Privacy Policy — Zoravet App (Pet Owners)
Dit document is momenteel alleen beschikbaar in het Engels. Een Nederlandse vertaling volgt na juridische toetsing.
This is the current version authored by Zoravet (Jensen Software, KvK 96526181). Independent privacy-law review and a Dutch-language version are in progress.
1. About this policy and who is responsible for your data
The Zoravet app is a white-label application provided to you by your veterinary clinic. Through the app you can view your pet’s information, manage appointments, message the clinic, and see invoices.
There are two organisations involved in handling your data, and it matters which one is responsible for what:
- Your veterinary clinic is the “data controller” (verwerkingsverantwoordelijke) for your account details, your pets, their medical dossiers, your appointments, messages, and invoices. The clinic decides why and how this data is used to provide veterinary care and run its practice. Your clinic’s name and contact details are shown in the app under Settings → About your clinic. Your clinic is the first point of contact for questions about your personal data and for exercising your rights (see section 8).
- Zoravet is the “data processor” (verwerker) for that same clinic and pet data. Zoravet builds and operates the app and the underlying platform on the clinic’s instructions and on its behalf. Zoravet does not use your clinic-related data for its own purposes.
- Zoravet is itself the “data controller” for a limited set of data it needs to run the platform as a product: your platform login account (managed via our identity system), security and audit logs, and basic operational/technical data needed to keep the service secure, reliable and working. This is described in section 4.2.
Zoravet’s legal entity details:
- Jensen Software
- 96526181
- Oanjelaan 32, 1421 AK Uithoorn, Netherlands
- info@zoravet.nl
2. A note on medical data about your pet
The medical dossier in the app concerns your animal, not you. Under the GDPR/AVG, health data about animals is not “special category” personal data under Article 9 (which protects data about a human’s health, and other sensitive categories about people).
We still treat your pet’s medical information carefully and with appropriate security, because it is linked to you as the owner and because it is confidential clinical information. But you should understand that the heightened Article 9 legal regime for human health data does not apply to animal medical records.
If the app ever stores health information about you personally (for example, a note that you have a mobility limitation affecting how you can bring your pet in), that would be your personal health data and would be treated under the stricter Article 9 rules. The app is not designed to collect such data; please do not enter it.
3. What data we handle
Depending on how you use the app, the following categories of personal data may be handled:
| Category | Examples |
|---|---|
| Account & identity | Name, email address, phone number, login credentials (managed via our identity system) |
| Pets | Pet name, species, breed, sex, date of birth, identification (e.g. chip number) |
| Medical dossier | Consultation notes, diagnoses, treatments, vaccinations, prescriptions, weight, lab results (data about the animal) |
| Appointments | Requested and scheduled appointments, reason for visit, status |
| Messages | Messages exchanged between you and the clinic through the app |
| Billing | Invoices, payment status, amounts (payment card data is not stored by the app) |
| Notifications | Push notification token(s) for your device, your notification preferences/opt-ins |
| Technical/operational | App version, device/OS type, error and security logs, timestamps of actions |
4. Why we use your data and the legal basis
4.1 Clinic-controlled purposes (clinic is controller, Zoravet is processor)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide veterinary care and maintain your pet’s medical dossier | Contract with the clinic (Art. 6(1)(b)); legitimate interest of running the practice (Art. 6(1)(f)) |
| Manage appointments | Contract (Art. 6(1)(b)) |
| Communicate with you (messages, transactional notifications about appointments, results, invoices) | Contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f)) |
| Send invoices and process payments | Contract (Art. 6(1)(b)); legal obligation for accounting (Art. 6(1)(c)) |
| Send news / marketing broadcasts (e.g. clinic newsletters, promotions) | Consent (Art. 6(1)(a)) — opt-in, which you can withdraw at any time |
The clinic determines these purposes and legal bases. The exact basis for a given message may depend on the clinic’s own policies.
4.2 Zoravet-controlled purposes (Zoravet is controller)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide, secure and maintain your platform login account | Legitimate interest in operating the service (Art. 6(1)(f)) |
| Keep the service secure (audit logs, abuse prevention, incident response) | Legitimate interest in security (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c)) |
| Diagnose technical problems and keep the app reliable | Legitimate interest (Art. 6(1)(f)) |
We do not perform behavioural product analytics or advertising tracking in the app (see section 10).
5. Notifications and push tokens
To send push notifications, the app registers a push token for your device. Sending a push notification technically requires transferring that token, and the notification payload, through Google Firebase Cloud Messaging (FCM) (for Android and, via Apple’s system, for iOS delivery). This means notification-related technical data passes through Google’s infrastructure. See section 6 on sub-processors and international transfers.
You control notifications:
- Transactional notifications (appointment reminders, results ready, new message, invoice) are part of the service.
- News / marketing broadcasts are opt-in only. You will not receive them unless you actively turn them on, and you can turn them off at any time in the app settings.
To reduce data sent to Google, we keep notification payloads minimal where practical. You can also disable push notifications entirely at the operating-system level.
6. Who else processes your data (sub-processors) and international transfers
Zoravet uses the following sub-processors to run the platform. These act on Zoravet’s (and ultimately the clinic’s) instructions under contract:
| Sub-processor | Role | Location / transfer note |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage, database, backups | EU region eu-central-1 (Frankfurt, Germany). Data is stored in the EU. |
| Amazon SES | Sending transactional/notification emails | EU region eu-central-1 (Frankfurt, Germany). Email content and recipient address are processed to deliver mail. |
| Google (Firebase Cloud Messaging) | Push notification delivery | Google is a US-headquartered provider; notification tokens/payloads may be processed outside the EEA. Google LLC is certified under the EU–U.S. Data Privacy Framework; EU Standard Contractual Clauses apply as a fallback under Google’s Data Processing Terms. |
Keycloak is used for authentication (login). It is self-hosted by Zoravet on our own EU infrastructure and is therefore not a third-party sub-processor — it is part of our own platform.
The full sub-processor list, kept in sync with this policy, is on the Subprocessors page.
Zoravet will not add or change sub-processors for clinic-controlled data without notifying the clinic as required by our agreement with them.
7. How long we keep your data (retention)
Retention of clinic data is ultimately decided by your clinic as controller. The platform defaults are:
- Medical dossiers: retained for the life of the pet plus 5 years, for veterinary care and professional record-keeping purposes.
- Invoices / financial records: retained for 7 years, in line with the Dutch fiscal retention obligation.
- Messages and appointments: retained for 5 years after last activity.
- Push tokens: removed when they become invalid or when you disable notifications / delete the app.
- Platform account & security logs (Zoravet as controller): kept while your account is active and for 12 months after account closure, for security and dispute purposes.
When retention periods end, data is deleted or anonymised.
8. Your rights and how to exercise them
You have the following rights over your personal data under the GDPR/AVG:
- Access — get a copy of the personal data held about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”) — have your data deleted, subject to legal retention obligations (e.g. invoices).
- Data portability — receive certain data in a structured, machine-readable format, or have it transferred.
- Objection — object to processing based on legitimate interest.
- Restriction — ask us to limit processing in certain cases.
- Withdraw consent — where processing is based on consent (e.g. marketing broadcasts), withdraw it at any time, without affecting past processing.
How to exercise them: Because your clinic is the controller for your pet and clinic data, please direct these requests to your clinic (contact details in section 1). Zoravet will assist the clinic in fulfilling your request, including providing data export (portability) and deletion support through the platform. For requests concerning data where Zoravet is the controller (your platform account, security logs), you may contact Zoravet directly at info@zoravet.nl.
We aim to respond within the timeframe required by law (generally one month).
9. Complaints
If you are not satisfied with how your data has been handled, you have the right to lodge a complaint with the Dutch supervisory authority:
Autoriteit Persoonsgegevens (AP) — www.autoriteitpersoonsgegevens.nl
We would appreciate the chance to resolve your concern first, but this does not limit your right to complain to the AP.
10. Automated decisions, profiling, analytics and sale of data
- No automated decision-making: We do not make decisions with legal or similarly significant effects about you based solely on automated processing.
- No profiling for advertising.
- No analytics/tracking SDKs: The app currently contains no third-party product-analytics or advertising trackers. If this changes, this policy will be updated and, where required, your consent will be requested first.
- No sale of data: We do not sell your personal data to anyone.
11. Security
Zoravet protects your data with technical and organisational measures including encryption in transit and at rest, strict separation between clinics (tenant isolation), access controls, and regular backups. See the Security Statement for detail. No system is perfectly secure, but we work to protect your data appropriately.
12. Changes to this policy
We may update this policy. Material changes will be communicated to you (for example, in the app), and where required we will ask you to acknowledge the new version. The current version and date are shown at the top.
13. Contact
- Your clinic (controller): shown in the app under Settings → About your clinic.
- Zoravet (processor / platform controller): Jensen Software, Oanjelaan 32, 1421 AK Uithoorn, Netherlands, info@zoravet.nl
- Data Protection Officer / privacy contact: Not appointed — a DPO is not required for this processing (no large-scale or special-category processing under GDPR Art. 37). Privacy contact: info@zoravet.nl.