Prijeđi na glavni sadržaj
REDCAT WEB

Prilagođene web-stranice za tvrtke – na pravim tehnologijama.

© 2026 RedCat Web · Red Cat Labs d.o.o. · OIB 00036628211. Sva prava pridržana.

Legal document

Privacy policy.

The procedure for the collection, processing, storage and protection of the personal data of visitors to the redcatweb.com website.

Effective from 25.02.2026 Version 1.0
Contents

1. General provisions

This Privacy Policy (hereinafter – the Policy) defines the procedure for the collection, processing, storage and protection of the personal data of persons who visit the redcatweb.com website (hereinafter – the Site) and/or use its functional capabilities (hereinafter – the User).

By using the Site, the User confirms that they have read this Policy and give their consent to the processing of their personal data in accordance with the terms set out below. If the User does not agree with the terms of this Policy, they must cease using the Site.

The processing of personal data is carried out in accordance with the Law of Ukraine “On the Protection of Personal Data” of 01.06.2010 No. 2297-VI, the Law of Ukraine “On Electronic Commerce” of 03.09.2015 No. 675-VIII, and also, insofar as it concerns interaction with residents of the European Union, in accordance with Regulation (EU) 2016/679 (GDPR).

Definitions. In this Policy, “personal data” means any information relating to an identified or identifiable natural person. “Processing” covers any operation performed on personal data, including collection, recording, storage, use, transfer and deletion.

2. Personal data controller

Controller: Sole Proprietor Nadaraia Kostiantyn Yemzariiovych
Individual Tax Number (IPN): 3683303471
Bank details: IBAN UA973220010000026000370038796, JSC “Universal Bank”, MFO 322001
E-mail: info@redcatweb.com
Website: redcatweb.com
Partner company: Red Cat Labs d.o.o. (Croatia, OIB 00036628211)

The Controller is the sole person responsible for making decisions regarding the purposes and means of processing the personal data collected through the Site.

Structure of service provision. Sole Proprietor Nadaraia K.Ye. provides services to clients who are residents of Ukraine on the basis of an agreement with the company Red Cat Labs d.o.o. (Croatia) and is the controller of their personal data. For clients from the European Union and other countries, the personal data controller is Red Cat Labs d.o.o.; the relevant terms are set out in the English-language version of this Policy.

No charge for requests. Users’ requests concerning the exercise of the rights provided for in this Policy are accepted and handled free of charge.

3. What personal data we collect

The scope of the data depends on the manner in which the User interacts with the Site. The Controller collects only such data as are necessary to achieve the defined purposes of processing (the data minimisation principle).

3.1. Data provided voluntarily by the User

When filling out forms on the Site (brief, cost calculator and other feedback forms), the User may provide:

  • surname, first name;
  • telephone number;
  • e-mail address;
  • company and/or website name;
  • information about the project (type of site, budget, desired functionality);
  • other data that the User specifies in free form.

User responsibility. The User is solely responsible for the accuracy, completeness and currency of the personal data they provide. The Controller does not verify the accuracy of the data provided and bears no responsibility for the consequences of the User providing inaccurate, incomplete or outdated information. If the User provides the personal data of third parties, they warrant that they have obtained the consent of those parties to do so.

3.2. Data collected automatically

When visiting the Site, the following are collected automatically:

  • IP address;
  • browser type and version, operating system, screen resolution;
  • date, time and duration of the visit;
  • the pages the User viewed and the sequence of transitions;
  • the referral source (referrer) and advertising campaign tags (UTM, gclid);
  • geolocation at country/city level (based on the IP address);
  • data on interaction with elements of the Site (clicks, scrolling, cursor movement) – via the Hotjar service.

3.3. Data we do NOT collect

The Controller knowingly does not collect or process: payment card data (processed exclusively by the payment provider), biometric data, health data, racial or ethnic origin, political opinions, religious beliefs or other special categories of personal data within the meaning of Article 9 of the GDPR.

4. Purposes of processing personal data

Personal data are processed solely for the following purposes:

  1. processing the User’s requests and communicating regarding a potential or ongoing project;
  2. preparing commercial offers and cost estimates;
  3. performing contractual obligations;
  4. analysing traffic and user behaviour on the Site with a view to improving its functionality and usability;
  5. ensuring the technical operability and security of the Site;
  6. preventing fraud, abuse and unauthorised access;
  7. complying with the requirements of applicable law.

Limitations. The Controller does not use personal data for automated decision-making or profiling that produces legal effects for the User. The Controller does not send advertising materials without the separate and explicit consent of the User.

5. Legal basis for processing

The processing of personal data is carried out on the basis of:

  • the User’s consent – when filling out forms on the Site and when giving consent to the use of analytics cookies (Article 6(1)(a) GDPR; Article 11 of the Law “On the Protection of Personal Data”);
  • performance of a contract or taking steps at the User’s request prior to entering into a contract (Article 6(1)(b) GDPR);
  • the legitimate interest of the Controller – to ensure the security of the Site, prevent fraud and improve the quality of services (Article 6(1)(f) GDPR);
  • compliance with a legal obligation – retention of data necessary to comply with tax, accounting and other legislation (Article 6(1)(c) GDPR).

Legitimate interest assessment. The Controller has carried out a Legitimate Interest Assessment and has established that: (a) the Controller’s interest in ensuring the operability, security and improvement of the Site is justified and proportionate; (b) the processing is necessary to achieve the stated purposes and cannot reasonably be replaced by less intrusive means; (c) the rights and freedoms of Users do not override the Controller’s legitimate interest, given the minimal volume of data processed and its predominantly anonymised nature. The User may obtain a copy of the assessment by contacting the Controller at info@redcatweb.com.

6. Cookies

The Site uses cookies – small text files that are stored in the User’s browser.

6.1. Necessary (technical) cookies

They ensure the basic functionality of the Site: session cookies, protection against CSRF attacks, remembering cookie consent. They are set without the User’s consent, as they are technically necessary. Validity period: until the session is closed or up to 12 months.

6.2. Analytics cookies

Google Analytics 4 (GA4). Provider: Google LLC (USA). They collect anonymised information about traffic. IP addresses are anonymised by means of GA4. Google Consent Mode v2 is implemented on the Site: analytics cookies and GA4 data collection are activated exclusively after the User’s explicit consent is obtained via the cookie banner. Until consent is given, no analytics data are collected or transmitted to Google’s servers. Data may be transmitted to Google’s servers in the USA on the basis of the EU–US Data Privacy Framework and/or standard contractual clauses (SCC). Cookie validity period: up to 14 months.

Hotjar. Provider: Hotjar Ltd (Malta, EU). It analyses interaction with elements of the Site (heatmaps, session recordings). Hotjar automatically masks text input in form fields and excludes confidential information from session recordings. Users’ IP addresses are anonymised (IP masking). The data are stored on servers in the EU. Cookie validity period: up to 12 months. They are set only after the User’s consent is obtained. The User may additionally opt out of Hotjar data collection at the link hotjar.com/opt-out.

6.3. Cookie management

On the first visit to the Site, the User is shown a banner requesting consent for analytics cookies. The User may: give or decline consent; change the settings at any time via the cookie banner or the browser settings; delete already installed cookies via the browser settings. Disabling analytics cookies does not affect the basic functionality of the Site. The Site respects the browser’s Do Not Track (DNT) signal: if DNT is enabled, analytics cookies are not set.

7. Transfer of data to third parties

The Controller may transfer personal data to third parties solely to the extent necessary to achieve the purposes specified in Section 4:

  • Hosting provider – the servers are located in the European Union. Data from forms are processed on the server and sent to the Controller’s e-mail. The hosting provider has access to the data solely within the scope of providing hosting services and is obliged to comply with confidentiality requirements;
  • Google LLC (Google Analytics) – traffic analytics. Google LLC is a participant in the EU–US Data Privacy Framework. Additionally, the transfer is safeguarded by standard contractual clauses (SCC);
  • Hotjar Ltd (Malta, EU) – behaviour analytics. The data do not leave the EU;
  • JSC “Universal Bank” (monobank) – processing of online payments (once activated). The Controller does not receive, store or process the User’s payment card data. All payment operations are carried out directly on the secure platform of the payment provider.

Limitations on transfer. The Controller does not sell, exchange or transfer personal data for the marketing purposes of third parties. The transfer of data to other third parties is possible only: (a) where there is separate consent of the User; (b) on the basis of a mandatory request from an authorised state body in accordance with applicable law; (c) to protect the legitimate rights and interests of the Controller in judicial or other legal proceedings.

8. International transfer of data

Personal data collected through the Site are processed and stored predominantly on servers within the European Union. In the event of transfer of data outside the EU (in particular, Google Analytics – USA), the Controller ensures the existence of appropriate safeguards for protection:

  • EU–US Data Privacy Framework (DPF) – for the transfer of data to companies participating in the DPF in the USA;
  • standard contractual clauses (SCC) approved by the European Commission – as an additional or alternative mechanism;
  • an adequacy decision on the level of data protection in the recipient country;
  • other mechanisms provided for in Articles 46–49 of the GDPR.

The User may obtain a copy of the relevant safeguards or information about the specific transfer mechanism by contacting the Controller at info@redcatweb.com.

9. Protection of personal data

The Controller takes organisational and technical measures to protect personal data against unauthorised access, alteration, disclosure or destruction:

  • the use of SSL/TLS encryption (HTTPS) for all connections to the Site;
  • restricting access to personal data exclusively to authorised persons of the Controller;
  • regular updating of the code, dependencies and platform;
  • the use of systems to protect against brute-force attacks and unauthorised login;
  • regular data backup;
  • the use of strong passwords and two-factor authentication for administrative access.

Limitation of warranties. Notwithstanding the measures indicated, the Controller cannot guarantee the absolute security of the transfer and storage of data over the Internet, since no protection system is impenetrable. The Controller makes every effort corresponding to the current state of technology and the nature of the data processed to minimise risks.

Incident notification. In the event of a breach of the security of personal data that may result in a high risk to the rights and freedoms of Users, the Controller shall: (a) notify the relevant supervisory authority within 72 hours of detecting the incident (in accordance with Article 33 of the GDPR); (b) notify the affected Users without undue delay (in accordance with Article 34 of the GDPR); (c) document the incident and the response measures taken.

10. Data retention periods

Personal data are stored for the period necessary to achieve the purpose of processing, but no less than the periods established by applicable law:

  • data from forms where a contract has been concluded: for the duration of the contractual relationship and 3 (three) years after its termination (the limitation period under the Civil Code of Ukraine);
  • data from forms where no contract has been concluded: no more than 12 (twelve) months from the moment of the last communication with the User;
  • data related to financial transactions: 7 (seven) years in accordance with the requirements of tax legislation;
  • Google Analytics analytics data: up to 14 months;
  • Hotjar data: up to 12 months;
  • technical server logs: up to 12 months;
  • cookie data: in accordance with the periods specified in Section 6.

After the expiry of the retention period, personal data are deleted or irreversibly anonymised. The User may request the early deletion of data in accordance with Section 11 of this Policy, except in cases where retention is mandatory by law.

11. User rights

In accordance with applicable law, the User has the following rights:

  1. The right of access – to obtain confirmation as to whether their personal data are being processed and to obtain a copy of such data;
  2. The right to rectification – to request the correction of inaccurate personal data or the completion of incomplete personal data;
  3. The right to erasure – to request the deletion of personal data (the “right to be forgotten”) where: the data are no longer necessary for the purposes of processing; the User withdraws consent; the User objects to the processing; the data were processed unlawfully;
  4. The right to restriction of processing – to request the temporary restriction of the processing of data while their accuracy or the lawfulness of the processing is being verified;
  5. The right to data portability – to receive their data in a structured, commonly used, machine-readable format and to transmit them to another controller;
  6. The right to object – to object to the processing of data on the basis of legitimate interest. The Controller shall cease processing unless it demonstrates the existence of compelling legitimate grounds;
  7. The right to withdraw consent – to withdraw previously given consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

Procedure for exercise. To exercise their rights, the User sends a request to info@redcatweb.com with the note “Personal data” in the subject line. The Controller undertakes to: (a) confirm receipt of the request within 3 working days; (b) provide a substantive response within 30 calendar days; (c) in the case of complexity or a large volume of requests, notify of an extension of the period by a further 60 days, stating the reasons. The exercise of rights is carried out free of charge.

Right of refusal. The Controller has the right to refuse to satisfy a request if: (a) it is impossible to identify the User as the data subject; (b) the request is manifestly unfounded or excessive (in particular, on account of systematic repetition); (c) fulfilment of the request would contravene the requirements of applicable law. In the event of a refusal, the Controller shall inform the User of the reasons and of the right to appeal.

The User has the right to lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or with the relevant supervisory authority in the EU Member State of their residence.

12. Links to third-party resources

The Site may contain links to external websites, services or resources that are not controlled or managed by the Controller. The Controller bears no responsibility for the content, privacy policy, data processing practices or security of such third-party resources. Following external links is done by the User at their own risk.

13. Data of minors

The Site and the Controller’s services are not intended for persons under the age of 16. This age threshold is established in accordance with Article 8 of the GDPR and applies to all Users of the Site regardless of their country of residence. The Controller knowingly does not collect or process the personal data of minors. If the Controller becomes aware that data of a person under the age of 16 have been collected without the consent of parents or legal representatives, such data will be deleted immediately. Parents or legal representatives may contact the Controller to have a minor’s data deleted.

14. Changes to the Policy

The Controller reserves the right to make changes to this Policy at any time. The current version is always available on the Site.

The Controller notifies of material changes (an expansion of the scope of data processed, new purposes of processing, new third-party recipients) via a banner on the Site or by e-mail, if the Controller has the User’s e-mail address and the changes concern their data.

Continued use of the Site after the publication of changes is deemed acceptance of the updated Policy. If the changes require the User’s renewed consent, the relevant request will be provided separately.

15. Governing law and dispute resolution

This Policy is governed by and construed in accordance with the legislation of Ukraine. For Users who are residents of the European Union, Regulation (EU) 2016/679 (GDPR) and the relevant national legislation of the EU Member State additionally apply.

All disputes arising in connection with this Policy are resolved through negotiations. If it is impossible to reach agreement, the dispute is referred for consideration by the competent court. For Users who are EU-resident consumers, jurisdiction is determined in accordance with the mandatory rules of Regulation (EU) No 1215/2012 (Brussels I bis), which may provide for the case to be heard by a court at the User’s place of residence. In other cases, jurisdiction is determined by the location of the Controller (Ukraine).

16. Severability of provisions

If any provision of this Policy is held to be invalid, unlawful or unenforceable by a competent court or authorised body, this does not affect the validity and enforceability of the remaining provisions of the Policy. The invalid provision shall be replaced by the closest valid provision in meaning that corresponds to the parties’ original intent.

17. Contact information

For matters relating to the processing of personal data, the User may contact the following e-mail address: info@redcatweb.com.

The Controller accepts requests in Ukrainian and English. All requests concerning the exercise of data subjects’ rights are handled free of charge.

This is a translation of the Ukrainian original, provided for convenience. It may contain inaccuracies; in case of any discrepancy the Ukrainian version prevails.