1. Data Controller
The controller of personal data collected through this website is:
Company Name: HARD sc publishing company
Registered Address: ul. Wengris 71, 10-765 Olsztyn, Poland
Tax Identification Number (NIP): 7391837147
For any matters regarding data protection and privacy, you can contact the Controller via the company’s official correspondence address.
2. Scope and Purpose of Data Processing
This website is strictly informational. The Controller does not provide user registration, contact forms, comment sections, or newsletter subscriptions. Consequently, no direct personal data is actively requested or collected from visitors.
However, the technical infrastructure automatically processes standard server connection data (Server Logs) during each visit. This data includes:
- The public IP address of the requesting device,
- Date and time of the server request,
- Browser type, language, and operating system configuration.
Legal Basis: Article 6(1)(f) of the General Data Protection Regulation (GDPR) – legitimate interest of the Controller. This processing is technically necessary to ensure server security, detect and prevent malicious activities (e.g., DDoS attacks), diagnose technical errors, and maintain website stability.
3. Data Recipients and Transfers
Server logs are hosted and processed by the third-party infrastructure provider: OVH Cloud (OVH Groupe SAS), located within the European Economic Area (EEA). Data is processed strictly under compliance with GDPR requirements.
The Controller does not transfer personal data to third countries (outside the EEA) or international organizations. Furthermore, all visual assets, including typography (Google Fonts “Open Sans”), are hosted locally on the Controller’s server infrastructure. No external connections are established to Google servers, preventing any secondary data leakage or third-party tracking.
4. Data Retention Period
Server logs are retained temporarily for administrative and security purposes in accordance with the standard log rotation policies of the hosting provider (OVH). Once this period expires, the data is automatically overwritten or securely deleted, unless a security incident requires prolonged investigation.
5. Rights of the Data Subject
Under the GDPR, visitors retain specific legal rights regarding their automated data, provided that the data can be technically linked to a specific natural person:
- Right to access data and obtain a copy,
- Right to rectification (correction) of inaccurate data,
- Right to erasure (“right to be forgotten”),
- Right to restriction of data processing,
- Right to object to processing based on legitimate interest (Article 6(1)(f) GDPR),
- Right to lodge a complaint with a supervisory authority (in Poland: Prezes Urzędu Ochrony Danych
- Osobowych – PUODO).
6. Cookies Policy
The website is optimized for maximum user privacy:
- No Tracking or Marketing Cookies: The website does not deploy analytical scripts (e.g., Google Analytics), tracking pixels (e.g., Meta Pixel), or behavioral advertising cookies.
- No Persistent Cookies: No data files are permanently written to the storage of your device for tracking purposes.
- Technical Cookies: The underlying Content Management System (CMS) may utilize strictly necessary, transient session cookies or tokens (such as CSRF protection) required solely for secure page transmission and rendering. These are volatile and expire instantly when the browser session terminates.
Users maintain absolute control over cookies and can completely block or delete them at any time through
their web browser configuration settings.
