LEGAL DOCUMENTATION // GDPR & COOKIES

Privacy & Medical Data Protection Policy

Document Version: 2.0 (Compliant with GDPR, EU Data Protection Standards, Polish Patient Rights Act, and Electronic Communications Law).

SZCZEGÓŁOWE ZAPISY // DETAILED CLAUSES

1. System Architecture & Dual GDPR Roles

PhysioNotes V2.0 desktop application and the jakubdyrszka.dev web portal operate under a strict separation of two data streams: • Patient Medical Data (Zero-Cloud Architecture): The sole Data Controller (ADO) of patient data entered into the PhysioNotes V2.0 application is the physiotherapist or medical practice. The software developer (Jakub Dyrszka) has zero access to patient data, stores nothing on remote cloud servers, and does not provide cloud processing for medical records. Consequently, the Developer is not a Data Processor under Art. 28 GDPR, and no Data Processing Agreement (DPA) is required. • Account & Telemetry Data (jakubdyrszka.dev Portal): For license and activation data (email address, encrypted hardware deviceId hash, license status) sent to the portal, the Data Controller is Jakub Dyrszka (contact: jakub.dyrszka@gmail.com). Processing is based on Art. 6(1)(b) GDPR (license contract performance) and Art. 6(1)(f) GDPR (legitimate interest in software verification and IP protection).

2. Scope & Purpose of Desktop Application Processing

Within PhysioNotes V2.0, the physiotherapist processes: • Identification & contact data: Name, national ID (PESEL)/date of birth, address, phone number, email. • Special category health data (Art. 9(1) GDPR): Medical history, chief complaints, pain scales (VAS/NRS), objective exams, range of motion (ROM), clinical diagnoses, ICD-10 codes, treatment plans, and clinical notes. The legal basis for the practitioner is Art. 9(2)(h) GDPR in conjunction with national healthcare regulations.

3. Cryptographic Security & Isolation (AES-256-GCM)

• Local Database Encryption: The local patient database (physionotes-secure.json) is encrypted using authenticated symmetric encryption AES-256-GCM. • Key Derivation (scrypt): The encryption key is derived directly from the physiotherapist's PIN using the memory-hard scrypt function, preventing brute-force and rainbow table attacks. • Session Security & Audit Trail: Includes PIN lockout timers, automatic session locking (Auto-Lock) on inactivity, and immutable historical audit trails for every clinical entry modification.

4. Medical Data Retention Period (20-Year Mandate)

In accordance with Polish and European medical documentation laws (Art. 29 of the Patient Rights Act), patient medical documentation must be retained for exactly 20 years from the end of the calendar year in which the last entry was made. The right to erasure ("right to be forgotten" under Art. 17 GDPR) does not apply to mandatory medical records during this 20-year retention window.

5. Patient Rights Compliance

The practitioner (Data Controller) enables full patient rights under GDPR through built-in software tools: • Right to Information (Art. 13 GDPR) tracked in the patient profile. • Right of Access & Data Portability (Art. 15 GDPR) via instantaneous, comprehensive PDF report generation. • Right to Rectification (Art. 16 GDPR) with full chronological audit logs.

6. Zero-Cloud Backups & Practitioner Responsibility

Because PhysioNotes operates on a Zero-Cloud Offline-First model, the physiotherapist bears sole responsibility for maintaining and securing database backups. The application automatically generates encrypted restore points in the local backups/ directory. The practitioner is required to regularly archive these files to secure external storage (such as hardware-encrypted SSDs). The Developer holds no master keys or backdoors.

7. Cookies & Local Storage Policy (jakubdyrszka.dev)

Our portal and website strictly respect user privacy: • Essential Local Storage: We only use local browser mechanisms (localStorage / sessionStorage) to remember language preferences (PL/EN), UI theme preference (Dark/Light), and cookie banner consent state. Under electronic communications law, these technical items do not require prior consent. • No Tracking/Ad Cookies: We do not deploy invasive third-party tracking scripts, advertising pixels, or sell telemetry data to external vendors.

8. Contact for Data Protection & Security

For questions regarding PhysioNotes V2.0 technical security, portal licensing, or web privacy practices, please contact the software creator: • Data Controller (Portal & Licensing): Jakub Dyrszka • Email: jakub.dyrszka@gmail.com For medical record inquiries concerning a specific patient, please contact the treating physiotherapist directly.