Legal
Privacy policy
This is a courtesy translation. The Spanish (es-ES) version of the legal documents is the only binding version and shall prevail in the event of any discrepancy, as provided for in the general conditions of use.
1. Data controller
Controller: DOMISIK S.L., Sociedad Unipersonal — NIF B27661990.
Registered office: Calle Julio Pellicer, 2, planta 1, puerta 2, 14005 Córdoba.
Contact for data protection matters: support@domisik.com (stating 'Data protection' in the subject line) or the internal support channel of the Platform.
Data Protection Officer (DPO): appointment pending assessment; if one is appointed, their contact details will be published in this document.
2. Data that we process
Identification and contact data (first name, surname, email, telephone, address), provided by the user themselves.
Account data: credentials, profile, role (Domisiker/DomiKator/DomikONG), provided by the user or by the social login provider.
Pet data (DomiKyn): name, species, breed, care needs, health and behaviour data and, where applicable, status as a potentially dangerous animal, provided by the user themselves.
Transaction and payment data: booking history, amounts, payment tokens (user and Stripe).
Reputation and interaction data: reviews, internal messaging messages, history, Dokens, generated by the use of the Platform itself.
Platform usage and activity data: pages and functionalities used, searches, interactions and browsing events, generated by the use of the Platform itself.
Location data: the approximate location of the profile, in order to display and find nearby services; and, only where the user activates it for a service that requires it (for example, the tracking of a walk or home-based services), precise location data, processed in a minimised manner and for the strictly necessary period of time.
Automatic technical data: IP, device identifiers, logs.
Domisik does not store the full details of credit or debit cards or banking credentials: the processing is carried out by Stripe Payments Europe, Ltd., an entity that complies with the PCI-DSS standard, and Domisik retains only tokenised identifiers, in accordance with apdo. 4 «Comisiones del proveedor de pago y datos de pago» de las Condiciones de contratación y pagos.
3. Purposes and legal bases
Management of the registration and of the account, and intermediation in and management of bookings between users: performance of a contract (art. 6.1.b RGPD).
Processing of payments and settlements via Stripe: performance of a contract (art. 6.1.b).
Reputation and ratings system: legitimate interest (art. 6.1.f) and performance of a contract.
Affinity analysis and recommendations (DomisikIA): consent (art. 6.1.a) and legitimate interest.
Domisik commercial communications: consent (art. 6.1.a). The user may withdraw this consent and object at any time, simply and free of charge, by means of the unsubscribe link included in each communication or from the preferences of their profile, in accordance with art. 21 of Ley 34/2002 (LSSI-CE).
Provision of services that require the precise location of the user or of the animal (walk tracking, home-visit services): performance of a contract (art. 6.1.b) and consent for the activation of precise geolocation (art. 6.1.a), which may be withdrawn at any time.
Internal usage analytics: compilation of statistics, measurement of the performance of the Platform, improvement of the service and of the user experience, and error detection, on the basis of aggregated or pseudonymised usage data: legitimate interest (art. 6.1.f), with the right to object. Analytics based on cookies or equivalent technologies are governed by the Cookies Policy and require consent.
Use of content published by the user for Domisik's own advertising or commercial purposes: express and revocable consent (art. 6.1.a), in accordance with the apdo. 4 «Contenidos del usuario y licencias de uso» de las Condiciones Generales de Uso.
Fraud prevention and security, including the maintenance of internal records of suspended or blocked users in order to prevent further fraudulent registrations: legitimate interest (art. 6.1.f).
Compliance with legal obligations (tax, accounting): legal obligation (art. 6.1.c).
Compliance with the tax information obligations of digital platform operators in respect of the income of the DomiKators (DAC7 — Directive (EU) 2021/514 and the Spanish legislation transposing it): legal obligation (art. 6.1.c).
The reputation and affinity analysis carried out by DomisikIA is performed on anonymised or pseudonymised data and is governed by the principle of effective human oversight (apdo. 2 «Principios» de el Aviso de uso de inteligencia artificial): no decision producing legal effects, or similarly significant effects, concerning the user (art. 22 RGPD) is taken on a solely automated basis. In any event, the user has the right to obtain human intervention, to express their point of view and to contest the measure through the channels indicated in the apdo. 2 «Comunicaciones y canales de contacto» de el Aviso Legal.
4. Recipients and data processors
Domisik shares data only with: Stripe (payment processing, collection agent/Stripe Connect); Google Cloud Platform / Google Cloud EMEA Ltd. (infrastructure and hosting); SendGrid / Twilio (transactional email and notification delivery); other DomiKators and Domisikers, to the extent strictly necessary in order to carry out a booking; and public authorities or law enforcement bodies where there is a legal obligation to do so, including the reporting to the tax authorities of the seller information required by the DAC7 rules.
All data processors sign the corresponding contract in accordance with art. 28 RGPD (Data Processing Agreement), and Domisik keeps its Record of Processing Activities up to date.
5. International transfers
Where a provider involves transfers outside the European Economic Area (for example, processing by parent companies in the United States), such transfers are based on the Standard Contractual Clauses of the European Commission and/or on the EU-US Data Privacy Framework, with any additional safeguards that may be appropriate.
6. Retention periods
Data are retained for as long as the relationship remains in force and, following its termination, for the statutory limitation periods (as a general rule, up to 6 years for commercial and accounting obligations, and the applicable tax periods). Reputation data may be retained in pseudonymised form in order to preserve the integrity of the system.
7. Account deletion, logical deletion and anonymisation
For reasons of system integrity, security and traceability, the deletion of information on the Platform is carried out by means of logical, not physical, deletion. Consequently, requests for the erasure of personal data are dealt with by means of the irreversible anonymisation of the requester's data, so that it no longer permits their identification, with the same practical effect as erasure for the purposes of art. 17 RGPD.
Domisik will retain, duly blocked and with restricted access, the data that are necessary for the establishment, exercise or defence of legal claims and for compliance with legal obligations, for the applicable limitation periods.
In cases of suspension or blocking for abuse, fraud or serious breach, Domisik may retain or obfuscate (by means of pseudonymisation or equivalent techniques) the minimum identifying data strictly necessary to prevent the infringing user from registering again on the Platform using other data. This retention is based on the legitimate interest of Domisik and of the other users in the prevention of fraud and in the security of the community (art. 6.1.f RGPD), is limited to the data strictly necessary for that purpose and is subject to periodic review of its necessity and proportionality.
8. Rights of individuals
The user may exercise their rights of access, rectification, erasure, objection, restriction of processing and portability, and their right not to be subject to automated decisions, as well as withdraw their consent, by contacting support@domisik.com (stating "Data protection" in the subject line) or through the Platform's internal support and disputes channel, attaching a copy of an identity document.
The user may also lodge a complaint with the Agencia Española de Protección de Datos (www.aepd.es).
9. Security measures
Domisik applies encryption of sensitive data and of communications, granular access control (OAuth 2.0 + JWT), pseudonymisation, auditable log records, secret rotation policies and documented backups.