Legal
Privacy Policy
- Effective date
- 27 May 2026
- Last updated
- 27 May 2026
Working draft
This document is a working draft prepared to give Human Builds a starting point for its privacy obligations. It has not been reviewed by a qualified solicitor. Before relying on it on a live service it should be reviewed by a UK data protection lawyer.
VetForms — a service operated by Josh Human trading as Human Builds, a sole trader established in the United Kingdom (“we”, “us”, “our”). The service is provided at vetforms.co.uk.
1. About this policy
VetForms is a web application that helps UK Official Veterinarians (“OVs”) and their veterinary practices prepare, validate, and issue Animal Health Certificates(“AHCs”) for companion animals (dogs, cats, ferrets) travelling from Great Britain to the European Union.
This policy explains:
- what personal data we handle,
- the basis on which we handle it,
- who else processes it for us,
- how long we keep it, and
- the rights you have under the UK GDPR and the Data Protection Act 2018.
If you are a pet owner whose details have been entered into VetForms by an OV (for example via a /collect/… link), please also see section 4 — your veterinary practice is the data controller for your information; we act as their processor.
2. Who is the data controller?
The data controller depends on whose data is being processed:
| Data subject | Controller | Our role |
|---|---|---|
| OVs, practice staff, and other registered users of VetForms | Human Builds (us) | Controller |
| Pet owners and authorised persons whose details are entered into a certificate | The veterinary practice that registered the certificate | Processor (on behalf of the practice) |
| Visitors to our marketing pages | Human Builds (us) | Controller |
We have adopted the B2B SaaS processorposture for pet-owner data: the veterinary practice determines the purposes and means of processing owner data (because the practice’s OV is the one signing the regulatory certificate); we provide the platform that lets them collect and process that data. We will only act on documented instructions from the practice in relation to owner data, save where UK law requires otherwise.
Practice administrators: to formalise this relationship, you accept our Data Processing Agreement when you create a practice account.
3. The data we handle, and why
3.1 OV and practice account data (we are the controller)
| Category | Examples | Why we hold it | Lawful basis (UK GDPR Art. 6) |
|---|---|---|---|
| Identity & contact | full name, work email, role | account creation, authenticating you, supporting you | (b) performance of a contract with you / your practice |
| Practice details | practice name, address, telephone | populating the certificate, multi-tenant separation | (b) contract |
| Professional credentials | qualifications, OCQ(V) number, signature stamp image | populating the certificate, regulatory traceability | (b) contract and (c) legal obligation (records that support a regulatory document) |
| Usage and technical data | IP address, audit trail of actions, error logs | security, fraud prevention, debugging, auditability of certificate edits | (f) legitimate interests in keeping the service secure and demonstrating regulatory compliance |
| Billing data (if/when introduced) | invoicing details | charging for the service | (b) contract |
We do not intentionally collect special-category personal data about OVs or practice staff. If you upload a stamp image that contains additional personal data (for example a hand-signed signature), we will treat it the same as any other professional credential.
3.2 Pet-owner data (the practice is the controller; we are the processor)
When an OV uses VetForms to prepare a certificate — either directly or by sending the owner a /collect/… link — the following categories of personal data are typically entered into the system:
- Owner identity & contact: full name, address, telephone, email.
- Authorised person details: name and relationship to the owner (where the owner is not personally accompanying the animal).
- Carrier details: name of the commercial carrier (where applicable).
- Travel details: planned travel date, EU point of entry, scheduled arrival.
The system also stores animal-related data (species, breed, name, sex, microchip number and location, date of birth, colour markings, rabies vaccination history, tapeworm treatment history). Animal health data is not special-category personal data under UK GDPR (which protects human health data), but where data such as a microchip number can be tied back to an identifiable human owner, we treat the combined record as personal data of that owner.
We process this data only on the documented instructions of the veterinary practice, for the purpose of preparing and issuing the AHC and keeping the audit trail required of the practice. We do not use it for any other purpose, and we do not sell it or share it for marketing.
3.3 Marketing site visitors (we are the controller)
If you visit our marketing pages we may set strictly necessary cookies and, only with your consent, analytics cookies. We will publish a separate cookie notice if and when analytics is introduced.
4. Information for pet owners
If you have been asked by your vet to complete an AHC owner-collection form via a /collect/… link:
- The veterinary practice is the data controller of the information you submit. You should ask them directly about how they will use, share and retain it.
- Human Builds acts as their processor — we operate the platform, but we do not decide what is done with your data.
- The link is time-limited (it expires 14 days after it was generated) and tied to a specific certificate; it can only be used once.
- You can refuse to use the link and provide your information to the practice by another route. The certificate cannot be issued without the information the OV needs to certify, but the route by which you provide it is a matter for you and your practice.
- We do not market to pet owners and do not retain a marketing list of owner contact details.
5. Who else has access to your data (“processors”)
We use a small number of trusted third-party providers to run AHC Companion. They process personal data on our behalf and are bound by written contracts.
| Provider | Purpose | Where data is processed |
|---|---|---|
| Vercel Inc. | Application hosting, PDF generation, file storage (Vercel Blob) | United States, with UK/EU edge regions where available |
| Neon Inc. | PostgreSQL database hosting | We select a region in the UK/EU |
| Clerk Inc. | Authentication, organisation management, user identity | United States |
We also use ordinary infrastructure such as email delivery and error monitoring; these will be listed in a sub-processor schedule attached to the practice DPA when it is finalised.
We do not sell personal data and do not share it with third parties for their own purposes. The only routine onward disclosure of certificate data is to the owner themselves (via the generated PDF) and, indirectly, to border authorities when the owner travels with the certificate.
6. International transfers
Some of the providers above (notably Clerk and Vercel) are established in the United States. Personal data transferred to them is protected by the standard UK GDPR transfer safeguards:
- the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum, plus
- supplementary technical measures (encryption in transit and at rest).
Where a provider is certified under the UK Extension to the EU–US Data Privacy Framework, we also rely on that certification.
7. How long we keep it
| Data | Retention |
|---|---|
| Certificate records (the AHC, supporting fields, generated PDF) | At least 3 years from the date of issue, in line with regulatory expectations for OV record-keeping. The practice may instruct us to retain for longer where a specific regulatory or contractual reason applies. |
Owner-link tokens (/collect/…) | 14 days from creation, then automatically expired and unusable. |
| Audit logs | Retained for the lifetime of the related certificate plus the certificate retention period, so the audit trail outlasts the record it relates to. |
| OV/practice account data | For the duration of the account, plus a short tail (currently up to 12 months) to handle disputes and reactivations. |
| Backups | Routine database backups expire on a rolling basis (currently up to 30 days). Deletions from the live system are reflected in backups by the end of that window. |
Where a practice or an individual exercises a valid erasure right (see section 9) we delete the personal data identifying the individual, but we may retain a redacted, non-identifying record of the certificate where regulatory record-keeping obligations require it.
8. Security
We protect VetForms using measures appropriate to the sensitivity of the data, including:
- TLS 1.2+ for all data in transit;
- encryption at rest provided by our database and storage providers;
- role-based access (OV, admin, support) and multi-tenant isolation by
practiceId/ Clerk organisation; - audit logging of every state change on a certificate;
- single sign-on and (where the practice enables it) multi-factor authentication via Clerk;
- short-lived, single-use tokens for owner-facing forms.
No security control is perfect. If you become aware of a vulnerability or a suspected breach, please contact us using the details in section 11 so we can investigate and, where required, notify the ICO within 72 hours.
9. Your rights
Where we are the controller of your data, you have the following rights under UK GDPR. You can exercise them by contacting us (section 11):
- access a copy of the personal data we hold about you;
- ask us to correct inaccurate or incomplete data;
- ask us to erase data where there is no good reason for us to continue processing it (this is not absolute — see section 7);
- ask us to restrict processing while a query is investigated;
- object to processing carried out on the basis of our legitimate interests;
- request data portability for data you provided to us under a contract or with your consent;
- withdraw consent at any time for any processing we carry out on the basis of consent.
Where we are a processor (pet-owner data) you should raise the request with your veterinary practice. If you raise it with us we will pass it to the practice and assist them with their response.
You also have the right to complain to the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first.
10. Automated decision-making
VetForms runs automated validation rules (rules V-001 to V-012 and warnings W-001 to W-005) against certificate data. These rules check for things like vaccination timing, certificate windows, and tapeworm treatment compliance. They produce blockers and warnings for the OV — they do not make a binding decision about whether an animal can travel. Every certificate is reviewed and signed by a human OV before it has any effect, so no decision producing legal or similarly significant effects is taken solely by automated means.
11. Contact
| Operator | Josh Human trading as Human Builds |
| Service | vetforms.co.uk |
| vetforms@humanbuilds.dev |
For data protection queries please use the email above with the subject line “Data protection”.
12. Changes to this policy
We will update this policy from time to time. The “Last updated” date at the top reflects the most recent change. Where a change materially affects how we use your data we will notify you by email or in-app notice before the change takes effect.
