Privacy Policy — Zoravet Admin Portal (Clinic Staff)
1. Who this is for
This policy is for staff members of a veterinary clinic who use the Zoravet admin portal (“the Portal”) to run the clinic — managing clients, pets, dossiers, appointments, messages, and billing.
It explains how Jensen Software (“Zoravet”) handles your personal data as a portal user. How the clinic and Zoravet handle client and pet data is covered by the app privacy policy and the data processing agreement (DPA) between Zoravet and your clinic.
2. The two roles, briefly
- Your employer (the clinic) is the controller for your work-account data as it relates to running the practice, and for all client/pet/clinical data you process in the Portal — including bank transaction data (counterparty names, IBANs, payment references of third parties) imported for bookkeeping and reconciliation. Zoravet is the processor for that data, acting on the clinic’s instructions.
- Zoravet is the controller for a minimal set of operational data it needs to provide, secure and support the Portal as a product (see section 4).
If you have questions about how your employer uses your work data, contact your clinic. For the operational data Zoravet controls, contact Zoravet (section 7).
3. What data we handle about you
| Category | Examples |
|---|---|
| Work account & identity | Name, work email, role/permissions, login credentials (via our identity system) |
| Usage & audit | Records of actions you take in the Portal (e.g. who edited a dossier, when), login history |
| Security & technical | IP address, device/browser type, session data, error and security logs |
| Support | Information you provide when contacting support |
The Portal is a professional tool. Please do not enter personal data about yourself beyond what your role requires.
4. Why we use it and legal basis
4.1 Clinic-controlled (Zoravet is processor)
| Purpose | Basis |
|---|---|
| Give you access to run the clinic’s operations | The clinic’s instruction under our DPA; clinic’s legitimate interest / contract |
| Maintain audit trails of who did what (accountability, tenant isolation) | Clinic’s legitimate interest and legal obligations as controller |
4.2 Zoravet-controlled (Zoravet is controller)
| Purpose | Basis (GDPR Art. 6) |
|---|---|
| Provide, secure and maintain the Portal and your login | Legitimate interest in operating the service (Art. 6(1)(f)) |
| Security, abuse prevention, incident response, audit logging | Legitimate interest (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c)) |
| Provide support you request | Legitimate interest / performing the support request (Art. 6(1)(f)/(b)) |
We do not use product-analytics or advertising trackers in the Portal (see section 9).
5. Sub-processors and hosting
The Portal runs on the same infrastructure as the platform:
| Sub-processor | Role | Note |
|---|---|---|
| AWS (Amazon Web Services EMEA SARL) | Cloud infrastructure: compute, storage, backups, transactional email (e.g. account emails), secrets | EU regions — primary Frankfurt (Germany), backup Ireland. Data stays in the EU/EEA. |
| Mollie B.V. | Payment processing (pay-by-link for clinic invoices, initiated from the Portal) | Netherlands. Planned, not yet active. Hosted checkout only — no card/payment-card data touches our servers. Each clinic uses its own Mollie account; Mollie settles funds directly to the clinic. Will be added here with advance notice before activation. |
Our login/identity service is self-hosted by Zoravet in the EU and is part of our own platform, not a third-party sub-processor. GitHub is used for source code and CI only; no clinic personal data flows through it.
The Portal does not send mobile push notifications — that is an app-only feature, delivered via Google Firebase Cloud Messaging and disclosed in the app privacy policy. The Portal does not currently send browser push notifications either.
6. Retention
- Work account: kept while you have access; removed or deactivated when your clinic revokes access to the Portal or you leave the clinic.
- Audit/security logs: retained for 24 months, for security and accountability.
- Support records: retained for 24 months.
7. Your rights
You have the GDPR rights of access, rectification, erasure, restriction, objection, and portability.
- For data your clinic controls (your work account in the context of employment, clinical data), contact your clinic.
- For data Zoravet controls (operational/security data about your Portal use), contact Zoravet at support@zoravet.nl.
You may also complain to the Autoriteit Persoonsgegevens (AP) — www.autoriteitpersoonsgegevens.nl.
8. Security
Zoravet protects Portal data with technical and organisational measures, including:
- Hosting with a leading cloud provider in EU (EEA) data centres, with backups replicated to a second EU region.
- Encryption in transit (TLS) and at rest.
- A managed, highly-available database service, with automated backups and point-in-time recovery, geo-redundant within the EU; recovery procedures are tested periodically.
- Continuous automated monitoring and alerting.
- Centralised, role-based, least-privilege access control, with strict per-tenant (per-clinic) isolation that fails closed and audit logging of Portal actions; our cross-tenant isolation controls have been independently reviewed. Access to your data by Zoravet staff is limited to what is needed to operate and support the service, and Zoravet personnel are bound by confidentiality obligations.
- A dedicated identity and access-management system; multi-factor authentication is supported and can be required, though it is not yet enforced platform-wide by policy.
- A web application firewall protects our services, and internal systems run in private networks.
- Changes are deployed via automated pipelines with automatic rollback, and production deployments are gated by a manual approval step.
No system is perfectly secure. Zoravet is an early-stage, single-operator business: we do not run a 24/7 security operations centre or on-call rotation, and we do not currently hold formal security certifications (e.g. ISO 27001, SOC 2) — we align our practices with recognised security frameworks proportionate to our size.
In the event of a personal data breach affecting Portal data, Zoravet (as processor) will notify the affected clinic (as controller) without undue delay and within 48 hours of becoming aware, so the clinic can meet its own 72-hour notification duty to the Autoriteit Persoonsgegevens. You can reach our security team at security@zoravet.nl.
More detail on our security and compliance posture is available in the Security Statement.
9. No analytics, no automated decisions, no sale
- No third-party product-analytics or advertising trackers in the Portal. If this changes, this policy is updated first.
- No automated decision-making with legal or similarly significant effects.
- We do not sell personal data.
10. Changes and contact
We may update this policy; material changes will be communicated to clinic administrators.
- Zoravet: Jensen Software, KvK 96526181, Oanjelaan 32, 1421 AK Uithoorn, Netherlands, support@zoravet.nl
- Security / data-breach contact: security@zoravet.nl
- Your clinic (your employer / controller): contact your clinic administrator — your clinic’s own contact details are recorded in your employer’s records, not in this platform-wide document.