Privacy Policy

PRIVACY POLICY AND PERSONAL DATA PROCESSING POLICY

Effective as of: 01 November 2021

1. GENERAL PROVISIONS

1.1. This Privacy Policy and Personal Data Processing Policy (hereinafter — the “Policy”) defines the procedure for the collection, receipt, storage, use, transfer, protection, updating and deletion of personal data processed by Individual Entrepreneur Karmanov Anton Volodymyrovych, registration number 3656506857 (hereinafter — “LMD Systems”, the “Company” or “we”).

1.2. This Policy applies to personal data that the Company receives or processes in connection with:

  • visiting and using the Company's websites;
  • registration and use of user accounts;
  • placing and fulfilling orders;
  • entering into and performing agreements;
  • providing goods, works, services and digital services;
  • using the control panel, personal account and other information systems of the Company;
  • making payments and conducting settlements;
  • contacting customer support;
  • identification or verification procedures;
  • use of domain, hosting, technical and other related services;
  • communication with the Company by email, messengers, telephone or other communication channels.

1.3. This Policy applies to website visitors, users, customers, subscribers, clients, their representatives, employees and other individuals whose personal data is lawfully obtained by the Company.

1.4. For the purposes of Ukrainian legislation, the Company is the personal data controller to the extent that the Company determines the purpose and composition of the processing of the relevant personal data, unless otherwise expressly provided by an agreement or applicable law.

1.5. Where the General Data Protection Regulation of the European Union 2016/679 (GDPR) applies to the relevant processing, the Company acts as a controller or processor of personal data, depending on the nature of the particular processing activity.

1.6. This Policy forms an integral part of the terms of use of the Company's websites, agreements, public offer and other Company documents, unless otherwise expressly provided by the relevant document.

1.7. By using the website, registering an account, placing an order, entering into an agreement or otherwise lawfully providing personal data to the Company, an individual confirms that they have read this Policy to the extent that such acknowledgement is required by applicable law.

2. PURPOSES AND LEGAL BASES FOR PROCESSING PERSONAL DATA

2.1. The Company processes personal data exclusively for specific, defined and lawful purposes and to the extent necessary to achieve the relevant purpose.

2.2. Personal data may be processed for, among other things, the following purposes:

  • creating, registering and administering a user account;
  • identifying and authenticating a user;
  • entering into, performing, amending and terminating agreements;
  • accepting, processing and fulfilling orders;
  • providing, extending, modifying, suspending and terminating services;
  • providing technical and informational support;
  • communicating with the user;
  • preparing invoices, statements and other primary and settlement documents;
  • processing payments and maintaining accounting, tax and financial records;
  • administering domain names;
  • registering, renewing, transferring and servicing domain names;
  • ensuring the operation of websites, information systems, control panels and other Company services;
  • ensuring information and cybersecurity;
  • detecting, preventing and investigating fraud, abuse, attacks, unauthorized access and other violations;
  • preventing violations of agreements and service rules;
  • diagnosing technical problems and resolving failures;
  • maintaining internal records and administering the Company's activities;
  • protecting the rights, property, information systems and legitimate interests of the Company, users and other persons;
  • complying with legal requirements;
  • complying with court decisions, requests and lawful demands of competent authorities;
  • asserting, substantiating and defending legal claims;
  • conducting audits, analysis and improving the operation of services;
  • generating statistics and analytics;
  • sending informational communications relating to ordered or used services;
  • sending advertising and marketing communications where and to the extent permitted by law;
  • performing other purposes expressly provided for by an agreement or law, or necessary for the proper provision of the relevant services.

2.3. The legal bases for processing personal data may include:

  • entering into and performing an agreement with an individual;
  • taking steps at the individual's request prior to entering into an agreement;
  • compliance with a legal obligation;
  • protection of the rights and legitimate interests of the Company or third parties;
  • consent of the data subject where obtaining such consent is required;
  • another legal basis expressly provided for by Ukrainian law or applicable legislation.

2.4. Not every processing operation involving personal data requires the user's separate consent. Where applicable law permits the relevant processing on another legal basis, the Company may carry out such processing without obtaining separate consent.

2.5. Where processing is based on consent, the data subject has the right to withdraw such consent in the cases and manner provided by applicable law.

2.6. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal and does not terminate processing carried out on another lawful basis.

2.7. Withdrawal of consent does not require the Company to delete personal data where continued storage or processing is necessary for performance of an agreement, compliance with legal requirements, protection of the Company's rights and legitimate interests, or protection of the rights and legitimate interests of other persons.

3. PERSONAL DATA THAT MAY BE PROCESSED

3.1. The categories of personal data depend on the nature of an individual's interaction with the Company, the particular service, the method of obtaining such service and applicable legal requirements.

3.2. The Company may process, among other things:

  • surname, first name and patronymic;
  • name of a legal entity or individual entrepreneur;
  • position and information regarding representation of a legal entity;
  • email address;
  • telephone number;
  • postal address;
  • payment and settlement information;
  • tax and accounting details;
  • account information;
  • login credentials, identifiers and other data necessary for authentication;
  • information about orders, agreements and services received;
  • payment information and settlement status;
  • data necessary for registration and maintenance of domain names;
  • documents and information necessary for identification or verification;
  • information voluntarily provided by an individual when contacting customer support;
  • correspondence and support requests;
  • information regarding service settings and usage;
  • IP address and other network identifiers;
  • technical information about the device, browser and operating system;
  • information about sessions, errors and interaction with services;
  • other data necessary for the relevant service or required by law.

3.3. The Company may request additional documents or information where objectively necessary for:

  • identification of an individual;
  • confirmation of a representative's authority;
  • performance of an agreement;
  • provision of the relevant service;
  • registration or maintenance of a domain name;
  • ensuring security;
  • preventing fraud;
  • complying with legal requirements;
  • protecting the Company's rights and legitimate interests.

3.4. If an individual refuses to provide data necessary for entering into or performing an agreement and performance of the agreement is impossible without such data, the Company may refuse to enter into the agreement, suspend the relevant service or terminate it in accordance with the agreement and applicable law.

4. SOURCES OF PERSONAL DATA

4.1. The Company may obtain personal data:

  • directly from the data subject;
  • from their legal or authorized representative;
  • during website registration;
  • when placing an order;
  • during the conclusion or performance of an agreement;
  • when making payments;
  • when contacting customer support;
  • automatically when using the website and information systems;
  • from providers of payment, technical, informational and other services;
  • from the Company's partners;
  • from registrars, registry operators and other participants in the domain infrastructure;
  • from publicly available sources where permitted by law;
  • from government authorities, courts and other persons in the cases and manner prescribed by law.

4.2. Where personal data is obtained from a third party, the Company may process such data in accordance with the specified purpose, agreement, applicable law or another appropriate legal basis.

5. COOKIES AND SIMILAR TECHNOLOGIES

5.1. The Company's websites and services may use cookies, local storage, session storage, pixels, event logs, web beacons and other similar technologies.

5.2. Such technologies may be used for:

  • ensuring the operation of the website;
  • authentication and maintaining user sessions;
  • storing user preferences;
  • storing the selected language;
  • ensuring security;
  • preventing fraud and abuse;
  • analyzing website usage;
  • diagnosing technical errors;
  • improving service functionality;
  • generating statistics;
  • personalizing content;
  • conducting and evaluating the effectiveness of advertising campaigns, where permitted by law.

5.3. Some cookies may be technically necessary for the operation of the website. Refusal to use certain categories of cookies may result in limited or unavailable functionality.

5.4. The Company may use services provided by third-party analytics, advertising, technical and other service providers. In such cases, the relevant providers may process technical information in accordance with their service terms and applicable law.

6. TECHNICAL INFORMATION AND EVENT LOGS

6.1. When using the website, control panel and other Company services, information systems may automatically collect and store technical information.

6.2. Such information may include:

  • IP address;
  • date and time of the request;
  • address of the requested page or resource;
  • address of the page from which the user arrived;
  • browser type and version;
  • device type;
  • operating system;
  • browser language;
  • session identifiers;
  • device identifiers;
  • error information;
  • results of requests;
  • technical logs;
  • other technical information necessary for the operation and protection of the services.

6.3. Technical information may be used for:

  • operation and administration of services;
  • authentication;
  • information security;
  • detecting and preventing attacks;
  • detecting fraud;
  • investigating incidents;
  • diagnosing failures;
  • monitoring system stability;
  • protecting the Company's rights and legitimate interests;
  • generating statistics.

7. DATA RECEIVED FROM PARTNERS AND THIRD PARTIES

7.1. If a user receives the Company's services through a partner, reseller or other third-party service, the Company may receive from such partner the data necessary to process and fulfill the order.

7.2. Such data may include:

  • first and last name;
  • contact details;
  • order information;
  • payment information;
  • order status;
  • information about the relevant service;
  • other data necessary to fulfill the order.

7.3. A partner transferring personal data to the Company is responsible for having an appropriate legal basis for such transfer, unless otherwise provided by applicable law or an agreement between the parties.

7.4. The Company may rely on information received from partners where there are no reasonable grounds to believe that such information was obtained or transferred in violation of applicable law.

8. ACCESS TO AND TRANSFER OF PERSONAL DATA

8.1. The Company does not sell users' personal data.

8.2. The Company may provide access to or transfer personal data to third parties where there is an appropriate legal basis and only to the extent necessary for the relevant purpose.

8.3. Recipients of personal data may include:

  • employees and authorized representatives of the Company;
  • contractors;
  • hosting and infrastructure service providers;
  • software providers;
  • technical and information service providers;
  • payment systems;
  • banks and financial institutions;
  • telecommunications operators;
  • email service providers;
  • analytics service providers;
  • information security service providers;
  • auditors and consultants;
  • lawyers and other professional advisers;
  • domain name registrars;
  • domain registry operators and administrators;
  • other persons whose involvement is necessary for the provision of services or conduct of the Company's activities.

8.4. Such persons receive only the amount of personal data necessary to perform the relevant task, unless otherwise provided by law.

8.5. The Company may engage third parties to process personal data on its behalf where necessary for the provision of services or conduct of business activities.

8.6. In cases provided for by an agreement or applicable law, relevant service providers may act as separate data controllers and independently determine the purposes and means of their own processing.

9. TRANSFER OF DATA FOR DOMAIN NAMES

9.1. For registration, renewal, transfer, administration and other servicing of domain names, the Company may transfer necessary registration data to:

  • registrars;
  • resellers;
  • registry operators;
  • administrators of domain zones;
  • ICANN and its related authorized entities;
  • approved escrow agents;
  • providers of domain name dispute resolution services;
  • other persons where such transfer is required by the rules of the relevant domain zone, an agreement or applicable law.

9.2. The categories of data transferred are determined by the rules of the relevant domain zone and the requirements of the registrar, registry operator, ICANN and applicable law.

9.3. Registration data may be made available or published through WHOIS, RDAP or other registration data services where required by the rules of the relevant domain zone and applicable law.

9.4. Where the rules of the relevant domain zone provide for the possibility of concealing or restricting public access to registration data, the Company applies the relevant mechanism within the technical and organizational capabilities available to it.

9.5. The Company is not responsible for the subsequent use of personal data by an independent registrar, registry operator, domain zone administrator or other independent recipient of the data where such recipient acts as a separate data controller.

10. TRANSFER OF DATA TO GOVERNMENT AUTHORITIES AND OTHER PERSONS

10.1. The Company may disclose personal data to courts, law enforcement agencies, government authorities, local self-government bodies and other authorized persons where there is a legal basis for such disclosure under applicable law.

10.2. Data may be transferred, in particular, on the basis of:

  • a court decision;
  • a lawful request from an authorized government authority;
  • another document provided for by law;
  • a direct legal obligation imposed on the Company.

10.3. The Company may assess the validity of a received request and, where permitted by law, require clarification, confirmation of authority or confirmation of the legal basis for the request.

10.4. Receipt of a lawyer's request does not in itself constitute grounds for automatic disclosure of personal data.

10.5. In response to a lawyer's request, the Company provides information only to the extent and in the cases in which disclosure is permitted by applicable law or another appropriate legal basis exists.

11. SECURITY OF PERSONAL DATA

11.1. The Company takes appropriate organizational and technical measures to protect personal data against:

  • unlawful or accidental destruction;
  • loss;
  • alteration;
  • damage;
  • unauthorized access;
  • unlawful disclosure;
  • unlawful use;
  • other forms of unlawful processing.

11.2. Security measures may include:

  • access controls;
  • segregation of access rights;
  • authentication;
  • encryption where appropriate;
  • backups;
  • information system monitoring;
  • event logging;
  • antivirus and other technical protection;
  • physical protection of equipment;
  • internal security procedures;
  • restriction of access by employees and contractors;
  • other technical and organizational measures.

11.3. At the same time, no system for transmitting or storing information over the Internet can guarantee absolute security.

11.4. The Company is not responsible for security breaches resulting from circumstances beyond its reasonable control, including:

  • actions of the user;
  • disclosure of passwords or codes by the user to third parties;
  • use of a compromised device by the user;
  • malware on the user's device;
  • attacks on third-party service providers;
  • failures of telecommunications networks;
  • cyberattacks whose consequences could not reasonably have been anticipated or prevented;
  • other circumstances beyond the Company's control.

12. CROSS-BORDER TRANSFER AND PROCESSING OF DATA

12.1. Depending on the infrastructure, service providers used and nature of the services, personal data may be stored or processed on servers located in Ukraine or other countries.

12.2. Personal data may be transferred outside Ukraine where necessary for:

  • provision of services;
  • use of cloud or server infrastructure;
  • operation of third-party software services;
  • payment processing;
  • registration and administration of domains;
  • technical support;
  • information security;
  • performance of an agreement;
  • compliance with legal requirements;
  • other lawful purposes defined by this Policy.

12.3. Where GDPR or other legislation governing cross-border transfers of personal data applies, the Company takes the measures required by the relevant legislation to ensure the lawfulness of such transfer.

13. PROCESSING OF DATA FOR THE PROTECTION OF RIGHTS AND SECURITY

13.1. The Company may process and, where there is an appropriate legal basis, transfer personal data where objectively necessary to:

  • prevent fraud;
  • detect unlawful activities;
  • stop abuse;
  • investigate incidents;
  • protect information systems;
  • protect property;
  • protect life and health;
  • protect the rights and legitimate interests of the Company;
  • protect the rights of users or third parties;
  • assert, substantiate or defend legal claims.

13.2. In such cases, the Company may retain the relevant data for the period necessary to achieve the stated purpose, including for the duration of a dispute, review, investigation or court proceedings.

14. USE OF DATA FOR COMMUNICATIONS AND MARKETING

14.1. The Company may use contact details to send communications necessary for the performance of an agreement or operation of the services.

14.2. Such communications may include:

  • registration confirmations;
  • order notifications;
  • payment notifications;
  • notifications regarding renewal or termination of services;
  • technical maintenance notifications;
  • security notifications;
  • account-related notifications;
  • other communications without which the proper provision of services may be impossible.

14.3. The Company may also conduct advertising and marketing communications in the cases and manner permitted by applicable law.

14.4. The user may opt out of receiving advertising communications using the method provided for this purpose. Such opt-out does not terminate the sending of communications necessary for performance of an agreement, security or operation of the services.

15. RETENTION PERIODS FOR PERSONAL DATA

15.1. The Company retains personal data for no longer than necessary to achieve the purpose of processing, unless a different period is established by law, an agreement or another appropriate legal basis.

15.2. Depending on the category of data, personal data may be retained:

  • for the duration of an agreement;
  • for the period during which the relevant service is used;
  • for the period necessary to comply with accounting, tax and other legal requirements;
  • for the period necessary to protect the Company's rights and legitimate interests;
  • for the applicable limitation period and/or another period necessary to assert, substantiate or defend legal claims;
  • for the period provided for by the rules of the relevant domain zone;
  • for the period necessary to ensure information security;
  • for another period expressly provided by applicable law.

15.3. Upon expiry of the relevant retention period, personal data may be deleted, destroyed or anonymized.

15.4. Certain data may temporarily remain in backups, archives, security logs or other technical systems until the relevant backup or deletion cycle is completed, where such retention is necessary for technical, security or legal reasons.

15.5. Data necessary to fulfill legal obligations or protect the Company's rights shall not be deleted solely on the basis of a user's request where such deletion would conflict with the relevant obligation or legitimate interest.

16. RIGHTS OF THE DATA SUBJECT

16.1. A data subject has the rights provided by Ukrainian law and, where applicable, by the GDPR or other applicable legislation.

16.2. In particular, an individual may have the right to:

  • know the sources from which their personal data was collected;
  • know the location and purpose of processing of their personal data;
  • receive information about the conditions of access to their personal data;
  • obtain access to their personal data;
  • request correction of inaccurate or outdated data;
  • request updating of personal data;
  • request deletion of data in cases provided by law;
  • object to certain types of processing in cases provided by law;
  • request restriction of processing in cases provided by law;
  • withdraw consent where processing is based on consent;
  • lodge complaints with a competent state authority;
  • exercise other rights provided by applicable law.

16.3. The exercise of the right to deletion, restriction or cessation of processing is not absolute and may be restricted where the Company has a legal obligation or another appropriate legal basis to continue processing.

16.4. In particular, the Company may refuse to delete or cease processing where retention of the data is necessary for:

  • performance of an agreement;
  • compliance with legal requirements;
  • accounting or tax purposes;
  • compliance with domain name requirements;
  • information security;
  • establishment, exercise or defense of legal claims;
  • protection of the rights and legitimate interests of the Company or third parties.

17. PROCEDURE FOR REQUESTS REGARDING PERSONAL DATA

17.1. To exercise their rights, a data subject may contact the Company using the contact details specified in this Policy or on the Company's website.

Contact for personal data matters:

Email: [●]

Postal address: [●]

17.2. A request must contain sufficient information to identify the applicant and determine the nature of their request.

17.3. To protect personal data, the Company may request the applicant to verify their identity or authority where failure to do so could create a risk of unlawful disclosure of personal data.

17.4. If a request is submitted by a representative, the Company may require a document confirming the representative's authority where necessary under applicable law.

17.5. The Company processes requests and provides responses within the time limits and in the manner prescribed by applicable law.

17.6. If the Company cannot satisfy a request in whole or in part, it may inform the applicant of the relevant legal or factual grounds for refusal.

18. ACCURACY OF PERSONAL DATA

18.1. The user is required to provide accurate information and, where such information changes, to update it in a timely manner where possible.

18.2. The Company is not required to continuously verify the accuracy of personal data provided by the user unless otherwise required by law or by the nature of the relevant service.

18.3. If the provision of inaccurate, incomplete or outdated information makes it impossible to properly provide services, identify the individual, process a payment or comply with legal requirements, the Company may request clarification or confirmation of the relevant data.

18.4. If the required information is not provided, the Company may temporarily restrict, suspend or terminate the relevant service where necessary to comply with applicable law, ensure security or perform an agreement.

19. DATA OF MINORS

19.1. The Company's services are not intended for persons who are not legally entitled to independently enter into the relevant agreements under applicable law, unless otherwise expressly provided by the terms of a particular service.

19.2. If the Company becomes aware that personal data of an individual was provided in violation of applicable legal requirements, the Company may take measures to cease the relevant processing or delete such data, unless otherwise required by law.

20. PROCESSING OF OTHER PERSONS' DATA BY THE USER

20.1. If a user provides the Company with personal data of another person, the user warrants that they have the appropriate authority or other legal basis for such transfer where such basis is required by law.

20.2. The user is responsible for the lawfulness of transferring personal data of third parties to the Company where the user is the person making such transfer.

20.3. The Company may rely on representations and information provided by the user unless otherwise required by law or the Company is aware that such information is inaccurate.

21. INTERACTION WITH THIRD-PARTY SERVICES

21.1. The Company's website and services may contain links to or integrations with third-party websites, applications, payment systems, social networks, analytics services and other resources.

21.2. Third-party services may process personal data in accordance with their own privacy policies.

21.3. The Company does not control the privacy policies of independent third parties and is not responsible for the processing of personal data by such parties where they act as independent data controllers.

21.4. Users are advised to review the privacy policies of the relevant third-party services before using them.

22. CHANGE OF PURPOSE OF PROCESSING

22.1. The Company does not use personal data for purposes incompatible with the purposes for which such data was collected, except where such processing is permitted by law or another appropriate legal basis exists.

22.2. If the Company intends to carry out processing that materially differs from the original purpose and requires an additional legal basis, the Company may notify the user and/or obtain the necessary consent where such consent is required by applicable law.

23. LIABILITY

23.1. The Company is responsible for the processing of personal data within the scope of its authority and in accordance with applicable law.

23.2. The Company is not responsible for:

  • personal data voluntarily made publicly available by the user;
  • actions of third parties that obtained data independently of the Company and act as independent data controllers;
  • consequences of the user providing inaccurate or third-party data;
  • compromise of account credentials caused by the user;
  • use of insecure passwords by the user;
  • consequences of the user disclosing passwords, verification codes or other access credentials to third parties;
  • security breaches of third-party services not controlled by the Company;
  • force majeure or other circumstances objectively beyond the Company's reasonable control.

23.3. Nothing in this Policy shall be construed as exempting the Company from obligations or liability from which it cannot be exempted under mandatory provisions of applicable law.

24. APPLICABLE LAW

24.1. This Policy is governed by the laws of Ukraine unless otherwise provided by applicable law.

24.2. The processing of personal data is carried out taking into account, in particular, the requirements of Ukrainian legislation concerning personal data protection, electronic commerce, electronic communications, civil and commercial legislation, as well as other regulatory legal acts applicable to the relevant activities.

24.3. Where GDPR or other foreign data protection legislation applies to particular processing activities, such processing shall also be carried out taking into account the requirements of such legislation.

25. CHANGES TO THIS POLICY

25.1. The Company may periodically amend and update this Policy.

25.2. A new version of the Policy becomes effective upon publication on the Company's website unless otherwise specified in the new version.

25.3. If changes materially affect the rights of individuals or the manner in which personal data is processed and applicable law requires separate notification or consent, the Company shall take such actions in accordance with the procedure prescribed by law.

25.4. Users are advised to periodically review the current version of this Policy.