🔒 RODO / GDPR
Privacy Policy
Last updated: 13 September 2026
DATA MINIMISATION PRINCIPLE
We collect only what is necessary for the portal to work. You enter the diary, action plan and reminder data yourself and remain in full control of it: you can export it, share it with selected people or permanently delete it at any time. We do not store photos or recordings, we do not profile users and we do not sell data.
§ 1. Personal data controller
The controller of your personal data is:
Fundacja NeuroDzieci (NeuroDzieci Foundation)
ul. Rembrandta 4a/39, 03-531 Warsaw, Poland
KRS (National Court Register): 0001221845 | NIP (Tax ID): 5243063842 | REGON: 543959788
E-mail: kontakt@neurodzieci.pl or kontakt@neurogpt.pl
The NeuroGPT Portal (autyzm.neurogpt.pl) is an educational service operated by the NeuroDzieci Foundation. The Portal is of an exclusively educational and informational nature — it does not provide medical services or medical advice. One account works on both of the Foundation's portals (neurogpt.pl and autyzm.neurogpt.pl), which share a common account database.
The controller has not appointed a data protection officer. In all matters concerning personal data, contact the Foundation directly at kontakt@neurodzieci.pl.
§ 2. What data we process and for what purpose
Categories of data:
- Account data: first name, surname (optional), e-mail address, password (only as a one-way cryptographic hash), role (parent / teacher / specialist), optionally the institution name or PWZ number, country (for the emergency number), preferences.
- Conversations with the AI assistant: the content of questions and answers saved in the account; with your consent (profile setting) a summary of the child context from the action plan, reminders and diary is attached to the conversation.
- Observation Diary, action plan and reminders (health data — Article 9 GDPR): episode records (date, duration, symptoms, triggers, notes), a description of episode video recordings (file name, length, time markers and a link to the file on your Google Drive — the video itself never reaches our servers: it stays on your device or on your own Drive), the child's action plan (first name, year of birth, diagnosis as stated by the carer, signs, rescue medication, emergency contacts), medication and reminder times, medication stock, appointment dates and questions for the doctor. This data is entered by the parent or legal guardian.
- Sharing: e-mail addresses of the people with whom you share the diary or plan, and tokens of links and QR codes generated at your request.
- Google integration (optional): the Google account identifier and an encrypted access token for the calendar and — if you send recordings to Drive — for the files the portal creates on your Google Drive; only after you connect the account.
- Notifications: the push subscription address of your browser or app.
- Assistant query counter: the number of queries made by the account on a given day (the count only, without content). It serves to enforce the free plan limit and to detect accounts used by several people at once (§ 7(3) of the Terms of Service).
- School licence (if applicable): the institution name, e-mail addresses of invited teachers, invitation and QR-code tokens, and the seat log — who invited, accepted or removed whom and when, and to whom administration was transferred.
- Payments: Stripe customer and subscription identifiers — the Foundation does not store card numbers.
- Contact and partner forms: the content of the request and contact details.
- Technical data: IP address, browser type, server logs (security), cookies and local storage — see the Cookie Policy.
Purposes and legal bases:
- Provision of the portal services (account, assistant, diary, reminders, sharing) — Article 6(1)(b) GDPR
- Processing of health data entered into the diary, action plan, reminders and chat — your explicit consent, Article 9(2)(a) GDPR (given when creating the account and enabling these features; you may withdraw it by deleting the data or the account)
- Processing of subscription payments — Article 6(1)(b) GDPR
- Statistics and marketing — only with consent to cookies, Article 6(1)(a) GDPR
- Compliance with legal obligations (accounting, responses to requests from authorities) — Article 6(1)(c) GDPR
- Security of the portal, prevention of abuse, pursuit of claims — legitimate interest, Article 6(1)(f) GDPR
We do not make decisions based solely on automated processing that would produce legal effects, and we do not profile users. AI assistant responses are generated automatically and are educational in nature.
Providing data is voluntary. A first name, an e-mail address and a password are necessary to create an account — without them we cannot provide services that require an account. The remaining data (surname, role, diary, action plan, reminders, country) is provided at your discretion; its absence only limits the operation of the given feature.
Data of the people with whom you share the diary or the action plan (carer, school): you are the source of this data. The invited person receives an invitation e-mail, may decline it, and you may revoke the share at any time; we delete the invitation data after it is revoked or expires.
§ 3. Children's data and health data
The Portal is intended for adult carers, teachers and specialists and for persons aged 16 or over. A child's data (diary, action plan, medication) is entered by their parent or legal guardian, who is responsible for its scope. You enter only what you consider necessary — the action plan fields are optional.
Health data is not used for any purpose other than the operation of the features for which it was entered; it is not passed to advertisers or used by the Foundation to train AI models.
§ 4. Data retention period
- Account data: until the account is deleted by the user or for 3 years from the last activity (after that time the account may be deleted after prior notification by e-mail)
- Diary, action plan, reminders, chat history: until deleted by the user or until the account is deleted
- Shares: until revoked by the user, until the link expires or until the account is deleted
- Push subscriptions: until you unsubscribe from notifications or until the account is deleted
- Assistant query counter: 90 days, after which the records are deleted automatically
- School licence invitations: the token stops working once accepted, revoked or expired (14 days for e-mail invitations, 24 hours for QR codes); the record is deleted 30 days later
- School licence seat log: 24 months — accountability towards the institution and control of account sharing
- Payment data (invoices, accounting documents): 5 years (Article 74 of the Polish Accounting Act)
- Form submissions: up to 12 months after the matter is closed
- Server logs: up to 30 days; analytics data: up to 14 months
- Cookies and local storage: in accordance with the Cookie Policy
§ 5. Data recipients and transfers outside the EEA
Data may be processed by the following entities (processors or independent controllers):
- Stripe, Inc. (USA/Ireland) — payment processing; participant in the EU-US Data Privacy Framework, standard contractual clauses
- Language model provider (currently DeepSeek) — generation of assistant responses: the conversation content, your first name and — only with your consent — a summary of the child context are transmitted; we do not transmit your e-mail address or account data. The provider is established outside the EEA (China); the transfer takes place with the safeguards of Article 46 GDPR (standard contractual clauses) — you may choose not to use the assistant, and conversations should not contain data identifying third parties
- Cloudflare, Inc. (USA) — hosting, CDN, firewall and the portal database; data stored in the Western Europe region; participant in the EU-US Data Privacy Framework, standard contractual clauses
- Google LLC (USA) — calendar synchronisation and, at your request, saving recordings to your Google Drive (only after connecting the account; your browser sends the file directly to Google) and Google Analytics 4 (only with consent to cookies); participant in the EU-US Data Privacy Framework, standard contractual clauses
- Meta Platforms, Inc. (USA/Ireland) — Meta Pixel (only with consent to marketing cookies; without consent the script is not loaded); participant in the EU-US Data Privacy Framework, standard contractual clauses
- Resend, Inc. (USA) — sending transactional messages: account activation, password reset, medication reminders, diary and school-licence invitations; the recipient e-mail address and the message content are transferred; participant in the EU-US Data Privacy Framework, standard contractual clauses
- Browser push notification services (Google LLC, Apple Inc., Mozilla Corporation — USA) — only the subscription address and the encrypted notification content; transfers outside the EEA are based on the EU-US Data Privacy Framework or standard contractual clauses
- People with whom you yourself share the diary or the action plan
- Public authorities — solely on the basis of legal provisions
§ 6. Your rights (GDPR Articles 15–22)
- Access to data — the right to obtain a copy of your data (JSON export in the profile)
- Rectification — the right to have inaccurate data corrected (editing in the profile)
- Erasure — the right to be forgotten (Article 17 GDPR) — deleting the account in the settings is immediate and irreversible
- Restriction of processing — the right to request that processing be suspended
- Data portability — the right to receive your data in JSON/CSV format
- Objection — the right to object to processing based on legitimate interest
- Withdrawal of consent — at any time (without affecting the lawfulness of processing carried out before the withdrawal); cookie consents can be changed in the footer ("Manage cookies"), consent to the child context in the chat — in the profile
- Complaint to a supervisory authority — Urząd Ochrony Danych Osobowych (Polish Personal Data Protection Office), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. If you live in another country of the European Economic Area, you may also lodge a complaint with the supervisory authority of your country of residence or place of work (Article 77 GDPR)
To exercise your rights, write to: kontakt@neurodzieci.pl. We respond within 30 days.
§ 7. Data security
We apply the following technical and organisational measures:
- Encryption in transit (TLS/HTTPS, HSTS) and security headers (CSP)
- Passwords are never stored: your browser derives a key from the password with PBKDF2-SHA256 (600,000 iterations) and the server keeps only a salted SHA-256 hash of that key (accounts moved from the previous version of the portal switch to this format at their first login); one-time tokens for activation, password reset and sharing
- Sessions in HttpOnly cookies with the Secure and SameSite flags; CSRF protection
- Google tokens encrypted with AES-256-GCM in the database
- Rate limiting on API endpoints, separation of data between accounts and shares
- No storage of media files; regular backups and security testing
§ 8. Cookies and local storage
Detailed information about cookies, browser local storage and consents can be found in the Cookie Policy.
§ 9. Changes to the Privacy Policy
The Policy is reviewed periodically (changes in law, new portal features, UODO guidance). The current version is always published at this address, and registered users are informed of material changes by e-mail.
§ 10. Contact
For matters concerning the protection of personal data, contact us at:
📧 kontakt@neurodzieci.pl
📍 Fundacja NeuroDzieci, ul. Rembrandta 4a/39, 03-531 Warsaw, Poland
© 2026 Fundacja NeuroDzieci. All rights reserved.
Terms of Service · Cookie Policy · Accessibility statement · Home