Get the privacy policy
GET/api/v1/privacy
- Since
- 1.7.0
- Auth
- Bearer key
- operationId
- getPrivacy
The clinic's privacy policy and the information clause for its forms: the same text the clinic's site shows at /polityka-prywatnosci and under its forms. Render your policy page at path from sections, show clause (no required consent) and the optional marketingText box under every form, and send privacyNoticeVersion = version (and marketingConsent when the box was ticked) with the submission. Responses are private to the key: Cache-Control: private, max-age=60, so cache them on your side for up to a minute.
Request
Send the clinic's key in Authorization: Bearer (see API keys).
No parameters and no body.
curl "https://app.pozyskajpacjenta.pl/api/v1/privacy" \
-H "Authorization: Bearer $PP_API_KEY"import { PozyskajPacjentaClient } from "@pozyskajpacjenta/sdk";
const client = new PozyskajPacjentaClient({
apiKey: process.env.PP_API_KEY ?? "",
baseUrl: "https://app.pozyskajpacjenta.pl",
});
const { privacy } = await client.getPrivacy();<?php
$response = wp_remote_get(
'https://app.pozyskajpacjenta.pl/api/v1/privacy',
array(
'headers' => array( 'Authorization' => 'Bearer ' . getenv( 'PP_API_KEY' ) ),
'timeout' => 10,
)
);
if ( is_wp_error( $response ) ) {
error_log( $response->get_error_message() );
return;
}
$status = wp_remote_retrieve_response_code( $response );
$data = json_decode( wp_remote_retrieve_body( $response ), true );Response
200The policy.
- privacyPrivacyPolicyrequired
The policy, the clause and its version.
Fields (8)
- versionstringrequired
Template date plus a digest of the text; it changes with every word of the policy and the clause.
- pathstringrequired
Path of the policy page on the clinic's site (the clause and the footer link to it).
- titlestringrequired
Title of the policy page.
- leadstringrequired
Sentence under the title.
- clauseobjectrequired
The clause under a form:
text, then the linklinkLabeltohref.Fields (3)
- textstringrequired
Text of the clause.
- linkLabelstringrequired
Text of the link to the policy.
- hrefstringrequired
Target of the link to the policy.
- marketingTextstringrequired
Label of the optional marketing box, unticked by default.
- sectionsobject[]required
Sections of the policy.
bodyis plain text: a blank line starts a paragraph, lines starting with "- " form a list.Fields of each item (3)
- idstringrequired
Stable id of the section, usable as an anchor.
- headingstringrequired
Heading of the section.
- bodystringrequired
Text of the section.
- missingstring[]required
Profile fields the policy needs that the clinic has not filled in yet (the policy is served anyway).
One of
legalNameaddressniprpwdlcontactEmail
Policy, clause and version (sections trimmed to two)
{
"privacy": {
"version": "2026-09-30.f0683640",
"path": "/polityka-prywatnosci",
"title": "Polityka prywatności",
"lead": "Jak Klinika Wzorcowa przetwarza dane osobowe osób, które kontaktują się z nami przez tę stronę i umawiają wizyty.",
"clause": {
"text": "Administratorem Twoich danych osobowych jest Klinika Wzorcowa sp. z o.o., ul. Przykładowa 12, 00-950 Warszawa. Dane z formularza przetwarzamy, aby odpowiedzieć na zapytanie oraz umówić i obsłużyć wizytę, w tym wysłać potwierdzenie i przypomnienie (art. 6 ust. 1 lit. b i art. 9 ust. 2 lit. h RODO). Kontakt w sprawie danych: recepcja@klinika-wzorcowa.example. Masz prawo dostępu do danych, ich sprostowania, usunięcia i ograniczenia przetwarzania, prawo sprzeciwu oraz skargi do Prezesa UODO. Szczegóły:",
"linkLabel": "polityka prywatności",
"href": "/polityka-prywatnosci"
},
"marketingText": "Zgoda marketingowa (Klinika Wzorcowa): chcę otrzymywać SMS-em lub e-mailem przypomnienia o wizytach kontrolnych, prośby o opinię i informacje o ofercie. Zgoda jest dobrowolna i mogę ją w każdej chwili wycofać.",
"sections": [
{
"id": "administrator",
"heading": "1. Administrator danych",
"body": "Administratorem Twoich danych osobowych jest Klinika Wzorcowa sp. z o.o., ul. Przykładowa 12, 00-950 Warszawa.\n\nW sprawach dotyczących Twoich danych osobowych skontaktujesz się z nami:\n- e-mailem: recepcja@klinika-wzorcowa.example\n- telefonicznie: +48 22 100 20 30\n- listownie: Klinika Wzorcowa sp. z o.o., ul. Przykładowa 12, 00-950 Warszawa"
},
{
"id": "iod",
"heading": "2. Inspektor ochrony danych",
"body": "Nie wyznaczyliśmy inspektora ochrony danych. We wszystkich sprawach dotyczących Twoich danych napisz lub zadzwoń do nas, dane kontaktowe są w pkt 1."
}
],
"missing": [
"nip",
"rpwdl"
]
}
}Errors
| Status | When |
|---|---|
| 401 | No Authorization header |
| 401 | Unknown or rotated key |
| 404 | The clinic's site is not published |
| 429 | Over 120 requests in this minute |
Branch on the status and code, never on the Polish error text. All statuses in Errors.
{
"error": "missing Authorization: Bearer <klucz z panelu Ustawienia>"
}{
"error": "invalid key"
}{
"error": "site not published"
}{
"error": "przekroczono limit 120 zapytań/min"
}Rate limit
- 120 requests per minute per key, shared by every endpoint.
- Every response to a valid key carries
RateLimit-RemainingandRateLimit-Reset; see Rate limits.
SDK method
client.getPrivacy(): Promise<PrivacyInfo>
The TypeScript tab above uses it. Install and errors: TypeScript SDK.