Personal Data Processing and Protection Policy

for Databases Owned by the Seller

1. General Provisions and Scope

1.1. Definitions:

  • Personal Data Database: A named collection of organized personal data in electronic and/or paper filing systems.

  • Controller (Owner): A person or entity authorized to process personal data, determining the purpose and composition of the data. (In this context, the Seller).

  • Processor: A person or entity authorized by the Controller to process data on their behalf.

  • Data Subject: An identified or identifiable individual whose data is being processed.

  • Personal Data: Any information relating to an identified or identifiable individual.

  • Processing: Any operation performed on personal data (collection, storage, adaptation, use, disclosure, destruction).

  • Consent: A voluntary, documented expression of will by an individual to allow the processing of their data for a specific purpose.

  • Sensitive Data: Data concerning racial or ethnic origin, political or religious beliefs, health, or sex life.

1.2. This Policy is mandatory for the Responsible Person and employees of the Seller who process or have access to personal data.

2. List of Personal Data Databases

2.1. The Seller is the owner of the "Counterparties" personal data database.

3. Purpose of Processing

3.1. The purpose is to ensure the implementation of civil law relations, provision of goods/services, and settlements in accordance with the Tax Code of Ukraine and accounting laws.

4. Processing Procedure and Consent

4.1. Consent must be voluntary. 4.2. Forms of Consent:

  • A paper document with identifying details.

  • An electronic document (preferably with an electronic signature).

  • A checkbox on an electronic page or file within the information system. 4.3. Consent is obtained during the establishment of civil-legal relations. 4.4. The processing of Sensitive Data (race, health, politics, etc.) is strictly prohibited.

5. Location of the Database

5.1. Databases are located at the Seller's registered business address.

6. Disclosure to Third Parties

6.1. Access by third parties is determined by the subject's consent or by law. 6.2. Access is denied if the third party cannot guarantee data protection. 6.3. Request Procedure: Third parties must submit a written request identifying themselves, the subject, and the legal grounds for the request. 6.4. Timelines:

  • 10 working days to review the request.

  • 30 calendar days to fulfill the request.

  • Maximum extension: 45 calendar days.

7. Data Protection and Retention

7.1. The Seller uses software and technical security measures to prevent loss, theft, or unauthorized access. 7.2. Responsible Person: Appointed by the Seller to organize data protection. 7.3. Employee Obligations: Staff must maintain strict confidentiality even after their employment or contract ends. 7.4. Retention: Data is stored no longer than necessary for the stated purpose or as defined by the subject's consent.

8. Rights of the Data Subject

Every individual has the right to:

  1. Know the location and purpose of the database.

  2. Access their data and know who it is shared with.

  3. Receive a response regarding their data status within 30 days.

  4. Object to data processing.

  5. Request the correction or destruction of inaccurate or illegally processed data.

  6. Be protected against accidental loss or illegal processing.

  7. Seek legal recourse or appeal to state authorities for rights violations.

9. Handling Subject Requests

9.1. Subjects may access their own data free of charge and without stating a reason. 9.2. Requests are reviewed within 10 working days and fulfilled within 30 calendar days.