Trust Centre

Data Privacy + Security

How we protect your data at Vedi

You’re trusting us with sensitive information about your clinic, your clients, and their pets, so protecting that data is our top priority.

Vedi is one of the most secure ways for veterinary professionals to capture, manage and share patient health data. With our advanced security features, including encryption, access controls and blockchain, our customers can trust that their information is protected and safe with us.

And, of course, nothing can be accessed without first scanning a patient’s microchip – which adds another layer of security.

Certain information, such as owner personally identifiable information (PII), is never shared. Other data types — for example, pathology results — are only shared with explicit consent. Core patient health data, like vaccination and immunity information, is shared by default as part of Vedi’s function to enable connected care across providers.

On this page, we address all the top questions and concerns about data security and privacy when it comes to using Vedi, but if you would like to ask us about anything not mentioned here, please contact us and we’ll get back to you right away. Our privacy policy and terms of use pages also contain more information.

Our commitment to compliance

As a data processor, Vedi is committed to complying with all applicable data protection laws, including the Australian Privacy Act and UK GDPR. We take our responsibility to protect personal information seriously and have implemented appropriate technical and organisational measures to ensure the confidentiality, integrity, and availability of the data we process.

As part of our compliance with GDPR, we act on behalf of our veterinary clinic and hospital clients, who are the data controllers. We assist our clients in fulfilling their GDPR obligations by providing appropriate technical and organisational measures to ensure that the data we process is secure and that we respond promptly to any exercising of GDPR rights, such as access or deletion requests, made by our clients on behalf of their clients.

The veterinary sector in Australia and worldwide is increasingly prioritising data accuracy, traceability, and accountability in veterinary care. Vedi also ensures that as a veterinary practice, you are always compliant with the veterinary practice regulations in your jurisdiction. For example, recent regulation amendments in Western Australia emphasise that clinical records must now include a unique animal identification, such as a microchip number, and the expectations around this are stricter than before.

How data is locked to the microchip

How it works:
Vedi is a world-first data technology that links a pet's health data directly to their microchip. The pet’s microchip acts as a unique identifier. Instead of storing medical data on the chip itself, Vedi links the chip’s ID to a secure digital record in our system. A simple scan of the microchip means that any subsequent procedures performed using Vedi (like vaccinations and external pathology tests) are always attributable and traceable to that patient, minimising errors and inaccuracies.

Security and data verification:
Vedi uses a secure event log data store, which means that data can’t be tampered with or accidentally overwritten. Once data is logged, it cannot be altered. Through automation and technology, Vedi can securely record and confirm details like time, location, identity, vaccination history and more. When a veterinary practice is using Vedi-verified data, they're working with the best quality health records.

Access control:
Only authorised users (vets, nurses, clinic staff) can see the medical record. If anyone scans a pet’s microchip with a non-Vedi scanner, it will just return the microchip number, not the full record.Similarly, only your clinic staff can see your pet patient’s medical record, unless you explicitly consent to sharing that data with our provider network, such as emergency hospitals, pathology labs and others.

Auditability:
Every change to a patient record is recorded in our event log data store which means a point in time view of a patient record can be produced. User logins and various interactions are also logged and recorded.

Owner protection:
Owners’ personal information is never exposed in a microchip scan. Owner personal information can only be viewed by the practice that supplied the owner data. This data is segregated per practice.

Data security practices

Encryption:
Encryption at Rest: AES-256. Encryption in Transit: TLS 1.2

Access management:
Vedi utilises strict role-based permissions. Only authorised staff access sensitive data.

Infrastructure:
All Vedi services and components, including business documents, emails, internal communications and source code, are managed within the Microsoft Office 365 and Microsoft Azure ecosystems.

Monitoring and security management:
At Vedi, we have strict security protocols in place to prevent data breaches. In the event of a breach, we have a comprehensive incident response plan that involves immediate containment, investigation, and remediation. Our team is trained to quickly and effectively respond to any security incident, and we work closely with relevant authorities to ensure that any impact to our customers is minimised. We also regularly review and update our security measures to stay up to date with the latest threats and vulnerabilities. Our commitment to data security and privacy is at the forefront of everything we do, and we take every precaution to ensure the safety of our customers' information.

AI and data privacy

How we use AI:
We use an Open AI model to summarise a patient’s medical history into more digestible summaries.

What we don’t do:
We never train external or public AI models on customer or patient data.

Safeguards:
Vedi uses a privately deployed version of OpenAI and models for use by Vedi only and is not shared with other organisation. Since it is a private deployed instance of Open AI, no anonymisation is needed.

Frequently asked questions.

Find the answers to the most frequently asked questions about Vedi.

What prevents unauthorized staff from linking or unlinking data to a chip?
What if a client does not want their or their pet’s data to be recorded on Vedi?
Who owns the data: the clinic, the owner, or Vedi?
Do clinics or pet owners need to give explicit consent before data is linked?
How long is the data retained?
What happens if a client moves clinics? Does the new clinic have access to the same data?
What happens if clinic staff accidentally link the wrong data to the chip?
What happens if the microchip is scanned with a non-Vedi scanner?
What data do you collect?
How do I know that my patient’s data won’t be disclosed to third parties?
What prevents someone from scanning a chip and accessing private information?
How is personal information protected, whether it’s pet parents or clinic staff?
How to Request Data Deletion Under GDPR
Where can I read more about security and privacy?

A better way to vaccinate.

Record detailed information in seconds and let our Smart Statuses calculate exactly which vaccines and boosters are needed. Plus, our Digital Vaccination Certificates can never be lost!

Learn more about digital vaccinations.