HART
HART Privacy Policy
Last updated: April 17, 2026
At HART, your privacy is a priority for me. This document explains what data I collect, why I do it, and how I protect it. Simply put: your data is safe with me, and I use it only to help you and your dog as well as I possibly can.
§ 1. Data Controller
The controller of your personal data is KAROL MICHALAK, operating under the business name KAROL MICHALAK DESIGNS, with its registered office at 08-110 Siedlce, ul. Czesława Dylewicza 15/E, Poland, NIP (tax ID) 8212664708, REGON 384169388 (the “Controller”). For any matter regarding the protection of personal data, you can reach me at: kontakt@hart-dog.pl.
§ 2. Purposes and Legal Bases for Processing
Providing your personal data is voluntary but necessary to achieve the purposes below. Your data will be processed to: a) Respond to your message and maintain further correspondence — legitimate interest of the Controller (Art. 6(1)(f) GDPR). b) Take steps necessary to conclude and properly perform a service agreement (e.g. a behavioural consultation, photography session), including analysis of the intake questionnaire you complete (Art. 6(1)(b) GDPR). c) Comply with legal obligations of the Controller, e.g. issuing invoices (Art. 6(1)(c) GDPR). d) Establish, pursue, or defend potential claims — legitimate interest of the Controller (Art. 6(1)(f) GDPR). e) Record the course of the consultation for the purpose of analysis and planning therapeutic work, solely for the Controller’s internal use; the recording may be made available to you as the Client upon request. Applicable only where you have given a voluntary, separate consent (Art. 6(1)(a) GDPR). f) Use and publish your image and your dog’s image for marketing, promotional, and educational purposes of the HART brand, solely on the basis of your voluntary, separate consent (Art. 6(1)(a) GDPR).
§ 3. Recipients of Data
Your data may be accessed by providers supplying services necessary to run my business, strictly within the necessary scope and under appropriate data processing agreements. In particular: • Supabase (database and authentication) — EU region • Resend (email delivery) • Vercel (website hosting) and Vercel Analytics (anonymous statistics) • Sentry (application error monitoring) Additionally, only after you grant consent in the cookie banner: • Google Ireland Ltd. — Google Analytics 4 and Google Ads (category: analytics, ads) • Meta Platforms Ireland Ltd. — Meta Pixel (category: ads) Some of these providers may transfer data to the United States. Transfers rely on the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) or Standard Contractual Clauses under Art. 46 GDPR. Additionally — accounting, banking, and email-hosting services required to run the business.
§ 3a. Cookies and Analytics
The site uses three cookie categories: 1. Necessary — admin session, language preference, anonymous Vercel Analytics (does not identify individuals, does not track across sites). Always on, no consent required — essential for the site to work. 2. Analytics — Google Analytics 4. Helps understand how visitors use the site, what content is valuable, and where issues appear. Active only after you grant consent. 3. Advertising — Meta Pixel and Google Ads conversion tag. Measure the effectiveness of ads that lead to this site (ads are not displayed on the site itself). Active only after you grant consent. Default state of all categories besides Necessary is "denied" per Google Consent Mode v2 standard. Your choice is stored in your browser (localStorage) and applies until changed. You can change preferences anytime by clicking "Manage consent" in the footer.
§ 4. Data Retention
Your personal data will be retained for the period necessary to achieve the purposes for which it was collected, in particular: • for the duration of our correspondence, • for the duration of the service agreement, and after that period until the expiry of the limitation period for any potential claims, in accordance with applicable law, • in the case of consultation recordings — until you withdraw your consent, • in the case of data processed on the basis of consent for marketing purposes — until you withdraw your consent.
§ 5. Your Rights (GDPR)
In connection with the processing of your personal data, you have the right to: • request access to your personal data, its rectification, deletion, or restriction of processing, • object to processing, • data portability, • withdraw consent at any time (for data processed on the basis of consent) — without affecting the lawfulness of processing carried out before its withdrawal, • lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland). Please direct any requests to exercise your rights to: kontakt@hart-dog.pl.
§ 6. Other Information
Providing your data is voluntary, but failing to provide it may make it impossible to contact you or enter into an agreement. Your personal data will not be transferred outside the European Economic Area. Your personal data will not be processed through automated decision-making, including profiling.
§ 7. Contact
For data protection matters, write to: kontakt@hart-dog.pl.