top of page

PRIVACY POLICY AND PERSONAL DATA PROTECTION

Last updated: 12 August 2026

PREAMBLE

This Privacy Policy and Personal Data Protection Policy (hereinafter — the "Policy") has been developed for the website papish.online (hereinafter — the "Website") in order to explain to its Users for what purposes and exactly which personal data is collected, processed, used, and stored when using the Website.

The Website is administered by the individual entrepreneur (sole proprietor) Oleksandr Mykhailovych Papish (hereinafter — the "Administration"), who is recognized as both the data processor and the data controller of personal data under the GDPR.

Please carefully review this Policy and its provisions if you wish to use the features and technical capabilities of the Website, receive technical support and/or feedback, and/or purchase the educational services (courses, webinars) offered on the platform.

​

1. Terms and Definitions

1.1. This clause defines the interpretation of the following terms, definitions, and expressions used in this Policy.

  • Website — a set of software, informational, and other tools, logically interconnected, accessible on the Internet at: papish.online.

  • Data Controller — an individual or legal entity that determines the purpose of processing personal data, establishes the composition of such data and the procedures for its processing, unless otherwise determined by law.

  • User — any individual who has access to the Website and uses it via the Internet.

  • Personal Data — information or a set of information about an individual who is identified or can be specifically identified.

  • Data Processor — an individual or legal entity to whom the data controller or the law has granted the right to process such data on behalf of the controller.

  • Authorized Persons — the Administration's contractors (for example, providers of payment, hosting, or email services) who have been granted access to personal data in order to perform technical or operational functions.

  • Mailing — electronic, text, and/or multimedia messages sent to an email address containing a commercial and/or non-commercial offer from the Administration and/or third parties.

  • Data Subject — an individual whose personal data is being processed.

  • Cookies — a small piece of data (a text file) that the Website stores on an electronic computing device (computer, phone, tablet, etc.) when it is visited by the User.

1.2. The above terms have the same meaning when used in the singular and plural, and regardless of capitalization. Other terms used in this Policy are defined in accordance with the norms of applicable Ukrainian legislation, and where no definition exists in legislation, they carry their commonly accepted meaning or are defined in accordance with business practice.

​

2. General Provisions

2.1. This Policy has been developed taking into account all requirements and in accordance with:

  • Regulation (EU) 2016/679 of 27 April 2016 (GDPR — General Data Protection Regulation);

  • the Law of Ukraine "On Personal Data Protection";

  • the Law of Ukraine "On Electronic Commerce";

  • the Law of Ukraine "On Consumer Rights Protection";

  • other regulatory acts of Ukrainian legislation governing legal relations related to the collection, processing, and storage of personal data, as well as citizens' rights to non-interference in private life and freedom of expression.

2.2. The provisions of this Policy apply exclusively to the Website papish.online.

2.3. The Website Administration does not control and bears no responsibility for personal data operations carried out through:

  • third-party services that ensure the full functioning of the Website (payment systems, hosting, analytics, etc.);

  • messengers and other means of communication that facilitate communication between the Administration and Users of the Website.

2.4. The Website Administration reserves the right to make any changes and corrections to this Policy in the event of a change in the manner, procedure, and/or purpose of collecting, processing, using, or storing personal data.

2.5. This Policy is deemed valid in the version and under the terms that existed at the time its terms were accepted by the User.

​

3. Category of Data Subjects

3.1. The category of data subjects includes Website Users who have reviewed the terms of this Policy, registered on the platform, purchased educational services (courses, webinars), and/or given consent to receive mailings.

​

4. Subject Matter of the Policy and Composition of Personal Data

4.1. This Policy imposes an obligation on the Website Administration and on Authorized Persons regarding non-disclosure and ensuring the confidentiality protection regime for Users' personal data.

4.2. The Policy establishes the purpose(s) and grounds for processing personal data, the categories of data subjects, the composition of personal data, the procedure for processing personal data and Cookies, and the procedure for conducting mailings, for the processing of which the User has given consent.

4.3. Sources from which personal data used in accordance with this Policy is obtained:

  • Registration forms: by the User completing registration forms, subscribing to a mailing list, or ordering educational services on the Website;

  • Payment for services: through payment systems integrated with the Website, when paying for courses/webinars;

  • Email: through the receipt/sending of electronic messages during interaction with the Administration;

  • Data from other sources: social networks (e.g., Instagram, Telegram, Facebook), public sources from which the Administration has obtained access to personal data (where lawful grounds exist).

4.4. The Administration collects only the personal data that has been knowingly and voluntarily provided by the User themselves for the use of the Website's resources and/or for communication with the Administration.

4.5. When the User uses the sources defined in this Policy, their personal data is processed, which may include:

  • surname, first name, and patronymic;

  • mobile phone number;

  • email address;

  • payment data (to the extent necessary to process payment; the Administration does not itself store bank card details directly — these are processed by the payment provider);

  • account identifier on Telegram/Instagram (if interaction occurs via these channels);

  • technical data (IP address, browser type, device data);

  • geolocation data (where technically possible to determine).

4.6. The Website Administration reserves the right to automatically collect Cookies during the User's visit to the Website.

4.7. The Website Administration does not collect data for which restrictions and/or prohibitions are established under the Law of Ukraine "On Personal Data Protection," and does not process personal data that poses a special risk to the rights and freedoms of data subjects (health data, religious beliefs, racial or ethnic origin, etc.).

​

5. Composition and Procedure for Processing Cookies

5.1. The Website Administration may use third-party analytics and payment processing services, and also collects its own session Cookies exclusively for tracking Website visit statistics and for the ability to optimize and adapt the Website to the interests of each User.

5.2. Cookies stored on the User's electronic computing device facilitate analysis of Website usage and store information about the User's online behavior. Cookies do not harm the User's device and do not contain viruses.

5.3. Cookies may collect the following information:

  • the addresses of Website pages viewed by the User;

  • the addresses of previous web pages from which access to the Website was obtained;

  • the browser's language settings;

  • the time, date, and duration of the visit to the Website;

  • information about the User's browser (name, version, etc.).

5.4. This Policy provides for the possible processing of "session" and "persistent" Cookies:

  • "Session" Cookies are temporary and are stored only until the browser session ends.

  • "Persistent" Cookies remain on the User's device until the User deletes them.

5.5. The Website Administration may process:

  • Necessary Cookies — provide the core functions of the Website (navigation, access to protected sections). The Website cannot function properly without these files.

  • Statistical Cookies — help understand how visitors interact with the Website by anonymously collecting and reporting information.

  • Marketing Cookies — used to track Users in order to display relevant advertising.

5.6. The User has the right to refuse the use of Cookies by changing the relevant browser settings or by sending an email to the Administration. If the User refuses the processing of Cookies, they may not have access to all of the Website's functions.

​

6. Purpose of Processing Personal Data

6.1. The processing of personal data under this Policy is carried out for the purpose of the Website Administration properly providing the User with access to use all the resources and capabilities of the Website, namely:

  • providing information about the content posted on the Website;

  • registering the User and granting access to purchased educational services (courses, webinars);

  • establishing communication with the User via the format they have chosen;

  • processing payment for educational services and sending payment confirmations;

  • conducting mailings with the additional consent of the data subject, to the email address;

  • providing the User with effective technical support in the event of problems related to the use of the Website;

  • monitoring the load on the Website;

  • analyzing the effectiveness of advertising campaigns whose traffic is directed to the Website;

  • conducting statistical and other research based on anonymized data.

6.2. The User's personal data may be used for other purposes not provided for in this Policy, if this is necessary for the proper fulfillment by the Administration of obligations imposed by the Public Offer Agreement.

​

7. Grounds for Processing Personal Data

7.1. A person who has attained full civil legal capacity in accordance with the applicable legislation of the country of their citizenship has the right to be a data subject and to give consent to the processing of their personal data. If a person does not have a sufficient level of legal capacity, consent to the processing of their personal data is given by parents, guardians (custodians), or adoptive parents.

7.2. The User's consent to the processing of personal data is given by:

  • checking a box granting permission for the processing of personal data during registration on the Website or when placing an order; or

  • communicating with the Administration via mobile communication or email.

7.3. Consent to the processing of Cookies is given by the User by checking a box granting permission in a pop-up window (cookie banner) during the first visit to the Website.

7.4. The Website does not provide for the possibility of processing personal data prior to the User giving the relevant consent.

7.5. By giving consent to data processing in the manner provided for in this section, the User fully and unconditionally agrees to all provisions of this Policy. The User gives their consent to the Administration for the collection, systematization, accumulation, storage, clarification (updating, correction), use, dissemination, anonymization, blocking, and destruction of their personal data within the limits set out in this Policy.

7.6. If the User does not give consent to the processing of their personal data in the manner provided for in clause 7.2 of this Policy, the User will not be able to use the resources and technical capabilities of the Website, including the purchase of educational services.

​

8. Procedure for Processing Personal Data

8.1. The Website Administration collects personal data from the sources provided for in Section 4 of this Policy.

8.2. Collected personal data is accumulated by entering it into the relevant database, which is stored in electronic form using the technical capabilities of the learning management systems (LMS), CRM systems, and payment services engaged by the Administration to ensure the operation of the Website.

8.3. The User's personal data is stored for 3 (three) consecutive years from the date of the User's last interaction with the Administration (use of services, inquiries, etc.), unless a longer storage period is required by Ukrainian legislation (in particular, accounting and tax record-keeping requirements).

8.4. Personal data is processed and stored in electronic form in compliance with technical and organizational protection measures.

8.5. The Website Administration uses personal data exclusively to properly provide services to the User and for the purposes defined in Section 6 of this Policy.

​

9. Procedure for Processing Personal Data for Marketing Purposes

9.1. The Website Administration may send electronic, text, and/or multimedia messages to an email address containing a commercial and/or non-commercial offer from the Administration and/or third parties.

9.2. The purpose of the mailing is to inform the data subject about the products, courses, webinars, events, etc. of the Administration and/or its partners, as well as to conduct anonymous surveys in order to gauge opinions about the services.

9.3. The data subject gives additional consent to the Administration's mailing through a separate confirmation (for example, a separate checkbox during registration), distinct from the general consent to the processing of personal data.

9.4. The data subject has the right to unsubscribe from the mailing at any time by following the "Unsubscribe" link provided in the email and/or by sending a free-form request to the Administration's email refusing the mailing.

​

10. Procedure for Access by Persons Processing Personal Data

10.1. The Website Administration processes personal data independently and/or with the involvement of third parties (Authorized Persons) that provide services or perform duties on behalf of the Administration, including payment processing, technical support for the hosting/LMS platform, email mailings, analytics, and conducting surveys.

10.2. The Website Administration keeps records of operations related to the processing of personal data and retains such records for 3 (three) years from the date of the relevant operation.

​

11. Rights and Obligations of the Data Subject

11.1. The data subject has the right to:

  • obtain information regarding the purposes for which their personal data is processed;

  • obtain information regarding the period during which their personal data is processed;

  • require the Administration to correct their inaccurate personal data without undue delay;

  • require that additions be made to incomplete personal data;

  • require the Administration to delete, without undue delay, personal data relating to them (the "right to be forgotten");

  • require the Administration to restrict the processing of their personal data;

  • receive the personal data that they provided to the Administration (the "right to data portability");

  • object to the processing of their personal data;

  • appeal against the actions or inaction of the Administration: under Ukrainian legislation — to the Ukrainian Parliament Commissioner for Human Rights (Ombudsman) or in court; under the legislation of European Union member states — to the authorized body for the protection of data subjects' rights in the country of which the data subject is a citizen (for Users from the EU, in accordance with the GDPR).

11.2. To exercise their rights, the User shall send a reasoned written request to the Administration's email address, specified on the Website, from the email address that they indicated during registration or when placing an order.

11.3. The data subject is obliged to comply with the provisions of this Policy and to notify the Administration of any change in the content of the personal data provided.

​

12. Rights and Obligations of the Website Administration

12.1. The Website Administration has the right to make changes to this Policy by publishing an updated version on the Website, indicating the date of the update, without separately notifying the data subject, except in cases provided for in this Policy.

12.2. The Website Administration is obliged to:

  • ensure the exercise of the data subject's rights;

  • take the necessary organizational and technical measures to protect personal data from unlawful or accidental access, destruction, distortion, blocking, copying, dissemination, and other unlawful actions of third parties;

  • fulfil all obligations imposed on it by this Policy.

​

13. Conditions and Procedure for Changing, Deleting, or Destroying Personal Data

13.1. The basis for making changes to personal data is a reasoned written application from the data subject, sent to the Administration's email from the address that the User indicated during registration. Changes are made without delay from the moment the discrepancy is established.

13.2. The grounds for deleting and destroying personal data are:

  • withdrawal of consent to the processing of personal data;

  • expiration of the personal data processing period provided for in this Policy.

13.3. The Administration notifies the data subject of the consequences of withdrawing consent and deletes/destroys personal data without undue delay, but no later than 10 (ten) business days from the date of receipt of the relevant request.

13.4. In the event of the deletion of personal data as a result of the withdrawal of consent to processing, the Administration has the right to deprive the User of access to the use of the Website and purchased services to the extent that this requires the processing of such data.

​

14. Dissemination and Cross-Border Transfer of Data

14.1. The User's personal data may be disseminated (transferred) to authorized state and judicial bodies exclusively where lawful grounds and a corresponding request exist.

14.2. The Website Administration may transfer personal data to Authorized Persons (payment providers, hosting providers, LMS/CRM services) to ensure the functioning of the Website and the provision of services, provided that such persons maintain an adequate level of personal data protection.

14.3. The cross-border transfer of personal data outside Ukraine (for example, when using cloud services located abroad) is carried out in compliance with the requirements of the Law of Ukraine "On Personal Data Protection" and, where relevant data subjects from the EU are involved, in compliance with the requirements of the GDPR, in particular on the basis of Standard Contractual Clauses or other lawful data transfer mechanisms.

​

15. Personal Data Protection Mechanisms

15.1. The Website Administration takes the necessary organizational and technical measures to protect personal information from unlawful or accidental access, destruction, distortion, blocking, copying, dissemination, as well as from other unlawful actions of third parties.

15.2. In the event of a leak or unlawful dissemination of personal data caused by the fault of third parties, the Administration shall immediately, upon discovering such a fact, notify data subjects by sending a notice to their email.

15.3. The services and systems in which Users' personal data is stored apply security measures provided for by their internal regulations and Data Processing Agreements.

​

16. Liability of the Parties

16.1. The Website Administration bears liability for damages incurred by the User in connection with the unlawful use of personal data, except in cases provided for in this section.

16.2. In the event of the loss or disclosure of personal data, the Administration bears no liability if such personal data:

  • had become or was public at the time of loss or disclosure;

  • was obtained from a third party prior to its receipt by the Administration;

  • was disclosed with the User's consent.

​

17. Dispute Resolution Procedure

17.1. The User and the Website Administration shall resolve all disputes and disagreements arising from the relationships covered by this Policy through negotiations.

17.2. Disputes not settled by the parties shall be resolved in court in accordance with the legislation of Ukraine.

​

18. Final Provisions

18.1. The Website Administration has the right to make changes to this Policy without separate consent or notification to the User, except in cases provided for in this Policy.

18.2. A new version of the Policy takes effect from the moment it is published on the Website, unless otherwise provided in the new version.

18.3. The informed consent to mailings and other provisions regarding the processing of personal data posted on the Website form an integral part of this Policy.

18.4. The text of the Policy is drawn up in the Ukrainian language; if an English-language version of the Policy exists, in the event of any conflict between the versions, the Ukrainian version shall prevail.

​

CONTACTING THE ADMINISTRATION

Sole Proprietor (FOP) Oleksandr Mykhailovych Papish

Address: Ukraine, 03022, Kyiv, Yulii Zdanovskoi Street, building 61

EDRPOU code / RNOKPP: 3556108833

IBAN: UA703348510000000026004370547

Bank: JOINT STOCK COMPANY "FIRST UKRAINIAN INTERNATIONAL BANK" (JSC "PUMB")

Bank MFO code: 334851

Bank EDRPOU code: 14282829

Platform: PAPISH.ONLINE

Email for inquiries regarding personal data: papish.online@gmail.com

bottom of page