Privacy policy
Last updated: 26 April 2026
1. Data controller
The controller of personal data processed in connection with the use of the drmajewska.pl website is dr Patrycja Majewska.
For matters related to the processing of personal data: [email protected]
2. What data we process
We only process data voluntarily provided by the User in the contact form on the website:
- full name
- email address
- message content (and optionally a subject)
Additionally, for security and traffic analysis, we process anonymous technical data (browser type, operating system, country) via Cloudflare Web Analytics, which operates without cookies and does not identify individual Users.
3. Purposes of processing
- Responding to inquiries sent via the contact form (e.g. consultation questions, general information).
- Statistical traffic analysis on the website (anonymous, without identifying Users).
- Security and protection against abuse (e.g. spam, automated attacks).
4. Legal basis
- Article 6(1)(a) GDPR — User consent (contact form: checking the consent checkbox).
- Article 6(1)(f) GDPR — legitimate interest of the controller (anonymous analytics, website security).
5. Data recipients
Data may be transferred to the following processors operating under data processing agreements:
- Web3Forms (USA) — receiving and forwarding messages from the contact form to the Controller's email address.
- Cloudflare, Inc. (USA) — website hosting, content delivery (CDN), anonymous analytics, attack protection.
Data may be transferred to third countries (USA). These entities apply the EU Standard Contractual Clauses and other mechanisms compliant with Article 46 GDPR, ensuring an adequate level of data protection.
6. Retention period
- Contact form data: 2 years from the date of last correspondence or until consent is withdrawn (whichever comes first).
- Server logs: a maximum of 90 days.
- Analytics data: anonymous — Cloudflare stores aggregated statistics that cannot be used to identify Users.
7. Your rights
Under GDPR, you have the right to:
- Access your data (Article 15 GDPR)
- Rectification of inaccurate data (Article 16 GDPR)
- Erasure of data ("right to be forgotten", Article 17 GDPR)
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Object to processing (Article 21 GDPR)
- Withdraw consent at any time — without affecting the lawfulness of processing carried out before withdrawal
To exercise these rights, write to: [email protected] You will receive a response within 30 days.
8. Complaint to the supervisory authority
You have the right to lodge a complaint with the President of the Personal Data Protection Office if you believe the processing of your data violates GDPR.
Address:
Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland.
uodo.gov.pl ↗
9. Voluntariness of providing data
Providing personal data in the contact form is voluntary, but necessary to respond to your inquiry. Without your name and email address, we will not be able to reply.
10. Profiling and automated decisions
Your data is not subject to profiling or automated decisions affecting your rights or freedoms.
11. Cookies
The drmajewska.pl website does not use cookies for analytics or marketing purposes. For details, see the cookie policy.
12. Policy changes
This privacy policy may be updated. Each update will be published on this page with a new date. We encourage you to review it periodically.