What this document is
It is the contract required by Article 28 of the General Data Protection Regulation when someone processes personal data on someone else's behalf. It binds both parties from the moment the shelter accepts it.
- The shelter is the controller of the data of the people who deal with it through Pets: whoever submits an application, whoever fosters an animal, whoever is part of its team. It decides what it asks, what it keeps, what for and for how long.
- We are the processor: we store that data, show it to whoever the shelter authorises and do nothing else with it.
For the data of the account each person signs in with, for their adopter profile before they send it to a shelter and for their contribution as a crew member, we answer as controller. That is not governed by this document but by the privacy policy, in the section "Two different roles".
This agreement is read together with the terms of use, of which it forms part. If anything here conflicts with them, this document prevails as far as personal data is concerned.
Who each party is
Controller: the shelter. The organisation that was registered in Pets, with the name and contact details it put in its request. It acts through whoever administers the shelter in the dashboard, or whoever that person designates.
Processor:
- Germán Ezequiel Laso Andino, sole trader (libero professionista), who operates under the trade name ProfBlu.
- VAT number (Partita IVA): 04702090988.
- Codice fiscale: LSNGMN88S04Z600M.
- Professional activity not registered in the Italian Business Register (Registro delle Imprese) (no REA number).
- Contact address: Via della Sega 1, 38080 Verdesina, Porte di Rendena (TN), Italia.
- Email for this contract: legal@profblu.com. For any data matter, privacidad@profblu.com.
No data protection officer has been appointed: the law does not require one for an activity of this size.
Where and when it is accepted
This agreement is accepted in the Pets dashboard, in Settings → Shelter, in the "Data protection" card, with an account that can administer the shelter's settings. Until it is accepted, the dashboard gives a reminder in that same card.
Of that acceptance we store three things, and only three: the date and time, the version of this document — which is its revision date, the one shown above — and who accepted it. The card shows it afterwards; it is the proof that the contract exists and of which text was accepted.
When we change this document we will give notice in advance, and the new version is accepted the same way. The card says which version is accepted and which is in force.
Subject matter, nature and duration
- Subject matter: providing Pets to the shelter — publishing its animals, receiving interest and applications, handling them and organising its care and fosters — and, in order to provide it, processing the personal data that comes in that way.
- Nature and purpose: only the operations needed for the tool to work. Collecting what applicants send and what the team writes, storing it, organising it, showing it to whoever the shelter authorises, modifying it when they modify it and erasing it when an erasure is asked of us. Nothing else.
- Duration: as long as the shelter has Pets active. It starts the day it is accepted and ends when the shelter deregisters, when we stop providing the service or when either party terminates it as set out below.
What data, and about whom
Categories of data subjects:
- The applicants: whoever shows interest in one of the shelter's animals and whoever submits an application to it.
- The people who foster one of the shelter's animals.
- The people on the shelter's team, in so far as they appear tied to that data: who writes a message, who assesses, who records a delivery of supplies.
Categories of data, as the application collects them:
- About whoever shows interest: that they are interested in a specific animal, when they said so and how it ended.
- About whoever submits an application, the copy of their adopter profile as it stood when it was sent: type of home, whether it has outdoor space, whether they are allowed animals, number of adults and of minors at home, previous experience and other animals, preferences, and whatever they have written in the free-text fields; and their answers to the shelter's questionnaire.
- The messages between the applicant and the shelter.
- The appointments: type, date, place, who attends and the notes on the outcome.
- The documents the shelter asks to be accepted and the record of their acceptance.
- The assessment of each application and the team's internal notes.
- The contributions the shelter records as received.
- About foster homes: who the contact person is, the capacity, which animals it is compatible with and the team's notes.
Pets does not ask for special categories of data under Article 9 GDPR. The free-text fields — the notes, the messages, the assessment — are written by people: the shelter undertakes not to use them to note down health data, beliefs or other sensitive information about a person. The health data Pets stores is that of the animals.
We do not process payment data on the shelter's behalf: Pets charges nothing, and what is recorded as a contribution is a ledger entry.
We only do what the shelter tells us
We process that data solely on the shelter's documented instructions. Its instructions are this contract, the terms of use and each thing its team does in the dashboard and in the application: reciprocating an interest, advancing or rejecting an application, writing a message, closing a case or asking us for an erasure.
Therefore:
- We do not use the shelter's data for anything of our own. No analytics, no advertising, no profiling, no training of models, and no disclosure or sale to anyone. Nothing in the code does it.
- We do not transfer it outside the European Economic Area except as stated in the list of sub-processors below.
- If a law of the Union or of a Member State requires us to process otherwise, we will tell the shelter before doing so, unless that same law forbids it.
- If an instruction from the shelter seems to us contrary to the GDPR, we will say so.
Confidentiality
Whoever has access to this data is bound by confidentiality, and that obligation survives the end of this agreement. Today, technical access to the database is held by one single person, the owner of ProfBlu. If tomorrow there are more, they will sign confidentiality before having access and will access only what their work requires.
Inside the shelter, who sees what is decided by the shelter with the roles it hands out: administration, care team, adoption team and read-only. We enforce that allocation; we do not choose for it.
Security measures
The ones that really exist, not a catalogue list:
- All traffic is encrypted with TLS, the application's and the dashboard's.
- The shelters are isolated from one another: each item of data carries the shelter it belongs to, and requesting an item of data belonging to one shelter with another's session does not return the data.
- Access depends on each person's role within their shelter.
- The audit log records each change without identifiers in the clear: the person and the animal appear as a pseudonym calculated with a key that only the server holds.
- The photos are stored in Hetzner's object storage in Nuremberg and are served with signed links that expire after fifteen minutes.
- The phone's session credentials live in the phone's own secure store.
And what there is not, so that nobody takes it for granted: we do not encrypt field by field inside the database, there is no external security certification and Pets runs today in a demonstration environment without scheduled backups. Until that changes — and this document will say so with its date — data of real people must not be loaded.
Sub-processors
The shelter gives us general authorisation to use other companies to provide the service. This is the complete list as of today:
- Hetzner Online GmbH — hosting of the server, the database and the photos, in Germany. Inside the EEA.
- Expo, Inc. — relay of the notifications to the phone, when they are turned on: it receives the device identifier and the text of the notification in order to deliver it to Apple or Google. It is in the United States and is covered by the safeguards of Chapter V GDPR (standard contractual clauses).
- Apple Inc. and Google LLC — when the application is distributed through their stores, as stores and as those who deliver the notifications. They do not access the shelter's database.
- Anthropic, PBC — only if someone on the shelter's team uses the dashboard's assistant: what that person writes to it and what the assistant looks up in order to answer passes through its model, in the United States, with the safeguards of Chapter V. Whoever does not use the assistant sends nothing.
With each of them the same data protection obligations this contract imposes are maintained, and we are liable to the shelter for what they do just as if we had done it ourselves.
If we are going to change the list we will notify whoever administers the shelter, by email and inside the dashboard, at least thirty days in advance. Within that period they may object in writing. If they object and there is no other reasonable way of providing the service, either party may terminate this agreement without cost or penalty.
Help with data subjects' rights
The rights of an applicant over what the shelter keeps about them — access, rectification, erasure, portability, objection and restriction — are exercised with the shelter, which is the controller. Our job is to make sure it can deal with them:
- The shelter consults the complete application, with its history, from the dashboard.
- The applicant can withdraw their application or their interest from the application. Withdrawing it closes the process; it does not erase what is already stored.
- The definitive erasure of a person's data is requested from us at privacidad@profblu.com and we carry it out, on the shelter's instruction.
If a request reaches us, we do not answer it on the shelter's behalf: we pass it on without undue delay and help with whatever is needed. We answer directly only the part that concerns the account data.
We also help the shelter, with the information we have, if it needs to carry out an impact assessment or consult the supervisory authority.
If there is a security breach
If we detect a personal data breach affecting the shelter's data, we will tell it without undue delay once we become aware of it, at the email of whoever administers it. We will tell it what we know: what has happened, which data and how many people it affects, what consequences we foresee and what we are doing.
The 72 hours for notifying the supervisory authority run for the shelter, which is the controller; our obligation is to warn it in time and give it what it needs to meet that deadline.
Information and verification
The shelter may ask us in writing for the information necessary to verify that we comply with this contract, and we provide it within one month. It may also request an audit; it is agreed with reasonable notice, no more than once a year unless there has been an incident, it is carried out without putting other shelters' data at risk and it is at the expense of whoever requests it.
What happens when this ends
This is what really happens:
- When the shelter is deregistered, its team's access to the dashboard and to the application is closed. The data is not erased by itself: it remains stored and inactive. The published animals are not removed by themselves either: it is advisable to unpublish them before deregistering, or to ask us to.
- Return and erasure are on request. Today the dashboard has no complete export: the shelter asks us for its data at privacidad@profblu.com from the email of whoever administers it and we deliver it in a readable format. With the same request, or with another, we erase it.
- The retention periods per class of data have been drafted and are pending approval. As long as they are not approved there is no automatic erasure: the shelter decides how long it keeps the data and tells us.
- What the law requires to be kept is kept, together with the record that this agreement was accepted, with its date and its version, which is the proof that the contract existed.
What falls to the shelter
As controller, the shelter undertakes to:
- Have a legal basis for what it asks and keeps, and ask only for what it needs to decide an adoption.
- Inform the applicants of what it keeps about them, what for and for how long, and show them this information and the privacy policy.
- Not use the free-text fields to note down sensitive data about a person.
- Have permission for each photo it publishes, and record it.
- Give its instructions through the channels of the product and of this contract, and make sure they are lawful.
- Look after its team's access: give each person the role that corresponds to them, withdraw it when they stop collaborating and not share passwords. What is done by whoever signs in with one of the shelter's credentials is the shelter's.
Liability
Each party answers for its own part: the shelter for what it decides to process and for the instructions it gives, and we for complying with this contract and for what our sub-processors do. Neither of the two answers for what the other does on its own account.
Changes to this agreement
If we change this document, we change its revision date and give sufficient advance notice, inside the dashboard or by email. The accepted version and the date are recorded, as stated above.
Governing law
Italian law applies, which is that of the place of domicile of the owner of ProfBlu, with the GDPR above it. For disputes between the shelter and us, the courts of that place of domicile have jurisdiction.