Privacy notice
On this page
1 · Who is responsible
The controller of personal data processed through pablorecords.eu and the Pablo application is Tina Klopčič, a natural person established in Slovenia, acting as an individual (no company is registered at the date of this notice).
Contact: tina@pablorecords.eu. There is no data protection officer; the controller answers directly.
Breeders act as controllers of their own waiting lists. A breeder decides who is on their list and why; Pablo processes that data on the breeder's behalf as a processor. For questions about a specific breeder's list, contact that breeder. For everything else, contact the address above.
2 · What is collected and why
| Website visits | Server access logs (IP address, requested page, timestamp, user agent), generated automatically by the hosting provider, used for security and troubleshooting. This website sets no cookies and uses no analytics, tracking pixels, advertising or externally hosted fonts. |
|---|---|
| Waiting-list entries | Name, email address, optional telephone number, the preferences a family provides, the date of joining and the date and content of each confirmation answer. Used to maintain the breeder's list and to tell the family where they stand. |
| Accounts | Email address and a hashed password. Used to authenticate you. Passwords are never stored in readable form. |
| Dog records | Data about animals (identifiers, pedigree, health and test records, documents, photographs) and the household members granted access. Animal health data is not personal data about you, but it is treated with the same care because it is linked to your household. |
| Correspondence | Emails and messages you send, kept so that a conversation can be continued. |
No automated decision-making with legal or similarly significant effects takes place. Nothing in Pablo rejects, ranks or scores a family; a breeder always decides.
3 · Legal bases
- Performance of a contract (Art. 6(1)(b) GDPR) — providing the account and the service you asked for.
- Legitimate interests (Art. 6(1)(f)) — keeping the service secure and functioning, and answering correspondence. Server logs rest on this basis.
- Consent (Art. 6(1)(a)) — where you choose to share something that is off by default, such as making part of a dog's record visible to a breeder or to other owners. Consent can be withdrawn at any time, with effect for the future.
4 · Who receives data
Personal data is never sold, rented or exchanged, and is not used for advertising or for training machine-learning models.
Data is shared only with:
- the breeder whose waiting list you joined, for entries on that list;
- people you deliberately give access to, such as a household member, a veterinarian or a boarding kennel receiving a time-limited link;
- the processors listed below, acting on documented instructions.
| Neoserv d.o.o. (Slovenia) | Website and email hosting. Data remains in the EU. |
|---|---|
| Supabase | Application database, authentication and file storage, in an EU region. |
| esm.sh | Public JavaScript delivery service. Loading the application causes your browser to request one library from it; the request exposes your IP address to that service. No account or dog data is transmitted. |
Data may also be disclosed where required by law. If that ever happens, you will be told unless the law forbids it.
5 · How long it is kept
- Server logs — the retention period set by the hosting provider, typically a matter of weeks.
- Waiting-list entries — until the family withdraws, the breeder removes the entry, or the breeder closes their account.
- Accounts and dog records — until you delete them. A dog's record is deliberately not tied to any breeder's account and does not expire when a kennel leaves.
- Correspondence — as long as needed for the conversation, and then deleted on request.
6 · Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, data portability, and objection to processing based on legitimate interests, as well as the right to withdraw consent at any time.
To exercise any of them, write to tina@pablorecords.eu. No explanation is required and there is no charge. You will receive an answer within one month.
You also have the right to lodge a complaint with a supervisory authority — in Slovenia, the Informacijski pooblaščenec (ip-rs.si), or with the authority in the EU country where you live.
7 · Security
Connections are encrypted in transit (HTTPS). Passwords are stored hashed. Access to records is enforced at the database level, so a person can only read the rows they are entitled to, rather than relying on the interface to hide them. Confirmation links carry single-purpose tokens that answer one question and give access to nothing else.
No system is beyond failure. If a breach ever affects your data, you will be informed, and the supervisory authority notified as required by law.
8 · Children
Pablo is not intended for people under 16. Accounts are not knowingly created for children, and any such account will be deleted on discovery.
9 · Changes
If this notice changes, the version and date at the top change with it, and anyone with an account is told about material changes by email before they take effect.