Privacy Policy
Last updated: 25 July 2026
1. Who we are
Suzana Lepanovic, trading as HearthlyLabs ("HearthlyLabs", "we", "us"), is the data controller for the personal data described in this policy.
Bregnegangen 8, 2300 Copenhagen, Denmark Email: [email protected]
HearthlyLabs is not yet incorporated. It currently operates as a sole proprietorship. When the company is incorporated we will update this policy with the company name and CVR number, and we will tell subscribers by email.
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy questions go to the address above and reach us directly.
2. What this policy covers
This policy covers our website at hearthlylabs.com and our email newsletter. It does not cover the HearthlyLabs product, which is not yet available. When the product launches it will have its own separate privacy notice, because it will process different data on a different legal basis.
3. What we collect, why, and on what legal basis
| What we collect | Why | Legal basis | How long we keep it |
|---|---|---|---|
| Email address | To send you the monthly update | Consent — Art. 6(1)(a) | Until you unsubscribe, or 24 months of inactivity, whichever comes first |
| First name | To address the email to you | Consent — Art. 6(1)(a) | Same as above |
| Role (optional) | To make what we send more relevant | Consent — Art. 6(1)(a) | Same as above |
| Design-partner interest | To identify people who want to test early and be considered for the first batch | Consent — Art. 6(1)(a) | Same as above |
| Record of your consent: timestamp, IP address, and the form wording you agreed to | To prove we have valid consent, which the law requires us to be able to do | Legal obligation — Art. 6(1)(c), read with the accountability duty in Art. 7(1) | 3 years after you unsubscribe |
| Server logs: IP address, browser type, time of visit | Security and keeping the site running | Legitimate interest — Art. 6(1)(f) | 30 days |
We do not collect health data, biometric data, or any other special category of personal data through this website. We do not ask for it, and you should not send it to us.
We do not use your data for automated decision-making or profiling within the meaning of Article 22 GDPR.
4. If you do not give us this data
Nothing happens except that you will not receive the newsletter. Providing your data is not a condition of using the website, and there is no other consequence.
5. Who else touches your data
We keep our list of processors deliberately short.
| Processor | What they do | Where data may go |
|---|---|---|
| MailerLite (MailerLite Limited, Ireland) | Sends the newsletter and stores the subscriber list | MailerLite Limited is the MailerLite contracting entity for customers whose account country is in the EEA, the UK or Switzerland. Subscriber data is hosted in the Netherlands by Google Cloud EMEA Ltd (Ireland), certified to ISO/IEC 27001:2022. MailerLite also uses Vercom S.A. (Poland) as a sub-processor for group corporate services. |
| Cloudflare, Inc. | Provides DNS, security, and content delivery for the website | This may involve processing your IP address outside the EU. |
We do not sell your data. We do not share it with advertisers. We do not disclose it to any third party for that party's own marketing purposes.
6. Transfers outside the EU and EEA
Newsletter data stays in the European Economic Area. Our email provider's contracting entity for customers in the EEA, the UK and Switzerland is MailerLite Limited in Ireland, and subscriber data is hosted in the Netherlands. Its named sub-processors are established in Ireland and Poland.
Website delivery through Cloudflare may involve processing in countries outside the EEA, including the United States. Where that happens the transfer is protected by the European Commission's Standard Contractual Clauses, together with the supplementary measures set out in Cloudflare's data processing addendum. You can ask us for details of the safeguards in place at any time.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict or object to our processing (Art. 18 and Art. 21);
- receive your data in a portable format (Art. 20);
- withdraw your consent at any time, free of charge, by clicking unsubscribe in any email or writing to us. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it (Art. 7(3)).
To exercise any of these, email [email protected]. We will respond within one month, as Article 12(3) requires.
You also have the right to complain to the Danish Data Protection Agency:
Datatilsynet · Carl Jacobsens Vej 35 · 2500 Valby · Denmark · datatilsynet.dk
If you are outside the EU, you may also have rights under your own local law, and you can raise any concern with us directly at the address above.
8. Children
This website is not directed at children. Under section 6(3) of the Danish Data Protection Act, a person must be at least 13 years old to consent to an information society service on their own; below that age, consent must be given or approved by a holder of parental responsibility. We do not knowingly collect data from children under 13. If you believe we have, contact us and we will delete it.
9. Cookies
See our Cookie Policy.
10. Security
We use encryption in transit (HTTPS), we restrict access to the subscriber list to people who need it, and we use processors certified to ISO/IEC 27001. No system is perfectly secure, but we take this seriously and we keep the amount of data we hold deliberately small.
11. Changes
If we change this policy we will update the date at the top. If the change is significant we will tell you by email. We will also re-issue this policy when HearthlyLabs is incorporated.