Privacy notice
1. Controller and contact
The controller for account, contact and service-security data is Pat Dimension Patryk Olędzki, a sole proprietorship operated by Patryk Olędzki, Polish tax ID (NIP) 7221621767, REGON 382606442, Stokowisko 8, 18-212 Nowe Piekuty, Poland. Contact PatDimension@gmail.com or the postal address above for any personal-data matter.
A business or organization uploading personal data for its own activities may be the controller for that content, which we process on its instructions. See the data processing agreement. The board owner should also inform its participants.
2. Data and purposes
- Accounts and collaboration: email, profile name, identifier, session, language, boards, files, comments, access permissions, invitations and history needed for saving and recovery. Basis: providing the service contract and taking steps at your request before entering it (GDPR Article 6(1)(b)).
- Age and guardians: age range, terms version and acceptance time; for ages 13–17, guardian email and approval time. These determine eligibility and document authority to enter the agreement. Bases: Article 6(1)(b) and (f), the legitimate interest in protecting minors and demonstrating proper activation. We do not collect birth dates or identity-document scans.
- Security and maintenance: IP, browser information, request time and type, event/error identifiers, change metadata and sending limits. Basis: Article 6(1)(f), legitimate interests in account protection, abuse prevention, diagnosis and recovery.
- Contact, complaints and rights: contact details, correspondence and information needed to handle a matter. Bases: Article 6(1)(b), (c) for legal duties and (f) for other correspondence and establishing, exercising or defending claims.
We do not use advertising, marketing profiling or solely automated decisions with legal or similarly significant effects. Data is not provided as payment for advertising. We do not request blanket consent for unspecified future uses.
3. Sources and recipients
If you choose optional Google sign-in, Google supplies your account identifier, verified email address, name and optional profile image. We use these to create an account or sign in to an existing account with the same verified email, to provide the service contract (GDPR Article 6(1)(b)). We also store the account link and technical authentication tokens. We do not request access to Gmail messages or Google Drive files. Google receives information about the use of sign-in with our application and connection data; its processing is described in the Google privacy policy. Email-link sign-in remains available.
Data comes from you, your browser and participants who add content, invite you or name a guardian. Invitations include an email and board role; guardian requests originate from the prospective user. If you do not recognize a message, you need not respond and may request deletion.
Authorized participants see shared content, comments, profile name and presence; access settings may reveal participants’ email addresses. Tools and agents explicitly authorized by an owner may also be recipients. We do not grant unrelated people access to boards.
4. Providers and international transfers
OVHcloud provides the VPS and active board/file storage. Cloudflare provides DNS, the product site, connection protection and tunnel, authentication and D1 account storage, transactional email and R2 encrypted backups. Google operates the Gmail contact mailbox; avoid sending unnecessary board content there. Data may also be disclosed to legally authorized authorities and confidential advisers handling a specific matter.
Global provider services may involve access from outside the European Economic Area. We do not guarantee exclusively EU processing. Provider terms describe safeguards, including standard contractual clauses and adequacy decisions where applicable: Cloudflare DPA, OVHcloud contracts and Google transfer frameworks. On request, we provide information on the mechanism applicable to a service and a copy of relevant safeguards, protecting others’ data and confidential information.
5. Retention
- Accounts, permissions and content: while providing the service until the relevant data is deleted. Board archiving is reversible and is not deletion. Library files and history can exist independently of a visible object.
- Sign-in links: 10 minutes; sessions: up to 7 days, renewable. Token expiry does not imply immediate deletion of all event metadata.
- Guardian links: 48 hours. Unconfirmed guardian addresses and tokens are cleared after 30 days; the account’s age range remains to preserve the restriction. Approval evidence is retained during use and afterwards only as needed to establish authority or handle claims.
- Local backups: 7 days; encrypted offsite backups: 30 days. Deleted active data may remain until backup expiry. Recovery respects earlier deletion requests.
- Server logs rotate by size, up to three 10 MB files per service, so their duration depends on traffic. Board event history remains with the information needed to operate the board. Guardian-request sending counters are removed within two days after their limiting window.
- Correspondence, requests and necessary evidence: until the matter is resolved, then only as necessary for applicable legal duties or limitation periods. The period depends on the matter; we limit retained information to what is needed.
6. Browser storage
Technical cookies maintain sessions and access to protected files. Local Storage and IndexedDB keep language, tool/panel settings, recent boards and recovery copies of pending changes. They are not used for advertising tracking. Preferences remain until changed or site data is cleared; local drafts may remain after sign-out. On shared devices, confirm your work is saved, then sign out and clear site data.
The homepage drawing demo runs locally and does not upload sketches. The site infrastructure still processes technical connection data.
7. Your rights
Subject to GDPR conditions, you may request access, a copy, rectification, erasure, restriction and portability. You may object to legitimate-interest processing for reasons relating to your particular situation. If a particular activity relies on consent, you may withdraw it without affecting earlier lawful processing.
Contact PatDimension@gmail.com. Account settings also provide a deletion-request function and the export menu provides board export. We may ask for information necessary to verify your entitlement. We normally respond within one month and notify you within that period of any legally permitted extension and its reasons. Identity scans are not a standard requirement.
You may complain to the Polish supervisory authority (UODO) or another competent supervisory authority. Providing data is voluntary, but email and activation information are necessary for an account. Board content and additional details are your choice; do not disclose data you are not entitled to share.