Privacy Policy

Effective date: 27 July 2026 Entity: Ryan Murdoch Haste (ABN 93 739 849 070) trading as Wattle Veterinary Health (“Wattle”, “we”, “us”, “our”). Privacy contact: [email protected] · 153 Arcadia Road, Arcadia NSW 2159

Wattle Clinic is a veterinary practice-management and electronic-records platform for veterinary clinics in Australia, comprising the web application (clinic.wattlevet.com), a native iOS companion app, a documentation site (docs.wattlevet.com), and this marketing site (wattlevet.com). This policy explains how we handle personal information, consistent with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Who this policy covers, and who is responsible for what

This policy covers personal information about:

Two different responsibility roles apply, and it matters which one you fall under:

2. What we collect

2.1 Information you give us

2.2 Information clinics record about their clients

Clinics enter and control the following records; we hold them on the clinic’s behalf:

2.3 Information collected automatically

3. Sensitive information

Veterinary clinical records are about animals, not people, so most of the platform’s content is not “sensitive information” as defined in the Privacy Act. However, some records touch sensitive or health-adjacent contexts — for example, a pet owner’s insurance details, notes that incidentally mention a person’s circumstances, or Schedule 8 controlled-drug register entries that record which staff member handled a controlled substance. We treat all such records with the same elevated care we would apply to sensitive information: strict per-clinic isolation, role-based access, and append-only audit trails. We do not intentionally collect sensitive information about pet owners beyond what a clinic records to provide veterinary services and billing.

4. How we use personal information

We use personal information only to:

We do not sell personal information. We do not use it for advertising, and we do not engage in cross-site tracking. We do not use clinic-entered client or patient data for our own purposes, except in aggregated, de-identified form to operate and improve the platform (for example, usage volumes and performance telemetry that cannot identify any person or clinic client).

5. Cookies and local storage

Authentication uses short-lived Bearer tokens, not tracking cookies. The web app stores session tokens locally in your browser strictly to keep you signed in. We set only what is essential for the Service to function — there are no advertising or analytics trackers in the clinic application, and our marketing site currently runs no analytics. If that changes, we will update this clause.

6. Disclosure and third-party service providers

We do not disclose personal information except: (a) to service providers who help us run the platform, under contract and only as needed; (b) where required or authorised by law (including to regulators and drug-register inspectors, at the clinic’s direction); or (c) with your consent.

We use third-party service providers for functions including: hosting and database storage, identity and sign-in services, transactional email delivery, error monitoring and diagnostics, payment processing, and AI text-processing services used to extract or summarise information you submit. We select these providers carefully, engage them under contract, and share only the minimum personal information needed for them to perform their function. Our core clinical database and file storage are hosted in Australia. Some service providers are located overseas (including in the United States) and may process limited personal information there in the course of providing their service. A current list of our sub-processors, including where each is located, is available on request to [email protected].

7. Cross-border disclosure (APP 8)

Your primary records — the database and stored files — stay in Australia. As noted in clause 6, some service providers are located overseas and may process limited personal information outside Australia. Before using an overseas provider, we take reasonable steps — including contractual data-protection commitments — to satisfy ourselves it will handle personal information consistently with the Australian Privacy Principles, as required by APP 8.1.

8. Security

We protect personal information with safeguards that include:

No system is perfectly secure; we work continuously to protect information using reasonable safeguards appropriate to its sensitivity.

9. Retention

10. Access and correction (APP 12 and APP 13)

You may request access to, or correction of, personal information we hold about you.

11. Deletion and anonymisation

Pet owners may ask to be deleted. Because clinics are legally required to retain clinical records for several years, the default response is anonymisation, not deletion: the clinic replaces the owner’s identifying details (name, email, phone, address) with placeholders while the animal’s clinical record is preserved. This de-identifies the record consistent with APP 11.2 while honouring the clinic’s retention obligations. True hard deletion is available on request via [email protected] but is discouraged where it would put the clinic in breach of its record-retention duties, and we will warn the clinic before proceeding.

12. Direct marketing

We do not send direct marketing. The only communications we send are service messages (for example, billing, security, and account-lifecycle notices) and product announcements about Wattle Clinic itself, which you may opt out of at any time. We never share personal information with third parties for their marketing.

13. Data breaches

We maintain an incident-response process for suspected data breaches. If a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches (NDB) scheme. Where the affected records belong to a clinic, we will notify the clinic without undue delay and assist it with its own NDB obligations.

14. Complaints

If you believe we have breached the APPs, contact us first at [email protected] — we will acknowledge your complaint within 1 business day and aim to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):

15. Mobile app

The Wattle Clinic iOS companion app processes the same data as the web application, through the same Australian-hosted backend. In addition, the app may hold an offline cache of clinic data on the device, capture photos for patient records (uploaded to the clinic’s private storage), and use on-device dictation (Apple’s speech recognition — no third-party speech service). The app contains no third-party analytics or advertising SDKs and sends no push notifications. Its update check contacts a public file containing build numbers only — no user data is sent. The data categories and your rights described elsewhere in this policy apply equally to mobile app users.

16. Changes to this policy

We may update this policy from time to time. Material changes will be notified via the app or by email before they take effect. The “Effective date” above reflects the current version.

17. Contact

Ryan Murdoch Haste (ABN 93 739 849 070) trading as Wattle Veterinary Health Email: [email protected] Address: 153 Arcadia Road, Arcadia NSW 2159