Privacy Policy
What personal data this site collects, who receives it, how it moves between countries, and the rights you have over it
Last updated and effective:
About this policy
This policy explains what personal data we collect through this website and during pre-contract contact, why we collect it, who receives it, and the rights you have over it.
It does not govern personal data contained in client business systems that we process during an engagement. In that work we act as a processor on the client's documented instructions, under a separate written agreement — see our Data Processing Addendum.
We update this policy when our processing or the applicable law changes. The date of the current version is shown at the top of this page.
Who is responsible for your data
Two legal persons operate under the N40 name, and which one is the controller depends on where you are and what you are contracting for.
- N40 Agency, LLC — a Delaware limited liability company (EIN 36-5172738, Delaware File No. 10548740). Registered agent: Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Operates this website and contracts with clients outside Ukraine.
- ФОП Василенко Вадим Володимирович — an individual entrepreneur registered in Ukraine, who contracts with, delivers to and invoices clients in Ukraine. Registration and contact details are set out in our Terms of Service.
For everything collected through this website — the contact form, analytics, scheduling — the controller is N40 Agency, LLC. Where you go on to contract for services in Ukraine, the individual entrepreneur becomes the controller of the contract and billing data arising from that engagement.
Our operations are carried out from Kyiv, Ukraine, and from the United States. Personal data is accessible to personnel in both locations. See International transfers.
What we collect
We collect three distinct kinds of data, on three different legal footings. They are separated here deliberately: some data reaches us only because you type it, and some reaches us simply because you loaded a page.
1. Data you give us directly
When you submit the contact form, book a call, or email us, we receive the information you choose to provide. In the contact form that is: your name, email address, and the message describing your situation. Optionally, you may also provide a phone number, company name, service of interest, timeline and budget range.
Please do not send us special-category data (health, biometric, political or religious views, trade-union membership, sex life or sexual orientation) or details of criminal offences through the contact form. We do not ask for it and have no use for it.
2. Technical data collected automatically
Some data is generated by the act of visiting the site and reaches our hosting and security infrastructure whether or not you interact with anything. This includes your IP address, browser type and version, device type, operating system, referring page, the pages you request, and the date and time of the request.
An IP address is personal data under the GDPR. We are stating plainly that we receive it, because the previous version of this policy said we collected personal data only when a form was completed and then listed IP address and location further down. That was contradictory. This is the accurate position.
3. Analytics and marketing data, only with consent
Analytics and marketing tags do not load until you accept them in the consent banner. If you do not consent, they are never loaded and set nothing on your device. If you do consent, the services listed in our Cookie Policy receive usage data including page views, session activity, approximate location derived from IP address, and device and browser characteristics.
You can withdraw consent at any time, as easily as you gave it, from the Cookie Policy page.
Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Replying to your enquiry and scoping a possible engagement | Contact form and email content | Art. 6(1)(b) — steps at your request prior to a contract |
| Delivering and administering agreed services | Contact and billing data | Art. 6(1)(b) — performance of a contract |
| Operating and securing the site; preventing abuse of the form | Technical data, including IP address | Art. 6(1)(f) — legitimate interests in security and availability |
| Measuring how the site is used; conversion and campaign measurement | Analytics and marketing identifiers | Art. 6(1)(a) — consent |
| Accounting, tax and defending legal claims | Contract and billing records | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — legal claims |
Where we rely on legitimate interests, you may object under Art. 21 GDPR. Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing carried out before you withdrew.
For processing carried out in Ukraine, the corresponding grounds are those in Article 11 of the Law of Ukraine "On Personal Data Protection" No. 2297-VI, and this section also serves as the notice required by Article 12(2) of that law.
Payment data
Engagements are invoiced business-to-business. There is no checkout on this website; payment follows an invoice, and how it is settled depends on where the client is.
- Ukraine — bank transfer only. Invoices are issued by ФОП Василенко Вадим Володимирович (РНОКПП 3809813776) and settled to the account held at JSC "Universal Bank" (АТ «УНІВЕРСАЛ БАНК», ЄДРПОУ 21133352, МФО 322001), the licensed bank operating under the monobank brand. No card payments are accepted in Ukraine. Account details are in our Terms of Service.
- Outside Ukraine. Invoices are issued by N40 Agency, LLC and may be settled either by bank transfer or by card through Stripe, Inc., which acts as the acquirer. Stripe processes the cardholder's name, email and billing address under its own privacy policy.
Where a card is used, the details are entered on Stripe's own hosted page. We do not receive or store full card numbers, expiry dates or security codes — we receive the payment status and the billing details needed for the invoice. Where settlement is by bank transfer, no card data is created at all.
Neither Stripe nor the receiving bank processes payment data on our instructions. Each determines its own purposes and means in order to execute the payment and to meet its own regulatory, anti-money-laundering and card-scheme obligations, and each is therefore an independent controller of that data. Information held by a Ukrainian bank is subject to payment-services secrecy under Article 70 of the Law of Ukraine "On Payment Services" No. 1591-IX.
Payment security certifications
Stripe, Inc. is certified as a PCI DSS Service Provider Level 1, the highest level under the standard. That certification is assessed annually by an independent Qualified Security Assessor, and Stripe is listed on the Visa Global Registry of Service Providers.
Because card details are handled entirely within Stripe's environment and never reach our systems, N40 is not itself required to hold a PCI DSS certificate, and we do not claim one. In Ukraine no card data exists at all, so the standard is not engaged there. We state only certifications actually held by the provider named above, on the basis of that provider's own published compliance information.
Who receives your data
We do not sell personal data, and we do not disclose it for anyone else's independent marketing. We use the following service providers, each under a written data-processing agreement, except where noted as an independent controller:
Provider
Purpose
Requires consent?
Netlify, Inc. (USA)
Website hosting, CDN, TLS
No — strictly necessary
Supabase Inc.
Database and edge function receiving contact-form submissions
No — needed to deliver your message
Resend (AWS SES)
Delivering the contact-form email to us
No — needed to deliver your message
Calendly, LLC (USA)
Appointment scheduling, if you book a call
No — you initiate it
Google LLC (USA)
Tag Manager and Analytics 4
Yes
Meta Platforms, Inc. (USA)
Meta Pixel — conversion measurement
Yes
LinkedIn Corporation (USA)
Insight Tag — conversion measurement
Yes
Stripe, Inc. (USA)
Card acquiring outside Ukraine — independent controller for payment data
No — needed to settle an invoice
JSC "Universal Bank" / monobank (Ukraine)
Receiving bank transfers against invoices in Ukraine — independent controller
No — needed to settle an invoice
We may also disclose data to professional advisers, to authorities where we are legally required to, and to a buyer or successor in the event of a merger, financing or sale of the business.
This list is the complete set of providers that may receive personal data from this website. If it changes, this page changes with it.
International transfers
We are established in the United States and operate from Ukraine. If you are in the European Economic Area or the United Kingdom, your data will be transferred outside it.
There is no single mechanism that covers every transfer, and we do not claim one. Under Chapter V of the GDPR the mechanism is determined for each recipient and each data flow:
- Adequacy (Art. 45). Where a recipient is covered by a European Commission adequacy decision, that decision is the mechanism and no additional safeguard is required. This includes US recipients holding a current certification under the EU–US Data Privacy Framework, which remains in force. We verify certification per entity rather than assuming it, and we monitor the pending appeal against that decision before the Court of Justice.
- Standard Contractual Clauses (Art. 46). Where a recipient is not covered by an adequacy decision, we rely on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, with the module appropriate to the role of each party, together with a documented assessment of the transfer and any supplementary measures that assessment calls for.
- Ukraine. Ukraine is not the subject of a European Commission adequacy decision. Access to personal data from our Kyiv operations is a restricted transfer and is governed by Standard Contractual Clauses.
Transfers of personal data collected in Ukraine to the United States are made under Article 29 of Law No. 2297-VI. The United States is not a party to Council of Europe Convention 108, so those transfers rest on the grounds available under that Article rather than on any adequacy finding.
A current list of the providers we use and the mechanism applying to each is available on request at contact@n40.agency.
How long we keep it
| Data | Retention | Reason |
|---|---|---|
| Enquiries that do not lead to an engagement | 24 months from last contact | Follow-up and evidence of the exchange |
| Contract and billing records | As required by applicable tax and accounting law | Legal obligation |
| Analytics data | Up to 14 months, per the provider retention setting | Consent |
| Server and security logs | Short-term, per our hosting provider's configuration | Security and availability |
When a retention period ends we delete the data or irreversibly anonymise it. Where deletion is not immediately possible — for example within a backup cycle — we isolate the data from further processing until deletion occurs.
Security
We apply technical and organisational measures appropriate to the risk, taking into account the nature and scope of the data we hold. In practice this means encrypted connections to the site, access limited to the people who need it for their work, confidentiality obligations on everyone with access, and reputable infrastructure providers.
No method of transmission or storage is completely secure, and we do not claim otherwise. We do not claim any certification we do not hold.
Personal data breaches
What we owe, and to whom, depends on the role we are acting in. The two cases are different and are set out separately.
Where we are the controller — for data collected through this website — we notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of a breach, unless the breach is unlikely to result in a risk to your rights and freedoms. Where a breach is likely to result in a high risk to you, we will also notify you directly, without undue delay. We record all breaches internally, including those that do not require notification.
Where we are a processor — for data inside client systems — we notify the client without undue delay after becoming aware of a breach, and assist them with their own obligations. In that role it is the client, as controller, who decides on and makes any notification to a supervisory authority or to affected individuals. We do not make that decision for them.
Your rights
To exercise any right below, email contact@n40.agency. We may need to verify your identity. We respond within one month, and will tell you if we need longer because a request is complex.
If the GDPR applies to you
- Access to your data and a copy of it (Art. 15);
- Correction of inaccurate or incomplete data (Art. 16);
- Erasure, where one of the grounds in Art. 17 applies;
- Restriction of processing (Art. 18);
- Portability of data you gave us, where processing rests on consent or contract (Art. 20);
- Objection to processing based on legitimate interests (Art. 21);
- Withdrawal of consent at any time, without affecting prior processing (Art. 7(3));
- Complaint to a supervisory authority in your country of residence, place of work, or the place of the alleged infringement (Art. 77). The list is at edpb.europa.eu.
If you are in Ukraine
Article 8 of Law No. 2297-VI gives you the right to know who holds your data and for what purpose, to access it, to have it corrected, and to object to its processing. We answer access requests within 30 calendar days and reasoned objections within 10 days. You may complain to the Ukrainian Parliament Commissioner for Human Rights, which is the supervisory authority for personal data in Ukraine.
If you are in the United States
State privacy laws generally apply to businesses above defined revenue or volume thresholds. We do not meet those thresholds, so most of them do not apply to us as a controller. We nevertheless offer the rights above to anyone who asks, regardless of where they live.
California. We do not sell or share personal information as those terms are defined in the CCPA, and we do not use or disclose sensitive personal information beyond the purposes permitted for a service provider. Note that in California business contact details — a work email address or job title — are personal information like any other, and we treat them accordingly. You will not be treated differently for exercising a privacy right.
Where a client engages us to handle data on their behalf, we act as a service provider or processor and process that data only for the purposes set out in the contract.
Use of AI systems
We build and operate AI-assisted tools for clients. Where you interact directly with an AI system operated by us, we tell you so. Where content is generated by an AI system, we mark it as such in line with the transparency obligations of the EU AI Act, which apply from 2 August 2026.
We do not use the personal data collected through this website to train AI models. We do not make decisions producing legal or similarly significant effects about you by automated means alone.
Children
This site sells business services and is not directed to children. We do not knowingly collect personal data from children under 13, and in the EEA we do not knowingly rely on the consent of a child below the age set by their member state (between 13 and 16). If you believe a child has given us personal data, contact us at contact@n40.agency and we will delete it.
External links
This site links to sites we do not operate. We are not responsible for their content or their privacy practices, and this policy does not apply to them.
Contact
Questions about this policy, or about how we handle your data, go to contact@n40.agency.
Controller for this website
N40 Agency, LLC
131 Continental Dr, Suite 305, Newark, DE 19713, USA
EIN 36-5172738 · Delaware File No. 10548740
Email: contact@n40.agency
Questions about your data? Contact us or email contact@n40.agency.
