Privacy Policy
1. Data Controller
The Lares Pecoris platform is operated by GROMA SRL, a Romanian legal entity with its registered office at Str. Mircea Dimitrie Rațiu nr. 5, Camera 1, Ap. 2, Timișoara, jud. Timiș, România, registered with the Trade Register under no. J2026035922005, sole registration code (CUI) 54804217, VAT-exempt, which is the controller of personal data within the meaning of the GDPR. Responsibility for data protection lies entirely with GROMA SRL. For any request concerning your data or the exercise of your GDPR rights, contact us at:
GROMA SRL is not required to designate a Data Protection Officer (DPO) within the meaning of Art. 37 GDPR, since its processing does not involve large-scale monitoring or large-scale processing of special categories of data; the address above is the single point of contact for all data-related requests.
2. The data we collect
We collect only the data necessary to provide the service and to comply with our legal obligations:
- Email address — account identifier, used for authentication via magic link and for service-related communications (account confirmation, subscription notifications, announcements of material changes to the terms).
- First and last name — optional at registration, used to personalise the interface and for the invoices issued through Stripe.
- Name of the veterinary clinic / practice — optional, provided by the user, used solely in the account profile.
- Veterinary specialty and content preferences — optional, used to personalise search results and the didactic studies displayed.
- Registration number with the College of Veterinary Physicians — optional; if provided, it serves to verify professional status.
- Subscription and payment data — chosen plan, start date, renewal date. We do not store card data. All payments are processed exclusively through Stripe; we receive only a reference token (Stripe customer ID) and the subscription status.
- Platform interactions — the queries entered in search, the didactic studies accessed, the feedback submitted (error reports, usefulness ratings). This data is used to deliver the service and to improve content quality.
- Minimal technical data — the IP address (or a hash of it), the browser type (user-agent), request timestamps — for security, abuse prevention and audit logs. Short retention (see §5).
What we do NOT collect: we do not collect data about our users' companion animals or veterinary patients. Please do not enter into the platform any identifiable information about animals, owners or real clinical records. The didactic studies are, by definition, anonymised scenarios.
3. How we use the data (legal basis)
We process your data on the following GDPR legal bases:
- Performance of the contract — Art. 6(1)(b) GDPR: delivery of the veterinary reference service (searching the guidelines, didactic studies, consensus synthesis), account management, subscription processing and the issuing of invoices.
- Legitimate interest — Art. 6(1)(f) GDPR: platform security, prevention of abuse and unauthorised access, detection of fraud attempts, improvement of content-synthesis quality based on aggregated and anonymous feedback.
- Legal obligation — Art. 6(1)(c) GDPR: retention of audit logs for compliance obligations, including fiscal obligations related to invoiced subscriptions.
- Consent — Art. 6(1)(a) GDPR: for optional marketing communications (newsletter, announcements of new features), if and when you explicitly opt in to them. Consent can be withdrawn at any time.
Lares Pecoris is a reference tool, not a clinical decision-support system and not a medical device. We do not process patients' medical data (Art. 9 GDPR does not apply under an exception regime, because we do not request and must not receive medical data about real human or animal patients).
4. Who we share the data with
We do not sell or transfer your data to third parties for advertising purposes. We share limited data with the following sub-processors, on the basis of data processing agreements (DPAs) that comply with the GDPR:
- Supabase Inc. (USA / EU) — the relational database and the authentication service. Data is stored in the EU region (Frankfurt, AWS eu-central-1). International transfer covered by Standard Contractual Clauses (SCC).
- Stripe Inc. (USA) — payment processing and subscription management. Stripe receives the billing data (email, name, plan) in order to issue invoices and process payments. International transfer covered by SCC. Stripe holds its own PCI-DSS certifications. We do not transmit card data to the Lares servers.
- Anthropic PBC (USA) — generation of the synthesised answers (the Claude model). Anonymised queries are transmitted to Anthropic for inference. International transfer covered by SCC.
- OpenAI Inc. (USA) — generation of the semantic-search vectors (embeddings) for indexing the guidelines. International transfer covered by SCC.
- Vercel Inc. (USA) — hosting of the web application and the global delivery network (CDN / Edge Network). International transfer covered by SCC.
- Resend Inc. (USA) — delivery of transactional emails (magic link, account notifications, invoices). International transfer covered by SCC.
- Upstash Inc. (USA / EU) — a Redis service for rate limiting and anti-abuse protection. It receives only a hash of the IP address and a numeric counter; it does not receive account data or content. International transfer covered by SCC.
- SmartBill SRL (Romania) — generation of fiscal invoices and their upload to the National RO e-Factura system. SmartBill receives the data needed to issue the invoice: the buyer's name, the billing address, the CUI/CIF (for B2B), the amount paid, the subscription period, the chosen plan. Data stored in the EU. DPA signed in accordance with Art. 28 GDPR.
- ANAF (the National Agency for Fiscal Administration) — a data recipient mandated by law. All invoices issued for B2B transactions (since July 2024) and B2C transactions (since January 2025) are uploaded automatically via SmartBill to the ANAF Virtual Private Space (SPV), in accordance with GEO 120/2021 and Law 296/2023. The invoice contains the buyer's identification data (name / legal name, CUI/CIF for B2B, address) and the description of the service. Legal basis: legal obligation (Art. 6(1)(c) GDPR + Art. 319 of the Fiscal Code).
All sub-processors operate under their own privacy policies and the DPAs signed with the operator of Lares Pecoris. The list of sub-processors may be updated — material changes will be announced in accordance with §9.
5. How long we keep the data
- Account data (email, name, preferences): for the lifetime of the account, plus a 30-day grace period after account deletion, to allow recovery in case of accidental deletion. When the grace period expires, the data is permanently deleted.
- History of queries and of accessed didactic studies: 24 months from creation, after which it is anonymised or deleted.
- Audit logs (audit_log): 24 months, for security and compliance. Financial audit logs related to subscriptions may be kept for 5 years in accordance with Romanian fiscal obligations.
- Technical data (IP, user-agent, timestamp in server logs): 30 days, after which it is deleted or anonymised.
- Payment data (Stripe reference, subscription status): for the duration of the active subscription plus 5 years in accordance with accounting and fiscal obligations. Card data is not stored by Lares.
6. Your rights
Under the GDPR (Regulation (EU) 2016/679) and Law 190/2018, you have the following rights:
- Right of access (Art. 15): you may request a copy of all the personal data we process about you.
- Right of rectification (Art. 16): you may request the correction of inaccurate data or the completion of incomplete data.
- Right of erasure / "right to be forgotten" (Art. 17): you may request the erasure of your data under the conditions set out by the GDPR (e.g., when the data is no longer necessary for the purpose for which it was collected). Mandatory retention (financial audit logs) may limit complete erasure for the duration of the statutory time limits.
- Right to restriction of processing (Art. 18): you may request the restriction of processing in the situations provided for by the GDPR (e.g., contesting the accuracy of the data, unlawful processing where you prefer restriction instead of erasure).
- Right to data portability (Art. 20): you may receive your data in a structured, commonly used and machine-readable format (JSON or CSV), and you may transmit it to another controller.
- Right to object (Art. 21): you may object to processing based on the controller's legitimate interest, including for direct-marketing purposes.
- Rights related to automated decisions (Art. 22): Lares Pecoris does not take automated individual decisions with significant legal effects on users. Decisions regarding account suspension for abuse are subject to human review.
- Right to lodge a complaint: you may lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP, the Romanian Data Protection Authority) — dataprotection.ro.
To exercise any right, send a written request to office@larespecoris.vet. We respond within 30 calendar days (with the possibility of extension by a further 60 days in complex cases, with prior notice).
7. International transfers
Several of the sub-processors mentioned in §4 are established in the United States of America (Stripe, Anthropic, OpenAI, Vercel, Resend, Upstash). The transfer of personal data to them is carried out on the basis of the Standard Contractual Clauses (SCC) adopted by the European Commission through Implementing Decision (EU) 2021/914, which provide appropriate safeguards in accordance with Art. 46 GDPR.
Supabase stores the data in the EU (Frankfurt); for its support and administration components located outside the EU, Supabase also applies the SCC.
You may request a copy of the applicable SCC for any sub-processor by writing to office@larespecoris.vet.
8. Cookies
Lares Pecoris uses essential cookies for the operation of the service:
- Supabase Auth session cookie — keeps the authentication state between requests. Without this cookie, you cannot stay signed in. The cookie expires when the session closes or after inactivity, according to the Auth configuration.
- CSRF cookie — protects forms against Cross-Site Request Forgery attacks. It does not contain personal data.
- Language cookie — remembers your interface language (Romanian / English / Hungarian).
Additionally, only with your consent (the cookie banner, GDPR art. 6(1)(a)), we use analytics cookies:
- Google Analytics 4 (Google Ireland Ltd.) — aggregated usage statistics (pages visited, traffic source, device type). Without consent no analytics cookie is set; only anonymous, identifier-free signals are sent.
- Microsoft Clarity (Microsoft Ireland Operations Ltd.) — understanding how the interface is used (interaction heatmaps). Loaded exclusively after consent.
You can withdraw or change your choice at any time via the "Cookies" link in the page footer — withdrawing is as easy as granting. We do not use advertising cookies, Meta Pixel or similar services, and we do not sell data.
9. Changes to this policy
When we materially change this policy (e.g., adding a new sub-processor, changing the retention periods, changing the legal basis for a processing operation), we will:
- Update the version date at the beginning of this document at least 30 days before the changes take effect;
- Notify users by email at the address registered in their account;
- Display a visible notice at the next sign-in.
Prior versions of the policy are available on request at office@larespecoris.vet.
10. Contact
For any question related to this policy, for the exercise of your GDPR rights or for notifications regarding data processing:
If you do not receive a satisfactory response within 30 days, you have the right to lodge a complaint with ANSPDCP (the Romanian Data Protection Authority) (dataprotection.ro).