LAST UPDATED 23 JULY 2026
Privacy Policy
This policy explains how Active Years Journal handles personal data for visitors in Poland and elsewhere in the European Economic Area.
1. Controller and Scope
Active Years Journal operates the informational website activeyearsjournal.info and acts as the controller for personal data described in this policy. Our contact address is ul. Długa 17, 31-147 Kraków, Poland. You can reach us at [email protected] or by telephone at +48 12 881 52 40. This policy applies to visits to the website, messages sent through the contact form, cookie choices, and ordinary technical records created when the website is requested.
The website provides general educational wellness material. We do not ask visitors to create an account, buy a product, provide payment details, or submit health records. Please do not include medical histories, diagnoses, identification documents, or other sensitive information in a contact message.
2. Data We Receive
When you use the contact form, we receive the name, email address, subject, message, and privacy acknowledgement that you submit. We also receive a short-lived technical submission fingerprint to reduce immediate duplicate messages. When you browse the website, the hosting environment may record an internet protocol address, date and time, requested page, response code, browser type, device information, referring page, and security events. These records are technical logs rather than reader profiles.
Cookie preference records stored in your browser show whether necessary, analytics, or preference categories were selected. Necessary local storage may remember that a choice was made. Analytics or preference technologies remain inactive until the relevant consent is recorded.
3. Purposes and Legal Bases
We process contact details to answer a request, maintain correspondence, and protect the form from misuse. Depending on the message, the legal basis is our legitimate interest in operating a responsive informational website, taking steps requested before a possible agreement, or consent where that is the appropriate basis. Technical logs are processed for security, error diagnosis, service availability, and prevention of abuse based on our legitimate interests.
Non-essential analytics and preference cookies are processed only with consent. You may refuse them without losing access to the educational content. Where we must retain a limited record to establish, exercise, or defend a legal claim, processing may rely on the relevant legal obligation or legitimate interest.
4. Cookies and Similar Storage
Necessary technologies support core functions such as cookie-choice storage, accessibility preferences, and form security. Analytics cookies, if enabled, help us understand aggregated page use. Preference cookies, if enabled, remember optional display choices. The cookie banner provides Accept All, Reject Non-Essential, and Manage Preferences controls. Detailed categories, purposes, and typical lifetimes are explained in the Cookie Policy.
Withdrawing consent does not make earlier consent-based processing unlawful. You can reopen preference controls from the Cookie Policy, clear browser storage, or change browser settings. Blocking necessary storage may prevent the preference record from being remembered, but the main reading experience remains available.
5. Recipients and Service Providers
Personal data may be handled by authorised personnel and carefully selected service providers that supply hosting, security, email delivery, diagnostics, and website maintenance. They receive only the data needed for their role and are expected to follow contractual confidentiality, security, and data-protection duties. We do not sell contact details, rent mailing lists, or share messages for unrelated advertising.
If a provider processes data outside the European Economic Area, we use an available lawful transfer mechanism, such as an adequacy decision or approved standard contractual clauses, together with supplementary safeguards where appropriate. Information may also be disclosed when required by law, a valid authority request, or a proportionate need to protect legal rights and website security.
6. Retention
Contact messages are normally retained for up to twenty-four months after the last meaningful exchange, then deleted or anonymised unless a longer period is needed for an unresolved request, legal obligation, or claim. Failed or abusive form attempts may be retained in security logs for up to twelve months. Routine server logs are normally kept for up to ninety days, while a smaller record connected with a confirmed security incident may be retained for up to twenty-four months.
Cookie choices remain in the browser for up to six months unless they are cleared earlier. Any analytics data activated by consent should be configured with proportionate retention, ordinarily no longer than fourteen months. Backup copies rotate on a controlled schedule and are not used for ordinary business access.
7. Security
We use reasonable organisational and technical measures designed for the nature of the website and the data involved. Measures may include encrypted transport, access controls, updates, security headers, logging, restricted administrative privileges, backup procedures, and duplicate-submission protection. No internet service can promise absolute security, so visitors should avoid sending unnecessary or sensitive information.
Access to contact messages is limited to people who need it for support or administration. Suspected incidents are assessed and documented. Where applicable law requires notification to an authority or affected person, we will make that notification within the required period and provide the information then available.
8. Your Rights
Subject to the conditions in the General Data Protection Regulation and Polish law, you may request access, correction, deletion, restriction, or portability of personal data. You may object to processing based on legitimate interests and withdraw consent at any time for future processing. Some rights are not absolute; for example, information may need to be retained to meet a legal obligation or address a legal claim.
To exercise a right, email [email protected] and describe the request clearly. We may ask for proportionate information to confirm identity, but we will not request more than is reasonably necessary. We aim to respond within one month, with any lawful extension explained. You may also lodge a complaint with the President of the Personal Data Protection Office in Poland or another competent supervisory authority.
9. Children and Sensitive Information
This website is written for adults aged 50+ and is not directed to children. We do not knowingly seek data from children. If a parent or guardian believes a child has submitted personal data, they should contact us so that the situation can be reviewed and the information removed where appropriate.
The contact form is not intended for health data, biometric data, political opinions, religious beliefs, or other special-category information. If such material is sent without a clear need, we may delete it without further use and retain only the minimum record required to document the action.
10. Updates and Contact
We may update this policy when the website, legal requirements, or service arrangements change. The date at the top identifies the current version. Material changes will be presented in a reasonably visible way before they take effect where practical. Earlier wording may be retained for accountability.
Questions about privacy can be sent to [email protected], posted to ul. Długa 17, 31-147 Kraków, Poland, or raised by telephone at +48 12 881 52 40 during the stated business hours. Please include only the information needed to understand the privacy question.