Go home

Get in Touch

Have a question about visiting Auschwitz? Send me a message and I'll get back to you.

Privacy Policy

Last updated: March 2026

Introduction

This website is operated by ŁUKASZ TARNOWSKI, conducting business under the name ŁUKASZ TARNOWSKI, registered in the Central Register and Information on Economic Activity (CEIDG), NIP: 5492257321, REGON: 12022820400000, with its registered office at UL. DR JANUSZA KORCZAKA 17, PL-32-600 RAJSKO, Poland ("Administrator"). This website is a personal and professional project and is not affiliated with, endorsed by, or officially connected to the Auschwitz-Birkenau State Museum or any other institution. This Privacy Policy explains how personal data is collected, used, and protected in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Polish Personal Data Protection Act, and other applicable laws.

Information I Collect

I collect the following personal data voluntarily provided through the contact form and newsletter signup:

  • Your email address
  • Topics of interest you select
  • Any book ideas, historical information, or suggestions you choose to share
  • Technical data processed automatically by infrastructure providers, including IP address logs processed by Cloudflare for security purposes and approximate geolocation data (country/region) derived from your IP address
  • Geolocation data — only when you explicitly use the "Locate Me" feature on the interactive map. Your location is processed locally in the browser to display your position on the map and is not stored or transmitted to any server

Legal Basis for Processing

Personal data is processed on the following legal bases under Article 6 GDPR: (a) your consent (Article 6(1)(a)) for email communications and analytics cookies; (b) the legitimate interest of the Administrator (Article 6(1)(f)) for responding to inquiries, improving the website, ensuring security, and protecting against abuse; (c) where applicable in the future, performance of a contract (Article 6(1)(b)) if paid products or services are offered.

How I Use Your Information

Your data may be used for the following purposes:

  • Responding to inquiries and communicating regarding the book project and related initiatives
  • Sending informational and promotional emails regarding my historical, educational, publishing, or future commercial projects, including books, digital products, consultations, guided services, and related resources
  • Understanding audience interests and improving content
  • Ensuring website security and preventing abuse
  • Developing future services, including online consultations, educational resources, or e-commerce offerings

Email Communications

By submitting your email address, you consent to receiving occasional informational and promotional communications related to my historical, educational, and publishing activities. This may include updates about books, digital products, consultations, and related initiatives. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal. Each email contains an unsubscribe option. You also have the right to object to the processing of your personal data for direct marketing purposes at any time under Article 21(2) GDPR. Upon receiving such an objection, your data will no longer be processed for direct marketing.

Cookies and Tracking Technologies

This website uses cookies and similar technologies.

Essential and Functional Cookies

These cookies are necessary for the website to function properly, including remembering your cookie preferences and interface settings such as dark mode. These cookies do not require consent.

Analytics Cookies

With your consent, Google Analytics 4 is used to analyze website traffic and improve user experience. Data retention in Google Analytics is set to the maximum available period. Analytics cookies are activated only after your explicit consent.

You can accept or decline analytics cookies via the cookie banner when visiting the site. You may also adjust your browser settings to control cookies.

Data Retention

Personal data is retained until you withdraw your consent or unsubscribe from communications. Data stored in MongoDB Atlas is deleted upon request or when no longer necessary for the purposes described in this policy. Data necessary for legal or accounting obligations (if applicable in the future) may be retained for the period required by law. Server security logs processed by Cloudflare are retained according to their infrastructure policies.

Data Storage

Personal data submitted through this website is stored in MongoDB Atlas, a cloud-hosted database service provided by MongoDB, Inc. Data is stored on servers located within the European Union (EU region). MongoDB Atlas is used to securely store user data, including account information, newsletter subscriptions, and other data necessary for the provision of services described in this policy. Additionally, approximate geolocation data (country/region level, derived from your IP address) may be stored to improve content relevance and comply with regional legal requirements. MongoDB Atlas employs encryption at rest and in transit, access controls, and regular security audits.

Third-Party Service Providers

The website uses the following service providers: Cloudflare (hosting, infrastructure, and security services), MongoDB Atlas (cloud database, EU region), Resend (email delivery), and Google (Google Analytics). These providers may process personal data on behalf of the Administrator under data processing agreements.

International Data Transfers

Data stored in MongoDB Atlas is hosted within the European Union. Some other service providers, including Cloudflare, Resend, and Google, may process personal data outside the European Economic Area (EEA), including in the United States. Transfers are carried out based on Standard Contractual Clauses (SCC) or other legally recognized safeguards, including participation in the EU–US Data Privacy Framework where applicable.

Data Concerning Third Parties

If you voluntarily provide personal data concerning third parties (for example historical references to family members), you are responsible for ensuring that you have a legal basis to share such information. Sensitive data should only be shared voluntarily and at your discretion.

Automated Decision-Making

This website does not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

Minimum Age

This website and its services are intended for individuals aged 16 years or older, in accordance with Article 8 of the GDPR and its implementation under Polish law. If you are under 16, you may not submit personal data through this website without the consent of your parent or legal guardian. The Administrator does not knowingly collect personal data from individuals under 16 years of age without such consent.

Your Rights

Under GDPR, you have the following rights:

  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to withdraw consent at any time
  • Right to lodge a complaint with the President of the Personal Data Protection Office (UODO) in Poland
  • Right to object to the processing of your personal data for direct marketing purposes at any time (Article 21(2) GDPR) — this is an absolute right that requires no justification

Contact

To exercise your rights or for any privacy-related questions, contact: [email protected]

Changes to This Policy

This Privacy Policy may be updated to reflect legal, technical, or business changes. The current version will always be available on this page with the updated date.