1. Who is responsible
Aniday is a trading name of the business registered with the Dutch Chamber of Commerce under number 55982638 and based in Nijmegen, the Netherlands. You can contact us at info@aniday.io.
Aniday is the controller for personal data we use for our website, sales, account management, billing, support, security and our own business operations.
Our business customers decide which personal data about their customers, staff and other contacts they store in Aniday. For that data, the customer is generally the controller and Aniday is the processor. Requests about such data are best directed to that organisation first.
2. Data we use
| Category | Examples |
|---|---|
| Contact and account data | Name, business email address, phone number, role, company and login details |
| Subscription and payment data | Plan, modules, invoice details, VAT and Chamber of Commerce number, payment status and payment provider |
| Communications | Demo requests, emails, chat and support conversations, feedback and cancellation reason |
| Technical data | IP address, browser, device, timestamps, session data, error reports and security logs |
| Usage data | Features used, searches, settings, click and screen interactions and performance data |
| Customer content | Data a business customer enters about customers, staff, animals, bookings, payments and communications |
3. Why we use data
You must provide data marked as required or needed for an account, agreement, security or payment to use that service. Without it, we may be unable to process a request or provide the service. Other data is optional.
| Purpose | Legal basis |
|---|---|
| Provide a demo, trial, subscription and support | Performance of a contract or steps you request before entering a contract |
| Secure accounts, prevent misuse and resolve incidents | Legitimate interest in keeping Aniday secure and reliable |
| Issue invoices, process payments and keep records | Performance of a contract and legal obligations |
| Improve the service and understand usage | Legitimate interest, or consent where the technology requires it |
| Send relevant product information and business offers | Legitimate interest for existing business relationships, or consent where required |
| Exercise rights, handle disputes and comply with the law | Legal obligation and legitimate interest |
4. Where data comes from
We receive data directly from you when you complete a form, create an account, choose a subscription, contact us or use Aniday. An employer or colleague may also create an account for you.
Technical data is created when you use the website and app. Payment providers, integration partners and public business registers may provide additional data needed for payment, integrations or verification of business details.
5. Who we share data with
We do not sell personal data. We share only what is needed with staff, professional advisers and suppliers that help us provide the service. Depending on the features used, this may include the following categories and providers.
| Service | Examples and purpose |
|---|---|
| Hosting and network | Hetzner and Cloudflare for hosting, delivery and security |
| Mandrill or SendGrid for transactional email | |
| Payment | Mollie or Pay.nl for payments and payment status |
| Support and customer contact | Intercom and the Aniday support environment for chat, support and account context |
| Diagnostics | Sentry for errors, performance and, depending on configuration, recordings of screen interactions |
| Google services | reCAPTCHA for abuse prevention, Tag Manager for tag management and Translate for translation features |
| Video | YouTube in privacy enhanced mode for video |
| Accounting integrations | For example Exact, Visma, Twinfield and SnelStart when you enable such an integration |
6. Transfers outside the EEA
Where possible, we choose processing within the European Economic Area. Some suppliers or their group companies may also process data outside the EEA. In that case, we use a valid transfer mechanism such as an adequacy decision or the European Commission’s standard contractual clauses, with supplementary measures where needed.
7. How long we keep data
We do not keep personal data longer than necessary for the purpose for which it was collected. The exact period depends on the type of data, the account term, support needs, security risks, possible disputes and legal retention duties.
- Invoices and financial records are generally kept for 7 years after the end of the relevant financial year.
- App login sessions expire after no more than 30 days without a valid renewal.
- Account and contract data is kept during the customer relationship and afterwards for as long as needed for records, questions or potential claims.
- Customer content is deleted or returned after the service ends in line with the agreement, legal retention duties and the normal backup cycle.
8. Security
We take appropriate technical and organisational measures that reflect the nature and risks of the processing. These include measures for access, logging, backups, encrypted connections, maintenance and incident handling.
No system is completely risk free. Report a possible security issue immediately at info@aniday.io and do not include sensitive data that is not needed for the investigation.
9. Your privacy rights
You may request access, correction, deletion, restriction or transfer of your personal data. You may object to processing based on legitimate interests and always object to direct marketing. Where processing relies on consent, you may withdraw that consent at any time. Withdrawal does not apply retrospectively.
Send your request to info@aniday.io. We may ask for additional information where needed to verify your identity securely. We do not routinely ask for a copy of your identity document. We generally respond within one month.
If your request concerns data managed about you by a boarding business, school, salon or another Aniday customer, contact that organisation first. We support the organisation in handling the request.
10. Children and automated decisions
Aniday does not direct its website or business software at children. Only enter data about minors where there is a valid legal basis and limit it to what is necessary.
Aniday does not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
11. Questions and complaints
If you have a privacy question or complaint, email info@aniday.io. We would like to resolve it with you. You also have the right to complain to the Dutch Data Protection Authority or the supervisory authority in the country where you live or work.
12. Changes
We update this privacy notice when our service, suppliers or legal obligations change. The date of the latest version is always shown at the top. We notify active customers appropriately of an important change.