Privacy

Privacy at Dyrli

This page explains what information Dyrli uses, why we need it and how long it is kept. We update the page when something changes.

In short

You can use Services, Insurance facts and Pet hazards without an account. New accounts are created by invitation only. Lost & Found is not open for public use. The providers that run Dyrli may record technical information such as IP addresses and requests to keep the service secure and available.

What is stored in your browser

If you choose dark mode, your browser stores the choice in localStorage and in the dyrli-theme cookie. This lets Dyrli remember the choice on your next visit. The cookie lasts for up to one year; localStorage remains until you clear site data. The preference is saved only when you change the theme.

Sign-in uses protected cookies for the session and 18+ declaration. Password recovery uses a short-lived cookie. If you message about a case, the browser receives a random HttpOnly cookie that only grants access to that conversation.

Advertising, analytics and tracking

Dyrli may be funded by clearly labelled, general advertising. Payment does not affect which businesses appear, their order in search results or the content of listings.

Vercel Web Analytics and Speed Insights are not enabled. Dyrli sends no browser visit measurements to these services.

Dyrli uses no advertising or tracking pixels. Necessary technical logs at our hosting providers support security and troubleshooting. We will provide information and obtain consent where required before introducing measurement.

Who is responsible – and where is data processed?

The controller is Hagman AS. Organisation no. NO 991 626 220 MVA (VAT registered), registered in the Norwegian Register of Business Enterprises. Address: Njærheimvegen 81, 4365 Nærbø, Norway. Privacy questions can be sent to thomas@dyrliapp.no.

Supabase stores Dyrli's project database in the Paris region in the EU. Vercel provides the website and technical logs and may process information in the United States and other countries outside the EEA. Domene AS provides email. When a provider or subprocessor handles information outside the EEA, the transfer must be covered by the provider's data processing agreement and the EU Standard Contractual Clauses or another valid transfer mechanism.

Supabase Data Processing AgreementVercel Data Processing AgreementDomene AS privacy

Accounts and email

The account uses email and password through Supabase Auth. Dyrli does not store the password in its own database. Email is used to confirm the account, sign in and choose a new password. You must confirm the email and declare that you are over 18 before using private Lost & Found features.

Before real accounts open, we will have agreements, retention periods, security limits, leaked-password checks and a clear privacy contact in place.

Google sign-in

Google sign-in is not enabled yet. If you later choose Google, Dyrli only requests basic sign-in information: openid, email and profile. Google sends a unique account identifier, email address and profile information you allow, such as name and profile picture, to Supabase Auth. Dyrli does not request access to Gmail, Google Drive, contacts or other Google services.

Dyrli uses the information to verify your identity, connect the sign-in to an invited Dyrli account and protect the account. Google and Supabase take part in the sign-in flow and process information under their own privacy policies. Dyrli's code does not store your Google password or use the sign-in with other Google services.

Google sign-in will only open after we publish why the information is used, how long it is kept, how it is deleted, which agreements apply and who is responsible.

Service directory

Services uses public information from the Brønnøysund Register Centre and the businesses' own websites. We may show a name, organisation number, municipality or postal place, services, animals, website, where the information came from and the date we last checked it. We do not show street addresses, phone numbers, email addresses, personal contacts, reviews or popularity rankings.

The aim is to help you find a pet service and continue to the business's own website. Information that can also be linked to a person is only processed when Dyrli can document a valid legal basis. The usual basis for directory information is legitimate interests under GDPR Article 6(1)(f).

Sole proprietorships and businesses we have not reliably linked to the Central Coordinating Register are only shown after the business has received the information required by Article 14 from us by email, and we have seen that the email was delivered. ANS and DA partnerships with a person's name in the business name are also only shown after the notice has been delivered. Business names are shown as they appear in the Central Coordinating Register or on the business's own website, also when the name contains a person's name. When information becomes too old or the page it came from disappears, we remove or recheck it. The directory makes no automated decisions, builds no profiles and provides no recommendations or popularity rankings.

Business pages can be viewed by everyone. Error reports are private and can only be read by Dyrli staff who need access and the providers running email, database and hosting. A report never changes the directory automatically. Providing an email address is optional. We use the information to handle the report and correct errors, based on legitimate interests. Where the message concerns a privacy right, we also process it to meet our legal obligations.

Use “Report an error” or email bedrift@dyrliapp.no if you want to access, correct, erase or restrict information, object or ask for a business to be removed. You may also complain to the Norwegian Data Protection Authority. We respond without undue delay and normally within one month. If a lawful extension is needed, we explain why within the first month.

The report queue stores the reason, optional message and optional email address privately. It does not store the raw IP address; a technical actor code used for abuse prevention is deleted after one hour. After confirmed email delivery, the report is deleted automatically after 90 days. Undelivered reports are retained until delivery so an objection is not lost during a transport failure.

The purpose is to make public pet services easier to find. Showing a business name, place, services, animals, website and where the information came from is necessary for the directory to work. The directory shows no street addresses, contact persons or personal contact details, including for sole proprietorships. Dyrli has completed a legitimate-interests balancing assessment for the directory's current contents, updated on 2 October 2026. It covers business names containing personal names and the possibility of general advertising that does not influence the directory. The assessment does not remove the requirement to deliver notice before showing sole proprietorships, businesses with an unknown legal form, or ANS/DA partnerships with personal names. New fields, tracking or other significant changes require a new assessment.

Complain to the Norwegian Data Protection Authority

Data in the tools

Insurance facts and pet-hazard information come from the pages linked in the tool. Search and filters are handled in the tool. When a tool fetches information, technical requests may be recorded in operational logs.

Lost & Found may process text, an approximate area, municipality, time, a private distinguishing feature, an image with hidden information removed, messages, blocks and reports. Phone numbers, email, exact addresses, chip numbers and the private feature must not be published. Images and text are checked before public display.

Contact

Privacy questions can be sent to thomas@dyrliapp.no. Accounts and Lost & Found will not open for real personal information until that service's separate privacy and operations review has been approved.

Email Dyrli about privacy