Juridisch

Privacy Policy — Zoravet Admin Portal (Clinic Staff)

Laatst bijgewerkt: 12 August 2026 · Versie 1.2

1. Who this is for

This policy is for staff members of a veterinary clinic who use the Zoravet admin portal (“the Portal”) to run the clinic — managing clients, pets, dossiers, appointments, messages, and billing.

It explains how Jensen Software (“Zoravet”) handles your personal data as a portal user. How the clinic and Zoravet handle client and pet data is covered by the app privacy policy and the data processing agreement (DPA) between Zoravet and your clinic.

2. The two roles, briefly

  • Your employer (the clinic) is the controller for your work-account data as it relates to running the practice, and for all client/pet/clinical data you process in the Portal — including bank transaction data (counterparty names, IBANs, payment references of third parties) imported for bookkeeping and reconciliation. Zoravet is the processor for that data, acting on the clinic’s instructions.
  • Zoravet is the controller for a minimal set of operational data it needs to provide, secure and support the Portal as a product (see section 4).

If you have questions about how your employer uses your work data, contact your clinic. For the operational data Zoravet controls, contact Zoravet (section 7).

3. What data we handle about you

CategoryExamples
Work account & identityName, work email, role/permissions, login credentials (via our identity system)
Usage & auditRecords of actions you take in the Portal (e.g. who edited a dossier, when), login history
Security & technicalIP address, device/browser type, session data, error and security logs
SupportInformation you provide when contacting support

The Portal is a professional tool. Please do not enter personal data about yourself beyond what your role requires.

4.1 Clinic-controlled (Zoravet is processor)

PurposeBasis
Give you access to run the clinic’s operationsThe clinic’s instruction under our DPA; clinic’s legitimate interest / contract
Maintain audit trails of who did what (accountability, tenant isolation)Clinic’s legitimate interest and legal obligations as controller

4.2 Zoravet-controlled (Zoravet is controller)

PurposeBasis (GDPR Art. 6)
Provide, secure and maintain the Portal and your loginLegitimate interest in operating the service (Art. 6(1)(f))
Security, abuse prevention, incident response, audit loggingLegitimate interest (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c))
Provide support you requestLegitimate interest / performing the support request (Art. 6(1)(f)/(b))

We do not use product-analytics or advertising trackers in the Portal (see section 9).

5. Sub-processors and hosting

The Portal runs on the same infrastructure as the platform:

Sub-processorRoleNote
AWS (Amazon Web Services EMEA SARL)Cloud infrastructure: compute, storage, backups, transactional email (e.g. account emails), secretsEU regions — primary Frankfurt (Germany), backup Ireland. Data stays in the EU/EEA.
Mollie B.V.Payment processing (pay-by-link for clinic invoices, initiated from the Portal)Netherlands. Planned, not yet active. Hosted checkout only — no card/payment-card data touches our servers. Each clinic uses its own Mollie account; Mollie settles funds directly to the clinic. Will be added here with advance notice before activation.

Our login/identity service is self-hosted by Zoravet in the EU and is part of our own platform, not a third-party sub-processor. GitHub is used for source code and CI only; no clinic personal data flows through it.

The Portal does not send mobile push notifications — that is an app-only feature, delivered via Google Firebase Cloud Messaging and disclosed in the app privacy policy. The Portal does not currently send browser push notifications either.

6. Retention

  • Work account: kept while you have access; removed or deactivated when your clinic revokes access to the Portal or you leave the clinic.
  • Audit/security logs: retained for 24 months, for security and accountability.
  • Support records: retained for 24 months.

7. Your rights

You have the GDPR rights of access, rectification, erasure, restriction, objection, and portability.

  • For data your clinic controls (your work account in the context of employment, clinical data), contact your clinic.
  • For data Zoravet controls (operational/security data about your Portal use), contact Zoravet at support@zoravet.nl.

You may also complain to the Autoriteit Persoonsgegevens (AP)www.autoriteitpersoonsgegevens.nl.

8. Security

Zoravet protects Portal data with technical and organisational measures, including:

  • Hosting with a leading cloud provider in EU (EEA) data centres, with backups replicated to a second EU region.
  • Encryption in transit (TLS) and at rest.
  • A managed, highly-available database service, with automated backups and point-in-time recovery, geo-redundant within the EU; recovery procedures are tested periodically.
  • Continuous automated monitoring and alerting.
  • Centralised, role-based, least-privilege access control, with strict per-tenant (per-clinic) isolation that fails closed and audit logging of Portal actions; our cross-tenant isolation controls have been independently reviewed. Access to your data by Zoravet staff is limited to what is needed to operate and support the service, and Zoravet personnel are bound by confidentiality obligations.
  • A dedicated identity and access-management system; multi-factor authentication is supported and can be required, though it is not yet enforced platform-wide by policy.
  • A web application firewall protects our services, and internal systems run in private networks.
  • Changes are deployed via automated pipelines with automatic rollback, and production deployments are gated by a manual approval step.

No system is perfectly secure. Zoravet is an early-stage, single-operator business: we do not run a 24/7 security operations centre or on-call rotation, and we do not currently hold formal security certifications (e.g. ISO 27001, SOC 2) — we align our practices with recognised security frameworks proportionate to our size.

In the event of a personal data breach affecting Portal data, Zoravet (as processor) will notify the affected clinic (as controller) without undue delay and within 48 hours of becoming aware, so the clinic can meet its own 72-hour notification duty to the Autoriteit Persoonsgegevens. You can reach our security team at security@zoravet.nl.

More detail on our security and compliance posture is available in the Security Statement.

9. No analytics, no automated decisions, no sale

  • No third-party product-analytics or advertising trackers in the Portal. If this changes, this policy is updated first.
  • No automated decision-making with legal or similarly significant effects.
  • We do not sell personal data.

10. Changes and contact

We may update this policy; material changes will be communicated to clinic administrators.

  • Zoravet: Jensen Software, KvK 96526181, Oanjelaan 32, 1421 AK Uithoorn, Netherlands, support@zoravet.nl
  • Security / data-breach contact: security@zoravet.nl
  • Your clinic (your employer / controller): contact your clinic administrator — your clinic’s own contact details are recorded in your employer’s records, not in this platform-wide document.