Privacy policy
This is my personal portfolio. There are no visitor accounts, advertising pixels or mailing lists. Here is what gets processed and why.
This is a practical, plain-language privacy notice, not formal legal advice or a guarantee of GDPR compliance.
Who is responsible
I, Marcin Jarota, based in Poznań, Poland, am the data controller for this portfolio. For privacy questions or requests, contact me by email:
Hosting and security logs
Cloudflare hosts and protects the site. When you visit, it processes technical request data such as your IP address, browser information, requested URL, referrer, time and response status to deliver pages, detect abuse and troubleshoot failures. Some of this data may appear in server or security logs.
I do not maintain a visitor database or sell your personal data. Technical processing still happens even if you do not download the CV or contact me.
Cloudflare Web Analytics
Where enabled, Cloudflare Web Analytics helps me understand visits and page performance through metrics such as page views, referrers, browser or device type, and loading times. Cloudflare describes it as cookieless: it does not use localStorage or fingerprint individuals, or track people across sites. This is separate from IP processing for hosting and security.
Analytics can be enabled through Cloudflare rather than the site code. This notice does not mean that the analytics beacon runs on every page.
Turnstile and CV downloads
Only the CV page loads Cloudflare Turnstile, which checks for bots using signals such as your IP address, browser information and connection characteristics. Cloudflare processes these signals on my behalf for security, and as a separate controller to improve its bot detection, as explained in its Turnstile notice.
Submitting the download form sends a challenge token to my Cloudflare Worker. The Worker passes the token and your IP address, when available, to Cloudflare’s Siteverify service. After verification, it streams a fixed PDF from a private Cloudflare R2 bucket. No name, email or account is required. R2 stores my CV, not a record of visitors.
The Worker does not save tokens or create a download history. Its diagnostic messages contain statuses, checks and error codes, not deliberately logged IP addresses, tokens or form bodies. Cloudflare may still keep platform or security logs. Verification can block a download; you can email me for the CV instead.
Email and outbound links
If you email me, I process your email address, name and whatever message or attachments you send so I can reply. My mailbox uses Google’s Gmail. Clicking an email link opens your email app; it does not submit a form to this site.
GitHub, LinkedIn and linked project sites have their own privacy policies. They receive data when you follow those links. You do not have to contact me or download the CV to browse the portfolio.
Why I can process this data
I rely on legitimate interests (GDPR Article 6(1)(f)) to deliver a working portfolio, keep it secure, prevent automated CV harvesting, understand basic site performance and answer correspondence. You can object to processing on this basis.
Where your enquiry requires steps towards a contract with you, Article 6(1)(b) applies to those steps. There are no advertising or behavioural profiling features. I do not make automated decisions with legal or similarly significant effects about you.
How long data is kept
The CV Worker uses the token during verification without saving it in an application database. Hosting, security, analytics and diagnostic data follow the relevant Cloudflare service and account retention settings; there is no single retention period for all of them.
I keep correspondence while needed to handle the conversation or working relationship, and longer only where needed for legal obligations or claims. You can ask me about retention or request deletion using the contact above.
Providers and international transfers
Cloudflare provides hosting, security, Turnstile, Workers, R2 and any enabled Web Analytics. Google provides email. They use affiliates and subprocessors, and data may be processed outside the EU/EEA, including in the United States.
Cloudflare’s Customer Data Processing Addendum describes its safeguards, including EU Standard Contractual Clauses for relevant transfers. Google’s privacy policy explains its transfer safeguards. The links below give provider and subprocessor details; you can also contact me for information about applicable safeguards. This site does not promise EU-only processing.
Your rights
Subject to GDPR conditions, you can request access, correction, deletion, restriction or portability of your personal data. You can object to processing based on legitimate interests. If processing ever relies on consent, you can withdraw it without affecting earlier lawful processing.
Email me to exercise these rights. I may need enough information to verify your identity and locate the data. I will respond without undue delay, normally within one month. If a permitted extension is needed, I will explain why within that month.
You can complain to Poland’s data protection authority, UODO, or the supervisory authority where you live or work in the EU/EEA, or where you believe an infringement occurred.
Changes to this notice
I will update this page and the date above when the site or its data processing changes. The current notice is always available here.