Data controller
The data controller is Aleksandra Bogocz, who runs the mrumi.com project. Contact: hello@mrumi.com.
Scope of processed data
The Controller processes account data (email address and hashed password), data provided by the User while using the Service, and technical data (IP address, anonymous application error logs).
Purposes and legal bases
Data is processed to provide the Service (Art. 6(1)(b) GDPR), to ensure security and prevent abuse (Art. 6(1)(f) GDPR), and — solely if the User signs up — to deliver the newsletter (Art. 6(1)(a) GDPR, consent).
Recipients of data
Data may be entrusted to processors acting on the Controller's behalf to the extent necessary to provide the Service. Some processors may be located outside the European Economic Area; in such cases transfers rely on standard contractual clauses approved by the European Commission. The Controller does not sell data and does not share it for advertising purposes.
Retention period
Account data is retained until the User deletes the account; after deletion — for the period necessary to establish, exercise, or defend legal claims (Art. 118 et seq. of the Polish Civil Code). Newsletter subscriber data — until consent is withdrawn. Application error logs and technical data — for the period necessary to fulfil the purpose for which they were collected.
User rights
The User has the right of access, rectification, erasure, restriction of processing, objection, data portability, and withdrawal of consent. To exercise any right, contact hello@mrumi.com. The Controller responds within one month (GDPR Art. 12(3)).
Right to lodge a complaint
The User has the right to lodge a complaint with the supervisory authority — the President of the Polish Personal Data Protection Office (uodo.gov.pl).
Cookies
The Service uses only strictly necessary cookies (authentication session, theme preference). No analytics or advertising tools are deployed. Should such tools be introduced, the Controller will obtain prior consent.
Security
Connections to the Service are encrypted (HTTPS). Passwords are stored in hashed form. Access to personal data is limited to authorized persons.
Changes to the policy
The Controller announces material changes to this policy with appropriate advance notice — by email (if the User has an account) or via an on-site notice.