# Get the privacy policy

`GET https://app.pozyskajpacjenta.pl/api/v1/privacy` · operationId `getPrivacy` · since 1.7.0 · tag Content

The clinic's privacy policy and the information clause for its forms: the same text the clinic's site shows at /polityka-prywatnosci and under its forms. Render your policy page at `path` from `sections`, show `clause` (no required consent) and the optional `marketingText` box under every form, and send `privacyNoticeVersion` = `version` (and `marketingConsent` when the box was ticked) with the submission. Responses are private to the key: `Cache-Control: private, max-age=60`, so cache them on your side for up to a minute.

## Request

Authorization: `Bearer <the clinic's key>`.

### cURL

```bash
curl "https://app.pozyskajpacjenta.pl/api/v1/privacy" \
  -H "Authorization: Bearer $PP_API_KEY"
```

### TypeScript

```ts
import { PozyskajPacjentaClient } from "@pozyskajpacjenta/sdk";

const client = new PozyskajPacjentaClient({
  apiKey: process.env.PP_API_KEY ?? "",
  baseUrl: "https://app.pozyskajpacjenta.pl",
});

const { privacy } = await client.getPrivacy();
```

### PHP

```php
<?php
$response = wp_remote_get(
    'https://app.pozyskajpacjenta.pl/api/v1/privacy',
    array(
        'headers' => array( 'Authorization' => 'Bearer ' . getenv( 'PP_API_KEY' ) ),
        'timeout' => 10,
    )
);
if ( is_wp_error( $response ) ) {
    error_log( $response->get_error_message() );
    return;
}
$status = wp_remote_retrieve_response_code( $response );
$data   = json_decode( wp_remote_retrieve_body( $response ), true );
```

## Response

### 200: The policy.

- `privacy` (`PrivacyPolicy`, required): The policy, the clause and its version.
  - `version` (`string`, required): Template date plus a digest of the text; it changes with every word of the policy and the clause.
  - `path` (`string`, required): Path of the policy page on the clinic's site (the clause and the footer link to it).
  - `title` (`string`, required): Title of the policy page.
  - `lead` (`string`, required): Sentence under the title.
  - `clause` (`object`, required): The clause under a form: `text`, then the link `linkLabel` to `href`.
    - `text` (`string`, required): Text of the clause.
    - `linkLabel` (`string`, required): Text of the link to the policy.
    - `href` (`string`, required): Target of the link to the policy.
  - `marketingText` (`string`, required): Label of the optional marketing box, unticked by default.
  - `sections` (`object[]`, required): Sections of the policy. `body` is plain text: a blank line starts a paragraph, lines starting with "- " form a list.
    - `id` (`string`, required): Stable id of the section, usable as an anchor.
    - `heading` (`string`, required): Heading of the section.
    - `body` (`string`, required): Text of the section.
  - `missing` (`string[]`, required): Profile fields the policy needs that the clinic has not filled in yet (the policy is served anyway). One of `legalName`, `address`, `nip`, `rpwdl`, `contactEmail`.

Example (Policy, clause and version (sections trimmed to two)):

```json
{
  "privacy": {
    "version": "2026-09-30.f0683640",
    "path": "/polityka-prywatnosci",
    "title": "Polityka prywatności",
    "lead": "Jak Klinika Wzorcowa przetwarza dane osobowe osób, które kontaktują się z nami przez tę stronę i umawiają wizyty.",
    "clause": {
      "text": "Administratorem Twoich danych osobowych jest Klinika Wzorcowa sp. z o.o., ul. Przykładowa 12, 00-950 Warszawa. Dane z formularza przetwarzamy, aby odpowiedzieć na zapytanie oraz umówić i obsłużyć wizytę, w tym wysłać potwierdzenie i przypomnienie (art. 6 ust. 1 lit. b i art. 9 ust. 2 lit. h RODO). Kontakt w sprawie danych: recepcja@klinika-wzorcowa.example. Masz prawo dostępu do danych, ich sprostowania, usunięcia i ograniczenia przetwarzania, prawo sprzeciwu oraz skargi do Prezesa UODO. Szczegóły:",
      "linkLabel": "polityka prywatności",
      "href": "/polityka-prywatnosci"
    },
    "marketingText": "Zgoda marketingowa (Klinika Wzorcowa): chcę otrzymywać SMS-em lub e-mailem przypomnienia o wizytach kontrolnych, prośby o opinię i informacje o ofercie. Zgoda jest dobrowolna i mogę ją w każdej chwili wycofać.",
    "sections": [
      {
        "id": "administrator",
        "heading": "1. Administrator danych",
        "body": "Administratorem Twoich danych osobowych jest Klinika Wzorcowa sp. z o.o., ul. Przykładowa 12, 00-950 Warszawa.\n\nW sprawach dotyczących Twoich danych osobowych skontaktujesz się z nami:\n- e-mailem: recepcja@klinika-wzorcowa.example\n- telefonicznie: +48 22 100 20 30\n- listownie: Klinika Wzorcowa sp. z o.o., ul. Przykładowa 12, 00-950 Warszawa"
      },
      {
        "id": "iod",
        "heading": "2. Inspektor ochrony danych",
        "body": "Nie wyznaczyliśmy inspektora ochrony danych. We wszystkich sprawach dotyczących Twoich danych napisz lub zadzwoń do nas, dane kontaktowe są w pkt 1."
      }
    ],
    "missing": [
      "nip",
      "rpwdl"
    ]
  }
}
```

## Errors

| Status | code | When |
| --- | --- | --- |
| 401 |  | No Authorization header |
| 401 |  | Unknown or rotated key |
| 404 |  | The clinic's site is not published |
| 429 |  | Over 120 requests in this minute |

401 (No Authorization header):

```json
{
  "error": "missing Authorization: Bearer <klucz z panelu Ustawienia>"
}
```

401 (Unknown or rotated key):

```json
{
  "error": "invalid key"
}
```

404 (The clinic's site is not published):

```json
{
  "error": "site not published"
}
```

429 (Over 120 requests in this minute):

```json
{
  "error": "przekroczono limit 120 zapytań/min"
}
```

## Rate limit

- 120 requests per minute per key, shared by every endpoint.

## SDK method

`client.getPrivacy(): Promise<PrivacyInfo>`
