← FIRST ● IFR

Privacy Policy

Effective date: 23 April 2026 | Version 1.0

1. General provisions

This Privacy Policy sets out the rules for processing and protecting the personal data of users of the website dedicated to the publication "First Steps in Practical IFR" (the "Website"). The document has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR"), the Polish Personal Data Protection Act of 10 May 2018 (Journal of Laws 2018 item 1000, as amended), the Polish Act of 18 July 2002 on the Provision of Electronic Services (Journal of Laws 2002 No. 144 item 1204, as amended) and the Polish Electronic Communications Law of 12 July 2024 (Journal of Laws 2024 item 1221), in particular with regard to cookies.

2. Data Controller

The controller of personal data within the meaning of Article 4(7) GDPR is Maciej Peikert, a natural person, author of the publication "First Steps in Practical IFR".

You can contact the Controller in any matter relating to the processing of personal data and to exercise the rights granted by the GDPR by email at: peikert@vp.pl.

Given the nature and scale of processing, the Controller is not required to appoint a Data Protection Officer (Article 37 GDPR).

3. Purposes, legal bases and scope of processing

3.1. Provision of electronic services

The Website provides information about the publication and educational quizzes ("Companion quizzes"). Access to the quizzes requires an access code delivered with the book. The code and the result of its verification are stored exclusively in the user's browser (using the localStorage mechanism) and are not transmitted to the Controller's server. Legal basis: Article 6(1)(b) GDPR (performance of a contract for the provision of electronic services).

3.2. Email correspondence

When you send an email to the Controller, the following data is processed: your email address, the content of your message and any other data you voluntarily include in your message. Purpose: responding to and handling your inquiry. Legal basis: Article 6(1)(f) GDPR (legitimate interest of the Controller in maintaining communication with users).

3.3. Statistical and analytics data

The Controller may use analytics tools (e.g. Plausible Analytics, Google Analytics 4) for the purpose of compiling visit statistics and improving the Website. The data is aggregated and, as a rule, does not allow identification of a specific person. Legal basis: Article 6(1)(a) GDPR (consent expressed via the cookie banner) — for cookies other than strictly necessary, in accordance with Article 173 of the Polish Electronic Communications Law.

3.4. Sale of the book

The publication "First Steps in Practical IFR" is sold exclusively through the external online shop shop.jetzone24.com. The Controller of the Website does not process transaction or payment data of customers. The controller of personal data within the purchase process is the operator of that shop, acting on the basis of its own privacy policy and terms of service.

4. Retention period

  • Email correspondence — for the period necessary to respond to and handle the matter, no longer than 3 years from the last contact, and in case of potential claims — until the limitation period expires (Article 118 of the Polish Civil Code).
  • Analytics data — for the period defined in the analytics tool settings, no longer than 26 months.
  • Data stored locally (localStorage) — until removed by the user via browser settings.

5. Recipients of data

Personal data may be entrusted to processors under Article 28 GDPR, in particular:

  • hosting and CDN providers running the Website;
  • email service providers;
  • analytics tool providers (where used).

Data is not sold or shared with third parties for marketing purposes.

6. Transfers outside the EEA

When the Controller uses providers established outside the European Economic Area (e.g. cloud computing providers), data is transferred only on the basis of appropriate safeguards, in particular the Standard Contractual Clauses approved by the European Commission (Implementing Decision 2021/914) or on the basis of an adequacy decision (e.g. EU–U.S. Data Privacy Framework).

7. Your rights

Under the GDPR you have the right to:

  • access your data (Article 15 GDPR);
  • rectify your data (Article 16 GDPR);
  • erase your data (Article 17 GDPR);
  • restrict processing (Article 18 GDPR);
  • data portability (Article 20 GDPR);
  • object to processing based on Article 6(1)(f) GDPR (Article 21 GDPR);
  • withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR);
  • lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland; www.uodo.gov.pl).

To exercise your rights, please contact: peikert@vp.pl.

8. Cookies and similar technologies

The Website uses cookies and the localStorage mechanism in accordance with Article 173 of the Polish Electronic Communications Law of 12 July 2024 and Article 6(1)(a) and (f) GDPR. On your first visit, a consent banner is displayed allowing you to accept or reject cookies other than strictly necessary.

CategoryPurposeDurationConsent
NecessaryStoring your cookie banner choice; quiz access (code in localStorage)up to 12 mo. / sessionNot required
AnalyticsAggregated traffic statistics (e.g. Plausible / Google Analytics 4)up to 26 monthsRequired

Withdrawing consent: you can withdraw your consent at any time by clearing site data in your browser — the next visit will display the consent banner again. Withdrawal of consent does not affect the lawfulness of processing performed before the withdrawal (Article 7(3) GDPR).

Most browsers also allow you to manage cookies in their settings (block, delete, private mode). Restricting cookies may affect the functionality of the Website.

9. Automated decision-making

Users' personal data is not subject to automated decision-making, including profiling producing legal effects, within the meaning of Article 22 GDPR.

10. Data security

The Controller applies appropriate technical and organisational measures to ensure the protection of processed personal data, in particular encryption of connections (TLS/HTTPS) and limiting data access to authorised persons only, in accordance with Article 32 GDPR.

11. Changes to this Privacy Policy

The Controller reserves the right to amend this Privacy Policy in case of changes in legislation, technology or the scope of services provided. Changes take effect upon publication of the updated version on the Website.