Data processing agreement
Article 28 agreement between Animiyo as processor and the tenant controller: instructions, security, sub-processors, breaches, audits and transfers.
- Effective from
- August 2, 2026
- Last updated
- August 2, 2026
- Version
- 1.0
When a veterinary clinic, a shop or a breeder uses Animiyo to manage its own clients, the roles separate: the tenant decides why and how that data is processed and is the controller, Animiyo carries out its instructions and is the processor. Article 28 of Regulation (EU) 2016/679 requires that relationship to be governed by a written legal act, and this document is that act. It is not a plain language summary of the privacy notice: it is the text that binds the two parties, that the controller can attach to its own record of processing activities and that a supervisory authority may ask to see. It sets out the subject matter, duration, nature and purpose of the processing, the types of data and the categories of data subjects, the instructions the controller may give and those that would be refused, the security measures actually active on the platform, the chain of sub-processors, the assistance owed to the controller, the deadlines for notifying a breach, the way an audit is exercised on a multi-tenant SaaS service, the basis for transfers to the United States and what happens to the data when the relationship ends. Every measure mentioned matches a configuration genuinely present in the Google Cloud project petdiary-10327, not a list of intentions.
Subject matter and scope of the agreement
This document governs the processing of personal data that Animiyo carries out on behalf of a tenant. Tenant means a veterinary clinic, a pet shop or service, or a breeder operating in a separate workspace of the platform, with its own staff and its own clients. Within that perimeter the tenant determines the purposes and means of the processing and is the controller; Animiyo provides the infrastructure, carries out the instructions received and is the processor within the meaning of Article 4 point 8 of Regulation (EU) 2016/679.
The agreement is concluded without a separate signature. It becomes binding the moment the tenant workspace is enabled and the terms published at /termini are accepted: from then on this text, in the version in force at the date shown at the top of the page, is the legal act required by Article 28 paragraph 3. A tenant needing a signed copy for its own documentation can request one from the /contatti page and receives the same text in a dated and signed document.
| Item | Value |
|---|---|
| Version | 1.0 |
| Effective from | 2 August 2026 |
| Last updated | 2 August 2026 |
| Processor | The entity operating Animiyo, identified on the /contatti page |
| Controller | The tenant operating in its own workspace on the platform |
| Scope | Web application on Cloud Run, native iOS application, shared backend in the Google Cloud project petdiary-10327 |
| Related documents | /privacy, /sub-responsabili, /diritti-privacy, /termini |
| Channel for communications | /contatti |
The agreement does not cover the processing in which Animiyo determines purposes and means itself, that is the accounts of pet owners using the platform for personal purposes: for those Animiyo is the controller and the applicable document is the notice at /privacy. Nor does it cover providers the tenant chooses on its own, which remain its responsibility as described at /sub-responsabili. The distinction matters because it determines who a data subject must address a request to and who answers before the supervisory authority.
Roles of the parties
Animiyo is a multi-tenant platform, so its role changes depending on the data in question, not on the moment. Two distinct processing operations can coexist around the same animal: the record an owner keeps for themselves, where Animiyo is the controller, and the clinical documentation a clinic writes in its own workspace, where the clinic is the controller. The table shows where the boundary runs, feature by feature, and should be read together with the matching table in the notice at /privacy, with which it coincides.
| Processing | Animiyo's role | Controller | Applicable document |
|---|---|---|---|
| Clinical records and SOAP notes written by a clinic | Processor | The veterinary clinic | This agreement |
| Laboratory results and consents signed at the clinic | Processor | The veterinary clinic | This agreement |
| Appointment diary, appointment types and hospital stays | Processor | The tenant managing them | This agreement |
| Estimates, invoices, orders, subscriptions and loyalty schemes | Processor | The tenant issuing them | This agreement |
| Records of the tenant's clients and of the animals it treats | Processor | The tenant | This agreement |
| Registration, sign in and management of an owner's account | Controller | Animiyo | Notice at /privacy |
| An owner's pet profiles, reminders, walks and budget | Controller | Animiyo | Notice at /privacy |
| Platform security, audit log, abuse prevention | Controller | Animiyo | Notice at /privacy |
| Measurement of the public site with Google Analytics 4 | Controller | Animiyo | Notice at /cookie |
The two roles do not overlap and are not swapped for convenience. When Animiyo acts as processor it does not decide which data to collect or how long to keep it: it carries out the tenant's documented instructions and, if it goes beyond them, for that processing it is considered a controller under Article 28 paragraph 10, with every consequence that follows. When it acts as controller, by contrast, it answers directly for its own choices and cannot invoke anyone's instruction.
Downstream of Animiyo the chain continues. The providers listed at /sub-responsabili process data on behalf of Animiyo and, in the relationship with the tenant, are sub-processors authorised under Article 28 paragraphs 2 and 4. The chain is therefore linear and verifiable: the tenant is the controller, Animiyo is the processor, Google Ireland Limited with Google LLC is the sub-processor for the infrastructure services. No other link exists at the date of this agreement.
Subject matter, duration, nature and purpose of the processing
Article 28 paragraph 3 requires the legal act to state certain elements precisely, and in practice they are often relegated to a generic annex. Here they are written in the body of the document and tied to features genuinely present in the platform, because an abstract list lets the controller verify nothing.
| Element | Content for this agreement |
|---|---|
| Subject matter | The processing of personal data that the tenant enters, generates or receives using the professional features of the platform |
| Duration | From the activation of the workspace until its closure, plus the return or deletion period described further down |
| Nature | Collection, recording, organisation, structuring, storage, consultation, retrieval, disclosure to the recipients authorised by the controller, export, restriction and erasure |
| Purpose | Delivering the features requested by the controller and safeguarding the security, integrity and continuity of the service |
| Types of personal data | The categories listed in the section on data and data subjects |
| Categories of data subjects | The tenant's clients, people they name as a contact, members of the tenant's staff |
| Obligations and rights of the controller | Those set out in Articles 24, 28, 32, 33, 34, 35 and 36 of the Regulation, recalled in the sections that follow |
The purposes are not generic. Each corresponds to a part of the product the tenant enables or leaves disabled, and none involves any use of the data other than the one requested by the controller. In particular, no data processed on behalf of a tenant is used for Animiyo's own purposes, for commercial statistics, for profiling or to train artificial intelligence models.
- Management of client records and of the animals treated, including the shares authorised by the owner.
- Writing and keeping clinical documentation: SOAP notes, laboratory results, chronic conditions, hospital stays.
- Recording vaccinations, drug therapies, deworming treatments and weight measurements.
- Appointment diary, appointment types configured by the tenant and the related reminders.
- Consent forms, signature capture and storage of signed consents.
- Estimates, invoices, orders, subscriptions and loyalty schemes run by the tenant.
- Conversations between the tenant's staff and clients inside the platform.
- Platform security, audit log and prevention of automated abuse.
- Export of the data at the request of the controller or of a data subject who addresses the controller.
One clarification about duration prevents a frequent misunderstanding. Processing does not end on the day the tenant stops using the platform, but on the day the return or deletion procedure described further down is completed. In the intervening period Animiyo continues to hold the data, restricting the processing to storage and to the operations needed to hand it over or erase it. That intervening period is not open ended: it has the deadlines set out in the section on the end of the relationship.
Types of personal data and categories of data subjects
The table lists the categories of data Animiyo processes on behalf of a tenant, with concrete examples and with the Firestore collections in which they reside. Naming the collections is not a superfluous technical detail: it lets the controller check that what is declared here matches what actually exists in the system, and lets it describe the processing in its own record with the same precision.
| Category of data | Concrete examples | Where it resides | Data subject |
|---|---|---|---|
| Client identifiers | Name, email address, contact details, public username, tenant membership in the custom claims of the token | Collections users, usernames, petMemberships | The tenant's client |
| Records of the animals treated | Name, species, breed, date of birth, sex, microchip number, weight, photographs | Collections pets, weightRecords, petActivity and Cloud Storage | The animal's owner |
| Contacts linked to the animal | Emergency contacts, referring veterinarian, people delegated to collect the animal or to decide | Collection petContacts | The owner and the people named |
| Clinical documentation | SOAP notes, laboratory results, chronic conditions, hospital stays | Collections soapNotes, labResults, petConditions, hospitalized | The animal's owner |
| Preventive care and therapies | Vaccinations, medicines administered or prescribed, deworming treatments, veterinary appointments | Collections vaccinations, medications, dewormingRecords, vetAppointments, appointmentTypes | The animal's owner |
| Consents | Consent forms prepared by the tenant, signed consents and the captured signature | Collections consentForms, signedConsents and Cloud Storage | Whoever signs the consent |
| Financial and commercial data | Estimates, invoices, orders, subscriptions, loyalty points, related expense items | Collections estimates, invoices, orders, subscriptions, rewards, budgetItems | The tenant's client |
| Communications and reviews | Conversations between the tenant's staff and clients, reviews received by the tenant | Collections conversations, reviews | Whoever writes and whoever is mentioned |
| Animal shares | Authorisations by which an owner opens the record of their animal and the chosen subcollections to the tenant | Collections petShares, petMemberships | The animal's owner |
| Data about the tenant's staff | Operator accounts, assigned role, permissions, author of every write | Collections users, tenants, auditLog | The member of staff |
| Technical and security data | Application audit log, FCM notification tokens, App Check tokens, Cloud Run request logs | Collection auditLog and the infrastructure provider's logs | Anyone using the platform |
Four categories of data subjects are involved and it is worth keeping them apart, because they have different expectations and rights and because the controller must inform all of them, not only its paying clients.
- The tenant's clients, that is the owners of the animals treated by the clinic, the shop or the breeder.
- The people named as a contact for an animal: family members, household members, delegates, referring veterinarian.
- The members of the tenant's staff who access the platform with their own account and whose actions end up in the audit log.
- Third parties occasionally mentioned in the free text of a note, a result, an estimate or a conversation.
The last category causes the most trouble and is also the least controllable by the processor. A free text field accepts whatever is typed into it, including data about people who have no relationship with the platform. Animiyo does not filter the content of professional notes, because filtering it would mean reading and assessing it, that is exceeding the instructions received. It is for the controller to instruct its own staff to write in free text fields only what is necessary and relevant, under the minimisation principle of Article 5 paragraph 1 point c.
Animal health data and owner data
The data held in an animal's health record is not data concerning health within the meaning of Article 9 of the Regulation. The reason is simple and admits no shortcuts: Article 9 protects special categories of personal data relating to a data subject, and a data subject is by definition a natural person. An animal is not one, so its clinical record does not trigger the prohibition in Article 9 paragraph 1 nor the search for a derogation among those in paragraph 2.
This does not make that data anonymous, which is the opposite and equally common error. A vaccination, a therapy, a hospital stay or a laboratory result is attributable to the owner identified by the account the animal is linked to: it describes their spending, their habits, their trips to a practice and, in many cases, their family situation. It therefore remains ordinary personal data of the owner and must be treated as such, with a legal basis, a notice, retention periods and fully applicable rights.
| Information | Legal classification | Who needs the legal basis |
|---|---|---|
| Vaccination, therapy or procedure recorded for an animal | Ordinary personal data of the owner, not Article 9 data | The tenant, as a rule for the performance of the contract with its client |
| SOAP note written by the veterinarian | Ordinary personal data of the owner, with professional content about the animal | The tenant, for professional and contractual obligations |
| Laboratory result relating to an animal | Ordinary personal data of the owner | The tenant, for professional and contractual obligations |
| Note that the animal is a guide dog or an assistance animal | Data concerning the health of the assisted person, Article 9 | The tenant, with explicit consent under Article 9 paragraph 2 point a |
| Reason for an appointment describing a condition of the owner | Data concerning the health of the owner, Article 9 | The tenant, with explicit consent or by removing the information |
| Owner's allergy noted for the handling of a medicine | Data concerning the health of the owner, Article 9 | The tenant, with explicit consent and limited retention |
| Emergency contact details of a family member or delegate | Ordinary personal data of a third party | The tenant, providing the notice to that third party itself |
| Handwritten signature on a consent form | Ordinary personal data with high identifying value | The tenant, to meet its obligation to prove consent |
The distinction has practical consequences in both directions. Downwards, it stops the controller from seeking explicit consent where a contract suffices, needlessly complicating data collection and making revocable a processing operation that is not. Upwards, it prevents an animal clinical record from being treated as irrelevant: if the tenant serves a large number of clients, the volume and the perceived sensitivity of that information weigh in the risk assessment even in the absence of Article 9.
Technically, Animiyo applies to this information the same safeguards used for special categories, regardless of its legal classification, because the potential harm from unauthorised access is comparable.
- Access limited to the owner and to those they have explicitly authorised through a share.
- Firestore and Cloud Storage security rules that check ownership of the document on every read and every write.
- Separation between tenants, so that a clinic sees only the animals shared with it.
- Recording of significant operations on clinical documentation in the application audit log.
- Encryption in transit with TLS and at rest with AES at 256 bits.
- No secondary use of any kind: no commercial statistics, no profiling, no model training.
One point remains for the controller to handle alone. Free text fields in clinical documentation can capture data about the health of natural persons, and in that case Article 9 applies in full. Animiyo cannot notice it, because it does not read the content of notes. The controller must therefore instruct its staff not to enter information about the health of the owner or of third parties when it is not necessary for the care of the animal, and to collect explicit consent when it is.
Documented instructions of the controller
Animiyo processes the tenant's data only on documented instructions from the controller, under Article 28 paragraph 3 point a. Documented does not necessarily mean written on paper: it means reconstructable, attributable to whoever gave the instruction and verifiable later. On a software platform most instructions are given by using the product, and this agreement acknowledges that explicitly instead of pretending that everything travels through an exchange of letters.
| Channel | Counts as an instruction | Note |
|---|---|---|
| This agreement and the documents it refers to | Yes | It is the baseline instruction: it describes everything the platform does on behalf of the controller |
| Settings chosen in the tenant panel | Yes | Operator roles and permissions, appointment types, consent forms, price lists, reminders |
| Operations performed by staff within the application features | Yes | Creating, editing, sharing, exporting and deleting are instructions given through the interface and recorded in the audit log |
| Written request sent from the /contatti page by the tenant administrator | Yes | It is the channel for instructions the interface does not cover, for example an extraordinary extraction |
| Verbal or telephone message | No | It must be confirmed in writing before being carried out, except during an ongoing security incident |
| Request from an address not linked to the administrator account | No | It is refused and reported to the tenant administrator |
| Request from an operator lacking the necessary permissions | No | It is refused: internal permissions are assigned by the tenant administrator, not by the processor |
| Request from a tenant's client addressed directly to Animiyo | No | It is forwarded to the controller under the procedure set out in the section on assistance |
Article 28 paragraph 3 closes with an obligation that runs in the opposite direction to all the others: the processor must immediately inform the controller if, in its opinion, an instruction infringes the Regulation or other Union or Member State data protection provisions. It is not a courtesy and it is the only case in which the processor is required to contradict the controller. Animiyo does so in writing, from the /contatti page to the email address of the tenant administrator, within five working days of receiving the instruction, and suspends execution of the contested part alone until it receives an answer.
The following instructions, by way of example and not exhaustively, would be reported and not carried out. They are realistic examples, drawn from features that genuinely exist in the platform, not textbook hypotheses.
- Disabling the audit log of the tenant or altering entries already written.
- Keeping a client's clinical documentation beyond the period set by the controller itself, without any further legal basis.
- Disclosing a client's data to a third party not authorised by the controller or by law.
- Accessing the data of a tenant other than the one giving the instruction, even for comparison or verification.
- Using the contact details of the tenant's clients for bulk commercial messages without valid consent.
- Reconstructing data erased at a data subject's request by drawing on backup copies.
- Transferring data to a provider chosen by the tenant that does not offer the guarantees required by Article 28 paragraph 1.
- Removing the separation between tenants to allow a cross search over the animals of other professionals.
If after the report the controller confirms the instruction in writing and the confirmation does not remove the unlawfulness identified, Animiyo does not carry it out and may terminate the relationship with the notice period set out in the terms at /termini. The report, the confirmation and the outcome are retained and made available to the controller on request, because they are the evidence of how each party behaved.
Confidentiality of personnel
Article 28 paragraph 3 point b requires that persons authorised to process the data have committed themselves to confidentiality or be under an appropriate statutory obligation of confidentiality. On Animiyo the number of people with access to production data is very small and coincides with those performing technical maintenance on the platform. Saying so is more useful than describing an organisation chart that does not exist: in a service of this size the main security measure is precisely that possible accesses are few and all traced.
- A written confidentiality undertaking for anyone accessing production data, effective after the end of the relationship as well.
- Administrative access granted on the principle of least privilege and withdrawn once the reason that justified it ceases.
- Access to production data allowed only for maintenance, defect correction, handling of a security incident or a written request from the controller.
- Multi-factor authentication mandatory on the Google Cloud console accounts of the petdiary-10327 project.
- Recording of significant administrative operations in the application audit log and in the infrastructure provider's logs.
- No third party customer support service with access to the data, as already declared at /sub-responsabili.
- No use of production data in test environments: tests use synthetic data or the local emulator.
The controller may request at any time, from the /contatti page, the current list of administrative roles active on the project and confirmation that the confidentiality undertakings are signed. It does not receive the names of the individuals, which are themselves personal data of third parties, but it receives the number of active accesses, the type of privilege attached to each and the date of the last review. That is the information needed to assess the measure without creating a new processing operation.
Security measures under Article 32
The measures listed here are the ones actually implemented in the platform. The third column is what makes the table useful: it states how the controller can check the measure independently, without having to trust the declaration. A security measure that cannot be checked is an assertion, not a guarantee.
| Measure | Where it applies | How the controller can verify it |
|---|---|---|
| Firebase Authentication with email address verification | Access to any account, on web and iOS | Attempting to sign in with an unverified address |
| Access control by role and by tenant in the custom claims of the token | Every backend request and every restricted screen | Inspecting the operator token and testing with a reduced role |
| Firestore security rules written per collection and per role | Every read and every write on the database | Attempting to read a document belonging to another tenant, which is refused |
| Cloud Storage security rules | Photographs, uploaded documents, consent signatures | Attempting to open a file not linked to one's own workspace |
| Separation of data between tenants, with no cross reading paths | All collections carrying the tenant reference | Searching for an animal that has not been shared, which returns nothing |
| Firebase App Check with reCAPTCHA Enterprise | Calls coming from the browser and from the iOS application | A request without a valid attestation token, which is refused |
| Encryption in transit with TLS | All connections to the site, to the backend and to Cloud Storage | Inspecting the certificate and the response headers |
| Encryption at rest with AES at 256 bits | Cloud Firestore and Cloud Storage for Firebase | Google Cloud documentation on default encryption at rest |
| Application audit log in the auditLog collection | Significant operations on data and settings | An extract of the log limited to one's own tenant, requested from /contatti |
| Content security policy in enforcing mode | Pages of the web application | Reading the response headers of the site |
| Backup and replication managed by Google Cloud | Cloud Firestore and Cloud Storage for Firebase | Provider documentation on the services enabled for the project |
| Least privilege on administrative accounts | Console of the Google Cloud project petdiary-10327 | List of active roles and date of the last review, requested from /contatti |
Article 32 paragraph 1 lists four categories of measure. The correspondence with the table above is set out below in full, so that the controller can copy it into its own record without having to reconstruct it.
- Pseudonymisation and encryption, point a: encryption in transit with TLS and at rest with AES at 256 bits; pseudonymous technical identifiers in the security logs and in the measurement of the public site.
- Confidentiality, integrity, availability and resilience, point b: security rules per collection, separation between tenants, role based control, App Check, managed services with the infrastructure provider's redundancy.
- Timely restoration, point c: backup and replication managed by Google Cloud for Cloud Firestore and Cloud Storage, with a restore procedure documented by the provider.
- Regular testing of effectiveness, point d: review of the measures at every release touching authentication, access rules or the data structure, with automated tests on the security rules.
Two things are not declared, and their absence is part of the information. Animiyo holds no certifications of its own: the available compliance reports are those Google publishes for the Google Cloud and Firebase services, and they concern the infrastructure, not the application. And no measure promises absolute security, which no system connected to a network can offer. The controller must take that into account in its own risk assessment, instead of treating the point as settled because the processor has listed it.
Sub-processors
By this agreement the controller grants Animiyo a general authorisation to engage sub-processors, under Article 28 paragraph 4 of Regulation (EU) 2016/679. A general authorisation is the only workable option in a SaaS service, because the infrastructure is shared by every tenant and a specific authorisation for each would make any maintenance impossible. It is not, however, a blank cheque: the controller keeps the right to know in advance what changes, to object and to terminate.
The authoritative and continuously updated list of sub-processors is published at /sub-responsabili, which states for each provider the service, the categories of data, the processing location and the transfer basis. At the date this agreement takes effect the chain is composed as follows.
- Google Ireland Limited, with Google LLC as further sub-processor, for Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase, Cloud Functions, Cloud Run, Firebase Cloud Messaging, Firebase App Check with reCAPTCHA Enterprise and Google Analytics 4.
- Stripe Payments Europe Limited for payment processing: the integration exists in the code but the gateway is switched off by a configuration flag, so at the date of this agreement it receives no data.
The external data sources queried directly by the user's browser are not sub-processors: openFDA, Open Pet Food Facts, dog.ceo, Wikipedia, iNaturalist, frankfurter.app and tile.openstreetmap.org. Those calls only read data, they carry neither account identifiers nor diary content and they are not made on Animiyo's instructions as to the use of the data collected. In relation to the connection data they receive, in particular the browser IP address, those services are independent controllers. The controller must take this into account in its own privacy notice if it enables the features that use them.
Publication of the notice
At least thirty days before adding or replacing a sub-processor, the change is published at /sub-responsabili stating the provider, the service, the data involved and the planned activation date.
Message to the controller
At the same time as publication the notice is sent to the email address the tenant has entered in its profile. Keeping that address up to date and monitored is a duty of the controller, because that is where the notice takes effect.
Reasoned objection
The controller may object within fifteen days of the notice, writing from the /contatti page. The objection must be reasoned, that is it must state which concrete risk or which legal constraint makes the proposed provider unacceptable.
Search for an alternative measure
Before the activation date the parties check whether the objection can be resolved by a different configuration, a different processing region, a reduction of the data transmitted or a different provider for that function.
Termination without penalty
If the objection cannot be resolved, the controller may terminate without penalty the part of the service affected by the change, with the right to have the data returned under the procedure described in the section on the end of the relationship.
| Stage | Deadline | Channel |
|---|---|---|
| Publication of the notice | At least thirty days before the change | The /sub-responsabili page |
| Message to the controller | At the same time as publication | Email address entered by the tenant in the profile |
| Reasoned objection | Within fifteen days of the notice | The /contatti page |
| Proposal of alternative measures | Before the activation date | Email address entered by the tenant in the profile |
| Termination without penalty | If the objection cannot be resolved by alternative measures | The /contatti page |
| Urgent replacement on security grounds | Shortened notice, with immediate communication and objection afterwards | The /sub-responsabili page and the tenant's email address |
On each sub-processor Animiyo imposes by contract data protection obligations no less onerous than those assumed under this agreement, as Article 28 paragraph 4 requires. The same provision states that, where the sub-processor fails to fulfil them, the processor remains fully liable to the controller for the performance of those obligations. This means the controller does not have to chase Google Ireland Limited over an infrastructure failure: it turns to Animiyo, which answers and then seeks redress downstream. The criteria by which a provider is admitted or excluded are described at /sub-responsabili and include an absolute ban on clauses allowing the provider to use the data for its own purposes.
Assistance to the controller
The processor must assist the controller with a set of duties that remain the controller's own but that, in practice, need information or tools only the processor has. The table states each obligation, the provision that sets it out, the concrete way it is met and the deadline within which the controller receives an answer.
| Obligation | Reference | How it is met | Deadline |
|---|---|---|---|
| Assistance with data subject requests | Article 28 paragraph 3 point e | Export and deletion tools available in the application, forwarding to the controller of requests received in error, extraordinary extractions on written request | Forwarding within five working days, technical assistance within ten working days |
| Assistance with the security of processing | Article 28 paragraph 3 point f and Article 32 | Up to date description of the active measures and answers to the controller's security questionnaires | Within thirty days of the request |
| Assistance with breach notification | Article 28 paragraph 3 point f, Articles 33 and 34 | Communication with the minimum content set out in the dedicated section and support in drafting the notification to the authority | First alert within twenty four hours of becoming aware |
| Assistance with the impact assessment | Article 28 paragraph 3 point f and Article 35 | Description of the data flows, the categories of data, the sub-processors, the measures and the known risks | Within thirty days of the request |
| Assistance with prior consultation | Article 28 paragraph 3 point f and Article 36 | Technical documentation to attach to the request addressed to the supervisory authority and answers to any of its questions | Within thirty days of the request |
| Information to demonstrate compliance | Article 28 paragraph 3 point h | This agreement, the list at /sub-responsabili, the description of the measures, the audit log extract for one's own tenant | Within thirty days of the request |
| Contribution to the processor's record of processing | Article 30 paragraph 2 | List of the categories of processing carried out on behalf of the controller, made available on request | Within thirty days of the request |
On data subject rights the rule is clear cut: Animiyo does not answer on the merits on behalf of the controller. If a clinic's client asks Animiyo for access to or erasure of their clinical data, the request is forwarded to the competent controller within five working days and the data subject is told it has been forwarded, with the name of the party to address. The full procedure, with response times, identity checks and the tools available directly in the application, is described at /diritti-privacy. The controller remains free to handle the request with its own tools; Animiyo provides the technical extractions it needs.
On the data protection impact assessment the division is equally clear. Deciding whether a DPIA is needed and carrying it out is a duty of the controller, which knows the context, the volume of its clients and the actual purposes. Animiyo supplies the technical raw material and flags the features that, from experience, deserve attention in the assessment. The list below does not replace the controller's own analysis, but it shows where the risk concentrates.
- Location data from walks, shared routes and group walks, which can reveal habits and frequented places.
- The public lost tag page, reachable by anyone holding the link even without an account.
- Sharing an animal between owner and tenant, which opens access to the selected health subcollections.
- Symptom triage, which produces an indicative suggestion and not a diagnosis, described at /privacy in the section on automated decisions.
- Large scale processing of clinical documentation, where the tenant serves a large number of clients.
- Transfer of the data to the us-central1 region, described in the section on transfers.
- Processing of data relating to minors, where a tenant's client is a minor or where data about minors appears in free text fields.
If, following the assessment, the controller must consult the supervisory authority in advance under Article 36, Animiyo provides the necessary technical documentation and answers any questions the authority puts through the controller. Assistance is provided at no additional cost within the limits shown in the table; requests that manifestly exceed those limits, in frequency or in scope, are subject to reimbursement of documented costs, notified in advance and accepted in writing before the work begins.
Personal data breach
A personal data breach means what Article 4 point 12 of the Regulation defines: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed. It therefore also covers cases where nobody has stolen anything, for example data loss through a technical fault or prolonged unavailability of a service. The processor does not decide whether the breach must be notified to the authority: that assessment belongs to the controller, and what matters is that everything needed to make it reaches the controller quickly.
Detection and qualification
Every internal report, every anomaly spotted in the audit log and every communication received from the infrastructure provider is qualified immediately: we establish whether it is a breach within the meaning of Article 4 point 12 and which tenants are affected.
First alert within twenty four hours
Within twenty four hours of Animiyo becoming aware of the breach, the affected controller receives a first alert at the email address in its profile, with what is already known and with an explicit statement of what is still being established.
Update within seventy two hours
Within seventy two hours the controller receives the communication with the minimum content set out in the table below, that is the elements it needs to decide whether to notify the supervisory authority and whether to communicate the breach to the data subjects.
Final report within fifteen days
Within fifteen days of becoming aware the controller receives the closing report: reconstruction of what happened, causes, data actually affected, corrective measures taken and preventive measures introduced to stop it happening again.
Support with notification and communication
At the controller's request, Animiyo supplies the technical elements to attach to the notification to the authority under Article 33 and to the communication to data subjects under Article 34, and answers the authority's follow up questions through the controller.
| Element | What it contains |
|---|---|
| Date and time | When the breach occurred, where this can be reconstructed, and the exact moment the processor became aware of it |
| Nature of the breach | Loss of confidentiality, integrity or availability, with a description of how it came about |
| Data involved | Categories of data and collections affected, identifying the documents attributable to the controller's workspace |
| Data subjects involved | Categories and approximate number of data subjects and of records affected |
| Likely consequences | Technical assessment of the risk to the rights and freedoms of data subjects, with the scenarios considered |
| Measures taken | Containment steps already carried out, planned steps and expected timing |
| Encryption status | Whether the data involved was encrypted and whether the keys remained intact, a decisive element in assessing the risk |
| Point of contact | Reference at the processor for follow up, reachable from the /contatti page |
Notification to the supervisory authority within seventy two hours under Article 33 is an obligation of the controller and Animiyo does not carry it out in its place, save under a specific written mandate for the individual event. The reason is not formal: notifying on the controller's behalf would mean qualifying the risk using information only the controller holds, such as the real number of its clients, their vulnerability and the context in which the data was collected. The twenty four hour deadline for the first alert is calibrated precisely to leave the controller time to act within its own seventy two hours.
Where the breach concerns data for which Animiyo is the controller, for example owner accounts or the platform audit log, notification to the authority and communication to data subjects fall on Animiyo as described at /privacy. An incident affecting the shared infrastructure normally produces both effects: Animiyo notifies for the part where it is the controller and informs tenants for the part where it is the processor, keeping the two communications separate to avoid confusion about roles.
Deletion or return of the data
At the end of the relationship the controller chooses between return and deletion of the data, under Article 28 paragraph 3 point g. The choice is the controller's and not the processor's, and must be communicated in writing from the /contatti page. In the absence of an express choice within the deadlines set out below, the data is deleted: that is the default outcome because keeping data with no instruction and no legal basis would be the riskiest option for the data subjects.
End of the relationship
The relationship ends through termination by either party, through expiry or withdrawal of the professional licence, through closure of the workspace or through exercise of the right to terminate after an objection to a sub-processor.
Thirty day export window
Thirty days run from the end of the relationship, during which the workspace remains accessible in read only mode and all export tools stay active. Within that window the controller can download whatever it needs without asking anyone.
Choice between return and deletion
Within the same thirty day window the controller states whether it wants an assisted handover of the data or whether deletion may proceed. The assisted handover also covers content that the in application tools do not export.
Deletion from live systems
At the end of the window, or earlier if the controller asks, the data is deleted from live systems within thirty days. Deletion covers Cloud Firestore and Cloud Storage and includes photographs, uploaded documents and consent signatures.
Written confirmation
Once deletion is complete the controller receives written confirmation stating the date of the operation, the collections affected and any data retained under a legal obligation, with the relevant legal basis.
| Content | Format | How to obtain it |
|---|---|---|
| User profile, animals and their subcollections, animal contacts, budget configuration, expense items and goals | JSON archive with a versioned schema and dates normalised to ISO 8601 | Data export from the application |
| Full record of an animal with vaccinations, medicines, visits, appointments, weight measurements and expenses | CSV file with comma separator and UTF-8 encoding | Export from the animal record |
| Readable report of an animal record | PDF document generated by the browser from the report | Printing the report from the animal record |
| Budget with movements, categories, limits and goals | CSV file and PDF document | Export from the budget section |
| Photographs, uploaded documents and consent signatures | Files in the original formats held on Cloud Storage | Download from the record they are attached to |
| Audit log extract for one's own tenant | JSON file | Written request from the /contatti page |
| Content not covered by the in application tools | Purpose built JSON archive using the same versioned schema | Assisted handover requested within the thirty day window |
Backup copies need a clarification that many agreements leave out. The backup copies and replicas managed by Google Cloud do not allow selective deletion of a single document: they remain until the rotation cycle configured on the project overtakes them, and they are never used to restore data deleted on request. The rotation window currently configured is disclosed to the controller on request from the /contatti page, together with the expected date on which the copies containing its data will be overtaken. Declaring instant deletion from backups too would be more reassuring and less true.
Data that the processor is required to retain under Union or Member State law is excluded from deletion, a case expressly preserved by Article 28 paragraph 3 point g. At the date of this agreement the main case concerns tax records, which will become relevant once payments are active and which civil and tax law requires to be kept for ten years. In those cases processing is restricted to storage alone, with no consultation or further use, and the deletion confirmation says so explicitly.
Audits and inspections
Article 28 paragraph 3 point h gives the controller the right to contribute to audits, including inspections. The clause was written with a processor that has a machine room to visit, and on a multi-tenant SaaS service that picture does not work: Animiyo owns no data centres, the infrastructure is shared by all tenants, and any access granted to one controller would risk exposing the data of the others. The right to audit remains intact, but it is exercised through tools other than a site visit, listed here so the controller knows in advance what it can obtain.
| Tool | What the controller obtains | Frequency and deadline | Cost |
|---|---|---|---|
| Permanent documentation | This agreement, the list at /sub-responsabili, the notice at /privacy, the description of the active security measures | Always available and public | None |
| Written security questionnaire | A specific answer on the measures, the provider chain, the data flows and the processing regions | Once a year, answer within thirty days | None |
| Audit log extract | The operations recorded in the auditLog collection concerning its own tenant, in JSON format | On request, delivered within thirty days | None |
| Remote verification session | Guided review of the configuration of its own workspace: roles, permissions, active shares, applicable rules, available exports | Once a year, with thirty days notice | None |
| Providers' compliance reports | The reports Google publishes for the Google Cloud and Firebase services used by the platform | Always available from the provider | None |
| Extraordinary verification | Further checks beyond the annual frequency, for example after a breach or a request from the supervisory authority | With thirty days notice, shortened in urgent cases | Reimbursement of documented costs |
| Penetration testing | Technical checks on the exposed interfaces, limited to the controller's workspace and to test data | Window agreed in writing, with thirty days notice | Borne by the controller |
Some things the controller cannot obtain, and it is worth writing them down before they are asked for in a tense moment. These are not limits set for the processor's convenience: each protects an interest the controller itself shares, since other tenants hold the same expectations about their own data that it holds about its own.
- Access to the data, documents or logs of a tenant other than its own, not even in partial or aggregated form.
- Direct access to the administration console of the Google Cloud project petdiary-10327.
- A full copy of the source code or of the complete security rules, which also describe the other tenants.
- Destructive tests, load tests or denial of service attacks, which would degrade the service for everyone.
- Physical inspections at the data centres, which belong to the infrastructure provider and not to the processor.
- Bulk extraction of production data for verification purposes, which would increase the risk rather than reduce it.
- Access to security logs in the part concerning operators or clients of other tenants.
If the controller considers the tools listed above insufficient for a specific case, it may propose an alternative approach from the /contatti page, stating which particular aspect it intends to verify. The parties then look for a solution that achieves the purpose without exposing third party data, for example a guided demonstration on a test environment or a technical statement on a narrow point. A request is not refused for being unusual, but only if there is no way to satisfy it without affecting the rights of other data subjects.
Transfers outside the European Economic Area
The main resources of the platform sit in the us-central1 region, in the United States. The data the tenant processes about its own clients is therefore processed outside the European Economic Area, and the controller must know this before signing the agreement rather than after. The transfer rests on a valid legal basis and on adequate technical measures, described here and more fully at /sub-responsabili.
| Service | Region | Transfer basis |
|---|---|---|
| Firebase Authentication | us-central1 (United States) | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Cloud Firestore | us-central1 (United States) | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Cloud Storage for Firebase | us-central1 (United States) | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Cloud Functions | us-central1 (United States) | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Cloud Run | us-central1 (United States) | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Firebase Cloud Messaging, Firebase App Check with reCAPTCHA Enterprise, Google Analytics 4 | Global infrastructure | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Stripe payment processing | European Union | No transfer to third countries; service not active |
The applicable standard contractual clauses are those adopted by the European Commission with implementing decision (EU) 2021/914. In the relationship between Animiyo and Google Ireland Limited module three applies, from processor to sub-processor, which is the correct module when the exporter is itself acting on behalf of a controller. The tenant controller remains the original controller in the chain and keeps the rights the clauses grant to the party on whose behalf the transfer takes place, including the right to obtain a copy of the applicable clauses.
- Google Ireland Limited as contracting counterparty, under the Google Cloud Data Processing Terms.
- Standard contractual clauses adopted with implementing decision (EU) 2021/914, module three.
- Certification of Google LLC under the EU United States Data Privacy Framework.
- Encryption of data in transit with TLS and at rest with AES at 256 bits.
- A transfer impact assessment documented by the project owner and made available to the tenant on request.
- Google's policy on handling requests from public authorities, together with the related transparency reports.
- An undertaking to inform the controller of any access request received from a third country authority, unless prohibited by law, and to challenge it where manifestly unlawful.
The transfer impact assessment considers the nature of the data involved, which in the vast majority of cases is not a special category relating to natural persons, the effectiveness of encryption in transit and at rest, the provider's documented practice in handling requests from public authorities, the remedies available to data subjects and the concrete likelihood that veterinary data about European clients becomes the object of an access request. The controller can obtain a copy from the /contatti page and must supplement it with an assessment of its own context, which only it knows.
Migrating the resources to a European region, in the europe-west area, is under consideration but is not a settled decision, because it means rebuilding part of the infrastructure and accepting a window of service unavailability. If it happens, it will be announced at /sub-responsabili with the same thirty day notice period set for sub-processor changes, so that controllers can update their own documentation before the change takes effect.
Liability, precedence and applicable law
Article 82 of the Regulation provides that a processor is liable for the damage caused by processing only where it has not complied with obligations specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller. Outside those two cases liability stays with the controller, which decided the purposes and means. The table translates the principle into the situations that genuinely arise on this platform.
| Situation | Who is liable | Why |
|---|---|---|
| The controller gives an unlawful instruction and the processor carries it out after reporting it in writing | The controller | The instruction is its own choice and it received the warning required by Article 28 paragraph 3 |
| The processor handles the data outside the documented instructions | The processor | For that processing it is considered a controller under Article 28 paragraph 10 |
| A sub-processor fails to meet its data protection obligations | The processor towards the controller, with redress against the sub-processor | Article 28 paragraph 4, final sentence |
| The controller does not inform its data subjects or lacks a valid legal basis | The controller | These are obligations placed on the controller by Articles 6, 13 and 24 |
| An operator of the tenant shares data with someone not entitled to it | The controller | Managing members, roles and internal permissions belongs to the tenant |
| A security measure described in this agreement turns out to be absent or ineffective | The processor | Article 32 places the security obligation on the processor as well |
| The controller connects one of its own external providers and exports data to it | The controller | That is processing outside the scope of this agreement, as stated at /sub-responsabili |
The limitations of liability set out in the terms published at /termini apply to this agreement as well, with two exceptions that cannot be waived: damage caused by wilful misconduct or gross negligence, and liability towards the data subject under Article 82, which the Regulation does not allow to be limited by contract. Where one party pays full compensation for the damage suffered by a data subject, it is entitled to claim back from the other the share corresponding to that party's responsibility, under Article 82 paragraph 5.
In the event of a conflict between the documents governing the relationship, the order of precedence set out at /termini applies, recalled here for the part concerning data processing.
- Any particular conditions agreed in writing with a tenant, which prevail in the relationship with that tenant alone.
- This agreement and the list of sub-processors at /sub-responsabili, for everything concerning the processing carried out on behalf of the controller.
- The terms published at /termini, which govern the use of the platform by every user.
- The notice at /privacy and the cookie notice at /cookie, which describe the processing where Animiyo is the controller and prevail on that point.
The agreement is governed by Italian law and by Regulation (EU) 2016/679, supplemented by legislative decree 196/2003 as amended by legislative decree 101/2018. Since the tenant acts in the course of its professional activity, disputes concerning this agreement fall within the exclusive jurisdiction of the court of the provider's registered office indicated on the /contatti page, consistently with what /termini provides for professional users. This does not affect the right of a data subject to bring proceedings before the court of their habitual residence under Article 79 of the Regulation, nor the right to lodge a complaint with a supervisory authority. The Italian and English versions have the same content; in the event of a difference of interpretation the Italian text prevails.
Changes to the agreement and version history
This agreement can change, because the platform features, the providers and the legal framework change. Substantive changes do not take effect by surprise: they follow the same notice, objection and termination mechanism set for sub-processors, because a change to the agreement affects the relationship as much as, and more than, a change of provider.
| Type of change | How it is communicated | Notice |
|---|---|---|
| Substantive change to the obligations of the parties | Publication on this page and message to the tenant's email address | At least thirty days |
| Addition or replacement of a sub-processor | Publication at /sub-responsabili and message to the tenant's email address | At least thirty days |
| Change of the processing region | Publication on this page and at /sub-responsabili, with a message to the tenant | At least thirty days |
| Change imposed by a legal rule or by a decision of an authority | Immediate communication stating the source of the obligation | The minimum compatible with the obligation |
| Introduction of an additional security measure | Update of the measures table and an entry in the change log | None, it does not reduce protections |
| Editorial correction with no substantive effect | Update of the date at the top of the page | None |
Faced with a substantive change the controller may object within fifteen days of the notice, writing from the /contatti page. If the objection cannot be resolved by alternative measures, it may terminate without penalty with the right to have the data returned under the procedure described above. Silence beyond fifteen days counts as acceptance, and that effect is stated here explicitly so the controller is aware of it before the period starts to run.
| Date | Version | Change |
|---|---|---|
| 2 August 2026 | 1.0 | Initial publication: subject matter and duration, roles of the parties, data and data subjects, documented instructions, confidentiality, security measures, sub-processors, assistance to the controller, breaches, end of the relationship, audits, transfers, liability and applicable law. |
Later revisions are added to this table and are tracked in the version control history of the code, which preserves the exact text of every version together with the date of the change. A controller needing to reconstruct which agreement was in force at a given moment, for example in response to a request from a supervisory authority, can obtain that version from the /contatti page.
Frequently asked questions
- Do I have to sign a separate contract or is this page enough?
- This page is enough. The agreement becomes binding when the tenant workspace is enabled and the terms at /termini are accepted: from then on this text, in the version in force at the date shown at the top of the page, is the legal act required by Article 28 paragraph 3 of Regulation (EU) 2016/679. If your practice needs a signed copy to keep alongside its record of processing activities, you can request one from the /contatti page and receive the same text in a dated and signed document.
- Is the health data of the animals I treat a special category under Article 9?
- No, and the reason is that Article 9 protects data relating to a natural person, while an animal is not a data subject. It does remain ordinary personal data of the owner, because it is attributable to the account the animal is linked to, so it needs a legal basis, a notice and retention periods. Article 9 comes back into play when a free text field contains information about a person's health, for example a note that the animal is a guide dog or an appointment reason describing a condition of the owner: in those cases explicit consent is required, and collecting it is for you as controller.
- Can I audit Animiyo and what do I actually get?
- Yes, using the tools described in the section on audits. You get the permanent documentation, a written answer to your security questionnaire once a year within thirty days, an audit log extract limited to your tenant, a remote verification session on the configuration of your workspace and the compliance reports Google publishes for the services the platform uses. You do not get access to other tenants' data, to the Google Cloud project console, to the complete source code or to the data centres, which belong to the infrastructure provider. Penetration testing limited to your workspace is possible in a window agreed in writing with thirty days notice.
- If I close my workspace, is the data returned to me or deleted?
- You choose. From the end of the relationship you have thirty days during which the workspace stays accessible in read only mode and the export tools remain active: JSON archive with a versioned schema and ISO 8601 dates, CSV files for each animal record and for the budget, PDF documents of the reports, attachments in their original formats from Cloud Storage. Within the same window you state whether you want an assisted handover for what the tools do not cover. At the end of the window the data is deleted from live systems within thirty days and you receive written confirmation. The backup copies managed by Google Cloud cannot be deleted selectively, they remain until the rotation cycle overtakes them and they are never used to restore deleted data.
- How quickly do you tell me if there is a data breach?
- The first alert reaches you within twenty four hours of the moment we become aware of the breach, at the email address in your profile. Within seventy two hours you receive the communication with the minimum content set out in the agreement: nature of the breach, data and collections involved, categories and approximate number of data subjects, likely consequences, measures taken, encryption status and point of contact. Within fifteen days you receive the closing report. Notification to the supervisory authority within seventy two hours remains your obligation as controller, and our deadlines are calibrated to leave you the time for it.
- Can I object if you change a provider that processes my clients' data?
- Yes. Under this agreement you grant a general authorisation pursuant to Article 28 paragraph 4, but you keep the right to know in advance what changes. Every addition or replacement of a sub-processor is published at /sub-responsabili at least thirty days beforehand and is sent to the email address in your profile. You may raise a reasoned objection within fifteen days from the /contatti page and, if it cannot be resolved by alternative measures such as a different configuration or a different provider, you may terminate without penalty the part of the service affected, with the right to have the data returned.
In short
Save this agreement alongside your record of processing activities: it is the document that shows on what basis you process your clients' data on the platform. Check three things straight away: that the email address in your profile is monitored, because that is where sub-processor notices and breach communications arrive; that your own notice to clients declares the transfer to the us-central1 region; and that your staff are instructed not to write data about the health of natural persons in free text fields when it is not needed for the care of the animal. Objections, security questionnaires, audit log extracts and a signed copy of the agreement all go through the /contatti page.