1. These terms
1.1 These terms govern your use of Planimal. “We”, “us” and “our” mean Planimal, operated by the trader whose registration details appear at the foot of this page. “You” and “Customer” mean the organisation that subscribes to the service.
1.2 You enter into this agreement in the course of a business or profession. The consumer provisions of Book 6 of the Dutch Civil Code do not apply, and there is no right of withdrawal on the subscription.
1.3 The agreement consists of these terms, Annex A (Data Processing Agreement), Annex B (Security measures and sub-processors), and the plan, fees and term you subscribed to. On their own subject matter the annexes take precedence over these terms.
2. The service
2.1 Planimal is a hosted application for businesses that train, teach and look after animals — dog schools, agility and obedience instructors, behaviourists, groomers and the like: scheduling, client and animal records, public booking, and invoicing. It is provided as software as a service, over the internet, on a subscription.
2.2 We provide the service as it is at the time you use it. Features may be added, changed or removed. We will not materially reduce core functionality without notice under clause 15.
3. Your account and your users
3.1 You create and manage accounts for the people in your organisation who use the service, and you assign their roles.
3.2 You are responsible for what those users do, for keeping their credentials secure, and for removing access from anyone who no longer needs it.
3.3 Sign-in is by password or by a single-use link sent to a user’s email address. Tell us without delay if you believe an account has been compromised.
4. Acceptable use
4.1 You must not use the service:
- in breach of the law, or to process data you have no right to process;
- to attempt to reach data belonging to another customer, to probe or test our security, or to work around access controls, rate limits or usage limits;
- to place an automated load on the service that degrades it for others;
- to resell, sublicense or white-label the service, unless we have agreed that in writing;
- to arrange, run or record any activity whose purpose or likely effect is to harm an animal — including hunting, animal fighting, baiting, and training or conditioning for any of them;
- for political campaigning, or to send political or electoral messaging to the people in your records.
4.2 You must not enter special categories of personal data (article 9 GDPR) or personal data relating to criminal convictions and offences into the service. See A5.
4.3 If you breach this clause we may suspend your access. Where it is practicable and the breach is not serious, we ask you to put it right first and give you a reasonable period to do so.
4.4 Where the breach is serious — in particular where it harms or endangers an animal or a person, breaks the law, or puts the service or another customer’s data at risk — we may suspend your access immediately and without notice, and terminate the agreement with immediate effect. We tell you what we have done and why. Clause 5.5 governs any refund.
5. Fees, VAT and price changes
5.1 You pay the fees for the plan you subscribed to, at the rates in force when you subscribed.
5.2 Fees are exclusive of VAT. VAT is added at the applicable rate. Where you provide a valid VAT identification number issued in another EU member state, VAT is reverse-charged to you.
5.3 Fees are invoiced in advance for each subscription period. Payment is due within 14 days of the invoice date.
5.4 We may change our prices. We give you at least two months’ written notice before a change takes effect, and it only takes effect at the start of a renewal period. If you do not accept the change you may terminate the agreement with effect from the date the change would take effect, at no cost. A change caused solely by a change in the statutory VAT rate is not a price change under this clause.
5.5 Fees paid for a period that has already begun are not refundable, except where you terminate under clause 5.4 or 15.2, or where we terminate other than for your breach. In those cases we refund the fees paid for the remainder of the period, pro rata.
6. Non-payment and suspension
6.1 If an invoice is not paid by its due date we send a reminder setting a further payment period of at least 14 days.
6.2 If it remains unpaid after that period we may suspend your access to the service. We give you at least 7 days’ notice before we do.
6.3 Suspension does not delete anything. We do not delete your data because of non-payment; deletion follows only from the end of the agreement, under clause 9.
7. Term and termination
7.1 The agreement starts when your account is created and runs for the subscription period you chose. It renews automatically for the same period unless it is terminated.
7.2 You may terminate at any time, in writing or through the service, with effect from the end of the current subscription period. See clause 11 for the exit process, which applies whatever the reason for termination.
7.3 We may terminate on at least two months’ written notice, expiring no earlier than the end of the period you have paid for.
7.4 Either party may terminate with immediate effect if the other is in material breach and has not put it right within 30 days of written notice, or if the other is declared bankrupt or granted a suspension of payments. Clause 4.4 lets us terminate a serious breach of clause 4 immediately, without that period.
7.5 On termination your access to the service ends, clause 11 applies, and any clause that by its nature is meant to continue — including clauses 8, 9, 12, 13, 14 and 16 and Annex A — continues.
8. Your data
8.1 The content you and your users put into the service, and everything your own customers submit through your public booking pages, is yours. We claim no ownership of it.
8.2 We process it only to provide, support, secure, maintain and improve the service, and on your instructions. Where it is personal data, Annex A governs the processing.
8.3 We do not sell your data, disclose it to third parties for their own purposes, or use it to train machine-learning models — ours or anyone else’s.
9. Retention and deletion
9.1 While the agreement is in force we retain your data so the service can work.
9.2 After the agreement ends, your data remains available for export for 30 days under clause 11. We then delete it from the live system within a further 30 days.
9.3 Backups are kept on a rolling window of at most 90 days and are overwritten as that window passes. Data deleted from the live system therefore continues to exist in backups until the window has run. We do not restore deleted data from a backup other than to recover from an incident affecting the service as a whole.
9.4 Independently of this clause, we keep the records of the subscription invoices we issue to you for 7 years, as Dutch tax law requires.
10. Availability and support
10.1 We aim to keep the service available at all times, but we do not commit to a service level. There is no SLA, no uptime guarantee and no service credits. This is what we offer, stated plainly, not an omission.
10.2 We may take the service offline for maintenance. Where the work is planned we give notice if it is reasonably practicable to do so, and choose a period of low use. We also release updates regularly; a release can interrupt the service briefly, and we do not give notice of those.
10.3 Support is by email, on a best-effort basis, normally on Dutch business days. We aim to acknowledge a request within two business days. We do not commit to a time to resolve one.
11. Switching and exit
This clause implements Chapter VI of Regulation (EU) 2023/2854 (the Data Act) and applies to every termination, whatever the reason.
11.1 You may switch to another provider, or to your own infrastructure, at any time. We do not impose any commercial, technical, contractual or organisational obstacle to your doing so.
11.2 The longest notice period we require to start the switching process is two months.
11.3 The transition period is 30 days, starting when the notice period ends. During it the service continues to work and we assist you with the switch. You may ask for a longer transition period. Where the switch cannot be completed in 30 days for technical reasons, we tell you within 14 working days of your request, explain why, and propose a longer period, which will not exceed seven months.
11.4 On written request during the transition period we export, at no charge, every category of data below, and within each category every field the service holds:
- Your organisation — its settings, branding, operating hours and invoicing configuration, and every version of the terms, cancellation policy and privacy notice you have published to your own customers.
- Your users — their accounts and preferences. Password hashes and session tokens are excluded, being of no use to you and unsafe to move.
- People (your clients) — their contact, billing and status details.
- Animals — their details, and the links between an animal and the people associated with it.
- Services and public listings, including prices, durations, capacity and booking settings.
- Scheduling — events and their recurrences, operating hours and time blocks, bookings, the people and animals attached to each, and booking status.
- Booking requests, with their content and status.
- Invoicing — invoices and credit notes with their lines, payments, counters, and the generated PDF documents.
- Tags and their assignments.
- Comments and notes attached to any of the above.
- Uploaded files, in their original format.
- The audit trail.
Anything we add to the service that holds your data falls into one of these categories and is exported with it.
Structured data is provided in a structured, commonly used, machine-readable format (CSV and/or JSON); files are provided in the format they were uploaded in.
11.5 The following are not exported — this list is exhaustive: system and server logs; database backups; error-monitoring events; email delivery logs; internal counters, caches and other derived values that are recomputed from the exported data; our own service configuration; and the data we process as controller in our own right, described in our privacy policy. None of them contain anything about you or your customers that the export does not already give you.
11.6 We charge nothing for switching, for the export, or for the data transferred out.
12. Warranties and disclaimers
12.1 We provide the service with due care and skill.
12.2 Beyond that, and to the fullest extent the law permits, the service is provided as it is. We do not warrant that it will be uninterrupted or error-free, or that it is fit for any particular purpose you have in mind.
12.3 The service does not replace your own judgement or your own record-keeping obligations. You are responsible for the accuracy of what you enter and of what you send out from it, including invoices and their tax treatment.
12.4 Where the service lets you publish your own terms, cancellation policy, privacy notice or similar text to your customers, that text is yours. Anything we supply as a starting point is a template, not legal advice, and we do not warrant that it is valid, complete or right for your business. Check it, and adapt it, before you rely on it.
13. Liability
13.1 Our total liability under or in connection with this agreement is limited to the fees you paid in the twelve months before the event giving rise to the claim.
13.2 We are not liable for indirect or consequential loss, including lost profit, lost turnover, lost savings, business interruption, damage to reputation, or loss or corruption of data beyond restoring the most recent backup we hold.
13.3 Nothing in this agreement limits our liability for intent or deliberate recklessness, for death or personal injury, or for anything else Dutch law does not permit us to limit or exclude.
13.4 Neither party is liable for a failure caused by force majeure within the meaning of article 6:75 of the Dutch Civil Code, which includes failures at the hosting, connectivity, email and storage providers listed in Annex B.
14. Intellectual property
14.1 The service, its software, design, documentation and brand are ours or our licensors’. Nothing in this agreement transfers them to you.
14.2 For the term of the agreement you have a non-exclusive, non-transferable, revocable right to use the service for your own business.
14.3 You may not copy, modify, decompile or reverse-engineer the software, except to the extent mandatory law permits regardless of this clause.
15. Changes to these terms
15.1 We may change these terms. We announce a change by email to the administrative contact on your account and by publishing the new version at its own permanent address on this site, at least 30 days before it takes effect.
15.2 If a change is materially to your disadvantage you may terminate the agreement with effect from the date the change takes effect, by telling us before then. Clause 5.5 applies to the refund.
15.3 A change we are required to make by law takes effect on the date the law requires. We tell you as soon as we reasonably can.
15.4 Every version of these terms stays available at its own permanent address. The version in force is always the one at /terms.
16. Governing law and disputes
16.1 Dutch law applies.
16.2 Disputes are submitted to the competent Dutch court for the district in which we are established, unless mandatory law designates another court.
17. Contact
Write to us at the email address in the footer of this page. That address reaches us for support, for anything under Annex A, and for notices under this agreement.
Annex A — Data Processing Agreement
This annex is the agreement required by article 28(3) GDPR. It applies whenever we process personal data on your behalf.
A1 — Roles. For the personal data you, your users and your own customers put into the service, you are the controller and we are the processor. For the personal data we process in our own right — your users’ account data, our billing records, our server logs and error monitoring — we are the controller; that is described in our privacy policy and this annex does not apply to it.
A2 — Subject matter, duration, nature and purpose.
- Subject matter: the processing of personal data in the course of providing the service.
- Duration: the term of the agreement, followed by the periods in clause 9.
- Nature: collection, storage, structuring, retrieval, use, transmission by email and as PDF documents, backup, and erasure, all by automated means.
- Purpose: providing the scheduling, client-record, public booking and invoicing functionality you use, and supporting, securing and maintaining it.
A3 — Types of personal data.
- Clients and other people you record: their contact details, their billing details, and the reference, language and status information you keep about them.
- Animals and their relationships: an animal’s details, and which people own or handle it — information which relates to those people.
- Your users: their account and contact details, their role and preferences, and authentication data.
- Bookings: which person and which animal attended which event, when, with which member of your staff, and the status of that booking.
- Invoicing: the invoices and credit notes you issue to your clients, their lines, amounts and payment status.
- Free text: notes and comments that you or your staff attach to a person, animal, booking or invoice, containing whatever you choose to put there.
- Public bookings: everything a booker submits through your public booking pages, including their contact details and those of the animal concerned.
- Records of use: audit trail entries recording which user performed which action on which record, when, from which IP address and with which browser.
A4 — Categories of data subjects. Your clients and the people they name; the owners and handlers of the animals you record; your staff and anyone else with an account on your organisation; and anyone who submits a booking or booking request through your public pages.
A5 — Special categories. You must not enter special categories of personal data (article 9 GDPR) or personal data relating to criminal convictions and offences into the service. It is not designed for them and Annex B is not calibrated to them. If such data is entered anyway you remain responsible for it, and we may remove it after telling you.
A6 — Instructions. We process personal data only on your documented instructions. This agreement, this annex, and your use of the features of the service are those instructions. Where EU or member state law requires us to process otherwise, we tell you what the law requires before we do, unless that law forbids it. We tell you if we consider an instruction infringes the GDPR or other data protection law.
A7 — Confidentiality. Everyone we authorise to process personal data is bound by an obligation of confidentiality.
A8 — Security. We take the technical and organisational measures required by article 32 GDPR. Annex B describes them. We may change them, provided the level of protection is not reduced.
A9 — Sub-processors. You give us general written authorisation to engage sub-processors. Those we currently engage are listed in Annex B. We give you at least 30 days’ written notice before adding or replacing one. You may object on reasonable data-protection grounds within that period; if we cannot resolve your objection, you may terminate the agreement with effect from the date the change takes effect and we refund the fees for the remainder of the period, pro rata. Every sub-processor is bound by written terms that are no less protective than this annex, and we remain fully liable to you for what they do.
A10 — Data subject requests. The service lets you find, correct, export and delete the personal data you hold, so you can answer a data subject yourself. If a data subject approaches us directly about data we hold on your behalf, we do not answer them substantively; we forward the request to you without undue delay. Where you cannot act through the service, we help you at your request; we may charge our reasonable costs for work that goes beyond the ordinary.
A11 — Assistance. Taking into account the nature of the processing and the information available to us, we help you meet your obligations under articles 32 to 36 GDPR — security, breach notification, data protection impact assessments and prior consultation.
A12 — Personal data breach. We notify you of a personal data breach affecting personal data we process for you without undue delay, and in any event within 48 hours of becoming aware of it. We write to the administrative contact email address on your account. The notification describes, as far as we know it at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and where you can get more information. We keep you updated as we learn more. Your own 72-hour deadline under article 33(1) GDPR runs from the moment we notify you. We do not notify a supervisory authority or data subjects on your behalf, unless you ask us to in writing.
A13 — Deletion or return. When the agreement ends you choose whether we return the personal data or delete it. Returning it means the export in clause 11. If you make no choice, we make the export available and then delete, as clause 9 sets out: removal from the live system within 30 days of the end of the export window, and from backups as the rolling window in clause 9.3 passes, at most 90 days later. Where EU or member state law requires us to keep something — our own invoicing records, for instance — we keep only what the law requires, for only as long as it requires, and it stays subject to this annex.
A14 — Audits and information. We make available to you the information needed to demonstrate compliance with article 28 GDPR. You may audit or have audited our compliance once in any twelve-month period, on 30 days’ notice, during business hours, at your own cost, by you or an auditor who is bound to confidentiality and is not a competitor of ours, and without disrupting the service. You may audit more often if a supervisory authority requires it or following a breach affecting your data.
A15 — Transfers. Personal data is processed and stored in the European Economic Area. Where a sub-processor processes personal data outside the EEA, we rely on an adequacy decision of the European Commission or on its Standard Contractual Clauses, together with any supplementary measures needed. Annex B records where each sub-processor processes.
Annex B — Security measures and sub-processors
These are the article 32 measures in force. We may change them, provided the level of protection is not reduced. A change to the sub-processor list is made under A9, with notice.
B1 — Access to the service
- All traffic is served over TLS. Plain HTTP is redirected.
- Passwords are stored only as salted hashes, never in plain text. Sessions use random tokens with a limited lifetime.
- Sign-in by single-use, expiring link is available as an alternative to a password.
- A booking made through a public page is confirmed by email before it is held, so the address given must be reachable.
B2 — Tenant isolation
Every customer’s data is separated by an organisation identifier, and every query the application makes is scoped to the organisation of the request — including counters, badges and dashboard figures. That scope is determined by the request and is never accepted from user input. It is enforced centrally, in the data-access layer, rather than left to each screen to remember.
B3 — Storage and encryption
- Data at rest is held in a PostgreSQL database on a dedicated server. Uploaded files are held in a private object-storage bucket that is not publicly listable.
- Database backups and object storage are encrypted at rest by the provider.
- Secrets and credentials are held as environment variables in the deployment platform, not in the source code repository.
B4 — Backups
- The database is backed up on a schedule, at least daily and typically more often, to a private bucket at a separate provider from the application host.
- Backups are retained on a rolling window of at most 90 days, then overwritten.
- Restores are exercised periodically against a throwaway database, not only when they are needed.
B5 — Logging and monitoring
- Application errors are captured by monitoring software we run ourselves. Personal data is stripped from a report before it is sent: the address of the page is reduced to its route, and the parameters of the request, the cookies, the request headers and the visitor’s IP address are dropped.
- The application writes an audit trail of who did what to which record, when, from which IP address and with which browser.
- Server and platform logs record request metadata, including IP addresses. They are retained for a limited period and are not exported (clause 11.5).
B6 — Operational access
Production access — servers, database, backups, object storage and deployment — is held only by authorised personnel of Planimal, and is kept to the smallest number of people who can run the service. Everyone with it is bound to confidentiality under A7.
Access is over SSH with key authentication; password authentication is disabled. The deployment platform is protected by its own authentication and is not publicly enumerable.
B7 — Incident response
- Errors and platform alerts are monitored and triaged.
- On discovering an incident we contain it first, then establish what data was affected.
- Where an incident is a personal data breach affecting data we hold for you, A12 applies: we notify you within 48 hours of becoming aware.
- After an incident we record what happened and what changed as a result.
B8 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application and database hosting | Nuremberg, Germany |
| Backblaze, Inc. | Object storage for uploads, and database backups | Amsterdam, Netherlands |
| Amazon Web Services EMEA SARL | Transactional email delivery (Amazon SES) | Frankfurt, Germany |
Backblaze, Inc. is incorporated in the United States. The data it holds for us is stored in the European Union, and the Standard Contractual Clauses in its data processing addendum cover any access from outside the EEA. The other two are EU companies processing in the EU.
Error monitoring runs on our own servers at Hetzner, so no third party receives error reports. We do not use analytics, advertising or session-recording services.