1. General Information and Scope of Application
The protection of your personal data is our priority. We process personal data in accordance with the requirements of the General Data Protection Regulation (GDPR) and applicable legislation. This Policy explains what data we collect, for what purposes, on what legal grounds, and what rights you have as a data subject.
2. Controller
Sole Proprietor Olha Chebotaryova
Address: 11a Nezalezhnosti Boulevard, Apartment 115, Brovary, 07400, Ukraine
E-mail: hello@neurochest.com
3. Principles of Data Processing
We process personal data in accordance with the principles of lawfulness, transparency, data minimization, accuracy, storage limitation, integrity, and confidentiality.
4. Legal Bases for Processing
Art. 6(1)(b) GDPR: Performance of a contract or pre-contractual measures.
Art. 6(1)(a) GDPR: Your voluntary consent.
Art. 6(1)(f) GDPR: Our legitimate interest (security, operation of the website, basic technical analytics without identification).
5. Server Log Files
The following data is automatically collected: IP address, date/time, browser, operating system, referrer URL.
Purpose: ensuring the stable and secure operation of the website.
Log file data is stored for a limited period and is automatically deleted.
The data is not used to identify individuals and is not combined with other data sources.
6. Communication (Email and Forms)
We process: name, e-mail, phone number, and message content.
Purpose: handling inquiries and communication.
Legal bases: Art. 6(1)(a/b/f) GDPR.
Correspondence may be stored as evidence of communication for the duration of the statutory limitation period or until dispute resolution.
7. Provision of Services and Client Content
We process identification and payment data, as well as client materials (photo, video, audio, brief).
The Client guarantees that they have all rights to the provided materials.
Processing is carried out exclusively for the performance of the contract (Art. 6(1)(b) GDPR).
8. Use of Artificial Intelligence (AI)
We use artificial intelligence tools as technical means for the execution of projects.
Such tools may be engaged as third-party service providers depending on the nature of the project.
Data is used exclusively for the fulfillment of the order and is not used by us for training third-party models.
9. No Automated Decision-Making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR that produces legal effects concerning you.
10. Cookies and Consent Management
We use a Consent Management Tool.
Technically necessary cookies are based on legitimate interest.
Analytical and marketing cookies are activated exclusively after your explicit consent via the cookie banner.
You may withdraw your consent or change cookie settings at any time.
11. Analytics and Marketing
Google Analytics (GA4): may be used to analyze user behavior (if activated and after obtaining consent). Data is processed in an anonymized form (IP anonymization). Legal basis: Art. 6(1)(a) GDPR.
Meta Pixel: may be used to assess advertising effectiveness and for retargeting (if activated and after obtaining consent). This includes processing of technical and behavioral data (clicks, views). Data may be transferred to the United States. Legal basis: Art. 6(1)(a) GDPR.
12. Recipients of Data (Third Parties)
We engage third-party service providers (data processors) in accordance with Art. 28 GDPR. Data processing agreements (DPA) are concluded where required.
Categories of recipients:
Hosting provider (Ukraine, .com.ua domain)
Purpose: technical operation of the website
Data: IP addresses, technical data
Email service (hello@neurochest.com)
Purpose: communication
Data: contact data and message content
Google Ireland Limited (Google Drive)
Purpose: storage of project materials
Data: files, media
Google Ireland Limited (Google Analytics), if used
Purpose: analytics
Meta Platforms Ireland Ltd., if used
Purpose: marketing and analytics
13. Data Security
We implement appropriate technical and organizational security measures, including SSL encryption, access control, secure storage systems, and regular software updates.
14. International Data Transfers
Transfers of personal data to third countries (including the United States and Ukraine) are carried out in accordance with Articles 44–49 GDPR using Standard Contractual Clauses (SCC) or other appropriate safeguards.
Such transfers may include technical (IP addresses), contact (e-mail), and project data.
15. Data Retention Periods
Requests: up to 12 months
Projects: up to 3 years
Accounting data: up to 10 years
Analytics: up to 14 months
After the retention period expires, data is deleted or anonymized.
16. Your Rights (Art. 15–21 GDPR)
You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing.
You may withdraw your consent at any time.
You have the right to lodge a complaint with a supervisory authority in an EU Member State at your place of residence, work, or the place of the alleged infringement.
To exercise your rights, contact: hello@neurochest.com
We respond within one month.
17. Obligation to Provide Data
Providing personal data may be necessary for the conclusion or performance of a contract. Without providing such data, some services may not be available.
18. Sources of Data
We obtain personal data:
directly from you (forms, email)
automatically (via cookies — only after your consent)
19. Changes to the Policy
We may update this Policy due to changes in legislation or our services.
The current version is always available on our website.