Privacy Policy
Effective date: April 1, 2025 — Last updated: April 1, 2025
1. Introduction
Tregovia is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our services.
This policy applies to all users of https://tregovia.com/, including veterinary clinics, medical practices, and service-based businesses.
Note for U.S. users: If you are a California resident, additional rights under the CCPA/CPRA may apply.
2. Data Controller
Tregovia
Privacy contact: legal@tregovia.com
3. What Personal Data We Collect
We collect the following categories of personal data:
- Account data: Name, email address, phone number, role, and login credentials.
- Billing data: Billing address, VAT/tax details, invoices, and payment status (processed via Stripe).
- Usage data: Logins, activity logs, device/browser metadata, and feature usage.
- Client/patient records: Data entered by tenants regarding their customers, patients, or pets.
- Communication data: Emails, support tickets, and chat messages with our team.
- Cookie/local storage data: Session data and saved preferences required for secure operation.
4. How Data Is Collected
- Registration forms: Information you submit when creating an account or updating profile and workspace settings.
- Automated collection: System logs and telemetry generated while using the platform.
- 9. Cookies & Local Storage: Cookies/local storage for authentication and preferences.
- Third-party services: Payment processors and communication providers required to deliver services.
5. Purpose & Legal Basis for Processing
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide and maintain the platform | Performance of a contract |
| Process subscriptions and payments | Performance of a contract; legal obligation |
| Customer support and account communication | Legitimate interests |
| Security monitoring and fraud prevention | Legitimate interests; legal obligation |
| Analytics and product improvements | Legitimate interests |
| Marketing emails (where applicable) | Consent (you can opt out anytime) |
6. Data Retention
- Account data: Retained while account is active and as needed for legal/accounting requirements.
- Audit logs/system logs: Retained for security, compliance, and incident response purposes.
- Billing records: Retained for statutory accounting and tax periods.
- Deleted accounts: Anonymized or deleted after required retention windows unless law requires longer storage.
- Tenant client/patient data: Controlled by tenant; export/delete options are available per policy and law.
7. Data Sharing with Third Parties
We do not sell personal data. We share data only with trusted processors necessary to operate the platform:
- Stripe — Payment processing and subscription billing.
- SMS provider — Delivery of SMS notifications when enabled.
- Cloud hosting provider — Infrastructure hosting and secure data storage in EU data centers.
- Legal authorities — Only when required by law, court order, or to protect legal rights.
All processors are bound by contractual data protection obligations.
Tenant data: acts as a data processor for tenant-submitted customer data; each tenant is the data controller for their records in Tregovia.
8. Your Rights
Under GDPR, you have the following rights:
- Right of access: Request a copy of your personal data.
- Right to rectification: Correct inaccurate or incomplete data.
- Right to erasure: Request deletion where legally permissible.
- Right to restriction: Request limited processing in specific cases.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Withdraw consent at any time for consent-based processing.
To exercise your rights, contact legal@tregovia.com.You may also lodge a complaint with your local supervisory authority.
9. Cookies & Local Storage
We use only essential cookies/local storage required for authentication, security, and core functionality.
- Authentication tokens: Used to keep you signed in securely.
- Preferences: Theme, language, and UI preferences.
- No third-party tracking cookies: We do not run third-party advertising trackers on core product pages.
You can clear cookies/local storage in your browser, but some functionality may stop working.
10. Data Security
We implement technical and organizational measures to protect personal data, including:
- Encrypted transport (HTTPS/TLS).
- Role-based access controls and least-privilege permissions.
- Tenant data isolation controls.
- Audit logging and monitoring.
- Regular backup and disaster recovery controls.
- Secure password hashing and authentication safeguards.
- Restricted production access and change controls.
No system is 100% secure, but we continuously improve safeguards and incident response processes.
11. International Data Transfers
Data is primarily stored and processed in the European Union. If transfers outside the EU/EEA occur, we apply appropriate safeguards such as Standard Contractual Clauses where required.
California residents (CCPA/CPRA): You may request disclosure, deletion, or correction rights by contacting legal@tregovia.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice. The "Last updated" date reflects the latest revision.
13. Contact Us
If you have questions about this Privacy Policy or data processing practices, contact us:
Tregovia — Data Protection
Email: legal@tregovia.com
Support: support@tregovia.com