Privacy at Heartkemy
Who is responsible
Heartkemy is the trading brand of Rafael Horvat EI, a French individual business, SIRET 99240617300011.
You can write to me at [email protected] about your personal information, or at [email protected] about a booking or service.
Postal address: Rafael Horvat, Chez Cazalavera, 16 rue des Marchands, 09000 Foix, France.
This notice covers Agency enquiries, session applications, bookings, payments, appointments and related correspondence. Separately agreed work may need additional information about its particular data use.
What I collect
For a booking, I ask for your name, email address, timezone and selected appointment. You may also provide context about the help you need. Required fields are marked; without the necessary contact and appointment details, I cannot arrange the session. Leaving optional context blank does not prevent an ordinary booking.
For a reduced or free consultation application, I also ask about the idea, intended benefit, proposed contribution and reason for applying. I review applications myself. An application may lead to a private invitation with a particular price and expiry, but does not reserve an appointment.
Please do not enter passwords, full payment-card details, medical information or other sensitive personal information in free-text fields. Share only what is useful for the requested service. Do not include another person's private information unnecessarily.
The operational record includes booking and payment references, the amount and currency, appointment/payment/refund status, and the version of the booking terms accepted. Related emails, working notes and the promised written report may also be kept. If a separate compensation payment needs payment details that I do not already hold, I ask only for the details necessary to make that payment through the agreed method. Do not send full card details or banking passwords.
Technical records may include access information, IP addresses and events needed to protect the service and investigate errors.
Why I use it
I use the information needed to respond to your request, consider your application, arrange and provide the agreed service, manage payment, and communicate about the appointment. For your own booking, the legal ground is preparing or performing the contract at your request. When you act for an organisation, handling its contact person's information is based on the legitimate interest in managing that professional relationship.
Keeping necessary invoice and accounting evidence, and handling requests to exercise data-protection rights, are based on legal obligations. Protecting the service, preventing misuse and handling disputes are based on legitimate interests in maintaining a secure service and establishing or defending rights.
Optional uses that require consent are treated separately. Accepting booking terms is not blanket consent to every use of your information.
Services involved
Only I have internal access within Heartkemy. The following services handle information for their respective functions:
- Contabo: Provides the virtual server on which Rafael hosts the website and booking application.
- Cloudflare: Proxies website and Cal.com traffic for DNS, TLS and network-security functions before it reaches the Contabo-hosted applications.
- Neon: Stores operational booking, application and payment-state records.
- Self-hosted Cal.com on Contabo: Manages availability, attendee details, appointments and scheduling messages.
- Daily: Provides video calls through Cal Video, including the connection information needed for the call.
- Apple iCloud: Sends and stores appointment correspondence and handles the connected calendar. Relevant working files may also be kept in iCloud Drive.
- Stripe: Hosts payment entry and processes payments/refunds. Any Stripe payment receipt is separate from the seller's invoice.
- Indy: Is used by Rafael to prepare and retain sequentially numbered invoices and related accounting evidence.
- Contabo / Obsidian LiveSync: Also stores relevant working notes when I synchronise them through my self-hosted notes system.
- Sanity: Holds website/editorial and CV content.
Stripe receives the payment information you enter on its hosted form. I do not receive or store your complete card number. Stripe also has its own responsibilities for some payment, fraud-prevention and legal processing, described in its privacy information.
Necessary information may also be provided to a mediator, authority or adviser when required to handle a complaint, comply with the law, or establish or defend rights.
Calls, recordings and AI
Recording and transcription are disabled in the Cal/Daily setup used for these sessions. I do not use AI to transcribe or process client transcripts.
A recording would require a separate, specific agreement with you before it starts. You can decline it and still receive the included written report.
Browser storage and private links
Necessary browser storage helps a booking request continue and protects access to it. Saved form progress is encrypted on the application server; the browser's session storage holds the private access capability rather than the form answers.
Private return and invitation links can give access to your request. Treat them like confidential correspondence and do not share them publicly. Expiry of a link does not remove your statutory rights: you can still contact me.
Locations and international transfers
The selected booking-database region is Frankfurt, Germany. The Contabo agreement identifies its French data-centre operator in Lauterbourg. The website, self-hosted Cal and self-hosted notes system use the Contabo infrastructure described above. These server locations do not mean that every connected provider, support team or subprocessor handles information only within the European Economic Area (EEA).
Some providers process information outside the EEA, including in the United States. Their published transfer arrangements are described below. The EU–US Data Privacy Framework (DPF) covers transfers to participating US organisations within the scope of their certification under the European Commission’s adequacy decision. European Commission standard contractual clauses (SCCs) provide contractual safeguards for transfers not covered by an applicable adequacy decision.
Stripe — payment information: Stripe’s Data Transfers Addendum gives the DPF priority for covered transfers to Stripe, LLC in the United States and provides SCCs as the alternative mechanism: https://stripe.com/legal/dta.
Cloudflare — traffic and security information; Daily — video-call connection information: their data-processing addenda provide for the DPF for covered US transfers and SCCs when the DPF does not apply. Daily identifies the United States as its primary processing location. Details: https://www.cloudflare.com/cloudflare-customer-dpa/ and https://www.daily.co/legal/data-processing-addendum/.
Neon / Databricks — booking records: choosing Frankfurt does not exclude international support or subprocessors. Databricks identifies Neon, LLC within its DPF certification and provides SCCs for restricted transfers. The current Neon schedule and relevant documents are available at https://neon.com/platform-terms, https://www.databricks.com/legal/privacynotice and https://www.databricks.com/legal/dpa.
Apple iCloud — correspondence, calendar information and relevant working files: Apple’s privacy notice states that its international transfers of EEA personal data are governed by SCCs and that data it collects is generally stored in the United States. Apple explains how to request copies at https://www.apple.com/legal/privacy/en-ww/ and https://www.apple.com/privacy/contact/.
Indy — invoice information: Indy’s published notice permits processing inside and outside the EEA and states that it checks DPF certification for US recipients. It does not identify every recipient of this account’s invoice data. Its notice and data-protection contact are https://www.indy.fr/politique-confidentialite/ and [email protected].
Sanity — editorial content and related technical processing: its data-processing addendum sets out the safeguards for international transfers, including SCCs for restricted transfers: https://www.sanity.io/legal/dpa. Agency booking-form answers are stored in Neon, not Sanity.
You can contact [email protected] for the relevant recipient details or a copy of the applicable safeguards. Information about other people or confidential commercial information may be redacted when copies are supplied.
How long I keep information
- Unfinished forms: 7 days after your last edit
- Declined, withdrawn or unused reduced/free-session applications: 90 days after the application closes or invitation expires
- Ordinary session notes, written reports, appointment contact/context and support emails: 1 year after the session or the relevant exchange closes
- Routine security/activity logs under my control: up to 6 months after the event
- Rolling recovery backups under my control: 90 days after creation
- A separately agreed recording or transcript, where one exists: 30 days after the written report is delivered
- Invoices and necessary accounting evidence: 10 years, using the applicable accounting starting date
- Electronic consumer contracts covered by the statutory archive rule: Kept from conclusion through 10 years after the service is performed
The long archive periods concern necessary evidence, not every working note. An unresolved payment issue, complaint, legal duty or dispute can justify retaining relevant information for longer than its ordinary working period. Unnecessary identifying details, including identifying free text, are removed when no longer needed.
The Agency application has a retention process to apply these periods to records it stores in Neon. When it runs, records connected to an unresolved payment, refund, appointment, active job or dispute are kept out of automated deletion, while eligible identifying free text, including names and email addresses, is removed.
Provider-held records and backup copies have their own deletion processes and any applicable legal obligations. Deleting or redacting an application record in Neon does not instantly delete every copy held by Stripe, Cal, iCloud Mail or Calendar, Obsidian LiveSync, Indy or a backup system. Rafael handles those systems through their available manual/provider processes. Owner-controlled rolling backups follow the 90-day target; provider recovery copies may age out on a different schedule. Expired records are not returned to ordinary use merely because a backup is restored.
Your rights
Depending on the circumstances, you can request access, correction, erasure, restriction or portability of your information. You can object to processing based on legitimate interests and withdraw consent for an optional use. Withdrawal does not change the lawfulness of what happened before it.
Write to [email protected]. I may ask for proportionate information to establish that the request concerns you, but will not routinely require extra identity documents. I respond without undue delay and normally within one month. If the law permits an extension because of complexity or the number of requests, I will explain it within that first month; the extension can be up to two further months.
Some information cannot be deleted immediately because of a legal obligation or a necessary dispute record. I will explain any applicable restriction.
You may complain to the CNIL, France's data-protection authority, using its complaints service, or to another supervisory authority competent for your situation.