List of sub-processors
Who processes personal data on behalf of Animiyo: providers, services, data categories, processing location, transfer basis and right to object.
- Effective from
- August 2, 2026
- Last updated
- August 2, 2026
- Version
- 1.0
Animiyo runs no servers of its own: the platform rests entirely on services operated by third party providers, which process personal data on our behalf and on our instructions. This page lists those providers, states which data they receive, where they process it and in which legal role. It is the document referred to by the data processing agreement published at /dpa and by the recipients section of the privacy notice published at /privacy. It contains three things that are often confused: the providers that genuinely process data on our behalf, the external data sources the browser queries without sending identifiers, and the procedure by which we announce a change and collect objections. Every row matches a service that is actually configured or a network call the product actually makes, not a list of abstract possibilities.
What this list is for
Animiyo is a multi-tenant SaaS platform for pet management: a Next.js web application hosted on Google Cloud Run and a native iOS application share the same Firebase backend, in the Google Cloud project petdiary-10327. None of these components runs on machines owned by whoever develops the service, so every piece of data handled by the platform passes through a third party provider. Publishing the list of those providers is the most direct way to let anyone check where their data ends up.
Animiyo has two distinct roles. It is the controller for pet owner accounts, that is for people who sign up and use the application for themselves. It is instead the processor for the data that tenants, veterinary clinics and shops, process about their own clients. This list applies in both cases, with a difference in legal qualification: in the first case the providers are processors appointed by Animiyo, in the second they are sub-processors authorised under Article 28 paragraphs 2 and 4 of Regulation (EU) 2016/679.
Two kinds of readers use this page. The data subject, meaning the person whose data is processed, uses it to check that the notice at /privacy tells the truth and to exercise the rights described at /diritti-privacy. The tenant controller uses it to meet the information obligation set out in the agreement at /dpa, to update its own record of processing activities and to decide whether to accept a provider or object to it. Publication therefore satisfies both the transparency obligation towards data subjects and the information obligation towards tenant controllers.
| Item | Value |
|---|---|
| Version | 1.0 |
| Effective from | 2 August 2026 |
| Last updated | 2 August 2026 |
| Scope | Web application, iOS application, shared backend |
| Related documents | /dpa, /privacy, /cookie, /diritti-privacy |
| Channel for questions and objections | /contatti |
The tables below are the substance of this document: the paragraphs only exist to explain them. If a row changes, the update date at the top of the page changes too and an entry appears in the change log at the end.
How we select providers
A provider is activated only after passing a fixed set of checks, always applied in the same order. This is not a discretionary assessment: they are minimum requirements, and a provider that fails them does not enter the platform, however convenient or cheap the service may be.
- Sufficient guarantees under Article 28 paragraph 1: a signed data processing agreement, documented security measures, transparency about where data is held.
- An absolute ban on clauses allowing the provider to process data for its own purposes, including training artificial intelligence models, without separate and revocable consent.
- Breach notification within twenty four hours, acceptable up to forty eight.
- An obligation to delete data within thirty days of the end of the relationship, with written confirmation that deletion took place.
- Publication by the provider of its own list of further sub-processors.
- Minimisation: for the same function we choose the provider that receives the smallest amount of data needed.
| Criterion | How it is checked | Consequence of a negative outcome |
|---|---|---|
| Data processing agreement | Reading the contract and the processing terms published by the provider | The provider is not activated |
| Data location | Region declared in the service configuration and in the contractual documentation | The service is configured in another region or dropped |
| Use of data for the provider's own purposes | Clauses on data use and on training artificial intelligence models | Immediate exclusion, with no negotiation |
| Breach notification timing | Contractual clause on notification deadlines to the processor | Request to amend; if refused, an alternative provider is considered |
| Deletion at the end of the relationship | Clause on return, deletion and written confirmation within thirty days | Request to amend; if refused, an alternative provider is considered |
| Further sub-processors | Existence of a public list kept up to date by the provider | The provider is not activated for services handling identifying data |
| Amount of data transmitted | Analysis of the calls actually required by the feature | The integration is redesigned to reduce the data sent |
One term alone is not negotiable. No provider may process user data for its own purposes, and in particular to train artificial intelligence models, without separate, informed and revocable consent. On every other point a less favourable clause can be balanced by technical or organisational measures; on this one it cannot, because data that has entered a model can no longer be retrieved or deleted in any verifiable way. If a provider introduces such a clause into its terms, the service is replaced through the procedure described further down.
List of sub-processors
This is the main table of the document. For each provider it states the service, the categories of data received, where processing takes place and the legal role. The role reads processor because the provider handles data on behalf of Animiyo and under its instructions; towards tenant controllers the same provider is an authorised sub-processor.
| Provider | Service | Data processed | Processing location | Role |
|---|---|---|---|---|
| Google Ireland Limited, with Google LLC as further sub-processor | Firebase Authentication | Email address, user identifier, sign in metadata, federated provider used | us-central1 (United States) | Processor |
| Google Ireland Limited, with Google LLC | Cloud Firestore | All application data: profiles, pets, health record, appointments, budget, walks, orders, conversations, audit log | us-central1 (United States) | Processor |
| Google Ireland Limited, with Google LLC | Cloud Storage for Firebase | Photographs, uploaded documents, consent signatures | us-central1 (United States) | Processor |
| Google Ireland Limited, with Google LLC | Cloud Functions | Server side processing: bookings, notifications, exports, deletions | us-central1 (United States) | Processor |
| Google Ireland Limited, with Google LLC | Cloud Run | Hosting of the web application and request logs | us-central1 (United States) | Processor |
| Google Ireland Limited, with Google LLC | Firebase Cloud Messaging | Device token, push notification content | Global infrastructure | Processor |
| Google Ireland Limited, with Google LLC | Firebase App Check with reCAPTCHA Enterprise | Browser fraud prevention signals, IP address, attestation token | Global infrastructure | Processor |
| Google Ireland Limited, with Google LLC | Google Analytics 4 | Pseudonymous usage data of the public site: page views, language, device, referral source | Global infrastructure | Processor |
| Stripe Payments Europe Limited | Payment processing | No data at present: the integration exists in the code but the gateway is switched off by a configuration flag | European Union | Processor, not active |
The Google group appears eight times rather than once. This is not pointless repetition: each row is a separate service, with its own configuration, its own location and its own category of data. Firebase Authentication knows the email address but not the contents of the health record; Cloud Storage for Firebase holds photographs but knows nothing about appointments; Google Analytics 4 sees only the public site and never the signed in area. Listing the services separately makes it possible to understand which data would be involved in an incident affecting only one of them, and to replace one without touching the others.
The wording global infrastructure marks the services that do not allow a processing region to be chosen: the provider delivers them from a distributed network and data may be handled in more than one location. This applies to push notifications, to fraud prevention checks and to public site measurement, that is to services handling technical identifiers rather than account content. For these cases the transfer basis is the same as described in the section on data location.
Stripe Payments Europe Limited appears in the list even though it receives no data. The integration exists in the code but the gateway is switched off by a configuration flag, so no payment information leaves the platform. The row stays in the table for transparency: the day the flag is switched on it will not be a hidden novelty, and activation will in any case follow the notice period set for sub-processor changes.
External services queried by the browser
Some features of the platform read information from public databases: a medicine data sheet, the nutritional value of a food, a breed description, an exchange rate, a map tile. These are calls that only read data, they start from the user's browser and they carry neither the account identifier nor any diary content. They do, however, transmit the browser IP address and the technical details of the request, which is why they must be declared.
| Service | What it is for | Data it receives |
|---|---|---|
| openFDA | Data sheets on veterinary and human medicines from the United States Food and Drug Administration database | IP address, medicine search term |
| Open Pet Food Facts | Data sheets on pet food from the collaborative database | IP address, barcode or product name |
| dog.ceo | Reference images of dog breeds | IP address, breed name |
| Wikipedia | Encyclopedic entries on breeds and species | IP address, entry title |
| iNaturalist | Taxonomic data and species images | IP address, species name |
| frankfurter.app | Exchange rates used to convert budget expenses | IP address, currency pair |
| tile.openstreetmap.org | Map tiles for the walks map | IP address, coordinates of the requested map area |
These services are not processors, because they do not process data on behalf of Animiyo and receive no instructions from Animiyo on how to use the information they obtain. In relation to the connection data they collect they are independent controllers: they determine purposes and means themselves, apply their own notices and answer directly for their own choices. The difference is not a formality. A processor handles data only as it has been told to and deletes it when asked; an independent controller answers in its own right, and requests concerning that connection data must be addressed to it.
Data location and transfers
The main resources of the platform sit in the us-central1 region, in the United States. This means that account data, uploaded content and system logs are processed outside the European Economic Area, and that the transfer must rest on a valid legal basis as well as on adequate technical measures.
| Service | Region | Transfer basis |
|---|---|---|
| Firebase Authentication | us-central1 (United States) | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Cloud Firestore | us-central1 (United States) | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Cloud Storage for Firebase | us-central1 (United States) | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Cloud Functions | us-central1 (United States) | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Cloud Run | us-central1 (United States) | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Firebase Cloud Messaging | Global infrastructure | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Firebase App Check with reCAPTCHA Enterprise | Global infrastructure | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Google Analytics 4 | Global infrastructure | Standard contractual clauses 2021/914 and EU United States Data Privacy Framework |
| Stripe payment processing | European Union | No transfer to third countries; service not active |
The safeguards accompanying the transfer to the United States are the following.
- Google Ireland Limited as contracting counterparty, under the Google Cloud Data Processing Terms.
- Standard contractual clauses adopted by the European Commission with implementing decision 2021/914.
- Certification of Google LLC under the EU United States Data Privacy Framework.
- Encryption of data in transit with TLS and at rest with AES at 256 bits.
- A transfer impact assessment documented by the owner.
- Google's policy on handling requests from public authorities.
Migrating the resources to a European region, in the europe-west area, is under consideration. It is not a settled decision, because it means rebuilding part of the infrastructure and accepting a window of service unavailability. If it happens, it will be announced on this page with the same notice period set for adding or replacing a sub-processor, so that tenant controllers can update their own documentation before the change takes effect.
Notice, objection and termination
Towards tenant controllers, the use of the listed providers rests on a general authorisation under Article 28 paragraph 4 of Regulation (EU) 2016/679. A general authorisation is not a blank cheque: whoever grants it keeps the right to know in advance what changes and to object. The procedure below describes how that right is exercised in practice.
Publication of the notice
At least thirty days before adding or replacing a sub-processor, the change is published on this page, stating the provider, the service, the data involved and the planned activation date.
Message to the tenant
At the same time as publication, the notice is sent to the email address the tenant has entered in its profile. Keeping that address up to date and monitored is the tenant's responsibility.
Reasoned objection
The tenant may object within fifteen days of the notice, stating the grounds for the objection. Objections are sent from the /contatti page and must be reasoned, that is they must explain which risk or which constraint makes the proposed provider unacceptable.
Search for an alternative measure
Before the activation date we assess whether the objection can be resolved by alternative measures: a different configuration, a different region, a reduction of the data transmitted or a different provider for that function.
Termination without penalty
If the objection cannot be resolved, the tenant controller may terminate without penalty the part of the service affected by the change, in the manner set out in the agreement published at /dpa.
| Stage | Deadline | Channel |
|---|---|---|
| Publication of the notice | At least thirty days before the change | This page |
| Message to the tenant | At the same time as publication | Email address entered by the tenant in the profile |
| Reasoned objection by the tenant | Within fifteen days of the notice | /contatti |
| Proposal of alternative measures | Before the activation date | Email address entered by the tenant in the profile |
| Termination without penalty | If the objection cannot be resolved by alternative measures | /contatti |
| Urgent replacement on security grounds | Shortened notice, with immediate communication | This page and the tenant's email address |
There is a single exception to the thirty day notice. If a provider must be replaced on security grounds, for example after a serious vulnerability or the sudden discontinuation of a service, the replacement may take place with shortened notice. In that case the message to tenants is immediate and the right to object remains intact, but it is exercised after the change rather than before. Waiting thirty days in the face of an ongoing risk would harm exactly the people the procedure is meant to protect.
Providers chosen by the tenant
This list covers the providers chosen by Animiyo to run the platform. It does not cover the providers chosen by the tenant. When a veterinary clinic or a shop connects its own tools, exports data from the platform or passes it to its own providers, those providers do not appear here and remain the tenant's responsibility: the tenant must appoint them as processors and inform its own data subjects.
| Situation | Who answers | What the tenant must do |
|---|---|---|
| The tenant uses the platform services as they are | Animiyo, as processor, within the limits of the agreement at /dpa | Nothing further: the providers listed on this page apply |
| The tenant exports data from the platform and loads it into its own management software | The tenant, as controller | Appoint the software provider as a processor and update its own privacy notice |
| The tenant connects one of its own tools to the data in its workspace | The tenant, as controller | Check the guarantees offered by the tool and add it to its own record of processing activities |
| The tenant passes data to one of its own external providers | The tenant, as controller | Govern the relationship with an agreement under Article 28 and inform its own data subjects |
The distinction matters above all for people who have left their data with a clinic or a shop. If a request concerns a provider the tenant has chosen on its own, it must be addressed to the tenant, because the tenant is the controller of that processing and only the tenant knows which tools it has connected. This page still remains the starting point for understanding which providers are common to everyone and which are not.
What we do not use
A list of sub-processors says a great deal through what it leaves out. The categories of provider below are absent from the platform, and their absence is a design choice, not a temporary situation waiting for budget.
- No advertising network, no data broker, no commercial profiling provider.
- No artificial intelligence model provider receiving user data.
- No third party customer support service with access to the data.
- No marketing email system fed with the user base.
- No sale or transfer of data to third parties.
Each of these entries corresponds to a provider that does not appear in the main table and will not appear without the notice described above. If one of these categories ever became necessary, the addition would follow the same notice and objection procedure set for other providers, and for purposes requiring consent that consent would be collected separately and revocably.
How to stay informed
Every change to this list is published on this same page, which is the authoritative source. Tenant controllers are additionally notified at the email address entered in their profile, because for them the notice has contractual effects and not merely informative ones.
| Type of change | How it is communicated | Notice |
|---|---|---|
| Adding a sub-processor | Publication on this page and message to the tenant | At least thirty days |
| Replacing a sub-processor | Publication on this page and message to the tenant | At least thirty days |
| Urgent replacement on security grounds | Immediate message to the tenant and update of the page | Shortened, with objection afterwards |
| Migration to a European region | Publication on this page and message to the tenant | At least thirty days |
| Removal of a provider no longer used | Update of the table and an entry in the change log | None, it does not add recipients |
| Editorial correction with no substantive effect | Update of the date at the top of the page | None |
The simplest way to tell whether something has changed is to check the update date at the top of the page and compare it with the change log at the end. For questions about the list, to request the contractual documentation relating to a provider or to raise an objection, use the /contatti page, which is the single channel for all communications about this document.
Change log
| Date | Version | Change |
|---|---|---|
| 2 August 2026 | 1.0 | Initial publication: list of sub-processors, external services queried by the browser, data location and transfer bases, notice and objection procedure. |
Later revisions are added to this table and are tracked in the version control history of the code, which preserves the exact text of every version together with the date of the change. Anyone who needs to reconstruct which list was in force at a given moment can ask through the /contatti page.
Frequently asked questions
- Why is the data in the United States and not in Europe?
- The platform resources were created in the us-central1 region and moving them requires rebuilding part of the infrastructure. The transfer rests on the standard contractual clauses adopted by the European Commission with implementing decision 2021/914, on the certification of Google LLC under the EU United States Data Privacy Framework and on a transfer impact assessment documented by the owner. Data is encrypted in transit with TLS and at rest with AES at 256 bits. Migration to a European region in the europe-west area is under consideration and, if it happens, it will be announced on this page with thirty days of notice.
- Can providers use the data to train artificial intelligence models?
- No, and this is the term that is not up for negotiation. No provider may process user data for its own purposes, including model training, without separate and revocable consent. On other contractual points a less favourable clause can be balanced by technical measures, whereas here no balancing is possible: data that has entered a model can no longer be deleted in any verifiable way. If a provider introduced such a clause, the service would be replaced.
- Stripe is on the list but payments are switched off: what does that mean?
- It means that the integration with Stripe Payments Europe Limited exists in the platform code, but the gateway is switched off by a configuration flag. At present no payment data is transmitted to the provider. The row stays published for transparency, so that any future activation does not look like an unannounced novelty. When the service is switched on, activation will follow the thirty day notice period set for sub-processor changes.
- How am I told if a sub-processor changes and how can I object?
- The change is published on this page at least thirty days before it takes effect and, if you are a tenant controller, it is sent to the email address entered in your profile. You may raise a reasoned objection within fifteen days of the notice, using the /contatti page. If the objection cannot be resolved by alternative measures, you may terminate without penalty the part of the service affected. The only replacements with shortened notice are urgent ones on security grounds, where the right to object remains intact but is exercised after the change.
- Do services such as openFDA or Wikipedia receive my pet's data?
- No. Those calls start from the browser and carry only the search term, for example the name of a medicine, the barcode of a food or the name of a breed. They receive neither your user identifier nor any content from your account. They do receive the browser IP address and the technical details of the request, so they are declared in a separate table: in relation to that connection data they are independent controllers and not processors. The owner plans to move these calls to the server, so that your IP address no longer reaches those providers.
In short
If you are an owner, read the sub-processor table together with the recipients section of /privacy: they describe the same perimeter at two levels of detail. If you are a clinic or a shop, save this page in your record of processing activities, make sure the email address in your profile is monitored, because that is where the thirty day notice arrives, and remember that the providers you connect yourself remain your responsibility. Objections and requests for contractual documentation go through the /contatti page.