This Privacy Policy (the Policy) provides information about the processing of your personal data in connection with your use of the AnimalAdmin Platform operating at https://www.animaladmin.com (the Platform).
Capitalised terms not otherwise defined in this Policy have the meanings given to them in the Terms.
If you are a User who books a stay or another pet care service through AnimalAdmin software, please read the User Information Notice.
Data Controller
The controller of your personal data is Dawid Grabowski, conducting business under the name Dawid Grabowski - Animal Admin in Komorniki (address: ul. Storczykowa 8/1, 62-052 Komorniki, Poland), NIP: 7773399315, REGON: 524026749 (the Controller).
Contacting the Controller
For all matters relating to the processing of personal data, contact the Controller by email at contact@animaladmin.com.
Data protection measures
The Controller applies modern organisational and technical safeguards to provide the best possible protection for your personal data and ensures that it processes such data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (the GDPR), the Polish Personal Data Protection Act of 10 May 2018 and other applicable data protection legislation.
Information about processing
Using the Platform requires the processing of your personal data. Detailed information about the purposes and legal bases of processing, the retention period and whether providing the data is required or voluntary is set out below.
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Entering into and performing the Service Supply Agreement |
| Article 6(1)(b) GDPR - processing is necessary to perform the agreement entered into with the data subject or to take steps at their request before entering into it. |
| Providing the above data is a condition of entering into and performing the Service Supply Agreement. Providing it is voluntary, but failure to do so will make it impossible to enter into and perform the agreement. The Controller retains this data until claims arising from the agreement become time-barred. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Handling complaints |
| Article 6(1)(b) GDPR - processing is necessary to perform the Agreement and enable the Service Recipient to exercise its contractual rights. |
| Providing the data is necessary to receive a response to a complaint or exercise rights under the Agreement. The Controller processes it for the duration of the complaint procedure and, where rights are exercised, until the related claims become time-barred. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Conducting proceedings concerning potentially unlawful content and examining appeals |
| Article 6(1)(c) GDPR - processing is necessary to comply with legal obligations, including providing a notice-and-action mechanism under Article 16 DSA and examining complaints under Article 20 DSA. |
| Providing the data is necessary to receive a response or exercise rights under the DSA. The Controller processes it for the duration of the verification and appeal proceedings and, where rights are exercised, until related claims become time-barred. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Conducting correspondence, including handling enquiries, the contact form and email messages |
| Article 6(1)(f) GDPR - the Controller's legitimate interest in responding to an enquiry. |
| Providing the data is voluntary but necessary to receive a response. The Controller processes it until a valid objection is made or the purpose is achieved, whichever occurs first. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Compliance with tax obligations, including issuing VAT invoices and retaining accounting records |
| Article 6(1)(c) GDPR - processing is necessary to comply with the Controller's obligations under tax law. |
| Providing the data is voluntary but necessary for the Controller to comply with its tax obligations. The Controller processes it for five years from the end of the year in which the deadline for payment of tax for the previous year expired. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Compliance with personal data protection obligations |
| Article 6(1)(c) GDPR - processing is necessary to comply with legal obligations arising from data protection law. |
| Providing the data is voluntary but necessary for the Controller to comply with data protection obligations, including responding to requests under the GDPR. The Controller processes it until claims concerning an infringement of data protection law become time-barred. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Establishing, pursuing or defending claims |
| Article 6(1)(f) GDPR - the Controller's legitimate interest in establishing, pursuing or defending claims connected with agreements entered into by the Controller. |
| Providing the data is voluntary but necessary for those activities. The Controller processes it until the relevant claims become time-barred. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Analysing your activity on the Platform website |
| Article 6(1)(f) GDPR - the Controller's legitimate interest in understanding activity on the Platform. |
| Providing the data is voluntary but necessary for the Controller to obtain this information. The Controller processes it until a valid objection is made or the purpose is achieved. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Administration of the Platform |
The data is recorded automatically in server logs whenever the Platform is used. The Platform could not be administered properly without server logging. | Article 6(1)(f) GDPR - the Controller's legitimate interest in ensuring the proper operation of the Platform. |
| Providing the data is voluntary but necessary for the Platform to function properly. The Controller processes it until a valid objection is made or the purpose is achieved. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Monitoring and correcting Platform errors |
| Article 6(1)(f) GDPR - the Controller's legitimate interest in ensuring the correct and secure operation of the Platform and correcting faults. |
| Providing the data is voluntary but necessary to diagnose and correct errors. The Controller processes the data until a valid objection is made or the purpose is achieved. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Publishing Reviews of Services |
| Article 6(1)(f) GDPR - the Controller's legitimate interest in publishing Reviews for information and promotional purposes. |
| Providing the data is voluntary but necessary to submit a Review. The Controller processes it until a valid objection is made or the purpose is achieved, whichever occurs first. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Operating chat on the website and within the Platform |
| Article 6(1)(f) GDPR - the Controller's legitimate interest in responding to messages sent through chat. |
| Providing the data is voluntary but necessary to receive a response. The Controller processes it until a valid objection is made or the purpose is achieved, whichever occurs first. | ||
| Purpose of processing | Personal data processed | Legal basis |
|---|---|---|
| Sending the newsletter and marketing information | email address | Article 6(1)(a) GDPR - processing is based on freely given consent. |
| Providing an email address is voluntary but necessary to receive the newsletter and marketing information. The Controller processes the data until consent is withdrawn or the purpose is achieved, whichever occurs first. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. | ||
Automated decision-making
Your personal data is not used for decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
Online payments through AnimalAdmin Pay
When the AnimalAdmin Pay online payment module is activated, the data required to create and verify an account in Stripe, including business data, data concerning persons representing the Service Recipient, bank account details and identity documents, is collected and verified directly by Stripe Payments Europe, Limited, with its registered office in Dublin, Ireland. Stripe acts as a separate controller for this processing under its own documentation. The Controller does not obtain access to identity documents submitted to Stripe during verification.
Recipients of personal data
The following external entities cooperate with the Controller and may receive personal data:
- Vercel Inc. - Platform hosting, application infrastructure and website analytics;
- Databricks, Inc. (Neon service) - database hosting;
- Cloudflare, Inc. - R2 file storage and Turnstile form protection;
- Plus Five Five, Inc. (Resend) - email delivery;
- LINK Mobility Poland sp. z o.o. (SMSAPI) - SMS delivery;
- Functional Software, Inc. d/b/a Sentry - Platform error, performance and security monitoring, including masked session recordings;
- Stripe Payments Europe, Limited - AnimalAdmin Pay services as a separate controller;
- Google LLC and Google Ireland Limited - Google account sign-in where selected by the User;
- Crisp IM SAS - website chat after the relevant consent is given;
- Sanity AS or Sanity US Inc. - website content management and delivery.
Personal data may also be disclosed to public or private entities where required by generally applicable law, a final court judgment or a final administrative decision.
Transfers to third countries
Because the Controller uses services supplied by providers including Stripe and Google LLC, your personal data may be transferred to the following third countries: the United Kingdom, Canada, the United States, Chile, Brazil, Israel, Saudi Arabia, Qatar, India, China, South Korea, Japan, Singapore, Taiwan (Republic of China), Indonesia and Australia. The legal safeguards for these transfers are:
- for the United Kingdom, Canada, Israel and Japan, European Commission adequacy decisions confirming an appropriate level of personal data protection;
- for the United States, Chile, Brazil, Saudi Arabia, Qatar, India, China, South Korea, Singapore, Taiwan, Indonesia and Australia, contractual safeguards consistent with the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for transfers of personal data to third countries under Regulation (EU) 2016/679.
You may obtain from the Controller a copy of the safeguards applying to personal data transferred to a third country.
Your rights
You have the following rights in connection with the processing of personal data:
- the right to obtain information about the personal data concerning you processed by the Controller and to receive a copy of that data. The first copy is provided free of charge; the Controller may charge a fee for further copies;
- the right to request rectification if the processed data becomes outdated, incomplete or otherwise inaccurate;
- the right, in certain circumstances, to ask the Controller to erase personal data, including where:
- the data is no longer required for the purposes communicated by the Controller;
- you have validly withdrawn consent and there is no other legal basis for processing;
- the processing is unlawful;
- erasure is required to comply with a legal obligation binding on the Controller;
- where personal data is processed on the basis of consent or to perform an agreement with you, the right to transmit your data to another controller;
- where processing is based on consent, the right to withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal;
- where you consider that personal data is inaccurate, processing is unlawful or the Controller no longer needs certain data, the right to require the Controller, for the necessary period, not to perform operations on the data other than storage;
- the right to object to processing based on the Controller's legitimate interests. Following a successful objection, the Controller will cease processing for that purpose;
- the right to lodge a complaint with the President of the Polish Personal Data Protection Office if you consider that processing infringes the GDPR.
If you are concerned about losing control over your information, tracking of your activity or your privacy, browser extensions, browser privacy settings, VPNs and privacy-focused browsers can help block or limit such activity. We deliberately do not recommend particular solutions because they vary widely, but encourage you to choose solutions suited to your needs. Comparisons and suggestions are available from Privacy Guides.
Cookies
- The Platform uses cookies installed on your end device. Cookies are small text files that can be read by the Controller's systems and by systems belonging to other entities whose services the Controller uses.
- The Controller uses cookies to:
- ensure the proper operation of the Platform, including use of its functionality and convenient navigation between pages;
- improve the comfort of using the Platform, including detecting errors on particular pages and continuously improving them;
- produce statistics concerning how Users use the Platform, enabling continuous improvement and adaptation to Users' preferences;
- conduct marketing activities, including delivering advertising adapted to Users' preferences.
- The Controller may place both persistent and temporary session cookies on your device. Session cookies are usually removed when the browser closes; closing the browser does not remove persistent cookies.
- Information about cookies used by the Controller is displayed in a panel when you first visit the Platform website. Depending on your choice, you may enable or disable particular cookie categories, except strictly necessary cookies, and change your settings at any time.
- Detailed information about cookies, including their name, provider, function, data collected and duration, is available in the panel referred to above.
- Most commonly used browsers allow you to check which cookies are installed, remove them and block future installation. Disabling or restricting cookies may cause significant difficulties in using the Platform, including repeated sign-in, longer loading times or limited functionality.
Final provisions
Matters not regulated by this Policy are governed by generally applicable data protection law.
This Policy is effective from 26 August 2026.