and Personal Data Processing
Effective date: 28 September 2026
This Privacy Policy sets out the procedure for collecting, using, storing, transferring, and protecting personal data when using the website https://mmwebxs.com/, the personal account, project management system, electronic communication channels, and when receiving IT services.
The personal data controller is:
Sole Proprietor Mykhailova Yuliia Ruslanivna, hereinafter referred to as the “Contractor”, “we”, “us”.
A person whose personal data is processed is hereinafter referred to as the “User”, “Customer”, “contact person” or “data subject” depending on the context.
1. Scope of the Policy
1.1.
This Policy applies to personal data that we receive in connection with:
- visiting the website;
- creating and using an account;
- receiving IT services;
- discussing a potential order;
- managing projects and tasks;
- technical support;
- monitoring and administration of systems;
- issuing invoices and carrying out settlements;
- communication via email, Telegram, or other agreed channels;
- use of APIs, integrations, and other information systems.
1.2.
This Policy does not govern the processing of personal data by independent third-party services, websites, or platforms, whose rules are determined by their own privacy policies.
2. Personal Data We May Process
2.1. Identification and Contact Data
We may process:
- first name;
- last name;
- patronymic;
- company name or sole proprietor name;
- position or role;
- phone number;
- email address;
- Telegram username;
- Telegram ID or another identifier in a messenger;
- other contact details provided by the person.
2.2. Account Data
The following may be processed:
- account identifier;
- association with a particular Customer;
- role;
- access rights;
- list of accessible projects;
- login history;
- information about activity in the personal account.
Passwords, if used by the system, must be stored in a protected form and are not used by the Contractor to determine the original password value.
2.3. Project and Communication Data
We may store:
- messages;
- task descriptions;
- technical requirements;
- comments;
- approvals;
- files and materials;
- change history;
- information about completed work;
- work time records;
- test results;
- technical support history;
- other information provided by a person in connection with the performance of an order.
2.4. Payment and Contractual Information
We may process:
- information about issued invoices;
- payment amount and currency;
- payment status;
- payment date;
- payment purpose;
- information required for accounting and tax records;
- settlement history.
We do not receive or store full payment card details. If payment is made through a bank or payment provider, such data is processed by the relevant payment service provider.
2.5. Technical Data
When using the website or information systems, the following may be processed automatically:
- IP address;
- date and time of the request;
- browser type;
- device type;
- operating system;
- URL of the requested page;
- referrer;
- technical logs;
- error data;
- authentication events;
- other technical data necessary for the operation and security of the system.
2.6. Data Required for Technical Maintenance
As part of technical work, the Customer may provide the Contractor with:
- login credentials;
- tokens;
- API keys;
- configuration files;
- server logs;
- database dumps;
- backups;
- other technical materials.
Such data is used only within the scope of the relevant order or technical maintenance.
3. Sources of Personal Data
3.1.
We may receive personal data:
- directly from the data subject;
- from the Customer who has designated the relevant person as their contact person;
- through the personal account;
- via email;
- via Telegram or other means of communication;
- through forms on the website;
- automatically when using the website or an information system;
- through integrated services and APIs;
- from other lawful sources where necessary to provide services.
3.2.
If the Customer provides us with personal data of its employees, representatives, or other persons, the Customer must have a lawful basis for such transfer.
4. Purposes of Personal Data Processing
Personal data may be processed for the purposes of:
- responding to inquiries;
- discussing a potential order;
- estimating and approving work;
- entering into and performing contracts;
- creating and administering accounts;
- identifying Customers and contact persons;
- managing access to projects;
- managing projects and tasks;
- technical support;
- administering and monitoring information systems;
- diagnosing technical issues;
- issuing invoices and monitoring payments;
- accounting and tax records;
- ensuring information security;
- detecting and preventing abuse or unauthorized access;
- maintaining event logs;
- protecting the rights and legitimate interests of the Contractor or third parties;
- complying with legal requirements;
- analyzing and improving the website and services;
- other purposes of which the data subject will be duly informed.
5. Legal Bases for Processing
5.1.
Depending on the specific situation, processing may be carried out on the basis of:
- the data subject’s consent;
- the need to take steps at the person’s request prior to entering into a contract;
- the need to enter into and perform a contract;
- compliance with the Contractor’s obligations established by law;
- the protection of the legitimate interests of the Contractor or a third party, provided that the rights and freedoms of the data subject do not override those interests;
- other grounds provided for by law.
5.2.
If certain processing is carried out exclusively on the basis of consent, the data subject may withdraw such consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal and does not stop processing where another lawful basis for it exists.
6. Data of the Customer’s Contact Persons
6.1.
The Customer may designate authorized contact persons to interact with the Contractor.
6.2.
For such persons, their contact details, role, access rights, communication history, and history of actions within the relevant projects may be processed.
6.3.
We use such data only to the extent necessary to organize and perform the work and provide the relevant access.
7. Personal Data Processed on the Customer’s Instructions
7.1.
During development, diagnostics, migration, administration, or technical support, the Contractor may obtain technical access to the Customer’s systems that contain personal data of third parties.
Such systems may include, in particular:
- websites;
- CRM;
- ERP;
- databases;
- order management systems;
- servers;
- backups;
- event logs.
7.2.
In such cases, personal data of third parties is processed by the Contractor only to the extent necessary to perform the agreed technical work.
7.3.
Where, based on the nature of the relationship, the Customer is the personal data controller and the Contractor processes such data on the Customer’s instructions, the Customer is responsible for having lawful grounds for the initial collection and transfer of such data.
7.4.
The Contractor must not use personal data of third parties obtained in this manner for its own independent purposes.
7.5.
Where necessary, the Parties may enter into a separate data processing agreement or another document setting out special requirements for such processing.
8. Use of Automated Systems and Artificial Intelligence
8.1.
When providing services, we may use automation software, artificial intelligence systems, and large language models.
8.2.
Such tools may be used, in particular, for:
- analyzing technical information;
- working with source code;
- classifying and routing requests;
- preparing drafts;
- analyzing tasks;
- searching for technical solutions;
- other auxiliary operations.
8.3.
We seek not to disclose personal data to third-party AI services beyond what is necessary for the relevant purpose.
Where possible, data minimization, removal, or replacement of identifying information is applied.
8.4.
If a third-party AI/LLM provider is used, certain information may be processed by that provider in accordance with its contractual terms and privacy policy.
8.5.
If the Customer imposes a specific prohibition or restriction on the use of certain external AI services in relation to its information, it must notify us before providing the relevant information or before its processing begins.
8.6.
We do not make solely automated decisions that produce legal or similarly significant effects for an individual without an appropriate legal basis and proper information being provided to that person.
9. Disclosure of Data to Third Parties
9.1.
We do not sell personal data.
9.2.
Personal data may be disclosed to third parties only to the extent necessary for the relevant purpose, including to:
- hosting and cloud providers;
- server infrastructure providers;
- email service providers;
- communication services;
- project management systems;
- software providers;
- AI/LLM providers;
- analytics services;
- banks and payment institutions;
- accountants and other professional advisers;
- contractors involved in performing the work;
- public authorities where such disclosure is required by law.
9.3.
Data is disclosed only where there is a lawful basis and with due regard to the nature and purpose of the relevant processing.
10. International Data Transfers
10.1.
Some services used for hosting, communication, automation, analytics, or AI/LLM processing may locate their servers or process information outside Ukraine.
10.2.
In such cases, personal data is transferred subject to the requirements of applicable law governing international transfers of personal data.
10.3.
Where European Union law applies to specific processing, the appropriate safeguards provided for by such law are used for international transfers.
11. Retention Period
11.1.
Personal data is retained no longer than necessary for the purpose for which it was collected, unless a longer period is required by law or is necessary to protect lawful rights and interests.
11.2.
When determining the retention period, the following may be taken into account:
- the duration of contractual relations;
- the need for technical support;
- warranty and dispute-related matters;
- limitation periods;
- accounting and tax law requirements;
- information security requirements.
11.3.
Technical logs may be retained for the period necessary to ensure security, diagnose issues, and investigate technical incidents.
11.4.
Backups may contain data throughout the technical backup retention cycle even after the relevant data has been deleted from the primary system.
After such a cycle is completed, the data is deleted or overwritten in accordance with the established procedure.
12. Cookies and Similar Technologies
12.1.
The website may use cookies and other local information storage technologies.
12.2.
They may be used for:
- authentication;
- maintaining a session;
- ensuring security;
- saving settings;
- operation of the personal account;
- analyzing website usage;
- other website functions.
12.3.
Strictly necessary cookies may be used to ensure the basic operation of the website.
12.4.
If optional analytics, marketing, or other similar technologies are used for which consent is required by law, the user is given the opportunity to make the relevant choice.
12.5.
The User may also manage cookies through their browser settings.
Restricting cookies may affect the operation of certain website functions.
13. Analytics
13.1.
Web analytics systems may be used to assess the performance and use of the website.
13.2.
Such systems may receive technical information about the device, browser, IP address, and website usage in accordance with their terms.
13.3.
If the use of a particular analytics system requires separate consent, it is activated in accordance with the User’s consent settings.
14. Information Security
14.1.
We apply reasonable organizational and technical measures to protect personal data against:
- unauthorized access;
- unlawful use;
- accidental deletion;
- loss;
- damage;
- unauthorized alteration or disclosure.
14.2.
Protective measures may include access control, segregation of permissions, authentication, logging, backups, software updates, and other measures depending on the specific system.
14.3.
No information system can guarantee absolute security; therefore, we cannot guarantee the complete prevention of every possible incident.
15. Rights of the Data Subject
15.1.
The data subject has the rights provided for by Ukrainian law, including the right to:
- know the sources from which their personal data was collected, the location of such data, the purpose of its processing, and the persons to whom it is disclosed;
- receive information about the conditions for access to personal data;
- access their own personal data;
- request correction of inaccurate or incorrect data;
- object to processing in cases provided for by law;
- request amendment or deletion of data where lawful grounds exist;
- withdraw consent where processing is based on consent;
- know the mechanism of automated personal data processing;
- be protected against unlawful processing;
- lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or apply to a court;
- exercise other rights provided for by law.
15.2.
To exercise their rights, a person may contact the Contractor using the contact details specified in this Policy.
15.3.
Before fulfilling a request, we may ask for information necessary to verify the identity of the applicant and prevent unauthorized access to another person’s data.
16. Additional Rights of Persons to Whom the GDPR Applies
16.1.
If Regulation (EU) 2016/679 (GDPR) applies to particular processing of personal data, the data subject may have additional rights, including:
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restriction of processing;
- the right to object to processing;
- the right to data portability in cases provided for by the GDPR;
- the right to withdraw consent;
- the right to lodge a complaint with the competent supervisory authority.
16.2.
The availability of a specific right and the conditions for exercising it are determined by applicable law and the legal basis for the relevant processing.
17. Informational and Marketing Communications
17.1.
Messages necessary for performance of a contract, operation of an account, security, invoicing, or technical support may be sent regardless of consent to marketing communications where sending them is necessary for the relevant purpose.
17.2.
Advertising or marketing communications may be sent where an appropriate legal basis exists.
17.3.
Where such communication is carried out on the basis of consent, the User may opt out of it.
18. Third-Party Links
18.1.
The website or project management system may contain links to third-party resources.
18.2.
We do not control the privacy policies of independent third-party resources and recommend reviewing their terms separately.
19. Children’s Data
19.1.
The Contractor’s services are primarily intended for persons who order or use IT services in the course of professional, business, or other independent activities.
19.2.
We do not intend to knowingly collect children’s personal data without an appropriate legal basis.
19.3.
If it is established that a child’s personal data was obtained without the required lawful basis, such data may be deleted or its processing may be restricted in accordance with the law.
20. Changes to the Policy
20.1.
We may periodically amend this Policy due to changes in:
- legislation;
- website functionality;
- information systems;
- the list of services used;
- data processing methods.
20.2.
The current version is published on the website.
20.3.
The date of the current version is indicated at the top of the document.
20.4.
If changes materially affect the rights of data subjects, we may additionally notify them of such changes by an available means where required by law.
21. Contact Information
For questions regarding personal data processing, exercising rights, or this Policy, you may contact:
Sole Proprietor Mykhailova Yuliia Ruslanivna
Website:
https://mmwebxs.com/
E-mail:
privacy-policy@mmwebxs.com
Current version of the Privacy Policy:
https://mmwebxs.com/en/privacy-policy/
