Privacy Policy

Last updated: 2019-12-10

PRIVACY POLICY

ONLINEVET 247 UK LTD (FirstVet)

1. Introduction

    1. Onlinevet 247 UK Ltd (trading as FirstVet) (the "Company", "we", "us" or "our") respects your privacy and is committed to treating any information that we obtain about you with as much care as possible and in a manner that is compliant with all applicable data protection legislation including the EU General Data Protection Regulation 2016/679 ("GDPR") and any national implementing laws in relation to the same including the Data Protection Act 2018 (collectively, "Data Protection Legislation").
    2. We have appointed Joakim Widigs as our data protection officer (DPO). If you have any questions about this privacy policy, please contact us by using the details provided in paragraph 1.6.
    3. Please read this data protection and privacy policy (the "policy") carefully. Among other things, it explains:
      1. what personal data we may collect about you in connection with:
        1. providing you with our goods and services;
        2. your online interaction with us (including via the FirstVet website at https://firstvet.com/uk/ and the FirstVet mobile application or any other website and apps we own/operate; and
        3. any other interaction between you and us through any other channels related or ancillary to the foregoing (including via telephone, social media or through our partners and affiliates),

(collectively, the "Channels");

      1. how we collect, store, disclose, transfer, protect and otherwise process that personal data (and for what purposes); and
      2. other important information, such as the lawful basis or bases by which we process your personal data, how long we retain your personal data, and the rights you have in relation to the personal data we hold about you.
    1. This policy supplements (and its terms apply in addition to) any other terms of use or other terms and conditions agreed between you and the Company from time to time , including our Terms of Service.
    2. In this policy, terms defined in the GDPR, including "data subject", "personal data", and "processing", have the same meaning when used in this policy. The words "include", "including", "such as" and similar words and phrases shall be construed to mean "including without limitation".
    3. This policy is intended to be communicated to you in a concise, transparent, intelligible and easily accessible manner, but we appreciate that you may have queries or want to seek clarification as to its terms. If so, please email support@firstvet.co.uk or write to Data Protection Enquiries, FirstVet Fox Court, Gray's Inn Road, London, England, WC1X 8HN and we will endeavour to respond as soon as possible.
    4. The Company reserves the right to make changes to this policy from time to time including as may be necessary or desirable to reflect any changes in: (i) the ways in which we gather and process personal data; (ii) Data Protection Legislation; or (iii) best practice. The Company will endeavour to notify you of such changes but you are advised to check for an updated version of this policy at https://firstvet.com/uk/privac... each time you interact with us through the Channels.
    5. It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

2. The personal data we process

    1. We collect personal data about you through the Channels when you:
      1. access and use our the FirstVet Websites or Mobile applications or other Channels (including automatically by way of cookies or similar technologies – please refer to paragraph 12 below for more information);
      2. register for an account on our websites, apps or other Channels, or subscribe for or participate in other services, competitions, contests, special events, or our mailing list;
      3. contact us (whether in writing, by email, by telephone or otherwise), including via any contact form available on the Channels;
      4. make any enquiry or application with respect to careers, vacancies or opportunities at the Company;
      5. purchase, request or subscribe for a product or service from us;
      6. request technical support or other customer care support;
      7. participate in polls, surveys and questionnaires on or related to the Channels;
      8. post content on our social media pages or such other Channels which provide for user-generated content; or
      9. otherwise interact with us through the Channels.
    2. Where lawful, we may also obtain personal data from third parties or public sources (for example, the open electoral register or credit reference agencies) and we may process that information where it is an essential component of the products and services we offer you.
    3. The type of personal data we process may include (if and as applicable):
      1. technical data including the information obtained through the use of cookies when you use the site (please refer to paragraph 12 below for more information) ("Technical Data");
      2. identity and contact information, such as your name, user name, email address, postal address, date of birth, telephone number and other information provided by you when you register for an account on our Channels or subscribe for other services, contests, special events or our mailing list ("Identity and Contact Data");
      3. information which you provide in any correspondence with us ("Correspondence Data");
      4. if you enquire or apply for any vacancies or opportunities at the Company, your CV, résumé, educational background, employment history and any other information you provide in connection with the same ("CV Data");
      5. in relation to any veterinary consultations booked by you, your booking details, insurance number, your device details, any images you upload via our app, records of any video calls with us, your pet's data details (name, species, breed, DOB, pet health details including veterinary medical records of any consultations conducted as part of FirstVet’s core service), payment information, preferences and other transaction information provided or obtained in connection with such booking or other similar product or service you have requested, bought or subscribed for ("Product and Service Data");
      6. your responses to any polls, surveys and questionnaires we may run from time to time ("Response Data");
      7. marketing and communications data, which includes your preferences in receiving marketing from us and our third parties and your communication preferences ("Marketing and Communications Data");
      8. any personal data contained in content you post on our social media pages, any reviews you post directly on our Channels (or via Trustpilot) or otherwise through posting any user-generated content ("User-Generated Data"); and
      9. information ascertained by your interaction with us through the Channels, including your interests and purchase/consultation history ("Transaction Data").
    4. We do not process:
      1. any special categories of personal data (including details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data);
      2. any information about criminal convictions and offences; or
      3. any information about individuals under the age of 18, and you should not provide us with any such information through any of the Channels.

3. Personal data being processed

    1. We sometimes obtain personal data from our commercial partners that you have agreed with them that may share with us, such as:
    2. via Google, further information of their use of data can be seen here: https://policies.google.com/privacy?hl=en;
    3. via Facebook, further information of their use of data can be seen here: https://www.facebook.com/legal/FB_Work_Privacy;
    4. via Trustpilot, further information of their use of data can be seen here: https://uk.legal.trustpilot.com/end-user-privacy-terms; and
    5. via Mailchimp, further information of their use of data can be seen here: https://mailchimp.com/legal/privacy/.

4. The purposes for which we process your personal data

    1. We use the personal data referred to in paragraph 2 above for the purposes of (if and as applicable):
      1. personalising content on the Channels;
      2. sending you promotional and marketing materials, notifications, updates and exclusive news;
      3. providing you with access to our products and services and fulfilling orders for products and/or services (including by arranging and facilitating veterinary consultations);
      4. to process payments (or to reclaim fees through your insurer) and validate insurance coverage;
      5. internal training and other internal uses to improve our services and customer experience (including improving our marketing and promotional efforts, analysing channel usage statistics, improving content and product offerings and customising the content and layout of our stores and Channels);
      6. responding to any correspondence from you including enquiries, comments, complaints and requests for technical assistance;
      7. if your data was provided in connection with a career opportunity or vacancy, assessing your fitness and eligibility for any particular role;
      8. administering any polls, services, questionnaires, competitions, contests, or special events which you may have subscribed for or participated in;
      9. recording your purchase, booking or usage history and administering your account with us;
      10. market research and demographic studies;
      11. complying with any legal obligation; and
      12. otherwise carrying out our business activities in circumstances where you ought reasonably to have an expectation that we will process your personal data for a particular purpose (including as may be provided for in any terms of use governing our website, our mobile apps or any other arrangement between us). We may also use anonymised data for statistical analysis and/or product development purposes. This data is anonymised and aggregated, meaning it can no longer be linked to you, either by us or by anyone else. This information no longer contains personal information.
    2. We may process your personal data for the purposes set out in paragraph 4.1 ourselves or in conjunction with our third party service providers (in accordance with paragraph 7).

5. The lawful bases by which we process your personal data

    1. Consent
      1. Generally, we do not rely on consent as a legal basis for processing your personal data. Occasionally, however, we will get your consent before sending marketing communications to you (e.g. via email or text message). If this policy has been communicated to you in relation to any such communications and you have consented to the same, then you give the Company your express, freely given consent to process any of your personal data in accordance with the terms of this policy for the purposes communicated to you at the time you gave that consent.
      2. If we do seek your consent, you may withdraw your consent at any time by following the unsubscribe link displayed at the bottom of each email. The withdrawal of your consent shall not affect the lawfulness of processing based on consent before withdrawal or the lawfulness of processing based on other lawful grounds as set out below.
    2. Other lawful grounds

The Company may process your personal data in any circumstances where such processing is necessary:

      1. in order to perform any agreement between us (including pursuant to our any terms of use governing our website or any other arrangement between us);
      2. to comply with any applicable law or regulation; or
      3. for the purposes of the legitimate interests pursued by us or third parties. These legitimate interests include the purposes identified above in paragraph 4.1 but also include other commercial interests and our internal administrative purposes.
    1. We may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data.
    2. More information about which lawful basis is used for which data processing activity is set out in the table below:

Purpose/Activity

Lawful basis for processing including basis of legitimate interest

To register you as a new customer or user

To enable you to make your pet's records available to you

(a) Performance of a contract with you

(b) Consent

To process and deliver any orders, subscriptions, or requested services including:

(a) Manage payments, fees and charges

(b) Collect and recover money owed to us

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to recover debts due to us)

(c) Consent

To process insurance data, insurance activation and validate insurance coverage

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to process insurance payments)

(c) Consent

To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or privacy policy

(b) Asking you to leave a review or take a survey

(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

(d) Consent

To enable you to partake in a prize draw, competition or complete a survey

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)

To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)

(b) Necessary to comply with a legal obligation

To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you

Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)

To use data analytics to improve our website, products/services, marketing, customer relationships and experiences

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)

To make suggestions and recommendations to you about goods or services that may be of interest to you

Necessary for our legitimate interests (to develop our products/services and grow our business)

    1. We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
    2. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
    3. Please note that we may process your personal data without your knowledge or consent, in compliance with the above bases or where this is required or permitted by law.

6. What if you refuse to provide us with any personal data?

    1. Where we need to collect personal data by law, or under the terms of an agreement we have with you, and you fail to provide that data when requested (or fail to consent to the processing of that data, if necessary), we may not be able to perform the contract or arrangement we have or are trying to enter into with you (for example, to provide you with products or services). In this case, we may have to cancel a product or service (e.g. a veterinary service) you have with us, but we will endeavour to notify you if this is the case at the time.
    2. Whilst we may be able to provide you with certain products and services notwithstanding your refusal to submit personal data, this may limit your ability to participate in some activities, or use certain features, services or functionality.

7. Sharing information with affiliates and third parties

    1. We will not share any of your personal data with third parties except as set out in this paragraph 7 or otherwise notified to you or agreed between you and us from time to time.
    2. We may share personal data with our group companies and partnered companies (together, "Affiliates") in order to provide our goods and services to you and for the other purposes outlined in this policy.
    3. From time to time, we will also need to share personal data with the following types of third party service providers who we engage to provide services which facilitate our business and who may need to process your personal data to the extent necessary to provide those services:
      1. MailChimp, operated by The Rocket Science Group LLC, our email marketing service;
      2. Trustpilot, operated by Trustpilot A/S, our consumer review provider;
      3. TokBox Inc., our video call provider (a company certified under Privacy Shield);
      4. our partner veterinary clinics;
      5. your indicated insurance provider;
      6. veterinary clinics and animal hospitals – FirstVet cooperates with various clinics and animal hospitals. When FirstVet refers your animal to a veterinary clinic or animal hospital, some personal information will be provided about you as the owner of the animal in order to facilitate the referral and care process;
      7. hired veterinarians – FirstVet collaborates with consulting veterinarians who help in making appointments and diagnoses;
      8. notification services – FirstVet uses third party services to communicate automatically with you, eg. with meeting confirmations or reminders. These companies only get access to your contact information and are committed to not sharing your personal information beyond what is necessary to perform the service;
      9. developers and consultants – FirstVet may engage developers and consultants from other companies to build FirstVet IT infrastructure and further develop the service. Such developers may need to have access to personal information when necessary for development or troubleshooting. All developers and consultants are bound by confidentiality agreements; and
      10. any similar or replacement third parties from time to time.
    4. We seek to ensure that any third party engaged by us who processes your personal data in connection with the purposes listed above has policies and procedures in place to ensure compliance with the Data Protection Legislation.
    5. For any third parties that are based, or process data, overseas, we only engage such third parties in accordance with paragraph 8.
    6. Unless otherwise disclosed to you from time to time, we will remain the data controller in respect of your personal data notwithstanding that third parties may be engaged as data processors.
    7. We may also share your personal information with third parties where we are required to do so by law or regulation (such as in connection with an investigation of fraud or other legal enquiry) or in connection with other legal proceedings (including where we believe that your actions violate applicable laws, any terms of use governing our website or any other arrangement between us, or any usage guidelines for specific products or services, or threaten the rights, property, or safety of our Company, our users, or others).

8. International transfers of personal data

    1. From time to time it may be necessary for us to transfer your information internationally. In particular your information may be transferred to and/or stored on the servers of our Affiliates or other third parties identified in paragraph 7 which are based outside of the EEA.
    2. However, we will not transfer your personal data outside of the EEA unless:
      1. such transfer is to a country or jurisdiction which the EU Commission has approved as having an adequate level of protection (including to the USA where Privacy Shield compliant);
      2. appropriate safeguards are in place as set out in Article 46 GDPR or equivalent provisions of other Data Protection Legislation; or
      3. the transfer is otherwise allowed by applicable Data Protection Legislation (such as in the form of a derogation under Article 49 GDPR).\

9. Your rights as a data subject

    1. Subject to any conditions or requirements set out in the relevant Data Protection Legislation, you may have some or all of the following rights in relation to the personal data we hold about you:
      1. the right to request a copy of your personal data held by us;
      2. the right to correct any inaccurate or incomplete personal data held by us. You can deactivate your account, or amend any personal data which cannot be modified online, by emailing us at support@firstvet.co.uk;
      3. the right to request that we erase the personal data we hold about you;
      4. the right to request that we restrict the processing of your data;
      5. the right to have your personal data transferred to another organisation;
      6. the right to object to certain types of processing of your personal data by us; and
      7. the right to complain (please see paragraph 14 of this policy).
    2. Please note however that these rights are not absolute in all situations and may be subject to conditions and provisos set out in relevant Data Protection Legislation. The Company cannot therefore guarantee that any request from you in connection with the rights set out above will be agreed to. For further information, or to see if you can exercise any particular right, please contact us at support@firstvet.co.uk.

10. Storage and retention of your personal data

    1. As a minimum, we need to store your data for as long as is necessary to enable us to provide you with the goods and services that you have requested from us (or to support your other uses of our Channels, such as maintaining your account(s)). However, we will retain certain of your personal data for longer if we think it is reasonably necessary to do so in the circumstances, taking into consideration factors such as:
      1. our need to perform any agreements between you and us (including the data contained in medical records);
      2. our need to answer any queries or resolve any problems you may have;
      3. your continued consent to receive marketing and other emails and communications from us;
      4. our continued provision of our services to you; and
      5. our need to comply with legal requirements (e.g. relating to record keeping).
    2. We maintain data contained in medical records for five years from the last assignment entered into the journal.
    3. If you tell us that you would like to delete your account, we will take steps to delete all the personal data we hold about you once it is no longer necessary for us to hold it (e.g. to fulfil any outstanding orders, resolve disputes, or as is permitted by applicable law or regulation).
    4. For as long as we do store your data, the Company follows generally accepted industry standards and maintains reasonable safeguards to attempt to ensure the security, integrity, and privacy of the information you have provided. All information you provide us is stored on Amazon Web Services (AWS) in Ireland. AWS employs a high level of data protection safeguards, more information of which can be seen here: https://aws.amazon.com/blogs/security/all-aws-services-gdpr-ready/. The Company has security measures in place designed to protect against the loss, misuse, and alteration of the information under our control.
    5. Notwithstanding our efforts to keep your personal data secure, no system can be 100% reliable. To the fullest extent permitted by law, we cannot be held liable for any loss you may suffer if a third party procures unauthorised access to any data you provide through the Channels. In addition, you are responsible for maintaining the strength and confidentiality of any login credentials.
    6. We will notify you as soon as reasonably practicable if we have reason to believe that there has been a personal data breach by us which could adversely affect your rights and freedoms.
    7. When we perform a disposal of personal data, this cannot be revoked / restored. When disposal has been carried out, no person can be associated with any retained aggregated and anonymised statistical information.

11. Links to third parties

    1. Our website may link or redirect to other websites that are beyond our control. Such links or redirections are not endorsements of such websites or representation of our affiliation with them in any way and such third party websites are outside the scope of this policy.
    2. If you access such third party websites, please ensure that you are satisfied with their respective privacy policies before you provide them with any personal data. We cannot be held responsible for the activities, privacy policies or levels of privacy compliance of any website operated by any third party.

12. Cookies

    1. A cookie is a small file of letters and numbers stored on your browser or the hard drive of your computer. Cookies contain information that is transferred to your computer's hard drive.
    2. Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a better experience when you browse our website and also allows us to improve our website.
    3. Some data collected by cookies is collected on an anonymous and/or aggregated basis. Where we use cookies that contain personal data, we will only process that personal data as set out in this policy.
    4. Our websites use some or all of the following cookies:
      1. Strictly necessary cookies. These are cookies that are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website, use a shopping cart or make use of e-billing services.
      2. Analytical/performance cookies. These allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
      3. Functionality cookies. These are used to recognise you when you return to our website. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
      4. Targeting cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.
    5. There are two types of cookies:
      1. A permanent cookie that is left on the visitor's computer for a certain amount of time.
      2. A session cookie stored temporarily in the computer's memory while a visitor is on a website. Session cookies disappear when you close your browser.
    6. Please note third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies and other technology (e.g. web beacons), over which we have no control.
    7. Your browser may give you the ability to block all or some cookies by activating a setting in your browser's options. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our Channels.
    8. Except for essential cookies, all cookies will remain unless the cookie cache is cleared (unless otherwise indicated in the table above).
    9. No personal identification information, such as email or name, is saved about visitors through cookies.
    10. The visitor may choose not to accept cookies by turning off cookies in their own browser's security settings.

13. Medical journal

    1. You have the opportunity to read and access your animal and meeting records. In your user account you can log in, see your visits and the veterinarian's conclusions, diagnoses and possible referrals.

14. Questions and complaints

    1. For all questions or complaints about this policy, we would appreciate the chance to deal with your concerns before you approach the relevant data protection authority. Please contact us in the first instance via email at support@firstvet.co.uk or write to Data Protection Enquiries, FirstVet Fox Court, Gray's Inn Road, London, England, WC1X 8HN.
    2. You have the right to make a complaint at any time to the relevant supervisory authority for data protection issues, which in the UK is the Information Commissioner's Office (ICO) (www.ico.org.uk).