Skip to main content

Privacy Policy

How FurDrive may handle personal information and pet records.

FurDrive is an owner-controlled pet health-record vault. This policy explains the personal information involved in operating the service and the choices available to account owners.

Document status

Effective 27 August 2026

VetWise Limited, New Zealand publishes this policy. Use the support and privacy-choice routes for privacy questions and requests. GDPR representative and Data Protection Officer details will be published when those appointments are legally required.

Scope, controller, and GDPR applicability

This policy covers the FurDrive website, signed-in vault, installable web app, uploads, processing, exports, sharing, billing, support, and related services. VetWise Limited provides FurDrive and acts as controller where it determines why and how personal information is processed.

GDPR does not apply merely because a New Zealand service is reachable from Europe. VetWise Limited assesses Article 3 for EEA offerings and monitoring, will appoint and publish an Article 27 EU representative where required, and assesses the need for a Data Protection Officer under Articles 37 to 39.

Data-protection principles

Where GDPR applies, FurDrive must process personal data lawfully, fairly, and transparently; use it only for specified purposes; minimise collection; keep it accurate; limit retention; protect confidentiality, integrity, and availability; and be able to demonstrate accountability. Privacy by design and by default must be applied to product and operational decisions.

Information and sources

  • Account identity, authentication, workspace, role, invitation, consent, preference, and support information.
  • Pet profiles and owner-held files, record metadata, notes, vaccination, medication, laboratory, imaging, insurer, and microchip details.
  • Extracted text, classifications, structured fields, indexes, processing and review state, and provider metadata when processing is eligible.
  • Sharing, clinic requests, proof packs, grants, recipients, downloads, expiry, revocation, and audit events.
  • Storage, credits, entitlements, subscriptions, transactions, notifications, device state, security, exports, and deletion information.

Information may come from the account holder, an authorised member, an invited clinic or recipient, user-directed files or messages, providers, and normal service activity. When information is not obtained from the person concerned, Article 14 notice duties must be assessed.

Purposes and lawful bases

Where GDPR applies, the current Article 6 mapping is:

PurposeLawful basis where GDPR applies
Create accounts, store records, provide owner-directed processing, export, sharing, and paid features.Performance of a contract or steps requested before entering one.
Secure accounts, prevent abuse, investigate failures, maintain proportionate audits, and improve reliability.Legitimate interests, subject to a documented necessity and balancing assessment; legal obligation where specifically applicable.
Billing, tax, disputes, regulatory requests, and lawful records.Contract, legal obligation, or legitimate interests as documented for the purpose.
Optional marketing, non-essential tracking, or another consent-based feature.Freely given, specific, informed, unambiguous consent that is as easy to withdraw as to give.

Consent is not bundled into service acceptance when processing is not necessary for the service. FurDrive documents the legitimate interests relied on for relevant processing.

Sensitive and third-party information

Pet health information is not automatically human health data under GDPR, but files can contain personal information about owners, clinicians, staff, or other people and can incidentally include special-category human data. FurDrive must minimise that information and document an Article 9 condition before intentionally processing special-category personal data. A user supplying another person's data must have authority and provide any required notice.

OCR, AI, and automated decisions

Eligible welcome credits or an active Intelligence membership can enable automated extraction and organisation. Basic is a processing depth, not a subscription. Vault continues without ongoing automatic processing after eligible welcome credits end.

Outputs may be incomplete or wrong; the original source file remains the source of truth. FurDrive does not use these tools to make solely automated decisions that produce legal or similarly significant effects about a person. Any future significant automated decision or profiling would require an Article 22 assessment, meaningful information about the logic and consequences, and applicable human-review rights.

Sharing, processors, and international transfers

Owners may deliberately share selected material through released features. Revoking FurDrive access cannot retrieve a copy independently held by a clinic or recipient.

Providers acting for FurDrive must be governed by Article 28 terms where GDPR applies. The provider register must list only active production providers. Transfers from the EEA require a documented Chapter V mechanism and, where appropriate, a transfer impact assessment and supplementary measures.

Retention, export, and deletion

Information must be retained only for approved periods or criteria tied to purpose, security, accounting, disputes, legal duties, and permitted backups. Final publication requires a category-specific schedule and deletion evidence.

File Trash, permanent purge, export, membership cancellation, offline copies, recipient copies, and full personal workspace closure are different. Review account deletion status. Erasure is not absolute where a lawful retention ground applies.

Security, breaches, and impact assessment

FurDrive must use appropriate technical and organisational measures based on risk, maintain a breach-response record, and assess notification duties. Where GDPR applies, a reportable breach must be notified to the competent supervisory authority without undue delay and, where feasible, within 72 hours; high-risk affected people must also be informed unless an exception applies. A DPIA must be completed before processing likely to create high risk, and residual unmitigated high risk requires prior supervisory consultation.

GDPR rights where applicable

A person may have rights to information, access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and safeguards relating to automated decisions. Requests must be supported electronically, identity may be proportionately verified, and a response is generally due without undue delay and within one month. A refusal must explain the reason, supervisory-authority complaint right, and judicial-remedy right. Rights can be limited by law and the rights of others.

Children

FurDrive is not directed to children and expects an adult to control permitted use involving a young person. Before any EEA launch involving a child's consent to an information-society service, Article 8 and applicable Member State age rules must be assessed and appropriate verification designed.

Contact, complaints, and changes

The operative notice must publish controller details, a verified privacy route, the DPO and EU representative where required, retention information, applicable supervisory authority, and effective date. Material changes require proportionate notice and a new affirmative choice where consent is required. No unverified inbox is presented as working in this draft.

FurDrive keeps this information separate from veterinary records. These pages describe the service; they do not interpret a pet's health information.

Effective 27 August 2026

Privacy | FurDrive