This policy explains what personal data we collect on status403.com, why we collect it, who processes it on our behalf and what rights you have. We have tried to write it so it can be read without a lawyer.
Who is responsible for your data
The controller of your personal data is status403 Sp. z o.o. (status403 Spółka z ograniczoną odpowiedzialnością) with its registered office in Warsaw, ul. Aleja "Solidarności" 68 lok. 121, 00-240 Warszawa, Poland, entered in the Register of Entrepreneurs of the National Court Register (KRS) kept by the District Court for the Capital City of Warsaw, 12th Commercial Division, under KRS number 0001269943, NIP 5253108931, REGON 54585207200000.
For anything concerning your personal data, write to privacy@status403.com. We have not appointed a data protection officer, because the scale of our processing does not require one; that address reaches the people who handle it. We answer every such message.
What data we collect and why
Booking a call
When you enter your email address in the Book a call form, we send you one email with a link to our Google Calendar appointment page. That is the only thing the form does: the address is used to deliver that email and is not added to any mailing list. Providing it is voluntary, but without it we cannot send you the link.
If you then pick a time on the appointment page, Google Calendar asks for your name and email address (and anything else you choose to type) and places the booking in our calendar. From that point we process your details to prepare for and hold the call and to discuss possible cooperation.
Writing to us
If you email us at hello@status403.com or any other address on this site, we process your address, your name if you give it, and the content of the correspondence, to answer you and to handle whatever the message is about.
Data collected automatically
When you open a page, your browser necessarily sends connection data: your IP address, browser and device type, the page requested, the referring page and the time of the request. We need this to deliver the page and to protect the site against abuse. The site is served by Cloudflare, which processes this data as part of hosting it. Our own application does not keep a visitor log.
Pages fetch the site's fonts (Inter and JetBrains Mono) from Google Fonts, and blog pages show our authors' profile pictures from GitHub. Each of those requests sends your IP address to Google or GitHub respectively, as any request to any server does. Nothing else is sent, and no cookies are set by them.
Analytics and advertising measurement, only with your consent
With your permission we use Google Analytics 4 to understand how the site is used and Google Ads to measure campaigns and show relevant ads. Both load through Google Tag Manager, and Tag Manager itself is not fetched until you allow at least one of them in the consent notice. Until then nothing is sent to Google's measurement servers and no Google cookies are set.
If you allow analytics, Google collects the pages you view, how you got here, approximate location derived from your IP address, your browser and device, interactions such as scrolling and outbound clicks, and three events from the booking form: that a submission was attempted, that it succeeded, or that it failed and why. Your email address is never sent to Google. If you allow advertising, Google additionally stores advertising identifiers and uses your activity to measure our campaigns and personalise ads. The two purposes are separate choices.
Agent endpoints
The site also serves machine-readable documents (an API description, a markdown version of each page, an MCP endpoint and a few discovery files) for software agents. They return public site content only and collect nothing beyond the connection data described above.
Legal bases
We process personal data under the GDPR, specifically:
- Art. 6(1)(b) — steps taken at your request before entering into a contract, and performing one: handling your booking, the call itself and any discussion of cooperation that follows.
- Art. 6(1)(a) — your consent: Google Analytics and Google Ads, and the cookies they set. You can withdraw consent at any time; withdrawal does not affect the lawfulness of what happened before it.
- Art. 6(1)(f) — our legitimate interests: delivering the site and keeping it secure, loading fonts and author pictures, answering correspondence, keeping internal records, and establishing, exercising or defending legal claims.
- Art. 6(1)(c) — legal obligations, above all tax and accounting rules, once cooperation leads to a contract.
How long we keep data
- Booking requests. Our application does not store the address you submit; it is handed to our email provider to send the one message and appears in that provider's delivery log. The resulting calendar booking stays in our calendar.
- Correspondence and call notes. For as long as the matter is open, and then for as long as claims could arise from it — generally no longer than three years from our last contact. If we end up working together, data connected to the contract is kept for the period tax and accounting law requires and until the limitation period for claims has run.
- Your consent choice. In your browser's local storage until you change it or clear your browser data.
- Google Analytics. Event-level data is retained by Google for 14 months, aggregated reports for longer. Cookie lifetimes are in the table below.
Who we share data with
We do not sell personal data and do not share it for purposes not described here. We use providers that process data on our behalf under data processing agreements:
- Cloudflare, Inc. — hosting, content delivery and protection of the site against attacks.
- Resend, Inc. — sending the booking email.
- Google Ireland Limited — Google Workspace (our email and calendar, including the appointment page), Google Fonts, and, with your consent, Google Tag Manager, Google Analytics and Google Ads.
- GitHub, Inc. — our authors' profile pictures on the blog.
Data may also be disclosed to public authorities entitled to it under the law, if they request it.
Transfers outside the European Economic Area
Cloudflare, Resend, Google and GitHub are headquartered in the United States, so data may be transferred outside the EEA. Each of them is certified under the EU–US Data Privacy Framework, the European Commission's adequacy decision for the United States; where a particular transfer is not covered by it, it is based on the Commission's standard contractual clauses. You can ask us which mechanism applies to a given provider.
Cookies and local storage
Cookies are small files a website stores in your browser. Polish law (Art. 399 of the Electronic Communications Law) and the GDPR allow them to be stored only after you have been told what they are for and have agreed, unless they are necessary to provide the service you asked for.
Our own site sets no cookies. It stores one entry in your browser's local storage, s403-consent, which remembers the choice you made in the consent notice; it is never sent to our servers and is necessary to honour that choice. Google's cookies are set only after you allow the corresponding purpose:
| Name | Purpose | Set by | Lifetime | Requires |
|---|---|---|---|---|
s403-consent | Remembers your consent choices (local storage, not a cookie) | status403 | Until you change or clear it | Nothing — necessary |
_ga, _ga_* | Distinguishes visitors and sessions in Google Analytics | 2 years | Analytics consent | |
_gcl_au | Measures the effectiveness of Google Ads campaigns | 3 months | Advertising consent |
Until you choose, both purposes are treated as refused. You can change or withdraw your choice at any time with Cookie settings in the footer of every page. You can also delete stored cookies and block new ones in your browser's settings — the browser decides the conditions under which information is stored on your device — but blocking the necessary entry means the consent notice will appear again on each visit.
Profiling and automated decisions
We do not make decisions about you that produce legal or similarly significant effects by automated means. Google may use the advertising data described above to personalise ads, but only if you have allowed the advertising purpose.
Your rights
In connection with our processing you have the right to:
- access your data and receive a copy of it,
- have inaccurate data corrected and incomplete data completed,
- have your data erased where we have no basis to keep processing it,
- restrict processing,
- receive the data you gave us in a portable format and have it transmitted to another controller,
- object to processing based on our legitimate interests,
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal.
To exercise any of them, write to privacy@status403.com. We respond without undue delay and at the latest within one month.
If you believe we process your data unlawfully, you have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl, or with the supervisory authority of the EU member state where you live or work.
Security
The site is served over HTTPS only. Access to the mailboxes, calendar and provider accounts that hold personal data is limited to the people who need it for the purposes above.
Children
This site is addressed to businesses and does not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, let us know and we will delete it.
Links to other sites
Our content links to sites run by others — GitHub, LinkedIn, X and the sources our articles cite. Their processing is governed by their own policies, which are worth reading before you use them.
Changes to this policy
We will update this document when the tools we use or the applicable law change. The date of the last update is shown at the top of the page. Its canonical location is https://status403.com/privacy-policy.