Privacy Policy
Last updated 20 September 2026
1. Who we are
This website, ukrpayroll.com, is operated by ТОВ «Апекс Автомотів» (APEX AV LLC), a limited liability company registered in Ukraine, ЄДРПОУ 38030670, registered office at 33 Universytetska Street, Office 52, Cherkasy, Ukraine.
For the purposes of the EU General Data Protection Regulation (GDPR) and the Ukrainian Law on Personal Data Protection No. 2297-VI, we are the controller of the personal data described below. You can reach us about anything in this policy at stefan@ukrpayroll.com.
2. What this policy covers, and what it does not
This policy covers personal data we collect through this website: when you book a call, send us an enquiry, or simply browse.
It does not cover the payroll and personnel data we process for client companies under a services agreement. In that work we act as a processor on the client’s instructions, and the terms sit in the engagement contract and its data processing agreement rather than here. If you are an employee of a client company with a question about your own payroll data, your employer is the controller and is the right first point of contact.
If we administer your sole proprietor (ФОП)
Where you engage us to administer your own sole proprietor (ФОП) under a separate mandate, we are the controller of the data we hold for that purpose: your registration and КВЕД details, your tax filings, and the transactions on the business account we administer for you. We process it in order to perform the mandate you signed. Legal basis: GDPR Article 6(1)(b).
That mandate also contains your written authorisation for us to inform the client who engages you when the account shows a conflict of interest with that client, such as a payment received from one of its competitors. We disclose the fact recorded on the account and nothing beyond it, we tell you each time we do so, and you may withdraw the authorisation at any time in writing, with effect from the moment it reaches us. Legal basis: GDPR Article 6(1)(a), your consent, which is given separately from the rest of the mandate.
We keep this data while the mandate is in force and for three years after it ends. We do not use it for any other purpose, and it goes to no one other than the client named in your authorisation, your bank, and the authorities where the law requires it.
3. What we collect, why, and on what legal basis
When you book a discovery call
Our booking tool asks for your name and email address, and offers an optional notes field. It also records the time slot you choose, your time zone and the language you booked in, so we can confirm the appointment in the right language at the right hour. This is stored in the website’s own database on our hosting account and is not sent to an external booking service.
Legal basis: GDPR Article 6(1)(b), steps taken at your request before entering into a contract.
When you send us an enquiry
Our enquiry form asks for your name, company and work email, asks without requiring an answer about your headcount in Ukraine and who handles HR administration today, and offers an optional field to describe what you want to solve. Before a submission is accepted, Cloudflare Turnstile checks that it comes from a person rather than an automated bot; for this check Cloudflare receives your IP address and technical information about your browser and device. Each submission is stored in the website’s own database on our hosting account, and a copy is sent to our business email. Alongside what you entered, the stored record holds the page you sent it from, the date and time, your IP address and your browser’s user agent string, which help us detect and discard spam. We also keep your name and email address in the site’s enquiry address book, so that later messages can be matched to the same conversation.
Legal basis: GDPR Article 6(1)(b) where your enquiry concerns a possible engagement, otherwise Article 6(1)(f), our legitimate interest in replying to people who contact us. The anti-spam check rests on Article 6(1)(f), our legitimate interest in keeping automated spam out of the form.
When you simply visit
Our hosting provider keeps standard server logs containing your IP address, the pages requested, the time of the request and your browser’s user agent string. These are generated automatically by the web server.
Legal basis: GDPR Article 6(1)(f), our legitimate interest in the security and availability of our own website.
Web fonts, together with the site’s own stylesheets and images, are served from our own servers. The site does not load fonts from Google Fonts or any other external font service, so opening a page does not send your IP address to a font provider. The third-party services that do run on the site are listed in section 5.
Analytics
We use Google Analytics 4 to understand in aggregate how the site is used: which pages are read, how people arrive, which countries they come from.
Analytics do not run until you allow them. The site loads with Google Consent Mode set to deny analytics and advertising storage by default. Until you accept the analytics category in our cookie banner, Google is instructed not to write analytics cookies or use identifiers. If you decline, or ignore the banner, no analytics cookies are set. You can change your mind at any time through the cookie preferences control.
Legal basis: GDPR Article 6(1)(a), your consent, which you may withdraw at any time.
What we do not do
We do not sell personal data and we do not share it with data brokers. We do not add you to a marketing list because you booked a call or sent an enquiry, and we do not send newsletters to people who have not asked for them. We run no advertising or retargeting on this site. We do not use automated decision-making or profiling that produces legal or similarly significant effects.
4. Cookies
| Purpose | What it does | Set before consent |
|---|---|---|
| Cookie preferences | Remembers the choice you made in the banner so we do not ask again | Yes, strictly necessary |
| Session and security | Standard WordPress cookies, set only if you log in to the site | Yes, strictly necessary |
| Language | Remembers whether you are reading the English or Ukrainian version | Yes, strictly necessary |
| Google Analytics (_ga, _ga_*, _gid, _gat) | Distinguishes visitors and sessions for aggregate statistics | No, only after you accept analytics |
You can withdraw or change your cookie consent at any time through the cookie preferences control, and you can delete cookies in your browser settings at any time.
5. Who else sees this data
We keep this list deliberately short. Each of the following processes data on our behalf, under contract.
| Provider | Role | Where |
|---|---|---|
| Hostinger | Website hosting and server logs | Our server is in the Netherlands (EU) |
| Google Analytics 4 | Aggregate website statistics, only after consent | EU / US |
| Google Search Console | Search performance data, aggregated, does not identify visitors | EU / US |
| Google Workspace | Our business email, through which enquiries and booking confirmations pass | EU / US |
| Google Drive | Encrypted off-site backups of the website | EU / US |
| ManageWP | Remote maintenance and update management for the website | EU / US |
| Cloudflare (Turnstile) | Anti-spam check on our contact forms; receives your IP address and browser information when a form is loaded and submitted | EU / US |
Our booking system, our enquiry form with its message store, and our translation layer all run on our own hosting and do not transmit your data to their vendors, apart from the Cloudflare anti-spam check described above. We may also disclose personal data where we are legally required to do so, for example in response to a lawful request from a competent authority.
Separately from the providers above: where we administer a contractor's sole proprietor (ФОП) and that contractor has authorised it in writing, we disclose to the client who engages them the facts described in section 2. That is a disclosure to a named client, not a processing arrangement.
6. International transfers
We are established in Ukraine, and this website is hosted in the European Union, in the Netherlands.
Ukraine is not covered by a European Commission adequacy decision. Where personal data of visitors in the EEA or the United Kingdom reaches us in Ukraine, it does so because it is necessary in order to take steps at your request before entering into a contract, or to perform one, which is the position set out in Article 49(1)(b) GDPR. In practice that means the booking or enquiry details you choose to send us.
Where the providers listed above process data outside the EEA, they do so under their own safeguards. Google and Cloudflare rely on a combination of the EU-US Data Privacy Framework and the European Commission’s Standard Contractual Clauses. We will provide details of the safeguards on request.
7. How long we keep things
| What | How long | Why |
|---|---|---|
| Booking records | 12 months from the date of the call | Long enough to follow up and keep a record of what was discussed, then deleted |
| Enquiries: stored form submissions, address-book entries and enquiry emails | 24 months from the last message about the enquiry | Business enquiries often resume after a long gap; beyond two years the context is stale, and the record is deleted |
| Server logs | As retained by our hosting provider in the ordinary course | Security and diagnostics |
| Analytics data | As configured in Google Analytics, in aggregate form only | Statistics |
| Website backups | The most recent three backup sets | Disaster recovery |
| Sole proprietor (ФОП) administration records | 3 years after the mandate ends | Matches the period we keep the underlying tax and accounting records |
If a conversation becomes an engagement, the data moves under the services agreement and its retention terms, and this policy no longer governs it.
8. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to its processing, to data portability, and, where processing rests on consent, to withdraw that consent at any time without affecting the lawfulness of what was done before.
Under Ukrainian Law No. 2297-VI you have equivalent rights, including the right to know who holds your data and for what purpose, to access it, and to require its correction or deletion.
To exercise any of these, write to stefan@ukrpayroll.com. We will respond within one month. We may ask you to confirm your identity, but only where we genuinely cannot otherwise be sure who is asking.
You also have the right to complain to a supervisory authority. In Ukraine that is the Ukrainian Parliament Commissioner for Human Rights. If you are in the EEA or the UK, you may complain to the data protection authority where you live or work.
9. Security
The site is served over HTTPS. Access to the website administration, to booking records and to stored enquiries is restricted to named accounts. Backups are encrypted and held off-site. Our email runs on Google Workspace with its standard protections.
No system is perfectly secure and we do not claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant authority and, where required, you.
10. Children
This site is aimed at businesses. We do not knowingly collect personal data from children.
11. Changes
If we change how this site handles personal data, we will update this policy and change the date at the top. Material changes will be flagged on the page itself.
