Privacy Policy

Draft – not yet legally binding. To be reviewed by a lawyer before publication. Operator: LetzPrint Sàrl-S. The platform’s public product/brand name is not yet final.

Privacy Policy

The protection of your personal data is important to us. This statement provides information, in accordance with Art. 13/14 GDPR, about the processing carried out within our online platform for booking appointments at veterinary practices.

1. Controller

LetzPrint Sàrl-S – Société à responsabilité limitée simplifiée, 19, rue des Alliés, L-4412 Belvaux, Luxembourg.
Email: hello@letzprint.lu · Authorised representative: Tom Schockmel & Jessica Avarello.
Data protection contact: No data protection officer has been appointed; for any request please write to hello@letzprint.lu..

2. Data processed

  • Appointment booking: name, email, telephone number, details about the animal (name, species, optional details), reason for visit/notes; for multi-animal appointments, several animals.
  • Customer account (optional): login credentials, saved animals, booking history, favourites.
  • Reviews: stars and text following a completed visit; after moderation, publicly visible.
  • Document upload (optional): files you attach to an appointment (e.g. prior findings), visible only to you and the respective practice.
  • Communication: email confirmations/reminders and – where a telephone number is stored and consent has been given – SMS; vaccination/preventive-care reminders.
  • Technical data: IP address, timestamp, browser/device information – for security and abuse prevention (server logs, rate limiting, bot protection) as well as an internal activity/audit log.

3. Purposes and legal bases

  • Appointment booking and account management – Art. 6(1)(b) GDPR (contract/pre-contractual).
  • Security, fraud/abuse prevention (rate limiting, Turnstile bot protection, audit log) – Art. 6(1)(f) GDPR (legitimate interest).
  • Reminders, vaccination/preventive-care notices, review invitations, marketing – Art. 6(1)(a) GDPR (consent), revocable at any time with effect for the future (e.g. “STOP” for SMS).
  • Publication of approved reviews – Art. 6(1)(f) or (a) GDPR.
  • Legal obligations (e.g. accounting) – Art. 6(1)(c) GDPR.

No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.

4. Recipients and processors

We disclose data only to the extent necessary for operation. Services used:

  • Hosting/servers in Luxembourg (platform operation).
  • Cloudflare (CDN/proxy and “Turnstile” bot protection): receives the IP address for delivery and protection.
  • Stripe (payment processing for practice subscriptions): only for paying practices.
  • OpenStreetMap (map tiles): when a map is loaded, the IP address is transmitted to OpenStreetMap.
  • Email/SMS dispatch service for confirmations/reminders – no external e-mail/SMS dispatch provider is currently active; the provider will be named here once activated.
  • Akismet (spam protection for forms), where active.
  • Practice integrations (webhooks): for practices on the highest tariff, booking data may be transmitted to an endpoint configured by the practice itself (the practice’s responsibility).

Contracts pursuant to Art. 28 GDPR are in place with processors. Where services transfer data to third countries (e.g. the USA), this is done on the basis of appropriate safeguards (EU Standard Contractual Clauses or an adequacy decision).

5. Retention period

  • Booking and account data: until the account is deleted or for as long as required to fulfil the purpose.
  • Uploaded appointment documents: automatic deletion 30 days after the appointment.
  • Server logs/security data: short-term, then deletion/anonymisation.
  • Records subject to a statutory retention obligation: until the respective period expires.

6. Data security

Transmission is encrypted (TLS/HTTPS). Particularly sensitive information is stored encrypted; access protection, rate limiting and an audit log secure access. Private documents can only be retrieved via an access-protected path that is locked down on both the server and application side.

7. Your rights

You have the right to access, rectification, erasure, restriction, data portability and objection, as well as the right to withdraw consent given. Logged-in customers can initiate a data export and request account deletion in their account under “Privacy” (self-service).

Right to lodge a complaint with the supervisory authority: Commission nationale pour la protection des données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg – cnpd.public.lu.

8. Cookies and local storage

We use only technically necessary cookies/storage: login session, selected language (Polylang) and bot protection (Cloudflare Turnstile). These are required for operation and do not require consent. No tracking for advertising purposes takes place.

9. Minors

The service is aimed at adult animal owners. Accounts and bookings should not be created by minors without the consent of a parent or guardian.

Last updated: June 2026 (draft).