[h] HearthlyLabs

Privacy Policy

Last updated: 20.07.2026
  1. Who we are
    Suzana Lepanovic, trading as HearthlyLabs (“HearthlyLabs”, “we”, “us”), is the data controller for the personal data described in this policy.

    Bregnegangen 8, 2300 Copenhagen, Denmark
    Email: hello@hearthlylabs.com

    HearthlyLabs is not yet incorporated. It currently operates as a sole proprietorship. When the company is incorporated we will update this policy with the company name and CVR number, and we will tell subscribers by email.

    We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy questions go to the address above and reach us directly.

  1. What this policy covers

    This policy covers our website at hearthlylabs.com and our email newsletter. It does not cover the HearthlyLabs product, which is not yet available. When the product launches it will have its own separate privacy notice, because it will process different data on a different legal basis.

  1. What we collect, why, and on what legal basis

What we collect

Why

Legal basis

How long we keep it

Email address

To send you the monthly update

Consent — Art. 6(1)(a)

Until you unsubscribe, or 24 months of inactivity — whichever comes first

First name

To address the email to you

Consent — Art. 6(1)(a)

Same as above

Role (optional)

To make what we send more relevant

Consent — Art. 6(1)(a)

Same as above

Design-partner interest

To identify people who want to test early and be considered for the first batch

Consent — Art. 6(1)(a)

Same as above

Record of your consent: timestamp, IP address, and the form wording you agreed to

To prove we have valid consent, as the law requires us to be able to do

Legal obligation — Art. 6(1)(c), read with the accountability duty in Art. 7(1)

3 years after you unsubscribe

Server logs: IP address, browser type, time of visit

Security and keeping the site running

Legitimate interest — Art. 6(1)(f)

30 days

We do not collect any health data, biometric data, or any other special category of personal data through this website. We do not ask for it and you should not send it to us. We do not use your data for automated decision-making or profiling within the meaning of Article 22 GDPR.

  1. If you don't give us this data
    Nothing happens except that you will not receive the newsletter. Providing your data is not a condition of using the website, and there is no other consequence.

  1. Who else touches your data
    We keep our list of processors deliberately short.

    · MailerLite (UAB MailerLite, Lithuania) sends the newsletter and stores the subscriber list. Under MailerLite's Data Processing Addendum, subscriber data for EEA customers is held in data centres in Germany and the Netherlands, certified to ISO/IEC 27001:2022.

    · Cloudflare, Inc. provides DNS, security, and content delivery for the website. This may involve processing your IP address outside the EU.

    We do not sell your data. We do not share it with advertisers. We do not disclose it to any third party for that party's own marketing purposes.

  1. Transfers outside the EU/EEA
    Newsletter data stays in the EU.
    Website delivery through Cloudflare may involve processing in countries outside the EEA, including the United States. Where that happens the transfer is protected by the European Commission's Standard Contractual Clauses, together with the supplementary measures set out in Cloudflare's data processing addendum. You can ask us for details of the safeguards in place at any time.

  1. Your rights
    Under the GDPR you have the right to:

    · access the personal data we hold about you (Art. 15);

    · have inaccurate data corrected (Art. 16);

    · have your data erased (Art. 17);

    · restrict or object to our processing (Art. 18 and Art. 21);

    · receive your data in a portable format (Art. 20);

    · withdraw your consent at any time, free of charge, by clicking unsubscribe in any email or writing to us. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it (Art. 7(3)).


To exercise any of these, email hello@hearthlylabs.com. We will respond within one month, as Article 12(3) requires.

You also have the right to complain to the Danish Data Protection Agency:

Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark · datatilsynet.dk

If you are outside the EU, you may also have rights under your own local law, and you can raise any concern with us directly at the address above.

  1. Children
    This website is not directed at children. Under section 6(3) of the Danish Data Protection Act, a person must be at least 13 years old to consent to an information society service on their own; below that age, consent must be given or approved by a holder of parental responsibility. We do not knowingly collect data from children under 13. If you believe we have, contact us and we will delete it.

  1. Cookies
    See our Cookie Policy.

  1. Security
    We use encryption in transit (HTTPS), we restrict access to the subscriber list to people who need it, and we use processors certified to ISO/IEC 27001. No system is perfectly secure, but we take this seriously and we keep the amount of data we hold deliberately small.

  1. Changes
    If we change this policy we will update the date at the top. If the change is significant we will tell you by email. We will also re-issue this policy when HearthlyLabs is incorporated.

The biological brain for indoor environments

Suzana Lepanovic, trading as HearthlyLabs · Bregnegangen 8, 2300 Copenhagen, Denmark · hello@hearthlylabs.com

HearthlyLabs interprets the environment, not you. It does not diagnose, measure your body, or predict individual health outcomes. Guidance is directional and evidence-based, not medical advice.