Booking PlatformApex Vet AssistanceOnline ConsultsMarketplaceFor ClinicsPricingWhy Apex VetAbout Book a demo
Trust

Security & Trust.

How we protect clinic and client data, and how partners and clinics can obtain our compliance documents and DPA.

Australian-built & AU-hosted Privacy Act + GDPR-aligned SOC 2 infrastructure Zero trackers on booking
Last updated 14 June 2026

Our approach

We treat clinic and client data as carefully as you do. Our security and privacy programme is designed to meet the Australian Privacy Act 1988 (APPs) and to align with the EU/UK GDPR where it applies. This page summarises how we protect data and how partners and clinics can obtain our compliance documents.

Where your data lives

Our primary database is hosted in Sydney, Australia. Some specialist functions — AI transcription and note-drafting, SMS and email — are performed by trusted providers, some located overseas, under contractual safeguards including Standard Contractual Clauses (SCCs) and data-processing agreements consistent with Australian Privacy Principle 8.

Security measures

  • Encryption in transit (TLS) and at rest across the platform.
  • Role-based access control; pet owners sign in with one-time SMS codes (no stored passwords); staff passwords stored only as secure hashes.
  • Audit logging of administrative actions on client data.
  • A documented breach-response procedure aligned to GDPR (72 hours) and the Australian Notifiable Data Breaches scheme.
  • No advertising or analytics trackers anywhere in the booking flow.

Data protection documents

For partnership and procurement reviews, we maintain a Data Protection & Compliance Pack (Article 30 record of processing, lawful bases, subprocessor register with SCCs, technical and organisational measures, breach procedure and data-subject-rights process) and can provide a signed Data Processing Agreement (DPA) to clinics and integration partners. To request these, contact support@apexhqvet.com.au.

Subprocessors

We use a small set of vetted providers (database hosting, application hosting and recording storage, SMS/voice, transcription, AI note-drafting, and email), each under a data-processing agreement. The current register is available on request as part of our compliance pack.

AI and clinical safety

AI-generated clinical notes are always drafts for a vet to review and approve — nothing is auto-finalised. Under our agreements, our AI providers do not use your content to train their models. We are introducing pseudonymisation to minimise the personal information sent to AI providers.

Your rights and contact

Individuals can request access to, correction, export or deletion of their personal information. We respond within 30 days. Privacy questions and DPA requests: support@apexhqvet.com.au. See also our Privacy Policy.