§1. Controller and contact
-
The controller of personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR” or “RODO”) is Damian “Kuljo” Kuliś (the “Controller” or the “Operator”), a natural person resident in Poland, with the following contact details:
- postal address: ul. Jarosława Dąbrowskiego 18/6, 02-561 Warszawa, Poland
- email: contact@eosinophilic-fasciitis.org
- telephone: +48 600 130 255
- email for data-protection matters (requests under Articles 15–22 GDPR, breach reports, related queries): rodo@eosinophilic-fasciitis.org
-
No Data Protection Officer. The Controller has not designated a Data Protection Officer pursuant to Article 37 GDPR. The Controller has assessed and determined that none of the conditions for the mandatory designation set out in Article 37(1) GDPR applies to its activity: the Controller is not a public authority or body; the Controller’s core activities do not consist of processing operations which require regular and systematic monitoring of data subjects on a large scale; and the Controller’s core activities do not consist of processing on a large scale of special categories of data. Communications regarding data protection should be directed to the address indicated in paragraph 1.
§2. Definitions and fundamental principles
-
Terms used in this Privacy Policy have the meanings ascribed to them in Article 4 GDPR. In particular:
- personal data — any information relating to an identified or identifiable natural person;
- processing — any operation performed on personal data;
- data subject — the natural person whose data are processed;
- processor — an external entity processing data on behalf of the Controller;
- special-category data — the categories listed in Article 9(1) GDPR, including data concerning health;
- consent — a freely given, specific, informed, and unambiguous indication of the data subject’s wishes, by way of a statement or clear affirmative action.
-
Default principle: zero data. The Site is designed in such a way that no visitor data are collected unless the visitor takes an affirmative action requiring such collection (sending the contact form, subscribing to the newsletter when active). The Site uses no analytics, no tracking cookies, no advertising technology, no third-party embeds at runtime, no third-party fonts at runtime, no user accounts, no logins, and no comment systems.
-
Principles of processing. The Controller processes personal data in accordance with the principles set out in Article 5(1) GDPR: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.
§3. Data we process — overview
For each surface on which the Controller processes personal data, the table below indicates: the data processed, the purpose, the legal basis under GDPR Article 6 (and Article 9 where applicable), and the retention period. Detailed descriptions follow in §§4–7.
| # | Surface | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|---|
| 1 | Contact form | name (optional), email address, role, message text; possibly minimal self-disclosed health data within the limits of Terms §5(2)(c) | reply to the User, including the automatic acknowledgement (§4(3)) | Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR for health data | up to 12 months from last correspondence |
| 2 | Staged cooperation regarding patient stories or clinician contributions | as specifically agreed in Stage 2 of the cooperation procedure | preparation and publication of cooperation outputs | Art. 6(1)(a), Art. 6(1)(b) GDPR; Art. 9(2)(a) GDPR to the extent the materials include special-category data | per Terms §6; minimal accountability record up to 3 years after termination |
| 3 | Newsletter (when active) | email address, role | dispatch of the newsletter | Art. 6(1)(a) GDPR + Art. 10 UŚUDE + Art. 172 Prawo telekomunikacyjne | until unsubscribe |
| 4 | Cloudflare access logs | IP address, timestamp, request path, user-agent, referrer (processed by Cloudflare on the Controller’s behalf) | security, abuse prevention, operation of CDN | Art. 6(1)(f) GDPR — legitimate interest | per Cloudflare’s standard log retention (days to weeks); the Controller does not configure additional retention |
| 5 | CF-IPCountry header for geo-IP root redirect | country code derived at the Cloudflare edge | routing of the root URL to the appropriate locale subpage | Art. 6(1)(f) GDPR — legitimate interest (user-experience routing) | not retained; per-request only |
| 6 | sessionStorage key disclaimer-dismissed | boolean state | retention of the User’s dismissal of the medical-disclaimer banner within the current session | not personal data; functional storage exempt under ePrivacy Directive Art. 5(3) sentence two | until tab close or until visit to a medical-content page |
| 7 | hCaptcha (planned) | data processed by hCaptcha per its own privacy policy, including IP address and certain device/browser signals | anti-spam protection of the contact form | Art. 6(1)(f) GDPR — legitimate interest | per hCaptcha’s retention policy |
| 8 | Publication of a patient story or clinician contribution on the Site | content explicitly consented to in Stage 5 of the cooperation procedure | publication on the Site under CC BY-SA 4.0 | Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR to the extent the content includes special-category data; Art. 6(1)(e) GDPR (Recital 50 — further processing for archival/scientific purposes) | indefinitely (CC BY-SA license is irrevocable in respect of distributed copies) |
| 9 | Contact-form submission limit | SHA-256 digest of the IP address combined with a secret salt, plus timestamps of accepted submissions | prevention of abuse of the contact form | Art. 6(1)(f) GDPR — legitimate interest | 24 hours; the entry expires automatically |
§4. Contact form
-
The contact form is intended exclusively to enable an initial contact between the User and the Controller. The data processing rules for the contact form are set out in detail in the Terms of Service §5 and are summarized below for the data subject’s information.
-
Data collected in the first message:
a) email address (required) — for the purpose of sending a reply;
b) message text (required, 10–5000 characters);
c) role indication (optional — patient, physician, family member, researcher, other);
d) name (optional);
e) implicit metadata processed during transmission: IP address (in the request envelope, processed by Cloudflare for security and seen by the planned anti-spam provider for the same purpose), timestamp, locale of the sending page (for reply locale).
-
Automatic acknowledgement. Immediately after the form is submitted, an automatic acknowledgement is sent to the email address provided. It carries the reference number of the submission and a copy of the text the User sent — the Controller keeps no database of submissions, so this is the only copy remaining in the User’s hands. The acknowledgement is sent in the language in which the form was completed, through the same processor and in the same region as the message addressed to the Controller (§9(2)(b)). The acknowledgement is not a marketing message and does not enrol the User on any mailing list.
-
Purpose. The data are processed exclusively for the purpose of replying to the User — including sending the automatic acknowledgement referred to in paragraph 3 — and, where applicable, of conducting initial correspondence leading to the cooperation procedure described in §5.
-
Legal basis. The express consent of the data subject, given through an explicit consent checkbox in the contact form before submission, jointly under Article 6(1)(a) GDPR (personal data in general) and Article 9(2)(a) GDPR (health data, in the minimal scope of self-disclosure permitted by Terms §5(2)(c)).
-
Data minimization rule. In accordance with Terms §5(2), the User is required not to transmit attachments, medical documentation, or detailed health information in the first message. The procedure for messages exceeding that scope is set out in Terms §5(4): such messages are deleted without being read in full and without further processing, in accordance with the principle of data minimization (Article 5(1)(c) GDPR) and the obligation to erase data processed without a valid legal basis (Article 17(1)(d) GDPR).
-
Retention. Correspondence is retained in the Controller’s mailbox for a maximum of 12 months from the date of the last message in the exchange. After expiry of that period, the correspondence is deleted, regardless of whether the matter has been formally concluded. The Controller does not maintain any database of contact-form submissions separate from the mailbox.
-
Provision of data is voluntary but is necessary for the Controller to send a reply. Without an email address the Controller has no means of replying.
§5. Staged cooperation regarding publication of patient stories or clinician contributions
-
Where the User and the Controller proceed beyond initial contact to a cooperation procedure for the purpose of publishing a patient story, a clinician contribution, or related material, the data processing follows the five-stage protocol set out in Terms §6. The procedure applies regardless of whether the User acts in the capacity of a person sharing their own patient experience or in the capacity of a physician, other healthcare professional, or researcher sharing professional knowledge and experience; the differences at the level of the legal basis of processing are set out in paragraph 2.
-
Legal basis per stage.
Stage Action Legal basis 1 Initial contact Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR in the minimal scope of self-disclosed health data (Terms §5(2)(c)) 2 Individual arrangements; obtaining express consent for the agreed scope of materials Art. 6(1)(a) GDPR (for the specifically agreed scope); Art. 9(2)(a) GDPR to the extent the materials include data concerning the User’s health or special-category data concerning third parties 3 Transmission of materials Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR to the extent it concerns special-category data — consent obtained at Stage 2 4 Preparation and preview Art. 6(1)(b) GDPR — necessity for performance of the cooperation arrangement established at Stage 2 5 Acceptance, revision, or withdrawal Art. 7(3) GDPR — right to withdraw consent -
Right of withdrawal. The User may withdraw consent at any stage without giving reasons. Upon withdrawal:
a) all materials received from the User and all draft versions of content prepared on their basis are permanently deleted within 30 days of receipt of the notice of withdrawal;
b) no content referring to the User is published;
c) the Controller maintains confidentiality with regard to the fact of the discussions and the content of the correspondence;
d) a minimal record may be retained by the Controller for up to 3 years for the purpose of demonstrating compliance with GDPR (Article 5(2) GDPR — accountability);
e) withdrawal does not affect the lawfulness of processing performed prior to withdrawal (Article 7(3) GDPR).
-
Post-publication. Content published on the Site with the User’s consent at Stage 5 of the cooperation procedure remains available under the CC BY-SA 4.0 license, which is irrevocable in respect of distributed copies. Withdrawal of consent after publication results in removal of the content from the Site and from materials under the Controller’s control but does not retroactively withdraw the license in respect of copies already distributed by third parties under CC BY-SA 4.0.
§6. Newsletter (planned, currently inactive)
-
The newsletter is a planned service of periodic information dispatch regarding developments in the field of M35.4. As of the effective date of this Privacy Policy, the newsletter is not operational. This section describes the rules that will apply upon activation.
-
Data collected: email address and (optional) role indication.
-
Purpose: dispatch of the periodic newsletter to the subscriber’s address.
-
Legal basis: the data subject’s consent, given through a double opt-in mechanism (signup form + confirmation of subscription by clicking a link sent to the indicated email address), jointly under:
a) Article 6(1)(a) GDPR;
b) Article 10 UŚUDE — express consent for the receipt of commercial information by electronic means;
c) Article 172 of the Polish Act of 16 July 2004 — Telecommunications Law — express consent for direct marketing using electronic means of communication.
-
Retention: until withdrawal of consent (unsubscribe).
-
Right of withdrawal: the subscriber may withdraw consent at any time without giving reasons, by clicking the unsubscribe link present in every newsletter message or by sending notice to the Controller at the address indicated in §1(1). The unsubscribe procedure requires a single click.
-
No commercial use of the subscriber list. The email addresses of subscribers shall not be transferred to third parties for any purpose other than technical dispatch of the newsletter through the mail provider, shall not be combined with any other data set, shall not be used for any purpose other than the newsletter, and shall not be sold or shared with marketing or advertising partners.
§7. Server logs and security
-
The Site is hosted on Cloudflare Pages, a service provided by Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA), acting as a processor on the Controller’s behalf within the meaning of Article 28 GDPR.
-
Data processed in server logs: IP address, timestamp, request path, HTTP method, user-agent, referrer, and standard HTTP request metadata.
-
Purpose: security of the Site, prevention and detection of abuse (denial-of-service attacks, exploit attempts, content scraping for malicious purposes), and operation of the content-delivery network.
-
Legal basis: Article 6(1)(f) GDPR — legitimate interest of the Controller (and of Cloudflare as processor) in ensuring the integrity and availability of the Site. The Controller has assessed that the data subject’s interests do not override this legitimate interest, taking into account: the minimal nature of the data processed, the absence of any combination with other data sets on the Controller’s side, the absence of any profiling, the short retention period applied by Cloudflare, and the security purpose served.
-
Retention: Cloudflare’s standard log retention applies. The Controller does not configure additional log retention, does not enable Cloudflare Log Push to its own storage, and does not consult raw logs in the ordinary course of operation of the Site. The Controller may consult summary panels provided by Cloudflare for the purposes set out in paragraph 3.
-
CF-IPCountry header. Cloudflare injects into incoming requests a
CF-IPCountryheader containing the two-letter country code corresponding to the IP geolocation as resolved by Cloudflare. The Controller uses this header in a Cloudflare Pages Function deployed at the bare/URL to redirect visitors to the locale-appropriate subpage (PL → /pl/, FR → /fr/, DE → /de/, IT → /it/, all others → /en/). The header is consumed per request at the edge; it is not stored, not combined with any other data, not visible to the Site’s client-side JavaScript, and not used for any purpose other than the routing described. -
Contact-form submission limit. To prevent abuse, the contact form accepts at most two submissions per day from a single IP address. To enforce this, the Controller stores in Cloudflare Workers KV only a cryptographic digest (SHA-256) of the IP address combined with a secret salt, together with the timestamps of accepted submissions. The IP address is not stored in clear form, the entry is not combined with the message content or the sender’s email address, and it expires automatically after 24 hours. Legal basis: Article 6(1)(f) GDPR — legitimate interest in protecting the form against abuse. Use of the digest constitutes pseudonymisation within the meaning of Article 4(5) GDPR, implemented as a safeguard under Article 32(1)(a) GDPR. Once the limit is reached the User is shown a message stating that the daily limit has been reached; the Site does not disclose the number of remaining submissions beforehand.
§8. Cookies and similar technologies
-
The Site does not use cookies requiring consent under Article 5(3) of Directive 2002/58/EC (ePrivacy Directive) or Article 173 of the Polish Telecommunications Law. There is no cookie consent banner because there is nothing for which consent is required.
-
sessionStorage. The Site uses a single
sessionStorageentry under the keydisclaimer-dismissedto remember whether the User has dismissed the medical-disclaimer banner within the current browsing session. This is strictly necessary functional storage for a User-requested feature (dismissal of the banner) and is exempt from the consent requirement under Article 5(3) sentence two of the ePrivacy Directive. The entry is cleared when the browser tab is closed or when the User navigates to a medical-content page (per the banner re-pop policy). -
No analytics technologies, ever. The Site does not employ any analytics tools — neither now nor in the future as currently designed. This is a settled decision of the Controller, not a default configuration that may be changed by reconfiguration alone: activation of any analytics in the future shall require a substantive amendment of this Privacy Policy and shall be communicated to data subjects in accordance with §13.
-
Self-hosted fonts. Web fonts used on the Site (Newsreader, Geist, JetBrains Mono) are downloaded from Google Fonts at the Controller’s build time and served from the Site’s own domain at runtime. No request is made to Google Fonts servers when a User loads the Site. This avoids the unlawful transmission of IP addresses to Google identified in German case law (LG München, 20.01.2022, ref. 3 O 17493/20).
-
hCaptcha (planned). When the contact-form backend and its anti-spam protection are activated, the hCaptcha widget provided by Intuition Machines, Inc. may set cookies or use other client-side storage strictly necessary for its operation as part of the contact-form submission flow. The Controller intends to implement the widget in a lazy-load manner — the widget shall load only at the moment the User initiates submission of the form — and shall surface a brief notice about hCaptcha activation. Activation of hCaptcha shall require updating of this Privacy Policy with details of the processing performed by Intuition Machines, Inc.
§9. Recipients of data and transfers to third countries
-
The Controller does not share personal data with third parties other than the processors expressly indicated below, except where required to do so by mandatory provisions of applicable law (in particular: requests from public authorities competent under Polish law).
-
Processors engaged by the Controller:
a) Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) — hosting of the Site (Cloudflare Pages), DNS resolution, content-delivery network, processing of access logs. Cloudflare’s privacy policy: https://www.cloudflare.com/privacypolicy/.
b) Mailgun Technologies, Inc. — a company within the Sinch AB (publ) group — for transmission of messages submitted through the contact form to the Operator’s mailbox, and in future for dispatch of the newsletter upon its activation. The Site’s sending domain is configured in the service’s European region (
api.eu.mailgun.net), meaning that message content is processed on infrastructure located within the European Economic Area. Privacy policy: https://www.mailgun.com/legal/privacy-policy/; the Sinch group’s data protection officer: dpo@sinch.com.c) Intuition Machines, Inc. (operator of hCaptcha; address per https://www.hcaptcha.com/) — anti-spam protection of the contact form upon its activation.
-
Transfers to third countries. The processors named in paragraph 2 are established in the United States and may process personal data in the United States. In respect of the processor named in paragraph 2(b), the Operator has selected the European service region, so the content of messages submitted through the contact form is stored and processed on infrastructure within the European Economic Area; this does not, however, exclude the possibility of administrative access by the US-established parent company, and the safeguards described below therefore apply to that processor as well. The transfers to the United States are based on:
a) Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU-US Data Privacy Framework, for processors certified under the Framework;
b) Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, included in the data processing agreements with each processor as a complementary safeguard.
The data subject may request a copy of the safeguards applied by sending a request to the address indicated in §1(1).
-
No use of services outside the EU/EEA for additional purposes. The Controller does not engage analytics providers, advertising networks, social-media plugins, content-delivery networks for embedded content, or any other third-party service that would result in additional transfers of personal data to third countries.
§10. Retention periods
The retention periods applied by the Controller are summarized below.
| Surface | Retention period |
|---|---|
| Contact-form correspondence | up to 12 months from last message |
| Materials received in the cooperation procedure (Terms §6 Stage 3) | through completion of Stage 5; upon withdrawal — deleted within 30 days |
| Minimal accountability record after withdrawal from cooperation | up to 3 years |
| Published patient-story or clinician-contribution content (with consent at Stage 5) | indefinitely; subject to removal upon withdrawal and to the irrevocability of CC BY-SA 4.0 in respect of distributed copies |
| Newsletter subscription | until withdrawal of consent |
| Cloudflare access logs | per Cloudflare’s standard retention (operator does not configure) |
| CF-IPCountry header | per request only, not retained |
sessionStorage disclaimer-dismissed | until tab close or visit to medical-content page |
| hCaptcha data | per Intuition Machines, Inc. retention policy |
| Contact-form rate-limit bucket (IP digest + timestamps) | 24 hours; the entry expires automatically |
§11. Rights of the data subject
-
The data subject has the following rights under Articles 15–22 GDPR:
a) right of access — to obtain confirmation of whether personal data are being processed and, if so, access to those data and to the information set out in Article 15(1) GDPR;
b) right to rectification — to obtain rectification of inaccurate personal data and completion of incomplete personal data;
c) right to erasure (“right to be forgotten”) — to obtain erasure of personal data without undue delay where one of the conditions in Article 17(1) GDPR is met;
d) right to restriction of processing — to obtain restriction of processing where one of the conditions in Article 18(1) GDPR is met;
e) right to data portability — to receive personal data concerning the data subject in a structured, commonly used, and machine-readable format, and to transmit those data to another controller, where the conditions in Article 20(1) GDPR are met;
f) right to object — to object, on grounds relating to the data subject’s particular situation, to processing based on Article 6(1)(e) or (f) GDPR;
g) rights related to automated decision-making — including the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject (Article 22 GDPR); the Controller does not perform such automated decision-making.
-
Right to withdraw consent. Where processing is based on the data subject’s consent (Article 6(1)(a) and Article 9(2)(a) GDPR), the data subject has the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing performed prior to withdrawal (Article 7(3) GDPR).
-
Exercise of rights. The data subject may exercise the rights referred to in paragraphs 1 and 2 by sending a request to rodo@eosinophilic-fasciitis.org. The Controller shall provide information on action taken on a request without undue delay and in any event within one month of receipt of the request, in accordance with Article 12(3) GDPR. That period may be extended by two further months where necessary, taking into account the complexity and number of requests; the Controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay.
-
Right to lodge a complaint. The data subject has the right to lodge a complaint with the supervisory authority. The competent authority in Poland is:
Prezes Urzędu Ochrony Danych Osobowych ul. Stawki 2 00-193 Warszawa, Poland https://uodo.gov.pl
-
Voluntary provision of data. Provision of personal data through the contact form is voluntary. Failure to provide an email address makes it impossible for the Controller to reply; failure to provide other data does not preclude reply but may reduce the Operator’s ability to address the User’s matter substantively.
-
No automated decision-making or profiling. The Controller does not engage in automated individual decision-making, including profiling, within the meaning of Article 22 GDPR.
§12. Security of processing
-
The Controller applies appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. In particular:
a) the Site is served over HTTPS with TLS encryption provided by Cloudflare;
b) the Site has no application-layer database and stores no personal data in any application-layer data store; correspondence resides only in the Controller’s mailbox after delivery by the mail provider;
c) the Controller’s accounts with hosting, DNS, and mail-provider services are protected by two-factor authentication;
d) data processing agreements (DPAs) under Article 28 GDPR are in place with each processor named in §9(2);
e) HTTP security headers are configured to mitigate common web-application attack vectors (
X-Content-Type-Options: nosniff,X-Frame-Options: DENY,Referrer-Policy: strict-origin-when-cross-origin,Permissions-Policy: camera=(), microphone=(), geolocation=()). -
Personal data breaches. In the event of a personal data breach within the meaning of Article 4(12) GDPR, the Controller shall:
a) notify the supervisory authority (President of the Personal Data Protection Office, “UODO”) of the breach without undue delay and, where feasible, not later than 72 hours after having become aware of it, in accordance with Article 33(1) GDPR;
b) where the breach is likely to result in a high risk to the rights and freedoms of natural persons, communicate the breach to the affected data subjects without undue delay, in accordance with Article 34(1) GDPR;
c) document the breach in accordance with Article 33(5) GDPR.
The internal procedure for handling personal data breaches is documented in the Controller’s internal records and is not published on the Site.
§13. Changes to this Privacy Policy and effective date
-
Amendments. The Controller may amend this Privacy Policy. Amendments shall be announced through:
a) update of the effective date and version number visible at the top of this document;
b) maintenance of the history of changes in the publicly accessible source-code repository of the Site;
c) in the case of substantive amendments — extending, restricting, or otherwise materially altering the scope of processing, the categories of recipients, the retention periods, or the means of exercising data-subject rights — a site-wide notice published on the Site for a period of 14 days before the amendments enter into force;
d) when the newsletter is active — notification of subscribers to the newsletter of substantive amendments by email.
-
Authoritative version. The Polish version of this Privacy Policy (
/pl/privacy) is the authoritative version for purposes of binding interpretation. In case of discrepancy between language versions, the Polish version prevails. -
Effective date. This Privacy Policy enters into force on 22 May 2026.