top of page

Privacy Policy

1

General provisions and definitions of terms

This Privacy Policy (hereinafter referred to as the Policy) defines the procedure for collecting, processing and protecting personal data of visitors (hereinafter referred to as Data Subjects, Users) of the Kit Publishing House website located at www.kit-publishing.com.

 

The Owner and Controller of the data is the individual entrepreneur Kryvenko Maria Anatoliivna, RNTRC (RNOKPP) is 3449313383, entry number in the Unified State Register of Legal Entities, Individual Entrepreneurs and Public Organizations is 2010350010001365250 dated 07/31/2023.

 

Contact email: info@kit-publishing.com

 

Providing personal data through web forms and/or placing an order on the Site means that the Data Subject has read this Policy and agrees to the terms of processing personal data to the extent necessary for using the Site and fulfilling the order.

 

Key terms:

  • Personal data: any information relating, directly or indirectly, to an identified or identifiable natural person (Data Subject).

  • Processing: any operation or set of operations such as collection, recording, accumulation, storage, adaptation, alteration, alteration, use and dissemination (dissemination, disclosure by transmission, alteration

  • Data Owner/Controller: Individual Entrepreneur Kryvenko Maria Anatoliivna, who determines the purposes and means of processing personal data.

  • User: any individual who visits the Site, uses its functionality, or provides personal data through web forms.

  • Data Controller (Processor): a natural or legal person who is authorized by the Owner or by law to process personal data on behalf of the Owner.

  • Buyer: A User who has placed an order for goods on the Site.

2

List of personal data processed

The Owner/Controller processes data that the User voluntarily and knowingly provides by filling out the relevant web forms on the website, as well as technical data collected automatically.

2.1.
Data provided by the User:
  • first and last name;

  • email address;

  • phone number;

  • nickname or contact in the messenger (provided that the User independently chooses this communication channel);

  • delivery address;

  • data of the recipient of the goods;

  • information about placing an order (ordered product, order date and transaction amount);

  • information about the fact and status of payment (without payment card details).

2.2.
Automatically collected (technical) data:
  • This data is collected automatically when you visit the site using cookie and web analytics technologies:

  • IP address;

  • browser type and version;

  • operating system;

  • date and time of access;

  • pages viewed;

  • source of referral to the site.

3

Purpose and objectives of personal data processing

Personal data is processed solely for legitimate, clearly defined purposes:

  • Communication: providing responses to requests, requests and messages from Users sent via contact forms.

  • Marketing and information: formation and maintenance of a contact database for email newsletters (subject to consent), information about publishing house news, announcements of new publications, events, promotions and special offers.

  • Conclusion and execution of a purchase and sale agreement: processing orders and pre-orders, payment, delivery of goods, formation and storage of settlement/accounting documents, accounting and/or tax accounting.

  • Service improvement: analysis of Users' interaction with the site to assess its effectiveness, eliminate technical malfunctions, and improve the user experience.

  • Security: ensuring the security of the site's operation and preventing fraud.

4

Legal basis for data processing

The processing of the User's personal data is carried out on the following legal grounds, in accordance with the Law of Ukraine "On Personal Data Protection" and EU Regulation 2016/679 (GDPR), if applicable:

  • Data subject consent (Art. 6(1)(a) GDPR): for the purposes of marketing communications and the use of optional cookies.

  • Legitimate interest of the Owner/Controller (Art. 6(1)(f) GDPR): to ensure the technical functioning of the site, non-personally identifiable analytics, and responses to general requests from Users.

  • Performance of the sales contract (Art. 6(1)(b) GDPR): to process orders, make payments, arrange delivery and fulfill obligations to the buyer.

  • Compliance with a legal obligation (Article 6(1)(c) GDPR): to comply with the requirements of Ukrainian legislation, in particular regarding accounting and/or tax accounting, document storage and provision of information upon lawful requests by authorized authorities.

5

Use of cookies and web analytics

The Website uses cookies (small text files stored on the User’s device) to ensure proper technical functioning as well as for statistical analysis.

The following types of cookies are used on the Website:

  • Essential (technical) cookies: required for basic navigation and operation of the Website (for example, for the functioning of the cookie consent banner).

  • Analytical (statistical) cookies: including those provided through Wix Analytics (as the Website platform) and Google Analytics. These cookies are used solely to obtain aggregated statistics regarding website traffic and user behavior.

The Website uses a cookie consent banner mechanism that allows the User to accept or reject the use of analytical cookies. The User may also manage or delete cookies at any time through the settings of the web browser. Detailed instructions are usually available in the help section of the User’s browser.

Data collected through analytical cookies is primarily used in aggregated form and is not used to identify a specific individual without separate consent or another lawful basis.

 

Refusal to use analytical cookies does not affect the use of essential (technical) cookies, which are necessary for the proper functioning of the Website.

6

Conditions for storing and transferring data to third parties

6.1.
Data retention period

Personal data is stored for the period necessary to achieve the purpose of their processing.

  • Data for mailings is stored until the User withdraws consent or until the publishing house ceases to operate.

  • Analytical data is stored in accordance with the policies of the respective services.

  • Personal data and documents related to the processing and fulfillment of an order (in particular, data on purchase, payment, delivery) may be stored for at least the period stipulated by the legislation of Ukraine for accounting and/or tax purposes.

6.2.
Transfer of personal data to third parties

Personal data may be transferred to third parties (personal data controllers) who ensure the functioning of the site and the fulfillment of orders, solely to the extent necessary to provide the relevant services. Such persons include:

 

  • payment provider monobank (plata by mono) — for payment processing;

  • providers of fiscalization services (including Vchasno.Kasa) — for the generation and delivery of electronic fiscal receipts in accordance with the requirements of Ukrainian legislation.

  • delivery services - for order fulfillment and delivery of goods;

  • accounting and bookkeeping service providers - for financial accounting;

  • hosting providers - for technical site hosting and data storage;

  • email newsletter services - for sending informational messages;

  • web analytics services - for statistical analysis of site usage.

 

The transmission may include data such as name, contact details, shipping address, order information and payment status.
The transfer of data to delivery services is carried out for the purpose of fulfilling the purchase and sale agreement and delivering the order.
Non-personalized and aggregated statistical data may be used for analytical purposes without the possibility of identifying a specific individual.
Personal data is not sold or transferred to third parties for marketing purposes.
All personal data controllers are obliged to ensure an adequate level of data protection in accordance with the law.
The transfer of personal data to third parties other than those specified in this Policy may be carried out exclusively in the following cases:

  • with the direct consent of the personal data subject;

  • in cases provided for by the legislation of Ukraine, in particular on the basis of lawful requirements of state bodies or court decisions.

6.3.
Payment and payment providers

Payment for goods on the Site is made through monobank (plata by mono) payment service. Payment card details are entered directly on the secure page of the payment provider.
Buyers' payment card details are not transferred to and are not stored by Maria Anatolyivna Kryvenko, an individual entrepreneur.
Payment data is processed in accordance with the terms and privacy policy of the payment provider.

6.4.
Data processing on servers outside of Ukraine

Due to the use of hosting, analytics and other technical providers, personal data may be processed on servers located outside of Ukraine. In such cases, processing is carried out in compliance with the requirements of the legislation on personal data protection and the terms of the relevant services.

7

Rights of the Personal Data Subject

In accordance with the Law of Ukraine "On Personal Data Protection" and the GDPR, if applicable, the Personal Data Subject has the following rights regarding the data:

  • Right of access: to receive information about what personal data is being processed.

  • Right to rectification: to request the updating or correction of inaccurate personal data.

  • Right to erasure ("right to be forgotten"): to request the erasure of personal data if it is no longer necessary for the purposes of the processing or if the User has withdrawn consent.

  • Right to withdraw consent: withdraw previously given consent to processing at any time (this does not affect the lawfulness of processing prior to withdrawal). Withdrawal of consent to the processing of personal data does not affect the lawfulness of processing carried out prior to withdrawal and does not apply to processing that is necessary for the performance of a contract or compliance with legal requirements (in particular regarding record keeping and document storage).

  • Right to restriction of processing: request temporary cessation or restriction of data processing.

  • Right to object: to object to the processing of personal data if it is based on the legitimate interest of the Controller.

  • Right to data portability: to receive User's data in a structured, commonly used format and transmit it to another controller.

  • Right to lodge a complaint: to lodge a complaint with the Commissioner for Human Rights of the Verkhovna Rada of Ukraine or the relevant EU supervisory authority if the Data Subject believes that his or her rights have been violated.

 

To exercise any of the above rights, the Data Subject may contact the Data Owner/Controller at the following email address: info@kit-publishing.com.

8

Safety measures

The Owner/Controller applies appropriate technical and organizational security measures (data encryption, access control, secure communication channels) to ensure the confidentiality and integrity of personal data, as well as to protect them from unauthorized access, alteration, disclosure or destruction.

To protect personal data during transmission between the User’s device and the Website’s servers, encryption based on the Transport Layer Security (TLS) protocol is used. The use of TLS ensures the confidentiality and integrity of information transmitted over the Internet (including when submitting web forms and placing orders) and prevents interception or alteration by unauthorized third parties.

9

Changes to the Privacy Policy

The Data Owner/Controller reserves the right to make changes to this Policy at any time. The current version of the Policy is always available on this website. Changes will take effect from the moment of their publication.

bottom of page