Home / Privacy Policy
Version 1.0 · Valsoft Corporation Inc. d/b/a Asteris · Last updated: June 26, 2026 · Effective: June 26, 2026
1.1 The Provider
Valsoft Corporation Inc. d/b/a Asteris, which offers the NewLumen veterinary imaging platform ("NewLumen," "we," "us," or "our"), provides a cloud-native veterinary Web Picture Archiving and Communication System ("WebPACS") and related software, including DICOM image storage and archival, a browser-based zero-footprint viewer, an optional on-site/desktop image-access client, integrated scheduling and Modality Worklist (MWL) services, teleconsultation/teleradiology workflows with structured reporting, 3D and segmentation modules, and artificial-intelligence-assisted features (collectively, the "Services").
Our place of business is 7405 Trans Canada Route #100, Saint-Laurent, QC Canada H4T 1Z2. You can reach us about privacy at the contact details in Section 16.
1.2 What This Policy Covers
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data about identifiable individuals, and the rights those individuals have. It applies to: visitors to our public websites and marketing properties; Customer staff Users — the veterinarians, radiologists, technicians, administrators, and other personnel of our Customers who access the Services; pet owners / clients of our Customers, to the limited extent their contact and billing information is processed through the Services; and individuals who otherwise contact us (e.g., sales inquiries, support requests).
A "Customer" is the veterinary practice, hospital, or corporate veterinary group that subscribes to the Services.
1.3 Our Role: Controller vs. Processor
Our role depends on the data and the context. For personal data within Customer Data submitted through the Services (e.g., pet-owner contact/billing details, User account records inside a Customer's instance), NewLumen acts as Processor / Service Provider — we process on the Customer's documented instructions, and the Customer acts as Controller / Business.
For personal data we determine the purposes of ourselves — website visitors, sales/marketing contacts, account administration, billing of the Customer, security and product improvement — NewLumen acts as Controller / Business.
Where we act as a Processor/Service Provider, our processing is also governed by the data-protection terms in the Agreement and the Data Processing & AI Use Addendum (the "DPA") between us and the Customer. If there is a conflict between this Policy and a negotiated DPA on matters of processing personal data on the Customer's behalf, the DPA controls for that Customer.
1.4 Region-Specific Terms
This Policy is global, with region-specific sub-sections. The terms that apply to you depend on where you are located and where the relevant Customer operates. Defined terms are capitalized and explained in context or in the Agreement.
2.1 Animal and Imaging Data Is Generally Not Regulated Human Health Data
The Services are used to store and work with veterinary Imaging Data (DICOM studies and images) and Report Data (radiology reports and findings) about animal patients. Animals are not "data subjects," "consumers," or "individuals" under privacy laws. Accordingly: animal medical and imaging data is not protected health information ("PHI") under HIPAA — HIPAA governs human health information only; it is not "special category" / "sensitive" personal data about health under the EU/UK GDPR or analogous APAC laws; and it is not "medical information" within the meaning of human-health privacy statutes.
This materially lowers the regulatory burden compared with human-healthcare PACS. It does not lower our security commitments — enterprise veterinary buyers reasonably expect robust protection of all Customer Data, and we provide it (see Section 11).
2.2 The Human Personal Data We Do Protect
Some data flowing through or around the Services does relate to identifiable humans and is protected by Applicable Data Protection Laws. This includes: pet-owner / client information — the human owner's or client's name, contact details, and billing/payment information; Customer staff User information — names, work email addresses, role/credential information, authentication data, and activity logs; and website visitor and prospect information — data we collect from our public sites and sales/marketing interactions.
DICOM headers can contain free-text fields, and source images can contain burned-in pixel annotations, in which a human owner's or client's name or contact details may be embedded. Our de-identification methodology (see Section 7) is designed to detect and scrub these owner/client identifiers — in structured DICOM tags, in free-text fields, and in burned-in pixel data.
We collect the following categories of personal data. Not all categories apply to every individual.
Identity & contact data
Name, job title/role, work email, work phone, employer (Customer). Source: the individual; the Customer; our sales process.
Account & authentication data
Username, hashed credentials, multi-factor tokens, single-sign-on identifiers, role/permission assignments. Source: the Customer's administrator; the User.
Customer-submitted personal data (we are Processor)
Pet-owner/client name and contact details; client billing/payment references entered or imported into the Services; any human-identifying free-text within DICOM headers or reports. Source: the Customer (entered, imported, or via connected modalities/practice-management systems).
Usage, log & device data
Access timestamps, IP address, browser/device type, pages/features used, audit logs, error/diagnostic logs. Source: automatically, via the Services and our infrastructure.
Support & communications data
Support tickets, correspondence, call/meeting notes, feedback. Source: the individual; the Customer.
Billing & commercial data
Customer billing contact, purchase orders, invoices, payment status, usage metering (e.g., per-study counts). Source: the Customer; our billing systems.
Website & marketing data
Form submissions, cookie/analytics identifiers, marketing preferences, event interactions. Source: the visitor; cookies and similar technologies (see Section 12).
We use personal data for the following purposes:
5.1 EU / UK GDPR Lawful Bases
Where the EU/UK GDPR applies, we rely on the following lawful bases under Article 6(1): Contract (Art. 6(1)(b)) for providing the Services to Customers and their Users; Legitimate interests (Art. 6(1)(f)) for securing the Services, preventing fraud/abuse, product analytics, De-Identified Data creation, benchmarking, B2B marketing, and defending legal claims; Legal obligation (Art. 6(1)(c)) for billing, tax, accounting, and other regulatory obligations; and Consent (Art. 6(1)(a)) for optional cookies/analytics and certain marketing.
Where we act as a Processor for a Customer, the Customer is the controller and is responsible for establishing the lawful basis. We do not knowingly process special-category data about humans (Art. 9) — animal-health data is not human-health data and is outside Article 9.
5.2 North America, Australia, New Zealand, Singapore
In jurisdictions that do not use the "lawful basis" framework, we process personal data as reasonably necessary to provide the Services, fulfill our contracts, meet legal obligations, and pursue legitimate business interests, with notice and, where required, consent consistent with PIPEDA and Quebec's Law 25, the Australian Privacy Act 1988 and Australian Privacy Principles (APPs), the New Zealand Privacy Act 2020, the Singapore Personal Data Protection Act (PDPA), and U.S. state privacy laws including the CCPA/CPRA.
6.1 Decision-Support Only; Human-in-the-Loop
AI Features are clinical decision-support tools only. They are not a diagnosis and not a substitute for the professional judgment of a licensed veterinarian or veterinary radiologist. The human professional retains full clinical responsibility, and Customers are responsible for clinical validation of any AI output.
NewLumen does not make decisions based solely on automated processing that produce legal effects concerning an individual or that similarly significantly affect an individual. AI Features operate with a human in the loop: outputs are surfaced to qualified professionals who review, edit, and accept or reject them. AI outputs may be inaccurate or incomplete and are provided on an "as available" basis without warranty of accuracy.
6.2 What Data AI Features Process
AI Features primarily process animal Imaging Data and Report Data, which (per Section 2) is generally not regulated human personal data. To the limited extent human-identifying data is present (e.g., owner name embedded in a DICOM field), our processing of that human data through AI Features is subject to this Policy and the Agreement.
6.3 Third-Party LLM Sub-processors — Transparency
Some AI Features call third-party large language model (LLM) / AI provider services that act as Sub-processors. Where they do: we disclose their use (see the Sub-processor list referenced in Section 8); we contractually bind them to confidentiality and to not train their models on Customer Data; and we send these providers only the data necessary to deliver the feature, minimized and (where feasible) de-identified.
We offer an enterprise "no-third-party-LLM" configuration for Customers who prefer that no Customer Data be sent to external LLM providers (see Section 7.4).
6.4 De-Identified Data and Model Training
We may create De-Identified Data and Aggregated Data from Customer Data to operate, secure, benchmark, and improve the Services, including to develop and improve AI Features. AI model training on Customer Data is permitted only in de-identified form. We will not attempt to re-identify De-Identified Data, and we contractually require recipients not to do so. We never sell raw Customer Data.
7.1 Creation and Use
We may de-identify and aggregate Customer Data and use the resulting De-Identified Data and Aggregated Data to operate, secure, benchmark, analyze, and improve the Services and to develop AI Features. De-identification is performed in accordance with a recognized methodology — the DICOM standard PS3.15 Annex E (Attribute Confidentiality Profiles) — and includes removing or obscuring DICOM owner/client-identifying fields and other human identifiers.
7.2 No Sale of Raw Customer Data; No Re-Identification
We do not sell raw Customer Data, and we do not sell personal data (see Section 10). We will not attempt to re-identify any De-Identified Data or Aggregated Data, and we contractually prohibit our Sub-processors and recipients from doing so.
7.3 AI Training Uses De-Identified Data Only
Use of Customer Data to train AI models is permitted only in de-identified form. Training is forward-looking: models already trained and datasets already de-identified are not unwound. NewLumen does not sell Customer Data and will not attempt to re-identify De-Identified Data.
7.4 Enterprise No-Training / No-Third-Party-LLM Configuration
We offer an enterprise configuration in which (a) Customer Data is not used for AI training and (b) no Customer Data is sent to third-party LLM providers. Availability and any feature limitations are described in the Order Form or Documentation.
8.1 We Do Not Sell Personal Data
We do not sell personal data, and we do not "share" personal data for cross-context behavioral advertising (as those terms are defined under CCPA/CPRA). See Section 10.1.
8.2 Categories of Recipients
We disclose personal data only as necessary to provide the Services, operate our business, and comply with law — including to hosting and infrastructure Sub-processors (Google Cloud Platform), AI/LLM Sub-processors where AI Features are used, professional advisers, and as required by law.
A current list of Sub-processors is available on request by contacting us at privacy@asteris.biz. We provide Customers advance notice of new or replacement Sub-processors and an opportunity to object, as set out in the Agreement/DPA.
9.1 Where Data Is Hosted
The Services run on Google Cloud Platform. We support data residency by region — Customer Data is stored in the Google Cloud region(s) associated with the Customer's market, as described in the Order Form or Documentation. Processing necessary to operate, support, and secure the Services may occur in other locations, subject to appropriate safeguards.
9.2 Regional Transfer Safeguards
North America (US, Canada): Personal data of U.S. and Canadian individuals is processed in Google Cloud region(s) in the United States. For Canada, transfers are conducted consistent with PIPEDA's accountability principle. For individuals in Quebec, we additionally observe Quebec's Law 25.
APAC (Australia, New Zealand, Singapore): We take reasonable steps consistent with APP 8 (Australia), IPP 12 of the Privacy Act 2020 (New Zealand), and the PDPA Transfer Limitation Obligation (Singapore) for cross-border disclosures.
EU / UK / Switzerland: We do not currently offer the Services in, or target, the EEA, UK, or Switzerland. Where, today, we transfer the personal data of an EU/UK/Swiss individual outside those regions to a country without an adequacy decision, we rely on the European Commission Standard Contractual Clauses (SCCs) and applicable addenda, supplemented by technical and organizational measures.
Subject to verification and legal limits, individuals have the rights described below. Where we act as a Processor for a Customer, we will route a request to the relevant Customer (the controller) or assist the Customer in responding. To exercise rights, see Section 16.
10.1 United States — California (CCPA/CPRA) and Other State Laws
If you are a California resident, you have the right to: know / access the categories and specific pieces of personal information we collect, use, and disclose; delete personal information, subject to exceptions; correct inaccurate personal information; opt out of the "sale" or "sharing" of personal information; opt out of automated decision-making / profiling that produces legal or similarly significant effects; limit the use of sensitive personal information; and non-discrimination for exercising your rights.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising. Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, and Texas) have analogous rights, which we extend on a comparable basis.
10.2 Canada (PIPEDA and Quebec Law 25)
You have the right to access the personal information we hold about you and to request correction of inaccuracies. You may withdraw consent (subject to legal/contractual limits), and you may challenge our compliance with PIPEDA by contacting us and, if unresolved, the Office of the Privacy Commissioner of Canada. If you are in Quebec, you have additional rights under Law 25 and may complain to the Commission d'accès à l'information (CAI).
10.3 Australia (Privacy Act 1988 / APPs)
Under the APPs you may request access to your personal information (APP 12) and correction of it (APP 13). You may also complain about how we handle your personal information; if unresolved, you may contact the Office of the Australian Information Commissioner (OAIC).
10.4 New Zealand (Privacy Act 2020)
You have the right to access and request correction of your personal information (IPP 6 and IPP 7). You may complain to the Office of the Privacy Commissioner (New Zealand) if you believe we have interfered with your privacy.
10.5 Singapore (PDPA)
You may request access to and correction of personal data we hold, and withdraw consent to its collection, use, or disclosure (subject to legal/contractual consequences). You may contact our Data Protection Officer (Section 16) and, if unresolved, the Personal Data Protection Commission (PDPC).
10.6 EU / UK / Switzerland (GDPR)
To the extent we process the personal data of an individual in the EEA, UK, or Switzerland, that individual has the rights to: access; rectification; erasure; restriction of processing; data portability; object to processing; withdraw consent where processing is consent-based; and lodge a complaint with a supervisory authority. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — and, as stated in Section 6.1, we do not make such decisions.
10.7 How We Handle Requests (All Regions)
We will acknowledge and respond within the timeframe required by Applicable Data Protection Laws. We may need to verify your identity and may decline or limit a request where an exception or legal obligation applies; we will explain why and, where the applicable law provides an appeal right, how to appeal. There is no charge for most requests; manifestly unfounded or excessive requests may incur a reasonable fee or be refused as permitted by law.
We maintain administrative, technical, and physical safeguards designed to protect personal data, appropriate to its sensitivity and the risk, including:
Data Breach Notification
If a personal-data breach affecting Customer Data occurs, we will notify the affected Customer without undue delay and no later than forty-eight (48) hours after we confirm the breach, and will provide information reasonably available to support the Customer's own notification obligations. We are progressing a security program aligned to recognized frameworks, including a SOC 2 roadmap. Our SOC 2 Type II attestation is in progress, with completion expected by mid-2027.
No system is perfectly secure; we cannot guarantee absolute security.
Our public websites use cookies and similar technologies for essential functionality, to remember preferences, and to measure and improve our sites (analytics). The authenticated Services use only cookies and storage necessary to operate (e.g., session and authentication tokens).
Where required, we obtain consent for non-essential cookies/analytics and provide a cookie management tool. You can also control cookies through your browser. We honor recognized opt-out preference signals (e.g., Global Privacy Control) where applicable. We do not use cookies for cross-context behavioral advertising.
13.1 Retention Principles
We retain personal data only for as long as necessary for the purposes described in this Policy, to provide the Services, to comply with legal, tax, and accounting obligations, to resolve disputes, and to enforce our agreements. Customer Data is retained for the Subscription Term and as set out in the Agreement, including the subscription's 7-year off-site archival.
13.2 Post-Termination: Data Return and the Custodial Archive
On termination, Customers may retrieve Customer Data through tiered options described in the Agreement, including: Standard Export — DICOM export via encrypted media or a time-limited signed download; and Custodial Archive — a continuity offering in which we retain Customer Data in a dedicated GCS bucket and provide the Customer time-boxed read/pull access while the Customer migrates, billed monthly per TB stored plus egress.
A standard retrieval window of sixty (60) days applies unless the Order Form specifies a different period. After return/retrieval and the applicable window (and absent a legal hold), we securely delete Customer Data and can provide a Certificate of Destruction on request.
The Services are business-to-business (B2B) tools intended for veterinary professionals and are not directed to children. We do not knowingly collect personal data from children. This Section is included for completeness; in practice, children's-data rules are not applicable to our B2B Services.
15.1 General Updates
We may update this Policy from time to time. For material changes, we will provide reasonable notice (e.g., by posting an updated "Last updated" date and, where appropriate, by additional notice such as email or in-product notification) at least 30 days before the change takes effect where required. For website visitors and other individuals not under a negotiated Agreement, continued use of our websites or the Services after the effective date constitutes acceptance of the updated Policy, to the extent permitted by law.
15.2 Negotiated Agreements Control
For any Customer (and its Users) under a negotiated Master Subscription Agreement and/or Data Processing & AI Use Addendum, the data-protection and processing terms of that Agreement and DPA govern and control over this Policy. Those obligations are amended only by a written amendment to the Agreement or DPA, and not by an update we make to this Policy.
16.1 General Privacy Contact
For privacy questions or to exercise your rights: Email: privacy@asteris.biz Mail: Valsoft Corporation Inc. d/b/a Asteris, Attn: Privacy (NewLumen), 7405 Trans Canada Route #100, Saint-Laurent, QC Canada H4T 1Z2
16.2 Data Protection Officer (DPO)
We have appointed a Data Protection Officer / Privacy Office, who can be reached at: DPO / Privacy Office: NewLumen Privacy Office Email: privacy@asteris.biz Mail: 7405 Trans Canada Route #100, Saint-Laurent, QC Canada H4T 1Z2
Our DPO's business contact information is published here in accordance with Section 11(3) of the Singapore PDPA.
16.3 EU / UK Representative
If and when our processing of the personal data of EU/UK individuals triggers GDPR Article 27 (see Section 9.2), our appointed representatives will be: EU Representative: to be appointed before any EU launch (the Services are not currently offered in the EU). UK Representative: to be appointed before any UK launch (the Services are not currently offered in the UK).
16.4 Regional Supervisory Authorities
You may also contact the relevant authority: the FTC or your State Attorney General (US); the Office of the Privacy Commissioner of Canada and, for Quebec, the Commission d'accès à l'information (CAI); the OAIC (Australia); the Office of the Privacy Commissioner (New Zealand); the PDPC (Singapore); and your local EU Data Protection Authority or the UK ICO.
Questions about this policy?
Contact us at privacy@asteris.biz