Privacy Policy

1. Purpose of this document

This Policy explains how Canterivo protects user data, billing and technical data, as well as data entered by individual Stables. We apply data minimisation, role-based access control, and separation of data between Stables.

2. Two roles in data processing

The Service Provider acts as the data controller for account, contract, trial, subscription, payment, support, complaint, security, and log data. For data entered within a Stable’s workspace, the controller is generally the Client operating the Stable, while Canterivo acts as the data processor.

3. Categories of data

We may process first and last name, email address, telephone number, roles, assignment to a Stable and horses, bookings, training sessions, tasks, reports, messages, notes, files, and billing data. Technical data may include a shortened or hashed IP address, operation timestamps, session identifiers, error logs, and security logs. Horse-related data may include feeding, care, restrictions, and veterinary documentation.

4. Recipients and transfers

Data may be accessed by authorised users of the relevant Stable and by hosting, email, backup, and support providers to the extent necessary to provide the service. HotPay receives the data required to process payments and may act as an independent data controller. An up-to-date list of subprocessors and information about any transfers outside the EEA are available upon request.

5. Retention

Data is retained for the duration of the service and for a configurable period after termination where necessary for reactivation, export, settlements, security, and legal claims. Data may remain for a limited period in rotating backups. Retention periods required by tax or other legal obligations apply independently.

6. Security

We use password and token hashing, HTTPS-encrypted connections in the deployed environment, CSRF protection, rate limiting, secure session cookies, file type restrictions, private media access, tenant isolation controls, and auditing of administrative operations. However, no system can guarantee the complete absence of risk.

7. Rights and contact

Depending on the legal basis, individuals may have the right to access, rectify, erase, restrict processing, object, data portability, and lodge a complaint with the President of the Personal Data Protection Office in Poland. For data managed by a Stable, you should first contact the controller of that Stable. For account- and service-related matters: kontakt@konnoprzezzycie.pl.

Agnieszka Zielińska
ul. Bolesława Chrobrego 11A, Legionowo, Poland
kontakt@konnoprzezzycie.pl · complaints: reklamacje@konnoprzezzycie.pl

Scroll to Top