Privacy Policy and GDPR Information Notice — DoggyRadar

Effective Date: September 1, 2026

Document Version: 4.0.0


1. Data Controller

The data controller for personal data processed within the DoggyRadar website and mobile application (for Android, iOS, and Web platforms) is:

Krzysztof Wołosik – Javor

Sole Proprietorship

Address: ul. Anastazego Wika-Czarnowskiego 1A/7, 80-365 Gdańsk, Poland

Tax ID (NIP): PL5922047567

The Data Controller has not appointed a Data Protection Officer. All inquiries concerning the exercise of rights under Regulation (EU) 2016/679 (GDPR) should be directed to rodo@doggyradar.com.


2. Scope and Nature of the Service

DoggyRadar is a social platform dedicated to dog owners and guardians, offering features including:


3. Categories of Personal Data Processed

  1. Account and Authentication Data: email address, password hash (bcrypt/argon2), date of birth (required for age verification), first name / username, phone number (optional), MFA status (multi-factor authentication).
  2. Supervised Accounts (individuals under 16 years of age):
  1. Dog Data: name, breed, age, weight, gender, behavioral traits, microchip number, passport details, and health card.
  2. Geolocation and Spatial Data:
  1. User Content: private and group chat messages, forum threads and replies, dog and profile photos (stripped of EXIF/GPS metadata prior to publication).
  2. Diagnostic and Technical Data: device identifiers, push notification tokens (FCM / APNs), IP addresses, error logs, and telemetry.
  3. Payment and Subscription Data: transaction identifiers, DoggyRadar FULL subscription status, expiration dates. The Data Controller does not process payment card numbers — billing is handled directly by Apple App Store, Google Play, or certified payment processors.

4. Purposes and Legal Bases for Processing (GDPR)

| Processing Purpose | Data Scope | Legal Basis (GDPR) |

|---|---|---|

| Registration and management of standard user account | Account data, email, password hash, birth date | Art. 6(1)(b) GDPR (contract performance) |

| Provision of Supervised Account services for minors | Child profile, dog data, walk records | Art. 6(1)(b) GDPR (contract performance) |

| Provision of map services, walk tracking, and patrol | GPS coordinates, dog data | Art. 6(1)(b) GDPR (contract performance) |

| Voluntary location sharing with other users on the map | Public map location data | Art. 6(1)(a) GDPR (GDPR consent) |

| Processing of minor's consent-based data (e.g., map visibility) | Child location data, dog profile | Art. 6(1)(a) in conjunction with Art. 8(1) GDPR (parental consent) |

| Recording and retaining legal guardian consent evidence | Guardian/child pseudonyms, scope, version, MFA, IP, User-Agent | Art. 6(1)(c) in conjunction with Art. 7(1) & Art. 8(2) GDPR (legal obligation to demonstrate consent) & Art. 6(1)(f) GDPR (defense of legal claims) |

| Chat and forum communication | Message contents, forum posts, attachments | Art. 6(1)(b) GDPR (service delivery) |

| Provision of DoggyRadar FULL subscriptions | App store purchase identifiers | Art. 6(1)(b) GDPR (contract) & Art. 6(1)(c) GDPR (tax and accounting obligations) |

| Sending push notifications regarding walks and hazards | Push token, device identifier | Art. 6(1)(a) GDPR (GDPR consent) |

| Displaying ads in free tier (Free Tier) | Advertising identifier (Google AdMob / UMP) | Art. 6(1)(a) GDPR (UMP consent; no profiling of children) |

| Ensuring security, abuse prevention | System logs, IP address, telemetry | Art. 6(1)(f) GDPR (legitimate interest) |

| Legal claims establishment and defense | Transaction records, correspondence, consent records | Art. 6(1)(f) GDPR (legitimate interest) |

*Note:* Device operating system location permissions (Android/iOS) represent hardware access permissions and are distinct from the legal bases for processing personal data under Article 6 GDPR.


5. Data Security and Communication Architecture

  1. Encryption in Transit: All communication between the app and server is protected using TLS (HTTPS / WSS).
  2. Server-Side Chat Encryption: Private and group chat messages are encrypted at rest on the server using AES-256-GCM. Chat is not end-to-end encrypted (E2EE) — the server processes and decrypts message content for standard delivery, history synchronization, and safety moderation.
  3. Photo Privacy: All photos uploaded to the service are automatically stripped of EXIF metadata, including GPS tags.
  4. Ghost Mode:

6. Data Recipients and Transfers Outside the EEA

Personal data is transferred only to trusted processors:

Transfers outside the EEA rely on Standard Contractual Clauses (SCC) approved by the European Commission or the EU-US Data Privacy Framework.


7. Data Retention (Objective Criteria — Art. 13(2)(a) GDPR)

  1. Account and profile data: for the duration of the active account in the service.
  2. GPS coordinate history:

Raw GPS coordinates collected during walks are stored in the database only for the time necessary to compute the walk route and provide the service, after which they are automatically purged in daily retention batches (default software configuration: 90 days, configurable from 1 to 3650 days or disabled for technical diagnostics). Aggregated walk summaries (distance, duration) remain on the user profile until explicitly deleted by the user.

  1. Data handling upon account deletion:
  1. Billing data: retained for statutory tax/accounting periods and until statutory limitation periods expire.
  2. Guardian consent evidence records after account deletion:

In the `guardian_consents` table, direct user foreign keys (`guardian_user_id`, `child_user_id`) are set to `NULL`, while profiles, dogs, chats, and routes are permanently purged. For statutory accountability (Art. 7(1) & Art. 8(2) GDPR) and legal defense (Art. 6(1)(c) & (f) GDPR), minimized pseudonymous audit trail records are retained:

These records are retained for the duration of statutory civil claim limitation or regulatory scrutiny periods, after which they are permanently purged. This process constitutes pseudonymization, not anonymization.

  1. Supervised Accounts upon consent withdrawal: retained in a locked state for 7 days (grace period), then permanently purged.

8. User Rights and Account Deletion Procedure

Users have the right to:

Account Deletion Procedure:

Accounts can be deleted directly in the mobile application (Profile → Settings → Your Data (GDPR) → Delete Account) or via the web form at https://doggyradar.com/delete-account. Deletion requires entering the account password, typing `USUWAM KONTO`, and MFA verification (if enabled).