Privacy Policy

Privacy Policy

Last updated: September 8, 2026

This Privacy Policy explains how personal data is processed when you visit piotrmechlinski.com, create a member account, subscribe to a newsletter, contact us, book a meeting or purchase a service.

1. Data controller

The controller is Piotr Mechlinski, Parkowa 4, 05-532 Solec, Poland. For privacy questions or requests, email pm@piotrmechlinski.com.

2. Data we collect

Information you provide

Depending on how you use the Service, we may collect your name, email address, member and newsletter preferences, messages, booking details, organisation, billing and invoice information, and information you choose to provide in an enquiry or consultation.

If you pay through Stripe, payment-card details are collected directly by Stripe. We generally receive transaction status, amount and limited payment and billing information rather than your full card number.

Website and member analytics

The website uses Ghost’s first-party web analytics. Ghost records page views, approximate unique visitors within 24-hour windows, referral sources and related technical information. This web analytics function is cookie-free and does not use persistent browser storage to recognise visitors across sessions, browsers or devices. For Ghost(Pro) sites, Ghost states that analytics data is stored in EU regions.

When a logged-in member visits, Ghost may record the member ID, whether the member is free or paid, and the posts viewed. This allows audience-level and content-engagement reporting.

Newsletter analytics

If you subscribe, Ghost stores your email address, subscription status and related member information. Newsletter analytics are enabled. Ghost may record whether a newsletter was opened and whether a subscriber clicked a link, so we can understand aggregate and individual engagement with a send. Every newsletter includes an unsubscribe link.

Ghost’s member-source tracking is enabled. At signup, Ghost may record a referral or campaign source, including source information carried in a link. Outbound link tagging is also enabled: links from this site to an external site may receive a source parameter identifying this publication as the referrer.

Cookies

Ghost may use cookies or similar storage that is strictly necessary for member sign-in, authentication, security and preferences. Ghost’s native web analytics does not use cookies. External services reached through links, such as Cal.com or Stripe, may use cookies under their own policies.

3. Why we use personal data

  • To operate, secure and improve the website and understand which content is useful.
  • To create and administer member accounts and newsletter subscriptions.
  • To send newsletters you requested and measure newsletter delivery and engagement.
  • To respond to enquiries and communicate through Microsoft 365 email.
  • To arrange consultations and meetings through Cal.com.
  • To form and perform contracts, process payments and issue invoices.
  • To meet tax, accounting and other legal obligations and establish or defend legal claims.

Where the GDPR applies, we rely on:

  • Consent for newsletter subscriptions and other optional communications. You may withdraw consent at any time.
  • Steps before a contract and performance of a contract for enquiries, bookings, payments and delivery of services.
  • Legal obligations for tax, accounting, regulatory and lawful disclosure requirements.
  • Legitimate interests in operating and securing the Service, understanding content performance, attributing member sources, measuring newsletter engagement, maintaining business records and handling legal claims. You may object to processing based on legitimate interests. Where consent is legally required for a particular analytics or communication activity, we rely on consent instead.

5. Service providers and recipients

We disclose data only where needed to operate the Service, perform a contract, obtain professional support or comply with law. The main providers are:

  • Ghost(Pro), for website hosting, publishing, member accounts, newsletter delivery and first-party analytics, together with Ghost’s subprocessors.
  • Microsoft 365, which hosts pm@piotrmechlinski.com and processes email messages, attachments and contact information under Microsoft’s data-protection terms.
  • Cal.com, for scheduling. A booking may include your name, email address, time zone, meeting details and answers to booking questions.
  • Stripe, if a paid service is purchased, for payment processing, fraud prevention and related legal obligations. Stripe may act as both processor and independent controller depending on the activity.
  • Professional advisers, insurers, public authorities or courts where reasonably necessary or legally required.

Each provider also publishes its own privacy information.

6. International transfers

Some providers or their subprocessors may process data outside the European Economic Area. Where required, transfers are protected by an adequacy decision, the EU–US Data Privacy Framework, Standard Contractual Clauses or another lawful safeguard. Ghost states that Ghost(Pro) native analytics data is stored in EU regions. Cal.com states that booking data may be processed in the United States with recognised transfer safeguards. Microsoft and Stripe describe their transfer arrangements in their privacy and data-protection terms.

7. Retention

We keep personal data only as long as necessary for the purpose for which it was collected:

  • Member and newsletter records are kept while the account or subscription is active. A limited suppression record may remain after unsubscribing so the preference can be honoured.
  • Enquiries and ordinary email correspondence are generally kept for up to 24 months after the last substantive contact, unless a longer period is needed for a continuing relationship or legal claim.
  • Booking, contract and service records are kept for the engagement and applicable limitation periods.
  • Invoices and tax or accounting records are kept for the period required by law.
  • Analytics and technical records follow the retention settings and schedules of Ghost and the relevant service provider.

8. Your rights

Where the GDPR applies, you may request access to your personal data, correction, deletion, restriction, portability, or object to certain processing. You may withdraw consent at any time without affecting processing already carried out lawfully.

To exercise a right, email pm@piotrmechlinski.com. We may need to verify your identity. You also have the right to lodge a complaint with the President of the Personal Data Protection Office in Poland (UODO) or another competent supervisory authority.

9. Required information and automated decisions

Data marked as required in a form is needed to provide the requested account, booking, payment or service. Without it, we may be unable to complete the request. We do not use personal data collected through the Service to make solely automated decisions that produce legal or similarly significant effects.

10. Security

We use reasonable organisational and technical measures and established service providers to protect personal data. No Internet transmission or storage system is completely secure.

11. Children

The Service is not directed to children under 18, and we do not knowingly collect their personal data. Contact us if you believe a child has provided personal data so that we can investigate and remove it where appropriate.

12. Changes

We may update this Privacy Policy to reflect changes in the Service, providers, settings or law. The current version will be posted on this page with a revised “Last updated” date.

13. Contact

Piotr Mechlinski
Parkowa 4, 05-532 Solec, Poland
pm@piotrmechlinski.com