Scope, controller, and GDPR applicability
This policy covers the FurDrive website, signed-in vault, installable web app, uploads, processing, exports, sharing, billing, support, and related services. VetWise Limited provides FurDrive and acts as controller where it determines why and how personal information is processed.
GDPR does not apply merely because a New Zealand service is reachable from Europe. VetWise Limited assesses Article 3 for EEA offerings and monitoring, will appoint and publish an Article 27 EU representative where required, and assesses the need for a Data Protection Officer under Articles 37 to 39.
Data-protection principles
Where GDPR applies, FurDrive must process personal data lawfully, fairly, and transparently; use it only for specified purposes; minimise collection; keep it accurate; limit retention; protect confidentiality, integrity, and availability; and be able to demonstrate accountability. Privacy by design and by default must be applied to product and operational decisions.
Information and sources
- Account identity, authentication, workspace, role, invitation, consent, preference, and support information.
- Pet profiles and owner-held files, record metadata, notes, vaccination, medication, laboratory, imaging, insurer, and microchip details.
- Extracted text, classifications, structured fields, indexes, processing and review state, and provider metadata when processing is eligible.
- Sharing, clinic requests, proof packs, grants, recipients, downloads, expiry, revocation, and audit events.
- Storage, credits, entitlements, subscriptions, transactions, notifications, device state, security, exports, and deletion information.
Information may come from the account holder, an authorised member, an invited clinic or recipient, user-directed files or messages, providers, and normal service activity. When information is not obtained from the person concerned, Article 14 notice duties must be assessed.
Purposes and lawful bases
Where GDPR applies, the current Article 6 mapping is:
| Purpose | Lawful basis where GDPR applies |
|---|---|
| Create accounts, store records, provide owner-directed processing, export, sharing, and paid features. | Performance of a contract or steps requested before entering one. |
| Secure accounts, prevent abuse, investigate failures, maintain proportionate audits, and improve reliability. | Legitimate interests, subject to a documented necessity and balancing assessment; legal obligation where specifically applicable. |
| Billing, tax, disputes, regulatory requests, and lawful records. | Contract, legal obligation, or legitimate interests as documented for the purpose. |
| Optional marketing, non-essential tracking, or another consent-based feature. | Freely given, specific, informed, unambiguous consent that is as easy to withdraw as to give. |
Consent is not bundled into service acceptance when processing is not necessary for the service. FurDrive documents the legitimate interests relied on for relevant processing.
Sensitive and third-party information
Pet health information is not automatically human health data under GDPR, but files can contain personal information about owners, clinicians, staff, or other people and can incidentally include special-category human data. FurDrive must minimise that information and document an Article 9 condition before intentionally processing special-category personal data. A user supplying another person's data must have authority and provide any required notice.
OCR, AI, and automated decisions
Eligible welcome credits or an active Intelligence membership can enable automated extraction and organisation. Basic is a processing depth, not a subscription. Vault continues without ongoing automatic processing after eligible welcome credits end.
Outputs may be incomplete or wrong; the original source file remains the source of truth. FurDrive does not use these tools to make solely automated decisions that produce legal or similarly significant effects about a person. Any future significant automated decision or profiling would require an Article 22 assessment, meaningful information about the logic and consequences, and applicable human-review rights.
Retention, export, and deletion
Information must be retained only for approved periods or criteria tied to purpose, security, accounting, disputes, legal duties, and permitted backups. Final publication requires a category-specific schedule and deletion evidence.
File Trash, permanent purge, export, membership cancellation, offline copies, recipient copies, and full personal workspace closure are different. Review account deletion status. Erasure is not absolute where a lawful retention ground applies.
Security, breaches, and impact assessment
FurDrive must use appropriate technical and organisational measures based on risk, maintain a breach-response record, and assess notification duties. Where GDPR applies, a reportable breach must be notified to the competent supervisory authority without undue delay and, where feasible, within 72 hours; high-risk affected people must also be informed unless an exception applies. A DPIA must be completed before processing likely to create high risk, and residual unmitigated high risk requires prior supervisory consultation.
GDPR rights where applicable
A person may have rights to information, access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and safeguards relating to automated decisions. Requests must be supported electronically, identity may be proportionately verified, and a response is generally due without undue delay and within one month. A refusal must explain the reason, supervisory-authority complaint right, and judicial-remedy right. Rights can be limited by law and the rights of others.
Children
FurDrive is not directed to children and expects an adult to control permitted use involving a young person. Before any EEA launch involving a child's consent to an information-society service, Article 8 and applicable Member State age rules must be assessed and appropriate verification designed.
Contact, complaints, and changes
The operative notice must publish controller details, a verified privacy route, the DPO and EU representative where required, retention information, applicable supervisory authority, and effective date. Material changes require proportionate notice and a new affirmative choice where consent is required. No unverified inbox is presented as working in this draft.