Homepage

Privacy Policy (GDPR)

1. Data Controller

The data controller is Maciej Jesiołowski (business activity: Maciej Jesiołowski - Web Developer), NIP: 6681963204. Contact: mjesiolowski.cranio@gmail.com Sessions take place in Poznań (near Lake Malta).

2. Purposes and Legal Basis

I process data for the purposes of: service delivery (booking appointments), communication, session safety (health interview — with explicit consent under Art. 9(2)(a) GDPR, as health data constitutes a special category of personal data), and technical purposes (server logs). Health interview notes are kept in paper form, stored securely with access limited to the practitioner, and used solely to ensure continuity and safety of sessions. Notes are retained for 3 years from the date of the last session and then destroyed. Newsletter / notifications: processing of first name, surname, email address and optionally phone number for the purpose of informing about available craniosacral therapy session slots and for marketing communications related to the practice and services offered (pricing, promotions, updates). Legal basis: consent (Art. 6(1)(a) GDPR). Newsletter data retention period: until consent is withdrawn. Consent may be withdrawn at any time via the unsubscribe link in every email or by contacting mjesiolowski.cranio@gmail.com. Providing data is voluntary; not signing up for notifications does not exclude you from booking sessions.

3. Data Recipients

Your data may be shared with technical service providers: Booksy (bookings), Vercel Inc. (hosting — based on standard contractual clauses (SCCs) and Data Processing Addendum), email provider, OVH SAS (domain registration, DNS — servers located in the EU, processing based on a Data Processing Agreement). Brevo (Sendinblue SAS, 17 rue Salneuve, 75017 Paris, France) — email marketing service provider, storing subscriber data and handling the delivery of notification and marketing emails. Processing based on a Data Processing Agreement (DPA). Servers located in the EU. No data transfers outside the EEA.

4. Cookies

The website does not use marketing cookies or analytics tools.

5. Your Rights

You have the right to: access your data (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), objection (Art. 21), and to lodge a complaint with the President of the Office for Personal Data Protection (ul. Stawki 2, 00-193 Warsaw, Poland). Contact: mjesiolowski.cranio@gmail.com. You have the right to withdraw your consent to data processing at any time (via the unsubscribe link in every email or by email contact). Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

6. Data Breach Notification

In the event of a personal data breach that may pose a risk to your rights, you will be notified without undue delay, in accordance with Art. 33 and 34 GDPR.

7. Data Protection Officer

Due to the nature and scale of processing (sole practitioner, no large-scale processing), a Data Protection Officer has not been appointed. For any matters regarding personal data, you may contact the controller directly at: mjesiolowski.cranio@gmail.com.