Privacy Policy

ChiPet Gazdi and ChiPet Menhely — iOS, Android and web

Version 1.0 · Effective: 27 September 2026 · Last updated: 27 September 2026

1. The controller

The operator of the ChiPet Gazdi and ChiPet Menhely applications, and — to the extent set out in section 3 — the data controller, is:

Name
Donát Polyák, sole trader (egyéni vállalkozó)
Registered / postal address
Újlak utca 5. 4/39, 1173 Budapest, Hungary
Registration number
62171436
Tax number
91963631-1-42
D-U-N-S number
302350030
E-mail
adatvedelem@chipet.app
Phone
+36 30 301 7733
Website
https://chipet.app

2. Scope

This notice covers the following services:

  • ChiPet Gazdi — the app for pet owners (iOS, Android, web: gazdi.chipet.app), in which a user stores their own animals' details, medical history and documents;
  • ChiPet Menhely — the app for rescue organisations and shelters (iOS, Android, web: menhely.chipet.app), in which an organisation manages its animals, medical events, adoptions, events and staff;
  • the chipet.app website and the associated api.chipet.app server;
  • publicly shared animal profiles (section 6).

The two applications use a single shared database. This is what allows an animal's record to move into the Gazdi app on adoption — where the organisation and the adopter intend it — without re-entering the data. The shared backend does not mean that organisations can see owners' private data, or that owners can see organisations' internal data: access is restricted by row-level security (RLS) rules.

3. Roles: when we are a controller and when we are a processor

This is the most important distinction in this notice, so we set it out separately.

3.1 Our own processing (we are the controller)

  • user accounts and sign-in (in both applications);
  • in the Gazdi app, the animals a user records as their own, and their documents;
  • sending notifications and handling device identifiers;
  • operational, security and logging data;
  • support correspondence.

3.2 Organisation processing (the organisation is the controller, we are a processor)

When a rescue organisation records, for example, an adopter's or a foster carer's details in the ChiPet Menhely app, it is the organisation that determines the purposes and means of that processing. There, the organisation is the controller and we act solely as a processor, on the organisation's instructions. That relationship is governed by a separate data processing agreement (Article 28 GDPR), which we conclude with every organisation.

If you are an adopter, a foster carer or an event participant and wish to raise a question or a request about your data, please contact the organisation concerned first. If you contact us, we will forward your request to the organisation without delay and assist in fulfilling it.

4. What data we process

The list below is based on the fields actually stored in the system. Where providing a piece of data is optional, we say so.

4.1 Account and profile data

  • e-mail address (required; it is also the identifier);
  • password — stored only as a one-way hash; we never store a readable password;
  • name;
  • phone number (optional);
  • city, country (optional; country also determines the language of our e-mails);
  • profile picture (optional);
  • user ID, account creation time, last sign-in;
  • a flag indicating whether the account is owner-side only;
  • one-time sign-in and confirmation codes (valid for 1 hour).

4.2 Animal data

  • name, breed, colour, date of birth, sex, neutered status;
  • microchip number;
  • custom identifier, date and circumstances of intake, free-text notes;
  • photographs and uploaded documents;
  • an optional public Facebook album link;
  • ownership data: who the current owner is, from when, until when, and which organisation the animal came from.

4.3 Health and treatment data (relating to the animal)

  • blood type, date of neutering;
  • heartworm status and start of treatment;
  • whether under treatment, date of last treatment;
  • medical history timeline: event date, title, description, category, state;
  • medical documents (vaccination record, lab result, invoice) — held in non-public storage.

4.4 Adoption data heightened protection

If you adopt an animal from an organisation, the organisation records the following in the system for the adoption contract:

  • full name, date of birth;
  • home address, phone number, e-mail address;
  • identity document number, issuing authority and date of issue;
  • a scan or photograph of the signed adoption contract;
  • probation period data (start, end, completion), where the organisation operates one;
  • answers extracted from the completed contract fields, and a record of who reviewed the data and when.

For this processing, the organisation is the controller (section 3.2). The system is built so that this data is accessible only to authorised staff of that organisation, and every access to a document is logged.

4.5 Event data

Organisations can publish events (dog walks, courses, open days). In connection with these we process:

  • for a registered user signing up: user ID, chosen animal, party size, note, signup status, check-in time;
  • for a walk-in (unregistered) guest: name, e-mail address, phone number, party size and note — entered by a member of the organisation's staff;
  • the names and roles of staff and trainers assigned to the event.

4.6 Temporary fostering and boarding

In the Gazdi app an owner can temporarily share an animal's record with someone else (for example while on holiday). For this we process:

  • the nominated carer's e-mail address — supplied by the owner, and therefore obtained from a third party;
  • the start and end of the boarding period and the owner's note;
  • a one-time access code allowing the carer to access that animal's record without registering.

We send an invitation e-mail to that address containing the animal's name, the end date, the owner's note and the code. If you received such a message and do not wish to use the service, simply ignore it: the invitation expires and the record is deleted automatically.

4.7 Ownership transfer and claim codes

When an organisation hands an animal's record over to the adopter, it creates a one-time, expiring code, associated with an e-mail address, the creator of the code, creation and expiry times, and whether and when it was redeemed.

4.8 Organisation membership and staff data

  • which organisation a user belongs to and in what role (e.g. administrator, shelter worker, trainer, veterinarian);
  • invitations and their status;
  • favourited organisation, followed organisations.

4.9 Notifications and device identifiers

  • push token (the device identifier issued by Google Firebase Cloud Messaging), platform (iOS/Android), and which app it came from;
  • the notification's title, body, type, target and the ID of the animal/event concerned;
  • delivery status and time of reading;
  • the fact and time of sending e-mail reminders.

4.10 Log and technical data

  • document access log: which user, acting for which organisation, accessed which animal's document, when, and what action they performed;
  • server error logs and request logs (which may contain IP address, device and browser type, and request time);
  • authentication events (sign-in, password change, e-mail address change);
  • e-mail dispatch logs — in which the address is stored masked (e.g. a***@gmail.com).

4.11 Error reporting and diagnostic data

We use the Sentry error monitoring service to detect faults in the applications and web interfaces. When an error occurs during operation, an error report is generated automatically, which may contain:

  • a technical description of the error: error message, stack trace, the relevant fragment of code;
  • the device type, the operating system and app version numbers, language and display settings, and for the web interface the browser type;
  • a breadcrumb trail of the last few actions before the error and the web addresses called;
  • the signed-in user's identifier and the IP address;
  • the time of the error.

Error reports are used solely to find and fix faults. We do not use them for analytics, for tracking user behaviour or for marketing. Password-type fields are filtered out automatically by the service, and error reports contain no uploaded documents (medical records or adoption contracts).

4.12 What we do not process

no location trackingno advertising identifiersno ad profilingno sale of datano purchased third-party data

We do not collect GPS or other location data, do not use advertising identifiers and do not track users across other apps or websites. We do not sell personal data and do not disclose it to third parties for marketing purposes.

5. Purposes and legal bases

Every processing operation has a defined purpose and a legal basis under Article 6 GDPR.

Creating an account, signing in, providing the serviceLegal basis: performance of a contract — Art. 6(1)(b) GDPR.

This data is indispensable: without it the service cannot be provided.

Authentication e-mails, one-time codes, password resetLegal basis: performance of a contract — Art. 6(1)(b).
Storing an animal's record, medical history and documentsLegal basis: performance of a contract — Art. 6(1)(b).
Push and e-mail notifications about your animals, due treatments and eventsLegal basis: performance of a contract — Art. 6(1)(b); where we ask for permission at device level, additionally your consent — Art. 6(1)(a). Notifications can be switched off at any time in the app or in your device settings.
Preparing and performing the adoption contract, identifying the adopter, tracking the probation periodLegal basis: performance of a contract — Art. 6(1)(b) — and the organisation's legitimate interest — Art. 6(1)(f) — in following up on the animal and placing animals responsibly. Controller: the organisation.
Temporary fostering and sending a boarding invitationLegal basis: performance of the contract between the owner and us — Art. 6(1)(b) — and, as regards the nominated carer, the owner's and our legitimate interest — Art. 6(1)(f) — in handing the animal over safely. The invitation is a single, non-marketing message.
Organising events, managing signups, on-site registrationLegal basis: performance of a contract — Art. 6(1)(b) — for registered participants; for walk-in guests, the organisation's legitimate interest — Art. 6(1)(f) — in running the event safely, or the guest's consent — Art. 6(1)(a).
Publicly sharing an animal's profile to help it find a homeLegal basis: the organisation's legitimate interest — Art. 6(1)(f) — in placing the animal. Sharing is the organisation's decision and can be withdrawn at any time.
System security, abuse prevention, logging of document accessLegal basis: legitimate interest — Art. 6(1)(f) — and legal obligation — Art. 6(1)(c) — to meet the security requirements of Article 32 GDPR.
Support and complaint handlingLegal basis: legitimate interest — Art. 6(1)(f).
Establishing, exercising and defending legal claims; responding to lawful requests from authoritiesLegal basis: legitimate interest — Art. 6(1)(f) — and legal obligation — Art. 6(1)(c).

6. Publicly visible content

Some content is deliberately public, because that is the point of the service. Please bear this in mind before entering data.

6.1 Public animal profiles

If an organisation shares an animal's profile, that profile can be viewed via a unique link without signing in. The public profile contains the animal's name, date of birth, breed, colour, sex, free-text description, intake date, the list of completed medical events, photographs, and the organisation's name, address, e-mail address, phone number and website.

The public profile does not show any owner's or adopter's name or contact details, nor the microchip number.

6.2 Public storage

Animal photographs and profile pictures are held in storage that can be reached without signing in by anyone who knows the direct file link. Medical documents and adoption contracts, by contrast, are held in private storage and can only be accessed after an authorisation check, through a time-limited link.

7. Recipients and processors

We use the service providers listed below. A data processing agreement is in place with each, and each has access only for the purpose and to the data stated.

Supabase Inc. (USA; the database itself runs in the European Union, in Frankfurt) Database, authentication, file storage, server functions. Access: to all stored data.
Amazon Web Services EMEA SARL (Luxembourg; eu-central-1 — Frankfurt, Germany) The infrastructure running the database and storage.
Google Ireland Ltd. / Google LLC — Firebase Cloud Messaging Delivery of push notifications. Data transferred: the device push token, the notification title and body, and the ID of the animal or event concerned. No name, e-mail address, phone number or address is transferred.
Apple Inc. / Apple Distribution International Ltd. — Apple Push Notification service Delivery of notifications to iOS devices (via Google's service), and distribution of the app through the App Store.
DotRoll Számítástechnikai Kft. — hosting Registered office: Fogarasi út 3–5, 1148 Budapest, Hungary · Company reg. no.: 01-09-882068 · Tax no.: 13962982-2-42 · E-mail: support@dotroll.com Operation of the chipet.app website and the api.chipet.app mail relay server. The servers are located in Budapest, Hungary. Data transferred: the recipient, subject and content of outgoing mail, and server log data.
Functional Software, Inc. (d/b/a Sentry) — error monitoring Registered office: 45 Fremont Street, 8th Floor, San Francisco, CA 94105, United States. EU representative: Sentry Software Netherlands B.V., Schiphol Boulevard 359, 1118 BJ Amsterdam, the Netherlands. Data transferred: the error reports described in section 4.11, including IP address and user identifier.
Google Play (Google Ireland Ltd.) and the Apple App Store — distribution of the apps and installation/crash statistics, which we receive in aggregated form.
Rescue organisations — as independent controllers under section 3.2, solely in respect of data belonging to their own organisation.
Authorities and courts — upon a lawful request based on legislation.

8. Transfers outside the European Economic Area

The database, uploaded files and server functions run in the European Union (Frankfurt, Germany). The servers of the hosting provider that operates the website and the mail relay are located in Hungary (Budapest).

Transfers to a third country (the United States) take place only in the following limited respects:

  • to Google and Apple for delivering push notifications (device token, notification text);
  • to Sentry (Functional Software, Inc.) for processing error reports (the data described in section 4.11);
  • to Supabase Inc. in the course of operational support.

These transfers rely on the European Commission's Standard Contractual Clauses (SCCs, Implementing Decision (EU) 2021/914) and, where the provider is certified, on the adequacy decision for the EU–U.S. Data Privacy Framework. Copies of the relevant agreements are available on request.

9. Retention periods

Account data: for as long as the account exists. On deletion it is removed from the live system immediately and from backups within 30 days at the latest.
Animal data, medical history, documents: until deleted by the owner or the organisation, or until the account is deleted.
Adoption data and signed contracts: for the period determined by the organisation (as controller) — typically the civil-law limitation period (5 years), or 8 years where the document is an accounting record under Act C of 2000 on Accounting. The system provides a dedicated erasure request workflow: a request can be recorded, the organisation must decide within a deadline, and overdue requests are escalated automatically.
Notification history: deleted automatically after 90 days.
Ownership transfer and claim codes: deleted automatically 7 days after redemption or expiry.
Temporary boarding records: deleted by an automatic weekly clean-up after the period ends or is cancelled; unredeemed invitations expire through a process that runs every 15 minutes.
Event data and guest data: 12 months after the event, then deleted.
Document access log: 12 months — this also serves as evidence of accountability.
Server and error logs: up to 30 days.
Error reports (Sentry): up to 90 days at the provider, after which they are deleted automatically.
Support correspondence: 1 year after the matter is closed; in the event of a dispute, until it is finally resolved.

10. Security

In line with Article 32 GDPR we apply technical and organisational measures proportionate to the risk:

  • all network traffic is encrypted (TLS); the database and storage are encrypted at rest;
  • row-level security (RLS) in the database: which organisation's and which animal's data a user can see is decided at query level;
  • role-based access within organisations (administrator, worker, trainer, veterinarian);
  • medical documents and adoption contracts are held in private storage, reachable only through checked, time-limited links;
  • every access to a document is logged;
  • passwords are stored only as one-way hashes, using industry-standard algorithms;
  • one-time codes valid for 1 hour;
  • regular backups; operator access limited to the necessary minimum;
  • e-mail addresses are masked in our logs.

In the event of a personal data breach we will notify the Hungarian National Authority for Data Protection and Freedom of Information without undue delay and within 72 hours of becoming aware of it, and will inform data subjects where the breach is likely to result in a high risk. Where we act as a processor, we will notify the organisation concerned without delay.

11. Your rights

Under Chapter III of the GDPR you have the following rights:

  • Access (Art. 15) — you may ask whether we process your data and request a copy of it.
  • Rectification (Art. 16) — you may ask for inaccurate data to be corrected. Most profile data can be edited directly in the app.
  • Erasure (Art. 17) — you may request deletion of your data. An account can also be deleted from within the app. Erasure does not extend to data we are required by law to retain or that is needed to establish or defend legal claims.
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20) — you may request data processed on the basis of contract or consent in a machine-readable format (JSON).
  • Objection (Art. 21) — you may object to processing based on legitimate interests.
  • Withdrawal of consent (Art. 7(3)) — withdrawal does not affect the lawfulness of processing carried out beforehand.

How to exercise your rights. Write to adatvedelem@chipet.app, or use Settings → Privacy in the app. We will respond within one month; for complex requests this may be extended by a further two months, of which we will inform you. Responding is free of charge; for manifestly unfounded or repetitive requests we may charge a reasonable fee or refuse to act.

Before acting on a request we may need to identify you — writing from the e-mail address registered to your account is sufficient.

12. Remedies

If you believe your data is being processed unlawfully, please contact us first — most questions can be resolved that way most quickly.

You may lodge a complaint with the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: Falk Miksa utca 9–11, 1055 Budapest, Hungary
Postal address: 1363 Budapest, Pf. 9, Hungary
Phone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu Web: https://naih.hu

You may also bring proceedings before a court. The action may be brought before the regional court with jurisdiction over your place of residence or stay. The proceedings are exempt from court fees.

If you do not live in Hungary, you may also complain to the supervisory authority of the Member State of your habitual residence or place of work.

13. Automated decision-making and profiling

We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).

Two automated helper processes operate, both with human review:

  • Contract reading: from an uploaded adoption contract the system proposes values for data fields (name, date of birth, address, phone number, document number). These are proposals: a member of the organisation's staff checks and approves them before they enter the record.
  • Microchip check: the system compares the chip number on the contract with the animal's recorded chip number and flags any discrepancy to staff.

We do not carry out profiling for marketing or scoring purposes.

14. Children

Our services are intended for persons aged 16 or over. We do not knowingly collect personal data from anyone under 16. If we learn that such data has entered the system without the consent of the holder of parental responsibility, we will delete it without delay.

For event signups, a minor may be registered by a parent or legal guardian by stating the party size; we record no separate data about the minor.

15. Cookies and local storage

The web interfaces (gazdi.chipet.app, menhely.chipet.app) use only strictly necessary cookies and local storage:

  • session and refresh tokens — to keep you signed in;
  • language and display settings;
  • temporary form data.

Under the e-privacy rules these do not require consent. We use no analytics, advertising or social media cookies. The error monitoring service described in section 4.11 likewise sets no cookies and does not analyse user behaviour.

The mobile apps store the sign-in token and app settings locally on the device; these are removed when the app is uninstalled.

16. Changes to this notice

We may update this notice from time to time — for example when we introduce a new feature or when the law changes. The version in force at any time is available at https://chipet.app/privacy.

We will give notice of any material change by e-mail or in the app at least 15 days before it takes effect. The version number and effective date are always shown at the top of this notice.