Data & Privacy

Privacy Policy

How we collect, use, store, and protect your personal and medical data

Effective Date: January 1, 2025
Last Updated: January 15, 2025
Version: 2.1.0

Individuals in the European Economic Area, United Kingdom and Switzerland can read this version of our Privacy Policy.

Introduction

Vetigen, Inc. (together with our affiliates, "Vetigen", "we", "our", or "us") respects your privacy and is committed to keeping the information we collect from you or about you secure.

This Privacy Policy explains our practices regarding the Personal Data we collect from you or about you when you use our website, applications, and services (collectively, "Services").

This Privacy Policy does not apply to content we process on behalf of business customers, such as our API. Our use of that data is governed by our customer agreements covering access to and use of those offerings.

Data Controller

The data controller of your personal data is:

Vetigen, Inc.

USA, DELAWARE

Email: privacy@vetigen.com

DPO: dpo@vetigen.com

Information We Collect

Personal Information

  • Name, surname, and title
  • Email address, phone number
  • Veterinary license number and diploma information
  • Clinic name, address, and tax information

Medical Data

  • Patient records (SOAP notes)
  • Laboratory test results and imaging data
  • Treatment plans and prescriptions
  • Vaccination records and health history

Usage Data

  • Platform usage activities and login logs
  • Device information (IP address, browser type)
  • Location data (city/country level)
  • Data collected through cookies and similar technologies

Financial Information

  • Payment card information (tokenized)
  • Billing address and tax ID
  • Payment transactions and invoice history

How We Collect Data

  • Direct Collection: Information you enter through registration forms, profile updates, and clinic management
  • Automated Collection: Through cookies, log files, and analytics tools
  • From Third Parties: Laboratory integrations, payment providers, and supplier systems

How We Use Data

  • Provide platform services and manage your account
  • Send you important notifications and support
  • Improve our services and develop new features
  • Ensure security, fraud prevention, and legal compliance
  • Comply with legal and regulatory requirements
  • Conduct usage analysis and performance measurement
  • Train and improve our AI models (with anonymized data)

Data Sharing

We do not share your personal data with third parties except in the following cases:

  • Service Providers: AWS (hosting), Stripe (payment), Twilio (communication), Sentry (error tracking)
  • Payment Processors: PCI-DSS compliant providers for secure payment processing
  • Legal Requests: Court orders, legal investigations, or regulatory requirements
  • Business Transfers: In case of merger, acquisition, or asset sale

All our third-party service providers are bound by strict data protection agreements.

International Data Transfers

Vetigen processes your Personal Data on servers located in various jurisdictions for the purposes described in this Privacy Policy. Our primary data center is AWS EU-Central-1 (Frankfurt, Germany).

As data protection laws vary from country to country, we apply the protections described in this policy for your Personal Data regardless of where they are processed, and only transfer in accordance with legally valid transfer mechanisms:

  • EU Commission adequacy decisions
  • Standard Contractual Clauses (SCC)
  • Binding Corporate Rules

Data Retention

We retain your personal data only as long as necessary:

  • Account Data: As long as account is active + 2 years
  • Medical Records: Legal retention period (10 years)
  • Financial Records: 10 years per tax law
  • Marketing Data: Until consent withdrawn or 3 years

Data Security

We use industry-standard measures to protect your data:

  • TLS 1.3 in transit, AES-256 encryption at rest
  • Role-based access control and multi-factor authentication
  • 24/7 security monitoring and threat detection
  • Daily automatic backups and disaster recovery plan
  • Incident response team and data breach notification procedures
  • Regular security training for employees

Your Rights

Depending on your location, you may have certain legal rights with respect to your Personal Data. For example, you may have the right to:

  • Right to Access: Request a copy of the data we process about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure (Right to be Forgotten): Request deletion of your data under certain conditions
  • Right to Restrict Processing: Request temporary suspension of data processing
  • Right to Data Portability: Receive your data in a structured, commonly used format
  • Right to Object: Object to processing based on legitimate interests
  • Automated Decision Making: Object to decisions based solely on automated processing
  • Withdraw Consent: Withdraw your consent at any time

To exercise your rights, email us at privacy@vetigen.com.

Cookies

Our website and platform use cookies.

For detailed information, please review our Cookie Policy.

Children's Privacy

Our services are not designed for individuals under 18 years old.

We do not knowingly collect data from persons under 18.

Policy Changes

We may update this privacy policy from time to time.

Significant changes will be notified via email.

Right to Complain

If you have concerns about our data processing, you can contact your local data protection supervisory authorities:

EU: European Data Protection Board (EDPB)

Website: https://edpb.europa.eu

Contact

For privacy-related questions:

Data Protection Officer

Email: dpo@vetigen.com

Privacy Team: privacy@vetigen.com

General Inquiries: legal@vetigen.com

For any questions or concerns regarding this policy, please contact us at legal@vetigen.com