1. The controller
The operator of the ChiPet Gazdi and ChiPet Menhely applications, and — to the extent set out in section 3 — the data controller, is:
- Name
- Donát Polyák, sole trader (egyéni vállalkozó)
- Registered / postal address
- Újlak utca 5. 4/39, 1173 Budapest, Hungary
- Registration number
- 62171436
- Tax number
- 91963631-1-42
- D-U-N-S number
- 302350030
- adatvedelem@chipet.app
- Phone
- +36 30 301 7733
- Website
- https://chipet.app
2. Scope
This notice covers the following services:
- ChiPet Gazdi — the app for pet owners (iOS, Android, web:
gazdi.chipet.app), in which a user stores their own animals' details, medical history and documents; - ChiPet Menhely — the app for rescue organisations and shelters (iOS, Android, web:
menhely.chipet.app), in which an organisation manages its animals, medical events, adoptions, events and staff; - the
chipet.appwebsite and the associatedapi.chipet.appserver; - publicly shared animal profiles (section 6).
The two applications use a single shared database. This is what allows an animal's record to move into the Gazdi app on adoption — where the organisation and the adopter intend it — without re-entering the data. The shared backend does not mean that organisations can see owners' private data, or that owners can see organisations' internal data: access is restricted by row-level security (RLS) rules.
3. Roles: when we are a controller and when we are a processor
This is the most important distinction in this notice, so we set it out separately.
3.1 Our own processing (we are the controller)
- user accounts and sign-in (in both applications);
- in the Gazdi app, the animals a user records as their own, and their documents;
- sending notifications and handling device identifiers;
- operational, security and logging data;
- support correspondence.
3.2 Organisation processing (the organisation is the controller, we are a processor)
When a rescue organisation records, for example, an adopter's or a foster carer's details in the ChiPet Menhely app, it is the organisation that determines the purposes and means of that processing. There, the organisation is the controller and we act solely as a processor, on the organisation's instructions. That relationship is governed by a separate data processing agreement (Article 28 GDPR), which we conclude with every organisation.
If you are an adopter, a foster carer or an event participant and wish to raise a question or a request about your data, please contact the organisation concerned first. If you contact us, we will forward your request to the organisation without delay and assist in fulfilling it.
4. What data we process
The list below is based on the fields actually stored in the system. Where providing a piece of data is optional, we say so.
4.1 Account and profile data
- e-mail address (required; it is also the identifier);
- password — stored only as a one-way hash; we never store a readable password;
- name;
- phone number (optional);
- city, country (optional; country also determines the language of our e-mails);
- profile picture (optional);
- user ID, account creation time, last sign-in;
- a flag indicating whether the account is owner-side only;
- one-time sign-in and confirmation codes (valid for 1 hour).
4.2 Animal data
- name, breed, colour, date of birth, sex, neutered status;
- microchip number;
- custom identifier, date and circumstances of intake, free-text notes;
- photographs and uploaded documents;
- an optional public Facebook album link;
- ownership data: who the current owner is, from when, until when, and which organisation the animal came from.
4.3 Health and treatment data (relating to the animal)
- blood type, date of neutering;
- heartworm status and start of treatment;
- whether under treatment, date of last treatment;
- medical history timeline: event date, title, description, category, state;
- medical documents (vaccination record, lab result, invoice) — held in non-public storage.
4.4 Adoption data heightened protection
If you adopt an animal from an organisation, the organisation records the following in the system for the adoption contract:
- full name, date of birth;
- home address, phone number, e-mail address;
- identity document number, issuing authority and date of issue;
- a scan or photograph of the signed adoption contract;
- probation period data (start, end, completion), where the organisation operates one;
- answers extracted from the completed contract fields, and a record of who reviewed the data and when.
For this processing, the organisation is the controller (section 3.2). The system is built so that this data is accessible only to authorised staff of that organisation, and every access to a document is logged.
4.5 Event data
Organisations can publish events (dog walks, courses, open days). In connection with these we process:
- for a registered user signing up: user ID, chosen animal, party size, note, signup status, check-in time;
- for a walk-in (unregistered) guest: name, e-mail address, phone number, party size and note — entered by a member of the organisation's staff;
- the names and roles of staff and trainers assigned to the event.
4.6 Temporary fostering and boarding
In the Gazdi app an owner can temporarily share an animal's record with someone else (for example while on holiday). For this we process:
- the nominated carer's e-mail address — supplied by the owner, and therefore obtained from a third party;
- the start and end of the boarding period and the owner's note;
- a one-time access code allowing the carer to access that animal's record without registering.
We send an invitation e-mail to that address containing the animal's name, the end date, the owner's note and the code. If you received such a message and do not wish to use the service, simply ignore it: the invitation expires and the record is deleted automatically.
4.7 Ownership transfer and claim codes
When an organisation hands an animal's record over to the adopter, it creates a one-time, expiring code, associated with an e-mail address, the creator of the code, creation and expiry times, and whether and when it was redeemed.
4.8 Organisation membership and staff data
- which organisation a user belongs to and in what role (e.g. administrator, shelter worker, trainer, veterinarian);
- invitations and their status;
- favourited organisation, followed organisations.
4.9 Notifications and device identifiers
- push token (the device identifier issued by Google Firebase Cloud Messaging), platform (iOS/Android), and which app it came from;
- the notification's title, body, type, target and the ID of the animal/event concerned;
- delivery status and time of reading;
- the fact and time of sending e-mail reminders.
4.10 Log and technical data
- document access log: which user, acting for which organisation, accessed which animal's document, when, and what action they performed;
- server error logs and request logs (which may contain IP address, device and browser type, and request time);
- authentication events (sign-in, password change, e-mail address change);
- e-mail dispatch logs — in which the address is stored masked (e.g.
a***@gmail.com).
4.11 Error reporting and diagnostic data
We use the Sentry error monitoring service to detect faults in the applications and web interfaces. When an error occurs during operation, an error report is generated automatically, which may contain:
- a technical description of the error: error message, stack trace, the relevant fragment of code;
- the device type, the operating system and app version numbers, language and display settings, and for the web interface the browser type;
- a breadcrumb trail of the last few actions before the error and the web addresses called;
- the signed-in user's identifier and the IP address;
- the time of the error.
Error reports are used solely to find and fix faults. We do not use them for analytics, for tracking user behaviour or for marketing. Password-type fields are filtered out automatically by the service, and error reports contain no uploaded documents (medical records or adoption contracts).
4.12 What we do not process
We do not collect GPS or other location data, do not use advertising identifiers and do not track users across other apps or websites. We do not sell personal data and do not disclose it to third parties for marketing purposes.
5. Purposes and legal bases
Every processing operation has a defined purpose and a legal basis under Article 6 GDPR.
This data is indispensable: without it the service cannot be provided.
6. Publicly visible content
Some content is deliberately public, because that is the point of the service. Please bear this in mind before entering data.
6.1 Public animal profiles
If an organisation shares an animal's profile, that profile can be viewed via a unique link without signing in. The public profile contains the animal's name, date of birth, breed, colour, sex, free-text description, intake date, the list of completed medical events, photographs, and the organisation's name, address, e-mail address, phone number and website.
The public profile does not show any owner's or adopter's name or contact details, nor the microchip number.
6.2 Public storage
Animal photographs and profile pictures are held in storage that can be reached without signing in by anyone who knows the direct file link. Medical documents and adoption contracts, by contrast, are held in private storage and can only be accessed after an authorisation check, through a time-limited link.
7. Recipients and processors
We use the service providers listed below. A data processing agreement is in place with each, and each has access only for the purpose and to the data stated.
eu-central-1 — Frankfurt, Germany) The infrastructure running the database and storage.chipet.app website and the api.chipet.app mail relay server. The servers are located in Budapest, Hungary. Data transferred: the recipient, subject and content of outgoing mail, and server log data.8. Transfers outside the European Economic Area
The database, uploaded files and server functions run in the European Union (Frankfurt, Germany). The servers of the hosting provider that operates the website and the mail relay are located in Hungary (Budapest).
Transfers to a third country (the United States) take place only in the following limited respects:
- to Google and Apple for delivering push notifications (device token, notification text);
- to Sentry (Functional Software, Inc.) for processing error reports (the data described in section 4.11);
- to Supabase Inc. in the course of operational support.
These transfers rely on the European Commission's Standard Contractual Clauses (SCCs, Implementing Decision (EU) 2021/914) and, where the provider is certified, on the adequacy decision for the EU–U.S. Data Privacy Framework. Copies of the relevant agreements are available on request.
9. Retention periods
10. Security
In line with Article 32 GDPR we apply technical and organisational measures proportionate to the risk:
- all network traffic is encrypted (TLS); the database and storage are encrypted at rest;
- row-level security (RLS) in the database: which organisation's and which animal's data a user can see is decided at query level;
- role-based access within organisations (administrator, worker, trainer, veterinarian);
- medical documents and adoption contracts are held in private storage, reachable only through checked, time-limited links;
- every access to a document is logged;
- passwords are stored only as one-way hashes, using industry-standard algorithms;
- one-time codes valid for 1 hour;
- regular backups; operator access limited to the necessary minimum;
- e-mail addresses are masked in our logs.
In the event of a personal data breach we will notify the Hungarian National Authority for Data Protection and Freedom of Information without undue delay and within 72 hours of becoming aware of it, and will inform data subjects where the breach is likely to result in a high risk. Where we act as a processor, we will notify the organisation concerned without delay.
11. Your rights
Under Chapter III of the GDPR you have the following rights:
- Access (Art. 15) — you may ask whether we process your data and request a copy of it.
- Rectification (Art. 16) — you may ask for inaccurate data to be corrected. Most profile data can be edited directly in the app.
- Erasure (Art. 17) — you may request deletion of your data. An account can also be deleted from within the app. Erasure does not extend to data we are required by law to retain or that is needed to establish or defend legal claims.
- Restriction of processing (Art. 18).
- Data portability (Art. 20) — you may request data processed on the basis of contract or consent in a machine-readable format (JSON).
- Objection (Art. 21) — you may object to processing based on legitimate interests.
- Withdrawal of consent (Art. 7(3)) — withdrawal does not affect the lawfulness of processing carried out beforehand.
How to exercise your rights. Write to adatvedelem@chipet.app, or use Settings → Privacy in the app. We will respond within one month; for complex requests this may be extended by a further two months, of which we will inform you. Responding is free of charge; for manifestly unfounded or repetitive requests we may charge a reasonable fee or refuse to act.
Before acting on a request we may need to identify you — writing from the e-mail address registered to your account is sufficient.
12. Remedies
If you believe your data is being processed unlawfully, please contact us first — most questions can be resolved that way most quickly.
You may lodge a complaint with the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)Address: Falk Miksa utca 9–11, 1055 Budapest, Hungary
Postal address: 1363 Budapest, Pf. 9, Hungary
Phone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu Web: https://naih.hu
You may also bring proceedings before a court. The action may be brought before the regional court with jurisdiction over your place of residence or stay. The proceedings are exempt from court fees.
If you do not live in Hungary, you may also complain to the supervisory authority of the Member State of your habitual residence or place of work.
13. Automated decision-making and profiling
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).
Two automated helper processes operate, both with human review:
- Contract reading: from an uploaded adoption contract the system proposes values for data fields (name, date of birth, address, phone number, document number). These are proposals: a member of the organisation's staff checks and approves them before they enter the record.
- Microchip check: the system compares the chip number on the contract with the animal's recorded chip number and flags any discrepancy to staff.
We do not carry out profiling for marketing or scoring purposes.
14. Children
Our services are intended for persons aged 16 or over. We do not knowingly collect personal data from anyone under 16. If we learn that such data has entered the system without the consent of the holder of parental responsibility, we will delete it without delay.
For event signups, a minor may be registered by a parent or legal guardian by stating the party size; we record no separate data about the minor.
15. Cookies and local storage
The web interfaces (gazdi.chipet.app, menhely.chipet.app) use only strictly necessary cookies and local storage:
- session and refresh tokens — to keep you signed in;
- language and display settings;
- temporary form data.
Under the e-privacy rules these do not require consent. We use no analytics, advertising or social media cookies. The error monitoring service described in section 4.11 likewise sets no cookies and does not analyse user behaviour.
The mobile apps store the sign-in token and app settings locally on the device; these are removed when the app is uninstalled.
16. Changes to this notice
We may update this notice from time to time — for example when we introduce a new feature or when the law changes. The version in force at any time is available at https://chipet.app/privacy.
We will give notice of any material change by e-mail or in the app at least 15 days before it takes effect. The version number and effective date are always shown at the top of this notice.