Legal

Privacy Policy

Version 2025-05-12. Last updated: 2025-05-12.

1. Data Controller

Veterinary Cabinet Arvanitis Georgios DVM
Evripidou 59-61, Piraeus 18532
Tel.: 210 410 0900 · Email: gioarvdv@gmail.com

We respect your personal data and process your information in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Greek law 4624/2019.

2. What data we collect

  • Identification & contact details: full name, phone, email, address.
  • Pet details: name, species, breed, gender, date of birth, microchip.
  • Pet medical data: visit history, diagnoses, treatments, vaccinations, deworming, prescriptions, lab tests, X-rays and other attachments.
  • Account data: password (encrypted), notification preferences.
  • Technical data: IP address and user-agent at the time of consent (for documentation only).

3. Purposes & legal basis

  • Provision of veterinary services (appointments, medical records, prescriptions): performance of a contract (Art. 6(1)(b) GDPR) and your explicit consent for pet health data combined with your personal details.
  • Legal obligations (tax, vaccination registry, reports to authorities): Art. 6(1)(c) GDPR.
  • Email reminders & updates: only after your explicit consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
  • Communication & customer support: legitimate interest (Art. 6(1)(f) GDPR).

4. Retention period

We retain pet medical data for as long as you maintain a relationship with the clinic and for at least 5 years after the last visit, in line with veterinary practice. Tax records are kept for 10 years. Data collected with consent are deleted as soon as you withdraw it, unless another legal basis for retention applies.

5. Recipients of data

  • Processor: Lovable Cloud (cloud infrastructure provider, with data stored on EU-based servers).
  • Email provider: for sending reminders & confirmations (only if you have consented).
  • Public authorities: where required by law (tax authority, EOF, veterinary authorities).
  • We never sell your data to third parties.

6. Transfers outside the EU

We do not transfer data outside the European Economic Area, unless required by our infrastructure (cloud) providers and always with appropriate safeguards (Standard Contractual Clauses).

7. Your rights

Under the GDPR you have the following rights:

  • Access to your data (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure / "right to be forgotten" (Art. 17)
  • Restriction of processing (Art. 18)
  • Portability — export your data in a readable format (Art. 20)
  • Objection to processing (Art. 21)
  • Withdrawal of consent at any time
  • Lodge a complaint with the Hellenic Data Protection Authority

From the "My account" page you can export your data or request deletion. Alternatively, contact us at gioarvdv@gmail.com.

8. Security

Your data is stored encrypted (at rest & in transit). We enforce strict access permissions (Row-Level Security): each customer can only see their own data.

9. Cookies

We use only strictly necessary cookies for the operation of the app (session & login). See the Cookies Policy.

10. Changes to this policy

We update this policy when needed. In case of material changes, you will be asked for renewed consent at your next sign-in.