01. Introduction and Privacy Commitment
At Vet Flows (“vetflows.com.br”, “we”, “us”, or “our”), we are committed to protecting the privacy, confidentiality, and security of personal data collected from veterinary professionals, clinics, and animal guardians.
This Privacy Policy describes how we process, store, and safeguard data in compliance with the Brazilian General Data Protection Law (LGPD - Law No. 13,709/2018), the European General Data Protection Regulation (GDPR - Regulation EU 2016/679), and relevant international data protection frameworks.
02. Data Roles: Controller vs. Processor
To provide transparency regarding data responsibilities, Vet Flows operates under two distinct legal capacities:
The veterinary clinic or individual practitioner is the Data Controller for all pet owner personal data (names, emails, phones, addresses) and patient clinical records entered into Vet Flows. The clinic determines the purposes and lawful bases for collecting patient and tutor information.
Vet Flows acts as a Data Processor on behalf of the clinic, securely storing, organizing, and transmitting diagnostic reports according to the clinic's instructions. For user account details (veterinarian login, CRMV, subscription billing), Vet Flows acts as Controller.
03. Personal Data We Collect
We process the following categories of data necessary to provide our diagnostic imaging and practice management platform:
- Veterinary Account Information: Full name, professional email address, encrypted password, CRMV / veterinary license number, clinic affiliation, profile avatar, and scanned professional signature.
- Pet Owner (Tutor) Data: Full name, contact telephone/WhatsApp, email address, physical address, and associated clinic records.
- Patient & Examination Data: Pet name, species, breed, sex, estimated age, microchip ID, neuter status, clinical history, uploaded ultrasound & X-ray imaging, DICOM metadata, and veterinary report findings.
- Billing & Subscription Data: Customer identifiers (Asaas / Stripe), billing history, and plan status. We never store credit card numbers directly; all payment card operations are handled directly by PCI-DSS certified payment processors.
- Technical & Usage Data: IP address, device type, browser specifications, session security cookies, and application audit logs.
04. Purposes and Legal Bases for Processing
We process personal data based on explicit legal grounds recognized under LGPD (Art. 7) and GDPR (Art. 6):
05. Third-Party Sub-processors and Sharing
We do not sell, rent, or trade personal data to third parties. Data is shared strictly with vetted infrastructure sub-processors necessary to operate Vet Flows:
- Cloudinary: Secure cloud storage, transformation, and distribution of diagnostic examination images.
- Resend: Reliable delivery of transactional emails and report notifications.
- Asaas / Stripe: PCI-DSS compliant processing of subscription payments and invoicing.
- PostgreSQL / Cloud Database: Encrypted persistent database hosting.
- Vercel: Global edge application delivery and serverless computing.
06. Data Retention and 5-Year Medical Records
In alignment with veterinary medical board mandates, Vet Flows maintains diagnostic imaging records and examination reports for a minimum archive period of 5 (five) years.
When a user terminates their account, they may request a full export of their clinic records. Inactive or deleted accounts undergo secure data purging according to statutory retention schedules and backup lifecycle policies.
07. Data Subject Rights (LGPD & GDPR)
Under LGPD (Art. 18) and GDPR (Art. 15-22), data subjects have the right to:
- Confirm the existence of data processing;
- Access and request a copy of their personal data;
- Correct incomplete, inaccurate, or outdated data;
- Request anonymization, blocking, or deletion of unnecessary data;
- Request data portability to another service provider;
- Revoke previously granted consent where applicable.
Requests can be submitted directly to our privacy team at contato@vetflows.com.br.
08. Information Security Measures
We deploy robust technical and organizational measures to safeguard data against unauthorized access, loss, or alteration:
- Encryption in Transit: All data transmitted between browsers and servers is encrypted using HTTPS and TLS 1.3.
- Multi-tenant Data Isolation: Strict tenant boundaries ensure data from one clinic cannot be accessed by another.
- Cryptographic Password Hashing: Passwords are protected using secure salted hashing algorithms.
- Automated Backups: Redundant database snapshots ensure business continuity and disaster recovery.
10. Contact and Data Protection Inquiries
If you have questions, feedback, or requests regarding this Privacy Policy or your personal data, please contact our Data Protection Officer / Privacy Team:
Questions or legal inquiries?
Contact our legal & privacy team at contato@vetflows.com.br