← Back to home

Privacy Policy

Last updated: June 3, 2026

1. General Information

This Privacy Policy outlines how your personal data is handled when you use the dcmage website (dcmage.com) and applications.

The controller of your personal data is Michal Sadurski, contactable via email at [email protected].

2. On-Device Processing (Zero PHI Collection)

dcmage is built as a local-first application. All core features (including DICOM tag editing, de-identification, HIPAA PS3.15 profile application, facial defacing, and 3D MPR rendering) run 100% on-device within your browser sandbox or local Tauri desktop installation.

No medical imaging files, metadata, or Protected Health Information (PHI) are ever uploaded, transmitted, or made accessible to our servers or any third parties.

3. Data Collection and Purposes

We do not collect personal tracking cookies or run invasive third-party analytics. The only data processed is:

  • Contact requests: If you send us an email at [email protected], we process your email address and any content provided to answer your inquiry based on our legitimate interest (Art. 6(1)(f) GDPR).
  • Server logs: When browsing our website, our hosting provider may collect standard server request logs (IP address, user agent). This is necessary for infrastructure security and maintenance (Art. 6(1)(f) GDPR).

4. Your Rights under GDPR

Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure / "right to be forgotten" (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to lodge a complaint with a supervisory authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych - UODO, ul. Stawki 2, 00-193 Warszawa).

5. Cookies and Local Storage

This website does not write non-essential tracking cookies or analytical storage keys to your browser. You can configure your browser to reject all cookies if desired.