party service listed in clause 16.1, except to the extent of our own obligations in respect of Sub-processors under Schedule 1 and except that clause 35.6 does not treat such a failure as force majeure.
30.9 Evidence and burden of proof. Where a claim turns on what the Platform stored, displayed, alerted on or transmitted, we will preserve and disclose to the Venue the relevant system logs, records and configuration history, promptly and at our own cost, and will not delete them while the claim is live. If those logs are unavailable because we failed to preserve or produce them, it is presumed, unless we prove otherwise, that the Platform did not store, display, alert on or transmit the data as designed.
30.10 As stated in clause 11.7, these caps allocate risk between the Venue and us. They do not limit a data subject's statutory claim under the PDPA, including the punitive damages available under section 78.
30.11 Each party must take reasonable steps to mitigate its loss.
31. Indemnities
31.1 The Venue's indemnity. Subject to clauses 31.2 to 31.4, the Venue will indemnify Education AI Group, its directors, employees, contractors and agents against claims, losses, liabilities, damages, fines, costs and expenses (including reasonable legal costs) arising out of:
(a) a claim by an End Customer, a member of an End Customer's household, a third party or a member of the Venue's staff arising from the Venue's own services, its handling, care or supervision of any animal, an incident at its premises, or injury to a person or animal — except to the extent that the claim was caused or contributed to by a defect, failure or error in the Platform;
(b) the Venue's failure to publish or comply with its own customer terms or privacy notice, or to give the information required by section 23 of the PDPA and itemised in clause 9.2(c);
(c) the Venue's failure to hold a lawful basis under the PDPA, or the explicit consent required by clause 9.4, or the parental consent required by clause 9.11;
(d) the Venue's breach of this Agreement or of applicable law, including animal-welfare, licensing, employment, tax or consumer-protection law;
(e) Venue Data entered by the Venue, including its inaccuracy, unlawfulness or infringement of a third party's rights; and
(f) an administrative fine or order imposed on us by the Personal Data Protection Committee to the extent it results from the Venue's instruction, act or omission.
31.2 The indemnity is capped. The Venue's total aggregate liability under clause 31.1 is subject to the cap in clause 30.3. It is not carved out of that cap.
31.3 Conduct of an indemnified claim. As a condition of the indemnity in clause 31.1, we must:
(a) give the Venue prompt written notice of the claim, and in any event within 10 Business Days of becoming aware of it;
(b) allow the Venue to assume conduct of the defence and settlement, with counsel of the Venue's choice, and provide reasonable assistance at the Venue's cost;
(c) make no admission of liability and enter into no settlement without the Venue's prior written consent; and
(d) take reasonable steps to mitigate the loss.
31.4 Reduction. The amount recoverable under clause 31.1 is reduced proportionately to the extent that our act, omission, negligence, breach of this Agreement, breach of law, or a defect in the Platform caused or contributed to the claim.
31.5 Our intellectual-property indemnity. We will indemnify the Venue against a third-party claim that the Platform, as supplied by us and used in accordance with this Agreement, infringes that third party's intellectual property rights, provided the Venue notifies us promptly, allows us to conduct the defence with the Venue's reasonable co-operation, and makes no admission without our consent. We may, at our option, procure the right to continue use, modify the Platform to make it non-infringing, or terminate the affected part of the service with a pro-rata refund and the exit assistance in clause 25.7. This indemnity does not apply to a claim arising from Venue Data, from the Venue's branding, from use in breach of this Agreement, or from combination with anything not supplied by us.
31.6 Our data-protection indemnity. We will indemnify the Venue against an administrative fine or order imposed on the Venue by the Personal Data Protection Committee, and against a data subject's claim under sections 77 or 78 of the PDPA, to the extent it results from our breach of Schedule 1 or our processing outside the Venue's documented instructions. This indemnity is subject to the cap in clause 30.4.
32. Non-solicitation and non-competition
32.1 We covenant that neither we, nor any of our affiliates, nor any assignee or successor under clause 35.4, will:
(a) contact, market to, solicit or attempt to solicit any End Customer of the Venue, other than to send a message on the Venue's own instruction as part of the service, or to answer a data-subject request under clause 11.5;
(b) use Venue Data, or any insight or model derived from it, to launch, operate or promote a consumer-facing pet-care booking, marketplace or discovery service;
(c) disclose venue-identifying data, pricing, customer lists or performance information to another venue, or use it for the benefit of another venue; or
(d) use Venue Data to compete with the Venue in the supply of pet-care services.
32.2 This covenant survives termination, binds any person to whom this Agreement or the business is assigned or transferred, and is enforceable in addition to clause 18. Breach is subject to the separate cap in clause 30.5.
32.3 The Venue is entitled to the benefit of clause 10.3(d) (access to benchmarks derived from its own data).
33. Changes to this Agreement
33.1 Non-material changes. We may amend this Agreement on not less than 60 days' written notice by email to the account address and by notice in the back office, stating the effective date. Continued use after the effective date constitutes acceptance of a non-material change.
33.2 Materially adverse changes require agreement. A change that is materially adverse to the Venue — including any change to Fees beyond clause 15.10, to liability, to an indemnity, to the export or deletion provisions, to Schedule 1, Schedule 2 or Schedule 3, to the tenant-separation warranty, or to clause 32 — takes effect only with the Venue's positive written agreement. Silence, continued use and continued payment do not constitute agreement to such a change.
33.3 If the Venue does not agree. Where we propose a materially adverse change and the Venue does not agree, either party may terminate on 60 days' notice, in which case the Venue receives a pro-rata refund of Fees paid in advance, the exit assistance in clause 25.7 at our cost, and continued service on the existing terms for a transition period of not less than 90 days from the date of the notice.
33.4 Schedule 1 cannot be varied unilaterally. Schedule 1 may be amended only by written agreement between the parties, save that we may add or replace a Sub-processor under the notice and objection procedure in paragraph 6 of Schedule 1. The processing terms are not varied by republication of any web page.
33.5 The Privacy Policy is informational (clause 4.3). A change to it does not vary this Agreement, and a commitment in this Agreement cannot be reduced by a change to it.
34. Governing law and disputes
34.1 This Agreement is governed by the laws of the Kingdom of Thailand.
34.2 Before bringing a formal claim, each party agrees to notify the other in writing — for us, at support@petflowhq.com — and to give a reasonable opportunity, of at least 30 days, to resolve the matter through good-faith discussion between senior representatives. This clause does not prevent either party from seeking urgent injunctive relief.
34.3 The courts of Thailand have exclusive jurisdiction over any dispute arising out of or in connection with this Agreement or the Platform.
35. General
35.1 Entire agreement. The documents listed in clause 4.1 constitute the entire agreement between the parties on their subject matter. This clause does not exclude, and the Venue may rely on: the specification and functionality description in the Order; the Documentation; and any written statement of functionality or capability given to the Venue during the sales process and annexed to the Order. Nothing in this clause limits liability for fraud, fraudulent misrepresentation or negligent misrepresentation.
35.2 Severability. If any provision is found unenforceable, the remaining provisions remain in effect and the provision concerned will be enforced to the greatest extent legally possible.
35.3 Waiver. No waiver is effective unless in writing. A failure or delay in enforcing a right is not a waiver of it.
35.4 Assignment and change of control.
(a) Neither party may assign or transfer its rights or obligations without the other's written consent, not to be unreasonably withheld, except to a successor of its business on notice.
(b) We will give the Venue written notice of any change of control of Education AI Group, or of any assignment or transfer of this Agreement or of the PetFlow HQ business, before it takes effect where lawfully possible and in any event within 5 Business Days.
(c) The Venue may terminate under clause 25.2(c), with a full assisted export under clause 25.7 and a pro-rata refund, by notice given within 60 days of that notice.
(d) We may not assign or transfer this Agreement, or transfer Venue Data, to a person who competes with the Venue in the supply of pet-care services or who operates a consumer-facing pet-care booking or marketplace service, without the Venue's prior written consent.
(e) Any assignee takes subject to clauses 10.2, 10.4, 13.5(c), 18 and 32.
35.5 No partnership. Nothing in this Agreement creates a partnership, joint venture, employment, franchise or agency relationship, except that clause 14.2(b) appoints us as collection agent for the limited purpose stated there. Neither party may otherwise bind the other.
35.6 Force majeure. Neither party is liable for a failure or delay in performance caused by an event beyond its reasonable control, including natural disaster, flood, fire, epidemic, war, civil unrest, act of government, strike, or failure of a public utility or telecommunications network. The failure, outage, degradation or withdrawal of a Sub-processor listed in clause 16.1 is not force majeure, because we select and contract with those providers. Force majeure does not excuse an obligation to pay money already earned, but the subscription Fee abates from the first day of any force-majeure event that materially affects availability. The affected party must notify the other promptly and mitigate. If the event continues for more than 15 days, either party may terminate on written notice, with a pro-rata refund of Fees paid in advance and a full export under Schedule 2.
35.7 Notices. Notices to the Venue are given by email to the account address and, where material, by notice in the back office. Notices to us are given by email to support@petflowhq.com and, for legal notices, in writing to the registered office in clause 36. Notice is deemed given on the day of sending if a Business Day, otherwise on the next Business Day.
35.8 Third-party rights. No person other than the parties has any right to enforce this Agreement, except that the confidentiality undertakings described in clause 16.4(d) are given for the benefit of, and are enforceable by, each Venue under section 374 of the Civil and Commercial Code.
35.9 Records. Each party must keep records sufficient to evidence its compliance with this Agreement for the periods stated in clause 26.
35.10 Language. A Thai-language version of this Agreement and of the Privacy Policy is issued alongside the English version. The Thai version governs all matters of notice, consent and data-subject information under the PDPA, including Schedule 1 and clause 9. The English version governs the commercial terms. Where the two conflict on any other matter, the English version prevails to the extent permitted by law.
36. Contact
Education AI Group Co., Ltd.
(บริษัท เอ็ดดูเคชั่น เอไอ กรุ๊ป จำกัด)
PetFlow HQ
2/1 Moo 6, Bophut, Ko Samui, Surat Thani, Thailand
Company registration number: 0845568020186
Email: support@petflowhq.com
Schedule 1 — Data Processing Schedule
This Schedule is the data processing agreement required by section 40 of the PDPA. It is annexed to and forms part of the Agreement. It is not a reference to another document.
1. Roles. The Venue is the controller and Education AI Group Co., Ltd. is the processor in respect of the personal data described in Annex 1. Education AI Group is a controller in its own right only in respect of the data described in clause 11.2 of the Terms.
2. Subject matter, duration, nature and purpose. Provision of the PetFlow HQ Platform to the Venue for the operation of the Venue's pet-care business, for the term of the Agreement and the export and deletion periods that follow it. The nature of the processing is collection, recording, storage, organisation, retrieval, display, transmission, back-up, aggregation as instructed, erasure and destruction.
3. Documented instructions. We process the personal data described in Annex 1 only on the Venue's documented instructions, which are: (a) the instructions given through the Venue's configuration and use of the Platform; (b) the instructed purposes listed in Annex 1, paragraph 4; and (c) any further written instruction the Venue gives. We will tell the Venue if we consider an instruction breaches the PDPA. Where we are required by law to process otherwise, we will inform the Venue first unless the law prohibits it.
4. Confidentiality of personnel. Our personnel and operators who may access Venue Data are bound by written confidentiality obligations that survive their engagement, are trained on the PDPA, and are granted access only under the operator-access gating and logging described in clause 11.6 of the Terms.
5. Security. We implement and maintain the measures in Schedule 3, which are mapped to the Notification of the Personal Data Protection Committee on Security Measures of the Data Controller B.E. 2565 (2022). Those measures may be improved but not materially reduced.
6. Sub-processors.
(a) The Venue authorises the Sub-processors listed in clause 16.1 of the Terms and in Annex 2.
(b) We will give at least 30 days' written notice before adding or replacing a Sub-processor.
(c) The Venue may object on reasonable data-protection grounds within that period. We will then work with the Venue to find a solution. If none is found, the Venue may terminate under clause 25.2(c) of the Terms with a pro-rata refund and the exit assistance in clause 25.7.
(d) We remain liable to the Venue for a Sub-processor's acts and omissions as if they were our own.
(e) Each Sub-processor is engaged under written terms imposing obligations no less protective than this Schedule.
7. Cross-border transfers. Transfers outside Thailand are made under the safeguards permitted by sections 28 and 29 of the PDPA and the Notification of the Personal Data Protection Committee on Criteria for the Protection of Personal Data Sent or Transferred Abroad B.E. 2566 (2023). The destination and mechanism for each Sub-processor is stated in Annex 2.
8. Breach notification. As set out in clause 11.4 of the Terms: notification to the Venue within 24 hours of becoming aware of an actual or suspected personal-data breach; the minimum content set in clause 11.4(b); evidence preservation for 3 years; and our funding of the Venue's notification costs where the breach arose from our act, omission or systems.
9. Assistance with data-subject requests. We will assist the Venue in responding to requests under sections 30 to 36 of the PDPA, by forwarding requests within 3 Business Days (clause 11.5), by providing access to and export of the relevant records, and by performing correction, deletion, anonymisation or restriction on the Venue's written instruction within 30 days (clause 26.5(a)). Assistance is at no charge for a reasonable volume of requests.
10. Assistance with the Venue's other obligations. We will provide the information the Venue reasonably needs for its record of processing under section 39, for a risk assessment, and for consultation with the Personal Data Protection Committee Office.
11. Audit and documentation. As set out in clause 12.5 of the Terms: annual independent penetration test summary; written security questionnaire response within 20 Business Days; the Venue's right to appoint an independent auditor; and, for the shared QuickBooks company, an independent accountant's report on access controls in place of inspection.
12. Return and deletion. On termination, export under Schedule 2 for 90 days, then deletion or irreversible anonymisation from live systems within 60 days and overwriting of backups within 90 days, with a written certificate of deletion on request, subject to the statutory carve-outs in clause 26.5(b) of the Terms.
13. Liability. Our liability under this Schedule is subject to clause 30.4 of the Terms. The indemnity in clause 31.6 applies. Nothing here limits a data subject's rights under sections 77 and 78 of the PDPA.
14. Variation. This Schedule may be varied only by written agreement (clause 33.4 of the Terms), save for the Sub-processor procedure in paragraph 6.
Annex 1 — Processing details
1. Categories of data subject: End Customers of the Venue and members of their households, including minors; the Venue's Authorised Users; individuals named in incident reports, including staff, End Customers and third parties; the Venue's veterinary and emergency contacts.
2. Categories of personal data:
(a) Contact and household data: name, address, email, telephone, household grouping, portal account credentials.
(b) Animal-linked data: animal name, breed, sex, date of birth or estimated age, weight, microchip number, markings, photographs, and the linked owner identity.
(c) Animal health data: vaccinations and expiry dates, medications and dosages, veterinary details, allergies, feeding instructions.
(d) Behaviour data: friendliness with dogs and people, nervousness, bite history, behaviour flags.
(e) Incident data: incident reports with a severity ladder, which may describe injury to an animal or to a person. Data describing injury to a person is health data about a human and may be sensitive personal data under section 26 of the PDPA.
(f) Booking and operational data: bookings, visits, check-in and check-out, care tasks, daily reports.
(g) Financial data: payments, invoices, receipts, refunds, packages, memberships, payment-method references (no card numbers).
(h) Documents: uploaded vaccination certificates, consent forms, signed waivers, parental consent records.
3. Sensitive personal data. Categories (c), (e) and, where it describes a person's health, (h) may constitute sensitive personal data. The Venue must hold explicit consent under section 26 obtained in the manner required by clause 9.4 of the Terms, or an applicable statutory exemption.
4. Instructed purposes. Hosting and operating the Platform for the Venue; authentication and account management; sending transactional and notification messages on the Venue's behalf; processing payments and producing invoices, receipts and accounting entries, including posting to the QuickBooks company described in clause 16.4; producing documents and reports; back-up, restore and disaster recovery; security monitoring and incident investigation; support at the Venue's request; the derivation of aggregated and anonymised statistics under clause 10.3 of the Terms; and deletion, anonymisation and export on instruction.
5. Duration. For the term of the Agreement and the export and deletion periods in clause 26 of the Terms.
Annex 2 — Sub-processors, destinations and transfer mechanisms
| Sub-processor | Processing | Destination | Transfer mechanism |
|---|---|---|---|
| Supabase Inc. | Application database, authentication, file storage | Hosting region notified in the Order; administrative and support access from the United States | Contractual safeguards under s.28 PDPA and the 2023 PDPC Notification, incorporated in our agreement with the provider |
| Opn (Omise) | Card and PromptPay processing | Thailand; group processing in Japan and Singapore | Thailand: domestic. Others: contractual safeguards under s.28 PDPA |
| Resend, Inc. | Transactional and notification email delivery | United States | Contractual safeguards under s.28 PDPA and the 2023 PDPC Notification |
| Intuit Inc. | Accounting records, invoices, receipts (including End Customer names) | United States | Contractual safeguards under s.28 PDPA and the 2023 PDPC Notification |
| Cloudflare, Inc. | DNS, CDN, security | United States and global edge locations | Contractual safeguards under s.28 PDPA and the 2023 PDPC Notification |
Schedule 2 — Data Export Schedule
1. Categories exported. A standard export contains all of the following for the Venue's tenant:
(a) End Customer records, including contact details, household grouping and portal account metadata;
(b) animal records, including breed, sex, date of birth or estimated age, weight, microchip number, markings and photograph references;
(c) animal health records: vaccinations with dates and expiry, medications and dosages, veterinary contacts, allergies, feeding instructions;
(d) behaviour records, including flags and bite history, with the date and author of each entry;
(e) incident reports, in full, with severity metadata, timestamps, author identity, edit history and all attachments;
(f) bookings, visits, check-in and check-out records, care tasks and daily reports;
(g) invoices, receipts, payments, refunds, packages and memberships, with their references and statuses;
(h) all uploaded documents and images in their original binary format, including vaccination certificates, consent forms, signed waivers and parental consent records;
(i) consent records, including category, wording version, timestamp and any withdrawal;
(j) the Venue's website content, images, copy, page structure and site configuration;
(k) the Venue's Authorised User list, roles and permission configuration;
(l) service catalogue, pricing, availability and policy configuration; and
(m) an extract of the audit trail for the Venue's tenant, and the operator-access log under clause 11.6.
2. Formats. Structured data is provided as CSV and JSON. Binary attachments are provided in their original format with a manifest mapping each file to the record it belongs to. Each export is accompanied by a documented schema describing every table, column and relationship, and a checksum manifest.
3. Integrity. Records that carry evidential weight — incident reports, waivers, consent records and documents — are exported with their creation and modification timestamps, author identity and version history intact, so that their evidential value is preserved for the 10-year retention period in clause 26.6(b).
4. Completeness. We warrant that a standard export contains all Venue Data held in the Platform for the Venue's tenant, other than derived caches and system-internal records with no informational content, and that it is capable of being loaded into another system by a competent third party using the supplied schema.
5. Availability and turnaround.
(a) Assisted export on written request, delivered within 10 Business Days, at no charge, as often as reasonably requested.
(b) Self-service export from the back office from the date in clause 21.4, at any time, at no charge.
(c) Available in full during any suspension and for 90 days after termination or expiry.
(d) Monthly continuity export to Venue-controlled storage on request, at no charge (clause 13.4).
(e) A non-standard export may be charged only as permitted by clause 26.2, capped at THB 20,000.
Schedule 3 — Technical and Organisational Security Measures
Mapped to the Notification of the Personal Data Protection Committee on Security Measures of the Data Controller B.E. 2565 (2022).
1. Confidentiality, integrity and availability. Measures are designed to preserve the confidentiality, integrity and availability of personal data and to prevent loss, unauthorised or unlawful access, use, alteration, correction or disclosure.
2. Access control — tenant scoping. Every record containing Venue Data is scoped to a single tenant. Access is enforced at the database layer by row-level security policies applied to the tables holding customer, animal, health, behaviour, incident, booking, financial and document records, so that a query executed in one tenant's security context cannot return another tenant's rows. No application query path bypasses that enforcement. Cross-tenant isolation is covered by automated tests exercised on each release.
3. Access control — users. Role-based permissions within a tenant; individual named logins; multi-factor authentication where we make it available; permission review and prompt offboarding by the Venue; least-privilege defaults.
4. Access control — our personnel. Operator access is restricted to authorised personnel, gated by role, logged with operator identity, time, tenant and reason, retained for 3 years, disclosable to the Venue on request, and subject to the break-glass notification procedure in clause 11.6(c).
5. Encryption and transmission. Encryption in transit using current TLS for all Platform surfaces and API traffic; encryption at rest for the database, file storage and backups; card data never held by us.
6. Logging and monitoring. Application audit logging of material actions; security and error monitoring; alerting on anomalous access patterns.
7. Back-up and recovery. Daily encrypted backups, 30-day retention, separate storage, annual restore testing, RPO 24 hours and RTO 48 hours, restore on request under clause 13.3.
8. Personnel. Written confidentiality obligations surviving engagement; PDPA awareness training; access granted on a need-to-know basis and revoked on departure.
9. Sub-processors. Written terms imposing equivalent obligations; the list, destinations and transfer mechanisms in Annex 2 to Schedule 1; 30 days' notice of change with an objection right.
10. Vulnerability management and testing. Dependency and platform patching; independent penetration testing at least annually from the date in clause 21.4, with the executive summary shared on request; remediation tracked to closure.
11. Incident response. Documented incident-response procedure; 24-hour notification to the Venue from awareness; evidence preservation for 3 years; post-incident written report.
12. Review. These measures are reviewed at least annually and after any material change to the Platform or any personal-data breach. They may be improved but not materially reduced without the Venue's agreement under clause 33.2.
13. What we do not claim. We hold no security certification, accreditation or third-party audit attestation. The only environment in which Venue records are not separated from those of other customers is the shared QuickBooks company described in clause 16.4, and that disclosure applies to that system alone.
*These Terms should be read together with the Order and the PetFlow HQ Privacy Policy. The Privacy Policy is informational and does not vary these Terms.*
Effective date: 5 August 2026