Juridisch

Privacy Policy — Zoravet Admin Portal (Clinic Staff)

Laatst bijgewerkt: 20 July 2026 · Versie 1.1

Dit document is momenteel alleen beschikbaar in het Engels. Een Nederlandse vertaling volgt na juridische toetsing.

This is the current version authored by Zoravet (Jensen Software, KvK 96526181). Independent privacy-law review and a Dutch-language version are in progress.

1. Who this is for

This policy is for staff members of a veterinary clinic who use the Zoravet admin portal (“the Portal”) to run the clinic — managing clients, pets, dossiers, appointments, messages, and billing.

It explains how Jensen Software (“Zoravet”) handles your personal data as a portal user. How the clinic and Zoravet handle client and pet data is covered by the app privacy policy and the data processing agreement (DPA) between Zoravet and your clinic.

2. The two roles, briefly

  • Your employer (the clinic) is the controller for your work-account data as it relates to running the practice, and for all client/pet/clinical data you process in the Portal — including bank transaction data (counterparty names, IBANs, payment references of third parties) imported for bookkeeping and reconciliation. Zoravet is the processor for that data, acting on the clinic’s instructions.
  • Zoravet is the controller for a minimal set of operational data it needs to provide, secure and support the Portal as a product (see section 4).

If you have questions about how your employer uses your work data, contact your clinic. For the operational data Zoravet controls, contact Zoravet (section 7).

3. What data we handle about you

CategoryExamples
Work account & identityName, work email, role/permissions, login credentials (via our identity system, Keycloak)
Usage & auditRecords of actions you take in the Portal (e.g. who edited a dossier, when), login history
Security & technicalIP address, device/browser type, session data, error and security logs
SupportInformation you provide when contacting support

The Portal is a professional tool. Please do not enter personal data about yourself beyond what your role requires.

4.1 Clinic-controlled (Zoravet is processor)

PurposeBasis
Give you access to run the clinic’s operationsThe clinic’s instruction under our DPA; clinic’s legitimate interest / contract
Maintain audit trails of who did what (accountability, tenant isolation)Clinic’s legitimate interest and legal obligations as controller

4.2 Zoravet-controlled (Zoravet is controller)

PurposeBasis (GDPR Art. 6)
Provide, secure and maintain the Portal and your loginLegitimate interest in operating the service (Art. 6(1)(f))
Security, abuse prevention, incident response, audit loggingLegitimate interest (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c))
Provide support you requestLegitimate interest / performing the support request (Art. 6(1)(f)/(b))

We do not use product-analytics or advertising trackers in the Portal (see section 9).

5. Sub-processors and hosting

The Portal runs on the same infrastructure as the platform:

Sub-processorRoleNote
AWSHosting, storage, backupsEU region eu-central-1 (Frankfurt, Germany). Data is stored in the EU.
Amazon SESTransactional email (e.g. account emails)EU region eu-central-1 (Frankfurt, Germany)

Keycloak (login) is self-hosted by Zoravet in the EU and is part of our own platform, not a third-party sub-processor. Push notifications (Firebase Cloud Messaging) are a feature of the pet-owner app, not of the Portal, which runs in a browser — no push-notification sub-processor applies here.

6. Retention

  • Work account: kept while you have access to the Portal; access is removed or deactivated when your clinic revokes it (for example, when you leave the clinic) through the Portal’s staff-management controls, or by Zoravet on the clinic’s request.
  • Audit/security logs: retained for 24 months, for security and accountability.
  • Support records: retained for 24 months.

7. Your rights

You have the GDPR rights of access, rectification, erasure, restriction, objection, and portability.

  • For data your clinic controls (your work account in the context of employment, clinical data), contact your clinic.
  • For data Zoravet controls (operational/security data about your Portal use), contact Zoravet at info@zoravet.nl.

You may also complain to the Autoriteit Persoonsgegevens (AP)www.autoriteitpersoonsgegevens.nl.

8. Security

Encryption in transit and at rest, strict tenant isolation between clinics, role-based access control, audit logging, and regular backups. Access to your data by Zoravet staff is limited to what is needed to operate and support the service. See the Security Statement for detail.

9. No analytics, no automated decisions, no sale

  • No third-party product-analytics or advertising trackers in the Portal. If this changes, this policy is updated first.
  • No automated decision-making with legal or similarly significant effects.
  • We do not sell personal data.

10. Changes and contact

We may update this policy; material changes will be communicated to clinic administrators.

  • Zoravet: Jensen Software, KvK 96526181, Oanjelaan 32, 1421 AK Uithoorn, Netherlands, info@zoravet.nl
  • Your clinic (your employer / controller): contact your clinic administrator