FAQ
Frequently asked questions
The questions clinics and their vendor assessments ask us most — answered briefly and honestly.
Where is data hosted?
In the EU: all primary storage and processing runs on AWS in eu-central-1 (Frankfurt, Germany). Backups are additionally replicated cross-region to eu-west-1 (Ireland) for regional-failure cover. The only processor with a possible location outside the EEA is Google Firebase Cloud Messaging for push notifications — see Subprocessors.
Is data encrypted, in transit and at rest?
Yes. All external traffic runs over HTTPS/TLS (TLS 1.2 minimum, TLS 1.3 where supported); plain HTTP is redirected to HTTPS. At rest: the database (RDS) has storage encryption enabled, secrets are KMS-encrypted, and file storage (S3) uses server-side encryption (SSE-S3/AES-256).
How is data kept separate between clinics (multi-tenancy)?
Each clinic is a separate tenant. A centrally enforced database-filter mechanism constrains every query to the caller's clinic, on every execution path (web requests, background jobs, events), and fails closed if tenant context is missing. An independent three-reviewer isolation audit (July 2026) found zero confirmed cross-tenant data leaks.
Are backups made, and have restores actually been tested?
Yes, both. Automated daily backups with 7-day retention and point-in-time recovery (RPO ≈ 5 minutes). A documented restore rehearsal has been executed against production (25 July 2026: restore to a disposable instance, schema and row-count checks both passed, restore-to-verified measured at 32 minutes). This rehearsal repeats quarterly.
What happens in a security incident or data breach?
Zoravet notifies clinics of a personal-data breach affecting their data without undue delay and at the latest within 48 hours of becoming aware. As controller, the clinic remains responsible for notifying the Autoriteit Persoonsgegevens and, where required, affected individuals; Zoravet supports with the information needed.
Does Zoravet hold certifications such as ISO 27001 or SOC 2?
No. We do not claim certifications we do not hold: there is no ISO 27001 or SOC 2 certification, and no independent penetration test has been performed. What we do describe — in the Security Statement and the DPA — is built, tested and active.
Who are the sub-processors, and how are they managed?
A small, documented list: AWS, Amazon SES and Google Firebase Cloud Messaging. See the Subprocessors page for the full list. Clinics get at least 30 days advance notice before a new or replaced sub-processor, with a right to object.
How can a pet owner access or delete their data?
Ask your clinic — it is the controller for your client and pet dossier. The platform provides a self-service export of your own personal data (portability); deletion requests are routed to the clinic, which today carries out the actual erasure as a manual action.
How long is data retained?
Medical dossiers: the life of the pet plus 5 years. Invoices/financial records: 7 years (Dutch fiscal retention obligation). Messages and appointments: 5 years after last activity. An automated retention sweep is built and runs in dry-run today (counts only, no deletions); full enforcement switches on at go-live.
How do I report a vulnerability or ask a compliance question?
Security reports: security@zoravet.nl (falls back to info@zoravet.nl). Compliance, privacy or data-processing questions (e.g. for a vendor assessment): grc@zoravet.com.
Don't see your question? Email grc@zoravet.com