Skip to content
Equimergency
  • How it works
  • Safety
  • For veterinarians
  • FAQ
Waitlist
Waitlist

Legal

Imprint Privacy Terms

Legal

Privacy policy

This policy describes which personal data are processed when you visit equimergency.de and when you sign up for the waitlist. It is deliberately specific: what this page does in your browser, and which fields a sign-up stores, can be verified against the code that is served to you. Where a statement instead depends on the settings of a provider account and is not visible in the source, we say so on the spot.

It applies to this website only. The app will have its own privacy policy at launch.

Last updated 8 September 2026 This English text is a translation for convenience. The German version is the legally binding one. Deutsch

Contents

  1. At a glance
  2. Controller
  3. Data protection officer
  4. Hosting, delivery and transport security
  5. No cookies, no tracking, one cookie-free reach measurement
  6. Waitlist: sign-up by double opt-in
  7. Sending the confirmation email
  8. Recipients of your data
  9. Transfers to third countries
  10. Retention and deletion
  11. Your rights
  12. Changes to this privacy policy
01

At a glance

  • This website sets no cookies. Exactly one value is stored on your device: the outcome of your waitlist confirmation, in the browser’s session storage, on that one page only and only while the tab is open (section 05).
  • There is no tracking. The only statistics tool is a cookie-free reach measurement with Cloudflare Web Analytics: no cookies, no fingerprinting, no personal profiles and no tracking across other websites. That is also why there is no consent banner (section 05).
  • While you view these pages your browser makes requests to a third party in one place only: to Cloudflare, for the measurement script (static.cloudflareinsights.com) and the measurements (cloudflareinsights.com). The only exceptions are the emergency page of a box sign (/notfall) and the stable poster page (/stall): there your browser talks to our own backend at Convex, and the measurement script is not included on those pages (section 05). Every other foreign origin is technically blocked, not merely promised away.
  • We store personal data only if you actively sign up for the waitlist. The entry is created the moment you submit the form; without your confirmation it stays in the “pending” state, and only confirmed entries are ever emailed.
  • The website and the waitlist database run on Cloudflare; the database was fixed to the Western Europe region when it was created — an account setting we carry in section 06 as a checked entry.
  • All three service providers involved are US companies. We disclose the possible transfer to a third country openly rather than passing over it.
02

Controller

The controller within the meaning of Art. 4 (7) GDPR is the natural or legal person who decides on the purposes and means of processing — here, the operator of this website. The full details, including the address for service of process, are given in the imprint.

Controller (Art. 4 (7) GDPR)
Constantin Alexander Vennekel, Zwingenbergstr. 108, 47802 Krefeld, Germany — email: kontakt@equimergency.de Go to the imprint
Name, legal form, address and a contact route for data protection enquiries. Identical to the details in the imprint.
03

Data protection officer

Whether a data protection officer must be appointed follows from Art. 37 GDPR and § 38 BDSG — as a rule from twenty people permanently engaged in the automated processing of personal data, and irrespective of that in certain cases, for instance where special categories of data are processed on a large scale.

We claim no appointment here as long as none has been made.

Data protection officer
Not appointed. There is currently no obligation to appoint a data protection officer under Art. 37 GDPR, Sec. 38 BDSG.
If nobody is appointed and no appointment is required, this section should either be removed before publication or state that fact explicitly.
04

Hosting, delivery and transport security

This website is provided by Cloudflare. Pages are served from Cloudflare’s data-centre network; the waitlist logic also runs there (Cloudflare Workers).

When a page is requested, Cloudflare processes technically necessary connection data: your IP address, the requested path, the date and time of the request, the volume of data transferred and details of your browser and operating system. Without these data no connection can be established. Cloudflare also uses them to repel attacks and keep the site available.

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in providing this website securely, reliably and resistant to abuse.

Cloudflare acts as our processor in doing so, as it does for the reach measurement described in section 05, on the basis of a data processing agreement under Art. 28 GDPR. We do not reproduce the details of that agreement here. On the company’s place of establishment and the question of third-country transfers, see section 09.

Logs at Cloudflare

Cloudflare’s logging feature is switched on in this website’s configuration file (Workers Logs). Cloudflare therefore records, for every invocation of our application logic, details of that run — time, requested address and method, response status — together with the messages our code writes itself. That is a setting we chose, not a technical inevitability, which is why it appears here.

Our code writes error messages only, and none of your details: that sending an email failed, with the status code returned by the sending service, and that a sign-up or a confirmation failed technically. Email address, role and region appear in none of those messages. The requested address of a confirmation link does, however, contain the confirmation token — anyone with access to the logs can therefore see that value too.

The legal basis is Art. 6 (1) (f) GDPR: our legitimate interest in troubleshooting and operational security. We have not set a retention period of our own; Cloudflare’s default for this feature applies.

Transport security

The connection is encrypted end to end with TLS. In addition, every page response carries the Strict-Transport-Security header, which instructs browsers to access this domain over an encrypted connection only.

05

No cookies, no tracking, one cookie-free reach measurement

This website sets no cookies. There are no tracking pixels, no advertising or social-media embeds, no embedded maps and no embedded videos. A single statistics tool is included: the reach measurement Cloudflare Web Analytics. It works without cookies and without fingerprinting, builds no personal profiles and does not follow you across other websites.

Every part of the page that we author ourselves (fonts, images, stylesheet and script) is served from our own domain. The one exception is Cloudflare’s measurement script: your browser loads it from static.cloudflareinsights.com and sends the measurements to cloudflareinsights.com.

This is not merely a promise but technically enforced: every page response from this website carries a Content-Security-Policy that forbids requests to foreign origins and permits exactly these two Cloudflare addresses as the exception. Only on the emergency page of a box sign (/notfall) and on the stable poster page (/stall) does a third address join them, our own backend at Convex; we describe both further down in this section. You can read the header yourself in your browser’s developer tools.

default-src 'self'
script-src 'self' https://static.cloudflareinsights.com
style-src 'self' 'unsafe-inline'
img-src 'self' data:
font-src 'self'
connect-src 'self' https://cloudflareinsights.com
form-action 'self'
frame-ancestors 'none'
base-uri 'self'
The Content-Security-Policy header as served

Strictly speaking, that applies to the pages as served. The two waitlist endpoints — /api/waitlist and /api/waitlist/confirm — answer with data and with a redirect respectively and do not carry those headers; they serve no document in which anything could be loaded. We say so because “every response” would be a claim the source code does not support.

The emergency page of a box sign (/notfall)

Every Equimergency box sign carries a QR code. Whoever scans it lands on the emergency page of this website (/notfall/ followed by the code of the sign) and can report an emergency to the owner without having an account. On this page your browser talks to our own backend, a deployment at Convex at the address https://clean-yak-730.eu-west-1.convex.site: there the Content-Security-Policy header additionally admits this address in connect-src (looking up the sign, the SMS code, sending the report) and in img-src (the photos on the sign). On every other page except the stable poster page (/stall, see below) it stays blocked. Cloudflare’s measurement script is not included on the emergency page because its address contains the code of the sign.

What is transmitted
When the page opens, the code of the sign; in return the page shows the digital box sign, that is the horse’s name, its photos and the contact details the owner has released for it. Your browser loads the photos from the same address via links that expire after 15 minutes. When you report: your phone number, the six-digit SMS code with which you confirm it and, if you fill it in, your note on the situation (up to 500 characters). The backend sees your IP address as with any request; we use it only to limit the number of requests per sender. The page does not ask for your location; the report uses the location the owner recorded for the sign.
What does not happen
Nothing is stored on or read from your device, there is no location request and no measurement script. The horse is named only if the sign is active; an unknown or not yet activated code is answered by the backend without any information about a horse.
Recipient
Convex, Inc., San Francisco, USA, as processor under Art. 28 GDPR. Convex runs the backend of the app that the emergency page reports to. The deployment is located in the European Union, in the EU West (Ireland) region; unlike the account settings in section 06 and section 07 you can check this here, because the address of the deployment carries the region in its name (eu-west-1). For the company’s seat and the transfer to a third country see section 09; the report itself reaches the owner, their trusted contact and the stable operator (section 08).
Legal basis
Art. 6 (1) (a) GDPR for the report: the notice immediately above the button says that we pass your phone number to the owner, their trusted contact and the stable operator, for that purpose only and for this report only; by sending you consent. For confirming your number by SMS code and for limiting the number of requests per sender we rely on Art. 6 (1) (f) GDPR: our legitimate interest, and the owner’s, that nobody enters someone else’s number and that the codes on the signs cannot be tried out one after another.
Retention
We delete the phone number and the note in the automatic sweep once 90 days have passed since the report; the fact that a report came in for this horse remains with the owner in the app. The SMS code is valid for ten minutes; we store its verification data only as hash values and delete them in the automatic sweep once they have been expired for more than 24 hours.

The stable poster page (/stall)

A stable operator can put up a poster with a QR code and a join code for their stable. Whoever scans the QR code or knows the join code lands on the stable poster page of this website (/stall/ followed by the join code) and sees the poster ready to print, without having an account. On this page too your browser talks to our own backend at Convex at the address https://clean-yak-730.eu-west-1.convex.site: there the Content-Security-Policy header admits this address in connect-src, for exactly one request, the name of the stable. The page loads no images from there; it draws the QR code itself. Cloudflare's measurement script is not included on this page either, because its address contains the join code.

What is transmitted
When the page opens, the join code from the address bar; in return the backend delivers only the name of the stable and nothing else, no address, no members, no contact details. The backend sees your IP address as with any request; we use it only to limit the number of lookups per sender.
What does not happen
Nothing is stored on or read from your device, there is no location request and no measurement script. An unknown, misspelled or no longer valid join code is answered by the backend always in the same way and without any indication of whether the stable exists. The page notifies nobody and creates nothing; joining itself happens in the app only.
Recipient
Convex, Inc., San Francisco, USA, as processor under Art. 28 GDPR, in the same deployment in the European Union as for the emergency page (see above). There are no further recipients; the name of the stable is the entry recorded for that stable in the app.

Reach measurement with Cloudflare Web Analytics

What is transmitted
The page viewed (address and path), the referring page (referrer), your browser’s identification string (user agent, from which browser and device type are derived), the country derived from your IP address, and page load timings. According to Cloudflare, neither the IP address nor the user agent is used to recognise individual visitors or to track them over time; rather than counting individual IP addresses, Web Analytics measures page views. That is a statement by the provider which we cannot verify in this website’s source code; we therefore say so.
What does not happen
No cookies are set, no fingerprinting takes place and no personal profiles are built, and you are not followed across other websites. Nothing beyond what is technically required is stored on or read from your device; § 25 TDDDG therefore requires no consent, and we do not ask for one.
Recipient
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, as processor. It is the same provider that serves this website (section 04). The transfer to the United States rests on Cloudflare, Inc.’s certification under the EU-US Data Privacy Framework and, in addition, on the EU standard contractual clauses in Cloudflare’s Data Processing Addendum (section 09).
Legal basis
Art. 6 (1) (f) GDPR. Our legitimate interest is in knowing the reach and the functioning of this page: whether visitors arrive, where they come from and whether the page loads quickly for them. You may object to this processing at any time (section 11). Because the measurement recognises no person, however, we cannot attribute any data to you; you can stop the measurement by having your browser block scripts from static.cloudflareinsights.com. The page then works exactly as before.
Source at the provider
Cloudflare describes Web Analytics and its privacy statements at cloudflare.com/web-analytics, the technical workings at developers.cloudflare.com/web-analytics; Cloudflare’s general privacy policy is at cloudflare.com/privacypolicy.

One value in session storage

We set no cookies. § 25 TDDDG, however, covers any storing of information on your terminal device and any access to it, not only cookies — and one such operation does take place on this website, in exactly one place: on the page that shows the outcome of your waitlist confirmation.

Name
eq:confirm-state in your browser’s session storage (sessionStorage).
Content
One of three fixed values — ok, invalid or error. It is the outcome the server had previously appended to the address of that page. No identifier, no timestamp, no link to your email address.
Purpose
So that the page shows the same outcome after a reload and after a language switch, instead of suddenly telling you something different about your consent.
Lifetime
Confined to this tab, unreadable by other websites, deleted when the tab closes. If storage is disabled, the page works exactly as before.
Legal basis
§ 25 (2) no. 2 TDDDG. The value serves solely to display the outcome of the operation you triggered yourself.

Whether this single value is “strictly necessary” in the narrow sense is arguable: without it the page shows no outcome after a language switch — rather than the wrong one. We therefore disclose it here instead of quietly relying on the exemption.

There is no consent banner. This is the only access to your device, it serves solely to display an operation you triggered yourself, and whether it happens changes nothing about the data that reach us: none.

06

Waitlist: sign-up by double opt-in

You can add yourself to a waitlist on this website in order to be notified at launch. Sign-up uses the double opt-in procedure: when you submit the form we create your entry in the “pending” state and send you a confirmation email. Only once you click the link in it does your consent count as given and the entry as confirmed.

What is stored in the process

Email address
Required. Used to address the confirmation email and the later launch notification.
Role selected
Horse owner or veterinarian. Determines which information you receive at launch.
Region or postcode
Optional. Helps us judge in which region a launch will hold. You may leave the field empty.
Language
German or English. Determines the language of the confirmation email.
Status
Pending, confirmed or unsubscribed. Documents whether consent exists.
Confirmation token
A random string that uniquely links the confirmation link to your entry. It contains no information about you.
SHA-256 hash of your IP address
We do not store your IP address but a one-way value derived from it. It serves solely to limit sign-ups per sender to eight per hour. Such a hash is pseudonymisation, not anonymisation — we therefore continue to treat it as personal data.
Browser identification (user agent)
Together with the timestamp, evidence of the consent given, as required by Art. 7 (1) GDPR.
Timestamps
The time of sign-up, of the last change and of confirmation.

The legal basis for storing your email address, role, region and language is your consent under Art. 6 (1) (a) GDPR. You may withdraw it at any time with effect for the future; the lawfulness of processing carried out until then remains unaffected.

An informal message to the contact address given in the imprint is enough to withdraw consent; we then delete your entry in full.

For the hash of the IP address and the browser identification we additionally rely on Art. 6 (1) (f) GDPR: our legitimate interest in preventing automated bulk sign-ups and in evidencing consent.

To guard against automated entries the form contains an additional field that is invisible to people. If it is filled in, we discard the sign-up without storing anything.

Where the entries are held

Entries are held in a Cloudflare D1 database that was fixed to the Western Europe region (WEUR) when it was created. That region is a setting of our Cloudflare account: it does not appear in the source code of this website but in Cloudflare’s management console — so you cannot verify it from here. It does, however, carry part of the assessment in section 09. That is why it appears here as a field rather than as a bare assurance in the running text.

Region of the database
WEUR (Western Europe) — verified 21 Aug 2026 (Cloudflare console, wrangler d1 info: running_in_region WEUR).
WEUR (Western Europe) is expected. To be looked up in the Cloudflare console before publication and confirmed with the date checked. If the region differs, section 09 must be corrected first.
07

Sending the confirmation email

We send the confirmation email and the later launch notification via the service Resend (resend.com). To do so we transmit your email address and the content of the message to Resend.

The sender domain and the region of the account are settings of our Resend account. They too are invisible in the source code of this website, and they too carry part of the assessment in section 09 — which is why they appear here as fields to be looked up before publication.

Sender domain
equimergency.de (sending via the subdomain send.equimergency.de) — SPF and DKIM records set and verified in DNS, checked 21 Aug 2026.
The domain our messages are sent from. Before publication, check in the Resend account whether it is verified there — that is, whether the required SPF and DKIM records are set — and confirm the result with a date.
Region of the sending account
eu-west-1 — verified 21 Aug 2026 (sending DNS points to feedback-smtp.eu-west-1.amazonses.com).
eu-west-1 is expected. To be looked up in the Resend account before publication and confirmed with the date checked. If the region differs, section 09 must be corrected first.

Resend processes these data as our processor under Art. 28 GDPR. Our messages contain no tracking pixel and no open tracking. The confirmation link serves solely to document your consent.

Case-file handback in the app: When you tap “Send to my regular practice” after the treatment record is finalised, you request its disclosure to your saved practice. If that practice is not on the platform, we use Resend to email a server-generated PDF to the practice email address you provided. The PDF contains the diagnosis, treatment, medications, follow-up date and notes finalised by the treating vet, the animal profile with owner contact details at the time of handback, and the case’s triage photos. Audio recordings and unverified AI fields are not transmitted. An email that has already been sent cannot be recalled.

08

Recipients of your data

Apart from the three processors named, nobody receives your data: Cloudflare for delivery, application logic, the database and the reach measurement, Resend for sending email, Convex for the backend behind the emergency page of a box sign and the stable poster page (section 05).

The emergency page itself names one exception: if you report an emergency there, the owner of the horse, their trusted contact and the stable operator receive your phone number so that they can call you back. Your note, if you filled it in, is shown to the owner only, in the app. It says so above the button you report with, and it applies to that one report only.

We do not sell data, do not pass them on for advertising purposes and do not combine them with data from other sources. Disclosure to public authorities takes place only where we are legally obliged to make it.

09

Transfers to third countries

All three processors are companies established in the United States: Cloudflare, Inc., Resend, Inc. and Convex, Inc. Delivery runs through European locations; the database, the sending account and the Convex deployment are fixed to European regions. The underlying account settings are carried in section 06 and section 07 as entries still to be checked, the region of the Convex deployment in section 05. Even so, access from a third country, in the course of operation, maintenance and support, for example, cannot be ruled out. We disclose this expressly, as Art. 13 (1) (f) GDPR requires.

Such a transfer is permitted only under the conditions of Art. 44 to 49 GDPR. The candidates are an adequacy decision under Art. 45 GDPR — for certified US companies, the EU-US Data Privacy Framework — or standard contractual clauses under Art. 46 (2) (c) GDPR, in each case supplemented by the measures agreed in the data processing agreement.

Which safeguard applies in the individual case follows from the agreement actually concluded and from the official certification list. We will enter it here only once it has been checked and evidenced for each provider: claiming a certification without having looked it up would be a false statement.

Safeguard for Cloudflare, Inc.
Certification under the EU-US Data Privacy Framework: active entry “Cloudflare, Inc.” on the DPF list (dataprivacyframework.gov), verified 21 Aug 2026. In addition, the EU standard contractual clauses in the Cloudflare Data Processing Addendum apply.
Enter the basis that actually applies — certification under the EU-US Data Privacy Framework or standard contractual clauses — with the reference in the data processing agreement and the date it was checked.
Safeguard for Resend, Inc.
Certification under the EU-US Data Privacy Framework: entry “Resend, Inc.” (confirmed at resend.com/changelog/data-privacy-framework-certification), verified 21 Aug 2026. In addition, the EU standard contractual clauses (Decision (EU) 2021/914) in the Resend Data Processing Addendum apply.
To be entered likewise: certification under the EU-US Data Privacy Framework or standard contractual clauses, with the reference and the date it was checked.
Safeguard for Convex, Inc.
According to our research of 3 September 2026: standard contractual clauses (Module 2) in the Convex Data Processing Addendum (convex.dev/legal/dpa), which forms part of Convex’s terms of service; no entry for Convex, Inc. appeared on the DPF list at that time. Confirmation by the operator with reference and date of checking is still outstanding.
To be entered likewise: certification under the EU-US Data Privacy Framework or standard contractual clauses, with the reference in the Convex Data Processing Addendum and the date it was checked.

You may request a copy of, or the reference for, the respective safeguards via the contact address given in the imprint (Art. 15 (2), Art. 46 (1) GDPR).

10

Retention and deletion

We keep confirmed entries until we have notified you at launch or until you withdraw your consent — whichever comes first. We then delete the entry.

An entry is created the moment the form is submitted, not when it is confirmed. If confirmation does not follow, it remains in the “pending” state. There is currently no automatic deletion routine for those entries; we say so explicitly rather than claim a deadline that does not exist in the code. On request we delete any entry without delay. Should the project not be pursued further, we delete the entire set.

11

Your rights

You have the following rights vis-à-vis the controller. Exercising them is free of charge; an informal message is sufficient.

Access (Art. 15 GDPR)
You may find out whether and which data we process about you, and request a copy.
Rectification (Art. 16 GDPR)
We must correct inaccurate data and complete incomplete data.
Erasure (Art. 17 GDPR)
You may request the erasure of your data unless a statutory retention obligation stands in the way.
Restriction of processing (Art. 18 GDPR)
Instead of erasure you may require that we merely store the data and otherwise do not use them.
Data portability (Art. 20 GDPR)
You receive the data you provided in a common, machine-readable format.
Objection (Art. 21 GDPR)
You may object at any time to processing based on a legitimate interest.
Withdrawal of consent (Art. 7 (3) GDPR)
You may withdraw your consent to the waitlist at any time with effect for the future.
Complaint (Art. 77 GDPR)
You may lodge a complaint with a data protection supervisory authority — at your habitual residence, your place of work or the place of the alleged infringement.
Competent supervisory authority
The State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de
The competent authority is the data protection authority of the federal state in which the controller is established. Name, address and website must be stated. We deliberately name no authority here while the registered address is not settled.

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

12

Changes to this privacy policy

We will adapt this policy as soon as the processing described here changes — when the app launches, for instance, or when a further service provider is added. The version published here at any given time, bearing the date shown above, is the authoritative one.

Imprint Back to the homepage

Equimergency is not available yet.

In an equine emergency, please contact your own veterinary practice or the regional veterinary emergency service immediately.

The app is in closed testing and cannot dispatch emergencies at this time.

Equimergency

Equimergency connects horse owners in an emergency with verified veterinarians nearby.

Product

  • How it works
  • Safety
  • FAQ

Take part

  • For veterinarians
  • Waitlist

© 2026 Equimergency

Imprint Privacy Terms Help & support
Deutsch

Germany