LEGAL DOCUMENTATION // PRIVACY & COOKIES

Privacy & Data Protection Policy

Document Version: 2.1 (Compliant with GDPR, EU Data Protection Standards, and Polish Patient Rights Regulations).

1. System Architecture & Role Separation

PhysioNotes V2.0 desktop application and the jakubdyrszka.dev portal operate under strict architectural role separation: • Patient Medical Data (Local Architecture): The sole Data Controller (ADO) of patient clinical data entered into the desktop application is the physiotherapist or medical practice. In standard operation, patient records are stored locally on the user's computer and are not transmitted to PhysioNotes infrastructure or external cloud servers. • Account & License Telemetry (jakubdyrszka.dev Portal): For license validation data (email address, hardware deviceId hash, license status) sent to the portal, the Data Controller is Jakub Dyrszka (contact: contact@jakubdyrszka.dev). Processing is based on Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in license validation).

2. Scope & Purpose of Desktop Application Processing

Within PhysioNotes V2.0, the practitioner processes locally on the workstation: • Identification & contact data: Name, national ID/date of birth, address, phone number, email. • Special category health data (Art. 9(1) GDPR): Medical history, chief complaints, pain scales (VAS/NRS), objective exams, range of motion (ROM), clinical diagnoses, ICD-10 codes, treatment plans, and visit notes.

3. Cryptographic Security & Database

• Database Encryption: Local patient database is secured with AES-256 standard encryption (SQLCipher). • Key Derivation (scrypt): The encryption key is derived directly from the practitioner's PIN using the memory-hard scrypt function. • Session Security & Audit Trail: Features PIN lockout protection, automatic idle screen locking, and local audit logs tracking medical entry changes.

4. Medical Data Retention Period (20-Year Mandate)

Pursuant to statutory patient rights laws, medical documentation must be retained for 20 years from the end of the calendar year of the last entry. The right to erasure (Art. 17 GDPR) does not apply during this mandatory statutory retention window.

5. Patient Rights Compliance

The practitioner (Data Controller) facilitates patient GDPR rights locally: • Right to Information (Art. 13 GDPR) tracked in patient profile. • Right of Access & Portability (Art. 15 GDPR) via immediate PDF export. • Right to Rectification (Art. 16 GDPR) with comprehensive chronological audit logging.

6. Data Backups

In the local storage model, the practitioner holds responsibility for maintaining and securing database backups. The application includes tools to generate encrypted backups. The developer holds no master keys or backdoors.

7. Cookies, Local Storage & Sub-Processors (Portal)

The jakubdyrszka.dev web portal processes data with strict privacy safeguards: • Essential Session Cookies: We use browser local storage and essential session cookies (__session, __client_uat) managed by Clerk authentication infrastructure strictly to maintain logged-in user sessions, locale, and visual theme. • Service Providers & Sub-Processors: - Clerk, Inc. (USA) – user authentication, account management, and session security, - HotPay (ePłatności sp. z o.o. sp. k., Poland) – online payment gateway, - Vercel Inc. (USA) – web application hosting and secure binary installer delivery (Vercel Blob Storage). • No Marketing Trackers: We do not deploy third-party advertising pixels or behavioral tracking scripts.

8. Privacy Inquiries & Contact

For questions regarding portal operations, license validation, or account data: • Data Controller (Portal & Licensing): Jakub Dyrszka • Address: ul. Szuwarków 24, 43-100 Tychy, Poland • Email: contact@jakubdyrszka.dev | Phone: +48 504 345 289 For medical inquiries concerning specific patient records, please contact the treating physiotherapist directly.