Privacy Policy
Effective date: 27 July 2026 Entity: Ryan Murdoch Haste (ABN 93 739 849 070) trading as Wattle Veterinary Health (“Wattle”, “we”, “us”, “our”). Privacy contact: [email protected] · 153 Arcadia Road, Arcadia NSW 2159
Wattle Clinic is a veterinary practice-management and electronic-records platform for veterinary clinics in Australia, comprising the web application (clinic.wattlevet.com), a native iOS companion app, a documentation site (docs.wattlevet.com), and this marketing site (wattlevet.com). This policy explains how we handle personal information, consistent with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Who this policy covers, and who is responsible for what
This policy covers personal information about:
- Clinic staff — veterinarians, nurses, practice managers, and other staff who hold Wattle accounts;
- Pet owners (clinic clients) — people whose contact and billing details a clinic records in Wattle;
- Website visitors — people who browse our marketing or documentation sites or contact us;
- Mobile app users — clinic staff using the Wattle Clinic iOS companion app.
Two different responsibility roles apply, and it matters which one you fall under:
- For clinic-staff account data, our own billing/support records, and website contact-form data, Wattle decides how and why the information is handled. We are the entity accountable under the Privacy Act for that information.
- For pet-owner and animal-patient records that a clinic enters into Wattle, the clinic decides how and why that information is handled — it is the clinic’s record, and the clinic is the entity accountable for it under the Privacy Act. Wattle handles that data only on the clinic’s behalf and on its instructions, as described in our Data Processing Addendum. If you are a pet owner with a question about your information, please contact your clinic first; we will assist the clinic in responding (see clauses 10 and 11).
2. What we collect
2.1 Information you give us
- Account data: name, email address, role (veterinarian, veterinary nurse, practice manager, or staff), professional title, and — for veterinarians — registration number and state of registration.
- Authentication data: sign-in is handled by our identity provider. We never store your password. Where a clinic enables the Schedule 8 register, we store a hashed per-user PIN used as a second verification step for that register.
- Contact and support data: messages you send via the marketing-site contact form or to [email protected].
- Subscription billing data: clinic legal name, ABN, billing address, and payment records. Card payments are processed by our payment processor; we never hold card numbers.
2.2 Information clinics record about their clients
Clinics enter and control the following records; we hold them on the clinic’s behalf:
- Client (pet owner) details: name, contact details, phone number, address, email, ABN for organisational payers, insurance details, and account status.
- Patient (animal) clinical records: signalment, microchip, weights, alerts and allergies, consultation/SOAP notes, treatments, vitals, prescriptions, laboratory results, documents, and photos.
- Billing records: an append-only ledger, invoices, payments, estimates, and receipts.
- Communications: records of outbound emails the clinic sends (with delivery status — sent/delivered/bounced/complained) and attachments.
- Files: patient photos, staff avatars, and clinic branding, held in private, clinic-scoped storage.
- Quick notes: private to their author.
- Schedule 8 controlled-drug register entries (where the clinic enables this feature), held in an isolated, append-only register schema.
2.3 Information collected automatically
- Audit logs: append-only records of who did what and when in the application (including before/after values), a separate Schedule 8 audit log, and separately logged platform-admin actions. These exist for security, accountability, and record-integrity reasons.
- Technical data: error diagnostics and standard request metadata (such as IP address and browser type in server logs).
- No advertising trackers. We use no advertising or cross-site tracking technologies anywhere in our products.
3. Sensitive information
Veterinary clinical records are about animals, not people, so most of the platform’s content is not “sensitive information” as defined in the Privacy Act. However, some records touch sensitive or health-adjacent contexts — for example, a pet owner’s insurance details, notes that incidentally mention a person’s circumstances, or Schedule 8 controlled-drug register entries that record which staff member handled a controlled substance. We treat all such records with the same elevated care we would apply to sensitive information: strict per-clinic isolation, role-based access, and append-only audit trails. We do not intentionally collect sensitive information about pet owners beyond what a clinic records to provide veterinary services and billing.
4. How we use personal information
We use personal information only to:
- Provide the Service — run the platform, sync data between devices, and deliver the features clinics use;
- Secure the Service — authenticate users, enforce per-clinic isolation, detect and investigate misuse, and maintain audit trails;
- Support you — respond to support requests and privacy queries;
- Maintain statutory records — Schedule 8 register integrity, financial and tax records;
- Bill our customers — manage subscriptions and payments;
- Communicate about the Service — transactional messages and product announcements (see clause 12);
- Meet our legal obligations.
We do not sell personal information. We do not use it for advertising, and we do not engage in cross-site tracking. We do not use clinic-entered client or patient data for our own purposes, except in aggregated, de-identified form to operate and improve the platform (for example, usage volumes and performance telemetry that cannot identify any person or clinic client).
5. Cookies and local storage
Authentication uses short-lived Bearer tokens, not tracking cookies. The web app stores session tokens locally in your browser strictly to keep you signed in. We set only what is essential for the Service to function — there are no advertising or analytics trackers in the clinic application, and our marketing site currently runs no analytics. If that changes, we will update this clause.
6. Disclosure and third-party service providers
We do not disclose personal information except: (a) to service providers who help us run the platform, under contract and only as needed; (b) where required or authorised by law (including to regulators and drug-register inspectors, at the clinic’s direction); or (c) with your consent.
We use third-party service providers for functions including: hosting and database storage, identity and sign-in services, transactional email delivery, error monitoring and diagnostics, payment processing, and AI text-processing services used to extract or summarise information you submit. We select these providers carefully, engage them under contract, and share only the minimum personal information needed for them to perform their function. Our core clinical database and file storage are hosted in Australia. Some service providers are located overseas (including in the United States) and may process limited personal information there in the course of providing their service. A current list of our sub-processors, including where each is located, is available on request to [email protected].
7. Cross-border disclosure (APP 8)
Your primary records — the database and stored files — stay in Australia. As noted in clause 6, some service providers are located overseas and may process limited personal information outside Australia. Before using an overseas provider, we take reasonable steps — including contractual data-protection commitments — to satisfy ourselves it will handle personal information consistently with the Australian Privacy Principles, as required by APP 8.1.
8. Security
We protect personal information with safeguards that include:
- Per-clinic isolation: row-level security on every database table, enforced by clinic identity in every request; private, clinic-scoped file storage.
- Access control: least-privilege roles; privileged service credentials are held server-side only and never exposed to browsers or devices.
- Session security: short-lived (15-minute) session tokens, verified signatures on identity tokens, and suspension enforced at token exchange. Bearer-token authentication (no cookies) structurally mitigates cross-site request forgery.
- Schedule 8 register access: password sign-in plus a per-user, server-verified PIN with lockout and idle re-authentication. This is two-step verification for register surfaces. (It is not multi-factor authentication; MFA is planned for a future release.)
- Encryption: TLS 1.2+ in transit; AES-256/provider-default encryption at rest.
- Hardening: security headers including CSP, X-Frame-Options DENY, nosniff, Referrer-Policy, Permissions-Policy, and HSTS.
- Backups: two independent, encrypted backups — our database provider’s managed daily backups (7-day retention) and a separate off-site backup held with a different provider (retained up to 45 days). Deleted data ages out of all backups within 45 days of permanent deletion.
- Integrity: append-only audit logs; the Schedule 8 register is append-only with a cryptographic hash chain and a verification function.
No system is perfectly secure; we work continuously to protect information using reasonable safeguards appropriate to its sensitivity.
9. Retention
- While a clinic is active, its records are retained for as long as the clinic keeps them — the clinic controls its own records.
- On cancellation: if the clinic holds a paid subscription, it keeps full access until the end of the billing period already paid for, then is soft-deleted. If it does not hold a paid subscription, it is soft-deleted immediately.
- After soft-deletion, we retain the clinic’s data for 90 days as a restore window, then permanently purge it. Within the 90 days, the account can be restored via support; after purge, restoration is impossible.
- Immediate purge on request: a clinic may request in writing that we purge immediately instead of waiting out the 90 days.
- Our own tax records: we retain a minimal set of our own billing/tax records for 5 years as required by Australian tax law — the clinic’s legal name, ABN, billing address, subscription invoice numbers/amounts/dates, and payment-processor identifiers. These are held by our payment processor, not a separate Wattle-side copy, and comprise transaction data only — no clinical or client data.
- The clinic’s own retention duties: statutory clinical-record and Schedule 8 register retention obligations bind the clinic, not Wattle. Clinics must export their records before or at cancellation (Settings → Data export, Schedule 8 full export, and register PDF/CSV reports) to meet those obligations. See the Data Processing Addendum, clause 6.
- Inactivity lifecycle: if a clinic is inactive for more than 12 months, we send a warning email, allow a 30-day grace period, and then suspend the account. We never delete an account automatically for inactivity.
10. Access and correction (APP 12 and APP 13)
You may request access to, or correction of, personal information we hold about you.
- Clinic staff: manage your own profile in Settings → Account, or contact [email protected].
- Pet owners: contact your clinic first — the clinic controls that record and is responsible for responding. We assist the clinic on request: we acknowledge within 1 business day and help the clinic deliver access within 30 days (the statutory maximum; we aim for a few days). Corrections are made by the clinic editing the record in-app, with every change captured in the audit trail. If a clinic declines a correction, you may ask for a statement of disagreement to be attached to the record.
- Direct requests to us: email [email protected]. We respond within the same timeframes. If we refuse a request, we will tell you why in writing and how to complain.
11. Deletion and anonymisation
Pet owners may ask to be deleted. Because clinics are legally required to retain clinical records for several years, the default response is anonymisation, not deletion: the clinic replaces the owner’s identifying details (name, email, phone, address) with placeholders while the animal’s clinical record is preserved. This de-identifies the record consistent with APP 11.2 while honouring the clinic’s retention obligations. True hard deletion is available on request via [email protected] but is discouraged where it would put the clinic in breach of its record-retention duties, and we will warn the clinic before proceeding.
12. Direct marketing
We do not send direct marketing. The only communications we send are service messages (for example, billing, security, and account-lifecycle notices) and product announcements about Wattle Clinic itself, which you may opt out of at any time. We never share personal information with third parties for their marketing.
13. Data breaches
We maintain an incident-response process for suspected data breaches. If a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches (NDB) scheme. Where the affected records belong to a clinic, we will notify the clinic without undue delay and assist it with its own NDB obligations.
14. Complaints
If you believe we have breached the APPs, contact us first at [email protected] — we will acknowledge your complaint within 1 business day and aim to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):
- Web: oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
15. Mobile app
The Wattle Clinic iOS companion app processes the same data as the web application, through the same Australian-hosted backend. In addition, the app may hold an offline cache of clinic data on the device, capture photos for patient records (uploaded to the clinic’s private storage), and use on-device dictation (Apple’s speech recognition — no third-party speech service). The app contains no third-party analytics or advertising SDKs and sends no push notifications. Its update check contacts a public file containing build numbers only — no user data is sent. The data categories and your rights described elsewhere in this policy apply equally to mobile app users.
16. Changes to this policy
We may update this policy from time to time. Material changes will be notified via the app or by email before they take effect. The “Effective date” above reflects the current version.
17. Contact
Ryan Murdoch Haste (ABN 93 739 849 070) trading as Wattle Veterinary Health Email: [email protected] Address: 153 Arcadia Road, Arcadia NSW 2159