Privacy Policy
Effective date: 14 September 2025
1) Who we are (Controller)
Martin Mička (“we”, “us”).
Contact: hey@martinmicka.me
We have not appointed a Data Protection Officer.
2) What we collect
- Account & access: your email address to create an account and send a magic-link for sign-in.
- Preferences: whether you wish to receive optional newsletter/updates.
- Technical logs: minimal data such as IP address, user-agent, timestamps to keep the service secure.
- Cookies on the site: only a strictly necessary first-party session cookie set by Ghost CMS to keep you logged in. No analytics or advertising cookies on the website.
3) Why we use your data (legal bases)
- Provide the service (account & login): create your account and send magic links. Legal basis: contract (GDPR Art. 6(1)(b)).
- Newsletter / updates (optional): only if you opt in; you can change this anytime in your profile or via unsubscribe in every email. Legal basis: consent (Art. 6(1)(a)).
- Security & service integrity: protect accounts, detect abuse, keep the service reliable. Legal basis: legitimate interests (Art. 6(1)(f)).
- Legal compliance: keep limited records where required. Legal basis: legal obligation (Art. 6(1)(c)).
4) Email analytics (opens & clicks)
If you subscribe to emails, our messages include open and click tracking (a tiny image “pixel” and link redirects) so we can understand deliverability and engagement. This may capture event metadata (e.g., time, user-agent, approximate location derived from IP).
You can withdraw consent at any time by unsubscribing, or email us at hey@martinmicka.me if you prefer to receive no-tracking emails (we can disable tracking for your address).
5) Where we process & store data
- Hosting: EU (Frankfurt, Germany) on DigitalOcean.
- Email delivery & analytics: Mailgun in the EU region.We configure providers to use the EU/EEA. If exceptional support access or sub-processing outside the EEA is necessary, it is covered by EU Standard Contractual Clauses or equivalent safeguards.
6) Retention
- Your account & content in Ghost: Ghost stores member records and content in our self-hosted database. We keep account data while your account exists and delete it when you delete your account or request deletion. Export and deletion are performed using Ghost’s built-in tools/API.
- Email analytics events (Mailgun): detailed event data (opens/clicks/deliveries) are kept by Mailgun for a limited time according to their retention schedule for the EU region.
- Backups: infrastructure backups/snapshots are retained by DigitalOcean according to their backup/snapshot schedules.If you need specifics, contact us and we’ll provide the current provider-level retention details for your data.
7) Sharing & processors
We don’t sell personal data. We only share it with necessary service providers acting as processors, bound by data-processing terms:
- Hosting: DigitalOcean (EU).
- Email delivery & analytics: Mailgun (EU region).We will update this list if we add more processors.
8) Your rights
You can access, rectify, erase, or export your personal data; restrict or object to certain processing; and withdraw consent at any time (this doesn’t affect processing already performed).
To exercise rights, contact hey@martinmicka.me.
You can also lodge a complaint with your local supervisory authority. In the Czech Republic: Úřad pro ochranu osobních údajů (UOOU).
9) Children
This service is not directed to persons under 16. If you believe we collected children’s data, contact us.
10) Changes
We may update this Privacy Policy from time to time. We will post the new version here with a new effective date.
Cookie note (for this site)
We use only a strictly necessary session cookie to keep you logged in. It expires when your browser session ends. We do not use analytics or advertising cookies on the website.