Skip to content
Animiyo

How to exercise your rights over your personal data

Practical procedure to exercise your rights from Article 15 to Article 22 of the GDPR on Animiyo: who to write to, what to do in app, timelines.

Effective from
August 2, 2026
Last updated
August 2, 2026
Version
1.0

Regulation (EU) 2016/679 grants every natural person a set of rights over their personal data and requires whoever processes those data to make exercising them easy. This page explains how to do that on Animiyo, a platform made of a web application served by Google Cloud Run and a native iOS application, both running on the Firebase backend of project petdiary-10327. The first step is understanding who the controller is in your case, because Animiyo is the controller for pet owner accounts but only a processor for the data that veterinary clinics and shops process about their own clients. The second step is checking whether what you need is already available inside the application, because data export, direct editing and account deletion are immediate tools that require writing to nobody. For everything else you will find here the procedure, the information to provide, the response times and the cases where a request can be limited or refused.

Which rights you have

The rights granted by the Regulation are not all alike: some always apply, some only to certain legal bases, others meet limits when they collide with legal obligations or with the rights of other people. The table below sums up what you can ask for, which article the request rests on and what the concrete limits are on our platform.

Data subject rights applied to the Animiyo platform
RightArticleWhat you can obtainLimits
AccessArticle 15Confirmation that processing is taking place, a copy of the data and information on purposes, categories of data, recipients and retention periodsThe copy must not adversely affect the rights and freedoms of others, for example another person who shares the same pet with you
RectificationArticle 16Correction of inaccurate data and completion of incomplete dataClinical data entered by a clinic are handled by the clinic, which is their controller; Animiyo forwards and assists
ErasureArticle 17Removal of data that are no longer necessary, of data processed on a consent you have withdrawn and of data subject to an upheld objectionDoes not apply to data that must be retained under a legal obligation or for the establishment, exercise or defence of legal claims
RestrictionArticle 18Freezing of the processing during a check: data stay stored but are not further usedStorage remains lawful, as does processing with your consent or for the exercise or defence of legal claims
Notification to recipientsArticle 19Communication of the rectification, erasure or restriction to anyone who received your dataNot owed where it proves impossible or involves disproportionate effort; in that case we tell you who the recipients are
PortabilityArticle 20A copy of the data you provided in a structured, commonly used and machine readable formatCovers only processing based on consent or contract and carried out by automated means
ObjectionArticle 21Stopping processing based on legitimate interest, unless the controller has compelling legitimate groundsDoes not apply to processing necessary to perform the contract or to comply with a legal obligation
Automated decisionsArticle 22The right not to be subject to a decision based solely on automated processing producing legal effects or similarly significantly affecting youAnimiyo makes no such decisions: there is no profiling with legal effects and no automated scoring governing access to the service
Withdrawal of consentArticle 7(3)Withdrawal of a given consent at any time, as easily as it was givenDoes not affect the lawfulness of processing carried out before the withdrawal
ComplaintArticle 77Reporting the processing to a competent supervisory authorityDoes not replace a judicial remedy, which remains available under Article 79

Exercising these rights is free of charge and needs no justification. You do not have to explain why you want a copy of your data or why you want to delete your account: reasons only matter for an objection based on your particular situation, where the Regulation expressly requires them.

Who to address your request to

Animiyo has two distinct roles, and the difference decides who you should write to. For pet owner accounts Animiyo is the controller: registration, authentication, pet profiles, reminders, budget, walks, uploaded documents and preferences are decided and managed by us. For the data a veterinary clinic or a shop processes about its own clients through the platform, Animiyo is instead a processor: the controller is the tenant, that is the business that opened the professional account.

The practical consequence is simple. If the data concern medical records, SOAP notes, reports, signed consent forms, estimates, invoices, orders or loyalty programmes, the request must be addressed to the clinic or the shop. Animiyo supports the tenant with the technical tools needed to reply, but does not replace it and does not decide on its behalf.

Who the controller is by type of data and where the request should go
Type of dataControllerWhere to send the request
Account, credentials, username and application preferencesAnimiyoAccount settings in the app or the Contacts page of the site, path /contatti
Pet profiles, reminders, budget, walks, routes and documents you uploadedAnimiyoAccount settings in the app or the Contacts page
Medical record, SOAP notes, reports, lab results, hospitalisationsThe veterinary clinic that entered themDirectly to the clinic; Animiyo forwards the request and gives technical support
Signed consent forms, estimates, invoices and appointments managed by a clinicThe clinicDirectly to the clinic
Orders, loyalty rewards and reviews at a shopThe shopDirectly to the shop
Audit log of operations on the platformAnimiyo for service security, the tenant for operations carried out on its clients' dataContacts page, naming the business involved

Requests addressed to Animiyo are handled by the owner of the project. No data protection officer has been designated because the conditions of Article 37 are not met: the processing is not carried out by a public authority, it does not consist of regular and systematic monitoring on a large scale and its core activity is not large scale processing of special categories of data.

What you can do yourself, right now

Before writing to anyone it is worth looking inside the application: several rights can be exercised on your own, in a few taps and with no waiting. The account settings section holds data export and account deletion; everything else is done from the screens where the data were entered.

  1. Open your account settings

    Data export and account deletion live in the account settings section, both in the web application and in the iOS application. They are two separate functions: the first deletes nothing, the second is final.

  2. Start the data export

    The function gathers the data linked to your account and prepares a JSON archive with a versioned schema. You do not have to give reasons and no document is requested, because you are already authenticated.

  3. Download and keep the archive

    Save it somewhere safe: it holds your personal data and information about your pets. From that moment the copy is under your control and Animiyo can no longer act on it.

  4. Check the contents

    Open the file and verify that what you expected is there. Dates are normalised to ISO 8601 format, so they stay readable over time and by software other than ours.

  5. If something is missing, ask for access in writing

    The archive covers the data managed by your account. For anything that does not appear, such as data entered by a clinic or security logs, you need a written request to the competent controller, as explained below.

The archive produced by the export contains the user profile, the pets and their subcollections, the pet contacts, the budget configuration, the expense items and the saving goals. It is a JSON file with a versioned schema, so the structure is declared and stays readable even if fields change in the future. It covers the right of access, because it shows you the data, and the right to portability, because it is structured and machine readable.

  • Immediate rectification: almost all data can be edited directly in the application screens. It is the fastest route to fix a mistake, far quicker than a written request.
  • Account deletion: removes the user profile, the pets and their subcollections, the contacts, the shares, the lost pet tags, the sightings, the budget items and the goals.
  • Withdrawal of system permissions: location and notifications are revoked from the device settings, not from the application, because the operating system governs them.
  • Withdrawal of shares: a shared pet, a shared route or a group walk are unshared from the same screen you shared them from.
  • Public lost pet tag: the feature that lets a finder contact you switches off when you mark the pet as found.

How to submit a request

When the in app tool is not enough, the request is submitted in writing. There is no mandatory form and no dedicated portal: a free text message from the Contacts page of the site, path /contatti, is enough, as long as it is clear who you are and what you are asking for.

  1. Check whether you can solve it yourself

    Export, direct editing, withdrawal of shares and account deletion are immediate. Using a written request for something that takes thirty seconds only makes it slower.

  2. Identify the competent controller

    If the data concern a medical record, a signed consent form, an invoice or an order, the controller is the clinic or the shop. Writing to them first avoids the forwarding step and shortens the reply.

  3. Write from the Contacts page

    Use the Contacts page of the site, path /contatti. If you can, write from the email address you registered with: it makes identity verification immediate.

  4. State which right you are exercising

    Say explicitly whether you are asking for access, rectification, erasure, restriction, portability, objection or withdrawal of consent. If you are unsure of the label, describe the outcome you want: mapping the request onto the correct article is our job.

  5. Define the scope of the request

    Tell us which data, which pet and which period you are interested in. A narrow request is handled faster; a blanket request about everything may trigger the extension for complexity.

  6. Say how you want the reply

    If you specify nothing we reply through the same channel you used and, for the data, with the JSON archive the platform already produces. If you prefer a different format say so upfront, so we can assess whether it is technically possible.

  7. Note the date you sent it

    The one month deadline runs from receipt of the request. Keeping the date lets you check that the timeline is respected and, if needed, document it in a complaint.

Some information is not mandatory but speeds up the reply considerably, because it saves a round of clarifications that eats up useful days.

  • The email address of the account, if you are writing from a different address.
  • The name of the pet, when the request concerns data linked to one pet in particular.
  • The reference period, if you are looking for data from a defined time range.
  • The name of the clinic or the shop, if the request arises from a professional service you received.
  • The format you prefer for receiving the data, if you have a specific reuse need.
  • You do not need to attach a copy of an identity document if you write from the authenticated account or from the registered email address.
  • You do not need to fill in forms: none exist, and no request is refused because of the way it is written.
  • You do not need to justify a request for access, portability or withdrawal of consent.
  • You do not need payment card details or any other element we have never collected.

When a request comes in, we check every system that may hold data about you. The list is not theoretical: it matches the real architecture of the platform.

  • Firebase Authentication, that is the identity you sign in with.
  • The Firestore collections users, usernames, pets, petContacts, petShares, petSightings, petMemberships, petConditions, petActivity, petMemories, foundTags, vaccinations, medications, dewormingRecords, weightRecords, labResults, soapNotes, vetAppointments, appointmentTypes, hospitalized, consentForms, signedConsents, estimates, invoices, orders, subscriptions, rewards, reviews, resources, walks, routes, routeShares, groupWalks, conversations, budgetItems, budgetGoals, budgetConfigurations, tenants and auditLog.
  • Cloud Storage, where photographs, documents and consent signatures are stored.
  • The FCM notification tokens tied to the devices where you installed the application.
  • Google Analytics 4, which processes pseudonymous identifiers and is cleared through the Google user deletion feature.
  • Backups and exports already generated, which are checked along with everything else.

Identity verification

Handing someone's data to a person impersonating them would be a breach, so before replying we must be reasonably certain who is writing. Verification must nonetheless stay proportionate: the Regulation requires identifying the data subject, not collecting documents that serve no purpose.

How identity is verified depending on the channel used
Request channelHow verification worksWhat you are asked for
Functions available inside the authenticated accountAuthentication itself counts as verification: whoever signed in is already identifiedNothing; no document is requested
Message from the Contacts page or another external channelA code is sent to the email address registered on the account and quoted back in your replyAccess to the mailbox linked to the account
Cases where doubt about identity persistsA proportionate request for additional information, assessed case by caseOnly strictly necessary elements; if a document is indispensable, excess data should be redacted

The emailed code is the standard method for requests arriving from outside the application, because it proves control of the address the account is registered on without collecting new data. A copy of an identity document is not requested unless strictly necessary, and in that case it is advisable to redact everything not needed to establish identity, such as the document number or the photograph.

If we cannot verify who you are, the request is refused with written reasons, as provided by Article 12(6). The refusal is not final: you can resubmit the request from the authenticated account or from the registered email address and we will process it normally.

Response times and costs

A reply arrives within one month of receiving the request. For complex or numerous requests the deadline can be extended by two further months, but the extension must be notified and reasoned within the first month: it is not silence, it is an explicit notice with the reason for the delay.

Response deadlines and legal references
StageDeadlineLegal reference
Receipt of the requestThe clock starts hereArticle 12(3)
Ordinary replyOne month from receiptArticle 12(3)
Notice of extension, with the reasons for the delayWithin one month of receiptArticle 12(3)
Reply after extension for complex or numerous requestsUp to three months in total from receiptArticle 12(3)
Reply where the request is not grantedOne month, with reasons, the right to complain and the right to a judicial remedyArticle 12(4)
Ordinary cost of a requestFree of chargeArticle 12(5)
Reasonable fee or refusal for manifestly unfounded or excessive requests, in particular because of their repetitive characterOnly in exceptional cases, with the burden of proof on the controllerArticle 12(5)

Even when a request is not granted we still reply within one month, explaining the reasons for the refusal and reminding you that you can lodge a complaint with a supervisory authority and seek a judicial remedy. Silence is not an answer allowed by the Regulation and is not our practice.

Requests are handled by the owner of the project and the current volume is zero, because the service has not been publicly launched yet. This means that at this stage actual times are far shorter than the legal deadline, and that the two month extension remains a theoretical possibility tied to the complexity of an individual request.

Access and portability

Access and portability are often confused because both produce a copy of the data, yet they serve different purposes. Access is a right to know: it tells you which data exist, why they are processed, to whom they are disclosed and how long they are kept. Portability is a right to reuse: it hands you, in a machine format, the data you provided, so you can take them elsewhere without retyping them.

Differences between the right of access and the right to portability
AspectAccess (Article 15)Portability (Article 20)
What you getA copy of the data plus information about the processingThe data you provided, ready to be reused elsewhere
Which data are coveredAll personal data processed about you, however collectedOnly data you provided and processed by automated means
Legal bases coveredAll of themConsent and contract only
FormatFree, provided it is concise, transparent and intelligibleStructured, commonly used and machine readable
Recipient of the copyYouYou or, where technically feasible, another controller you name
Tool on AnimiyoData export, supplemented by a written reply for what the archive does not containData export as a JSON archive with a versioned schema

The archive generated by the application contains the user profile, the pets and their subcollections, the pet contacts, the budget configuration, the expense items and the goals. Dates are normalised to ISO 8601 format and the schema is versioned, so whoever receives the file knows how to read it. For most users this file satisfies both access and portability.

  • It does not contain data entered by a clinic or a shop in their professional records, because the controller of those data is the tenant.
  • It does not contain the audit log, which is kept for security purposes and is disclosed, in the part concerning you, upon an access request.
  • It does not contain the pseudonymous Google Analytics 4 identifiers, which are not directly linked to your account.
  • It does not contain the copy of conversations kept by the professional recipient, which stays in their hands.

If you want the portable data transmitted directly to another controller, say so in the request: Article 20(2) recognises this option where it is technically feasible. Feasible means a suitable channel must exist on the other side; the Regulation does not require building bespoke interoperable systems. If direct transfer is not possible we hand you the archive, which you can upload wherever you prefer.

Account deletion and its consequences

Account deletion is available in the account settings section and requires no message to us. It removes the user profile, the pets and their subcollections, the pet contacts, the shares, the lost pet tags, the sightings, the budget items and the goals. It is irreversible: once completed there is no restore function, so exporting your data beforehand is the sensible move.

What happens to each category of data when the account is deleted
DataOutcome of deletionReason
User profile, username and sign in credentialsDeletedOnce the purpose is gone the processing has no basis left
Pets and subcollections where you are the only holder of accessDeletedThey are data linked exclusively to your account
Pet shared with other peopleKept if at least one other holder of access remainsDeleting your account cannot strip the other co-owners of their data
Pet contacts, shares, lost pet tags and sightingsDeletedThey follow the fate of the account that created them
Budget items, goals and budget configurationDeletedThey are personal management data with no retention obligation
Medical record, reports and signed consent forms held by a clinicKept according to the clinic's own rulesThe controller of those data is the clinic, not Animiyo
Tax and accounting documents, once payments are activeKept for the period required by lawLegal obligation in tax and accounting matters
Audit logKept for twenty four monthsPlatform security and the need to demonstrate the integrity of the system
Messages sent to a professionalThe recipient's copy remainsIt works like email: deletion covers your own copy
Pseudonymous Google Analytics 4 identifiersCleared through the Google user deletion featureThey are not directly linked to the account and follow their own route
Export archives you already downloadedThey stay on your deviceThey are in your hands and outside the control of the platform

If full erasure is not possible for one of the reasons listed, we do not leave you without an answer: we explain which data remain, under which obligation and for how long, and we consider restriction of processing as an intermediate measure. Restriction means the data stay stored but are no longer used for any other purpose until the obligation ends.

Objection and restriction

The objection under Article 21 does not apply to every processing operation: it covers those based on the controller's legitimate interest or on a task carried out in the public interest. On Animiyo the processing based on legitimate interest is platform security, abuse prevention and the audit log. When you object to one of these, we weigh your particular situation against the compelling legitimate grounds that justify the processing.

When an objection is available and what outcome it usually has
ProcessingLegal basisApplicable rightUsual outcome
Providing the service and managing the accountContractNo objection availableWithout the processing the service cannot be provided; the route is account deletion
Platform security and abuse preventionLegitimate interestObjection under Article 21(1)Case by case balancing; as a rule the interest in the security of all users prevails
Audit logLegitimate interest and the need to demonstrate the integrity of the systemRestriction preferred over erasureData stay stored for twenty four months but are not used for other purposes
Usage statistics with Google Analytics 4ConsentWithdrawal of consent, which replaces objectionCollection stops right after the withdrawal
Retention of tax and accounting documentsLegal obligationNo objection availableRetention continues until the statutory period expires

Restriction under Article 18 is a different tool and often more useful than it looks, because it freezes the situation while a question is clarified. It applies in four cases: when you contest the accuracy of a piece of data, for the time needed to verify it; when the processing is unlawful but you prefer restriction to erasure; when we no longer need the data but you need them for legal claims; and when you have objected and the balancing assessment is still under way.

During restriction the data stay stored but are not otherwise processed, except with your consent, for the establishment or defence of legal claims or to protect the rights of another person. We inform you before the restriction is lifted, as Article 18(3) requires.

Withdrawing consent

Where processing rests on consent, consent can be withdrawn whenever you like and as easily as it was given. On Animiyo this covers push notifications, geolocation of walks, usage statistics and the shares that make a pet's data visible to third parties. Every withdrawal is exercised at the point where consent was given, without going through a written request.

Where each consent is withdrawn and what effect it has
ConsentWhere to withdraw itEffect of withdrawal
Push notifications for reminders and eventsDevice settings, notification section for the applicationThe FCM token stops receiving alerts; reminders stay visible inside the application
Location access for recording walksDevice settings, location permissionsRecording new routes is no longer possible; walks already saved remain until you delete them
Usage statistics with Google Analytics 4Cookie preferences panel of the siteCollection stops; for identifiers already collected the Google user deletion feature is needed
Sharing a pet with another personThe same screen you shared the pet fromThat person loses access to the pet profile
Sharing a route or joining a group walkThe same screen you shared the route from or created the groupSharing ends and the route becomes visible to you alone
Public lost pet tagIt switches off when you report the pet as foundThe public page stops being reachable by whoever finds the pet

Withdrawal works for the future: it does not affect the lawfulness of processing carried out on the basis of consent before the withdrawal, as Article 7(3) states. In concrete terms, walks recorded while the location permission was active remain lawful, and they remain yours: you can delete them whenever you want, but they do not become unlawful retroactively.

Withdrawing a consent does not cost you the account, nor does it reduce the features that do not depend on that consent. Some features simply stop working, because without the data they have no way to operate: without location permission there is no route tracking, without notification permission no alert arrives.

Special cases and conflicts

Some requests hit a limit that does not depend on our willingness but on the structure of the processing or on an external obligation. Declaring them upfront prevents them from looking like excuses invented after the request.

Situations where a request is only partly granted
CaseWhat you can obtainWhat you cannot obtain
Data entered by a clinic in the medical recordForwarding of the request to the competent tenant and our technical assistanceA change or an erasure decided by Animiyo on its own initiative
Tax and accounting documents, once payments are activeAccess to the documents concerning youErasure before the statutory retention period expires
Audit logDisclosure of what concerns you and restriction of the processingFull erasure before the twenty four month retention ends
Pet shared among several peopleDeletion of your account and of your access to the petDeletion of the pet if at least one other holder of access remains
Conversations with a professionalDeletion of your own copy of the conversationDeletion of the copy kept by the recipient
Published reviewsRemoval of the review on requestErasure of the trace of the removal operation in the audit log
Google Analytics 4 identifiersDeletion through the Google user deletion featureA lookup by name or by email, because the identifiers are pseudonymous and not linked to the account

The audit log deserves a separate explanation. It records the operations carried out on the platform and is kept for twenty four months for security purposes. Erasing it in full would clash with the obligation to demonstrate the integrity of the system, which is a safeguard for you too: without the log it would be impossible to reconstruct who did what in case of unauthorised access. This is why, faced with an erasure request, we consider restriction as a proportionate alternative.

The shared pet is the second recurring case. When a profile is accessible to several people, the data entered by each of them remain theirs. Deleting your account removes your access and your content, but it does not delete the pet if at least one other holder of access remains: doing so would mean erasing someone else's data at your request, which the Regulation does not allow.

Conversations work like email. A message sent to a professional lands in their copy of the conversation and stays there, because it is data concerning them as well. The erasure you can obtain covers your own copy; nobody can erase the recipient's memory, and no messaging system allows it without the agreement of both parties.

For Google Analytics 4, finally, collection happens on pseudonymous identifiers that are not directly linked to your account. Deletion goes through the user deletion feature made available by Google and requires the client identifier, which you can remove yourself by clearing the site data in your browser. After clearing, the next session is associated with a new identifier, unrelated to the previous one.

Complaint to the supervisory authority

If you believe the processing of your data infringes the Regulation, you can lodge a complaint with a supervisory authority. Writing to the controller first is advisable because many issues close with a clarification or an immediate correction, but it is not a mandatory step: the right to complain under Article 77 requires no prior attempt.

  • Garante per la protezione dei dati personali, piazza Venezia 11, 00187 Rome, Italy.
  • Alternatively, the supervisory authority of the Member State where you habitually reside.
  • Alternatively, the supervisory authority of the Member State where you work.
  • Alternatively, the supervisory authority of the Member State where the alleged infringement took place.

The judicial remedy provided by Article 79 remains unaffected and can be pursued in parallel with the complaint. The two routes do not exclude each other: a complaint goes to a supervisory authority, a claim goes to a court, and they have different requirements and outcomes.

If the complaint concerns data whose controller is a clinic or a shop, it must be brought against that business, not against Animiyo. If in doubt write to us anyway from the Contacts page: we can tell you which role we play in that specific processing, so that the complaint reaches the right party.

Frequently asked questions

Do I have to pay to exercise a right?
No, requests are free of charge. Only for manifestly unfounded or excessive requests, in particular repetitive ones, does Article 12(5) allow a reasonable fee or a refusal. In that case the burden of proving the unfounded or excessive character lies with the controller, not with you. In practice, for a platform that has not been publicly launched yet, this is a remote scenario.
How long does it take to get a reply?
The ordinary deadline is one month from receipt of the request. For complex or numerous requests it can be extended by two further months, but the extension must be notified to you with its reasons within the first month. If the request is not granted you still receive a reasoned reply within one month, telling you about the right to complain and the right to a judicial remedy. Silence is not a permitted outcome.
Do I need to attach a copy of my identity document?
If you write from the authenticated account nothing is needed, because authentication already counts as verification. If you write from an external channel, such as the Contacts page, we send a code to the email address registered on the account and simply need you to quote it back. A copy of a document is requested only if strictly necessary, and in that case it is wise to redact every detail not needed to identify you.
I asked the clinic to correct a clinical note and they told me to contact you. Who is right?
For the data a clinic enters in the medical record the controller is the clinic, not Animiyo. We provide the tool and act as a processor, so we do not amend or erase that content on our own initiative. If you write to us we forward the request to the competent tenant and support them technically in replying. The decision on the merits, however, belongs to the clinic.
Does the export really contain everything you hold about me?
The JSON archive contains the user profile, the pets with their subcollections, the pet contacts, the budget configuration, the expense items and the goals. It does not contain the audit log, the data entered by clinics or shops, the copy of conversations kept by the recipient or the pseudonymous Google Analytics 4 identifiers. For those categories you can submit a written access request and we reply with what concerns you. The distinction is not arbitrary: it depends on who the controller is and on the legal basis of each processing operation.
If I delete my account, does the pet I share with someone else disappear too?
No. If at least one other holder of access remains on the pet, the profile keeps existing for that person. Deletion removes your account, your access and the data linked exclusively to you. Content entered by other users stays theirs, because erasing it at your request would mean disposing of someone else's data.
I deleted my account by mistake: can I recover the data?
Account deletion is irreversible and there is no restore function. That is why data export sits on the same screen: it is the step to take before confirming. If you already downloaded the JSON archive you can consult it freely, but it cannot be uploaded back to rebuild the previous account. If you did not download it, the deleted data cannot be recovered.

In short

Before writing to anyone, open your account settings: data export covers access and portability, direct editing handles rectification, and shares are withdrawn from the screen you shared them from. If you need more, write from the Contacts page stating which right you are exercising, which data it concerns and over which period; if the data were entered by a clinic or a shop, address them directly, and keep the date you sent the request so you can check the one month deadline.

How to exercise your rights over your personal data · Animiyo