Armidus Privacy Policy

Effective date: July 22, 2026

Armidus, Inc. ("Armidus," "we," "us," or "our") provides a veterinary post-visit care and operations platform for veterinary clinics and pet owners. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit armidus.com, use an Armidus clinic or owner application, communicate with us, or otherwise interact with our services.

In this Policy, "Service" includes our public website, clinic applications, owner applications, APIs, support and contact channels, and related services. "Clinic" means a veterinary clinic, hospital, practice group, or other organization using the Service. "Clinic Data" means information submitted to or collected through the Service by or for a Clinic, including clinic, owner, animal patient, care-plan, task, and interaction information.

This Policy should be read with our Terms of Service at https://armidus.com/terms, Cookie Policy at https://armidus.com/cookies, Data Processing Addendum at https://armidus.com/dpa, Subprocessors and Service Providers page at https://armidus.com/subprocessors, Security page at https://armidus.com/security, and Data privacy overview at https://armidus.com/data-privacy.

1. When Armidus acts for a Clinic and when it acts for itself

Our role depends on the information and why we process it.

1.1 Information processed for a Clinic

For most Clinic Data, the Clinic decides why the information is collected and how it is used in providing veterinary care. Armidus processes that information for the Clinic to provide the Service. Depending on the applicable law, the Clinic is the controller, business, or organization, and Armidus is its processor, service provider, or data intermediary.

The Clinic is responsible for its veterinary records, clinical decisions, owner communications, privacy notices, permissions, and lawful basis for providing Clinic Data to Armidus. If you are a pet owner and your request concerns a record controlled by a Clinic, we may refer your request to that Clinic or assist it in responding.

1.2 Information processed by Armidus for its own purposes

Armidus determines how and why it processes information used to administer accounts and subscriptions, secure and operate the Service, manage billing, respond to inquiries, meet legal obligations, and understand use of our public website. For that information, Armidus acts as the controller, business, or organization, as those terms apply.

2. Information we collect

The information we collect depends on how you interact with Armidus.

2.1 Clinic and professional account information

We may collect:

2.2 Pet owner account and contact information

We may collect:

An Armidus identity can be recognized across regional applications, but the owner profile and patient links in each country environment are separate. They are not automatically synchronized or merged across regions.

2.3 Animal patient and care information

Clinics and owners may provide information relating to animal patients and post-visit care, including:

An Armidus "Patient" is a clinic-specific record for an animal. Records created by different Clinics are not automatically merged, even when they may refer to the same animal.

Animal health information is not human medical information, but it can still be confidential Clinic Data and may reveal personal information about owners, Clinic personnel, or other individuals. Users should not include unnecessary human health, financial, identity-document, or other highly sensitive personal information in animal care records, owner submissions, support requests, or contact forms.

2.4 AI inputs and output

When a Clinic uses an AI-assisted feature, we may process the source text, selected animal context, supported block-library information, prompts, generated output, validation results, model identifiers, and operational metrics needed to provide and monitor that feature.

Current AI features help organize or structure information supplied by a Clinic. The application treats model output as untrusted, validates its structure, and requires Clinic review before it is used as owner-facing care content. Armidus does not use AI features to diagnose an animal, prescribe treatment, or replace veterinary judgment.

2.5 Subscription and transaction information

We may collect:

Payment-card numbers and security codes are entered on Stripe-hosted surfaces. They do not pass through Armidus application servers. Stripe processes payment information under its own terms and privacy notice.

2.6 Website, device, and usage information

When you visit the website or use the Service, we and our providers may collect:

2.7 Communications, forms, and support information

We collect information you provide through contact, demo, support, billing, security, legal, and privacy forms, or through other communications with us. This may include your name, business contact details, Clinic, request type, message, attachments, and our response and follow-up records.

Do not submit passwords, payment-card details, claim links, patient records, or other sensitive Clinic Data through a general website or legal contact form.

3. Where information comes from

We collect information:

4. How we use information

We use personal information to:

Where a law requires a legal basis, we process information as necessary to perform a contract or take requested pre-contract steps, comply with law, pursue legitimate interests that are not overridden by individual rights, or based on consent. The applicable basis depends on the activity and jurisdiction. Where processing is based on consent, consent can be withdrawn for future processing, although withdrawal does not affect prior lawful processing.

5. How we disclose information

We may disclose personal information as follows.

5.1 Clinics and authorized users

We disclose Clinic Data within the relevant Clinic organization and to linked owners as directed by the Clinic and permitted by the Service. Clinic personnel may see owner follow-through information and owner submissions connected to the Clinic's patient records. Owners may see only records linked to their verified regional account.

5.2 Service providers and subprocessors

We use providers for cloud infrastructure, databases, authentication, transactional email, AI processing, payments, website hosting, forms, customer relationship management, business email, monitoring, and related operations. They receive only the information reasonably needed for their role and are subject to applicable contractual and confidentiality obligations.

Our current provider list, processing purpose, role, and relevant location information are published on our Subprocessors and Service Providers page. Not every provider receives Clinic Data. For example, HubSpot generally handles website inquiry, chat, marketing-site analytics, and business-relationship data, and Microsoft 365 generally handles business communications and internal working documents. They should not be used as repositories for patient records.

5.3 Payment processing

We disclose billing and transaction information to Stripe to provide Checkout, subscription billing, tax, fraud-prevention, and customer-portal functions. Stripe may act as our processor for some functions and as an independent controller for functions it determines under applicable law.

5.4 Legal, safety, and rights protection

We may disclose information when we reasonably believe it is necessary to:

Where lawful and appropriate, we seek to review requests, limit disclosure to what is required, and notify the affected customer before disclosure.

5.5 Corporate transactions

Information may be disclosed in connection with due diligence, financing, reorganization, merger, acquisition, sale of assets, insolvency, or another corporate transaction. A recipient will be required to handle personal information consistently with applicable law and any continuing contractual obligations.

5.6 With direction or consent

We may disclose information at the direction of a Clinic or individual, with appropriate consent, or as otherwise described when the information is collected.

6. No sale of Clinic Data

Armidus does not sell identifiable Clinic Data. We do not use Clinic Data for third-party advertising.

We do not sell personal information for money. We also do not disclose personal information for cross-context behavioral advertising. If our practices change, we will update this Policy and provide any notice and choice required by law before the change applies.

Armidus may use Service Data and aggregated or de-identified information to operate, secure, measure, and improve the Service, provided it does not identify a Clinic, owner, user, or other individual and we do not attempt to re-identify it. Any future use of customer data for research, real-world evidence, product development beyond providing and improving the Service, or a third party's commercial purpose will require separate legal review and any agreement, notice, authorization, or consent required by law.

7. AI processing

Clinic-authored source text and limited animal context may be processed through Google Cloud Vertex AI when an authorized Clinic user invokes an AI feature. For the Singapore Service, Armidus configures Vertex AI to use a supported Singapore regional endpoint in the same country-specific Google Cloud project. Features that require a global endpoint or processing outside the configured region are not enabled for Clinic Data.

Google's applicable Cloud terms state that Google will not use Customer Data (as Google defines that term in its Cloud agreement) to train or fine-tune AI or machine-learning models without prior permission or instruction. Prompt and generated-output handling remains subject to the Google Cloud agreement, data processing addendum, security controls, and any limited security, abuse-prevention, or legal processing described there.

Clinics should provide only information needed for the task and should avoid including owner contact details or other direct identifiers in free-text AI inputs unless necessary and authorized. AI output is subject to human review and is not a medical diagnosis or autonomous clinical decision.

8. Regional environments and international transfers

Armidus uses a separate production environment for each country in which the Service is launched. Each environment has its own application services, database, and secrets. Core Clinic, owner, patient, care-plan, task, and interaction records for the Singapore Service are stored in Armidus's Google Cloud Singapore environment. Regional owner and patient application records are not automatically synchronized or merged with another country environment.

Regional storage does not mean that every category of information remains only in that country. The Singapore Vertex AI workflow is configured for supported regional processing, but providers supporting identity, transactional email, payments, website forms, CRM, business communications, monitoring, and support may process limited information in the United States or other locations where they or their subprocessors operate. Service metadata that is outside a Google Cloud data-location commitment may also be processed as described in Google's terms. Authorized personnel may access information from another location when necessary for support, security, legal compliance, or incident response.

When personal information is transferred internationally, we use measures appropriate to the information, provider, and applicable law. These may include contractual data-protection terms, transfer clauses, provider due diligence, regional configurations, access controls, and security safeguards. For Singapore personal data transferred outside Singapore, we take steps intended to ensure a standard of protection comparable to the protection required by the Personal Data Protection Act 2012.

9. Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, follow Clinic instructions, meet veterinary-record and contractual needs, protect the Service, resolve disputes, enforce agreements, and comply with legal, tax, accounting, and regulatory obligations.

Retention depends on the information and context:

If information is subject to a legal hold, security investigation, dispute, or regulatory requirement, we may retain it until that matter is resolved.

10. Security

We use administrative, technical, and organizational measures designed to protect personal information. Current measures include country-specific cloud environments, authenticated access, Clinic and owner authorization checks, encryption in transit and at rest, secrets management, restricted production ingress, backups, monitoring, and logging rules that prohibit raw secrets, tokens, and complete owner or patient payloads.

More information is available on our Security and Data Privacy page. No method of transmission, storage, or processing is completely secure, and we cannot guarantee absolute security. Users are responsible for protecting their accounts, authentication methods, devices, and authorized-user access.

11. Your privacy rights and choices

Depending on your location and the law that applies, you may have rights to:

These rights are not absolute. We may need to verify your identity and may decline or limit a request where permitted by law, including to protect another person's rights, preserve Clinic-controlled veterinary records, maintain security, comply with law, or establish or defend legal claims.

To submit a request, use the Privacy option at https://armidus.com/submit-request. Provide your name, contact address, relevant Clinic if any, request type, and enough detail to identify the information. Do not include patient records, passwords, payment-card details, or claim links in the form. We may ask for additional verification through a secure channel.

If Armidus processes the relevant information for a Clinic, please contact the Clinic first. We may forward your request to the Clinic and assist it as required by our agreement and applicable law.

You may opt out of non-essential marketing communications using the unsubscribe method in the message or through the Contact Form. You cannot opt out of transactional or security messages necessary to administer an account or provide the Service.

Cookie choices are described in our Cookie Policy. Where our website provides a cookie-settings control, you can use it to change non-essential cookie preferences at any time.

12. Singapore

For personal data subject to Singapore's Personal Data Protection Act 2012, Armidus applies the data-protection obligations relevant to its role, including requirements concerning purpose, notification, consent where required, protection, retention, access and correction, overseas transfers, and breach assessment and notification.

The Privacy option at https://armidus.com/submit-request and privacy@armidus.com are Armidus's published business contact channels for questions, access and correction requests, withdrawal requests, and complaints under the Act. They route requests to Armidus's Data Protection Officer. We will acknowledge and respond in accordance with applicable law. You may also have the right to raise a complaint with Singapore's Personal Data Protection Commission.

13. Australia

The Service is not yet offered through an Australian production environment. Before an Australian launch, Armidus will assess and update this Policy and its practices for the Privacy Act 1988 and Australian Privacy Principles to the extent they apply, including notice, use and disclosure, security, access and correction, overseas disclosure, and eligible data-breach requirements.

If Australian privacy law applies to a particular interaction before then, an eligible individual may use the Privacy option at our Contact Form to request access or correction or to make a complaint. We will respond within the period required by applicable law. An eligible individual may be able to complain to the Office of the Australian Information Commissioner after first giving us a reasonable opportunity to address the complaint.

14. United States and California

The Service is not yet offered through a United States production environment. Before a United States launch, Armidus will assess applicable federal and state requirements and publish any supplemental notices that apply.

If the California Consumer Privacy Act, as amended, applies to Armidus and a particular individual, that individual may have rights to know, access, correct, delete, and obtain a copy of certain personal information, and to limit certain uses of sensitive personal information. California law also provides rights to opt out of sale or sharing and to receive equal service without unlawful discrimination for exercising a privacy right.

Armidus does not sell personal information for money and does not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics about individuals. An eligible California resident may submit a request using the Privacy option at our Contact Form. An authorized agent may submit a request where permitted by law, subject to verification of the agent's authority and the resident's identity.

Nothing in this section states that Armidus currently meets the statutory thresholds that make an entity a regulated business under California law.

15. Children

The Service is intended for adults acting for Clinics or caring for animals. It is not directed to individuals under 18, and Armidus does not knowingly create accounts for children. If you believe a child has provided personal information directly to Armidus without appropriate authorization, use the Privacy option at our Contact Form.

16. Third-party services and links

The Service may link to or interoperate with third-party websites or services. When you interact directly with a third party, its terms and privacy practices apply. Armidus is not responsible for the privacy practices of a third-party site or service that we do not control.

17. Changes to this Policy

We may update this Policy to reflect changes in the Service, providers, law, or our practices. We will post the revised version with a new effective date. If a change materially affects how we use information already collected, we will provide additional notice or seek consent where required by law or contract.

18. Contact us

Use the appropriate request type at https://armidus.com/submit-request for privacy, security, legal, support, or billing matters. Privacy and data-protection requests may also be sent to Armidus's Data Protection Officer at privacy@armidus.com.

Please do not submit patient records, passwords, payment-card information, claim links, or other sensitive Clinic Data through the general form.

You may also contact us by post:

Armidus, Inc. 1111B South Governors Avenue #49736 Dover, DE 19904 United States

For notices that must be delivered in a legally recognized form, use tracked delivery and select Legal in the Contact Form to alert us that a notice was sent.