1. Data Controller
The controller of your personal data is Corvino Marta Todek, ul. Jugosłowiańska 76a, 51-112 Wrocław, Poland, NIP (Tax ID) 8951810286, REGON (Business Registry No.) 383117426, providing the app under the brand "Milo App". For all matters concerning data processing please contact us at: hello@miloapp.pet.
2. Scope of processed data
User data
- first and last name;
- e-mail address;
- Google or Apple login identifier;
- device data used to deliver push notifications.
Pet data
- name, species, breed, sex, date of birth;
- microchip number (if the user provides it);
- photos of the pet.
Documents
- health record;
- certificates, test results, veterinary recommendations;
- photos of documents.
3. Purposes and legal bases for processing
- providing the service and maintaining the account — Article 6(1)(b) GDPR (performance of a contract);
- handling complaints and contact with the user — Article 6(1)(b) and (c) GDPR;
- delivering push notifications — Article 6(1)(b) GDPR (performance of a function requested by the user);
- ensuring the security of the App and detecting abuse — Article 6(1)(f) GDPR (legitimate interest);
- fulfilling the Controller's legal obligations, including storing information about acceptance of the Terms of Service — Article 6(1)(c) GDPR.
Pet data and veterinary documents do not constitute personal data within the meaning of the GDPR. They are stored in connection with the provision of the service and are visible only to the owner and invited caregivers.
The user should avoid including in documents special-category data relating to natural persons (e.g. health data of other people), unless this is necessary to use the App's functionality. The Controller does not require the provision of such data to use the basic functions of Milo App.
The user is responsible for the correctness, completeness and currency of the data entered into the App. The Controller does not verify the truthfulness of data concerning animals, documents, dates, identification numbers or other information entered by the user.
4. Terms of Service acceptance register
Milo stores information on the date, version and fact of the user's acceptance of the Terms of Service in order to fulfil legal obligations and to demonstrate consent to the terms of use of the service. Entries in the acceptance register are of an audit nature — they are immutable and retained for the period necessary to demonstrate consent in accordance with the GDPR.
5. Recipients of data
Data is processed using trusted technical infrastructure providers (Lovable Cloud and Supabase, including a PostgreSQL database and Supabase Storage). Data may be disclosed to state authorities solely on the basis of applicable law.
The Controller does not sell users' data and does not use it for behavioural advertising.
6. Retention period
Data is stored for the period of use of the App. After the account is deleted, data is erased, subject to the "Recently deleted" mechanism (30 days for restoration) and obligations arising from applicable law, including the retention of the Terms of Service acceptance register.
7. User rights
You have the right to:
- access your data and obtain a copy of it;
- rectify your data;
- erase your data ("right to be forgotten");
- restrict processing;
- data portability (export);
- object to processing based on a legitimate interest;
- lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) (ul. Stawki 2, 00-193 Warsaw, Poland).
The account can be deleted independently from within the App. A request for export or the exercise of other rights can be submitted to hello@miloapp.pet.
8. Data security
Data is encrypted at rest and transmitted over an encrypted connection. Access to the database is protected by a Row Level Security mechanism, and pet documents and photos are stored in private buckets.
9. Transfer of data outside the EEA
To the extent that the providers' infrastructure may involve processing outside the European Economic Area, the Controller ensures appropriate safeguards in accordance with the GDPR (including standard contractual clauses).
10. Changes to the Policy
The Policy may be updated. We always publish the current version in the App together with the date of the last update.