Legal
Privacy Policy
Last updated: 16 June 2026
This policy explains how Roman Bednarik processes personal data when you visit https://romanbednarik.com. We focus on data minimisation, transparency, and your right to choose analytics cookies.
1. Data controller
The data controller is Roman Bednarik, who operates this website.
We process data in accordance with the GDPR and applicable privacy laws.
2. What data we process
Depending on how you use the site, we may process:
- Identity and contact details from the contact form (name, email, subject, message).
- Technical data when browsing (device type, browser, operating system, page locale).
- On-site behaviour if you consent to analytics (pages viewed, time on page, clicks, referrer, UTM parameters).
- Hashed IP address (SHA-256) to limit abuse – we do not store full IP addresses.
- Analytics cookie consent decisions.
3. Purposes and legal bases
We process data for the following purposes:
- Contact form – handling your message and communication (legitimate interest / pre-contract steps).
- First-party analytics – understanding traffic and improving the site (consent via cookie banner).
- Security and operations – rate limiting, spam protection, and HTTP error logging (legitimate interest).
5. Analytics
Analytics runs entirely on our infrastructure. Data is not sold to third parties.
We measure pageviews, time on page, scroll depth, clicks, outbound links, entry and exit pages, referrers, and device metadata.
If you decline analytics, we do not store on-site behaviour. You can withdraw consent anytime by clearing cookies in your browser.
6. Retention
Contact messages are kept as long as needed to handle your enquiry and follow-up communication.
Analytics data is automatically deleted after 90 days unless configured otherwise.
HTTP request logs (status codes, errors) are kept for the same period for operational diagnostics.
8. Your rights
Under the GDPR you have the right to:
- request access, rectification, or erasure,
- restrict processing or object to processing,
- withdraw analytics consent (without affecting lawfulness before withdrawal),
- lodge a complaint with your supervisory authority.
9. Security
We apply appropriate technical and organisational measures including IP hashing, restricted admin access, and encrypted transport (HTTPS).
10. Changes
We may update this policy. The last updated date is shown above. Please review this page from time to time.