Hello from Poland
Privacy policy
Last updated: 31 July 2026
Current status. Hello from Poland is presently an informational website. Volunteer registration, telephone routing, recordings, and the mobile-app API are not active. The sections marked “when launched” describe the planned service and apply only once that service is made available.
1. Controller and contact
The controller of personal data described in this policy is:
Baghdad Telecom – Omar Alshaker
ul. Szkolna 78/2
05-270 Marki, Poland
NIP: 7010644234 · REGON: 366150049
The business details above are taken from the public CEIDG register entry. For privacy requests, write to the Controller at the address above. A dedicated electronic privacy contact will be added before volunteer registration opens.
2. Website visitors
- Data
- Technical access-log data, which may include IP address, requested URL, date and time, response status, and user-agent information.
- Purpose and legal basis
- Operating, securing, and diagnosing the website, based on the Controller’s legitimate interests (Article 6(1)(f) GDPR).
- Retention
- Nginx access and error logs are rotated daily and retained for up to 14 days, unless a longer period is necessary to investigate a security incident or meet a legal obligation.
The website does not currently use advertising trackers, analytics, account creation, contact forms, or non-essential cookies.
3. Volunteer registration — when launched
To register as a volunteer, the app will ask for a Polish phone number and use Twilio Verify to send an SMS code. The registration service is designed to store an HMAC-protected identifier derived from that number, phone-verification and English-check timestamps, account timestamps, and short-lived session/challenge identifiers. It does not store the raw phone number in its SQLite database, English-check audio, or English-check transcripts.
The purposes are to operate the requested volunteer-registration flow, verify control of the supplied number, protect the service from misuse, and determine whether the basic spoken-English check was completed. The intended legal bases are steps taken at the volunteer’s request and performance of the volunteer-service arrangement (Article 6(1)(b) GDPR), together with the Controller’s legitimate interests in security and abuse prevention (Article 6(1)(f) GDPR).
The app uses the device’s speech-recognition services to produce text from the volunteer’s spoken responses. The project backend receives the resulting text only to assess the check and does not retain it. Apple or Android speech services may process voice data under their own terms and device settings.
4. Calls and safety recordings — when launched
If the calling service launches with recording enabled, callers and volunteers will receive a clear notice before a recording starts. The current proposed retention period is 90 days from the call date for safety, moderation, and incident investigation. The final live notice will identify the recording provider, legal basis, access controls, any legal-hold exception, and the exact deletion process before recordings begin.
Do not rely on the planned service description as confirmation that calls are currently recorded or connected: neither is active today.
5. Recipients and international transfers
Website hosting and security operations use Hetzner Online GmbH. When volunteer registration is enabled, the relevant phone number and SMS-verification event will be processed by Twilio Verify. Twilio may process personal data in countries outside the European Economic Area; before activation, the Controller will ensure the applicable contractual and transfer safeguards are in place and keep the processor record current. Platform speech services are provided by Apple or the applicable Android-device service.
6. Retention and deletion
- Short-lived registration sessions expire after 30 minutes, and English-check challenges expire after 10 minutes.
- An active volunteer registration record is retained while the volunteer account remains active. The app will provide a profile page to view the registration-service record, log out, and request deletion.
- Deleting an account removes the active registration record and its related registration sessions and English-check challenges. It does not by itself remove data held by a future call-recording system, a telecommunications provider, security logs, or backup copies.
- Before backups or a recording service are enabled, the Controller will publish their retention periods and ensure that restoration procedures do not silently restore a deleted active account.
7. Your rights
Subject to the GDPR and applicable law, you may request access, rectification, erasure, restriction, objection, and portability; you may also withdraw consent where processing relies on consent. Send a request to the Controller at the postal address in section 1. You may lodge a complaint with the President of the Personal Data Protection Office in Poland (UODO).
8. Changes
This policy will be updated before the app, telephone service, SMS verification, or recording is made public, and whenever the actual data flow or retention rules change materially.
Back to the project