Privacy Policy

Effective date: April 1, 2025Last updated: April 1, 2025

1. Introduction

Tregovia is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our services.

This policy applies to all users of https://tregovia.com/, including veterinary clinics, medical practices, and service-based businesses.

Note for U.S. users: If you are a California resident, additional rights under the CCPA/CPRA may apply.

2. Data Controller

Tregovia

Privacy contact: legal@tregovia.com

3. What Personal Data We Collect

We collect the following categories of personal data:

  • Account data: Name, email address, phone number, role, and login credentials.
  • Billing data: Billing address, VAT/tax details, invoices, and payment status (processed via Stripe).
  • Usage data: Logins, activity logs, device/browser metadata, and feature usage.
  • Client/patient records: Data entered by tenants regarding their customers, patients, or pets.
  • Communication data: Emails, support tickets, and chat messages with our team.
  • Cookie/local storage data: Session data and saved preferences required for secure operation.

4. How Data Is Collected

  • Registration forms: Information you submit when creating an account or updating profile and workspace settings.
  • Automated collection: System logs and telemetry generated while using the platform.
  • 9. Cookies & Local Storage: Cookies/local storage for authentication and preferences.
  • Third-party services: Payment processors and communication providers required to deliver services.

5. Purpose & Legal Basis for Processing

PurposeLegal basis (GDPR Art. 6)
Provide and maintain the platformPerformance of a contract
Process subscriptions and paymentsPerformance of a contract; legal obligation
Customer support and account communicationLegitimate interests
Security monitoring and fraud preventionLegitimate interests; legal obligation
Analytics and product improvementsLegitimate interests
Marketing emails (where applicable)Consent (you can opt out anytime)

6. Data Retention

  • Account data: Retained while account is active and as needed for legal/accounting requirements.
  • Audit logs/system logs: Retained for security, compliance, and incident response purposes.
  • Billing records: Retained for statutory accounting and tax periods.
  • Deleted accounts: Anonymized or deleted after required retention windows unless law requires longer storage.
  • Tenant client/patient data: Controlled by tenant; export/delete options are available per policy and law.

7. Data Sharing with Third Parties

We do not sell personal data. We share data only with trusted processors necessary to operate the platform:

  • StripePayment processing and subscription billing.
  • SMS providerDelivery of SMS notifications when enabled.
  • Cloud hosting providerInfrastructure hosting and secure data storage in EU data centers.
  • Legal authoritiesOnly when required by law, court order, or to protect legal rights.

All processors are bound by contractual data protection obligations.

Tenant data: acts as a data processor for tenant-submitted customer data; each tenant is the data controller for their records in Tregovia.

8. Your Rights

Under GDPR, you have the following rights:

  • Right of access: Request a copy of your personal data.
  • Right to rectification: Correct inaccurate or incomplete data.
  • Right to erasure: Request deletion where legally permissible.
  • Right to restriction: Request limited processing in specific cases.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests.
  • Right to withdraw consent: Withdraw consent at any time for consent-based processing.

To exercise your rights, contact legal@tregovia.com.You may also lodge a complaint with your local supervisory authority.

9. Cookies & Local Storage

We use only essential cookies/local storage required for authentication, security, and core functionality.

  • Authentication tokens: Used to keep you signed in securely.
  • Preferences: Theme, language, and UI preferences.
  • No third-party tracking cookies: We do not run third-party advertising trackers on core product pages.

You can clear cookies/local storage in your browser, but some functionality may stop working.

10. Data Security

We implement technical and organizational measures to protect personal data, including:

  • Encrypted transport (HTTPS/TLS).
  • Role-based access controls and least-privilege permissions.
  • Tenant data isolation controls.
  • Audit logging and monitoring.
  • Regular backup and disaster recovery controls.
  • Secure password hashing and authentication safeguards.
  • Restricted production access and change controls.

No system is 100% secure, but we continuously improve safeguards and incident response processes.

11. International Data Transfers

Data is primarily stored and processed in the European Union. If transfers outside the EU/EEA occur, we apply appropriate safeguards such as Standard Contractual Clauses where required.

California residents (CCPA/CPRA): You may request disclosure, deletion, or correction rights by contacting legal@tregovia.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice. The "Last updated" date reflects the latest revision.

13. Contact Us

If you have questions about this Privacy Policy or data processing practices, contact us:

TregoviaData Protection

Email: legal@tregovia.com

Support: support@tregovia.com