Version 1.0 of 4 October 2026. This document will be reviewed by a lawyer before the Application is made available beyond family and friends.
This is a translation for convenience. The Polish version is binding.
1. Controller
Andrzej Brzeziński, NEW PROJECT Andrzej Brzeziński, ul. Mickiewicza 4/8, 19-300 Ełk, Poland, NIP (tax ID) 8481164296. Contact on data matters: office@newproject360.pl. No data protection officer has been appointed.
2. What data, why and on what basis
| Who it concerns | Data | Purpose | Basis (GDPR) | How long |
|---|---|---|---|---|
| Owner | first name, surname, e-mail, password (hash), authenticator app secret (encrypted), language | account, login | Art. 6(1)(b) | until the account is deleted |
| Owner | Folder content: documents, notes, contacts, checklist, letters, text recognised from scans | keeping the Folder and Emergency Access | Art. 6(1)(b) | until the account is deleted; after death see section 5 |
| Owner | health data | as above | Art. 9(2)(a): explicit consent | until consent is withdrawn or the data is deleted |
| Owner | Safe (ciphertext) | storing passwords and codes | Art. 6(1)(b); we do not know the content | as for the Folder |
| Folder Helper, second person of a couple | first name, e-mail, account, change history | keeping the Folder at the Owner's invitation | Art. 6(1)(b) | until access is withdrawn or the Folder is split |
| Trusted Person | first name, e-mail, account, logins, requests, view history | invitation, Emergency Access, security | before accepting the invitation: Art. 6(1)(f); after accepting: Art. 6(1)(b) | until removed by the Owner or until the Trusted Person withdraws |
| Persons entered by the Owner (family, doctor, notary, adviser) | contact details, role, sometimes data from documents | passing information to close ones | Art. 6(1)(f); health data only with that person's consent | as for the Folder |
| Everyone | IP address, time, browser, security events | security, detecting abuse | Art. 6(1)(f) and Art. 32 | 12 months |
| Everyone | version of accepted documents and consents, date, IP address | proof of consent and of the agreement | Art. 6(1)(c) and (f) (Art. 7(1)) | until claims become time-barred |
We do not profile, we do not sell data, and we do not use advertising or third-party analytics. Emergency Access opens automatically only according to the Owner's own settings.
3. Where we get the data from
From the Owner (about themselves and about the persons they have entered), from Trusted Persons and Folder Helpers (when they accept the invitation), and from the user's device (technical logs).
4. Recipients
- Hostinger: VPS server in the European Union, a processor under a data processing agreement.
- Outgoing mail provider (the office@newproject360.pl mailbox): sending e-mails.
- Trusted Persons: within the scope set by the Owner, after Emergency Access is opened.
- Public authorities: only where required by law.
We do not transfer data outside the European Economic Area.
5. Death of the Owner
- The GDPR does not protect the data of deceased persons (Recital 27), but it does protect the data of living persons in the Folder; we treat the deceased's data with the same care.
- After Emergency Access is opened on the grounds of death, the Folder is available to the Trusted Persons in read-only mode for 12 months. 30 days before the end of that period they receive an e-mail reminding them to download the data. The Folder is then deleted, and backups expire within 30 days.
- We recommend recording in the Folder who was authorised during the Owner's lifetime to access their medical records, or whether the Owner objects to the records being made available to close ones (Art. 26 of the Act on Patient Rights and the Patient Ombudsman).
6. Your rights
Access, rectification, erasure, restriction of processing, objection (where the basis is Art. 6(1)(f)), data portability (downloading data in the account settings), and withdrawal of consent at any time without affecting earlier processing. Complaints: President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, Poland.
If someone else entered your data in a Folder, you may ask whether we process it and exercise the rights above. We do not review Folders; we will notify the Folder's Owner of your request. This information fulfils the obligation under Art. 14(5)(b) GDPR.
7. Security
Encryption of documents on the server (AES-256-GCM, with the key kept outside the database and outside backups), the Safe encrypted in the browser (PBKDF2-SHA256, 600 000 iterations, AES-256-GCM), two-factor authentication, sessions of 8 h and 30 min of inactivity, daily backups (the 30 most recent), access log. Text recognised from scans and document descriptions are stored unencrypted in the database so that search works; they are protected by access controls on the server.
8. Cookies
We use only essential cookies: session, form protection, language and theme. They are necessary to provide the service (Art. 399(3)(2) of the Electronic Communications Law), so we do not ask for consent. We do not use analytics or advertising cookies.
9. Changes to the policy
We give notice of changes by e-mail and in the Application; previous versions are available in the Application.