Privacy

How Reactive Dog Stays handles personal information and provider records in the free directory.

Effective date: 27 July 2026.

1. Controller and contact

Reactive Dog Stays is operated by Henrique Miguel Filipe Reis, a self-employed individual in Portugal. He is the controller for the processing described here.

Address: Rua Alfageme de Santarém, nº 19, 2000-584 Santarém, Portugal. Portuguese tax identification number (NIF): 222 788 992. Privacy contact: privacy@reactivedogstays.com. General contact: hello@reactivedogstays.com.

2. Directory-only service configuration

The reviewed release is a static public-web directory delivered by Cloudflare Workers Static Assets. It uses self-hosted fonts and contains no analytics. Cloudflare delivers and caches the static site and applies the configured security controls. The public artefact contains only the validated Airtable Public release and does not bundle private Ops or Intake records.

The release contains 31 approved providers and 25 confirmed claims. Nine providers and six claims remain on Hold, and 207 Unknown claims remain excluded. The private Airtable Ops register contains 40 real provider records. That count is operational inventory and is not represented as evidence that personal data is present. No personal Intake, Provider Contacts or Evidence Items were introduced by T7-T9. Provider business facts are not represented as personal-data classifications.

Proton Mail handles operational email. Airtable Public and private operational records remain separated. Directify is retained only during the approved 14-day rollback window and may remain the legacy public host during that window. Softr is not part of the public request path.

No public submission form, paid service, checkout or affiliate tracking is active in this release.

3. Information we handle

Site delivery and security. Cloudflare may receive technical request information needed to deliver and protect the site, such as IP address, requested URL, method, timestamps, browser or device information and security events. The exact deployed observability, export, cache and deletion settings must match the final reviewed configuration. This notice does not claim an EU-only service path.

Provider listings and evidence. We may handle public business names and contact details, website URLs, service areas, source links and dates, provider evidence and provider email confirmations. Safety-relevant information is never inferred. It is published only when stated on the provider's own website with a check date or confirmed by the provider by email with a confirmation date.

Messages, corrections and privacy requests. When you contact us, Proton Mail receives the message and the information you choose to provide. This may include your name, email address, organisation, message, evidence and details of a correction, removal or privacy request.

There is no public submission mechanism, user account or operator commercial-service data flow in this release.

4. Sources, purposes and legal bases

Listing information comes from logged-out public pages on a provider's own website, permitted official or open sources and information supplied directly by the provider. We do not bulk scrape marketplace or social-platform profiles, account-only pages, or use the Pet Sitters International locator for outreach.

We use information to deliver and secure the site, research and maintain sourced listings, answer email enquiries, handle corrections and removals, prevent abuse, meet legal obligations and establish or defend legal claims.

Where GDPR applies, the basis depends on the purpose and the information involved: legitimate interests in maintaining a secure, accurate and transparent directory; steps taken at your request before a response; legal obligations; and consent where the law requires it. We do not rely on consent where another lawful basis is being used. You may object to processing based on legitimate interests.

5. Email contact and human review

Public contact routes provide email guidance only. They do not submit information through the website. Messages sent by email are handled through Proton Mail and reviewed by the operator.

No message can publish directly. Movement into private Ops and release into Public require the configured evidence gates and human review. A message cannot create a verification badge, change compatibility information or publish a listing.

We do not make a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. Search filters and operational checks do not decide provider suitability or publication on their own; safety-relevant evidence, corrections, removals and release decisions require the stated human review gates. You may contact us to ask how a decision affecting you was made and to challenge it.

6. Service providers and international processing

The directory-only flow uses Cloudflare for static website delivery and security controls, Proton for email, and Airtable for separated public and private operational records.

Directify/WebTouch Ltd remains only for the approved 14-day rollback window. Its Article 28 DPA is executed and covers documented instructions, confidentiality, security, subprocessors, international transfers, rights and breach assistance, DPIAs, deletion or return, audits and the processing, TOM and subprocessor annexes. Directify is not part of the intended public request path after cutover.

Cloudflare's reviewed self-serve DPA path is conditionally applicable if the relevant Customer Content personal-data condition occurs. Product coverage is confirmed; the current record does not establish that runtime trigger. Cloudflare services are globally distributed and no EU-only execution is claimed.

Some providers may process information outside Portugal or the European Economic Area under their applicable safeguards. A current processor and transfer register records the services in scope, their roles, purposes, data categories, locations, safeguards and the evidence or unknowns for each. Account applicability, exact routes, countries and settings that have not been verified remain unknown.

Contact privacy@reactivedogstays.com for information about safeguards relevant to your data.

7. Retention and deletion controls

The operator approved 24 months for closed rights cases and commercial entitlement mirrors as operational periods subject to final legal review. Legal holds are case-specific only. Every routine deletion or anonymisation batch requires a separate written operator authorisation identifying the exact system, rule and targets. This notice creates no automatic deletion or standing delete authorisation.

A current provider questionnaire is retained while the listing remains active, with re-verification every 12 months. Superseded questionnaires and provider-verification records are retained for up to 24 months after replacement or listing removal, then deleted or anonymised unless a specific dispute or legal duty applies.

A full correction, removal or rights case and related correspondence are retained for up to 24 months after closure, then deleted or anonymised. Request content and identity material are removed earlier when no longer needed. A minimal do-not-relist record may remain while needed to prevent republication.

Raw provider or correction email is cleared by the earlier of 90 days after receipt or 30 days after a terminal decision. A minimal submission tombstone may remain for 24 months after the decision. General email is deleted 12 months after the case closes. Linked provider-evidence, correction, removal and privacy email follows the linked 24-month deadline so email does not become a longer duplicate archive.

Written accountant confirmation supplied on 23 July 2026 sets the routine baseline for the operator's current stated tax status at 10 years for applicable fiscal and accounting records. The start depends on the relevant issue, receipt, regularisation, declaration or financial year. The later applicable date prevails where an inspection, complaint, challenge, litigation, criminal inquiry, tax-control period or another right or duty remains open.

Directify is retained for the approved 14-day rollback window. After separately authorised decommissioning, the deletion and backup path will be verified at days 30 and 60. The published Worker's deployed configuration disables Workers Logs, invocation logs and Workers Traces and declares no Logpush or export destination, but account-level export controls and Cloudflare Static Assets cache deletion remain unverified. Airtable backup deletion and other vendor residual periods also remain unknown until verified.

8. Cookies and tracking

The directory-only release does not set an application cookie, load Google Fonts, contain analytics or load a website submission control. Cloudflare may process delivery and security metadata as described above.

No tracked affiliate link, affiliate cookie or visitor tracking is active. A tracking feature must not be added to the public visitor path without a separate reviewed update to this notice and any required consent control.

During the approved 14-day rollback period, Directify/WebTouch Ltd may remain the legacy host. Anonymous checks of the current Directify origin observed XSRF-TOKEN and directify_session cookies, built-in Directify analytics and a Google Fonts request. Directify forms and commercial features remain disabled during rollback. These legacy behaviours are not part of the directory-only release and will be rechecked before the rollback period ends.

The final hostname must be checked for cookies, telemetry, fonts, Turnstile, cache and security headers before publication. A prospective control is not represented as active until that check passes.

9. Sharing, sale and external sites

We share information with the service providers described above only as needed for an enabled service, when required by law, or to protect rights or safety. We do not sell personal information or use directory information to create unsolicited outreach lists for third parties.

Provider websites and other external destinations are governed by their own privacy practices.

10. Rights and complaints

Depending on applicable law, you may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint. Send a request to privacy@reactivedogstays.com. We may request proportionate information to verify identity or authority.

Where GDPR applies, we will respond within one month of receiving a rights request. If a lawful extension of up to two further months is necessary, we will tell you within the first month and explain the reason. You may complain to Portugal's supervisory authority, the Comissão Nacional de Proteção de Dados, at www.cnpd.pt, or to another competent supervisory authority where applicable.

11. Children, security and minimisation

The site is intended for adults and has no age-assurance control. If we learn that a child has submitted personal information, contact privacy@reactivedogstays.com so we can review the request and take the action required by applicable law. We use reasonable organisational and technical controls, including separate public and private data stores, validated Intake, inactive-by-default automations and human release decisions. No online service can guarantee perfect security.

Do not send passwords, authentication codes, full payment-card details, identity documents, unnecessary medical details or other information not needed for the relevant email or privacy workflow.

12. Changes

We will update this notice before activating a materially new provider, public submission mechanism, commercial service, affiliate tracking, non-essential analytics, AI feature or public-host configuration. The effective date changes only when reviewed, feature-matched text is deliberately published.