Why does a dog app need GDPR seriously?

You might wonder: what really sensitive data does a dog app handle? More than you'd think. CanAI stores health records, photos, walking-location patterns, behavioural observations — and indirectly personal data about you (email, payment, address). That data deserves the same protection as your banking app.

What CanAI actually processes

About your dog

About you

Where the data lives

All active data sits on servers in Frankfurt (Hetzner). That means: EU legal jurisdiction, GDPR / UK GDPR oversight, no transfer to the US. Backups run encrypted to a secondary EU data centre in Helsinki.

How it's encrypted

What we don't do

Your UK GDPR rights — how to use them

RightHow to exerciseResponse time
Subject access (Art. 15)Account → Privacy → "Show all my data"Instant
Rectification (Art. 16)Edit profile or contact supportWithin 24h
Erasure (Art. 17)Account → "Permanently delete account"Immediate + backups within 30 days
Data portability (Art. 20)Account → Privacy → "Export my data" (JSON)Instant
Object to processing (Art. 21)support@canai.appWithin 72h

Sub-processors (as of 2026)

CanAI uses these external providers — all UK GDPR compliant with signed DPAs:

What really happens when you delete

  1. Click "Delete account": immediate disconnection of your profile from all content.
  2. Content (dog profile, images, chat) removed from the active database within 24 hours.
  3. Backups: overwritten within 30 days.
  4. Payment data: retained by Stripe for 7 years per PCI-DSS legal requirement.
  5. Confirmation email with the final deletion date.

Security incidents

If, despite our safeguards, a personal-data breach occurs, we notify the Information Commissioner's Office (ICO) and any affected users within 72 hours per Article 33-34. As of May 2026: no incidents recorded.

Your own role in security

Questions?

Data protection enquiries to privacy@canai.app. The account section contains all data tools for self-service. Our designated Data Protection Officer is registered with the ICO and reachable on request.