GDPR
Privacy policy
What data we process, why, how long we keep it and what rights you have.
1. Data controller
The controller of personal data processed in connection with the use of the radio.kusy.net service is Rafał Kusy, a natural person not running a registered business in this respect.
Contact on matters relating to personal data protection: radio@kusy.net.
2. Legal bases and principles of processing
Users' personal data are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Polish law.
The sections below describe the categories of data processed in connection with the individual features of the Service, the purposes and legal bases of processing, and the data retention periods.
3. Account data
In connection with creating and maintaining an Account, the following are processed: e-mail address, display name, hashed password, Account creation date, e-mail confirmation date, information on the role in the Service and any Account block, as well as the preferred language of the Service (Polish or English) in which e-mails and notifications are sent.
The legal basis for processing these data is the performance of the contract for the provision of electronic services (Article 6(1)(b) GDPR), concluded by accepting the Terms.
Account data are kept for as long as the Account exists. After an Account is deleted at the User's request, the data are deleted or anonymised, except for data whose retention is necessary to demonstrate the lawfulness of earlier actions (e.g. archived declarations made with Track submissions, described in section 6).
4. Logging in with a Google or Discord account
When logging in or registering with a Google account, the Service receives from Google: a stable account identifier, the e-mail address, information on whether it has been confirmed, and the first and last name or profile name.
When logging in or registering with a Discord account, the Service receives from Discord: the account identifier, the username, the e-mail address and information on whether it has been confirmed.
The Service does not permanently store access tokens for these accounts or any other profile data beyond those listed above. These data are stored in connection with the Account for as long as it exists.
The legal basis for processing is the performance of the contract for the provision of electronic services (Article 6(1)(b) GDPR). Using Google or Discord login involves transferring data to these providers, which are established outside the European Economic Area (United States), on the terms set out in their own privacy policies and the GDPR compliance mechanisms they use.
5. Sessions and authentication cookies
After you log in, the Service stores a session cookie in your browser, valid for 30 days and used solely to keep you logged in.
During login with Google or Discord, the Service stores temporary cookies needed to carry out the login process, valid for 10 minutes and deleted automatically after a single use. One of them remembers the language version of the page from which the login was started, so that you return to the same version after logging in.
The above cookies are necessary for the Service to work and do not require the User's separate consent.
6. Data processed when submitting tracks
When a Track is submitted, the data described in detail in the Track Submission Terms are processed, including the submission data itself and the content of the declarations made (among others, concerning age, rights held, the track not being subject to collective management, and rights to content generated by an AI tool).
The content of the declarations made, together with the exact wording presented to the User at the time of submission, is kept indefinitely as proof of consent and as a basis for settling any liability of the submitter.
In addition, the User's IP address and browser user agent are recorded with the submission and used solely to demonstrate the circumstances of the submission in the event of a dispute about its authenticity. These data are deleted 730 days after the submission, regardless of the continued retention of the declarations themselves.
The legal basis for processing is the performance of the contract (Article 6(1)(b) GDPR) and the Controller's legitimate interest in being able to demonstrate the lawfulness of accepted submissions (Article 6(1)(f) GDPR).
The submitter's data, including e-mail address, display name, IP address and the content of the declarations made, are available only to authorised Service moderators, for the purpose of reviewing the submission.
7. Data processed when voting
Each vote cast is linked to the User's Account and to the Track being rated.
When voting, the IP address and browser user agent are also recorded, as well as, for logged-in Users, their periods of listening to the stream, used solely to detect attempts to artificially inflate voting results (e.g. using multiple Accounts from the same device or connection). These data are deleted after 90 days.
The legal basis for processing the IP address, user agent and listening periods for this purpose is the Controller's legitimate interest in ensuring the integrity of the ranking (Article 6(1)(f) GDPR).
8. Listener and page-view statistics
Apart from the listening periods of logged-in Users described in section 7, the Service collects only the aggregated number of stream listeners at a given moment, together with information on the Track currently being broadcast. These data do not allow individual listeners or their IP addresses to be identified at the Service's application level.
Raw listener-count samples are kept for 90 days, after which they are aggregated into daily statistics (average and peak number of listeners) and deleted in raw form.
Independently of the above, the server handling the audio stream (Icecast) keeps its own technical logs of access to the stream, described in section 15.
The Service also keeps statistics of visits to its web pages: the number of views of individual pages and the approximate number of unique visitors on a given day. These statistics work without cookies and without storing any information on the User's device.
When a page is displayed, the browser sends the address of that page to the Service. On this basis, a one-way hash is calculated from the IP address, the browser user agent and a random key changed daily, which makes it possible to recognise a repeat visit from the same device only within a single day. The IP address and user agent themselves are not stored for this purpose.
The daily key and the calculated hashes are deleted promptly at the end of the given day – from then on, the statistics can no longer be linked to any device or person. Only the aggregated numbers of views and visitors for individual days and pages, which do not constitute personal data, are kept permanently.
Visit statistics are not combined with the User's Account or used for profiling, and no external analytics provider is used to keep them. Visits in which the browser sends a Do Not Track (DNT) or Global Privacy Control (GPC) signal are not included in the statistics – enabling either of these settings in your browser is a simple way to object to this processing.
The legal basis for the short-term processing of the IP address and user agent for the purpose of visit statistics is the Controller's legitimate interest in understanding interest in the various parts of the Service and developing it (Article 6(1)(f) GDPR).
9. Infringement reports and appeals
In connection with reporting an infringement or appealing against a decision to take a Track off air, the data provided by the reporting person and the content of the report are processed, as well as the reporting person's IP address and user agent, used to prevent abuse of this feature. The language version of the Service from which the report was sent is also recorded, so that the reply on the outcome is sent in the same language.
The IP address and user agent associated with an infringement report or appeal are deleted after 90 days.
Only the Operator and authorised Service moderators have access to the content of infringement reports.
10. Bug reports and suggestions
Using the "Report a bug" form, anyone, including people without an Account, can report a bug in the Service or suggest a change. The following are then processed: the content of the report (title, description, expected behaviour), the address of the page from which it was sent, technical information about the browser (user agent) and screen size, and, for a logged-in User, the link between the report and the Account. The language version of the Service from which the report was sent is also recorded, so that any notice of the report being closed is sent in the same language. The reporting person's IP address is not stored with the report.
Providing an e-mail address is optional. It is used solely to inform the reporting person once that the report has been closed.
The legal basis for processing is the Controller's legitimate interest in keeping the Service working properly and handling reports (Article 6(1)(f) GDPR).
The content of the report together with the technical information – without the e-mail address and without the reporting person's Account data – is transferred to the issue-tracking system run on GitHub (GitHub, Inc., United States), acting as a processor, on the terms of the data processing agreement offered by GitHub and the mechanisms ensuring GDPR compliance of transfers outside the European Economic Area. For this reason, please do not include personal data in the content of a report.
The reporting person's e-mail address and the link between the report and the Account are deleted 30 days after the report is closed, or immediately if the Account is deleted. The content of the report, stripped of these data, is kept as technical documentation of the Service.
11. E-mail correspondence and notifications
The Service informs Users about events relating to their Account and submissions by e-mail, through notifications displayed in the Service after logging in and – if the User enables them on a given device – through browser push notifications.
Regardless of notification settings, e-mails necessary for the Account to work or of a legal nature are always sent: registration confirmation, password reset messages, notice of a Track being taken off air with a link to appeal, confirmation of receipt of an infringement report or appeal and notice of its outcome, as well as notices of significant changes to this Privacy Policy or the Terms.
Information on the course of moderation – in particular on a Track submission being accepted for moderation, its approval or rejection, decisions on proposed changes to a Track, its cover and an artist profile, and the result of profile ownership verification – is sent to the User in the form chosen in the Account settings: by e-mail, in the Service, or both. At least one of these forms always remains enabled, so that the User can always learn the outcome. By default, this information is sent by e-mail and displayed in the Service, except for information on a decision concerning a Track's cover, which by default is displayed only in the Service.
Informational messages, such as information on Tracks' achievements, their place in the chart or news about the Service, are sent by e-mail only after the User has given consent in the Account settings. Consent can be withdrawn at any time in the same place, without affecting the lawfulness of messages sent before its withdrawal.
The legal basis for processing data in connection with messages and notifications is the performance of the contract for the provision of electronic services (Article 6(1)(b) GDPR) and, for informational messages sent by e-mail, the User's consent (Article 6(1)(a) GDPR).
Notifications displayed in the Service are stored in connection with the Account for 180 days from their creation. Notification settings are stored for as long as the Account exists.
The content of sent e-mails is kept in an internal sending log for 90 days from the date of its final outcome (delivery or failure to send).
E-mails are sent through an external e-mail service provider (OVH), acting as a processor on behalf of the Controller.
Push notifications are enabled on a chosen device after granting permission in the browser prompt. The Service then stores the subscription address provided by the browser, pointing to the server of the browser vendor's notification service, and the keys used to encrypt notifications. These data are stored until notifications are disabled on the device, the notification service reports that the subscription has expired, or the Account is deleted.
Push notifications are delivered through the notification service of the vendor of the browser used by the User (e.g. Google for Chrome, Mozilla for Firefox, Apple for Safari, Microsoft for Edge). The content of a notification is encrypted in a way that prevents that vendor from reading it, but the vendor processes the subscription address and technical delivery data on the terms set out in its own privacy policy. These vendors may be established outside the European Economic Area (in particular in the United States).
12. Cookies
The Service uses only cookies necessary for it to work: the login session cookie and the temporary cookies of the Google or Discord login process, described in section 5, as well as the cookie remembering the chosen language version of the Service, described below.
After you switch to the English version of the Service (addresses starting with /en), the Service stores in your browser the rk-lang cookie, containing only the code of the chosen language ("en" or, after returning to the Polish version, "pl"). This cookie is used to display the Service's messages in the chosen language, contains no User or device identifier, and is valid for 1 year. People using only the Polish version of the Service do not receive this cookie.
The Service does not use analytics, statistics or advertising cookies, or cookies used to track the User across websites. The page-view statistics described in section 8 work without cookies.
Given the necessary nature of the cookies used, storing them does not require the User's separate consent under Article 399(3)(2) of the Polish Electronic Communications Law Act of 12 July 2024.
13. Data stored locally in the browser
The Service stores in the browser's local storage (localStorage) the visual theme chosen by the User and the most recently set player volume.
These data are stored only locally on the User's device, are not sent to the Controller and are not linked to the Account.
14. Data recipients and processors
Users' personal data are accessible to: the Operator and the Service moderators authorised by the Operator, to the extent necessary for moderation and handling reports.
Data may also be transferred to the following entities acting as service providers to the Controller: the SMTP e-mail service provider (OVH), login service providers (Google, Discord) to the extent necessary for authentication, the provider of the server hosting (VPS) on which the Service runs, and, for Users who have enabled push notifications, the browser notification service providers (Google, Mozilla, Apple, Microsoft) to the extent described in section 11, and the issue-tracking system provider (GitHub) with respect to the content of bug reports and suggestions, as described in section 10.
Data backups are currently stored locally on the Service's server. In the future, these backups may additionally be stored on the Controller's private home server – in that case the data remain under the Controller's exclusive control and no new external processor is involved.
The Controller does not transfer Users' personal data to third parties for marketing purposes and does not sell personal data.
15. Technical server logs
Independently of the data described above, the Service's technical infrastructure generates standard technical logs:
Service application logs, kept for 14 days;
logs of the server handling the website (access to the Service's pages, containing the IP address, user agent, requested URL and response code), kept for 14 days;
logs of the server handling the audio stream (access to the stream, containing the client's IP address and user agent), kept for up to about 7 weeks.
These logs are used solely for diagnostic purposes and to ensure the security of the Service, on the basis of the Controller's legitimate interest (Article 6(1)(f) GDPR).
16. Summary of data retention periods
Account data: until the Account is deleted.
Login session: 30 days from the last login or until logging out.
Cookie remembering the chosen language version of the Service (rk-lang): 1 year from the last change of language.
Content of declarations made with a Track submission: indefinitely, as proof of consent.
IP address and user agent associated with a Track submission: 730 days.
IP address and user agent associated with voting: 90 days.
Stream listening periods linked to an Account: 90 days.
IP address and user agent associated with an infringement report or appeal: 90 days.
Content of sent e-mails: 90 days from the final outcome of sending.
Notifications displayed in the Service: 180 days from their creation.
Push notification subscription: until notifications are disabled on the device, the subscription expires, or the Account is deleted.
Application logs: 14 days.
Website server logs: 14 days.
Audio stream server logs: about 7 weeks.
Raw listener-count samples: 90 days, then only in aggregated form (daily statistics).
Daily key and hashes used in page-view statistics: until the end of the given day, after which they are promptly deleted.
Aggregated page-view statistics: indefinitely (they do not constitute personal data).
E-mail address provided in a bug report and the link between the report and the Account: 30 days from the report being closed, or immediately if the Account is deleted. Content of the report stripped of these data: as technical documentation of the Service.
17. User rights
Users have the right to access their personal data, to rectification, erasure, restriction of processing, data portability, and to object to processing based on the Controller's legitimate interest.
The right to erasure is limited to the extent that retaining the data (in particular the content of declarations made with Track submissions) is necessary for the Controller to demonstrate lawfulness and to defend against possible claims.
Users have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) if they consider that the processing of their data infringes the GDPR.
To exercise the above rights, please contact the Controller at radio@kusy.net.
18. No verification of Users' age
The Service does not verify the User's age when an Account is registered or when voting. The only moment at which the User makes a declaration concerning age is when submitting a Track, in accordance with the Track Submission Terms.
Use of the Service requires being at least 18 years old or acting with the consent of a legal guardian.
19. Planned changes to data processing
If voluntary payments or donations to the Service (e.g. via Patronite or a similar platform), or advertisements broadcast on the stream or displayed on the Service's pages, are introduced in the future, this Privacy Policy will be updated before the feature is launched, indicating any new categories of data processed and any new processors.
20. Changes to the Privacy Policy
The Controller reserves the right to amend this Privacy Policy, in particular in connection with changes to the Service's functionality or changes in the law.
Registered Users will be informed of significant changes to the Privacy Policy by e-mail or by a message in the Service, with adequate notice before the changes take effect.
The current version of the Privacy Policy is always available at /polityka-prywatnosci (English translation: /en/polityka-prywatnosci).
The Privacy Policy may also be made available in an English translation, for information purposes only. In the event of any discrepancy between the versions, the Polish version of the Privacy Policy is binding.
21. Contact
Any questions about this Privacy Policy and the processing of personal data in the Service should be sent to: radio@kusy.net.
Version: 2026-10-03.v1 · published 03/10/2026
