Skip to content
Animiyo

Privacy notice

How Animiyo processes data for owners, clinics and shops: purposes, legal bases, retention, transfers to the United States and your rights.

Effective from
August 2, 2026
Last updated
August 2, 2026
Version
1.0

Animiyo is a platform for managing companion animals, available as a web application and as a native iOS application sharing the same Firebase backend. Three kinds of user coexist on the platform, pet owners, veterinary clinics and shops or services, and the rules that govern data processing differ for each of them. This notice explains which data we collect when you use Animiyo as an owner, on which legal bases we process them, who receives them, where they are stored and for how long. It also describes the cases where Animiyo does not decide the purposes of processing but acts on behalf of a clinic or a shop, and points to the document that governs those relationships. Every section refers to concrete features of the application, so you can tell which processing starts when you use a given part of the product.

Data controller and contact details

The data controller is the party that operates Animiyo, the platform available as a web application hosted on Google Cloud Run and as a native iOS application, both relying on the same Firebase backend in the Google Cloud project petdiary-10327. The controller decides the purposes and means of processing for everything that concerns pet owner accounts: registration, authentication, pet profiles, reminders, budget, walks, uploaded documents and interface preferences.

For any request concerning personal data you can use the Contacts page of the website, at the path /contatti. Requests concerning the exercise of your rights follow the procedure described in /diritti-privacy, which also lists the tools available directly in the application to export or delete your data without waiting for a reply from us.

No data protection officer has been appointed because the conditions set out in Article 37 of the regulation are not met: the processing is not carried out by a public authority or body, it does not consist of regular and systematic monitoring of data subjects on a large scale, and its core activity is not the large scale processing of special categories of data. The assessment is repeated whenever the service is extended and, should the outcome change, the appointment will be published in this section.

Scope and dual role

Animiyo is a multi-tenant platform: veterinary clinics, shops and services work in separate spaces, with their own staff and their own clients. This is why the role of Animiyo is not always the same. On the data of an owner account Animiyo is the controller and answers directly. On the data that a clinic or a shop enters about its own clients through the platform Animiyo is instead a processor: the controller is the tenant and the relationship is governed by the agreement published in /dpa.

Who decides what, feature by feature
ActivityAnimiyo roleControllerApplicable document
Registration, sign in and management of an owner accountControllerAnimiyoThis notice
Pet profiles, health record, remindersControllerAnimiyoThis notice
Walks, budget and documents uploaded by the ownerControllerAnimiyoThis notice
Reviews, memories and notes written by the ownerControllerAnimiyoThis notice
Platform security and audit logControllerAnimiyoThis notice
Clinical records and SOAP notes written by a clinicProcessorThe veterinary clinicProcessing agreement in /dpa
Laboratory results and consents signed at the clinicProcessorThe veterinary clinicProcessing agreement in /dpa
Estimates, invoices and the tenant appointment scheduleProcessorThe tenant that issues themProcessing agreement in /dpa
Orders and loyalty programmes of a shop or serviceProcessorThe shop or serviceProcessing agreement in /dpa

The distinction is not merely formal. When Animiyo acts as a processor it does not decide which data to collect or how long to keep them, but follows the documented instructions of the tenant. If you want to exercise a right over data entered by a clinic or a shop, the request must be addressed to that party; if you send it to us, we provide the technical assistance needed and forward it to the competent controller, telling you that we have done so.

Categories of data processed

The list below is not a generic formula: it reports the categories actually present in the system, with examples drawn from the data structures of the application. The Source column shows where the information comes from, because that changes both the legal basis and the way you can act on it.

Categories, concrete examples and source of the data
CategoryConcrete examplesSource
Account identifiersFirebase uid, email address, display name, public username chosen by you, role and tenant membership in the token custom claimsProvided by the user and generated by use
Pet identity dataName, species, breed, date of birth, sex, microchip number, weight, photographsProvided by the user
Uploaded documentsCertificates, forms and other files stored on Cloud Storage together with photographsProvided by the user
Animal health dataVaccinations, medications and treatments, deworming, visits, appointments, chronic conditions, hospital stays, symptom triage outcomesProvided by the user or entered by a professional
Professional clinical documentationSOAP notes, laboratory results, consent forms and signed consentsEntered by a professional
Location dataGPS tracks of walks, saved and shared routes, group walks, sightings, public lost pet tag pageGenerated by use
Financial dataExpenses, budgets, saving goals, orders, subscriptions, loyalty points, estimates and invoices issued by tenantsProvided by the user or entered by a professional
Generated contentConversations between users and professionals, reviews, memories and notesProvided by the user
Technical and security dataApplication audit log, FCM notification tokens, App Check tokens, interface preferencesGenerated by use
Usage dataPseudonymous Google Analytics 4 statistics on pages viewed and features usedGenerated by use
Supporting descriptive informationReference entries on breeds, species and active substances shown next to your dataDerived from public sources

Technically the data live in the Firestore collections users, usernames, pets, petContacts, petShares, petSightings, petMemberships, petConditions, petActivity, petMemories, foundTags, vaccinations, medications, dewormingRecords, weightRecords, labResults, soapNotes, vetAppointments, appointmentTypes, hospitalized, consentForms, signedConsents, estimates, invoices, orders, subscriptions, rewards, reviews, resources, walks, routes, routeShares, groupWalks, conversations, budgetItems, budgetGoals, budgetConfigurations, tenants and auditLog. Photographs, uploaded documents and consent signatures are stored on Cloud Storage. We publish the list because it makes it possible to check that what is declared here matches what actually exists in the system.

Purposes, legal bases, retention and recipients

This is the central section of the document. The two tables connect each purpose to the categories of data used, to the legal basis, to the retention period and to the recipients. The first covers the processing needed to provide the service you asked for; the second covers processing based on consent, on legitimate interest or on a legal obligation.

Processing necessary for performance of the contract and for core features
PurposeCategories of dataLegal basisRetentionRecipients
Creating and managing the accountIdentifiers, email address, username, role and tenant membershipPerformance of the contract (Article 6 paragraph 1 letter b)For the duration of the relationship and up to thirty days from the deletion requestGoogle as infrastructure provider
Pet profiles and health recordPet identity and health data, uploaded documents, photographsPerformance of the contract (Article 6 paragraph 1 letter b)For the duration of the relationship, then thirty days from the deletion requestGoogle; the tenants and users you share the pet with
Appointments and communication with clinicsPet data, appointment data, messages exchangedPerformance of the contract (Article 6 paragraph 1 letter b)For the duration of the relationship; conversations no longer than twenty four months from the last messageGoogle; the clinic you choose
Budget, expenses and saving goalsFinancial data, currency, budget configurationPerformance of the contract (Article 6 paragraph 1 letter b)For the duration of the relationship, then thirty days from the deletion requestGoogle
Orders, loyalty points and subscriptionsFinancial data, identifiers, shop or service dataPerformance of the contract (Article 6 paragraph 1 letter b)For the duration of the relationship; tax documents ten years once payments are activeGoogle; the shop or service handling the order
Chat with professionals and reviewsGenerated content, identifiers, public usernamePerformance of the contract (Article 6 paragraph 1 letter b)Conversations no longer than twenty four months from the last message; reviews until you delete themGoogle; the receiving professional; the public for reviews
Support and replies to data subject requestsIdentifiers, content of the request, attached documentsPerformance of the contract (Article 6 paragraph 1 letter b) and legal obligation (Article 6 paragraph 1 letter c)Until the request is closed and for as long as needed to document its outcomeGoogle
Processing based on consent, legitimate interest or legal obligation
PurposeCategories of dataLegal basisRetentionRecipients
Reminders and push notificationsFCM notification token, reminder content, identifiersConsent (Article 6 paragraph 1 letter a)Token until the permission is withdrawn or the application is uninstalledGoogle through Firebase Cloud Messaging
Walks and GPS tracksPrecise location during the walk, route, duration, distanceConsent (Article 6 paragraph 1 letter a)Until you delete the track; shared visibility ends when sharing is revokedGoogle; the users you share a route or a group walk with
Lost pet tag and sightingsPet data you choose to publish, sighting location, contact detailsConsent (Article 6 paragraph 1 letter a)Until you switch off the public tag pageGoogle; anyone who opens the public link
Security, abuse prevention and audit logApp Check token, browser antifraud signals, audit log events, identifiersLegitimate interest (Article 6 paragraph 1 letter f)Audit log twenty four monthsGoogle; reCAPTCHA Enterprise
Usage statisticsPseudonymous usage data, event, page, device typeConsent (Article 6 paragraph 1 letter a)Fourteen monthsGoogle Analytics 4
Service improvement and fault diagnosisTechnical data, interface preferences, aggregated error indicatorsLegitimate interest (Article 6 paragraph 1 letter f)For the duration of the relationshipGoogle
Tax and accounting obligations and replies to authority requestsFinancial data, identifiers, tax documentsLegal obligation (Article 6 paragraph 1 letter c)Ten years for tax documents, once payments are activeGoogle; the competent authorities making a lawful request
Information about your own health entered voluntarilyFree text in notes, memories, conditions and messagesExplicit consent (Article 9 paragraph 2 letter a)Until you delete the contentGoogle; the parties you shared that content with

Consent can always be withdrawn and withdrawal does not affect the lawfulness of processing carried out before. You can remove the notification and location permissions from your device settings, switch off statistics from the panel described in /cookie, and turn off the public lost pet tag page from the pet record. Where processing rests on legitimate interest we have verified that our interest in keeping the service secure and working does not override your rights, because the data used are limited to technical ones, retention is short and no decision about you follows from them; you can still object under Article 21 of the regulation.

Animal health data and Article 9

The health data of an animal are not health data within the meaning of Article 9 of the regulation, because an animal is not a natural person and therefore not a data subject. This does not make them anonymous, however: a vaccination, a treatment or a hospital stay can be traced back to the owner identified by the account that entered them, so they remain personal data of the owner and are treated as such.

The practical consequence is that the legal basis for the health record is performance of the contract, not the explicit consent of Article 9. Technically, however, we apply to this information the same safeguards used for special categories, because the perceived sensitivity and the potential harm in case of unauthorised access are comparable.

  • Access limited to the owner and to the parties the owner has explicitly authorised.
  • Firestore and Cloud Storage security rules that verify document ownership on every read and every write.
  • Separation of data between tenants, so that a clinic only sees the pets that have been shared with it.
  • Recording of significant operations in the application audit log.
  • Encryption in transit with TLS and at rest with AES-256.

Article 9 may become relevant indirectly in one specific case: when you voluntarily enter information about your own health, for example by stating that the animal is a guide dog or an assistance animal. In that situation the data concern a natural person and the legal basis is the explicit consent provided for by Article 9 paragraph 2 letter a, which you give by choosing to write that information in a free text field. You can remove it at any time by editing or deleting the content, and we encourage you not to enter data about your health when it is not necessary for the care of the animal.

Location data: a high risk category

Walk tracks are the most sensitive category of data processed by Animiyo as a controller. A sequence of routes can reveal far more than an itinerary: the times you go out, daily habits, the places you visit and, indirectly, your home address. This is why we treat them as a high risk category and not as ordinary application content.

  • Precise location is requested only when a walk starts and the system permission stays revocable from the device settings.
  • Tracks are private by default: no other user sees them until you choose to share them.
  • Sharing a route and joining a group walk are voluntary and reversible acts; once sharing is revoked the content is no longer visible to others.
  • Tracks never feed advertising, commercial profiling or inferences about your habits.
  • The public lost pet tag page shows only the information needed to return the animal and can be switched off at any time.
  • Deleting a track is immediate and does not require a formal request.
  • Every new feature that processes location is preceded by a data protection impact assessment.

No location data are disclosed to third parties beyond the sharing you choose and the infrastructure provider that hosts the database. The map tiles shown under the track come from an external service queried by your browser, as explained further below, and that service receives the portion of the map requested and the IP address of the connection, not the full track nor your Animiyo identifier.

Content you make public

Some features exist precisely to show something to other people: finding a lost pet, being recognised during a group walk, leaving a review for a clinic. In all these cases publication is an explicit choice of yours, never a default setting. The table sums up what becomes visible, to whom, and how to undo it.

Visibility of published content and how to revoke it
FeatureWhat becomes visibleTo whomHow to revoke it
Public usernameThe username you chose and the content that stays associated with itTo other users of the platformBy changing the username from your profile
Public lost pet tag pageThe pet details needed to recognise the animal and a contact channelTo anyone who opens the link, even without an accountBy switching the tag off from the pet record
Reported sightingsThe location of the sighting and the note written by the reporterTo the owner and to anyone viewing the tag pageBy removing the report or switching the tag off
Reviews of clinics and shopsThe text, the rating and the usernameTo anyone viewing the professional profileBy deleting the review
Shared routesThe track, the distance and the duration of the routeTo the users you shared the route withBy revoking sharing on the route
Group walksYour participation and your position during the walkTo the other participants in the same walkBy leaving the group walk
Sharing a petThe pet record and the subcollections you choose to includeTo the user or tenant you share withBy revoking sharing from the pet record

Bear in mind a technical limit that no platform can overcome: once content has been public, whoever saw it may have copied, saved or indexed it elsewhere. Revoking stops publication on our side and makes the content inaccessible through Animiyo, but it cannot delete copies already made by others. This is why we suggest publishing on the lost pet tag only the information genuinely useful to return the animal.

Recipients and sub-processors

Animiyo runs no servers of its own: the whole platform relies on managed Google Cloud and Firebase services, which act as sub-processors on our documented instructions. The table lists the services actually in use, the data each of them processes and the region where it operates.

Active sub-processors and the data each one handles
ProviderServiceData processedRegion
Google Ireland Limited and Google LLCFirebase AuthenticationEmail address, uid, sign in metadataus-central1, United States
Google Ireland Limited and Google LLCCloud FirestoreAll application data in the collections listed aboveus-central1, United States
Google Ireland Limited and Google LLCCloud Storage for FirebasePhotographs, uploaded documents, consent signaturesus-central1, United States
Google Ireland Limited and Google LLCCloud FunctionsServer side processing of application operationsus-central1, United States
Google Ireland Limited and Google LLCCloud RunHosting of the web applicationus-central1, United States
Google Ireland Limited and Google LLCFirebase Cloud MessagingDevice token and notification contentGlobal infrastructure
Google Ireland Limited and Google LLCApp Check with reCAPTCHA EnterpriseBrowser antifraud signalsGlobal infrastructure
Google Ireland Limited and Google LLCGoogle Analytics 4Pseudonymous usage dataGlobal infrastructure
Stripe Payments Europe LimitedPaymentsIntegration prepared but not active, no data transmittedEuropean Union

The current list, together with any replacements and the notice periods owed to tenants, is published in /sub-responsabili. Besides infrastructure providers, your data may reach other recipients, always as a result of a choice of yours or of a legal duty.

  • The tenants you choose to share a pet with or book an appointment with, limited to the data needed for the service.
  • The other users you share a pet, a route or a group walk with.
  • Anyone who accesses the content you voluntarily make public, such as a review or the lost pet tag page.
  • The competent authorities, where disclosure is imposed by law or by a binding order.

Animiyo does not sell personal data, does not disclose them to advertising networks and does not use them to train artificial intelligence models, whether our own or those of third parties. There are no third party profiling cookies and no data exchange arrangements for marketing purposes.

Transfers to the United States

The main resources of the platform, namely Cloud Run, Cloud Functions, Cloud Firestore and Cloud Storage, are hosted in the us-central1 region, which is located in the United States. This means that your personal data, including animal health data, photographs, uploaded documents and walk tracks, are stored and processed on servers located in the United States. We state this explicitly because it is something you need to know before deciding whether to use the service, not a secondary technical note.

  • Google Ireland Limited as contracting party, with the Google Cloud Data Processing Terms applying to the project.
  • Standard contractual clauses adopted by the European Commission with implementing decision 2021/914.
  • Certification of Google LLC under the Data Privacy Framework between the European Union and the United States.
  • Encryption of data in transit with TLS and at rest with AES-256.
  • A transfer impact assessment documented by the controller, taking account of the access laws in force in the destination country.
  • Google's public policy on how it handles access requests from public authorities.

None of these safeguards removes the risk entirely: United States surveillance law may in principle allow access requests by public authorities, and on this point it would be dishonest to promise absolute protection. To reduce the risk at its root, a technical and economic assessment is under way for migrating the infrastructure to a European region, in the europe-west area. Until that decision is taken and the migration is complete, the transfer remains as described here; when the location changes, this section will be updated and the change will be announced in the application.

External services queried by the browser

Some of the information shown in the application comes from public databases queried directly by your browser, read only. We do not send these services your identifier, your email address or your pets' data, but the provider still receives the IP address of your connection and the usual request information: that is enough for the processing to require disclosure.

External sources contacted by the browser during use
ServiceWhat it providesData that reach the providerCountry
openFDAMedicine records from the database of the United States Food and Drug AdministrationIP address, name of the active substance searched, request informationUnited States
Open Pet Food FactsInformation on pet food from the collaborative databaseIP address, barcode or product name searched, request informationNot declared by the provider
dog.ceoImages of dog breedsIP address, breed requested, request informationNot declared by the provider
WikipediaEncyclopaedic entries on breeds and speciesIP address, title of the entry requested, request informationNot declared by the provider
iNaturalistData on species and their classificationIP address, species requested, request informationNot declared by the provider
frankfurter.appExchange rates for converting expensesIP address, currency pair requested, request informationNot declared by the provider
tile.openstreetmap.orgMap tiles for the walk mapsIP address, coordinates of the map portion requested, request informationNot declared by the provider

Since not all of these providers state where the servers answering the requests are located, we treat these calls as possible transfers outside the European Union and we make sure you know about them. Map tiles in particular reveal to the provider the area you are looking at, and therefore indirectly the area of the walk. The controller plans to move these calls to the server side, so that the Animiyo backend queries the external sources and your IP address no longer reaches third party providers.

Retention periods

We keep each category of data for as long as the purpose it was collected for requires, then we delete it. The table brings together every period we apply, with the criterion that justifies it.

Retention periods applied to each category
Data or categoryRetention periodCriterion
Account and connected dataFor the duration of the relationship and up to thirty days from the deletion requestContractual necessity, subject to legal obligations
Application audit logTwenty four monthsSecurity and reconstruction of access events
GPS tracks of walksUntil you delete themUser control over their own content
Shared routes and group walksThey stop being visible when sharing is revokedReversibility of sharing
Public lost pet tag pageActive until you switch it offUser control over publication
Conversations with professionalsFor the duration of the relationship and in any case no longer than twenty four months from the last messageContinuity of care and minimisation
Google Analytics 4 analytics dataFourteen monthsLimit set on the analytics property
FCM notification tokensUntil the permission is withdrawn or the application is uninstalledTechnical validity of the token
Tax documents, once payments are activeTen yearsCivil and tax law obligation
Data processed on behalf of tenantsAccording to the tenant instructions, with deletion within thirty days from the end of the relationshipProcessor role, under the agreement in /dpa

Deletion from live systems is immediate when you request it from the application and in any case completed within thirty days. Backup copies and replicas managed by Google Cloud are superseded by later cycles and are never used to restore data deleted on request. Once the periods expire, data are erased or irreversibly anonymised, that is, stripped of every link to your account.

Security measures

The measures listed here are the ones actually implemented in the platform, not a catalogue of good intentions. They were chosen against the concrete risks of the service: access to a pet's data by someone with no title to it, confusion between the data of different tenants, automated abuse of the interfaces, loss of data.

  • Firebase Authentication with email address verification.
  • Access control by role and by tenant through the token custom claims.
  • Firestore and Cloud Storage security rules written per collection and per role, verifying document ownership on every read and every write.
  • Separation of data between different tenants, with no cross reading paths.
  • Firebase App Check with reCAPTCHA Enterprise, to reject requests that do not come from a legitimate application.
  • Application audit log in the auditLog collection.
  • Encryption of data in transit with TLS and at rest with AES-256.
  • Content security policy in enforcement mode on the web pages.
  • Backups and replication managed by Google Cloud.
  • Least privilege principle for administrative accounts.

We do not claim certifications we have not obtained and we do not promise absolute security, which no system connected to a network can offer. The measures described above are reviewed at every release that touches authentication, access rules or the structure of the data. In the event of a personal data breach posing a risk to your rights and freedoms, notification to the supervisory authority and, where the risk is high, communication to data subjects take place within the deadlines set by Articles 33 and 34 of the regulation.

Your rights

The regulation grants you the rights described from Articles 15 to 22, which you can exercise at any time and free of charge. The table sums them up as they apply to Animiyo; the operational procedure, with response times and identity checks, is described in /diritti-privacy.

Rights granted and what you can actually obtain
RightReferenceWhat you can obtain
AccessArticle 15Learn whether we process your data, which data, for which purposes and to whom we disclose them, and obtain a copy
RectificationArticle 16Correct inaccurate data or complete incomplete data, for example the microchip number or a pet's date of birth
ErasureArticle 17Obtain removal of the data when they are no longer necessary or when you withdraw the consent they rested on
RestrictionArticle 18Freeze the processing while we verify the accuracy of a data point or assess an objection of yours
Notification to recipientsArticle 19Have rectification, erasure or restriction communicated to those who received your data
PortabilityArticle 20Receive in a machine readable format the data you provided to us, to reuse them elsewhere
ObjectionArticle 21Object to processing based on legitimate interest, explaining your particular situation
Automated decisionsArticle 22Not be subject to solely automated decisions with legal or similarly significant effects
Withdrawal of consentArticle 7 paragraph 3Withdraw consent to notifications, location, statistics and publications, with no effect on processing already carried out
  • In app export: you generate a JSON archive containing the user profile, pets and their subcollections, pet contacts, budget configuration, expense entries and goals.
  • In app account deletion: it removes the user profile, pets and subcollections, contacts, shares, lost pet tag, sightings, budget entries and goals.
  • Requests the in app tools do not cover: the procedure is described in /diritti-privacy, with forwarding to the tenant where the controller is a clinic or a shop.

If you believe the processing infringes the regulation you can lodge a complaint with the Italian supervisory authority, Garante per la protezione dei dati personali, piazza Venezia 11, 00187 Roma, or with the supervisory authority of the country where you habitually live or work. A complaint is independent of any other remedy and does not require you to have contacted us first, although a direct request is often the quickest way to solve the problem.

Minors

The service is reserved for people who are at least eighteen years old, as set out in the terms of use published in /termini, and we do not knowingly process data of children under sixteen. We do not collect the user's date of birth, so we cannot verify age automatically: the safeguard rests on the age limit stated in the terms of use and on the reports we receive.

If we become aware that an account was created by a minor, we suspend access and delete the connected data as quickly as possible, unless retention is imposed by a legal obligation. If you are a parent or guardian and believe a minor has opened an account, report it from the Contacts page at the path /contatti, indicating the username or the email address concerned: we check the report and confirm the outcome to you. The same applies if a minor appears in a photograph or in a document uploaded by another user.

Automated decisions and symptom triage

Animiyo does not carry out solely automated decision making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 of the regulation. We do not score users, we do not build profiles for advertising purposes and we do not let an automatic calculation determine access to the service or its commercial terms.

In the same way, reminders, vaccination due date alerts and budget estimates are deterministic calculations based on the data you entered, not profiling. If a date is close you get an alert; if an expense exceeds the threshold you set, you see it in the summary. None of these automatic behaviours draws conclusions about your personal characteristics and none of them is disclosed to third parties.

App Check antifraud controls operate on the single technical request and not on the user profile: when a check is not passed, that request is rejected, not the account. If you believe a block is wrong you can report it from the /contatti page and the review is carried out by a person.

Updates to this notice

This notice is identified by a version number and by an effective date, both shown at the top of the document. The current version is 1.0, effective from 2 August 2026. Every time the document changes, the version and the date change with it.

When a change is substantial, for example the introduction of a new purpose, a change of legal basis, the addition of a sub-processor or the move of data to another region, we publish a notice in the application before the change takes effect; where the change requires your consent, we ask for it again and the service keeps working even if you do not give it. Editorial corrections and clarifications that do not change the processing are published without notice, but they still update the revision date.

Previous versions remain tracked in the source code version control, which is the authoritative history of the document: every change is tied to a date and to the reason that prompted it. If you need the text in force at a past moment, you can ask for it from the /contatti page.

Frequently asked questions

Does Animiyo sell my data or my pets' data?
No. We do not sell personal data, we do not disclose them to advertising networks and we do not use them to train artificial intelligence models. The only parties that receive the data are the infrastructure providers listed among the sub-processors, acting on our documented instructions, and the professionals or users you choose to share something with. If this ever changed, it would be a substantial change and it would be announced in the application before taking effect.
Where exactly are my pets' data stored?
In the us-central1 region of Google Cloud, which is located in the United States. That is where the Firestore database, the files uploaded to Cloud Storage, the server side functions and the web application hosting all live. The transfer is covered by the standard contractual clauses of decision 2021/914, by the Google Cloud Data Processing Terms and by the certification of Google LLC under the Data Privacy Framework, but the residual risk linked to United States surveillance law cannot be reduced to zero. An assessment is under way to migrate the infrastructure to a European region.
Who can see the clinical record created by my veterinary clinic?
SOAP notes, laboratory results and signed consents are processed by Animiyo on behalf of the clinic, which is their controller. They are visible to the authorised staff of the clinic and to you, if the clinic makes them available in the pet record. Animiyo does not use them for its own purposes and does not disclose them to other tenants, because the data of different workspaces are kept separate. For an access or rectification request on those documents you must contact the clinic, and the document governing the relationship is /dpa.
How do I download everything you hold about me?
From the application you can generate a JSON archive containing the user profile, pets with their subcollections, pet contacts, budget configuration, expense entries and goals. The file can be read with any text editor and is also designed for portability towards another service. If you need material the export does not include, such as uploaded documents or conversations, you can ask for it following the procedure described in /diritti-privacy. We reply within the deadlines set by the regulation.
If I delete my account, what is left?
Deletion from the application removes the user profile, pets and subcollections, contacts, shares, lost pet tag, sightings, budget entries and goals, and is completed within thirty days of the request. What remains is the data we must keep because of a legal obligation, such as tax documents once payments are active. Data that a clinic or a shop processes as controller also remain, and they follow that party's rules rather than ours. The audit log keeps the technical trace of operations for twenty four months, which is what allows us to show that deletions took place.
Can anyone see my walks?
No, tracks are private by default. They become visible only if you share a route or join a group walk, and in both cases you can revoke sharing: from that moment the content is no longer accessible to others. Precise location is requested only when you start a walk and the permission stays revocable from your device settings. Tracks are never used for advertising, commercial profiling or inferences about your habits.
Is my dog's health data sensitive data?
Not in the sense of Article 9 of the regulation, which concerns data about the health of a natural person: an animal is not a data subject. They do remain your personal data, because they are linked to your account and make you identifiable, so they enjoy the same protection as other data and, technically, the same safeguards reserved for special categories. Article 9 becomes relevant again if you write information about your own health, for example by stating that the animal is a guide dog: in that case the legal basis is explicit consent. You can remove that information at any time by editing the content.
Why do notifications, location and statistics ask for separate consent?
Because they are not necessary to provide the service: you can use Animiyo without push notifications, without recording walks and without contributing to statistics. The legal basis for this processing is therefore consent, which you give separately for each of them. You can withdraw it at any time from your device settings or from the panel described in /cookie, and withdrawal does not affect the lawfulness of processing already carried out. No essential feature is limited if you choose not to give consent.

In short

If you want to check your own situation right away, open your profile settings and export the JSON archive of your data: it contains the user profile, pets and their subcollections, pet contacts, budget configuration, expense entries and goals. Then review which pets you have shared and with whom, and switch off the public lost pet tag page if you no longer need it. To exercise a right, or for any request the in app tools do not cover, follow the procedure described in /diritti-privacy or write to us from the /contatti page.

Privacy notice · Animiyo