§1. Controller and contact
-
The controller of personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the “GDPR”) is Damian “Kuljo” Kuliś (the “Controller”), a natural person resident in Poland:
- correspondence address: ul. Jarosława Dąbrowskiego 18/6, 02-561 Warsaw, Poland
- e-mail: contact@eosinophilic-fasciitis.org
- telephone: +48 600 130 255
- data protection matters (requests under Articles 15 to 22 GDPR, breach notifications): rodo@eosinophilic-fasciitis.org
-
No Data Protection Officer. The Controller has not designated a Data Protection Officer, none of the conditions in Article 37(1) GDPR being met: the Controller is not a public authority or body, and the Controller’s activity consists neither in regular and systematic monitoring of data subjects on a large scale nor in processing of special category data on a large scale. Correspondence on data protection matters should be sent to the address given in paragraph 1.
§2. Basic principles
-
Terms used in this Policy have the meaning given to them in Article 4 GDPR.
-
Default rule: no data. The Service collects no data about a visitor unless the visitor takes an action that requires it (submitting the contact form; subscribing to the newsletter once launched). The Service uses no analytics, no tracking cookies and no advertising technology, loads no resources from third-party servers at runtime, and operates no user accounts, log-in or comment system.
-
The Controller processes personal data in accordance with the principles set out in Article 5(1) GDPR.
§3. Processing operations — overview
The table below states, for each processing surface, the data concerned, the purpose, the legal basis and the retention period. Details are set out in §§4 to 7.
| # | Surface | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|---|
| 1 | Contact form | name (optional), e-mail address, role (optional), message; any self-disclosed health data within the limits of Terms §5(2)(c) | replying to the User, including the automatic acknowledgement of receipt | Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR for health data | up to 12 months from the last correspondence |
| 2 | Cooperation on publication (Terms §6) | the scope agreed at Stage 2 of the procedure | preparing and publishing the material | Art. 6(1)(a) and (b) GDPR; Art. 9(2)(a) GDPR as regards special category data | until completion of the procedure; minimum accountability record up to 3 years |
| 3 | Newsletter (once launched) | e-mail address, role (optional) | sending the newsletter | Art. 6(1)(a) GDPR; Article 398(1) of the Act of 12 July 2024 — Electronic Communications Law (the “ECL”) | until consent is withdrawn |
| 4 | Cloudflare access logs | IP address, timestamp, request path, HTTP method, user agent, referer | security of the Service, abuse prevention, content delivery | Art. 6(1)(f) GDPR — legitimate interest (Recital 49 GDPR) | Cloudflare’s standard log retention; the Controller does not alter it |
| 5 | CF-IPCountry header | country code determined at the Cloudflare edge | routing the root address to the appropriate language version | Art. 6(1)(f) GDPR — legitimate interest | not stored; used only while the request is served |
| 6 | Contact-form rate limit | SHA-256 digest of the IP address combined with a secret salt, and the timestamps of accepted submissions | preventing abuse of the contact form | Art. 6(1)(f) GDPR — legitimate interest | 24 hours; the entry expires automatically |
| 7 | Material published on the Service with the User’s consent (Terms §6) | the content consented to at Stage 5 of the procedure | publication on the Service under CC BY-SA 4.0 | Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR as regards special category data | until consent is withdrawn; subject to §5(4) |
| 8 | sessionStorage entry disclaimer-dismissed | a boolean value, not linked to any person | remembering dismissal of the banner in the current session | not personal data; exempt under Article 399(3)(2) ECL | until the browser tab is closed |
§4. Contact form
-
The contact form serves solely to establish initial contact. The rules for using it are set out in Terms §5.
-
Data collected in the first message:
a) e-mail address (required) — in order to reply;
b) message (required, 10 to 5,000 characters);
c) role (optional: patient, physician, family, researcher, other);
d) name (optional);
e) transmission metadata: IP address (processed by Cloudflare), timestamp and the language version of the form (to determine the language of the reply).
-
Automatic acknowledgement. After the form is submitted, an automatic acknowledgement of receipt is sent to the e-mail address given, containing a reference number and a copy of the text submitted by the User. The Controller keeps no database of submissions, so this is the only copy remaining in the User’s hands. The acknowledgement is not a marketing message and involves no subscription to any mailing list.
-
Purpose. The data are processed solely to reply to the User and, where applicable, to conduct the initial correspondence preceding the cooperation procedure referred to in §5.
-
Legal basis. The User’s consent, given by ticking an express consent statement in the form before submission — jointly Article 6(1)(a) GDPR and Article 9(2)(a) GDPR as regards self-disclosed health data. Without consent the message is not accepted.
-
Data minimisation. Under Terms §5(2) the User does not submit attachments, medical records or detailed health information in the first message. Messages exceeding that scope are deleted without their full content being read, under Terms §5(4).
-
Retention. Correspondence is kept in the Controller’s mailbox for no longer than 12 months from the last message in the exchange, irrespective of whether the matter was concluded earlier. The Controller keeps no database of submissions separate from the mailbox.
-
Voluntary provision. Providing the data is voluntary but necessary in order to reply. Without an e-mail address no reply is possible.
§5. Cooperation on publication
-
Moving beyond initial contact — to the procedure for publishing a patient story or clinician contribution — follows the five-stage procedure set out in Terms §6, applied identically to both categories of material.
-
Legal basis at each stage.
Stage Action Legal basis 1 Initial contact Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR as regards self-disclosed health data (Terms §5(2)(c)) 2 Individual arrangements; explicit consent to the agreed scope Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR as regards special category data 3 Transfer of materials Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR — on the consent given at Stage 2 4 Drafting and preview Art. 6(1)(b) GDPR — necessity for performance of the agreed cooperation 5 Approval, correction or withdrawal Art. 6(1)(a) GDPR; Art. 7(3) GDPR where consent is withdrawn -
Withdrawal of consent. The User may withdraw consent at any stage, without giving reasons. The consequences are set out in Terms §6(7): permanent deletion of materials and drafts within 30 days, no publication, confidentiality of the correspondence, and retention of the minimum accountability record for no longer than 3 years (Article 5(2) GDPR). Withdrawal does not affect the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR).
-
After publication. Withdrawal of consent after publication results in removal of the content from the Service and from materials under the Controller’s control. It has no effect on copies previously distributed by third parties under the CC BY-SA 4.0 licence, which is irrevocable in that respect. The Controller informs the User of this before publication.
§6. Newsletter (planned, currently inactive)
-
As at the effective date of this Policy the newsletter is not active. This paragraph describes the rules that will apply once it is launched.
-
Data: e-mail address and, optionally, role. Purpose: sending the newsletter.
-
Legal basis: consent given through double opt-in (subscription form and confirmation via a link sent to the address given) — Article 6(1)(a) GDPR and Article 398(1) ECL.
-
Retention: until consent is withdrawn. Unsubscription is effected through the link included in every message or by notice to the Controller.
-
Subscribers’ addresses are not disclosed to third parties for any purpose other than technical delivery of the newsletter, are not combined with any other data set, and are not made available to marketing or advertising entities.
§7. Server logs and security
-
The Service is hosted on Cloudflare Pages, a service provided by Cloudflare, Inc., acting as a processor for the Controller (Article 28 GDPR).
-
Data in the logs: IP address, timestamp, request path, HTTP method, user agent, referer and standard HTTP request metadata.
-
Purpose and legal basis: ensuring the security and availability of the Service, detecting and preventing abuse, and operating the content delivery network — Article 6(1)(f) GDPR. That interest is expressly recognised in Recital 49 GDPR. Having regard to the minimal scope of the data, the absence of profiling, the absence of combination with other data sets and the short retention period, the Controller has concluded that the interests of data subjects do not override that interest.
-
Retention. Cloudflare’s standard log retention applies. The Controller configures no additional retention, exports no logs to its own storage and does not review raw logs in the ordinary operation of the Service.
-
CF-IPCountryheader. Cloudflare adds to the request a header containing a two-letter country code derived from the IP address. The Controller uses it solely to redirect a visitor from the root address to the appropriate language version (PL →/pl/, FR →/fr/, DE →/de/, IT →/it/, all others →/en/). The header is not stored, is not combined with any other data and is not made available to scripts running in the browser. -
Rate limit. The contact form accepts at most two submissions per day from one IP address. To that end the Controller stores only a SHA-256 digest of the IP address combined with a secret salt, together with the timestamps of accepted submissions. The IP address is not stored in clear form, the entry is not linked to the message or to the sender’s address, and it expires automatically after 24 hours. Use of the digest is a security measure within the meaning of Article 32(1)(a) GDPR. Legal basis: Article 6(1)(f) GDPR.
§8. Cookies and browser storage
-
The Service uses no cookies. There is no processing requiring consent under Article 399(1) ECL (the provision implementing Article 5(3) of Directive 2002/58/EC), and the Service therefore displays no consent banner.
-
sessionStorage. The Service writes a single entry under the keydisclaimer-dismissed, recording that the medical disclaimer banner was dismissed in the current browsing session. This is storage strictly necessary to perform a function requested by the User and is exempt under Article 399(3)(2) ECL. The entry contains no identifier and is removed when the browser tab is closed. -
No analytics. The Service uses no analytics tools. This is a settled decision of the Controller rather than a configuration setting: introducing any analytics would require a material amendment to this Policy, announced under §13.
-
Locally served fonts. The web fonts used by the Service (Newsreader, Geist, JetBrains Mono) are embedded at build time and served from the Service’s own domain. The User’s browser sends no requests to third-party servers and the User’s IP address is not disclosed to them.
§9. Recipients and transfers outside the EEA
-
The Controller discloses personal data to no recipients other than the processors listed in paragraph 2, except where disclosure is required by mandatory provisions of law.
-
Processors:
a) Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) — hosting of the Service (Cloudflare Pages), DNS, content delivery network, processing of access logs. Privacy policy: https://www.cloudflare.com/privacypolicy/.
b) Mailgun Technologies, Inc. (a company of the Sinch AB group) — delivery of messages submitted through the contact form to the Controller’s mailbox and of automatic acknowledgements to Users and, once the newsletter is launched, its distribution. The sending domain is configured in the European region of the service (
api.eu.mailgun.net), which means that message content is processed on infrastructure within the European Economic Area. Privacy policy: https://www.mailgun.com/legal/privacy-policy/. -
Transfers to third countries. Both entities are established in the United States and may process personal data there; the choice of the European region for the processor named in paragraph 2(b) does not exclude administrative access by the US parent company. Transfers are made on the basis of:
a) the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, forming part of the data processing agreements concluded with each of those entities;
b) Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU–US Data Privacy Framework — as regards entities certified under that framework.
The Controller provides a copy of the safeguards applied on request sent to the address given in §1(1).
-
The Controller uses no analytics providers, advertising networks, social media plug-ins or other third-party services that would result in further transfers of personal data.
§10. Retention periods
| Surface | Retention |
|---|---|
| Contact-form correspondence | up to 12 months from the last message |
| Materials received in the cooperation procedure (Terms §6) | until completion of the procedure; on withdrawal — deleted within 30 days |
| Minimum accountability record after withdrawal | up to 3 years |
| Material published with the User’s consent | until consent is withdrawn; subject to §5(4) |
| Newsletter subscription | until consent is withdrawn |
| Cloudflare access logs | Cloudflare’s standard retention |
CF-IPCountry header | not stored |
| Contact-form rate limit (IP digest and timestamps) | 24 hours; the entry expires automatically |
sessionStorage entry disclaimer-dismissed | until the browser tab is closed |
§11. Data subject rights
-
Data subjects have:
a) the right of access to their data and to the information listed in Article 15 GDPR;
b) the right to rectification of inaccurate data and completion of incomplete data (Article 16 GDPR);
c) the right to erasure in the cases set out in Article 17(1) GDPR;
d) the right to restriction of processing in the cases set out in Article 18(1) GDPR;
e) the right to data portability in the cases set out in Article 20(1) GDPR;
f) the right to object to processing based on Article 6(1)(f) GDPR, on grounds relating to their particular situation (Article 21 GDPR).
-
Withdrawal of consent. Where processing is based on consent (Article 6(1)(a) or Article 9(2)(a) GDPR), consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR).
-
Exercising rights. Requests are to be sent to rodo@eosinophilic-fasciitis.org. The Controller provides information on the action taken without undue delay and in any event within one month of receipt of the request (Article 12(3) GDPR). That period may be extended by two further months where necessary, taking into account the complexity and number of requests; the Controller informs the data subject of any such extension, and of the reasons for it, within one month of receipt of the request.
-
Complaint to a supervisory authority. Data subjects have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl.
-
Voluntary provision of data. Providing data through the contact form is voluntary. Without an e-mail address no reply can be given; withholding the remaining data does not prevent a reply.
-
No automated decision-making. The Controller takes no decisions based solely on automated processing, including profiling, within the meaning of Article 22 GDPR.
§12. Security of processing
-
The Controller applies technical and organisational measures appropriate to the risk (Article 32 GDPR), in particular:
a) the Service is served over HTTPS with TLS encryption;
b) the Service has no application-layer database; correspondence resides solely in the Controller’s mailbox once delivered;
c) the Controller’s accounts with the hosting, DNS and e-mail providers are protected by two-factor authentication;
d) a data processing agreement (Article 28 GDPR) has been concluded with each processor listed in §9(2);
e) HTTP security headers are configured (
X-Content-Type-Options: nosniff,X-Frame-Options: DENY,Referrer-Policy: strict-origin-when-cross-origin,Permissions-Policy: camera=(), microphone=(), geolocation=()). -
Personal data breaches. In the event of a personal data breach (Article 4(12) GDPR) the Controller notifies the President of the Personal Data Protection Office without undue delay and, where feasible, not later than 72 hours after becoming aware of it (Article 33(1) GDPR); communicates the breach to the data subjects affected without undue delay where it is likely to result in a high risk to their rights and freedoms (Article 34(1) GDPR); and documents the breach in accordance with Article 33(5) GDPR.
§13. Amendments to this Policy
-
The Controller may amend this Policy. Amendments are announced by updating the version number and effective date shown at the head of the document and by maintaining a change history in the publicly available source-code repository of the Service.
-
Material amendments — extending or otherwise materially changing the scope of processing, the categories of recipients, the retention periods or the manner in which data subject rights are exercised — are additionally announced visibly on the Service for 14 days before they take effect and, once the newsletter is active, by e-mail to subscribers.
-
The binding version is the Polish version (
/pl/privacy).