Privacy notice
How Animiyo processes data for owners, clinics and shops: purposes, legal bases, retention, transfers to the United States and your rights.
- Effective from
- August 2, 2026
- Last updated
- August 2, 2026
- Version
- 1.0
Animiyo is a platform for managing companion animals, available as a web application and as a native iOS application sharing the same Firebase backend. Three kinds of user coexist on the platform, pet owners, veterinary clinics and shops or services, and the rules that govern data processing differ for each of them. This notice explains which data we collect when you use Animiyo as an owner, on which legal bases we process them, who receives them, where they are stored and for how long. It also describes the cases where Animiyo does not decide the purposes of processing but acts on behalf of a clinic or a shop, and points to the document that governs those relationships. Every section refers to concrete features of the application, so you can tell which processing starts when you use a given part of the product.
Data controller and contact details
The data controller is the party that operates Animiyo, the platform available as a web application hosted on Google Cloud Run and as a native iOS application, both relying on the same Firebase backend in the Google Cloud project petdiary-10327. The controller decides the purposes and means of processing for everything that concerns pet owner accounts: registration, authentication, pet profiles, reminders, budget, walks, uploaded documents and interface preferences.
For any request concerning personal data you can use the Contacts page of the website, at the path /contatti. Requests concerning the exercise of your rights follow the procedure described in /diritti-privacy, which also lists the tools available directly in the application to export or delete your data without waiting for a reply from us.
No data protection officer has been appointed because the conditions set out in Article 37 of the regulation are not met: the processing is not carried out by a public authority or body, it does not consist of regular and systematic monitoring of data subjects on a large scale, and its core activity is not the large scale processing of special categories of data. The assessment is repeated whenever the service is extended and, should the outcome change, the appointment will be published in this section.
Scope and dual role
Animiyo is a multi-tenant platform: veterinary clinics, shops and services work in separate spaces, with their own staff and their own clients. This is why the role of Animiyo is not always the same. On the data of an owner account Animiyo is the controller and answers directly. On the data that a clinic or a shop enters about its own clients through the platform Animiyo is instead a processor: the controller is the tenant and the relationship is governed by the agreement published in /dpa.
| Activity | Animiyo role | Controller | Applicable document |
|---|---|---|---|
| Registration, sign in and management of an owner account | Controller | Animiyo | This notice |
| Pet profiles, health record, reminders | Controller | Animiyo | This notice |
| Walks, budget and documents uploaded by the owner | Controller | Animiyo | This notice |
| Reviews, memories and notes written by the owner | Controller | Animiyo | This notice |
| Platform security and audit log | Controller | Animiyo | This notice |
| Clinical records and SOAP notes written by a clinic | Processor | The veterinary clinic | Processing agreement in /dpa |
| Laboratory results and consents signed at the clinic | Processor | The veterinary clinic | Processing agreement in /dpa |
| Estimates, invoices and the tenant appointment schedule | Processor | The tenant that issues them | Processing agreement in /dpa |
| Orders and loyalty programmes of a shop or service | Processor | The shop or service | Processing agreement in /dpa |
The distinction is not merely formal. When Animiyo acts as a processor it does not decide which data to collect or how long to keep them, but follows the documented instructions of the tenant. If you want to exercise a right over data entered by a clinic or a shop, the request must be addressed to that party; if you send it to us, we provide the technical assistance needed and forward it to the competent controller, telling you that we have done so.
Categories of data processed
The list below is not a generic formula: it reports the categories actually present in the system, with examples drawn from the data structures of the application. The Source column shows where the information comes from, because that changes both the legal basis and the way you can act on it.
| Category | Concrete examples | Source |
|---|---|---|
| Account identifiers | Firebase uid, email address, display name, public username chosen by you, role and tenant membership in the token custom claims | Provided by the user and generated by use |
| Pet identity data | Name, species, breed, date of birth, sex, microchip number, weight, photographs | Provided by the user |
| Uploaded documents | Certificates, forms and other files stored on Cloud Storage together with photographs | Provided by the user |
| Animal health data | Vaccinations, medications and treatments, deworming, visits, appointments, chronic conditions, hospital stays, symptom triage outcomes | Provided by the user or entered by a professional |
| Professional clinical documentation | SOAP notes, laboratory results, consent forms and signed consents | Entered by a professional |
| Location data | GPS tracks of walks, saved and shared routes, group walks, sightings, public lost pet tag page | Generated by use |
| Financial data | Expenses, budgets, saving goals, orders, subscriptions, loyalty points, estimates and invoices issued by tenants | Provided by the user or entered by a professional |
| Generated content | Conversations between users and professionals, reviews, memories and notes | Provided by the user |
| Technical and security data | Application audit log, FCM notification tokens, App Check tokens, interface preferences | Generated by use |
| Usage data | Pseudonymous Google Analytics 4 statistics on pages viewed and features used | Generated by use |
| Supporting descriptive information | Reference entries on breeds, species and active substances shown next to your data | Derived from public sources |
Technically the data live in the Firestore collections users, usernames, pets, petContacts, petShares, petSightings, petMemberships, petConditions, petActivity, petMemories, foundTags, vaccinations, medications, dewormingRecords, weightRecords, labResults, soapNotes, vetAppointments, appointmentTypes, hospitalized, consentForms, signedConsents, estimates, invoices, orders, subscriptions, rewards, reviews, resources, walks, routes, routeShares, groupWalks, conversations, budgetItems, budgetGoals, budgetConfigurations, tenants and auditLog. Photographs, uploaded documents and consent signatures are stored on Cloud Storage. We publish the list because it makes it possible to check that what is declared here matches what actually exists in the system.
Purposes, legal bases, retention and recipients
This is the central section of the document. The two tables connect each purpose to the categories of data used, to the legal basis, to the retention period and to the recipients. The first covers the processing needed to provide the service you asked for; the second covers processing based on consent, on legitimate interest or on a legal obligation.
| Purpose | Categories of data | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Creating and managing the account | Identifiers, email address, username, role and tenant membership | Performance of the contract (Article 6 paragraph 1 letter b) | For the duration of the relationship and up to thirty days from the deletion request | Google as infrastructure provider |
| Pet profiles and health record | Pet identity and health data, uploaded documents, photographs | Performance of the contract (Article 6 paragraph 1 letter b) | For the duration of the relationship, then thirty days from the deletion request | Google; the tenants and users you share the pet with |
| Appointments and communication with clinics | Pet data, appointment data, messages exchanged | Performance of the contract (Article 6 paragraph 1 letter b) | For the duration of the relationship; conversations no longer than twenty four months from the last message | Google; the clinic you choose |
| Budget, expenses and saving goals | Financial data, currency, budget configuration | Performance of the contract (Article 6 paragraph 1 letter b) | For the duration of the relationship, then thirty days from the deletion request | |
| Orders, loyalty points and subscriptions | Financial data, identifiers, shop or service data | Performance of the contract (Article 6 paragraph 1 letter b) | For the duration of the relationship; tax documents ten years once payments are active | Google; the shop or service handling the order |
| Chat with professionals and reviews | Generated content, identifiers, public username | Performance of the contract (Article 6 paragraph 1 letter b) | Conversations no longer than twenty four months from the last message; reviews until you delete them | Google; the receiving professional; the public for reviews |
| Support and replies to data subject requests | Identifiers, content of the request, attached documents | Performance of the contract (Article 6 paragraph 1 letter b) and legal obligation (Article 6 paragraph 1 letter c) | Until the request is closed and for as long as needed to document its outcome |
| Purpose | Categories of data | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Reminders and push notifications | FCM notification token, reminder content, identifiers | Consent (Article 6 paragraph 1 letter a) | Token until the permission is withdrawn or the application is uninstalled | Google through Firebase Cloud Messaging |
| Walks and GPS tracks | Precise location during the walk, route, duration, distance | Consent (Article 6 paragraph 1 letter a) | Until you delete the track; shared visibility ends when sharing is revoked | Google; the users you share a route or a group walk with |
| Lost pet tag and sightings | Pet data you choose to publish, sighting location, contact details | Consent (Article 6 paragraph 1 letter a) | Until you switch off the public tag page | Google; anyone who opens the public link |
| Security, abuse prevention and audit log | App Check token, browser antifraud signals, audit log events, identifiers | Legitimate interest (Article 6 paragraph 1 letter f) | Audit log twenty four months | Google; reCAPTCHA Enterprise |
| Usage statistics | Pseudonymous usage data, event, page, device type | Consent (Article 6 paragraph 1 letter a) | Fourteen months | Google Analytics 4 |
| Service improvement and fault diagnosis | Technical data, interface preferences, aggregated error indicators | Legitimate interest (Article 6 paragraph 1 letter f) | For the duration of the relationship | |
| Tax and accounting obligations and replies to authority requests | Financial data, identifiers, tax documents | Legal obligation (Article 6 paragraph 1 letter c) | Ten years for tax documents, once payments are active | Google; the competent authorities making a lawful request |
| Information about your own health entered voluntarily | Free text in notes, memories, conditions and messages | Explicit consent (Article 9 paragraph 2 letter a) | Until you delete the content | Google; the parties you shared that content with |
Consent can always be withdrawn and withdrawal does not affect the lawfulness of processing carried out before. You can remove the notification and location permissions from your device settings, switch off statistics from the panel described in /cookie, and turn off the public lost pet tag page from the pet record. Where processing rests on legitimate interest we have verified that our interest in keeping the service secure and working does not override your rights, because the data used are limited to technical ones, retention is short and no decision about you follows from them; you can still object under Article 21 of the regulation.
Animal health data and Article 9
The health data of an animal are not health data within the meaning of Article 9 of the regulation, because an animal is not a natural person and therefore not a data subject. This does not make them anonymous, however: a vaccination, a treatment or a hospital stay can be traced back to the owner identified by the account that entered them, so they remain personal data of the owner and are treated as such.
The practical consequence is that the legal basis for the health record is performance of the contract, not the explicit consent of Article 9. Technically, however, we apply to this information the same safeguards used for special categories, because the perceived sensitivity and the potential harm in case of unauthorised access are comparable.
- Access limited to the owner and to the parties the owner has explicitly authorised.
- Firestore and Cloud Storage security rules that verify document ownership on every read and every write.
- Separation of data between tenants, so that a clinic only sees the pets that have been shared with it.
- Recording of significant operations in the application audit log.
- Encryption in transit with TLS and at rest with AES-256.
Article 9 may become relevant indirectly in one specific case: when you voluntarily enter information about your own health, for example by stating that the animal is a guide dog or an assistance animal. In that situation the data concern a natural person and the legal basis is the explicit consent provided for by Article 9 paragraph 2 letter a, which you give by choosing to write that information in a free text field. You can remove it at any time by editing or deleting the content, and we encourage you not to enter data about your health when it is not necessary for the care of the animal.
Location data: a high risk category
Walk tracks are the most sensitive category of data processed by Animiyo as a controller. A sequence of routes can reveal far more than an itinerary: the times you go out, daily habits, the places you visit and, indirectly, your home address. This is why we treat them as a high risk category and not as ordinary application content.
- Precise location is requested only when a walk starts and the system permission stays revocable from the device settings.
- Tracks are private by default: no other user sees them until you choose to share them.
- Sharing a route and joining a group walk are voluntary and reversible acts; once sharing is revoked the content is no longer visible to others.
- Tracks never feed advertising, commercial profiling or inferences about your habits.
- The public lost pet tag page shows only the information needed to return the animal and can be switched off at any time.
- Deleting a track is immediate and does not require a formal request.
- Every new feature that processes location is preceded by a data protection impact assessment.
No location data are disclosed to third parties beyond the sharing you choose and the infrastructure provider that hosts the database. The map tiles shown under the track come from an external service queried by your browser, as explained further below, and that service receives the portion of the map requested and the IP address of the connection, not the full track nor your Animiyo identifier.
Content you make public
Some features exist precisely to show something to other people: finding a lost pet, being recognised during a group walk, leaving a review for a clinic. In all these cases publication is an explicit choice of yours, never a default setting. The table sums up what becomes visible, to whom, and how to undo it.
| Feature | What becomes visible | To whom | How to revoke it |
|---|---|---|---|
| Public username | The username you chose and the content that stays associated with it | To other users of the platform | By changing the username from your profile |
| Public lost pet tag page | The pet details needed to recognise the animal and a contact channel | To anyone who opens the link, even without an account | By switching the tag off from the pet record |
| Reported sightings | The location of the sighting and the note written by the reporter | To the owner and to anyone viewing the tag page | By removing the report or switching the tag off |
| Reviews of clinics and shops | The text, the rating and the username | To anyone viewing the professional profile | By deleting the review |
| Shared routes | The track, the distance and the duration of the route | To the users you shared the route with | By revoking sharing on the route |
| Group walks | Your participation and your position during the walk | To the other participants in the same walk | By leaving the group walk |
| Sharing a pet | The pet record and the subcollections you choose to include | To the user or tenant you share with | By revoking sharing from the pet record |
Bear in mind a technical limit that no platform can overcome: once content has been public, whoever saw it may have copied, saved or indexed it elsewhere. Revoking stops publication on our side and makes the content inaccessible through Animiyo, but it cannot delete copies already made by others. This is why we suggest publishing on the lost pet tag only the information genuinely useful to return the animal.
Recipients and sub-processors
Animiyo runs no servers of its own: the whole platform relies on managed Google Cloud and Firebase services, which act as sub-processors on our documented instructions. The table lists the services actually in use, the data each of them processes and the region where it operates.
| Provider | Service | Data processed | Region |
|---|---|---|---|
| Google Ireland Limited and Google LLC | Firebase Authentication | Email address, uid, sign in metadata | us-central1, United States |
| Google Ireland Limited and Google LLC | Cloud Firestore | All application data in the collections listed above | us-central1, United States |
| Google Ireland Limited and Google LLC | Cloud Storage for Firebase | Photographs, uploaded documents, consent signatures | us-central1, United States |
| Google Ireland Limited and Google LLC | Cloud Functions | Server side processing of application operations | us-central1, United States |
| Google Ireland Limited and Google LLC | Cloud Run | Hosting of the web application | us-central1, United States |
| Google Ireland Limited and Google LLC | Firebase Cloud Messaging | Device token and notification content | Global infrastructure |
| Google Ireland Limited and Google LLC | App Check with reCAPTCHA Enterprise | Browser antifraud signals | Global infrastructure |
| Google Ireland Limited and Google LLC | Google Analytics 4 | Pseudonymous usage data | Global infrastructure |
| Stripe Payments Europe Limited | Payments | Integration prepared but not active, no data transmitted | European Union |
The current list, together with any replacements and the notice periods owed to tenants, is published in /sub-responsabili. Besides infrastructure providers, your data may reach other recipients, always as a result of a choice of yours or of a legal duty.
- The tenants you choose to share a pet with or book an appointment with, limited to the data needed for the service.
- The other users you share a pet, a route or a group walk with.
- Anyone who accesses the content you voluntarily make public, such as a review or the lost pet tag page.
- The competent authorities, where disclosure is imposed by law or by a binding order.
Animiyo does not sell personal data, does not disclose them to advertising networks and does not use them to train artificial intelligence models, whether our own or those of third parties. There are no third party profiling cookies and no data exchange arrangements for marketing purposes.
Transfers to the United States
The main resources of the platform, namely Cloud Run, Cloud Functions, Cloud Firestore and Cloud Storage, are hosted in the us-central1 region, which is located in the United States. This means that your personal data, including animal health data, photographs, uploaded documents and walk tracks, are stored and processed on servers located in the United States. We state this explicitly because it is something you need to know before deciding whether to use the service, not a secondary technical note.
- Google Ireland Limited as contracting party, with the Google Cloud Data Processing Terms applying to the project.
- Standard contractual clauses adopted by the European Commission with implementing decision 2021/914.
- Certification of Google LLC under the Data Privacy Framework between the European Union and the United States.
- Encryption of data in transit with TLS and at rest with AES-256.
- A transfer impact assessment documented by the controller, taking account of the access laws in force in the destination country.
- Google's public policy on how it handles access requests from public authorities.
None of these safeguards removes the risk entirely: United States surveillance law may in principle allow access requests by public authorities, and on this point it would be dishonest to promise absolute protection. To reduce the risk at its root, a technical and economic assessment is under way for migrating the infrastructure to a European region, in the europe-west area. Until that decision is taken and the migration is complete, the transfer remains as described here; when the location changes, this section will be updated and the change will be announced in the application.
External services queried by the browser
Some of the information shown in the application comes from public databases queried directly by your browser, read only. We do not send these services your identifier, your email address or your pets' data, but the provider still receives the IP address of your connection and the usual request information: that is enough for the processing to require disclosure.
| Service | What it provides | Data that reach the provider | Country |
|---|---|---|---|
| openFDA | Medicine records from the database of the United States Food and Drug Administration | IP address, name of the active substance searched, request information | United States |
| Open Pet Food Facts | Information on pet food from the collaborative database | IP address, barcode or product name searched, request information | Not declared by the provider |
| dog.ceo | Images of dog breeds | IP address, breed requested, request information | Not declared by the provider |
| Wikipedia | Encyclopaedic entries on breeds and species | IP address, title of the entry requested, request information | Not declared by the provider |
| iNaturalist | Data on species and their classification | IP address, species requested, request information | Not declared by the provider |
| frankfurter.app | Exchange rates for converting expenses | IP address, currency pair requested, request information | Not declared by the provider |
| tile.openstreetmap.org | Map tiles for the walk maps | IP address, coordinates of the map portion requested, request information | Not declared by the provider |
Since not all of these providers state where the servers answering the requests are located, we treat these calls as possible transfers outside the European Union and we make sure you know about them. Map tiles in particular reveal to the provider the area you are looking at, and therefore indirectly the area of the walk. The controller plans to move these calls to the server side, so that the Animiyo backend queries the external sources and your IP address no longer reaches third party providers.
Retention periods
We keep each category of data for as long as the purpose it was collected for requires, then we delete it. The table brings together every period we apply, with the criterion that justifies it.
| Data or category | Retention period | Criterion |
|---|---|---|
| Account and connected data | For the duration of the relationship and up to thirty days from the deletion request | Contractual necessity, subject to legal obligations |
| Application audit log | Twenty four months | Security and reconstruction of access events |
| GPS tracks of walks | Until you delete them | User control over their own content |
| Shared routes and group walks | They stop being visible when sharing is revoked | Reversibility of sharing |
| Public lost pet tag page | Active until you switch it off | User control over publication |
| Conversations with professionals | For the duration of the relationship and in any case no longer than twenty four months from the last message | Continuity of care and minimisation |
| Google Analytics 4 analytics data | Fourteen months | Limit set on the analytics property |
| FCM notification tokens | Until the permission is withdrawn or the application is uninstalled | Technical validity of the token |
| Tax documents, once payments are active | Ten years | Civil and tax law obligation |
| Data processed on behalf of tenants | According to the tenant instructions, with deletion within thirty days from the end of the relationship | Processor role, under the agreement in /dpa |
Deletion from live systems is immediate when you request it from the application and in any case completed within thirty days. Backup copies and replicas managed by Google Cloud are superseded by later cycles and are never used to restore data deleted on request. Once the periods expire, data are erased or irreversibly anonymised, that is, stripped of every link to your account.
Security measures
The measures listed here are the ones actually implemented in the platform, not a catalogue of good intentions. They were chosen against the concrete risks of the service: access to a pet's data by someone with no title to it, confusion between the data of different tenants, automated abuse of the interfaces, loss of data.
- Firebase Authentication with email address verification.
- Access control by role and by tenant through the token custom claims.
- Firestore and Cloud Storage security rules written per collection and per role, verifying document ownership on every read and every write.
- Separation of data between different tenants, with no cross reading paths.
- Firebase App Check with reCAPTCHA Enterprise, to reject requests that do not come from a legitimate application.
- Application audit log in the auditLog collection.
- Encryption of data in transit with TLS and at rest with AES-256.
- Content security policy in enforcement mode on the web pages.
- Backups and replication managed by Google Cloud.
- Least privilege principle for administrative accounts.
We do not claim certifications we have not obtained and we do not promise absolute security, which no system connected to a network can offer. The measures described above are reviewed at every release that touches authentication, access rules or the structure of the data. In the event of a personal data breach posing a risk to your rights and freedoms, notification to the supervisory authority and, where the risk is high, communication to data subjects take place within the deadlines set by Articles 33 and 34 of the regulation.
Your rights
The regulation grants you the rights described from Articles 15 to 22, which you can exercise at any time and free of charge. The table sums them up as they apply to Animiyo; the operational procedure, with response times and identity checks, is described in /diritti-privacy.
| Right | Reference | What you can obtain |
|---|---|---|
| Access | Article 15 | Learn whether we process your data, which data, for which purposes and to whom we disclose them, and obtain a copy |
| Rectification | Article 16 | Correct inaccurate data or complete incomplete data, for example the microchip number or a pet's date of birth |
| Erasure | Article 17 | Obtain removal of the data when they are no longer necessary or when you withdraw the consent they rested on |
| Restriction | Article 18 | Freeze the processing while we verify the accuracy of a data point or assess an objection of yours |
| Notification to recipients | Article 19 | Have rectification, erasure or restriction communicated to those who received your data |
| Portability | Article 20 | Receive in a machine readable format the data you provided to us, to reuse them elsewhere |
| Objection | Article 21 | Object to processing based on legitimate interest, explaining your particular situation |
| Automated decisions | Article 22 | Not be subject to solely automated decisions with legal or similarly significant effects |
| Withdrawal of consent | Article 7 paragraph 3 | Withdraw consent to notifications, location, statistics and publications, with no effect on processing already carried out |
- In app export: you generate a JSON archive containing the user profile, pets and their subcollections, pet contacts, budget configuration, expense entries and goals.
- In app account deletion: it removes the user profile, pets and subcollections, contacts, shares, lost pet tag, sightings, budget entries and goals.
- Requests the in app tools do not cover: the procedure is described in /diritti-privacy, with forwarding to the tenant where the controller is a clinic or a shop.
If you believe the processing infringes the regulation you can lodge a complaint with the Italian supervisory authority, Garante per la protezione dei dati personali, piazza Venezia 11, 00187 Roma, or with the supervisory authority of the country where you habitually live or work. A complaint is independent of any other remedy and does not require you to have contacted us first, although a direct request is often the quickest way to solve the problem.
Minors
The service is reserved for people who are at least eighteen years old, as set out in the terms of use published in /termini, and we do not knowingly process data of children under sixteen. We do not collect the user's date of birth, so we cannot verify age automatically: the safeguard rests on the age limit stated in the terms of use and on the reports we receive.
If we become aware that an account was created by a minor, we suspend access and delete the connected data as quickly as possible, unless retention is imposed by a legal obligation. If you are a parent or guardian and believe a minor has opened an account, report it from the Contacts page at the path /contatti, indicating the username or the email address concerned: we check the report and confirm the outcome to you. The same applies if a minor appears in a photograph or in a document uploaded by another user.
Automated decisions and symptom triage
Animiyo does not carry out solely automated decision making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 of the regulation. We do not score users, we do not build profiles for advertising purposes and we do not let an automatic calculation determine access to the service or its commercial terms.
In the same way, reminders, vaccination due date alerts and budget estimates are deterministic calculations based on the data you entered, not profiling. If a date is close you get an alert; if an expense exceeds the threshold you set, you see it in the summary. None of these automatic behaviours draws conclusions about your personal characteristics and none of them is disclosed to third parties.
App Check antifraud controls operate on the single technical request and not on the user profile: when a check is not passed, that request is rejected, not the account. If you believe a block is wrong you can report it from the /contatti page and the review is carried out by a person.
Updates to this notice
This notice is identified by a version number and by an effective date, both shown at the top of the document. The current version is 1.0, effective from 2 August 2026. Every time the document changes, the version and the date change with it.
When a change is substantial, for example the introduction of a new purpose, a change of legal basis, the addition of a sub-processor or the move of data to another region, we publish a notice in the application before the change takes effect; where the change requires your consent, we ask for it again and the service keeps working even if you do not give it. Editorial corrections and clarifications that do not change the processing are published without notice, but they still update the revision date.
Previous versions remain tracked in the source code version control, which is the authoritative history of the document: every change is tied to a date and to the reason that prompted it. If you need the text in force at a past moment, you can ask for it from the /contatti page.
Frequently asked questions
- Does Animiyo sell my data or my pets' data?
- No. We do not sell personal data, we do not disclose them to advertising networks and we do not use them to train artificial intelligence models. The only parties that receive the data are the infrastructure providers listed among the sub-processors, acting on our documented instructions, and the professionals or users you choose to share something with. If this ever changed, it would be a substantial change and it would be announced in the application before taking effect.
- Where exactly are my pets' data stored?
- In the us-central1 region of Google Cloud, which is located in the United States. That is where the Firestore database, the files uploaded to Cloud Storage, the server side functions and the web application hosting all live. The transfer is covered by the standard contractual clauses of decision 2021/914, by the Google Cloud Data Processing Terms and by the certification of Google LLC under the Data Privacy Framework, but the residual risk linked to United States surveillance law cannot be reduced to zero. An assessment is under way to migrate the infrastructure to a European region.
- Who can see the clinical record created by my veterinary clinic?
- SOAP notes, laboratory results and signed consents are processed by Animiyo on behalf of the clinic, which is their controller. They are visible to the authorised staff of the clinic and to you, if the clinic makes them available in the pet record. Animiyo does not use them for its own purposes and does not disclose them to other tenants, because the data of different workspaces are kept separate. For an access or rectification request on those documents you must contact the clinic, and the document governing the relationship is /dpa.
- How do I download everything you hold about me?
- From the application you can generate a JSON archive containing the user profile, pets with their subcollections, pet contacts, budget configuration, expense entries and goals. The file can be read with any text editor and is also designed for portability towards another service. If you need material the export does not include, such as uploaded documents or conversations, you can ask for it following the procedure described in /diritti-privacy. We reply within the deadlines set by the regulation.
- If I delete my account, what is left?
- Deletion from the application removes the user profile, pets and subcollections, contacts, shares, lost pet tag, sightings, budget entries and goals, and is completed within thirty days of the request. What remains is the data we must keep because of a legal obligation, such as tax documents once payments are active. Data that a clinic or a shop processes as controller also remain, and they follow that party's rules rather than ours. The audit log keeps the technical trace of operations for twenty four months, which is what allows us to show that deletions took place.
- Can anyone see my walks?
- No, tracks are private by default. They become visible only if you share a route or join a group walk, and in both cases you can revoke sharing: from that moment the content is no longer accessible to others. Precise location is requested only when you start a walk and the permission stays revocable from your device settings. Tracks are never used for advertising, commercial profiling or inferences about your habits.
- Is my dog's health data sensitive data?
- Not in the sense of Article 9 of the regulation, which concerns data about the health of a natural person: an animal is not a data subject. They do remain your personal data, because they are linked to your account and make you identifiable, so they enjoy the same protection as other data and, technically, the same safeguards reserved for special categories. Article 9 becomes relevant again if you write information about your own health, for example by stating that the animal is a guide dog: in that case the legal basis is explicit consent. You can remove that information at any time by editing the content.
- Why do notifications, location and statistics ask for separate consent?
- Because they are not necessary to provide the service: you can use Animiyo without push notifications, without recording walks and without contributing to statistics. The legal basis for this processing is therefore consent, which you give separately for each of them. You can withdraw it at any time from your device settings or from the panel described in /cookie, and withdrawal does not affect the lawfulness of processing already carried out. No essential feature is limited if you choose not to give consent.
In short
If you want to check your own situation right away, open your profile settings and export the JSON archive of your data: it contains the user profile, pets and their subcollections, pet contacts, budget configuration, expense entries and goals. Then review which pets you have shared and with whom, and switch off the public lost pet tag page if you no longer need it. To exercise a right, or for any request the in app tools do not cover, follow the procedure described in /diritti-privacy or write to us from the /contatti page.