Privacy Policy
Published: 01.03.2026
Last updated: 13.04.2026
This website follows a practical and minimalist approach to data protection. Only data necessary for communication, security, and basic analytics is processed. The aim is transparency, simplicity, and alignment with real operational needs. This document fulfills the information obligations under Article 13 of the GDPR.
1. Data Controller
The data controller is Andrzej Dudek, a natural person residing in Poland, who operates this website.
For all data protection matters, please contact: andrzej.dudek@securehavenet.ovh
2. Scope and Purpose of Data Processing
Data is processed only when necessary and for clearly defined purposes:
- Contact form: processing of email address and message content to respond to inquiries and maintain communication.
- Security and administration: processing of technical data (e.g., IP address, browser type, timestamps). IP addresses are treated as personal data and are processed only for security purposes.
- Analytics: analysis of website usage patterns to improve content and usability — only after the user gives voluntary consent.
3. Legal Basis
- Art. 6(1)(a) GDPR – voluntary consent (analytics, contact form submission).
- Art. 6(1)(f) GDPR – legitimate interest (security of the hosting cluster and communication handling).
4. Analytics (Google Analytics 4)
This website uses Google Analytics 4. This service is activated only after you give consent in the cookie banner. Data is partially anonymized (IP masking) and used to improve the website. Data may be transferred to the USA based on Standard Contractual Clauses (SCC).
5. Contact Form
The technical operation of the contact form is provided by Formspree Inc. based in the USA. Data is transmitted securely via TLS directly to my email inbox. Transfer to the USA is based on Standard Contractual Clauses (SCC).
6. Data Sharing
Data may be shared only with trusted technology partners:
- OVHcloud (OVH SAS): server infrastructure provider based in France.
- Google LLC: for analytics (only with consent).
- Formspree Inc.: for contact form message delivery.
7. Data Retention
- Server logs (OVH): Technical data (IP) is stored for 12 months (required for infrastructure diagnostics and security).
- Analytics (GA4): User-level data is automatically deleted after 2 months.
- Email contact: Formspree deletes data from its servers after 30 days. I keep the content of correspondence in my mailbox for up to 12 months after the end of contact, unless legal regulations or the nature of the inquiry require a longer period.
8. User Rights
You have the right to:
- Access, rectify, or delete your data.
- Restrict or object to processing.
- Data portability and withdrawal of consent.
- Lodge a complaint with a supervisory authority (in Poland: President of the Personal Data Protection Office - PUODO).
9. Cookies
This website uses cookies in a minimal way:
- Essential cookies: required for basic operation and security.
- Analytics cookies: used only after explicit consent (opt-in).
A simple consent mechanism (cookie banner) allows you to manage your choice. Your decision is stored locally (e.g., in localStorage). You can change it at any time by clearing your browser data or clicking the "Manage cookies" link in the footer. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. No profiling or marketing cookies are used.
10. Data Security
Technical measures such as SSL/TLS encryption, limited access, and data minimization are applied to protect your information. The contact form is protected by Google reCAPTCHA mechanism to prevent spam and automated attacks.
11. Contact & Data Protection Officer
For inquiries: andrzej.dudek@securehavenet.ovh. A Data Protection Officer has not been appointed, as it is not required under applicable law.