Privacy notice
Last updated
Who is responsible
The controller of the personal data described here is Maciej Jasiewicz, Gliwice, Poland. For anything to do with your data, write to maciej@jasiewicz.pro.
This is a personal, professional site: static pages about my work. It has no accounts, forms, comments or newsletter. The only personal data it involves is what every web request carries and whatever you choose to send me by email.
Visiting the site
The site is served through Cloudflare (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA), which hosts the static files and sits between your browser and them. Every request passes through Cloudflare’s network, which processes the data needed to deliver a page and to keep the site up: your IP address, the address of the page you requested, the time of the request, the page that referred you and technical details your browser sends, such as its user-agent string.
Cloudflare uses this data to serve and cache the pages, to detect and block abusive traffic, and to show me aggregated statistics: requests, bandwidth, countries and blocked threats. I do not run a server of my own and keep none of this data anywhere else.
Legal basis: my legitimate interest in running a working, secure website (art. 6(1)(f) GDPR). Cloudflare processes the data on my behalf under its Data Processing Addendum and retains it for the limited period described in its Privacy Policy.
Performance measurement
Cloudflare Web Analytics is enabled for this site. As a page passes through Cloudflare’s network, Cloudflare inserts a small script into it (beacon.min.js from static.cloudflareinsights.com). Cloudflare can skip this for visitors who connect through its data centres in the EU and EEA; whether it does so here depends on the setting in my Cloudflare account.
The script measures how the page loaded in your browser: timings from the browser’s performance APIs, Core Web Vitals such as LCP, CLS and INP, the page address without its query string, the referring page, the type of navigation, and your browser’s engine and version. It sends these to /cdn-cgi/rum on this domain, which Cloudflare handles, together with a random identifier for that single page load. Cloudflare states that the script sets no cookies, uses no local storage and does not fingerprint visitors, and that the IP address arriving with the report is discarded at the receiving data centre rather than stored. Details: Cloudflare’s description of the RUM beacon.
I see the results only as aggregate statistics: page views, visits counted from the referring site, load times and Web Vitals broken down by page, country, browser, operating system and device type. Cloudflare keeps the unsampled data for seven days and aggregated data for six months. Legal basis: my legitimate interest in knowing whether the site loads quickly for the people who visit it (art. 6(1)(f) GDPR).
You can stop the script by blocking static.cloudflareinsights.com with a content blocker or by disabling JavaScript. The site is fully readable without it.
Writing to me
If you email me, I process your email address, your name if you give it, and the content of your message in order to reply and to deal with what you wrote about. Legal basis: my legitimate interest in handling correspondence (art. 6(1)(f) GDPR) or, when the correspondence concerns a contract with you, the steps needed before or under that contract (art. 6(1)(b) GDPR).
My mailbox is hosted by Google (Google Workspace), which processes the messages on my behalf under Google’s data processing terms. I keep correspondence for as long as I need it to handle the matter and to document what was agreed.
Giving me your data is voluntary. Without an address I cannot reply.
Links to other services
The site links to my profiles on GitHub, LinkedIn and WakaTime. Following a link takes you to those services, which process your data under their own policies. Nothing from them is embedded here, so no data reaches them until you click.
Where the data goes
Cloudflare and Google are based in the United States and process data in the EU and in the US. Both are certified under the EU-U.S. Data Privacy Framework, and their data processing terms include the European Commission’s standard contractual clauses for transfers outside the EEA (art. 45 and 46 GDPR). I pass your data to no one else.
Your rights
Under the GDPR you can ask me for access to your data, for its rectification or erasure, for restriction of its processing and, for data you gave me under a contract, for a copy in a portable format. Write to maciej@jasiewicz.pro.
You can object at any time to processing based on my legitimate interests (art. 21 GDPR). I will then stop, unless I can show compelling legitimate grounds that override your interests, rights and freedoms.
You can lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), uodo.gov.pl.
I make no automated decisions about you and do not profile you.
Changes
This notice describes what the site actually does. When that changes, this page changes with it; the date of the last update is shown above.