Privacy Policy

1. Key information

www.piotr-kowalewski.com is Piotr Kowalewski’s personal portfolio website.

The website:

  • does not use application analytics;
  • does not display advertising;
  • does not profile visitors;
  • does not use marketing trackers;
  • does not sell personal data;
  • does not set its own analytics or advertising cookies.

The website uses only the mechanisms required to display the site, remember settings chosen by the user, support offline use, protect the service from abuse and operate the contact form.

2. Data controller

The data controller is Piotr Kowalewski.

The controller can be contacted about privacy and data-protection rights through the contact form available on the website.

The controller’s e-mail address is not publicly displayed on this page. The form provides an electronic contact channel without publishing an address exposed to automated harvesting and spam.

3. Data processed during a normal visit

When the website is used, the browser connects to Cloudflare infrastructure, which delivers and protects the website.

Standard connection handling may involve technical data such as:

  • IP address;
  • date and time of the request;
  • requested resource;
  • browser and device type;
  • basic HTTP headers;
  • security information generated by Cloudflare.

This data is used to deliver the website, maintain security, detect automated or harmful traffic and diagnose technical errors.

4. Contact form

When the contact form is submitted, the data entered by the user is processed, in particular:

  • a name or other sender identifier, when the form contains such a field;
  • e-mail address;
  • subject;
  • message content.

Technical data required to secure the form is also processed and may include the IP address, request origin, Turnstile token, Cloudflare security signals and technical identifiers related to request handling.

The form uses:

  • Cloudflare Pages Functions to handle the request;
  • Cloudflare KV to limit request frequency;
  • a honeypot and Cloudflare security signals;
  • Cloudflare Turnstile to protect against automated submissions;
  • Resend to deliver the message;
  • a Gmail/Google mailbox as the destination mailbox.

Cloudflare KV stores a technical rate-limit counter associated with requests from a given IP address. The counter is incremented before the later form checks. Each request accepted by the rate-limiting step renews the entry’s lifetime to 86,400 seconds, or 24 hours from the last such request. KV is not used to store the message content.

5. Purposes and legal bases

Data is processed for the following purposes:

Replying to messages and conducting correspondence

The legal basis is the controller’s legitimate interest in handling correspondence and replying to messages — Article 6(1)(f) GDPR.

Taking steps before cooperation or carrying out cooperation

When a message concerns a commission or other cooperation, the legal basis is taking steps at the user’s request before entering into a contract or performing a contract — Article 6(1)(b) GDPR.

Security and abuse prevention

Technical data, Turnstile and the rate-limit counter are used for the controller’s legitimate interest in protecting the website, form and mailbox against spam, bots and abuse — Article 6(1)(f) GDPR.

Legal obligations and claims

When cooperation creates legal obligations, data may be processed under Article 6(1)(c) GDPR. Data may also be retained for the legitimate interest of establishing, pursuing or defending claims — Article 6(1)(f) GDPR.

6. Retention

Data is not retained for longer than necessary for the purpose for which it was collected.

In particular:

  • a contact-form draft stored in sessionStorage is retained until the browser session ends or it is removed after successful submission;
  • the Cloudflare KV rate-limit counter is retained for 24 hours from the last request accepted by the rate-limiting step;
  • messages are retained for as long as needed to handle the enquiry and conduct correspondence;
  • messages that do not lead to cooperation and are no longer needed may be deleted earlier;
  • when contact leads to cooperation, data may be retained during the cooperation and afterwards for as long as required to comply with legal obligations and establish, pursue or defend possible claims;
  • interface preferences remain in the browser until they are reset on the website or the user removes the website’s data;
  • application cache is managed by the browser and Angular Service Worker and can be removed through browser settings.

Specific retention periods in Cloudflare, Resend and Google systems also depend on the configuration and policies of those providers.

7. Recipients

Data may be disclosed to providers of infrastructure and technical services:

  • Cloudflare — hosting, content delivery, server-side functions, security, Turnstile and KV;
  • Resend — e-mail delivery;
  • Google/Gmail — operation of the destination mailbox;
  • authorities or other entities entitled to receive data under applicable law.

Service providers may use infrastructure outside the European Economic Area. In such cases, data transfers are carried out using mechanisms permitted by Chapter V GDPR, as applied by the relevant provider and arising from appropriate agreements or decisions.

Sanity is used to prepare portfolio content during the website build process. A normal visit does not require the browser to contact Sanity in order to display that content.

8. Browser storage and cache

The website uses the following browser-side mechanisms:

localStorage

It stores preferences selected by the user:

  • theme-mode — system, light or dark theme;
  • fs-multiplier — text size;
  • animations — animation preference;
  • highContrast — high-contrast mode;
  • haptics — haptic-feedback preference.

These settings are not used to track the user. They can be changed or reset in the settings panel or removed by clearing the website’s data in the browser.

sessionStorage

It may store:

  • a draft of the contact form;
  • technical interface flags needed during the current session.

Session data is removed when the browser session ends, and the form draft is also removed after successful submission.

Cache API and Service Worker

Angular Service Worker may store application files, fonts and images locally to speed up later visits and allow parts of the website to work without an internet connection. The cache is not used for profiling or analytics.

9. Cookies and similar technologies

The application does not set its own analytics, advertising or marketing cookies.

Cloudflare may set the technical cf_clearance cookie, which records successful security verification and helps distinguish legitimate traffic from bots. The cookie is controlled by Cloudflare and is not used by the application for analytics or advertising.

The website does not display a consent banner because it does not use optional analytics, advertising or marketing tracking. The storage and security mechanisms described above support user-requested functions, deliver the website or protect it.

10. External links

The website may contain links to external profiles, projects or services. After an external link is opened, the privacy rules of the destination provider apply. This website does not control how external websites process data.

11. User rights

To the extent provided by the GDPR, the user may request:

  • access to personal data;
  • a copy of personal data;
  • rectification;
  • erasure;
  • restriction of processing;
  • data portability, where applicable;
  • objection to processing based on legitimate interests.

A request can be submitted through the contact form.

The user also has the right to lodge a complaint with the President of the Polish Personal Data Protection Office.

12. Voluntary provision of data

Providing data through the form is voluntary. Without an address that allows a reply and the message content, the controller may be unable to respond or take steps related to cooperation.

13. Automated decisions

The controller does not make decisions producing legal effects solely by automated means and does not conduct marketing profiling.

Automated security mechanisms may reject a request that appears to be spam or automated traffic. They are used only to protect the form and infrastructure.

14. Changes to this policy

This policy may be updated when the website’s operation, the scope of processed data or the providers used by the website change. The current version is published on this page together with its update date.

Last updated

24 July 2026.