Data Privacy + Security
You’re trusting us with sensitive information about your clinic, your clients, and their pets, so protecting that data is our top priority.
Vedi is one of the most secure ways for veterinary professionals to capture, manage and share patient health data. With our advanced security features, including encryption, access controls and blockchain, our customers can trust that their information is protected and safe with us.
And, of course, nothing can be accessed without first scanning a patient’s microchip – which adds another layer of security.
Certain information, such as owner personally identifiable information (PII), is never shared. Other data types — for example, pathology results — are only shared with explicit consent. Core patient health data, like vaccination and immunity information, is shared by default as part of Vedi’s function to enable connected care across providers.
On this page, we address all the top questions and concerns about data security and privacy when it comes to using Vedi, but if you would like to ask us about anything not mentioned here, please contact us and we’ll get back to you right away. Our privacy policy and terms of use pages also contain more information.
As a data processor, Vedi is committed to complying with all applicable data protection laws, including the Australian Privacy Act and UK GDPR. We take our responsibility to protect personal information seriously and have implemented appropriate technical and organisational measures to ensure the confidentiality, integrity, and availability of the data we process.
As part of our compliance with GDPR, we act on behalf of our veterinary clinic and hospital clients, who are the data controllers. We assist our clients in fulfilling their GDPR obligations by providing appropriate technical and organisational measures to ensure that the data we process is secure and that we respond promptly to any exercising of GDPR rights, such as access or deletion requests, made by our clients on behalf of their clients.
The veterinary sector in Australia and worldwide is increasingly prioritising data accuracy, traceability, and accountability in veterinary care. Vedi also ensures that as a veterinary practice, you are always compliant with the veterinary practice regulations in your jurisdiction. For example, recent regulation amendments in Western Australia emphasise that clinical records must now include a unique animal identification, such as a microchip number, and the expectations around this are stricter than before.
How it works:
Vedi is a world-first data technology that links a pet's health data directly to their microchip. The pet’s microchip acts as a unique identifier. Instead of storing medical data on the chip itself, Vedi links the chip’s ID to a secure digital record in our system. A simple scan of the microchip means that any subsequent procedures performed using Vedi (like vaccinations and external pathology tests) are always attributable and traceable to that patient, minimising errors and inaccuracies.
Security and data verification:
Vedi uses a secure event log data store, which means that data can’t be tampered with or accidentally overwritten. Once data is logged, it cannot be altered. Through automation and technology, Vedi can securely record and confirm details like time, location, identity, vaccination history and more. When a veterinary practice is using Vedi-verified data, they're working with the best quality health records.
Access control:
Only authorised users (vets, nurses, clinic staff) can see the medical record. If anyone scans a pet’s microchip with a non-Vedi scanner, it will just return the microchip number, not the full record.Similarly, only your clinic staff can see your pet patient’s medical record, unless you explicitly consent to sharing that data with our provider network, such as emergency hospitals, pathology labs and others.
Auditability:
Every change to a patient record is recorded in our event log data store which means a point in time view of a patient record can be produced. User logins and various interactions are also logged and recorded.
Owner protection:
Owners’ personal information is never exposed in a microchip scan. Owner personal information can only be viewed by the practice that supplied the owner data. This data is segregated per practice.
Encryption:
Encryption at Rest: AES-256. Encryption in Transit: TLS 1.2
Access management:
Vedi utilises strict role-based permissions. Only authorised staff access sensitive data.
Infrastructure:
All Vedi services and components, including business documents, emails, internal communications and source code, are managed within the Microsoft Office 365 and Microsoft Azure ecosystems.
Monitoring and security management:
At Vedi, we have strict security protocols in place to prevent data breaches. In the event of a breach, we have a comprehensive incident response plan that involves immediate containment, investigation, and remediation. Our team is trained to quickly and effectively respond to any security incident, and we work closely with relevant authorities to ensure that any impact to our customers is minimised. We also regularly review and update our security measures to stay up to date with the latest threats and vulnerabilities. Our commitment to data security and privacy is at the forefront of everything we do, and we take every precaution to ensure the safety of our customers' information.
How we use AI:
We use an Open AI model to summarise a patient’s medical history into more digestible summaries.
What we don’t do:
We never train external or public AI models on customer or patient data.
Safeguards:
Vedi uses a privately deployed version of OpenAI and models for use by Vedi only and is not shared with other organisation. Since it is a private deployed instance of Open AI, no anonymisation is needed.
Find the answers to the most frequently asked questions about Vedi.
As part of our compliance with GDPR, we act on behalf of our veterinary clinic and hospital clients, who are the data controllers. If any one of your clients does not want their data to be stored by Vedi, they can ask to delete their data here: https://www.vedi.io/data-deletion-request Once submitted, we will verify their identity and proceed with their request, ensuring their data is handled securely and in compliance with GDPR guidelines.
The clinic that creates the data owns it. By using Vedi, clinics consent to share specific parts of that animal health data within the Vedi ecosystem. Certain information, such as owner personally identifiable information (PII), is never shared. Other data types — for example, pathology results — are only shared with explicit consent. Core patient health data, like vaccination and immunity information, is shared by default as part of Vedi’s function to enable connected care across providers.
Clinics grant consent to share data such as pathology results to other practices. For pet owners, implied consent is granted for owner data to be stored in Vedi. However that data is never shared with anyone except for the practice that consent is given to on behalf of the owner. This is like how a customer of a company gives the company implied consent for their data to be stored in the customer relationship management (CRM) database of that company.
The new clinic will have access to the shared animal health data (vaccination details and basic pet data such as the pet’s name, age, desex status and immunisation status). Owner personal data is not transferred. Pathology results are not shared unless specifically granted by the original practice.
Vedi collects the objective medical data you would find on a vaccination certificate, a clinical pathology submission form or a microchip registration form. For Vedi to create verifiable medical data, some recorded events may capture location and user data when scanning a microchip or recording data. All the data remains the property of the veterinary business.
Vedi will never disclose personal private information to a third party that hasn't been authorised by you as the veterinary practice. For example, by submitting a pathology lab request, the vet is authorising Vedi to transmit the specific information required for the submission. Vedi uses SSL/TLS encryption for all communication, ensuring the highest security and data protection standards. Data is always transmitted securely over an encrypted channel (TLS encryption in transit), with sensitive data always encrypted at rest, within the database adhering to stringent Australian Digital Health Agency operating standards. Our software packages are digitally signed to prevent tampering.
At Vedi, only authorised users can access our data, and by design from the original vet who created that data. Access is tightly controlled through advanced security features such as encryption. Service providers can access data only when explicitly requested by the vet and often only if they scan the animal's microchip. We ensure that sensitive owner personal information is kept separate from animal health data. Lastly, we have full traceability over who accessed what piece of data and when.
Owner or Vedi user personal information is always kept separate from animal health data. Owner data and other personal identifiable information (PII) is segregated from shared animal health data in the Vedi event data store as separate data events.
If you wish to exercise your GDPR rights and request the deletion of your personal data or account, we've made the process straightforward for you. Simply fill out our GDPR Data Deletion Request Form accessible through your account settings or directly from our Privacy Policy page. This form allows you to specify whether you'd like to delete specific data or your entire account. Once submitted, we will verify your identity and proceed with your request, ensuring your data is handled securely and in compliance with GDPR guidelines. For any further questions or assistance, please do not hesitate to contact our support team.
Privacy and security are our top priority. Our focus is to provide the highest standards of care and confidentiality. Vedi complies with the Australian Privacy Principles, the Privacy Act, and the Veterinary Surgeons Act. Our privacy policy, terms-of-service, and end-user licence agreements detail our obligations as a service provider and the responsibilities of the entities and users utilising our service. These agreements are available for review on vedi.io/legal.
Record detailed information in seconds and let our Smart Statuses calculate exactly which vaccines and boosters are needed. Plus, our Digital Vaccination Certificates can never be lost!
Learn more about digital vaccinations.