EasyCAN Forum
Homepage
PL EN
Sign in Register

EasyCAN Forum Privacy Policy

Effective date: 04.09.2026

This document explains which personal data is processed when using the EasyCAN Forum, why it is processed and which rights users have.

1. Data controller and contact

The controller of personal data is Andrzej Michalak EasyCAN, Polish tax ID (NIP) 8262031661, business register number (REGON) 545572898, address: ul. Ekologiczna 8/48, 02-798 Warszawa, Poland.

For privacy matters and requests concerning your rights, contact ebt25@easycan.pl, telephone +48 455 400 025, or use the postal address above.

2. Data we process

  • account data: email address, display name visible to signed-in users, cryptographic password hash, role, account status, authentication generation number, and account creation, verification and last sign-in dates;
  • forum content: topic titles, posts, their association with an author, and publication or modification dates;
  • account-service data: hashes of email-verification and password-reset tokens and their expiry times;
  • data contained in correspondence, complaints, appeals and content notices, including the notifier's contact details and information necessary to review the matter;
  • technical and security data: session identifier, session start and last-activity times, hashes derived from an IP address, account ID or normalised account identity for abuse prevention, and server logs which may include an IP address, requested resource and browser information.

Passwords are never stored in plain text.

3. Purposes and legal bases

  • creating and maintaining an account, authentication and enabling users to publish content — Article 6(1)(b) GDPR;
  • email verification, service messages concerning the account and password resets — Article 6(1)(b) GDPR;
  • moderation, approval of accounts and topics, protecting the forum, preventing spam and abuse, and maintaining security logs — the controller's legitimate interests, Article 6(1)(f) GDPR;
  • handling complaints, appeals and reports of illegal content or breaches of the Terms — Article 6(1)(b), Article 6(1)(c) or Article 6(1)(f) GDPR, depending on the matter;
  • establishing, exercising or defending legal claims and complying with legal obligations — Article 6(1)(f) or Article 6(1)(c) GDPR, as applicable.

Forum users' data is not used for advertising or marketing profiling.

4. Data visible to other users

Display names, topic and post content, and publication dates are available only to administrators and users signed in to an active account. Email addresses are not displayed to other users. A person who can access content may nevertheless retain a copy or share it further outside the forum.

5. Recipients of data

Data may be processed by the forum controller and providers necessary to operate the forum:

  • OVHcloud — website hosting, server logs and email delivery;
  • Neon — PostgreSQL database hosting and its infrastructure providers and subprocessors;
  • competent public authorities where disclosure is required by law.

Content and display names are disclosed to active, signed-in forum users. Topic pages are not made available to people who are not signed in and receive headers preventing caching and indexing, but the controller cannot control copies made or shared further by authorised recipients.

6. Transfers outside the EEA

The forum's primary database uses a European region. However, Neon is established in the United States and may use subprocessors outside the European Economic Area. Where this occurs, transfers rely on an appropriate legal mechanism, such as an adequacy decision or Standard Contractual Clauses. Further information is available in Neon's documentation and Data Processing Agreement.

7. How long data is retained

  • active account data — until the account is deleted, except for data needed to protect legal claims or meet legal obligations; on deletion, the email address and display name are replaced with neutral data, while a limited technical record may remain to preserve links to content and database integrity;
  • unverified pending-account data — for 30 days after registration and then removed by the daily maintenance process; verified pending-account data — until approved or rejected by the administrator or until deletion is requested; the verification link is valid for 24 hours and may be resent after password confirmation;
  • password reset token hash — becomes unusable after one hour and is removed after use, replacement, account deletion, or during technical cleanup of expired data;
  • hashes used for abuse prevention — generally for up to 2 days;
  • hosting-provider technical logs — for the period resulting from the provider's configuration and retention rules, no longer than needed for security and diagnostics;
  • correspondence, complaints, appeals and notices — until the matter is closed and then for the period needed to protect legal claims or comply with legal obligations;
  • posts and topics available to signed-in users — until removed by an administrator. When an account is deleted, its content may remain under the neutral display name “Deleted user” to preserve the continuity of discussions.

8. Your rights

Subject to the conditions in the GDPR, you have the right to access your data and obtain a copy, rectify or erase it, restrict its processing, receive portable data, and object to processing based on legitimate interests. Send requests to ebt25@easycan.pl.

You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO). Current contact details are available at uodo.gov.pl.

9. Whether data is required

Providing an email address, display name and password is voluntary but necessary to create an account. Without an active account, topics and posts cannot be viewed or published. Publishing is voluntary, and the content becomes visible to administrators and active, signed-in users.

10. Cookies and sessions

The forum uses one essential session cookie. It supports authentication, form security, language selection and status messages. It is protected with Secure, HttpOnly and SameSite=Lax settings. An authenticated session expires after 2 hours of inactivity and no later than 12 hours after sign-in; closing the browser will usually remove the cookie sooner. The forum does not use analytics, advertising or tracking cookies, so no consent banner is displayed for its current scope.

11. Automated decisions

Data is not used for automated decision-making that produces legal effects or for profiling.

12. Changes to this policy

This policy may be updated if the forum, its providers or the law changes. The current version will always be available at the same address.

© 2026 Andrzej Michalak EasyCAN · Members-only forum · Business details · Terms of Service · Privacy Policy · Report illegal content