Privacy policy
This is an early-stage site. The product is not on sale yet and no payments are taken — the only thing you can do here is reserve a place or join the waitlist with your e-mail. This policy describes honestly everything the site does with data, including how we measure visits and reservations.
1. Who we are
This website (circadiam.shop) is operated by SIA „Psihologs Tavā kabatā”, reg. no. 40103550818, registered address Georga Apiņa iela 12, Valmiera, Valmieras nov., LV-4201, Latvija (“we”, “us”). We are the controller of the personal data described here. Contact for anything data-related: gunita@gudone.lv.
2. What data we collect
2.1. Data you give us
When you reserve a place or join the waitlist, we store:
- your e-mail address (required — the form has no other field);
- the kit you chose and its planned price, if you reserve a place (“Starter kit” — €75, or “3-month plan” — €185);
- the type of sign-up — reservation or waitlist — and the language the page was read in (LV, RU or EN);
- the fact of your consent and its time.
2.2. Data about how the site was used
We measure how many people reach the pricing block and how many of them reserve a place — to understand whether the offer is wanted at all, before the product is manufactured. The price is the same for every visitor; nothing is shown differently to different people. To measure it, we collect:
- a session identifier — a randomly generated UUID created in your browser each time the page loads, held only in the memory of the open page. It is not stored on your device (see section 4), and reloading creates a new one. On our side we keep it only on event records; it is not attached to the sign-up itself, so it is not linked to your e-mail address;
- the page language (LV, RU or EN);
- whether you pressed a reserve button and which one, together with the kit and price it carried;
- how far you scrolled (0/25/50/75/100 %) and how long you stayed;
- UTM parameters (utm_source, utm_medium, utm_campaign) and the referrer, if the link you arrived by carried them;
- the type and time of each event: page opened, pricing block viewed, reserve button pressed, form filling started, and a sign-up successfully sent.
These events are sent to our own server (not to any advertising network) and stored in our own database. If you send a sign-up, we store alongside it the chosen kit and its price, the sign-up type, the language, the scroll depth, the time on page and the campaign parameters — but not the session identifier.
2.3. IP address
We do not store raw IP addresses. When a sign-up is saved, an irreversible hash (SHA-256) is created from your IP address and a secret salt, and only that hash is stored. We use it solely to limit spam and automated repeat sign-ups. The IP address cannot be recovered from the hash.
2.4. Correspondence
If you e-mail us, we keep the correspondence and the information it contains.
2.5. What we do not collect
- No Meta (Facebook) pixel or other advertising trackers, and we build no advertising audiences.
- No payment data — nothing is bought on this site, so we never see or store card details.
- No special-category (health) data — we do not ask for any.
- No automated decision-making with legal effects.
- We do not sell personal data.
3. Why we use the data, and our legal bases
- Reservations, the waitlist and messages about availability — your consent (GDPR art. 6(1)(a)). We only write about the product's availability and launch. You can withdraw consent at any time — every e-mail we send carries an unsubscribe link, or write to gunita@gudone.lv — and that does not affect processing carried out before the withdrawal.
- Measuring site usage and reservations — our legitimate interests (art. 6(1)(f)) in understanding whether people want this offer before investing in production. The measurement uses neither cookies nor any other information stored on your device (see section 4), so it needs no separate consent. We do not use this data to build advertising audiences and do not pass it to advertising networks.
- Site security and spam prevention (the IP hash, the hidden honeypot field) — legitimate interests (art. 6(1)(f)).
- Meeting legal obligations, should any arise — legal obligation (art. 6(1)(c)).
4. Cookies and browser storage
This site uses no cookies at all — not for marketing, not for analytics, none. It also stores nothing on your device: no local storage (localStorage), no session storage (sessionStorage), and no other technology that would leave data in your browser. That is exactly why there is no cookie consent banner — there is nothing for it to be about.
The session identifier we use to count the events of a single visit exists only in the memory of the open page and disappears as soon as you close or reload it. The consequence deserves to be said plainly: we count visits, not people — if you come back, we have nothing by which to recognise you. We accept that deliberately: measuring visits is not a good enough reason to leave anything on your device.
The only external tool that may be switched on is Cloudflare Web Analytics: it measures traffic without cookies, uses no browser storage and does no cross-site tracking; Cloudflare does not use this data for advertising.
5. Who we share data with
We share data only with service providers acting on our behalf as processors:
- Cloudflare, Inc. — site hosting and sign-up storage;
- Google Ireland Ltd. — e-mail delivery;
- Cloudflare, Inc. — content delivery, if the site is served by the Cloudflare network, and, when enabled, cookieless traffic measurement.
We do not sell personal data and do not pass it to advertising networks. We may disclose data where the law or a competent authority requires it.
6. Transfers outside the EU/EEA
If any provider processes data outside the EU/EEA, the transfer is protected by appropriate safeguards — the EU Standard Contractual Clauses or a European Commission adequacy decision.
7. How long we keep it
- Reservation and waitlist data (e-mail, the chosen kit and price, the sign-up type, the language and the technical fields attached to the sign-up) — until you withdraw consent, or no longer than 24 months after our last contact with you, whichever comes first.
- Event data (page opened, pricing block viewed, reserve button pressed, form started and sent) — up to 12 months; after that we delete it or keep it only in aggregated, non-identifying form.
- The IP hash — together with its sign-up; it is not reversible.
- E-mail correspondence — up to 24 months.
8. Your rights
Under the GDPR you have the right to:
- access your data and receive a copy of it;
- correct inaccurate data;
- have data erased (“the right to be forgotten”);
- restrict processing or object to it, including processing based on legitimate interests;
- receive your data in a structured, machine-readable format (portability);
- withdraw consent at any time — this does not affect processing carried out before the withdrawal.
To exercise these, write to gunita@gudone.lv. We answer within one month. If you believe your rights have been breached, you have the right to lodge a complaint with the Latvian supervisory authority — Datu valsts inspekcija (www.dvi.gov.lv).
9. Security
We use appropriate technical and organisational measures: an encrypted connection (HTTPS), restricted database access, a password-protected admin view, and replacing the IP address with an irreversible hash. No method of transmission is completely secure, but we work to protect your information and will report data breaches where the law requires it.
10. Children
The product and the site are intended for adults (18+). We do not knowingly collect data from anyone under 18. If we learn that we have, we delete it.
11. Changes
We may update this policy. The date above shows the latest version; we will inform you by e-mail about material changes if you are on the list.
12. Contact
Questions or requests: gunita@gudone.lv, SIA „Psihologs Tavā kabatā”, Georga Apiņa iela 12, Valmiera, Valmieras nov., LV-4201, Latvija.