How to exercise your rights over your personal data
Practical procedure to exercise your rights from Article 15 to Article 22 of the GDPR on Animiyo: who to write to, what to do in app, timelines.
- Effective from
- August 2, 2026
- Last updated
- August 2, 2026
- Version
- 1.0
Regulation (EU) 2016/679 grants every natural person a set of rights over their personal data and requires whoever processes those data to make exercising them easy. This page explains how to do that on Animiyo, a platform made of a web application served by Google Cloud Run and a native iOS application, both running on the Firebase backend of project petdiary-10327. The first step is understanding who the controller is in your case, because Animiyo is the controller for pet owner accounts but only a processor for the data that veterinary clinics and shops process about their own clients. The second step is checking whether what you need is already available inside the application, because data export, direct editing and account deletion are immediate tools that require writing to nobody. For everything else you will find here the procedure, the information to provide, the response times and the cases where a request can be limited or refused.
Which rights you have
The rights granted by the Regulation are not all alike: some always apply, some only to certain legal bases, others meet limits when they collide with legal obligations or with the rights of other people. The table below sums up what you can ask for, which article the request rests on and what the concrete limits are on our platform.
| Right | Article | What you can obtain | Limits |
|---|---|---|---|
| Access | Article 15 | Confirmation that processing is taking place, a copy of the data and information on purposes, categories of data, recipients and retention periods | The copy must not adversely affect the rights and freedoms of others, for example another person who shares the same pet with you |
| Rectification | Article 16 | Correction of inaccurate data and completion of incomplete data | Clinical data entered by a clinic are handled by the clinic, which is their controller; Animiyo forwards and assists |
| Erasure | Article 17 | Removal of data that are no longer necessary, of data processed on a consent you have withdrawn and of data subject to an upheld objection | Does not apply to data that must be retained under a legal obligation or for the establishment, exercise or defence of legal claims |
| Restriction | Article 18 | Freezing of the processing during a check: data stay stored but are not further used | Storage remains lawful, as does processing with your consent or for the exercise or defence of legal claims |
| Notification to recipients | Article 19 | Communication of the rectification, erasure or restriction to anyone who received your data | Not owed where it proves impossible or involves disproportionate effort; in that case we tell you who the recipients are |
| Portability | Article 20 | A copy of the data you provided in a structured, commonly used and machine readable format | Covers only processing based on consent or contract and carried out by automated means |
| Objection | Article 21 | Stopping processing based on legitimate interest, unless the controller has compelling legitimate grounds | Does not apply to processing necessary to perform the contract or to comply with a legal obligation |
| Automated decisions | Article 22 | The right not to be subject to a decision based solely on automated processing producing legal effects or similarly significantly affecting you | Animiyo makes no such decisions: there is no profiling with legal effects and no automated scoring governing access to the service |
| Withdrawal of consent | Article 7(3) | Withdrawal of a given consent at any time, as easily as it was given | Does not affect the lawfulness of processing carried out before the withdrawal |
| Complaint | Article 77 | Reporting the processing to a competent supervisory authority | Does not replace a judicial remedy, which remains available under Article 79 |
Exercising these rights is free of charge and needs no justification. You do not have to explain why you want a copy of your data or why you want to delete your account: reasons only matter for an objection based on your particular situation, where the Regulation expressly requires them.
Who to address your request to
Animiyo has two distinct roles, and the difference decides who you should write to. For pet owner accounts Animiyo is the controller: registration, authentication, pet profiles, reminders, budget, walks, uploaded documents and preferences are decided and managed by us. For the data a veterinary clinic or a shop processes about its own clients through the platform, Animiyo is instead a processor: the controller is the tenant, that is the business that opened the professional account.
The practical consequence is simple. If the data concern medical records, SOAP notes, reports, signed consent forms, estimates, invoices, orders or loyalty programmes, the request must be addressed to the clinic or the shop. Animiyo supports the tenant with the technical tools needed to reply, but does not replace it and does not decide on its behalf.
| Type of data | Controller | Where to send the request |
|---|---|---|
| Account, credentials, username and application preferences | Animiyo | Account settings in the app or the Contacts page of the site, path /contatti |
| Pet profiles, reminders, budget, walks, routes and documents you uploaded | Animiyo | Account settings in the app or the Contacts page |
| Medical record, SOAP notes, reports, lab results, hospitalisations | The veterinary clinic that entered them | Directly to the clinic; Animiyo forwards the request and gives technical support |
| Signed consent forms, estimates, invoices and appointments managed by a clinic | The clinic | Directly to the clinic |
| Orders, loyalty rewards and reviews at a shop | The shop | Directly to the shop |
| Audit log of operations on the platform | Animiyo for service security, the tenant for operations carried out on its clients' data | Contacts page, naming the business involved |
Requests addressed to Animiyo are handled by the owner of the project. No data protection officer has been designated because the conditions of Article 37 are not met: the processing is not carried out by a public authority, it does not consist of regular and systematic monitoring on a large scale and its core activity is not large scale processing of special categories of data.
What you can do yourself, right now
Before writing to anyone it is worth looking inside the application: several rights can be exercised on your own, in a few taps and with no waiting. The account settings section holds data export and account deletion; everything else is done from the screens where the data were entered.
Open your account settings
Data export and account deletion live in the account settings section, both in the web application and in the iOS application. They are two separate functions: the first deletes nothing, the second is final.
Start the data export
The function gathers the data linked to your account and prepares a JSON archive with a versioned schema. You do not have to give reasons and no document is requested, because you are already authenticated.
Download and keep the archive
Save it somewhere safe: it holds your personal data and information about your pets. From that moment the copy is under your control and Animiyo can no longer act on it.
Check the contents
Open the file and verify that what you expected is there. Dates are normalised to ISO 8601 format, so they stay readable over time and by software other than ours.
If something is missing, ask for access in writing
The archive covers the data managed by your account. For anything that does not appear, such as data entered by a clinic or security logs, you need a written request to the competent controller, as explained below.
The archive produced by the export contains the user profile, the pets and their subcollections, the pet contacts, the budget configuration, the expense items and the saving goals. It is a JSON file with a versioned schema, so the structure is declared and stays readable even if fields change in the future. It covers the right of access, because it shows you the data, and the right to portability, because it is structured and machine readable.
- Immediate rectification: almost all data can be edited directly in the application screens. It is the fastest route to fix a mistake, far quicker than a written request.
- Account deletion: removes the user profile, the pets and their subcollections, the contacts, the shares, the lost pet tags, the sightings, the budget items and the goals.
- Withdrawal of system permissions: location and notifications are revoked from the device settings, not from the application, because the operating system governs them.
- Withdrawal of shares: a shared pet, a shared route or a group walk are unshared from the same screen you shared them from.
- Public lost pet tag: the feature that lets a finder contact you switches off when you mark the pet as found.
How to submit a request
When the in app tool is not enough, the request is submitted in writing. There is no mandatory form and no dedicated portal: a free text message from the Contacts page of the site, path /contatti, is enough, as long as it is clear who you are and what you are asking for.
Check whether you can solve it yourself
Export, direct editing, withdrawal of shares and account deletion are immediate. Using a written request for something that takes thirty seconds only makes it slower.
Identify the competent controller
If the data concern a medical record, a signed consent form, an invoice or an order, the controller is the clinic or the shop. Writing to them first avoids the forwarding step and shortens the reply.
Write from the Contacts page
Use the Contacts page of the site, path /contatti. If you can, write from the email address you registered with: it makes identity verification immediate.
State which right you are exercising
Say explicitly whether you are asking for access, rectification, erasure, restriction, portability, objection or withdrawal of consent. If you are unsure of the label, describe the outcome you want: mapping the request onto the correct article is our job.
Define the scope of the request
Tell us which data, which pet and which period you are interested in. A narrow request is handled faster; a blanket request about everything may trigger the extension for complexity.
Say how you want the reply
If you specify nothing we reply through the same channel you used and, for the data, with the JSON archive the platform already produces. If you prefer a different format say so upfront, so we can assess whether it is technically possible.
Note the date you sent it
The one month deadline runs from receipt of the request. Keeping the date lets you check that the timeline is respected and, if needed, document it in a complaint.
Some information is not mandatory but speeds up the reply considerably, because it saves a round of clarifications that eats up useful days.
- The email address of the account, if you are writing from a different address.
- The name of the pet, when the request concerns data linked to one pet in particular.
- The reference period, if you are looking for data from a defined time range.
- The name of the clinic or the shop, if the request arises from a professional service you received.
- The format you prefer for receiving the data, if you have a specific reuse need.
- You do not need to attach a copy of an identity document if you write from the authenticated account or from the registered email address.
- You do not need to fill in forms: none exist, and no request is refused because of the way it is written.
- You do not need to justify a request for access, portability or withdrawal of consent.
- You do not need payment card details or any other element we have never collected.
When a request comes in, we check every system that may hold data about you. The list is not theoretical: it matches the real architecture of the platform.
- Firebase Authentication, that is the identity you sign in with.
- The Firestore collections users, usernames, pets, petContacts, petShares, petSightings, petMemberships, petConditions, petActivity, petMemories, foundTags, vaccinations, medications, dewormingRecords, weightRecords, labResults, soapNotes, vetAppointments, appointmentTypes, hospitalized, consentForms, signedConsents, estimates, invoices, orders, subscriptions, rewards, reviews, resources, walks, routes, routeShares, groupWalks, conversations, budgetItems, budgetGoals, budgetConfigurations, tenants and auditLog.
- Cloud Storage, where photographs, documents and consent signatures are stored.
- The FCM notification tokens tied to the devices where you installed the application.
- Google Analytics 4, which processes pseudonymous identifiers and is cleared through the Google user deletion feature.
- Backups and exports already generated, which are checked along with everything else.
Identity verification
Handing someone's data to a person impersonating them would be a breach, so before replying we must be reasonably certain who is writing. Verification must nonetheless stay proportionate: the Regulation requires identifying the data subject, not collecting documents that serve no purpose.
| Request channel | How verification works | What you are asked for |
|---|---|---|
| Functions available inside the authenticated account | Authentication itself counts as verification: whoever signed in is already identified | Nothing; no document is requested |
| Message from the Contacts page or another external channel | A code is sent to the email address registered on the account and quoted back in your reply | Access to the mailbox linked to the account |
| Cases where doubt about identity persists | A proportionate request for additional information, assessed case by case | Only strictly necessary elements; if a document is indispensable, excess data should be redacted |
The emailed code is the standard method for requests arriving from outside the application, because it proves control of the address the account is registered on without collecting new data. A copy of an identity document is not requested unless strictly necessary, and in that case it is advisable to redact everything not needed to establish identity, such as the document number or the photograph.
If we cannot verify who you are, the request is refused with written reasons, as provided by Article 12(6). The refusal is not final: you can resubmit the request from the authenticated account or from the registered email address and we will process it normally.
Response times and costs
A reply arrives within one month of receiving the request. For complex or numerous requests the deadline can be extended by two further months, but the extension must be notified and reasoned within the first month: it is not silence, it is an explicit notice with the reason for the delay.
| Stage | Deadline | Legal reference |
|---|---|---|
| Receipt of the request | The clock starts here | Article 12(3) |
| Ordinary reply | One month from receipt | Article 12(3) |
| Notice of extension, with the reasons for the delay | Within one month of receipt | Article 12(3) |
| Reply after extension for complex or numerous requests | Up to three months in total from receipt | Article 12(3) |
| Reply where the request is not granted | One month, with reasons, the right to complain and the right to a judicial remedy | Article 12(4) |
| Ordinary cost of a request | Free of charge | Article 12(5) |
| Reasonable fee or refusal for manifestly unfounded or excessive requests, in particular because of their repetitive character | Only in exceptional cases, with the burden of proof on the controller | Article 12(5) |
Even when a request is not granted we still reply within one month, explaining the reasons for the refusal and reminding you that you can lodge a complaint with a supervisory authority and seek a judicial remedy. Silence is not an answer allowed by the Regulation and is not our practice.
Requests are handled by the owner of the project and the current volume is zero, because the service has not been publicly launched yet. This means that at this stage actual times are far shorter than the legal deadline, and that the two month extension remains a theoretical possibility tied to the complexity of an individual request.
Access and portability
Access and portability are often confused because both produce a copy of the data, yet they serve different purposes. Access is a right to know: it tells you which data exist, why they are processed, to whom they are disclosed and how long they are kept. Portability is a right to reuse: it hands you, in a machine format, the data you provided, so you can take them elsewhere without retyping them.
| Aspect | Access (Article 15) | Portability (Article 20) |
|---|---|---|
| What you get | A copy of the data plus information about the processing | The data you provided, ready to be reused elsewhere |
| Which data are covered | All personal data processed about you, however collected | Only data you provided and processed by automated means |
| Legal bases covered | All of them | Consent and contract only |
| Format | Free, provided it is concise, transparent and intelligible | Structured, commonly used and machine readable |
| Recipient of the copy | You | You or, where technically feasible, another controller you name |
| Tool on Animiyo | Data export, supplemented by a written reply for what the archive does not contain | Data export as a JSON archive with a versioned schema |
The archive generated by the application contains the user profile, the pets and their subcollections, the pet contacts, the budget configuration, the expense items and the goals. Dates are normalised to ISO 8601 format and the schema is versioned, so whoever receives the file knows how to read it. For most users this file satisfies both access and portability.
- It does not contain data entered by a clinic or a shop in their professional records, because the controller of those data is the tenant.
- It does not contain the audit log, which is kept for security purposes and is disclosed, in the part concerning you, upon an access request.
- It does not contain the pseudonymous Google Analytics 4 identifiers, which are not directly linked to your account.
- It does not contain the copy of conversations kept by the professional recipient, which stays in their hands.
If you want the portable data transmitted directly to another controller, say so in the request: Article 20(2) recognises this option where it is technically feasible. Feasible means a suitable channel must exist on the other side; the Regulation does not require building bespoke interoperable systems. If direct transfer is not possible we hand you the archive, which you can upload wherever you prefer.
Account deletion and its consequences
Account deletion is available in the account settings section and requires no message to us. It removes the user profile, the pets and their subcollections, the pet contacts, the shares, the lost pet tags, the sightings, the budget items and the goals. It is irreversible: once completed there is no restore function, so exporting your data beforehand is the sensible move.
| Data | Outcome of deletion | Reason |
|---|---|---|
| User profile, username and sign in credentials | Deleted | Once the purpose is gone the processing has no basis left |
| Pets and subcollections where you are the only holder of access | Deleted | They are data linked exclusively to your account |
| Pet shared with other people | Kept if at least one other holder of access remains | Deleting your account cannot strip the other co-owners of their data |
| Pet contacts, shares, lost pet tags and sightings | Deleted | They follow the fate of the account that created them |
| Budget items, goals and budget configuration | Deleted | They are personal management data with no retention obligation |
| Medical record, reports and signed consent forms held by a clinic | Kept according to the clinic's own rules | The controller of those data is the clinic, not Animiyo |
| Tax and accounting documents, once payments are active | Kept for the period required by law | Legal obligation in tax and accounting matters |
| Audit log | Kept for twenty four months | Platform security and the need to demonstrate the integrity of the system |
| Messages sent to a professional | The recipient's copy remains | It works like email: deletion covers your own copy |
| Pseudonymous Google Analytics 4 identifiers | Cleared through the Google user deletion feature | They are not directly linked to the account and follow their own route |
| Export archives you already downloaded | They stay on your device | They are in your hands and outside the control of the platform |
If full erasure is not possible for one of the reasons listed, we do not leave you without an answer: we explain which data remain, under which obligation and for how long, and we consider restriction of processing as an intermediate measure. Restriction means the data stay stored but are no longer used for any other purpose until the obligation ends.
Objection and restriction
The objection under Article 21 does not apply to every processing operation: it covers those based on the controller's legitimate interest or on a task carried out in the public interest. On Animiyo the processing based on legitimate interest is platform security, abuse prevention and the audit log. When you object to one of these, we weigh your particular situation against the compelling legitimate grounds that justify the processing.
| Processing | Legal basis | Applicable right | Usual outcome |
|---|---|---|---|
| Providing the service and managing the account | Contract | No objection available | Without the processing the service cannot be provided; the route is account deletion |
| Platform security and abuse prevention | Legitimate interest | Objection under Article 21(1) | Case by case balancing; as a rule the interest in the security of all users prevails |
| Audit log | Legitimate interest and the need to demonstrate the integrity of the system | Restriction preferred over erasure | Data stay stored for twenty four months but are not used for other purposes |
| Usage statistics with Google Analytics 4 | Consent | Withdrawal of consent, which replaces objection | Collection stops right after the withdrawal |
| Retention of tax and accounting documents | Legal obligation | No objection available | Retention continues until the statutory period expires |
Restriction under Article 18 is a different tool and often more useful than it looks, because it freezes the situation while a question is clarified. It applies in four cases: when you contest the accuracy of a piece of data, for the time needed to verify it; when the processing is unlawful but you prefer restriction to erasure; when we no longer need the data but you need them for legal claims; and when you have objected and the balancing assessment is still under way.
During restriction the data stay stored but are not otherwise processed, except with your consent, for the establishment or defence of legal claims or to protect the rights of another person. We inform you before the restriction is lifted, as Article 18(3) requires.
Withdrawing consent
Where processing rests on consent, consent can be withdrawn whenever you like and as easily as it was given. On Animiyo this covers push notifications, geolocation of walks, usage statistics and the shares that make a pet's data visible to third parties. Every withdrawal is exercised at the point where consent was given, without going through a written request.
| Consent | Where to withdraw it | Effect of withdrawal |
|---|---|---|
| Push notifications for reminders and events | Device settings, notification section for the application | The FCM token stops receiving alerts; reminders stay visible inside the application |
| Location access for recording walks | Device settings, location permissions | Recording new routes is no longer possible; walks already saved remain until you delete them |
| Usage statistics with Google Analytics 4 | Cookie preferences panel of the site | Collection stops; for identifiers already collected the Google user deletion feature is needed |
| Sharing a pet with another person | The same screen you shared the pet from | That person loses access to the pet profile |
| Sharing a route or joining a group walk | The same screen you shared the route from or created the group | Sharing ends and the route becomes visible to you alone |
| Public lost pet tag | It switches off when you report the pet as found | The public page stops being reachable by whoever finds the pet |
Withdrawal works for the future: it does not affect the lawfulness of processing carried out on the basis of consent before the withdrawal, as Article 7(3) states. In concrete terms, walks recorded while the location permission was active remain lawful, and they remain yours: you can delete them whenever you want, but they do not become unlawful retroactively.
Withdrawing a consent does not cost you the account, nor does it reduce the features that do not depend on that consent. Some features simply stop working, because without the data they have no way to operate: without location permission there is no route tracking, without notification permission no alert arrives.
Special cases and conflicts
Some requests hit a limit that does not depend on our willingness but on the structure of the processing or on an external obligation. Declaring them upfront prevents them from looking like excuses invented after the request.
| Case | What you can obtain | What you cannot obtain |
|---|---|---|
| Data entered by a clinic in the medical record | Forwarding of the request to the competent tenant and our technical assistance | A change or an erasure decided by Animiyo on its own initiative |
| Tax and accounting documents, once payments are active | Access to the documents concerning you | Erasure before the statutory retention period expires |
| Audit log | Disclosure of what concerns you and restriction of the processing | Full erasure before the twenty four month retention ends |
| Pet shared among several people | Deletion of your account and of your access to the pet | Deletion of the pet if at least one other holder of access remains |
| Conversations with a professional | Deletion of your own copy of the conversation | Deletion of the copy kept by the recipient |
| Published reviews | Removal of the review on request | Erasure of the trace of the removal operation in the audit log |
| Google Analytics 4 identifiers | Deletion through the Google user deletion feature | A lookup by name or by email, because the identifiers are pseudonymous and not linked to the account |
The audit log deserves a separate explanation. It records the operations carried out on the platform and is kept for twenty four months for security purposes. Erasing it in full would clash with the obligation to demonstrate the integrity of the system, which is a safeguard for you too: without the log it would be impossible to reconstruct who did what in case of unauthorised access. This is why, faced with an erasure request, we consider restriction as a proportionate alternative.
The shared pet is the second recurring case. When a profile is accessible to several people, the data entered by each of them remain theirs. Deleting your account removes your access and your content, but it does not delete the pet if at least one other holder of access remains: doing so would mean erasing someone else's data at your request, which the Regulation does not allow.
Conversations work like email. A message sent to a professional lands in their copy of the conversation and stays there, because it is data concerning them as well. The erasure you can obtain covers your own copy; nobody can erase the recipient's memory, and no messaging system allows it without the agreement of both parties.
For Google Analytics 4, finally, collection happens on pseudonymous identifiers that are not directly linked to your account. Deletion goes through the user deletion feature made available by Google and requires the client identifier, which you can remove yourself by clearing the site data in your browser. After clearing, the next session is associated with a new identifier, unrelated to the previous one.
Complaint to the supervisory authority
If you believe the processing of your data infringes the Regulation, you can lodge a complaint with a supervisory authority. Writing to the controller first is advisable because many issues close with a clarification or an immediate correction, but it is not a mandatory step: the right to complain under Article 77 requires no prior attempt.
- Garante per la protezione dei dati personali, piazza Venezia 11, 00187 Rome, Italy.
- Alternatively, the supervisory authority of the Member State where you habitually reside.
- Alternatively, the supervisory authority of the Member State where you work.
- Alternatively, the supervisory authority of the Member State where the alleged infringement took place.
The judicial remedy provided by Article 79 remains unaffected and can be pursued in parallel with the complaint. The two routes do not exclude each other: a complaint goes to a supervisory authority, a claim goes to a court, and they have different requirements and outcomes.
If the complaint concerns data whose controller is a clinic or a shop, it must be brought against that business, not against Animiyo. If in doubt write to us anyway from the Contacts page: we can tell you which role we play in that specific processing, so that the complaint reaches the right party.
Frequently asked questions
- Do I have to pay to exercise a right?
- No, requests are free of charge. Only for manifestly unfounded or excessive requests, in particular repetitive ones, does Article 12(5) allow a reasonable fee or a refusal. In that case the burden of proving the unfounded or excessive character lies with the controller, not with you. In practice, for a platform that has not been publicly launched yet, this is a remote scenario.
- How long does it take to get a reply?
- The ordinary deadline is one month from receipt of the request. For complex or numerous requests it can be extended by two further months, but the extension must be notified to you with its reasons within the first month. If the request is not granted you still receive a reasoned reply within one month, telling you about the right to complain and the right to a judicial remedy. Silence is not a permitted outcome.
- Do I need to attach a copy of my identity document?
- If you write from the authenticated account nothing is needed, because authentication already counts as verification. If you write from an external channel, such as the Contacts page, we send a code to the email address registered on the account and simply need you to quote it back. A copy of a document is requested only if strictly necessary, and in that case it is wise to redact every detail not needed to identify you.
- I asked the clinic to correct a clinical note and they told me to contact you. Who is right?
- For the data a clinic enters in the medical record the controller is the clinic, not Animiyo. We provide the tool and act as a processor, so we do not amend or erase that content on our own initiative. If you write to us we forward the request to the competent tenant and support them technically in replying. The decision on the merits, however, belongs to the clinic.
- Does the export really contain everything you hold about me?
- The JSON archive contains the user profile, the pets with their subcollections, the pet contacts, the budget configuration, the expense items and the goals. It does not contain the audit log, the data entered by clinics or shops, the copy of conversations kept by the recipient or the pseudonymous Google Analytics 4 identifiers. For those categories you can submit a written access request and we reply with what concerns you. The distinction is not arbitrary: it depends on who the controller is and on the legal basis of each processing operation.
- If I delete my account, does the pet I share with someone else disappear too?
- No. If at least one other holder of access remains on the pet, the profile keeps existing for that person. Deletion removes your account, your access and the data linked exclusively to you. Content entered by other users stays theirs, because erasing it at your request would mean disposing of someone else's data.
- I deleted my account by mistake: can I recover the data?
- Account deletion is irreversible and there is no restore function. That is why data export sits on the same screen: it is the step to take before confirming. If you already downloaded the JSON archive you can consult it freely, but it cannot be uploaded back to rebuild the previous account. If you did not download it, the deleted data cannot be recovered.
In short
Before writing to anyone, open your account settings: data export covers access and portability, direct editing handles rectification, and shares are withdrawn from the screen you shared them from. If you need more, write from the Contacts page stating which right you are exercising, which data it concerns and over which period; if the data were entered by a clinic or a shop, address them directly, and keep the date you sent the request so you can check the one month deadline.