Regulations on the Processing and Protection of Personal Data

(Within the databases owned by the Seller)

This document establishes the procedure for handling client information (data subjects) to ensure their privacy and security in compliance with applicable laws.

1. Terminology and Legal Scope

1.1. Definitions:

  • Personal Data Database — a structured collection of personal information in digital or physical (filing system) form.

  • Responsible Person — an employee appointed by the Owner to oversee data security and compliance during processing.

  • Owner (Controller) — the Seller, who determines the purpose of data collection, the scope of the data, and the processing procedures.

  • Consent of the Data Subject — a voluntary, documented permission (physical or electronic) allowing the processing of personal data for a specific purpose.

  • Data Processing — any operation or set of operations performed on data, including collection, storage, adaptation, use, disclosure, or destruction.

  • Sensitive Categories — information regarding racial/ethnic origin, political or religious beliefs, health, or private life. The Seller does not collect such data.

1.2. These regulations are mandatory for the Responsible Person and all employees of the Seller who process or have access to personal data as part of their duties.


2. Databases and Purpose of Processing

2.1. The Seller is the owner of the Counterparty Personal Data Database.

2.2. Purpose: To facilitate civil-law relationships, process payments for goods and services, and comply with tax and accounting legislation (including the Tax Code and the Law "On Accounting and Financial Reporting").


3. Consent and Notification Procedures

3.1. Consent must be a voluntary expression of will by the individual.

3.2. Forms of Consent:

  • A physical document with identifying details.

  • An electronic document verified by an electronic signature.

  • A checkbox or "click-to-agree" feature on the website's checkout or registration pages.

3.3. Upon data collection, the Seller notifies the subject of their rights, the purpose of the collection, and the parties to whom the data may be transferred (e.g., delivery services).


4. Disclosure to Third Parties

4.1. Access by third parties is governed by the user's consent or specific legal requirements.

4.2. Access is denied if the third party cannot guarantee compliance with data protection laws.

4.3. Data Requests: Requests for access to data are reviewed within 10 working days. A decision to grant or deny access is provided within 30 calendar days (extendable to 45 days in specific cases).

4.4. Any refusal of access must be provided in writing with a stated reason and information on the appeal process.


5. Security Measures and Liability

5.1. The Owner employs systematic software and hardware solutions to prevent data loss, theft, unauthorized destruction, or falsification.

5.2. Responsibilities of the Authorized Person:

  • Ensuring staff compliance with data protection laws.

  • Developing internal access procedures based on professional duties.

  • Reporting any data breaches to the Owner within one business day of discovery.

5.3. Employees are bound by confidentiality agreements that remain in effect even after their employment or involvement with the data ends.

5.4. Retention Period: Data is stored no longer than necessary for the stated purpose, or as defined by the user's consent.


6. Rights of the Data Subject

Every user has the right to:

  • Know the location and purpose of the database containing their information.

  • Access their personal data and receive details regarding its processing.

  • Request the correction or deletion of data if it is inaccurate or processed unlawfully.

  • Object to data processing or withdraw consent at any time.

  • Seek legal protection or lodge a complaint with the relevant state authorities if their rights are violated.


7. Analytics and Technical Data

7.1. To improve user experience, the website may use third-party analytical tools (such as Microsoft Clarity, Hotjar, etc.).

7.2. These tools collect anonymous behavioral data (click maps, session duration, device types). This information does not identify individual users and is used solely for service optimization.


8. Registration

8.1. State registration of personal data databases is conducted in accordance with Article 9 of the Law of Ukraine "On the Protection of Personal Data."