My Horse Diary

Privacy

Notice under Regulation (EU) 2016/679 (GDPR) · Last updated: 17 September 2026

1. Data controller

Debora Carofiglio, Strada Lungofino 187, 65013 Città Sant’Angelo (PE), P.IVA IT02411430685. For any request about your data: debora.carofiglio@gmail.com.

2. What data we process

3. Why and on what basis

We do no profiling and no advertising based on your data.

4. Schools and students: who is responsible for what

When a school enters its students’ data, the school is the controller of that processing and My Horse Diary acts as processor on its behalf (art. 28 GDPR): we store and display the data according to the school’s instructions and use it for nothing else. The school must inform its students and have a legal basis for entering them.

If the student has their own account, the data in their diary remains theirs: the school sees the horse and health due dates only if the student consents; the lessons, competitions and fees the school schedules are shown to them because they gave the school their email. The student can leave the school at any time from their app.

5. Who sees the data

Only you (and your school, within the limits above). To run the service we rely on providers that process data on our behalf, with contractual guarantees:

Fonts and images are served from our own servers: opening the site contacts no third-party services other than those listed. We do not disclose data to anyone else, except where required by law or by an authority.

6. For how long

As long as your account is active. If you delete it, the data is erased within 30 days, except what we must keep by law (for example accounting records of payments, 10 years). An account inactive for more than 24 months may be closed after an email notice.

7. Your rights

You can ask us at any time to access your data, correct it, delete it, restrict its processing, receive it in a portable format (export), object to processing and withdraw the consents you gave. Write to debora.carofiglio@gmail.com: we reply within 30 days. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or with the supervisory authority of your country.

8. Security

Encrypted connections (HTTPS), passwords stored with hash and salt, signed sessions, database in the European Union with backups, keys kept outside the code. No system is perfect: if we detect a breach that concerns you, we notify you as required by law.

9. Minors

The service is intended for adults. A school may register underage students with the consent of whoever holds parental responsibility, for which the school is responsible.

10. Cookies

We use only technical cookies: see the Cookie policy.

11. Changes

If this notice changes, we publish it here with the new date; for significant changes we notify you by email or in the app.