VETERINARIAN-LED · REPTILE HEALTH REGISTRY · EUROPE
§ 01 — PRIVACY AND GDPR

How ERHR handles information.

This notice explains how personal data and confidential sample information is handled in connection with accounts, test orders and test reports.

Data controller

European Reptile Health Registry (ERHR), operated by veterinarian Mark Krabbe in Denmark, determines the purposes and means of the registry’s processing of personal data. ERHR is a privately operated company; it is not an official EU institution, public authority or government body. Privacy requests may be submitted through the contact channel supplied with your order or by replying to ERHR correspondence.

Information we process

We process account and contact details, delivery information, registered animal information, orders, sample identities and events, selected investigations, laboratory source documentation and issued test reports. Authentication providers also process the information needed to sign you in.

Purposes and legal basis

Information is used to create and secure accounts, prepare and deliver kits, maintain sample traceability, perform and document requested testing, issue and verify reports, answer enquiries, prevent misuse and meet legal obligations. Processing is based as applicable on performance of a contract, legitimate interests in secure and traceable registry operation, legal obligations and consent where consent is specifically requested.

Full confidentiality and access

Private customer, delivery, order, sample and original laboratory information is treated as confidential. Access is limited according to role to the account holder and authorised ERHR, laboratory or technical service personnel who need it to provide or secure the service. Only the limited fields shown in the public verification lookup are public.

Recipients and service providers

Relevant information may be shared with the performing veterinary laboratory, delivery providers, authentication, hosting, database, storage and operational service providers, and public authorities where required by law. Providers may process information only for their assigned service and under applicable data-protection obligations.

Storage, security and international transfers

Access controls, account authentication and restricted private document storage are used to protect information. If a provider processes information outside the EU/EEA, ERHR requires a valid GDPR transfer basis and appropriate safeguards. No online service can promise absolute security, but suspected incidents are assessed and handled under applicable law.

Retention

Personal and operational information is kept only as long as needed for the stated purposes and applicable documentation, accounting, veterinary, dispute and legal requirements. Public verification records may need to remain available to preserve report authenticity and correction history. Information that is no longer required is deleted or anonymised where legally and technically possible.

Your GDPR rights

Depending on the circumstances, you may request access, correction, deletion, restriction, objection and data portability, or withdraw consent without affecting earlier lawful processing. Identity may be verified before a request is completed. Some information must be retained where a legal obligation or overriding legitimate reason applies.

Questions and complaints

Contact ERHR first through your order correspondence so the request can be investigated. You also have the right to complain to the Danish Data Protection Agency (Datatilsynet) or the competent supervisory authority where you live or work.

Cookies and marketing

The service uses necessary first-party storage to maintain sign-in, remember language and support interface preferences. ERHR does not currently use advertising or marketing cookies and does not sell personal data.

Last updated: 22 September 2026.