Updated 8 September 2026

Privacy policy

This policy explains how MLDYX processes personal data for mldyx.com, the contact form, conversation booking, and email. It is written to meet GDPR.

Controller

The controller is MLDYX, an independent software practice established in Poland (Europe/Warsaw).

Privacy contact: hello@mldyx.com. Send GDPR requests from the email address the matter concerns, or with another reliable identity check.

We have not appointed a data protection officer. We are not required to.

Scope and purposes

The site presents the practice and lets people start a conversation. There is no shop, no user accounts, and no advertising profile.

We process data you submit (form, booking) and technical data needed to run and protect the service.

We do not seek children's data. The site is not directed at anyone under 16.

Contact form

Data: name, email, optional organisation, message, interface language, time sent, record that the privacy notice was acknowledged. A hidden honeypot field is not meant to be filled; it filters bots.

Purpose: receive and answer the enquiry. Legal basis: GDPR art. 6(1)(f) (legitimate interest: correspondence with a person who contacted us). Also art. 6(1)(b) where the message is a step toward a contract.

The form has one required checkbox: confirmation that you have read the privacy policy. It is information, not marketing consent, and not art. 6(1)(a) as a condition of sending. The box is not pre-ticked.

Object to art. 6(1)(f): hello@mldyx.com, from the address the matter concerns. After an objection we may keep correspondence if needed to establish, exercise, or defend legal claims (art. 6(1)(f)).

Storage: Cloudflare D1 bound to this site, until correspondence ends, not longer than 24 months from last contact unless a claim needs more.

Booking a conversation

Data: name, email, optional organisation and topic, chosen slot, tool (Google Meet or Zoom), language, booking status, record that the privacy notice was acknowledged.

Purpose: schedule the call and confirm it by email. Basis: art. 6(1)(b) (pre-contractual steps at your request).

The same required privacy-information checkbox applies. Without it the server rejects the booking. It is not marketing consent.

Confirmation may go out through Resend. If outbound mail is not configured, the booking is still stored and we reply by hand.

Meet or Zoom is a standing room URL from our settings, not a login to your account.

To cancel, write to hello@mldyx.com. Cancelled bookings are kept up to 24 months, same as correspondence.

Technical data and security

Cloudflare (hosting, DNS, CDN, WAF, Bot Fight, optional Turnstile) processes IP address, user agent, timestamps, and request diagnostics to deliver the site and limit abuse. Basis: art. 6(1)(f) (security of the network and service).

Turnstile, when enabled, checks that a human sent the form. It is not advertising.

Security logs are retained by Cloudflare under its own policy. We do not sell logs.

Analytics (consent only)

Google Analytics 4 loads only after explicit consent (art. 6(1)(a)). Without consent this site does not set Google scripts, tags, or cookies.

Purpose: see which pages are read. We do not use GA for ads, remarketing, or ad-network sharing.

You may refuse on first visit (“Reject analytics”), withdraw on the Cookies page, or email hello@mldyx.com. Withdrawal does not affect processing before that moment.

If no GA measurement ID is configured, analytics does not exist here and the consent bar is not shown.

Recipients and transfers

Recipients: Cloudflare (hosting and protection); Google (Analytics, only with consent); Resend (transactional email, if configured); Google or Zoom only as the meeting tool you pick.

Some providers are in the United States or use US subprocessors. Chapter V GDPR tools apply: adequacy (EU-US Data Privacy Framework where the entity is certified) and the European Commission’s standard contractual clauses.

We do not sell data, use brokers, or run an ad profile. There is no automated decision-making under art. 22 GDPR.

Retention

Messages and bookings: up to 24 months from last activity, then deletion or anonymisation, unless law or a dispute requires more.

Analytics consent: 180 days or until withdrawn, whichever comes first.

After withdrawal we delete Google cookies for this domain on this browser; copies inside Google Analytics follow Google’s retention.

Your rights

You may request access, rectification, erasure, restriction, portability, objection to legitimate-interest processing, and withdrawal of consent where consent is the basis.

You may complain to your EU supervisory authority. In Poland: President of the Personal Data Protection Office (UODO), Stawki 2, 00-193 Warsaw, uodo.gov.pl.

We answer without undue delay, within one month, extendable by two months for complex requests.

Changes

The current text lives at mldyx.com/en/privacy. A material change gets a new date at the top of the page.