Menu

Interactive customisation requires JavaScript. You can view the card and use the links below. Card preview

Readability, Use your browser’s zoom to enlarge the text.

Version dated 4 September 2026

Privacy

Controller

MOLDEREZ-CONSULT SRL, 13/5 Square Valère Gille, 1050 Ixelles, Belgium, VAT BE0842.262.084, controls UFoundMe! processing. Privacy contact: hello@ufoundme.eu.

Data and purposes

Account and authentication data secure access; pet profile, photograph, card, QR and selected medical details provide the service; addresses, order, invoice and Mollie references support purchase, delivery and accounting; encrypted messages and reports enable and protect chat; name, e-mail and message support replies to the contact form; optional first name, e-mail, language and consent evidence support requested campaign communications; language preferences and minimal logs operate and defend the service. Legal bases are contract, pre-contractual steps, legal obligation, legitimate security interests and consent where required.

Protected by default and Essential mode

With Protection, owner and trusted-contact details are not published on the card: contact uses the private chat. If Protection is not renewed after the grace period, the card moves to Essential and the account e-mail address becomes the visible direct contact. Only other information selected by the owner to help the pet is accessible through the QR or URL; medical display can be switched off. Public cards use an unguessable link and a no-index instruction. No full payment-card data, sale of data or advertising profiling.

Recipients and processors

OVHcloud hosts the service in France, including the Gravelines region. Other necessary recipients are the email provider, Mollie for payment, the delivery carrier, and Google only if you choose Google sign-in. Langbly may receive public-card text fields and chat text for translation. Z.AI (JINGSHENG HENGXING TECHNOLOGY PTE. LTD., Singapore) is our optional technology partner for Wall of Fame pre-screening: only when you leave the option selected, it receives the WebP re-encoding and caption. You may choose human-only review with no transfer to Z.AI. Transfers outside the EEA require GDPR Chapter V safeguards.

Wall of Fame and automation

Before submission, you choose either Z.AI pre-screening followed by a human decision, or human-only review. Unticking the AI option prevents the photograph and caption from being sent to Z.AI. Z.AI publishes nothing: a human operator always decides and the QR must be blurred before publication. A rejected submission is erased; a pending submission is erased after 30 days; a published photograph remains until withdrawal by its author or a moderation decision.

Retention

Browser registration draft: 2 hours; Studio draft including photograph: 24 hours. Expired OTP, Magic Link and e-mail change request: no more than one additional day. Encrypted chat content: up to 30 days. Chat report and minimal associated metadata: 365 days. Metadata for sent or abandoned email, without content: 90 days. Unconfirmed campaign signup: 7 days; withdrawn signup: 30 days; confirmed signup: until withdrawal. Aggregate-only analytics: 400 days. Minimized audit evidence: 5 years. Orders, invoices and legally required accounting records: generally 10 years. Active accounts, cards and purchases remain for the service; after closure, only data required by law or to defend claims is retained, then erased or anonymised. A legal hold suspends the affected deletion.

Rights and complaints

Request access, rectification, erasure, restriction, objection, portability or withdrawal of consent at hello@ufoundme.eu. State the account address and your request; proportionate identity verification may be required. We answer without undue delay and within one month, extendable by two months for a complex request with notice during the first month. You may complain to the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, dataprotectionauthority.be. Accounts are for people aged 18 or over.

Security and breaches

Restricted access, UFoundMe! separation, CSRF protection, rate limits, secrets kept outside the repository, encrypted chats and mail queue, content-free audit logs and scheduled deletion reduce risk. No system is infallible. Each breach is assessed and documented and, where GDPR requires it, notified to the authority within 72 hours and to affected people.

Chat location and photographs

Location and photographs are always optional in chat. The browser asks for location only after the “Share my location” action. Refusal does not block the conversation. Consent and its date are recorded; coordinates and photographs are encrypted, limited to participants and deleted within 30 days. Photographs are checked, re-encoded as WebP without unnecessary metadata, never published automatically and can be deleted by their sender.

Optional cart reminder

At checkout, an unticked checkbox lets you request one e-mail reminder two days after an order remains unpaid. The e-mail address, language and order reference are used only for this purpose. The reminder is cancelled as soon as payment is confirmed; no second reminder is sent. Its content is encrypted in the delivery queue, then erased after delivery or abandonment; minimal metadata is kept for no more than 90 days.

Questions? hello@ufoundme.eu →
Back to top