Privacy Policy — Zoravet Admin Portal (Clinic Staff)
This is the current version authored by Zoravet (Jensen Software, KvK 96526181). Independent privacy-law review and a Dutch-language version are in progress.
1. Who this is for
This policy is for staff members of a veterinary clinic who use the Zoravet admin portal (“the Portal”) to run the clinic — managing clients, pets, dossiers, appointments, messages, and billing.
It explains how Jensen Software (“Zoravet”) handles your personal data as a portal user. How the clinic and Zoravet handle client and pet data is covered by the app privacy policy and the data processing agreement (DPA) between Zoravet and your clinic.
2. The two roles, briefly
- Your employer (the clinic) is the controller for your work-account data as it relates to running the practice, and for all client/pet/clinical data you process in the Portal — including bank transaction data (counterparty names, IBANs, payment references of third parties) imported for bookkeeping and reconciliation. Zoravet is the processor for that data, acting on the clinic’s instructions.
- Zoravet is the controller for a minimal set of operational data it needs to provide, secure and support the Portal as a product (see section 4).
If you have questions about how your employer uses your work data, contact your clinic. For the operational data Zoravet controls, contact Zoravet (section 7).
3. What data we handle about you
| Category | Examples |
|---|---|
| Work account & identity | Name, work email, role/permissions, login credentials (via our identity system, Keycloak) |
| Usage & audit | Records of actions you take in the Portal (e.g. who edited a dossier, when), login history |
| Security & technical | IP address, device/browser type, session data, error and security logs |
| Support | Information you provide when contacting support |
The Portal is a professional tool. Please do not enter personal data about yourself beyond what your role requires.
4. Why we use it and legal basis
4.1 Clinic-controlled (Zoravet is processor)
| Purpose | Basis |
|---|---|
| Give you access to run the clinic’s operations | The clinic’s instruction under our DPA; clinic’s legitimate interest / contract |
| Maintain audit trails of who did what (accountability, tenant isolation) | Clinic’s legitimate interest and legal obligations as controller |
4.2 Zoravet-controlled (Zoravet is controller)
| Purpose | Basis (GDPR Art. 6) |
|---|---|
| Provide, secure and maintain the Portal and your login | Legitimate interest in operating the service (Art. 6(1)(f)) |
| Security, abuse prevention, incident response, audit logging | Legitimate interest (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c)) |
| Provide support you request | Legitimate interest / performing the support request (Art. 6(1)(f)/(b)) |
We do not use product-analytics or advertising trackers in the Portal (see section 9).
5. Sub-processors and hosting
The Portal runs on the same infrastructure as the platform:
| Sub-processor | Role | Note |
|---|---|---|
| AWS | Hosting, storage, backups | EU region eu-central-1 (Frankfurt, Germany). Data is stored in the EU. |
| Amazon SES | Transactional email (e.g. account emails) | EU region eu-central-1 (Frankfurt, Germany) |
Keycloak (login) is self-hosted by Zoravet in the EU and is part of our own platform, not a third-party sub-processor. Push notifications (Firebase Cloud Messaging) are a feature of the pet-owner app, not of the Portal, which runs in a browser — no push-notification sub-processor applies here.
6. Retention
- Work account: kept while you have access to the Portal; access is removed or deactivated when your clinic revokes it (for example, when you leave the clinic) through the Portal’s staff-management controls, or by Zoravet on the clinic’s request.
- Audit/security logs: retained for 24 months, for security and accountability.
- Support records: retained for 24 months.
7. Your rights
You have the GDPR rights of access, rectification, erasure, restriction, objection, and portability.
- For data your clinic controls (your work account in the context of employment, clinical data), contact your clinic.
- For data Zoravet controls (operational/security data about your Portal use), contact Zoravet at info@zoravet.nl.
You may also complain to the Autoriteit Persoonsgegevens (AP) — www.autoriteitpersoonsgegevens.nl.
8. Security
Encryption in transit and at rest, strict tenant isolation between clinics, role-based access control, audit logging, and regular backups. Access to your data by Zoravet staff is limited to what is needed to operate and support the service. See the Security Statement for detail.
9. No analytics, no automated decisions, no sale
- No third-party product-analytics or advertising trackers in the Portal. If this changes, this policy is updated first.
- No automated decision-making with legal or similarly significant effects.
- We do not sell personal data.
10. Changes and contact
We may update this policy; material changes will be communicated to clinic administrators.
- Zoravet: Jensen Software, KvK 96526181, Oanjelaan 32, 1421 AK Uithoorn, Netherlands, info@zoravet.nl
- Your clinic (your employer / controller): contact your clinic administrator