Legal
Privacy Policy
Last updated: 15 April 2025
1. Data Controller
This website is a personal portfolio operated by Patrycja Piotrowska, Senior Product Designer.
Contact: [email protected]
2. What Data Is Collected
This site does not collect any personal data directly (e.g. no registration, no contact forms that store data server-side). However, third-party analytics tools may collect the following data automatically when you visit:
- IP address (anonymised where possible)
- Browser type and version
- Operating system
- Pages visited and time spent on each page
- Referring URL
- Clicks, scrolls, and mouse movements (heatmaps via Hotjar)
- Session recordings (Hotjar) — these are anonymised and do not capture passwords or payment data
This data is collected only if you consent to analytics cookies.
3. Legal Basis for Processing (GDPR Art. 6)
Analytics data is processed based on your consent (Art. 6(1)(a) GDPR). You are asked for consent via the cookie banner when you first visit the site. You may withdraw consent at any time — see Section 7.
Strictly necessary cookies (required for the site to function) are processed on the basis of legitimate interest (Art. 6(1)(f) GDPR).
4. Hotjar (Analytics & Heatmaps)
This site uses Hotjar (Hotjar Ltd., Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian's STJ 3141, Malta) to understand how visitors interact with the site.
Hotjar may collect:
- Heatmaps — where users click, move, and scroll
- Session recordings — anonymised recordings of user sessions
- Device and browser information
- Approximate geographic location (country/city level, derived from IP)
Hotjar is contractually obligated not to sell this data. IP addresses are automatically anonymised. Hotjar does not track users across websites.
You can opt out of Hotjar data collection at any time by visiting: hotjar.com/legal/compliance/opt-out
Hotjar's Privacy Policy: hotjar.com/legal/policies/privacy
5. Cookies
This site uses the following categories of cookies:
Necessary cookies
Required for the website to function. Cannot be disabled. These include the cookie storing your consent preferences.
Analytics cookies (optional)
Set by Hotjar to collect anonymised usage data (heatmaps, session recordings, page views). Only placed after your consent.
Cookies: _hjSessionUser_*, _hjSession_*, _hjid — retained for up to 365 days.
6. Data Retention
Hotjar retains session and heatmap data for 365 days by default. After that period, data is automatically deleted. Your consent preference is stored locally in your browser until you clear it or change it.
7. Your Rights Under GDPR
As a data subject in the EU/EEA, you have the following rights:
- Right of access — you can request a copy of data held about you.
- Right to rectification — you can request correction of inaccurate data.
- Right to erasure — you can request deletion of your data.
- Right to restrict processing — you can request that processing be limited.
- Right to data portability — you can request your data in a portable format.
- Right to object — you can object to processing based on legitimate interests.
- Right to withdraw consent — you can withdraw analytics consent at any time using the link below, or via Hotjar's opt-out page.
To exercise any of these rights, contact: [email protected]
You also have the right to lodge a complaint with your local data protection authority.
8. Third-Party Links
This site may contain links to external websites (LinkedIn, Dribbble, etc.). This Privacy Policy does not apply to those sites. Please review their respective privacy policies.
9. Changes to This Policy
This policy may be updated occasionally. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the site after changes constitutes acceptance of the updated policy.
Manage your cookie preferences
You can change or withdraw your consent at any time.