1. Controller

The controller for processing is:

Blocksize One UG (haftungsbeschränkt)
Oberstr. 3
47829 Krefeld
Germany

Represented by managing director Holger Köther. Register court: Amtsgericht Krefeld, HRB 21178. VAT ID: DE456304266.

Privacy and support contact: webmaster@blocksize.one

2. Data processed by PawSafe

Account and accessApple identity identifier, display name, short-lived access and refresh tokens, and device and security information needed for sign-in. The server keeps protected verification data and revocation state for tokens.
Safety configurationPet names and species, time limits, home address, home-area coordinates, radius, and an optional access note.
ContactsName and, depending on the selected channel, email address and phone number of contacts selected by the owner, plus invitation, response, and revocation status.
Email sign-inWhen a contact uses email sign-in, PawSafe processes the email address, a short-lived request for the six-digit one-time code, and its binding to the invitation or device. The code is not stored in plaintext, is accepted once, and expires after ten minutes.
Active flowStart and end times, session state, return signals, location coordinates, accuracy, distance, and derived status values. The latest return signal, including its coordinates, accuracy, and distance, remains in the session record and closed history. PawSafe does not build a continuous location history.
Contact pageIncident information, a short-lived protected session, response status, and SMS delivery status.
Technical useWebsite and API requests may involve IP address, time, requested page or function, response status, browser and device information, and security events.
Device and appApple device tokens may be stored for push notifications. The app protects credentials, a device-bound signing key, and pending owner actions in the iOS Keychain or local storage until they are sent or expire.

The contact page receives full address and pet details only after the explicit “Open incident” action. Access information is shown only after a further explicit action.

3. Sources of the data

Account information and safety configuration come from the owner. Contact details are entered by the owner. A selected contact first receives an invitation through the chosen channel, such as email, a shared link, or SMS. For email sign-in, the contact can request a six-digit one-time code. When an incident is triggered, the contact receives the incident link through the configured notification channel. The first communication provides privacy information and a way to object to further contact.

Location data comes from the owner’s device when the owner grants location access for a started flow. The required return measurements are sent to the server for the configured home area and return confirmation. The latest return signal is stored in the session and history record; PawSafe does not build a continuous location history.

4. Purposes and legal bases

  • Providing the owner account, safety window, and return confirmation on the basis of Article 6(1)(b) GDPR.
  • Processing the home area and return signals where required for the flow started by the owner, on the basis of Article 6(1)(b) GDPR. The app respects operating-system permission for location access.
  • Inviting contacts selected by the owner, providing contact access, and sharing incident status on the basis of Article 6(1)(f) GDPR. The legitimate interest is to organize the help requested by the owner. Contacts receive information in the first communication and may object to further notifications.
  • Protecting the service against misuse and keeping security-relevant actions traceable on the basis of Article 6(1)(f) GDPR. PawSafe does not create advertising profiles.

5. Recipients and service providers

We use the following service providers to provide PawSafe:

  • Cloudflare Workers, Durable Objects, D1, Queues, and Email Service for the API, sessions, encrypted state, task processing, invitations, and email sign-in codes.
  • Twilio for SMS delivery.
  • Apple for Sign in with Apple and Apple Push Notification Services where that feature is enabled.

Cloudflare and Twilio may process data outside the European Union. The relevant Cloudflare DPA, Cloudflare privacy policy, Twilio DPA, Twilio privacy notice, and, for Apple services, Apple privacy policy describe the applicable terms and safeguards. Whether a particular service and transfer mechanism is used depends on the operator configuration. We do not promise EU-only processing.

The website uses no analytics, advertising, or marketing services and sets no marketing cookies.

6. Sessions and cookies

The public website needs no analytics or advertising cookies. The contact page uses a strictly necessary HttpOnly, Secure, and SameSite protected server session. The contact cookie expires after 24 hours, and the incident link expires after seven days.

Storage strictly necessary for a service expressly requested by the user falls under the exception in Section 25(2)(2) TDDDG.

7. Retention and deletion

Invitation and incident links expire after seven days. An email sign-in code expires after ten minutes and can be used only once. A contact session expires after 24 hours. A closed incident, including its latest return signal, is retained for up to 30 days to keep the flow traceable, then deleted unless a statutory retention duty applies. The owner account and active configuration remain stored while the account exists.

Owners can start deletion in the app under Settings > Delete account and data. The server deletes the account data and revokes Apple sign-in credentials when they are stored; the app clears local credentials and pending local commands. The contact address above is an additional route. Cloud logs and backups remain subject to verified provider configuration, and statutory retention duties remain unaffected.

8. Data subject rights

Subject to the GDPR, people may request access, correction, erasure, restriction, portability, and object to processing. Owners can start deletion in the app under Settings > Delete account and data; the address above is an additional route. Reasonable identity verification may be required where there are doubts about the requester’s identity.

Contacts may object to further notifications through the path described in the first invitation or notification. Requests are handled within the statutory time limits.

9. Complaints

You may lodge a complaint with a data protection authority, including the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia: LDI NRW complaint information.

10. Changes

This notice will be updated when data flows, providers, purposes, or legal requirements change. The version and date will be shown when it is published.