FAQ

Frequently asked questions

The questions clinics and their vendor assessments ask us most — answered briefly and honestly.

Where is data hosted?

In the EU. All primary storage and processing takes place in EU (EEA) data centres, and backups are additionally replicated to a second EU region for regional-failure cover. The only sub-processor that may process data outside the EEA is Google Firebase Cloud Messaging for push notifications, covered by the EU–U.S. Data Privacy Framework with Standard Contractual Clauses as fallback — see Subprocessors.

Is data encrypted, in transit and at rest?

Yes — in transit and at rest. All external traffic runs over encrypted connections (HTTPS/TLS), and plain HTTP is redirected to HTTPS. Data at rest — the database, file storage and secrets — is encrypted using our cloud provider's managed encryption.

How is data kept separate between clinics (multi-tenancy)?

Each clinic is a separate tenant. A centrally enforced database-filter mechanism constrains every query to the caller's clinic, on every execution path (web requests, background jobs, events), and fails closed if tenant context is missing. An independent three-reviewer isolation audit (July 2026) found zero confirmed cross-tenant data leaks.

Are backups made, and have restores actually been tested?

Yes, both. We take automated daily backups with point-in-time recovery, retained for 7 days and geo-redundant within the EU. Restores are not just assumed to work: we have run a documented restore rehearsal against production (schema and row-count checks both passed) and repeat it periodically. Specific recovery objectives are available on request.

What happens in a security incident or data breach?

Zoravet notifies clinics of a personal-data breach affecting their data without undue delay and at the latest within 48 hours of becoming aware. As controller, the clinic remains responsible for notifying the Autoriteit Persoonsgegevens and, where required, affected individuals; Zoravet supports with the information needed.

Does Zoravet hold certifications such as ISO 27001 or SOC 2?

No. We do not claim certifications we do not hold: there is no ISO 27001 or SOC 2 certification, and no independent penetration test has been performed. What we do describe — in the Security Statement and the DPA — is built, tested and active.

Who are the sub-processors, and how are they managed?

A small, documented list: AWS (EU infrastructure) and Google Firebase Cloud Messaging (push notifications). See the Subprocessors page for the full list, including Mollie for payments, which is planned but not yet active. Clinics get at least 30 days advance notice before a new or replaced sub-processor, with a right to object.

How can a pet owner access or delete their data?

Ask your clinic — it is the controller for your client and pet dossier. The platform provides a self-service export of your own personal data (portability); deletion requests are routed to your clinic, which can carry out the erasure directly in the platform — owner erasure and anonymisation are built and live, while records that must be kept by law (e.g. invoices) are retained.

How long is data retained?

No longer than necessary. Medical dossiers are kept as lifelong patient history under the clinic's control and erased on the owner's request. Invoices/financial records: 7 years (Dutch fiscal retention obligation). Veterinary-medicine dispensing records: 5 years (EU Regulation 2019/6). Operational logs: around 2 years. An automated retention routine enforces these periods in production — see the Data Retention document for the full overview.

How do I report a vulnerability or ask a compliance question?

Security reports: security@zoravet.nl. Compliance, privacy or data-processing questions (e.g. for a vendor assessment): support@zoravet.nl.

Don't see your question? Email support@zoravet.nl