๐Ÿพ
KAVORA

Privacy Policy

Version 1.2 ยท Effective 28 July 2026 ยท VEMIORA LTD (Company No. 17352395)
Book I

General Provisions

Article 1 โ€” Introduction and Acceptance

This Privacy Policy explains how VEMIORA LTD ("Vemiora", "we", "us") collects, uses, discloses, and protects personal data when a person accesses, browses, or uses the Kavora Platform.

By creating an account or otherwise using the Platform, users confirm that they have read and understood this Privacy Policy.

This Privacy Policy operates together with the Terms & Conditions and the User Agreement. Where a term is defined in those documents, it carries the same meaning here.

Article 2 โ€” Definitions

Platform

Means Kavora Platform, including all mobile applications, websites, backend systems, APIs, and future services operated by VEMIORA LTD.

Personal Data

Means any information relating to an identified or identifiable individual.

Processing

Means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.

Customer

Means any user seeking pet-related services.

Provider

Means any individual or company offering services through the Platform.

Booking

Means a service request created through the Platform.

Trust Score

Means the Platform-generated trust indicator described in Article 15.

Article 3 โ€” Scope

This Privacy Policy applies to personal data processed through the Platform, including data collected during registration, booking, payment, verification, support, and ordinary use of the mobile applications and website.

It does not apply to third-party websites or services that the Platform may link to, including payment processor pages operated by Stripe, PayPal, or Wise, which are governed by those providers' own privacy notices.

Article 4 โ€” Data Controller

VEMIORA LTD, a company registered in England and Wales (Company Number 17352395), registered office 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom, is the data controller responsible for personal data processed through the Platform.

Contact details for privacy requests are set out in Article 35.

Book II

Information We Collect

Article 5 โ€” Account Information

Full name.

Email address and password, managed through Firebase Authentication. Vemiora does not store passwords in plain text; authentication credentials are handled by Firebase's authentication infrastructure.

Selected country, preferred language, and account role (Customer or Provider).

Acceptance records for the Terms & Conditions, this Privacy Policy, and the User Agreement, including version and timestamp.

Article 6 โ€” Pet Information

For Customers who register a pet: species, breed, age, medical conditions, vaccination status, behavioural notes, location, and photographs supplied for the pet's profile.

This information is collected because Providers require it to deliver safe, appropriate care, and is shared only with a Provider engaged for a Booking involving that pet.

Pet medical and vaccination information describes an animal and is used only for animal welfare and safe service delivery. Users should not upload a person's medical records or unrelated human health information.

Article 7 โ€” Provider and Verification Information

Business or individual profile information: display name, provider type, years of experience, languages spoken, service areas, and biography.

Verification documents required to activate a Provider profile, which may include government identification, commercial licence numbers, and professional licence documentation, uploaded to protected Cloud Storage locations accessible only to the Provider and platform administrators.

Seller-reporting information required by applicable tax law, which may include legal name, primary address, date of birth or company registration details, tax identification numbers, VAT registration details, financial-account identifiers, and the identity of an account holder where different from the Provider.

Verification status, trust indicators, and completed-booking history used to determine eligibility to appear publicly on the Platform.

Article 8 โ€” Booking, Communication and Review Information

Booking details including service selected, preferred date and time, price, currency, and notes exchanged between a Customer and Provider.

Reviews submitted after a completed Booking.

Support tickets, reports about other users, and blocks placed between users.

Article 9 โ€” Payment and Financial Information

Vemiora does not receive or store raw payment card numbers. Card payments are processed directly by Stripe or PayPal, and payouts to verified Providers may be processed through Stripe Connect or Wise.

Vemiora stores payment-related records that do not include full card numbers: subscription and trial status, checkout session identifiers, payment provider account identifiers (such as a Stripe Connect account id or a Wise recipient id), and transaction status.

Payment ledger entries reflecting amounts owed, commission, and payout status. These records are controlled exclusively by server-side systems; no client application can alter them directly.

For digital-platform reporting, Vemiora may record the consideration paid or credited to each Provider by quarter, the number of services, and the amount of fees, commissions, or taxes withheld or charged.

Article 10 โ€” Location Information

Approximate or precise location is collected only when a user grants device permission or supplies an address as part of a pet, Provider, or Booking profile.

Location data is used to show relevant, registered, verified Providers near a Customer, and is not used to import unrelated third-party listings.

Article 11 โ€” Device, Usage and Security Information

Technical signals used to protect the Platform, including Firebase App Check attestations that confirm requests originate from a genuine, unmodified installation of the app rather than a scripted or tampered client.

As of 28 July 2026, Firebase Crashlytics and Firebase Analytics are active on supported platforms (iOS, Android, macOS, and, for Analytics, web). They collect device type, operating system version, app version, crash diagnostics, and in-app usage events such as screens viewed, strictly to diagnose faults and improve reliability. This tooling is not active on Windows or Linux, where no Crashlytics or Analytics provider exists yet.

Article 12 โ€” Information from Other Sources

Where lawful and necessary, Vemiora may receive limited information from payment processors (such as payment status) or from verification and fraud-prevention partners, strictly to operate the Platform safely.

Book III

How We Use Information

Article 13 โ€” Purposes of Processing

To create, secure, and administer accounts.

To operate Bookings, payments, reviews, and dispute resolution.

To process payments and Provider payouts through Stripe, PayPal, and Wise.

To verify Provider identity and eligibility before allowing a profile to become publicly visible.

To show a Customer relevant, registered, verified Providers, including by approximate proximity where location is provided.

To prevent fraud, abuse, and unauthorised access, including through Firebase App Check.

To provide customer support and respond to reports, complaints, and legal requests.

To comply with legal, tax, and regulatory obligations applicable to Vemiora.

To improve the Platform's quality, reliability, and safety.

Article 14 โ€” Legal Bases for Processing

Where the UK GDPR, EU GDPR, or an equivalent framework applies, Vemiora relies on the following legal bases as applicable: performance of the contract formed by the Terms & Conditions and User Agreement; compliance with a legal obligation; Vemiora's legitimate interests in operating a safe, functioning marketplace; and, where required, the user's consent, for example for optional location permissions or future marketing communications.

Seller identity, tax, transaction, and payout information required for digital-platform reporting is processed to comply with Vemiora's legal obligations. It is not processed on the basis of marketing consent.

Article 15 โ€” Automated Decision-Making and Trust Score

The Platform calculates a Trust Score from objective account activity, such as completed Bookings, verification status, and dispute history, to help Customers assess a Provider.

This score supports, but does not replace, human review of verification documents and disputes. It is not used to make legal or similarly significant decisions about a user without the ability to request human review through Platform support.

Article 16 โ€” Marketing Communications

Vemiora may send service communications necessary to operate an account, such as booking confirmations, verification updates, and security alerts, regardless of marketing preferences.

Optional marketing communications, where introduced, will only be sent with the user's consent or another valid legal basis, and every such communication will include a clear way to opt out.

Article 17 โ€” Artificial Intelligence Features

Consistent with Article 83 of the Terms & Conditions, future versions of the Platform may incorporate artificial intelligence technologies to assist users, improve recommendations, and improve fraud detection.

Any such feature will be designed so that artificial intelligence does not replace human judgement in legal, financial, or dispute decisions unless explicitly permitted by future Platform policies and applicable law, and this Privacy Policy will be updated before such a feature processes personal data in a materially new way.

Book IV

Sharing, Disclosure & International Transfers

Article 18 โ€” Sharing Between Customers and Providers

Information reasonably necessary to complete a Booking is shared between the Customer and the Provider engaged for that Booking, such as pet care information, booking location, and communication needed to deliver the service.

Article 19 โ€” Service Providers and Processors

Vemiora uses vetted infrastructure and service providers to operate the Platform, including Google Firebase for authentication, database, storage, functions, and app-integrity services.

These processors act under Vemiora's instructions and are contractually restricted from using personal data for their own purposes.

Article 20 โ€” Payment Processors

Stripe, PayPal, and Wise process payment, subscription, and payout information under their own applicable privacy notices and regulatory status as payment institutions.

Vemiora shares only the information necessary to process a payment or payout, such as an amount, currency, and the relevant user identifier.

Article 21 โ€” Legal and Safety Disclosures

Personal data may be disclosed where required by law, to respond to a valid legal process, to protect the rights, property, or safety of Vemiora, its users, or the public, or to investigate suspected fraud or violations of the Terms & Conditions.

Where digital-platform reporting rules apply, Vemiora may disclose verified Provider identity, address, tax identifiers, financial-account information, quarterly consideration, transaction counts, commissions, fees, and taxes to HM Revenue & Customs or another competent tax authority, and provide the Provider with a copy of the information reported.

Article 22 โ€” Business Transfers

If Vemiora is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to the same protections described in this Privacy Policy or notice of any material change.

Article 23 โ€” No Sale of Personal Data

Vemiora does not sell personal data to third parties as a data product.

Article 24 โ€” International Data Transfers

Vemiora is registered in the United Kingdom and the Platform operates internationally. Personal data may be processed in countries other than the user's own, including where Vemiora's infrastructure providers operate data centres.

Where personal data is transferred outside the United Kingdom or European Economic Area, Vemiora uses appropriate safeguards required by applicable law, such as adequacy decisions or standard contractual clauses, before completing such a transfer.

Book V

Security, Retention & Your Rights

Article 25 โ€” Security Measures

Vemiora applies technical and organisational safeguards proportionate to the sensitivity of the data involved, including deny-by-default access rules on the Platform's database and file storage, restricted access to verification documents, encrypted transport, and Firebase App Check attestation on sensitive server requests.

No online system can guarantee absolute security. Users are responsible for keeping their account credentials confidential and for reporting any suspected unauthorised access without delay.

Article 26 โ€” Data Retention

Personal data is retained only for as long as reasonably necessary for the purposes described in this Privacy Policy, including the duration of an active account, the completion and dispute period following a Booking, and any longer period required for financial record-keeping, tax, fraud prevention, or other legal obligations.

Digital-platform due-diligence and reporting records are retained for at least five years after the relevant reportable period. Company tax and accounting records are normally retained for at least six years after the relevant accounting period, and longer where an enquiry, litigation, fraud-prevention need, unresolved dispute, or other legal requirement applies.

Verification documents and financial records may therefore be retained beyond account closure where Vemiora is legally required or has a documented lawful need to keep them.

Article 27 โ€” Your Rights

Subject to applicable law, users may have the right to request access to their personal data, correction of inaccurate data, deletion of data, restriction of processing, a portable copy of their data, and to object to certain processing.

These rights are not absolute and may be limited where Vemiora has a legal obligation or legitimate ground to retain particular information, such as an unresolved Booking, dispute, or financial record.

Article 28 โ€” Exercising Your Rights

Requests to exercise a right described in Article 27 may be submitted through Platform support using the contact details in Article 35. Vemiora will respond within the timeframe required by applicable law.

Article 29 โ€” Children's Privacy

The Platform is not directed at children and is not intended for use by anyone below the age required to enter a binding agreement in their jurisdiction. Vemiora does not knowingly collect personal data from children; a parent or guardian who believes a child has provided personal data may contact Platform support for its removal.

Article 30 โ€” Account Deletion

A user may request account deletion at any time through the Platform. Deletion requests are processed under the Platform's account-deletion workflow and do not remove records Vemiora is required to retain for financial, legal, or dispute-resolution purposes.

Book VI

Cookies, Changes & Contact

Article 31 โ€” Cookies and Similar Technologies

The Platform's website may use strictly necessary cookies or similar local storage required for authentication and basic functionality.

Any non-essential cookies, such as those used for analytics, will only be set with appropriate notice and, where required by law, the user's consent.

Article 32 โ€” Do Not Track

Because there is no common industry standard for responding to browser "Do Not Track" signals, the Platform does not currently respond to them differently from other visitors.

Article 33 โ€” Changes to this Policy

Vemiora may update this Privacy Policy from time to time. Material changes will be presented in the app or on the website with a revised version number and effective date before they take effect.

Continued use of the Platform after a material change constitutes acceptance of the revised Privacy Policy, unless applicable law requires a different form of consent.

Article 34 โ€” Governing Law

This Privacy Policy is governed by the same governing law provisions set out in the Terms & Conditions, without prejudice to any mandatory data-protection rights a user has under the law of their own country of residence.

Article 35 โ€” Contact Information

Questions, complaints, and requests concerning this Privacy Policy or the processing of personal data may be submitted to customerhappiness@vemiora.uk, by telephone on +44 7541 469736, or in writing to VEMIORA LTD, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom.

Users in the European Economic Area or United Kingdom also have the right to lodge a complaint with their local data protection supervisory authority. In the United Kingdom, this is the Information Commissioner's Office.

Completion Statement

This Privacy Policy, together with the Terms & Conditions and the User Agreement, defines how VEMIORA LTD collects, uses, and protects personal data while operating the Kavora Platform for customers, providers, and administrators worldwide.