Privacy policy
Last updated: 11 August 2026
This document is a draft. It will be completed with the operator's details before the service goes live.
Below we explain what personal data we process in connection with Zamerdane, for what purpose, and on what legal basis.
Data controller
The controller of personal data is [nazwa firmy], [adres siedziby], VAT ID [NIP].
For anything concerning personal data, write to kontakt@zamerdane.pl.
Controller and processor roles
For the data of people who create a School, and for billing data, we act as the controller.
For end-client and dog data entered into the Service by a School, we act as a processor — the School remains the controller of that data.
What we process
Account data: email address, name, school name, role in the team.
Billing data: invoicing details, issued invoices with their KSeF number, payment history and subscription status.
Data entered by the School: client contact details, dog profiles, booking history, session notes, and dogs’ training goals and progress.
Processing agreements with guest trainers: the agreement text, the parties’ details, and who accepted it and when.
Technical data: IP address, browser information and events needed to keep the Service secure.
Purposes and legal bases
Providing the service and running your account — Art. 6(1)(b) GDPR (performance of a contract).
Billing, accounting and tax obligations — Art. 6(1)(c) GDPR (legal obligation).
Security, handling enquiries and pursuing claims — Art. 6(1)(f) GDPR (legitimate interest).
Marketing messages — Art. 6(1)(a) GDPR (consent), which you can withdraw at any time.
Recipients
We use trusted providers who process data only on our instructions: Supabase (database and authentication), Vercel (hosting), Stripe (payments), Google (Google Calendar sync, only once a user connects their account), Mapbox (geocoding location addresses), Microsoft Azure OpenAI (walk arrangement suggestions and turning dictated notes into text), inFakt (issuing subscription invoices and submitting them to KSeF — subscription buyer details only) and Sentry (error monitoring, data held in the EU — it receives only the error description, app version, device and browser type and the signed-in account id when something in the app fails; no IP address, no screen recording, no usage measurement).
Walk arrangement suggestions are proposals only — they never create or change a booking without a trainer’s decision. The recording of a dictated note is not kept: only the text remains, which the trainer reads and can correct before saving.
A guest trainer invited by a School sees its clients’ data only on the sessions they run themselves, and acts as the School’s processor — not as our sub-processor.
Transfers outside the EEA
Some providers may process data outside the European Economic Area. Where they do, the transfer relies on standard contractual clauses approved by the European Commission.
Retention
Account data is kept for the duration of the contract and for up to 12 months afterwards.
Billing data and invoices are kept for the period required by tax law, as a rule 5 years — including after the account is deleted.
Data entered by a School is deleted or returned after the contract ends, according to the School’s instruction.
Error reports in Sentry are kept for up to 90 days.
Your rights
You have the right to access your data, rectify it, erase it, restrict processing, port it, and object to processing based on legitimate interest.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office in Poland.