Legal

Privacy Policy

Last updated: 16 June 2026

This policy explains how Roman Bednarik processes personal data when you visit https://romanbednarik.com. We focus on data minimisation, transparency, and your right to choose analytics cookies.

1. Data controller

The data controller is Roman Bednarik, who operates this website.

We process data in accordance with the GDPR and applicable privacy laws.

2. What data we process

Depending on how you use the site, we may process:

  • Identity and contact details from the contact form (name, email, subject, message).
  • Technical data when browsing (device type, browser, operating system, page locale).
  • On-site behaviour if you consent to analytics (pages viewed, time on page, clicks, referrer, UTM parameters).
  • Hashed IP address (SHA-256) to limit abuse – we do not store full IP addresses.
  • Analytics cookie consent decisions.

3. Purposes and legal bases

We process data for the following purposes:

  • Contact form – handling your message and communication (legitimate interest / pre-contract steps).
  • First-party analytics – understanding traffic and improving the site (consent via cookie banner).
  • Security and operations – rate limiting, spam protection, and HTTP error logging (legitimate interest).

4. Cookies

We use first-party cookies only. No third-party ad or tracking services.

Analytics cookies are set only after you accept them in the cookie banner.

  • _pv_consent – stores your analytics decision (1 year).
  • _pv_sid – session identifier for analytics (30 minutes, after consent).
  • _pv_vid – anonymous visitor identifier (1 year, after consent).
  • locale – preferred site language.

5. Analytics

Analytics runs entirely on our infrastructure. Data is not sold to third parties.

We measure pageviews, time on page, scroll depth, clicks, outbound links, entry and exit pages, referrers, and device metadata.

If you decline analytics, we do not store on-site behaviour. You can withdraw consent anytime by clearing cookies in your browser.

6. Retention

Contact messages are kept as long as needed to handle your enquiry and follow-up communication.

Analytics data is automatically deleted after 90 days unless configured otherwise.

HTTP request logs (status codes, errors) are kept for the same period for operational diagnostics.

7. Recipients and transfers

We do not share data with advertisers. Hosting, email, or database providers may process data on our behalf under data processing agreements.

We do not sell data or transfer it outside the EEA unless necessary to provide the service with appropriate safeguards.

8. Your rights

Under the GDPR you have the right to:

  • request access, rectification, or erasure,
  • restrict processing or object to processing,
  • withdraw analytics consent (without affecting lawfulness before withdrawal),
  • lodge a complaint with your supervisory authority.

9. Security

We apply appropriate technical and organisational measures including IP hashing, restricted admin access, and encrypted transport (HTTPS).

10. Changes

We may update this policy. The last updated date is shown above. Please review this page from time to time.