Menu
alexambros
The problem entiway How I work Contact PL / EN
The problem entiway How I work Contact
PL / EN

Document

Privacy and cookie policy

Last updated: 20 August 2026

1. Data controller

The controller of your personal data is Aleksander Ambros, conducting unregistered business activity within the meaning of art. 5 of the Act of 6 March 2018 — Entrepreneurs’ Law, contact address: POLAND 41-902 Bytom, ul. Łukasza Wallisa 19/3, e-mail: [email protected].

2. Nature of the site

alexambros.com is a portfolio site and a server-side PHP application with no database. The site offers no registration, no user accounts and no direct payment processing.

3. Scope, purposes and legal bases of processing

3.1. Contact form and e-mail correspondence

Sending a message through the contact form does not write anything to a database; it directly composes and sends an e-mail to the controller’s mailbox.

  • Scope of data: e-mail address, message content, and automatically attached technical metadata: the sender’s public IP address, a timestamp (date and time) and the selected language version of the site.
  • Purposes and legal bases:
    • Conducting business correspondence and replying to the enquiry (art. 6(1)(f) GDPR — the controller’s legitimate interest).
    • Protecting the form against abuse and spam, and ensuring IT security (art. 6(1)(f) GDPR — the controller’s legitimate interest).
  • Retention period: messages are kept in the mailbox for the duration of the contact and for up to 12 months after it ends, for archiving purposes and to defend against potential claims.

3.2. Web server logs

The HTTP server (Nginx) automatically records technical requests made to the site (including IP address, date and time, the requested resource/URL, HTTP response code, the referring page (referer) and browser information).

  • Purpose and legal basis: technical diagnostics, keeping the site stable and protecting it against network attacks (art. 6(1)(f) GDPR — the controller’s legitimate interest).
  • Retention period: server logs are rotated automatically and permanently deleted after roughly 10 days (rotate 10).

4. Cookies and local storage

The site uses strictly necessary technical and functional mechanisms only. No marketing, tracking or profiling cookies are used.

4.1. Table of local technologies in use

Name Type Retention When it is set Purpose
PHPSESSID Cookie (HttpOnly, Secure, SameSite=Lax) Session (until the browser is closed) On entering the site Maintaining the technical session and protecting the contact form against CSRF attacks.
lang_choice Cookie (Secure, SameSite=Lax) 365 days After the user manually switches language Remembering the chosen interface language (“pl” or “en”).
theme Local Storage Indefinitely (until the browser is cleared) After the user manually switches theme Remembering the chosen theme (light / dark).
__cf_bm, cf_clearance Cookie (HttpOnly, Secure) — set by Cloudflare, Inc. __cf_bm: 30 minutes; cf_clearance: as configured by the Cloudflare service During the anti-bot verification performed by Cloudflare Telling human traffic apart from automated traffic and remembering a passed verification so that it is not repeated on every request.

The __cf_bm and cf_clearance cookies are not set by the site’s own code but by Cloudflare, Inc. as the provider of protection against automated traffic (see section 5). They are a mechanism necessary to keep the site secure, so their use does not require the user’s consent. Only a visitor who is put through the anti-bot verification receives them.

4.2. Analytics (Matomo)

The site uses its own, self-hosted instance of Matomo Analytics installed on the controller’s private server.

  • Analytics runs in cookieless mode (disableCookies) with IP address anonymisation enabled.
  • Statistical data is aggregated only and is not linked to identified natural persons.
  • Analytics data is not shared with any third parties.

5. Data recipients (third parties)

Technical data may be processed by external providers of services necessary for the site to work correctly and securely:

  • Hetzner Online GmbH (Germany, EEA): provider of the VPS server infrastructure and e-mail.
  • Cloudflare, Inc. (USA / global): provider of the CDN, DNS, DDoS protection and reverse proxy. All HTTP/HTTPS traffic passes through Cloudflare’s infrastructure, which processes visitors’ IP addresses for security and content delivery optimisation. Data transfers rely on standard contractual clauses (SCC) or other mechanisms compliant with the GDPR.
  • Google LLC (Google Fonts): the site loads fonts from fonts.googleapis.com and fonts.gstatic.com. While the font files are being fetched, the user’s IP address is sent to Google’s servers in order to serve the HTTP request.

6. Rights of the data subject

Everyone whose data is processed has the rights granted by the GDPR:

  • the right of access to the data and to receive a copy of it (art. 15 GDPR),
  • the right to rectification of the data (art. 16 GDPR),
  • the right to erasure of the data (art. 17 GDPR),
  • the right to restriction of processing (art. 18 GDPR),
  • the right to object to processing based on the controller’s legitimate interest (art. 21 GDPR),
  • the right to lodge a complaint with the supervisory authority: the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).

All privacy enquiries and requests should be sent to: [email protected].

This is a translation provided for convenience. In case of any discrepancy, the Polish version of this policy prevails.

Back to the homepage

alexambros.com Aleksander Ambros, I design and build B2B applications.

entiway.com entiway, my economic event sourcing system.

[email protected] Cookieless analytics, on my own server. Privacy & cookie policy © 2026 Aleksander Ambros · Silesia, Poland