- Author: Jonasz Maczyński
- Server: Ubuntu VPS
- Stack: LEMP
1. General information
This policy applies to the website operating at the url address sculptor.dev. The website operator and personal data administrator is Jonasz Maczyński. Operator's e-mail contact address is firstname.lastname@example.org. The operator is the administrator of your personal data in relation to the data provided voluntarily on the website. The website uses personal data for the following purposes:
- - running a newsletter,
- - supporting inquiries via the form,
- -implementing ordered services,
- - presenting offers or information.
The website collects information about users and their behavior in the following ways:
- - data entered voluntarily in the forms, which are stored in the operator's systems,
- - saving cookie files in end devices (also known as "cookies").
2. Selected data protection methods used by the operator
The areas where personal data is logged in and entered are protected in the transmission layer with an SSL certificate. This ensures that personal data and login details entered on the website are encrypted on the user's computer and can only be read on the target server. Personal data stored in the database are encrypted in a way that only the operator, holding the key, can access them. This ensures data protection even in the event of a database being stolen from the server. User passwords are stored in a hashed format, which means they cannot be reversed. This method is considered the modern standard for storing user passwords. The website also employs two-factor authentication as an additional layer of protection for logging into the website. The operator regularly changes its administrative passwords to enhance security. Additionally, the operator performs regular backups to protect data. Keeping all software used by the operator to process personal data updated is an essential aspect of data protection, which includes regular updates of programming components.
The website is hosted (technically maintained) on the servers of the operator: OVH, Germany
4. Personal data
In certain situations, the administrator has the right to transfer your personal data to other recipients if it is necessary to perform the contract concluded with you or to fulfill obligations incumbent on the administrator. The following groups of recipients may receive your personal data:
- - hosting company based on an entrustment agreement,
- - authorized employees and associates who use the data to achieve the purpose of the website,
- - companies providing marketing services to the administrator.
The administrator processes your personal data for no longer than necessary to perform the related activities specified in separate regulations (e.g., for accounting purposes). Marketing data will not be processed for more than 3 years. You have the right to request the following from the administrator:
- - access to personal data concerning you,
- - rectification of personal data,
- - deletion of personal data,
- - restriction of data processing,
- - data portability.
You also have the right to object to the processing of personal data for legitimate interests pursued by the administrator, including profiling. However, the right to object will not be exercised if there are valid legitimate grounds for processing, overriding interests, rights, and freedoms, especially in cases involving the determination, investigation, or defense of claims. If you believe that the administrator has violated your rights, you can file a complaint with the President of the Personal Data Protection Office at ul. Stawki 2, 00-193 Warsaw. Providing personal data is voluntary but necessary to operate the website. Automated decision-making, including profiling, may be used for providing services under a concluded contract and for direct marketing purposes. Personal data may be transferred to third countries outside the European Union as defined in the provisions on the protection of personal data.
5. Information in forms
The website collects information provided voluntarily by the user, including personal data, if provided. The website may also store information about connection parameters (time stamp, IP address). In some cases, the website may save information that facilitates linking the data in the form with the user's email address. In such cases, the user's email address is included in the URL of the page containing the form. The data provided in the form is processed for the specific purpose stated in the context and description of the form, such as processing service requests, commercial contacts, or service registration.
6. Administrator logs
Information about user behavior on the website may be logged for administrative purposes.
7. Essential marketing techniques
8. Information about cookie files
- - maintaining the user's session on the website (after logging in), eliminating the need to re-enter login and password on each subpage,
- - achieving the goals outlined in the "Essential Marketing Techniques" section.