Privacy Policy

Effective date: 3 July 2026 · Version 1.0

Operated by: Safadi Abdulsalam MWN E.V., 1095 Budapest, Lechner Ödön fasor 2. em. 1, ajtó 6., Hungary

1. Who we are

hello DORA ("DORA", "we", "us") is a dog daycare and boarding management platform operated by:

  • Operator: Safadi Abdulsalam MWN E.V. (sole proprietorship registered in Hungary)
  • Registered address: 1095 Budapest, Lechner Ödön fasor 2., 1st floor, door 6, Hungary
  • Registration number: 62174295
  • Tax number: 91965626-1-43
  • Contact: info@hellodora.app

2. Our two roles under the GDPR

DORA is business software used by dog daycare and boarding facilities ("Facilities"). Depending on the data, we act in one of two roles:

  • We are the data controller for the data of people who hold an account with us directly: Facility staff accounts, dog-owner portal accounts, billing records, and website visitor data.
  • We are a data processor for the data a Facility stores in DORA about its own customers — dog owners, their contact details, and their dogs. For that data, the Facility is the controller and this processing is governed by our Service Agreement (including its data processing terms). If you are a dog owner with questions about how a Facility handles your data, please contact the Facility first.

3. What we collect and why

3.1 Account data (we are controller)

  • Facility staff accounts: full name, email address, role, password (stored as a secure hash). Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
  • Dog-owner portal accounts: name, email address, password (hashed). Legal basis: performance of a contract (Art. 6(1)(b)).
  • Billing data: subscription plan, payment status and invoicing details, processed through Stripe. We do not store card numbers. Legal bases: contract (Art. 6(1)(b)) and legal obligation — accounting rules (Art. 6(1)(c)).
  • Technical data: server logs (IP address, timestamps, requested pages) kept for security and fault diagnosis. Legal basis: legitimate interest (Art. 6(1)(f)) in keeping the service secure.

3.2 Facility data (we are processor)

  • Client records entered by a Facility: owner names, email addresses, phone numbers, addresses, emergency contacts.
  • Dog records: name, breed, photos, health and behaviour notes, medication, vet contacts, microchip number, uploaded documents (e.g. vaccination records).
  • Operational records: bookings, check-ins/check-outs, kennel assignments, payments recorded by the Facility.

We process this data solely on the Facility's instructions and never use it for our own purposes.

4. Cookies

DORA uses only essential cookies required to keep you signed in (authentication session). We do not use advertising or third-party analytics cookies.

5. Who we share data with

We use a small number of service providers (subprocessors) to run DORA:

  • Supabase — database, authentication and file storage.
  • Stripe — subscription payments and invoicing.
  • Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA — application hosting.

We do not sell personal data and do not share it with anyone else, except where required by law.

6. International transfers

Where a service provider processes data outside the European Economic Area, the transfer is protected by an adequacy decision of the European Commission or by Standard Contractual Clauses.

7. How long we keep data

  • Account data: for the life of the account, then deleted or anonymised within 90 days of account closure.
  • Individual dog or client profiles: when a Facility removes a dog or client profile while the Facility account remains active, that profile is immediately removed from active use. The underlying data is permanently deleted or anonymised within 90 days, consistent with our standard retention window.
  • Billing records: 8 years, as required by Hungarian accounting law.
  • Facility data (processor role): retained as long as the Facility's subscription is active; deleted within 90 days after termination of the Service Agreement, on the Facility's instruction.
  • Server logs: up to 12 months.

8. Your rights

Under the GDPR you may request access to, correction of, deletion of, or a portable copy of your personal data; you may also object to or ask us to restrict certain processing. Contact us at info@hellodora.app — we respond within 30 days.

You also have the right to lodge a complaint with the Hungarian supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9–11., naih.hu — or with the supervisory authority of your own EU member state.

9. Security

All traffic is encrypted in transit (TLS). Data is stored in access-controlled infrastructure with row-level security that isolates each Facility's data. Passwords are stored only as cryptographic hashes.

10. Changes to this policy

We may update this policy from time to time. Material changes will be announced in the application or by email at least 15 days before they take effect.