Legal

Privacy Policy — Zoravet App (Pet Owners)

Last updated: 12 August 2026 · Version 1.1

1. About this policy and who is responsible for your data

The Zoravet app is a white-label application provided to you by your veterinary clinic. Through the app you can view your pet’s information, manage appointments, message the clinic, and see invoices.

There are two organisations involved in handling your data, and it matters which one is responsible for what:

  • Your veterinary clinic is the “data controller” (verwerkingsverantwoordelijke) for your account details, your pets, their medical dossiers, your appointments, messages, and invoices. The clinic decides why and how this data is used to provide veterinary care and run its practice. Your clinic’s name and contact details are shown in the app under Settings → About your clinic. Your clinic is the first point of contact for questions about your personal data and for exercising your rights (see section 8).
  • Zoravet is the “data processor” (verwerker) for that same clinic and pet data. Zoravet builds and operates the app and the underlying platform on the clinic’s instructions and on its behalf. Zoravet does not use your clinic-related data for its own purposes.
  • Zoravet is itself the “data controller” for a limited set of data it needs to run the platform as a product: your platform login account (managed via our identity system), security and audit logs, and basic operational/technical data needed to keep the service secure, reliable and working. This is described in section 4.2.

Zoravet’s legal entity details:

  • Jensen Software
  • KvK 96526181
  • Oanjelaan 32, 1421 AK Uithoorn, Netherlands
  • support@zoravet.nl (Mon–Fri 09:00–17:00 CET, excluding Dutch public holidays; best-effort outside these hours)
  • Security or data-breach contact: security@zoravet.nl
  • Governing law: the Netherlands

2. A note on medical data about your pet

The medical dossier in the app concerns your animal, not you. Under the GDPR/AVG, health data about animals is not “special category” personal data under Article 9 (which protects data about a human’s health, and other sensitive categories about people).

We still treat your pet’s medical information carefully and with appropriate security, because it is linked to you as the owner and because it is confidential clinical information. But you should understand that the heightened Article 9 legal regime for human health data does not apply to animal medical records.

If the app ever stores health information about you personally (for example, a note that you have a mobility limitation affecting how you can bring your pet in), that would be your personal health data and would be treated under the stricter Article 9 rules. The app is not designed to collect such data; please do not enter it.

3. What data we handle

Depending on how you use the app, the following categories of personal data may be handled:

CategoryExamples
Account & identityName, email address, phone number, login credentials (managed via our identity system)
PetsPet name, species, breed, sex, date of birth, identification (e.g. chip number)
Medical dossierConsultation notes, diagnoses, treatments, vaccinations, prescriptions, weight, lab results (data about the animal)
AppointmentsRequested and scheduled appointments, reason for visit, status
MessagesMessages exchanged between you and the clinic through the app
BillingInvoices, payment status, amounts (payment card data is not stored by the app)
NotificationsPush notification token(s) for your device, your notification preferences/opt-ins
Technical/operationalApp version, device/OS type, error and security logs, timestamps of actions

4.1 Clinic-controlled purposes (clinic is controller, Zoravet is processor)

PurposeLegal basis (GDPR Art. 6)
Provide veterinary care and maintain your pet’s medical dossierContract with the clinic (Art. 6(1)(b)); legitimate interest of running the practice (Art. 6(1)(f))
Manage appointmentsContract (Art. 6(1)(b))
Communicate with you (messages, transactional notifications about appointments, results, invoices)Contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f))
Send invoices and process paymentsContract (Art. 6(1)(b)); legal obligation for accounting (Art. 6(1)(c))
Send news / marketing broadcasts (e.g. clinic newsletters, promotions)Consent (Art. 6(1)(a)) — opt-in, which you can withdraw at any time

The clinic determines these purposes and legal bases. The exact basis for a given message may depend on the clinic’s own policies.

4.2 Zoravet-controlled purposes (Zoravet is controller)

PurposeLegal basis (GDPR Art. 6)
Provide, secure and maintain your platform login accountLegitimate interest in operating the service (Art. 6(1)(f))
Keep the service secure (audit logs, abuse prevention, incident response)Legitimate interest in security (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c))
Diagnose technical problems and keep the app reliableLegitimate interest (Art. 6(1)(f))

We do not perform behavioural product analytics or advertising tracking in the app (see section 10).

5. Notifications and push tokens

To send push notifications, the app registers a push token for your device. Sending a push notification technically requires transferring that token, and the notification payload, through Google Firebase Cloud Messaging (FCM) (for Android and, via Apple’s system, for iOS delivery). This means notification-related technical data passes through Google’s infrastructure. See section 6 on sub-processors and international transfers.

You control notifications:

  • Transactional notifications (appointment reminders, results ready, new message, invoice) are part of the service.
  • News / marketing broadcasts are opt-in only. You will not receive them unless you actively turn them on, and you can turn them off at any time in the app settings.

To reduce data sent to Google, we keep notification payloads minimal where practical. You can also disable push notifications entirely at the operating-system level.

6. Who else processes your data (sub-processors) and international transfers

Zoravet uses the following sub-processors to run the platform. These act on Zoravet’s (and ultimately the clinic’s) instructions under contract:

Sub-processorRoleLocation / transfer note
AWS (Amazon Web Services EMEA SARL)Cloud infrastructure: compute, database, object storage, backups, transactional email, secretsEU regions — primary Frankfurt (Germany), backup Ireland. Data stays in the EU/EEA.
Google LLC (Firebase Cloud Messaging)Mobile push-notification delivery (app only)Google is a US-headquartered provider; notification tokens/payloads may be processed outside the EEA. Google LLC is covered by the EU–U.S. Data Privacy Framework, with EU Standard Contractual Clauses as a fallback.
Mollie B.V.Payment processing (pay-by-link for clinic invoices)Netherlands. Planned, not yet active. Hosted checkout only — no card/payment-card data touches our servers. Each clinic uses its own Mollie account; Mollie settles funds directly to the clinic. Will be added here with advance notice before activation.

Our login/identity service is self-hosted by Zoravet on our own EU infrastructure and is therefore not a third-party sub-processor — it is part of our own platform. GitHub is used for source code and CI only; no clinic or owner personal data flows through it.

The full sub-processor list, kept in sync with this policy, is on the Subprocessors page.

Zoravet will not add or change sub-processors for clinic-controlled data without notifying the clinic as required by our agreement with them.

7. How long we keep your data (retention)

Retention of clinic data is ultimately decided by your clinic as controller. The platform defaults are:

  • Medical dossiers: retained for the life of the pet plus 5 years, for veterinary care and professional record-keeping purposes.
  • Invoices / financial records: retained for 7 years, in line with the Dutch fiscal retention obligation.
  • Messages and appointments: retained for 5 years after last activity.
  • Push tokens: removed when they become invalid or when you disable notifications / delete the app.
  • Platform account & security logs (Zoravet as controller): kept while your account is active and for 12 months after account closure, for security and dispute purposes.

When retention periods end, data is deleted or anonymised.

8. Your rights and how to exercise them

You have the following rights over your personal data under the GDPR/AVG:

  • Access — get a copy of the personal data held about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure (“right to be forgotten”) — have your data deleted, subject to legal retention obligations (e.g. invoices).
  • Data portability — receive certain data in a structured, machine-readable format, or have it transferred.
  • Objection — object to processing based on legitimate interest.
  • Restriction — ask us to limit processing in certain cases.
  • Withdraw consent — where processing is based on consent (e.g. marketing broadcasts), withdraw it at any time, without affecting past processing.

How to exercise them: Because your clinic is the controller for your pet and clinic data, please direct these requests to your clinic (contact details in section 1). Zoravet will assist the clinic in fulfilling your request — data export (portability) and account/pet-record erasure are implemented as platform features that the clinic can use on your behalf. For requests concerning data where Zoravet is the controller (your platform account, security logs), you may contact Zoravet directly at support@zoravet.nl.

We aim to respond within the timeframe required by law (generally one month).

9. Complaints

If you are not satisfied with how your data has been handled, you have the right to lodge a complaint with the Dutch supervisory authority:

Autoriteit Persoonsgegevens (AP)www.autoriteitpersoonsgegevens.nl

We would appreciate the chance to resolve your concern first, but this does not limit your right to complain to the AP.

10. Automated decisions, profiling, analytics and sale of data

  • No automated decision-making: We do not make decisions with legal or similarly significant effects about you based solely on automated processing.
  • No profiling for advertising.
  • No analytics/tracking SDKs: The app currently contains no third-party product-analytics or advertising trackers. If this changes, this policy will be updated and, where required, your consent will be requested first.
  • No sale of data: We do not sell your personal data to anyone.

11. Security

Zoravet protects your data with technical and organisational measures, including:

  • Hosting with a leading cloud provider in EU (EEA) data centres, with backups replicated to a second EU region.
  • Encryption in transit (TLS) and at rest.
  • A managed, highly-available database service.
  • Automated backups with point-in-time recovery, geo-redundant within the EU; recovery procedures are tested periodically. Specific recovery objectives are available on request.
  • Continuous automated monitoring and alerting.
  • Centralised, role-based, least-privilege access control, with strict per-tenant (per-clinic) isolation that fails closed; our cross-tenant isolation controls have been independently reviewed.
  • A dedicated identity and access-management system; multi-factor authentication is supported and can be required, though it is not yet enforced platform-wide by policy.
  • A web application firewall protects our services, and internal systems run in private networks.
  • Changes are deployed via automated pipelines with automatic rollback, and production deployments are gated by a manual approval step.

No system is perfectly secure, and we are honest about our current stage: Zoravet is an early-stage, single-operator business. We do not run a 24/7 security operations centre or on-call rotation, and we do not currently hold formal security certifications (e.g. ISO 27001, SOC 2) — we are not pursuing these at this scale today, but we align our practices with recognised security frameworks proportionate to our size.

In the event of a personal data breach affecting your data, Zoravet (as processor) will notify the affected clinic (as controller) without undue delay and within 48 hours of becoming aware, so the clinic can meet its own 72-hour notification duty to the Autoriteit Persoonsgegevens. You can reach our security team at security@zoravet.nl.

More detail on our security and compliance posture is available in the Security Statement.

12. Changes to this policy

We may update this policy. Material changes will be communicated to you (for example, in the app), and where required we will ask you to acknowledge the new version. The current version and date are shown at the top.

13. Contact

  • Your clinic (controller): shown in the app under Settings → About your clinic.
  • Zoravet (processor / platform controller): Jensen Software, KvK 96526181, Oanjelaan 32, 1421 AK Uithoorn, Netherlands, support@zoravet.nl
  • Security / data-breach contact: security@zoravet.nl
  • Data Protection Officer / privacy contact: Not appointed — a DPO is not required for this processing (no large-scale or special-category processing under GDPR Art. 37). Privacy contact: support@zoravet.nl.