Skip to content
Animiyo

Data processing agreement

Article 28 agreement between Animiyo as processor and the tenant controller: instructions, security, sub-processors, breaches, audits and transfers.

Effective from
August 2, 2026
Last updated
August 2, 2026
Version
1.0

When a veterinary clinic, a shop or a breeder uses Animiyo to manage its own clients, the roles separate: the tenant decides why and how that data is processed and is the controller, Animiyo carries out its instructions and is the processor. Article 28 of Regulation (EU) 2016/679 requires that relationship to be governed by a written legal act, and this document is that act. It is not a plain language summary of the privacy notice: it is the text that binds the two parties, that the controller can attach to its own record of processing activities and that a supervisory authority may ask to see. It sets out the subject matter, duration, nature and purpose of the processing, the types of data and the categories of data subjects, the instructions the controller may give and those that would be refused, the security measures actually active on the platform, the chain of sub-processors, the assistance owed to the controller, the deadlines for notifying a breach, the way an audit is exercised on a multi-tenant SaaS service, the basis for transfers to the United States and what happens to the data when the relationship ends. Every measure mentioned matches a configuration genuinely present in the Google Cloud project petdiary-10327, not a list of intentions.

Subject matter and scope of the agreement

This document governs the processing of personal data that Animiyo carries out on behalf of a tenant. Tenant means a veterinary clinic, a pet shop or service, or a breeder operating in a separate workspace of the platform, with its own staff and its own clients. Within that perimeter the tenant determines the purposes and means of the processing and is the controller; Animiyo provides the infrastructure, carries out the instructions received and is the processor within the meaning of Article 4 point 8 of Regulation (EU) 2016/679.

The agreement is concluded without a separate signature. It becomes binding the moment the tenant workspace is enabled and the terms published at /termini are accepted: from then on this text, in the version in force at the date shown at the top of the page, is the legal act required by Article 28 paragraph 3. A tenant needing a signed copy for its own documentation can request one from the /contatti page and receives the same text in a dated and signed document.

Identifying details of this version of the agreement
ItemValue
Version1.0
Effective from2 August 2026
Last updated2 August 2026
ProcessorThe entity operating Animiyo, identified on the /contatti page
ControllerThe tenant operating in its own workspace on the platform
ScopeWeb application on Cloud Run, native iOS application, shared backend in the Google Cloud project petdiary-10327
Related documents/privacy, /sub-responsabili, /diritti-privacy, /termini
Channel for communications/contatti

The agreement does not cover the processing in which Animiyo determines purposes and means itself, that is the accounts of pet owners using the platform for personal purposes: for those Animiyo is the controller and the applicable document is the notice at /privacy. Nor does it cover providers the tenant chooses on its own, which remain its responsibility as described at /sub-responsabili. The distinction matters because it determines who a data subject must address a request to and who answers before the supervisory authority.

Roles of the parties

Animiyo is a multi-tenant platform, so its role changes depending on the data in question, not on the moment. Two distinct processing operations can coexist around the same animal: the record an owner keeps for themselves, where Animiyo is the controller, and the clinical documentation a clinic writes in its own workspace, where the clinic is the controller. The table shows where the boundary runs, feature by feature, and should be read together with the matching table in the notice at /privacy, with which it coincides.

Animiyo's role by type of processing
ProcessingAnimiyo's roleControllerApplicable document
Clinical records and SOAP notes written by a clinicProcessorThe veterinary clinicThis agreement
Laboratory results and consents signed at the clinicProcessorThe veterinary clinicThis agreement
Appointment diary, appointment types and hospital staysProcessorThe tenant managing themThis agreement
Estimates, invoices, orders, subscriptions and loyalty schemesProcessorThe tenant issuing themThis agreement
Records of the tenant's clients and of the animals it treatsProcessorThe tenantThis agreement
Registration, sign in and management of an owner's accountControllerAnimiyoNotice at /privacy
An owner's pet profiles, reminders, walks and budgetControllerAnimiyoNotice at /privacy
Platform security, audit log, abuse preventionControllerAnimiyoNotice at /privacy
Measurement of the public site with Google Analytics 4ControllerAnimiyoNotice at /cookie

The two roles do not overlap and are not swapped for convenience. When Animiyo acts as processor it does not decide which data to collect or how long to keep it: it carries out the tenant's documented instructions and, if it goes beyond them, for that processing it is considered a controller under Article 28 paragraph 10, with every consequence that follows. When it acts as controller, by contrast, it answers directly for its own choices and cannot invoke anyone's instruction.

Downstream of Animiyo the chain continues. The providers listed at /sub-responsabili process data on behalf of Animiyo and, in the relationship with the tenant, are sub-processors authorised under Article 28 paragraphs 2 and 4. The chain is therefore linear and verifiable: the tenant is the controller, Animiyo is the processor, Google Ireland Limited with Google LLC is the sub-processor for the infrastructure services. No other link exists at the date of this agreement.

Subject matter, duration, nature and purpose of the processing

Article 28 paragraph 3 requires the legal act to state certain elements precisely, and in practice they are often relegated to a generic annex. Here they are written in the body of the document and tied to features genuinely present in the platform, because an abstract list lets the controller verify nothing.

Elements required by Article 28 paragraph 3
ElementContent for this agreement
Subject matterThe processing of personal data that the tenant enters, generates or receives using the professional features of the platform
DurationFrom the activation of the workspace until its closure, plus the return or deletion period described further down
NatureCollection, recording, organisation, structuring, storage, consultation, retrieval, disclosure to the recipients authorised by the controller, export, restriction and erasure
PurposeDelivering the features requested by the controller and safeguarding the security, integrity and continuity of the service
Types of personal dataThe categories listed in the section on data and data subjects
Categories of data subjectsThe tenant's clients, people they name as a contact, members of the tenant's staff
Obligations and rights of the controllerThose set out in Articles 24, 28, 32, 33, 34, 35 and 36 of the Regulation, recalled in the sections that follow

The purposes are not generic. Each corresponds to a part of the product the tenant enables or leaves disabled, and none involves any use of the data other than the one requested by the controller. In particular, no data processed on behalf of a tenant is used for Animiyo's own purposes, for commercial statistics, for profiling or to train artificial intelligence models.

  • Management of client records and of the animals treated, including the shares authorised by the owner.
  • Writing and keeping clinical documentation: SOAP notes, laboratory results, chronic conditions, hospital stays.
  • Recording vaccinations, drug therapies, deworming treatments and weight measurements.
  • Appointment diary, appointment types configured by the tenant and the related reminders.
  • Consent forms, signature capture and storage of signed consents.
  • Estimates, invoices, orders, subscriptions and loyalty schemes run by the tenant.
  • Conversations between the tenant's staff and clients inside the platform.
  • Platform security, audit log and prevention of automated abuse.
  • Export of the data at the request of the controller or of a data subject who addresses the controller.

One clarification about duration prevents a frequent misunderstanding. Processing does not end on the day the tenant stops using the platform, but on the day the return or deletion procedure described further down is completed. In the intervening period Animiyo continues to hold the data, restricting the processing to storage and to the operations needed to hand it over or erase it. That intervening period is not open ended: it has the deadlines set out in the section on the end of the relationship.

Types of personal data and categories of data subjects

The table lists the categories of data Animiyo processes on behalf of a tenant, with concrete examples and with the Firestore collections in which they reside. Naming the collections is not a superfluous technical detail: it lets the controller check that what is declared here matches what actually exists in the system, and lets it describe the processing in its own record with the same precision.

Categories of data processed on behalf of the tenant
Category of dataConcrete examplesWhere it residesData subject
Client identifiersName, email address, contact details, public username, tenant membership in the custom claims of the tokenCollections users, usernames, petMembershipsThe tenant's client
Records of the animals treatedName, species, breed, date of birth, sex, microchip number, weight, photographsCollections pets, weightRecords, petActivity and Cloud StorageThe animal's owner
Contacts linked to the animalEmergency contacts, referring veterinarian, people delegated to collect the animal or to decideCollection petContactsThe owner and the people named
Clinical documentationSOAP notes, laboratory results, chronic conditions, hospital staysCollections soapNotes, labResults, petConditions, hospitalizedThe animal's owner
Preventive care and therapiesVaccinations, medicines administered or prescribed, deworming treatments, veterinary appointmentsCollections vaccinations, medications, dewormingRecords, vetAppointments, appointmentTypesThe animal's owner
ConsentsConsent forms prepared by the tenant, signed consents and the captured signatureCollections consentForms, signedConsents and Cloud StorageWhoever signs the consent
Financial and commercial dataEstimates, invoices, orders, subscriptions, loyalty points, related expense itemsCollections estimates, invoices, orders, subscriptions, rewards, budgetItemsThe tenant's client
Communications and reviewsConversations between the tenant's staff and clients, reviews received by the tenantCollections conversations, reviewsWhoever writes and whoever is mentioned
Animal sharesAuthorisations by which an owner opens the record of their animal and the chosen subcollections to the tenantCollections petShares, petMembershipsThe animal's owner
Data about the tenant's staffOperator accounts, assigned role, permissions, author of every writeCollections users, tenants, auditLogThe member of staff
Technical and security dataApplication audit log, FCM notification tokens, App Check tokens, Cloud Run request logsCollection auditLog and the infrastructure provider's logsAnyone using the platform

Four categories of data subjects are involved and it is worth keeping them apart, because they have different expectations and rights and because the controller must inform all of them, not only its paying clients.

  • The tenant's clients, that is the owners of the animals treated by the clinic, the shop or the breeder.
  • The people named as a contact for an animal: family members, household members, delegates, referring veterinarian.
  • The members of the tenant's staff who access the platform with their own account and whose actions end up in the audit log.
  • Third parties occasionally mentioned in the free text of a note, a result, an estimate or a conversation.

The last category causes the most trouble and is also the least controllable by the processor. A free text field accepts whatever is typed into it, including data about people who have no relationship with the platform. Animiyo does not filter the content of professional notes, because filtering it would mean reading and assessing it, that is exceeding the instructions received. It is for the controller to instruct its own staff to write in free text fields only what is necessary and relevant, under the minimisation principle of Article 5 paragraph 1 point c.

Animal health data and owner data

The data held in an animal's health record is not data concerning health within the meaning of Article 9 of the Regulation. The reason is simple and admits no shortcuts: Article 9 protects special categories of personal data relating to a data subject, and a data subject is by definition a natural person. An animal is not one, so its clinical record does not trigger the prohibition in Article 9 paragraph 1 nor the search for a derogation among those in paragraph 2.

This does not make that data anonymous, which is the opposite and equally common error. A vaccination, a therapy, a hospital stay or a laboratory result is attributable to the owner identified by the account the animal is linked to: it describes their spending, their habits, their trips to a practice and, in many cases, their family situation. It therefore remains ordinary personal data of the owner and must be treated as such, with a legal basis, a notice, retention periods and fully applicable rights.

Classification of the information recurring in the platform
InformationLegal classificationWho needs the legal basis
Vaccination, therapy or procedure recorded for an animalOrdinary personal data of the owner, not Article 9 dataThe tenant, as a rule for the performance of the contract with its client
SOAP note written by the veterinarianOrdinary personal data of the owner, with professional content about the animalThe tenant, for professional and contractual obligations
Laboratory result relating to an animalOrdinary personal data of the ownerThe tenant, for professional and contractual obligations
Note that the animal is a guide dog or an assistance animalData concerning the health of the assisted person, Article 9The tenant, with explicit consent under Article 9 paragraph 2 point a
Reason for an appointment describing a condition of the ownerData concerning the health of the owner, Article 9The tenant, with explicit consent or by removing the information
Owner's allergy noted for the handling of a medicineData concerning the health of the owner, Article 9The tenant, with explicit consent and limited retention
Emergency contact details of a family member or delegateOrdinary personal data of a third partyThe tenant, providing the notice to that third party itself
Handwritten signature on a consent formOrdinary personal data with high identifying valueThe tenant, to meet its obligation to prove consent

The distinction has practical consequences in both directions. Downwards, it stops the controller from seeking explicit consent where a contract suffices, needlessly complicating data collection and making revocable a processing operation that is not. Upwards, it prevents an animal clinical record from being treated as irrelevant: if the tenant serves a large number of clients, the volume and the perceived sensitivity of that information weigh in the risk assessment even in the absence of Article 9.

Technically, Animiyo applies to this information the same safeguards used for special categories, regardless of its legal classification, because the potential harm from unauthorised access is comparable.

  • Access limited to the owner and to those they have explicitly authorised through a share.
  • Firestore and Cloud Storage security rules that check ownership of the document on every read and every write.
  • Separation between tenants, so that a clinic sees only the animals shared with it.
  • Recording of significant operations on clinical documentation in the application audit log.
  • Encryption in transit with TLS and at rest with AES at 256 bits.
  • No secondary use of any kind: no commercial statistics, no profiling, no model training.

One point remains for the controller to handle alone. Free text fields in clinical documentation can capture data about the health of natural persons, and in that case Article 9 applies in full. Animiyo cannot notice it, because it does not read the content of notes. The controller must therefore instruct its staff not to enter information about the health of the owner or of third parties when it is not necessary for the care of the animal, and to collect explicit consent when it is.

Documented instructions of the controller

Animiyo processes the tenant's data only on documented instructions from the controller, under Article 28 paragraph 3 point a. Documented does not necessarily mean written on paper: it means reconstructable, attributable to whoever gave the instruction and verifiable later. On a software platform most instructions are given by using the product, and this agreement acknowledges that explicitly instead of pretending that everything travels through an exchange of letters.

What counts as a documented instruction and what does not
ChannelCounts as an instructionNote
This agreement and the documents it refers toYesIt is the baseline instruction: it describes everything the platform does on behalf of the controller
Settings chosen in the tenant panelYesOperator roles and permissions, appointment types, consent forms, price lists, reminders
Operations performed by staff within the application featuresYesCreating, editing, sharing, exporting and deleting are instructions given through the interface and recorded in the audit log
Written request sent from the /contatti page by the tenant administratorYesIt is the channel for instructions the interface does not cover, for example an extraordinary extraction
Verbal or telephone messageNoIt must be confirmed in writing before being carried out, except during an ongoing security incident
Request from an address not linked to the administrator accountNoIt is refused and reported to the tenant administrator
Request from an operator lacking the necessary permissionsNoIt is refused: internal permissions are assigned by the tenant administrator, not by the processor
Request from a tenant's client addressed directly to AnimiyoNoIt is forwarded to the controller under the procedure set out in the section on assistance

Article 28 paragraph 3 closes with an obligation that runs in the opposite direction to all the others: the processor must immediately inform the controller if, in its opinion, an instruction infringes the Regulation or other Union or Member State data protection provisions. It is not a courtesy and it is the only case in which the processor is required to contradict the controller. Animiyo does so in writing, from the /contatti page to the email address of the tenant administrator, within five working days of receiving the instruction, and suspends execution of the contested part alone until it receives an answer.

The following instructions, by way of example and not exhaustively, would be reported and not carried out. They are realistic examples, drawn from features that genuinely exist in the platform, not textbook hypotheses.

  • Disabling the audit log of the tenant or altering entries already written.
  • Keeping a client's clinical documentation beyond the period set by the controller itself, without any further legal basis.
  • Disclosing a client's data to a third party not authorised by the controller or by law.
  • Accessing the data of a tenant other than the one giving the instruction, even for comparison or verification.
  • Using the contact details of the tenant's clients for bulk commercial messages without valid consent.
  • Reconstructing data erased at a data subject's request by drawing on backup copies.
  • Transferring data to a provider chosen by the tenant that does not offer the guarantees required by Article 28 paragraph 1.
  • Removing the separation between tenants to allow a cross search over the animals of other professionals.

If after the report the controller confirms the instruction in writing and the confirmation does not remove the unlawfulness identified, Animiyo does not carry it out and may terminate the relationship with the notice period set out in the terms at /termini. The report, the confirmation and the outcome are retained and made available to the controller on request, because they are the evidence of how each party behaved.

Confidentiality of personnel

Article 28 paragraph 3 point b requires that persons authorised to process the data have committed themselves to confidentiality or be under an appropriate statutory obligation of confidentiality. On Animiyo the number of people with access to production data is very small and coincides with those performing technical maintenance on the platform. Saying so is more useful than describing an organisation chart that does not exist: in a service of this size the main security measure is precisely that possible accesses are few and all traced.

  • A written confidentiality undertaking for anyone accessing production data, effective after the end of the relationship as well.
  • Administrative access granted on the principle of least privilege and withdrawn once the reason that justified it ceases.
  • Access to production data allowed only for maintenance, defect correction, handling of a security incident or a written request from the controller.
  • Multi-factor authentication mandatory on the Google Cloud console accounts of the petdiary-10327 project.
  • Recording of significant administrative operations in the application audit log and in the infrastructure provider's logs.
  • No third party customer support service with access to the data, as already declared at /sub-responsabili.
  • No use of production data in test environments: tests use synthetic data or the local emulator.

The controller may request at any time, from the /contatti page, the current list of administrative roles active on the project and confirmation that the confidentiality undertakings are signed. It does not receive the names of the individuals, which are themselves personal data of third parties, but it receives the number of active accesses, the type of privilege attached to each and the date of the last review. That is the information needed to assess the measure without creating a new processing operation.

Security measures under Article 32

The measures listed here are the ones actually implemented in the platform. The third column is what makes the table useful: it states how the controller can check the measure independently, without having to trust the declaration. A security measure that cannot be checked is an assertion, not a guarantee.

Active technical and organisational measures and how to verify them
MeasureWhere it appliesHow the controller can verify it
Firebase Authentication with email address verificationAccess to any account, on web and iOSAttempting to sign in with an unverified address
Access control by role and by tenant in the custom claims of the tokenEvery backend request and every restricted screenInspecting the operator token and testing with a reduced role
Firestore security rules written per collection and per roleEvery read and every write on the databaseAttempting to read a document belonging to another tenant, which is refused
Cloud Storage security rulesPhotographs, uploaded documents, consent signaturesAttempting to open a file not linked to one's own workspace
Separation of data between tenants, with no cross reading pathsAll collections carrying the tenant referenceSearching for an animal that has not been shared, which returns nothing
Firebase App Check with reCAPTCHA EnterpriseCalls coming from the browser and from the iOS applicationA request without a valid attestation token, which is refused
Encryption in transit with TLSAll connections to the site, to the backend and to Cloud StorageInspecting the certificate and the response headers
Encryption at rest with AES at 256 bitsCloud Firestore and Cloud Storage for FirebaseGoogle Cloud documentation on default encryption at rest
Application audit log in the auditLog collectionSignificant operations on data and settingsAn extract of the log limited to one's own tenant, requested from /contatti
Content security policy in enforcing modePages of the web applicationReading the response headers of the site
Backup and replication managed by Google CloudCloud Firestore and Cloud Storage for FirebaseProvider documentation on the services enabled for the project
Least privilege on administrative accountsConsole of the Google Cloud project petdiary-10327List of active roles and date of the last review, requested from /contatti

Article 32 paragraph 1 lists four categories of measure. The correspondence with the table above is set out below in full, so that the controller can copy it into its own record without having to reconstruct it.

  • Pseudonymisation and encryption, point a: encryption in transit with TLS and at rest with AES at 256 bits; pseudonymous technical identifiers in the security logs and in the measurement of the public site.
  • Confidentiality, integrity, availability and resilience, point b: security rules per collection, separation between tenants, role based control, App Check, managed services with the infrastructure provider's redundancy.
  • Timely restoration, point c: backup and replication managed by Google Cloud for Cloud Firestore and Cloud Storage, with a restore procedure documented by the provider.
  • Regular testing of effectiveness, point d: review of the measures at every release touching authentication, access rules or the data structure, with automated tests on the security rules.

Two things are not declared, and their absence is part of the information. Animiyo holds no certifications of its own: the available compliance reports are those Google publishes for the Google Cloud and Firebase services, and they concern the infrastructure, not the application. And no measure promises absolute security, which no system connected to a network can offer. The controller must take that into account in its own risk assessment, instead of treating the point as settled because the processor has listed it.

Sub-processors

By this agreement the controller grants Animiyo a general authorisation to engage sub-processors, under Article 28 paragraph 4 of Regulation (EU) 2016/679. A general authorisation is the only workable option in a SaaS service, because the infrastructure is shared by every tenant and a specific authorisation for each would make any maintenance impossible. It is not, however, a blank cheque: the controller keeps the right to know in advance what changes, to object and to terminate.

The authoritative and continuously updated list of sub-processors is published at /sub-responsabili, which states for each provider the service, the categories of data, the processing location and the transfer basis. At the date this agreement takes effect the chain is composed as follows.

  • Google Ireland Limited, with Google LLC as further sub-processor, for Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase, Cloud Functions, Cloud Run, Firebase Cloud Messaging, Firebase App Check with reCAPTCHA Enterprise and Google Analytics 4.
  • Stripe Payments Europe Limited for payment processing: the integration exists in the code but the gateway is switched off by a configuration flag, so at the date of this agreement it receives no data.

The external data sources queried directly by the user's browser are not sub-processors: openFDA, Open Pet Food Facts, dog.ceo, Wikipedia, iNaturalist, frankfurter.app and tile.openstreetmap.org. Those calls only read data, they carry neither account identifiers nor diary content and they are not made on Animiyo's instructions as to the use of the data collected. In relation to the connection data they receive, in particular the browser IP address, those services are independent controllers. The controller must take this into account in its own privacy notice if it enables the features that use them.

  1. Publication of the notice

    At least thirty days before adding or replacing a sub-processor, the change is published at /sub-responsabili stating the provider, the service, the data involved and the planned activation date.

  2. Message to the controller

    At the same time as publication the notice is sent to the email address the tenant has entered in its profile. Keeping that address up to date and monitored is a duty of the controller, because that is where the notice takes effect.

  3. Reasoned objection

    The controller may object within fifteen days of the notice, writing from the /contatti page. The objection must be reasoned, that is it must state which concrete risk or which legal constraint makes the proposed provider unacceptable.

  4. Search for an alternative measure

    Before the activation date the parties check whether the objection can be resolved by a different configuration, a different processing region, a reduction of the data transmitted or a different provider for that function.

  5. Termination without penalty

    If the objection cannot be resolved, the controller may terminate without penalty the part of the service affected by the change, with the right to have the data returned under the procedure described in the section on the end of the relationship.

Deadlines of the sub-processor procedure
StageDeadlineChannel
Publication of the noticeAt least thirty days before the changeThe /sub-responsabili page
Message to the controllerAt the same time as publicationEmail address entered by the tenant in the profile
Reasoned objectionWithin fifteen days of the noticeThe /contatti page
Proposal of alternative measuresBefore the activation dateEmail address entered by the tenant in the profile
Termination without penaltyIf the objection cannot be resolved by alternative measuresThe /contatti page
Urgent replacement on security groundsShortened notice, with immediate communication and objection afterwardsThe /sub-responsabili page and the tenant's email address

On each sub-processor Animiyo imposes by contract data protection obligations no less onerous than those assumed under this agreement, as Article 28 paragraph 4 requires. The same provision states that, where the sub-processor fails to fulfil them, the processor remains fully liable to the controller for the performance of those obligations. This means the controller does not have to chase Google Ireland Limited over an infrastructure failure: it turns to Animiyo, which answers and then seeks redress downstream. The criteria by which a provider is admitted or excluded are described at /sub-responsabili and include an absolute ban on clauses allowing the provider to use the data for its own purposes.

Assistance to the controller

The processor must assist the controller with a set of duties that remain the controller's own but that, in practice, need information or tools only the processor has. The table states each obligation, the provision that sets it out, the concrete way it is met and the deadline within which the controller receives an answer.

Assistance obligations and response deadlines
ObligationReferenceHow it is metDeadline
Assistance with data subject requestsArticle 28 paragraph 3 point eExport and deletion tools available in the application, forwarding to the controller of requests received in error, extraordinary extractions on written requestForwarding within five working days, technical assistance within ten working days
Assistance with the security of processingArticle 28 paragraph 3 point f and Article 32Up to date description of the active measures and answers to the controller's security questionnairesWithin thirty days of the request
Assistance with breach notificationArticle 28 paragraph 3 point f, Articles 33 and 34Communication with the minimum content set out in the dedicated section and support in drafting the notification to the authorityFirst alert within twenty four hours of becoming aware
Assistance with the impact assessmentArticle 28 paragraph 3 point f and Article 35Description of the data flows, the categories of data, the sub-processors, the measures and the known risksWithin thirty days of the request
Assistance with prior consultationArticle 28 paragraph 3 point f and Article 36Technical documentation to attach to the request addressed to the supervisory authority and answers to any of its questionsWithin thirty days of the request
Information to demonstrate complianceArticle 28 paragraph 3 point hThis agreement, the list at /sub-responsabili, the description of the measures, the audit log extract for one's own tenantWithin thirty days of the request
Contribution to the processor's record of processingArticle 30 paragraph 2List of the categories of processing carried out on behalf of the controller, made available on requestWithin thirty days of the request

On data subject rights the rule is clear cut: Animiyo does not answer on the merits on behalf of the controller. If a clinic's client asks Animiyo for access to or erasure of their clinical data, the request is forwarded to the competent controller within five working days and the data subject is told it has been forwarded, with the name of the party to address. The full procedure, with response times, identity checks and the tools available directly in the application, is described at /diritti-privacy. The controller remains free to handle the request with its own tools; Animiyo provides the technical extractions it needs.

On the data protection impact assessment the division is equally clear. Deciding whether a DPIA is needed and carrying it out is a duty of the controller, which knows the context, the volume of its clients and the actual purposes. Animiyo supplies the technical raw material and flags the features that, from experience, deserve attention in the assessment. The list below does not replace the controller's own analysis, but it shows where the risk concentrates.

  • Location data from walks, shared routes and group walks, which can reveal habits and frequented places.
  • The public lost tag page, reachable by anyone holding the link even without an account.
  • Sharing an animal between owner and tenant, which opens access to the selected health subcollections.
  • Symptom triage, which produces an indicative suggestion and not a diagnosis, described at /privacy in the section on automated decisions.
  • Large scale processing of clinical documentation, where the tenant serves a large number of clients.
  • Transfer of the data to the us-central1 region, described in the section on transfers.
  • Processing of data relating to minors, where a tenant's client is a minor or where data about minors appears in free text fields.

If, following the assessment, the controller must consult the supervisory authority in advance under Article 36, Animiyo provides the necessary technical documentation and answers any questions the authority puts through the controller. Assistance is provided at no additional cost within the limits shown in the table; requests that manifestly exceed those limits, in frequency or in scope, are subject to reimbursement of documented costs, notified in advance and accepted in writing before the work begins.

Personal data breach

A personal data breach means what Article 4 point 12 of the Regulation defines: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed. It therefore also covers cases where nobody has stolen anything, for example data loss through a technical fault or prolonged unavailability of a service. The processor does not decide whether the breach must be notified to the authority: that assessment belongs to the controller, and what matters is that everything needed to make it reaches the controller quickly.

  1. Detection and qualification

    Every internal report, every anomaly spotted in the audit log and every communication received from the infrastructure provider is qualified immediately: we establish whether it is a breach within the meaning of Article 4 point 12 and which tenants are affected.

  2. First alert within twenty four hours

    Within twenty four hours of Animiyo becoming aware of the breach, the affected controller receives a first alert at the email address in its profile, with what is already known and with an explicit statement of what is still being established.

  3. Update within seventy two hours

    Within seventy two hours the controller receives the communication with the minimum content set out in the table below, that is the elements it needs to decide whether to notify the supervisory authority and whether to communicate the breach to the data subjects.

  4. Final report within fifteen days

    Within fifteen days of becoming aware the controller receives the closing report: reconstruction of what happened, causes, data actually affected, corrective measures taken and preventive measures introduced to stop it happening again.

  5. Support with notification and communication

    At the controller's request, Animiyo supplies the technical elements to attach to the notification to the authority under Article 33 and to the communication to data subjects under Article 34, and answers the authority's follow up questions through the controller.

Minimum content of the communication to the controller
ElementWhat it contains
Date and timeWhen the breach occurred, where this can be reconstructed, and the exact moment the processor became aware of it
Nature of the breachLoss of confidentiality, integrity or availability, with a description of how it came about
Data involvedCategories of data and collections affected, identifying the documents attributable to the controller's workspace
Data subjects involvedCategories and approximate number of data subjects and of records affected
Likely consequencesTechnical assessment of the risk to the rights and freedoms of data subjects, with the scenarios considered
Measures takenContainment steps already carried out, planned steps and expected timing
Encryption statusWhether the data involved was encrypted and whether the keys remained intact, a decisive element in assessing the risk
Point of contactReference at the processor for follow up, reachable from the /contatti page

Notification to the supervisory authority within seventy two hours under Article 33 is an obligation of the controller and Animiyo does not carry it out in its place, save under a specific written mandate for the individual event. The reason is not formal: notifying on the controller's behalf would mean qualifying the risk using information only the controller holds, such as the real number of its clients, their vulnerability and the context in which the data was collected. The twenty four hour deadline for the first alert is calibrated precisely to leave the controller time to act within its own seventy two hours.

Where the breach concerns data for which Animiyo is the controller, for example owner accounts or the platform audit log, notification to the authority and communication to data subjects fall on Animiyo as described at /privacy. An incident affecting the shared infrastructure normally produces both effects: Animiyo notifies for the part where it is the controller and informs tenants for the part where it is the processor, keeping the two communications separate to avoid confusion about roles.

Deletion or return of the data

At the end of the relationship the controller chooses between return and deletion of the data, under Article 28 paragraph 3 point g. The choice is the controller's and not the processor's, and must be communicated in writing from the /contatti page. In the absence of an express choice within the deadlines set out below, the data is deleted: that is the default outcome because keeping data with no instruction and no legal basis would be the riskiest option for the data subjects.

  1. End of the relationship

    The relationship ends through termination by either party, through expiry or withdrawal of the professional licence, through closure of the workspace or through exercise of the right to terminate after an objection to a sub-processor.

  2. Thirty day export window

    Thirty days run from the end of the relationship, during which the workspace remains accessible in read only mode and all export tools stay active. Within that window the controller can download whatever it needs without asking anyone.

  3. Choice between return and deletion

    Within the same thirty day window the controller states whether it wants an assisted handover of the data or whether deletion may proceed. The assisted handover also covers content that the in application tools do not export.

  4. Deletion from live systems

    At the end of the window, or earlier if the controller asks, the data is deleted from live systems within thirty days. Deletion covers Cloud Firestore and Cloud Storage and includes photographs, uploaded documents and consent signatures.

  5. Written confirmation

    Once deletion is complete the controller receives written confirmation stating the date of the operation, the collections affected and any data retained under a legal obligation, with the relevant legal basis.

Available export formats
ContentFormatHow to obtain it
User profile, animals and their subcollections, animal contacts, budget configuration, expense items and goalsJSON archive with a versioned schema and dates normalised to ISO 8601Data export from the application
Full record of an animal with vaccinations, medicines, visits, appointments, weight measurements and expensesCSV file with comma separator and UTF-8 encodingExport from the animal record
Readable report of an animal recordPDF document generated by the browser from the reportPrinting the report from the animal record
Budget with movements, categories, limits and goalsCSV file and PDF documentExport from the budget section
Photographs, uploaded documents and consent signaturesFiles in the original formats held on Cloud StorageDownload from the record they are attached to
Audit log extract for one's own tenantJSON fileWritten request from the /contatti page
Content not covered by the in application toolsPurpose built JSON archive using the same versioned schemaAssisted handover requested within the thirty day window

Backup copies need a clarification that many agreements leave out. The backup copies and replicas managed by Google Cloud do not allow selective deletion of a single document: they remain until the rotation cycle configured on the project overtakes them, and they are never used to restore data deleted on request. The rotation window currently configured is disclosed to the controller on request from the /contatti page, together with the expected date on which the copies containing its data will be overtaken. Declaring instant deletion from backups too would be more reassuring and less true.

Data that the processor is required to retain under Union or Member State law is excluded from deletion, a case expressly preserved by Article 28 paragraph 3 point g. At the date of this agreement the main case concerns tax records, which will become relevant once payments are active and which civil and tax law requires to be kept for ten years. In those cases processing is restricted to storage alone, with no consultation or further use, and the deletion confirmation says so explicitly.

Audits and inspections

Article 28 paragraph 3 point h gives the controller the right to contribute to audits, including inspections. The clause was written with a processor that has a machine room to visit, and on a multi-tenant SaaS service that picture does not work: Animiyo owns no data centres, the infrastructure is shared by all tenants, and any access granted to one controller would risk exposing the data of the others. The right to audit remains intact, but it is exercised through tools other than a site visit, listed here so the controller knows in advance what it can obtain.

Verification tools available to the controller
ToolWhat the controller obtainsFrequency and deadlineCost
Permanent documentationThis agreement, the list at /sub-responsabili, the notice at /privacy, the description of the active security measuresAlways available and publicNone
Written security questionnaireA specific answer on the measures, the provider chain, the data flows and the processing regionsOnce a year, answer within thirty daysNone
Audit log extractThe operations recorded in the auditLog collection concerning its own tenant, in JSON formatOn request, delivered within thirty daysNone
Remote verification sessionGuided review of the configuration of its own workspace: roles, permissions, active shares, applicable rules, available exportsOnce a year, with thirty days noticeNone
Providers' compliance reportsThe reports Google publishes for the Google Cloud and Firebase services used by the platformAlways available from the providerNone
Extraordinary verificationFurther checks beyond the annual frequency, for example after a breach or a request from the supervisory authorityWith thirty days notice, shortened in urgent casesReimbursement of documented costs
Penetration testingTechnical checks on the exposed interfaces, limited to the controller's workspace and to test dataWindow agreed in writing, with thirty days noticeBorne by the controller

Some things the controller cannot obtain, and it is worth writing them down before they are asked for in a tense moment. These are not limits set for the processor's convenience: each protects an interest the controller itself shares, since other tenants hold the same expectations about their own data that it holds about its own.

  • Access to the data, documents or logs of a tenant other than its own, not even in partial or aggregated form.
  • Direct access to the administration console of the Google Cloud project petdiary-10327.
  • A full copy of the source code or of the complete security rules, which also describe the other tenants.
  • Destructive tests, load tests or denial of service attacks, which would degrade the service for everyone.
  • Physical inspections at the data centres, which belong to the infrastructure provider and not to the processor.
  • Bulk extraction of production data for verification purposes, which would increase the risk rather than reduce it.
  • Access to security logs in the part concerning operators or clients of other tenants.

If the controller considers the tools listed above insufficient for a specific case, it may propose an alternative approach from the /contatti page, stating which particular aspect it intends to verify. The parties then look for a solution that achieves the purpose without exposing third party data, for example a guided demonstration on a test environment or a technical statement on a narrow point. A request is not refused for being unusual, but only if there is no way to satisfy it without affecting the rights of other data subjects.

Transfers outside the European Economic Area

The main resources of the platform sit in the us-central1 region, in the United States. The data the tenant processes about its own clients is therefore processed outside the European Economic Area, and the controller must know this before signing the agreement rather than after. The transfer rests on a valid legal basis and on adequate technical measures, described here and more fully at /sub-responsabili.

Processing region and transfer basis
ServiceRegionTransfer basis
Firebase Authenticationus-central1 (United States)Standard contractual clauses 2021/914 and EU United States Data Privacy Framework
Cloud Firestoreus-central1 (United States)Standard contractual clauses 2021/914 and EU United States Data Privacy Framework
Cloud Storage for Firebaseus-central1 (United States)Standard contractual clauses 2021/914 and EU United States Data Privacy Framework
Cloud Functionsus-central1 (United States)Standard contractual clauses 2021/914 and EU United States Data Privacy Framework
Cloud Runus-central1 (United States)Standard contractual clauses 2021/914 and EU United States Data Privacy Framework
Firebase Cloud Messaging, Firebase App Check with reCAPTCHA Enterprise, Google Analytics 4Global infrastructureStandard contractual clauses 2021/914 and EU United States Data Privacy Framework
Stripe payment processingEuropean UnionNo transfer to third countries; service not active

The applicable standard contractual clauses are those adopted by the European Commission with implementing decision (EU) 2021/914. In the relationship between Animiyo and Google Ireland Limited module three applies, from processor to sub-processor, which is the correct module when the exporter is itself acting on behalf of a controller. The tenant controller remains the original controller in the chain and keeps the rights the clauses grant to the party on whose behalf the transfer takes place, including the right to obtain a copy of the applicable clauses.

  • Google Ireland Limited as contracting counterparty, under the Google Cloud Data Processing Terms.
  • Standard contractual clauses adopted with implementing decision (EU) 2021/914, module three.
  • Certification of Google LLC under the EU United States Data Privacy Framework.
  • Encryption of data in transit with TLS and at rest with AES at 256 bits.
  • A transfer impact assessment documented by the project owner and made available to the tenant on request.
  • Google's policy on handling requests from public authorities, together with the related transparency reports.
  • An undertaking to inform the controller of any access request received from a third country authority, unless prohibited by law, and to challenge it where manifestly unlawful.

The transfer impact assessment considers the nature of the data involved, which in the vast majority of cases is not a special category relating to natural persons, the effectiveness of encryption in transit and at rest, the provider's documented practice in handling requests from public authorities, the remedies available to data subjects and the concrete likelihood that veterinary data about European clients becomes the object of an access request. The controller can obtain a copy from the /contatti page and must supplement it with an assessment of its own context, which only it knows.

Migrating the resources to a European region, in the europe-west area, is under consideration but is not a settled decision, because it means rebuilding part of the infrastructure and accepting a window of service unavailability. If it happens, it will be announced at /sub-responsabili with the same thirty day notice period set for sub-processor changes, so that controllers can update their own documentation before the change takes effect.

Liability, precedence and applicable law

Article 82 of the Regulation provides that a processor is liable for the damage caused by processing only where it has not complied with obligations specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller. Outside those two cases liability stays with the controller, which decided the purposes and means. The table translates the principle into the situations that genuinely arise on this platform.

Allocation of liability in typical situations
SituationWho is liableWhy
The controller gives an unlawful instruction and the processor carries it out after reporting it in writingThe controllerThe instruction is its own choice and it received the warning required by Article 28 paragraph 3
The processor handles the data outside the documented instructionsThe processorFor that processing it is considered a controller under Article 28 paragraph 10
A sub-processor fails to meet its data protection obligationsThe processor towards the controller, with redress against the sub-processorArticle 28 paragraph 4, final sentence
The controller does not inform its data subjects or lacks a valid legal basisThe controllerThese are obligations placed on the controller by Articles 6, 13 and 24
An operator of the tenant shares data with someone not entitled to itThe controllerManaging members, roles and internal permissions belongs to the tenant
A security measure described in this agreement turns out to be absent or ineffectiveThe processorArticle 32 places the security obligation on the processor as well
The controller connects one of its own external providers and exports data to itThe controllerThat is processing outside the scope of this agreement, as stated at /sub-responsabili

The limitations of liability set out in the terms published at /termini apply to this agreement as well, with two exceptions that cannot be waived: damage caused by wilful misconduct or gross negligence, and liability towards the data subject under Article 82, which the Regulation does not allow to be limited by contract. Where one party pays full compensation for the damage suffered by a data subject, it is entitled to claim back from the other the share corresponding to that party's responsibility, under Article 82 paragraph 5.

In the event of a conflict between the documents governing the relationship, the order of precedence set out at /termini applies, recalled here for the part concerning data processing.

  1. Any particular conditions agreed in writing with a tenant, which prevail in the relationship with that tenant alone.
  2. This agreement and the list of sub-processors at /sub-responsabili, for everything concerning the processing carried out on behalf of the controller.
  3. The terms published at /termini, which govern the use of the platform by every user.
  4. The notice at /privacy and the cookie notice at /cookie, which describe the processing where Animiyo is the controller and prevail on that point.

The agreement is governed by Italian law and by Regulation (EU) 2016/679, supplemented by legislative decree 196/2003 as amended by legislative decree 101/2018. Since the tenant acts in the course of its professional activity, disputes concerning this agreement fall within the exclusive jurisdiction of the court of the provider's registered office indicated on the /contatti page, consistently with what /termini provides for professional users. This does not affect the right of a data subject to bring proceedings before the court of their habitual residence under Article 79 of the Regulation, nor the right to lodge a complaint with a supervisory authority. The Italian and English versions have the same content; in the event of a difference of interpretation the Italian text prevails.

Changes to the agreement and version history

This agreement can change, because the platform features, the providers and the legal framework change. Substantive changes do not take effect by surprise: they follow the same notice, objection and termination mechanism set for sub-processors, because a change to the agreement affects the relationship as much as, and more than, a change of provider.

Types of change, communication and notice
Type of changeHow it is communicatedNotice
Substantive change to the obligations of the partiesPublication on this page and message to the tenant's email addressAt least thirty days
Addition or replacement of a sub-processorPublication at /sub-responsabili and message to the tenant's email addressAt least thirty days
Change of the processing regionPublication on this page and at /sub-responsabili, with a message to the tenantAt least thirty days
Change imposed by a legal rule or by a decision of an authorityImmediate communication stating the source of the obligationThe minimum compatible with the obligation
Introduction of an additional security measureUpdate of the measures table and an entry in the change logNone, it does not reduce protections
Editorial correction with no substantive effectUpdate of the date at the top of the pageNone

Faced with a substantive change the controller may object within fifteen days of the notice, writing from the /contatti page. If the objection cannot be resolved by alternative measures, it may terminate without penalty with the right to have the data returned under the procedure described above. Silence beyond fifteen days counts as acceptance, and that effect is stated here explicitly so the controller is aware of it before the period starts to run.

Version history of this agreement
DateVersionChange
2 August 20261.0Initial publication: subject matter and duration, roles of the parties, data and data subjects, documented instructions, confidentiality, security measures, sub-processors, assistance to the controller, breaches, end of the relationship, audits, transfers, liability and applicable law.

Later revisions are added to this table and are tracked in the version control history of the code, which preserves the exact text of every version together with the date of the change. A controller needing to reconstruct which agreement was in force at a given moment, for example in response to a request from a supervisory authority, can obtain that version from the /contatti page.

Frequently asked questions

Do I have to sign a separate contract or is this page enough?
This page is enough. The agreement becomes binding when the tenant workspace is enabled and the terms at /termini are accepted: from then on this text, in the version in force at the date shown at the top of the page, is the legal act required by Article 28 paragraph 3 of Regulation (EU) 2016/679. If your practice needs a signed copy to keep alongside its record of processing activities, you can request one from the /contatti page and receive the same text in a dated and signed document.
Is the health data of the animals I treat a special category under Article 9?
No, and the reason is that Article 9 protects data relating to a natural person, while an animal is not a data subject. It does remain ordinary personal data of the owner, because it is attributable to the account the animal is linked to, so it needs a legal basis, a notice and retention periods. Article 9 comes back into play when a free text field contains information about a person's health, for example a note that the animal is a guide dog or an appointment reason describing a condition of the owner: in those cases explicit consent is required, and collecting it is for you as controller.
Can I audit Animiyo and what do I actually get?
Yes, using the tools described in the section on audits. You get the permanent documentation, a written answer to your security questionnaire once a year within thirty days, an audit log extract limited to your tenant, a remote verification session on the configuration of your workspace and the compliance reports Google publishes for the services the platform uses. You do not get access to other tenants' data, to the Google Cloud project console, to the complete source code or to the data centres, which belong to the infrastructure provider. Penetration testing limited to your workspace is possible in a window agreed in writing with thirty days notice.
If I close my workspace, is the data returned to me or deleted?
You choose. From the end of the relationship you have thirty days during which the workspace stays accessible in read only mode and the export tools remain active: JSON archive with a versioned schema and ISO 8601 dates, CSV files for each animal record and for the budget, PDF documents of the reports, attachments in their original formats from Cloud Storage. Within the same window you state whether you want an assisted handover for what the tools do not cover. At the end of the window the data is deleted from live systems within thirty days and you receive written confirmation. The backup copies managed by Google Cloud cannot be deleted selectively, they remain until the rotation cycle overtakes them and they are never used to restore deleted data.
How quickly do you tell me if there is a data breach?
The first alert reaches you within twenty four hours of the moment we become aware of the breach, at the email address in your profile. Within seventy two hours you receive the communication with the minimum content set out in the agreement: nature of the breach, data and collections involved, categories and approximate number of data subjects, likely consequences, measures taken, encryption status and point of contact. Within fifteen days you receive the closing report. Notification to the supervisory authority within seventy two hours remains your obligation as controller, and our deadlines are calibrated to leave you the time for it.
Can I object if you change a provider that processes my clients' data?
Yes. Under this agreement you grant a general authorisation pursuant to Article 28 paragraph 4, but you keep the right to know in advance what changes. Every addition or replacement of a sub-processor is published at /sub-responsabili at least thirty days beforehand and is sent to the email address in your profile. You may raise a reasoned objection within fifteen days from the /contatti page and, if it cannot be resolved by alternative measures such as a different configuration or a different provider, you may terminate without penalty the part of the service affected, with the right to have the data returned.

In short

Save this agreement alongside your record of processing activities: it is the document that shows on what basis you process your clients' data on the platform. Check three things straight away: that the email address in your profile is monitored, because that is where sub-processor notices and breach communications arrive; that your own notice to clients declares the transfer to the us-central1 region; and that your staff are instructed not to write data about the health of natural persons in free text fields when it is not needed for the care of the animal. Objections, security questionnaires, audit log extracts and a signed copy of the agreement all go through the /contatti page.

Data processing agreement · Animiyo