Your information
Privacy notice
Version 2 · Effective 28 August 2026
This notice covers all of Tazain, not one feature. It says who processes your data, what is held, why, on what legal basis, for how long, and what you can do about it.
Who is responsible
Tazain is operated under the trading name Tazain. The registered entity name, jurisdiction and postal address are not yet published here; write to the privacy address below and we will send them to you.
For anything about your data, including a request to see, correct or delete it, write to . Acknowledged within five working days. Every other way to reach us is on the contact page.
What Tazain holds
Every category below corresponds to something the product actually stores. It is kept in step with Tazain’s internal data inventory, which is generated from the database models rather than written by hand.
| Category | What it contains | Where it comes from | How long it is kept |
|---|---|---|---|
| Account | Your email address, a hashed password or the fact that you signed in with Google, and whether your account is clinic staff or a Tazain operator. | Given by you when you register or sign in. | Kept while the account is active. Removed when you delete the account. |
| Sessions | Session and cross-site-request-forgery material that keeps you signed in. | Created when you sign in. | Expired sessions are pruned automatically; all are revoked on deletion. |
| Pet profiles | Name, species, breed, sex, date of birth, colour, identifying marks, and profile photo metadata. | Entered by you, or by someone you granted write access to. | Kept while you own the pet. Removed when you delete the account. |
| Health records | Vaccinations, medications, veterinary visits, weights, and the uploaded documents behind them. | Entered by you, or recorded by a clinic you granted access to. | Kept with the pet and removed when you delete the account — except records a clinic authored, which are retained as clinical history with your and your pet’s references removed. |
| Care tasks and reminders | The care needs you create and the reminders Tazain generates from them. | Created by you, or derived from a record you added. | Kept with the pet; removed when you delete the account. |
| Appointments | Appointment requests, their status history, and which clinic and pet each one concerns. | Created when you request an appointment or a clinic responds. | Retained as the audit trail for the appointment, with your reference removed when you delete the account. |
| Sharing grants | Who you shared a pet with, which scopes you granted, why, and when the access expires. | Created when you invite someone to a pet’s trusted circle. | Pruned after expiry; revoked when you delete the account. |
| Clinic membership and consent | Which clinics you are staff of, and the consent you gave a clinic to see a pet’s records. | Created when you register or join a clinic, or grant a clinic access. | Kept as the consent record; your side is removed when you delete the account. |
| Notification history | In-app notifications Tazain has delivered to you. | Generated by care reminders, appointments and access changes. | Read notifications are pruned after the retention window. |
| Audit records | Records of clinic access, privacy operations and appointment changes, so a disputed access can be answered. | Written automatically when an access or change happens. | Retained as immutable audit history, with the actor and subject references removed when you delete the account. |
Deleting your account applies each category’s rule above. Records a clinic authored are retained as clinical history with your and your pet’s references removed, because a clinic’s own record of care it gave is not yours to erase. If you are the only administrator of a clinic, you will be asked to transfer that clinic before the account can be deleted.
Why, and on what legal basis
| Purpose | Legal basis | Why this basis |
|---|---|---|
| Running your account and the features you use | Performance of a contract | Tazain cannot hold a pet profile, a care record or an appointment for you without processing it. |
| Keeping accounts and pet records secure | Legitimate interests | Session protection, rate limiting and access auditing exist so one account cannot reach another’s records. |
| Sending care reminders and in-app notifications | Performance of a contract | Telling you what a pet needs next is the feature you signed up for. |
| Sharing a pet’s records with a clinic or a caregiver | Consent | Nothing is shared until you grant it, and withdrawing the grant ends the access. |
| Finding clinics near a location you choose | Consent | Device location is used only after you select it, for that one search, and is never stored. |
| Measuring how the public pages are used | Consent | Off until you allow it, and it never carries a pet name, a record, a contact value or a coordinate. |
| Answering a legal or regulatory request | Legal obligation | Where the law requires Tazain to retain or disclose something. |
Nearby Vets and location
Nearby Vets asks for device location only after you select “Use my current location.” The browser rounds the coordinates to roughly 110 metres before putting them in the request URL. Tazain uses that location for the current search and does not save it to your profile, browser storage, or database. You can enter a locality or PIN code instead.
A rounded coordinate or the locality you type is sent to Google Maps Platform through the Places API to return clinic information. No Tazain account identifier, pet record, or clinic record is included in that provider request. Google processes this information under the Google Privacy Policy.
Nearby Vets search results and locations are not persisted by Tazain. Reloading the page starts a new location choice. You may decline browser location and use the manual locality search, or avoid Nearby Vets entirely without affecting the rest of Tazain.
Who else processes your data
Tazain does not sell personal data and does not share it for advertising. These are the companies that process it on Tazain’s behalf in order to run the service.
| Processor | Role | Region |
|---|---|---|
| Neon | Managed PostgreSQL hosting — the database every record above lives in. | European Union |
| Vercel | Application and API hosting, including request logs. | Global edge network, with the API region pinned to the European Union |
| Google Maps Platform | Clinic information for Nearby Vets, from a rounded coordinate or a locality you type. | Global |
Tazain’s database is hosted in the European Union. Where a processor operates outside it — a global edge network, or a Google Maps request — the transfer relies on the processor’s standard contractual clauses, and no Tazain account identifier, pet record or health record is included in a Maps request.
Your rights
You can ask Tazain to:
- tell you what personal data it holds about you, and give you a copy of it;
- correct anything that is wrong;
- delete your account and the data that belongs to it;
- restrict or object to a particular use;
- withdraw a consent you gave, including sharing and optional analytics;
- send your data to you in a portable form.
Account export and deletion are available in the product. For anything else, write to . If you are not satisfied with the response, you have the right to complain to your national data protection authority.
If something goes wrong
If you believe Tazain has exposed data, or you have found a vulnerability, write to . Acknowledged within one working day. Please do not include anyone else’s personal data in the report.
Changes to this notice
This notice carries a version and an effective date. A change that widens what is collected, why, or who it is shared with is announced in the product before it takes effect, and any consent given under an earlier version is asked for again rather than assumed.
Version 2, effective 28 August 2026. Read the terms of use for the agreement between you and Tazain, or the contact page for every way to reach us.