Merdilo Pro Privacy Policy
This policy explains when Merdilo determines how information is processed and when it acts on behalf of the selected practice.
In short: the Merdilo operator is the controller for accounts, billing, security and support. For client records maintained in Pro, the practice is normally the controller and Merdilo acts as its processor.
1. Operator and contact
Merdilo Pro is operated by Software Damian Wiliński, ul. Władysława Łokietka 5, 87-100 Toruń, Poland, tax ID (NIP) 9562270904, statistical number (REGON) 341538899. For privacy matters, email kontakt@merdilo.com.
2. Merdilo's two roles
Merdilo as controller
We determine the purposes and means of processing for team-member accounts, the B2B agreement, plans and payments, security, access auditing, abuse prevention, support, operational communication and optional telemetry.
Merdilo as processor
When a practice enters guardian profiles, cases, questionnaires, appointments, messages, files, notes and professional records, the practice determines the purpose and legal basis. Merdilo acts on its documented instructions under the data processing agreement.
3. Categories of information
- Account and team: name or display name, email address, identifier, roles, workspace, sign-in and verification details.
- Practice and agreement: name, contact details, address, public profile, services, plan, invoices and billing status; card information is handled by the payment provider.
- Security: IP address and request metadata available to the infrastructure, device or app information, App Check, sessions, action logs and error codes.
- Support: request content, contact details, attachments and resolution history.
- Practice content: guardian and dog profiles, appointments, forms, responses, messages, materials, files, client billing records, notes and case history.
- Public enquiries: contact details, dog profile, description of the need and selected appointment provided to the chosen practice.
- Telemetry: after an optional choice, pseudonymised usage events and technical codes without case or form content.
Please do not enter human health data or information about third parties unless it is necessary for the practice's lawful work. Free-text fields may nevertheless contain such information; the practice is responsible for data minimisation and the legal basis.
4. Merdilo's purposes and legal bases as controller
| Purpose | Legal basis |
|---|---|
| Account, workspace, features, plan and support covered by the agreement | Article 6(1)(b) GDPR; for people acting on behalf of a business, also the legitimate interest in performing the B2B relationship |
| Invoices, taxes and obligations to public authorities | Article 6(1)(c) GDPR |
| Security, auditing, abuse prevention, legal claims and continuity | Article 6(1)(f) GDPR — the operator's and its clients' legitimate interest in a secure service |
| Optional telemetry and non-essential technologies | Article 6(1)(a) GDPR and applicable electronic communications law; the choice can be withdrawn |
| Electronic marketing | Separate, optional consent; it is not a condition of an account |
5. Information provided by a practice
The practice is responsible for the legal basis, privacy notices, correct team permissions, retention and responses to individuals. Merdilo supports access, export, correction, restriction and deletion under the data processing agreement. A public form identifies the relevant practice as controller.
6. Care and Watching results
Connecting with a practice does not by itself share Watching results. A guardian makes a separate choice for a specific dog, practice, scope and period and can withdraw that choice under Care. Merdilo remains the controller for source results in the consumer Merdilo app. When a guardian shares a copy with a selected practice, the practice becomes the controller of that copy for the purpose of providing care, and Merdilo Pro processes it on the practice's behalf. Withdrawal stops further sharing and restricts or removes the projection in Pro according to the scope of the decision, retention rules and applicable law.
7. Recipients and service providers
Access may be provided to authorised practice members, operators supporting the service within their duties, public authorities where required by law and infrastructure providers. We do not sell information or use it for cross-app tracking advertising.
8. Transfers outside the EEA
Selected workloads are configured in EU regions, but this does not mean that every provider layer, support function or technical access always remains in Poland or the EEA. Where information is transferred outside the EEA, we require an appropriate mechanism, such as an adequacy decision or standard contractual clauses, together with safeguards proportionate to the risk.
9. Retention
We keep account and agreement information while the service is provided and for the period required for legal obligations, security and claims. Client records follow the practice's instructions and retention settings, subject to legal exceptions. Logs, links and working files have shorter periods depending on the feature. After logical deletion, isolated backups expire in their ordinary cycle and are not restored to operational use.
Each category has a period appropriate to its purpose, the practice's settings and legal duties. Active retention settings for records are visible in the Privacy Centre. Categories may not all be deleted at the same time where law, security or the protection of legal claims requires longer, restricted retention.
10. Your rights
Depending on the legal basis, you may request access, a copy, correction, deletion, restriction or portability, or object to processing. You may withdraw consent for the future as easily as it was given. If your request concerns records maintained by a practice, contact that practice first; Merdilo will support it as processor.
You may lodge a complaint with the President of the Polish Personal Data Protection Office or the competent authority in your country of residence. Contact Merdilo at kontakt@merdilo.com.
11. Security
We use workspace separation, roles and least-privilege access, reauthorisation for sensitive commands, provider-managed encryption in transit and at rest, integrity controls, operation auditing, backups, an incident process and access-rule tests. No system provides an absolute guarantee; safeguards are reviewed according to risk.
12. Automated decisions and AI
AI features assist with preparing draft content or summaries. They do not make decisions on behalf of a practice that produce legal effects for a guardian. An authorised person should review the output. We do not use practice content to train our own public model without a separate, explicit legal basis and notice.
13. Account deletion
An individual can delete their account directly in the app under Practice → Account. If you cannot sign in, you can begin a verified process through the public account-deletion page. Deleting an individual's account, closing a workspace and retaining practice records are separate processes.
14. Changes to this policy
We communicate a material change in the product or to the workspace owner's address with reasonable notice. The current version and date are always available at this address. A new purpose that requires a new legal basis is not hidden in a document update alone.