Privacy Policy

Below you will find information regarding the processing of personal data when using this website and contacting me via the contact form.

Last updated:

1. Personal Data Controller

The controller of personal data processed through this website is Mariia Drotianko.

For matters relating to the processing of personal data, you may contact: mashadrotyanko@gmail.com.

2. What Data Is Processed?

When submitting the contact form, the following data may be processed:

  • the name or designation provided in the form,
  • email address,
  • the content of the submitted message,
  • other information voluntarily included in the message,
  • basic technical data relating to the connection to the website, such as the IP address, date and time of the request, browser type, device information and error information.

You are not required to provide special categories of personal data, including information concerning health, origin, beliefs, political opinions or private life. Please do not include such information in the form.

3. Purposes and Legal Bases for Processing

Data may be processed for the purpose of:

  • receiving messages, conducting correspondence and providing responses — on the basis of the controller's legitimate interest pursuant to Article 6(1)(f) of the GDPR;
  • preparing an offer, discussing a project or taking steps at the request of the data subject prior to entering into a contract — pursuant to Article 6(1)(b) of the GDPR;
  • establishing, pursuing or defending against potential claims — pursuant to Article 6(1)(f) of the GDPR;
  • protecting the website against spam, abuse and attempted security breaches — on the basis of the controller's legitimate interest.

4. Voluntary Provision of Data

Providing data is voluntary, but necessary in order to send a message and receive a response. Without providing a valid email address, it may not be possible to provide a response.

5. Contact Form

The form allows you to provide your name, email address and message content. Before submitting it, you are required to confirm that you have read the Privacy Policy.

The form contains a honeypot security field that is invisible to ordinary users. This field is intended to detect simple bots that automatically complete forms and is not used to collect additional data from legitimate users.

Messages are submitted without reloading the page to the form's server endpoint, where they are verified and then forwarded to the service responsible for sending email messages.

6. Data Recipients

Data may be entrusted to entities supporting the operation of the website and the handling of correspondence, in particular:

  • OVHcloud — as the provider of the VPS server and hosting infrastructure;
  • Resend, provided by Plus Five Five, Inc. — as the provider of the email delivery service;
  • the provider of the email inbox to which messages are delivered;
  • entities providing technical, IT, security or legal services, where access to the data is necessary to perform the relevant service.

These entities are granted access to the data only to the extent necessary to perform the specified tasks.

7. Website Hosting and Server Logs

The website is hosted on a VPS server provided by OVHcloud. In connection with handling connections, the server and the software installed on it may automatically record technical data.

Server logs may include, among other things:

  • the device's IP address,
  • the date and time of the request,
  • the requested website or resource address,
  • the server response code,
  • the browser and operating system type,
  • information about errors and failed requests,
  • data required to detect attempted attacks and abuse.

Logs are used solely to ensure the proper operation of the website, diagnose problems, create backups, protect the server and detect abuse.

Standard application and server logs should be automatically deleted or overwritten after a maximum of 30 days, unless they need to be retained for longer in order to investigate a security incident, failure, or to pursue or defend claims.

8. Transfers of Data Outside the European Economic Area

Some service providers may be established in or use infrastructure located outside the European Economic Area, particularly in the United States.

Resend stores customer data in the United States. Data transfers should be carried out using appropriate legal mechanisms, such as Standard Contractual Clauses, an adequacy decision or another mechanism provided for under the GDPR.

9. How Long Are Messages Retained?

Data is not retained indefinitely. The retention period depends on the nature of the correspondence and the subsequent course of communication.

Spam and Accidental Messages

Messages identified as spam, automated submissions, unsolicited offers or messages unrelated to the portfolio's activities may be deleted immediately, generally no later than within30 days.

Enquiries That Did Not Lead to Cooperation

Ordinary contact correspondence that did not lead to the commencement of cooperation is retained for the period necessary to handle the enquiry, but no longer than 12 months from the last message.

After this period, the message and the related data are deleted from the active email inbox, unless there is a justified need to retain them for longer, for example due to ongoing negotiations or the need to protect against claims.

Correspondence Related to Cooperation

Where contact leads to the preparation of an offer, the completion of a project or the conclusion of a contract, correspondence may be retained for the duration of the cooperation and, after its completion, for the period required by law or until the relevant limitation period for claims has expired.

Messages containing information required to document project delivery, arrangements, payments or settlements may be retained for longer than ordinary contact enquiries.

Message Deletion and Backups

Deleting a message from the active inbox means removing it from the email account used in the ordinary course of operations. Where the email provider or server uses recurring backups, deleted data may remain in those backups for a limited period until the relevant backup is automatically overwritten.

Data stored exclusively in a backup is not used for ongoing correspondence. It may be restored only in the event of a failure, data loss or security incident.

Request for Earlier Deletion

The data subject may request earlier deletion of their data by sending a message to: mashadrotyanko@gmail.com.

The data will be deleted unless there is an overriding legal basis for its continued retention, such as a legal obligation or the need to establish, pursue or defend claims.

10. Rights of the Data Subject

Depending on the legal basis and circumstances of the processing, you have the right to:

  • access your data,
  • rectify inaccurate data,
  • erase your data,
  • restrict processing,
  • data portability,
  • object to processing based on the controller's legitimate interest.

Requests concerning the exercise of these rights may be sent to: mashadrotyanko@gmail.com.

11. Right to Lodge a Complaint

If you believe that your data is being processed in breach of applicable law, you have the right to lodge a complaint with the President of the Personal Data Protection Office.

Before lodging a complaint, you may contact the controller in order to clarify the matter or exercise your rights.

12. Automated Decision-Making

Data submitted through the form is not used for profiling or automated decision-making that produces legal effects or similarly significantly affects the user.

13. Cookies and Similar Technologies

What Are Cookies?

Cookies are small pieces of information stored by the browser on the user's device. They may be used, among other things, to maintain a session, remember settings, ensure security, generate statistics or conduct advertising activities.

Cookies Used on the Website

The website does not currently use advertising, profiling or analytics tools such as Google Analytics, Meta Pixel, Hotjar or similar systems that track user behaviour.

The website may use only cookies or similar technical mechanisms that are necessary to:

  • ensure the proper operation of the website,
  • ensure connection security,
  • protect the form against abuse,
  • support server-side functions or sessions,
  • remember essential technical settings.

Technically necessary cookies are not used to create a marketing profile or display personalised advertising.

Cookie Duration

Session cookies are deleted when the browser is closed or when the relevant session ends. Persistent cookies, where used, remain on the device for the period specified in their settings or until they are manually deleted.

Managing Cookies

Users may view, block or delete cookies through their browser settings. Blocking technically necessary cookies may cause certain website functions to operate incorrectly.

Because the website does not currently use analytics, marketing or profiling cookies, no separate consent banner is displayed for such technologies.

Future Changes

If analytics tools, marketing tools, embedded videos, maps or other services using non-essential cookies are added in the future, this policy will be updated and a consent management mechanism may be introduced before such tools are activated.

The website may contain links to external profiles and services, such as Instagram, LinkedIn or Behance.

After visiting an external service, data is processed in accordance with the rules established by its operator. The website controller does not control how external services operate or the cookies they use.

15. Data Security

Appropriate technical and organisational measures are implemented to protect data against loss, unauthorised access, accidental alteration or disclosure.

These measures include, in particular, securing access to the VPS server, updating software, protecting access credentials and restricting access to data solely to persons and entities that require it.

However, no method of transmitting or storing data on the Internet can guarantee complete security.

16. Changes to the Privacy Policy

This policy may be updated in connection with changes to the operation of the website, the services used, the hosting configuration, the scope of the form or applicable laws.

The current version of this document will be available on this page together with the date of the most recent update.