Please update your browser

This site relies on modern web technologies your browser does not support. The layout and colors will not display correctly.

Supported browsers:

Chrome, Edge, Opera111+
Firefox128+
Safari (macOS / iOS)16.4+

Easiest fix: open this site on another device, e.g. your phone, or update your browser and come back.


You can also reach me directly:

LinkedIn
Back to home page

<PrivacyPolicy />

Privacy Policy

1. Data Controller

The controller of your personal data is Kamil Pawelec, operating under the business name Kamil Pawelec E-GAMES, NIP (Tax ID): 7133091784, REGON: 364446350 (hereinafter: the "Controller").

2. Legal Basis

This Privacy Policy has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), the Polish Act of 10 May 2018 on the Protection of Personal Data, and the Polish Act of 18 July 2002 on Providing Services by Electronic Means.

3. Contact Information

For matters related to personal data protection, you can contact the Controller through the contact form available on the home page or via LinkedIn (opens in new tab).

4. Data Collection Methods

The Controller collects personal data through the following channels:

  • Contact form - name, email address, message content. Data is encrypted using AES-256-GCM before being stored in the database. Additionally, an HMAC-SHA256 hash of the email address is created to detect duplicate submissions. After you submit the form, an automatic confirmation containing a copy of your message is sent to the email address you provided, and the Controller receives the delivery status of both emails (sent, delivered, delayed, bounced, reported as spam, not sent)
  • Challenges - nickname, completion time and a hashed browser identifier (a SHA-256 digest of the User-Agent header and the IP address). The nickname and time are published in the public ranking for the given month; the identifier is never published and is used solely to prevent multiple result submissions
  • Technical data - IP address, User-Agent header and browser language are automatically collected by the hosting server (Vercel). For rate limiting purposes, temporary SHA-256 digests are created: one from the combination of these three values and one from the IP address alone, stored in Redis memory; the raw IP address is not stored there
  • Visit statistics (Vercel Web Analytics) - anonymous traffic data: visited page URL, traffic source (referrer), country, browser, OS and device type. The service uses no cookies and no persistent identifiers - visitors are distinguished by a temporary hash valid for at most a single day, which cannot identify a person

5. Purposes and Legal Bases of Processing

Your personal data is processed for the following purposes:

  • Responding to contact form inquiries - based on your consent (Art. 6(1)(a) GDPR) and the Controller's legitimate interest (Art. 6(1)(f) GDPR)
  • Recording challenge results - based on consent (Art. 6(1)(a) GDPR), given by voluntarily submitting a result
  • Protection against abuse (rate limiting, Turnstile) - based on the Controller's legitimate interest (Art. 6(1)(f) GDPR)
  • Ensuring proper website functionality (technical cookies, session storage) - based on the Controller's legitimate interest (Art. 6(1)(f) GDPR)
  • Maintaining anonymous visit statistics (Vercel Web Analytics) - based on the Controller's legitimate interest (Art. 6(1)(f) GDPR); the collected data cannot identify a user

6. Cloudflare Turnstile

The contact form uses Cloudflare Turnstile to protect against automated submissions (bots). Turnstile verifies the browser in the background; if it cannot decide automatically you will see a simple checkbox to tick. There are no image puzzles and no profiling for advertising purposes. In the configuration used on this website Turnstile stores no cookies in your browser. When the Controller verifies the token server side it does not send your IP address to Cloudflare; Cloudflare does see it when the widget loads, because that is a direct connection between your browser and its servers. The Controller receives no information about you beyond the verification result: passed or not. Processing is described in Cloudflare's Privacy Policy (opens in new tab) and the Turnstile Privacy Notice (opens in new tab).

7. Data Recipients

To provide its services, the Controller uses the following data processors:

  • Vercel Inc. (USA) - website hosting, server log processing (IP address, User-Agent) and anonymous visit statistics (Vercel Web Analytics)
  • Supabase Inc. (USA) - database storing encrypted contact data and challenge results
  • Resend Inc. (USA) - sending email notifications to the Controller about new contact form messages and the automatic confirmation to the sender; for this purpose the name, email address and message content are passed to the service, which returns the identifier and delivery status of each email to the Controller
  • Upstash Inc. (USA) - temporary storage of hashed identifiers for rate limiting purposes (Redis)
  • Cloudflare, Inc. (USA) - Turnstile service protecting the contact form against bots

8. International Data Transfers

The entities listed in Section 7 are based in the United States. Data transfers are carried out on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, under the EU-U.S. Data Privacy Framework. The Controller has made efforts to ensure that selected providers guarantee an adequate level of personal data protection in compliance with GDPR requirements.

9. Data Security

The Controller applies the following technical and organizational measures to protect personal data: encryption of contact data using AES-256-GCM (authenticated encryption ensuring confidentiality and integrity), HMAC-SHA256 deduplication hashing, transmission exclusively via HTTPS, HTTP security headers (Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), admin panel authentication via Supabase Auth, and multi-layered form protection (rate limiting, Turnstile, Zod validation).

10. Data Retention Period

Personal data is stored for the following periods:

  • Contact form data - until the correspondence is concluded and the purpose of the inquiry is fulfilled. Messages marked as read and requiring no further action are deleted from the database automatically 90 days after receipt (a daily clean-up job); unread messages and messages marked as requiring further correspondence are kept until it is concluded. Regardless of the above, data is deleted earlier at your request or when consent is withdrawn
  • Challenge results (nickname, time, identifier) - indefinitely, as archived monthly rankings, until deleted at your request
  • Rate limiting data (digests) - deleted automatically when the time window expires, at the latest after 48 hours
  • Server logs (Vercel) - according to Vercel's retention policy (up to 30 days)

11. Your Rights

Under GDPR, you have the following rights:

  • Right to access your data (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure - "right to be forgotten" (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw consent at any time - without affecting the lawfulness of processing carried out before the withdrawal
  • Right to lodge a complaint with the President of the Personal Data Protection Office (UODO)

12. Cookies and Similar Technologies

This website does not use cookies for analytics or marketing purposes and therefore displays no consent banner - the technologies in use are strictly necessary for the service to function and, under electronic communications law, do not require user consent. Visit statistics (Vercel Web Analytics) operate entirely without cookies and without cross-site tracking. The statistics also include single technical events, for example the detection of an unsupported browser, without any user identifier. Only the following items are used:

  • NEXT_LOCALE cookie - remembers the selected site language (strictly necessary)
  • Supabase Auth cookies - login session, set exclusively in the admin panel (necessary for the Controller)
  • Cloudflare Turnstile - contact form bot protection, sets no cookies (see Section 6)
  • localStorage - remembers the preferred theme (light/dark)
  • sessionStorage - temporary Challenges state and the most recently selected language, within a single browser session only

13. Voluntary Provision of Data

Providing personal data is voluntary but necessary to use the contact form or submit a challenge result. Failure to provide the required data will prevent the use of these features.

14. Changes to the Privacy Policy

The Controller reserves the right to make changes to this Privacy Policy. Any significant changes will be communicated by updating the content on this page. It is recommended to periodically review the current version of the policy. This privacy policy was prepared by attorney-at-law Karolina Marchut (kancelariamarchut.pl (opens in new tab)).

Last updated: September 2, 2026