UAENLaunch a project

Personal data processing · Version 2.0

Privacy
policy.

What data we collect on the site and in the billing service, on what legal basis, who we share it with, how long we keep it and how you can control it.

DATA MANIFEST —
what we collect, why, on what basis, who receives it and how to withdraw.

Minimum data. No third-party advertising. No selling of data.

Who processes the data

Andrii Dubniuk

Version

2.0 of 05.08.2026

Contact

support@avia.ovh

Data sources

Contact form · Payments · Logs

Third-party sharing

Limited, listed in Art. 09

Sale of data

Never

01

General provisions

This Privacy Policy sets out how Andrii Dubniuk ("we", the "Controller") processes and protects personal data received from users of the site https://avia.ovh and the billing service https://billing.avia.ovh.

The Policy is drafted under the Law of Ukraine "On Personal Data Protection" No. 2297-VI, the Law of Ukraine "On Electronic Commerce" No. 675-VIII, the Law of Ukraine "On Information" No. 2657-XII and the Model Procedure for Processing Personal Data approved by Order of the Ukrainian Parliament Commissioner for Human Rights No. 1/02-14 of 08.01.2014.

The Policy forms an integral part of the Public Offer. By using the site and submitting data through it, you confirm that you have read this Policy.

We process only the data needed for a specific stated purpose and do not collect excessive information. We do not sell personal data and do not share it with advertising networks or data brokers.

We do not process special categories of personal data (racial or ethnic origin, political, religious or philosophical beliefs, trade union membership, health, sex life, biometric or genetic data) and ask you not to submit such data through forms on the site.

02

The data controller and contacts

Controller within the meaning of Article 2 of the Law of Ukraine "On Personal Data Protection" No. 2297-VI: Andrii Dubniuk, Ukraine, Zhytomyr.

Contact address for any questions or requests concerning personal data: support@avia.ovh. Alternatively — support@avia.ovh or by post to the address above.

Requests from data subjects are answered within thirty calendar days of receipt, under Article 16 of the Law of Ukraine "On Personal Data Protection" No. 2297-VI. Working hours: Mon–Fri, 10:00–18:00 (Kyiv time).

No separate data protection officer has been appointed, as the volume and nature of processing do not require one. The Controller performs data protection duties personally.

The supervisory authority for personal data protection in Ukraine is the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua). You have the right to lodge a complaint with them.

03

Data you provide through the contact form

The contact form on the site collects: contact person's name, company name (optional), email address, phone number or Telegram handle, service name and the message describing the task.

You provide this data voluntarily in order to obtain a consultation, a price estimate or to order a digital service. Without the mandatory fields we cannot process the request or reply to it.

The date and time of submission are recorded automatically. Requests are stored in a PostgreSQL database on the infrastructure described in Article 09.

Please do not include passwords, access credentials, card details, identity document data or third-party personal data in the message without a lawful basis for sharing it.

04

Data processed for payments and subscriptions

In the billing service at https://billing.avia.ovh, when a payment or subscription is set up, we process: the payer's first and last name, email address, company name (optional), phone number (if provided) and time zone.

We also generate and store operational payment data: the chosen plan, amount, currency, frequency, payment and subscription status, start date, next charge date and period end date, the history of charge attempts, failure codes and messages, invoice, subscription and checkout session identifiers, and the payment service's responses.

For stored payment methods we keep: an encrypted payment token, the masked card number (first and last digits) and its expiry date. We never receive or store the full card number, CVV/CVC code or PIN — see Article 11.

To sign in to the subscription portal we process your email address and generate a one-time sign-in link (magic link) and a session token with a limited lifetime.

We record the fact that transactional emails were sent: recipient address, message type, delivery status and time of dispatch — to evidence compliance with our information duties and to prevent duplicate sends.

A personal payment link, if we create one for you, may contain a pre-filled name, email address and company name; the link itself is stored as a hash, has an expiry date and can be revoked.

05

Technical data, cookies and local storage

The site uses no web analytics, advertising pixels, social network trackers or other third-party tracking tools. We do not build advertising profiles of users.

We use strictly necessary cookies only. This is the session cookie in the billing service, which keeps you signed in to the subscription portal for a limited period. It is a functional cookie, set with protective attributes (HttpOnly, Secure, SameSite), and is not used for advertising or analytics.

Browser local storage holds only your chosen interface language. This data is not sent to the server and does not identify you.

At server and hosting provider level, technical logs may temporarily record the IP address, browser type, request time and page address. These records are used solely to keep the service running, diagnose failures and protect against attacks.

Because we use strictly necessary cookies only, no cookie consent banner is displayed: such files are required for the service to function and do not require separate consent. If analytics or marketing cookies are added in future, we will introduce a consent mechanism and update this Article.

You can manage cookies and local storage in your browser settings. Deleting the session cookie will sign you out of the subscription portal.

06

Legal bases for processing

We process personal data on the grounds set out in Article 11 of the Law of Ukraine "On Personal Data Protection" No. 2297-VI, namely:

Consent of the data subject (Article 11(1)(1)) — to process a request submitted through the form on the site, and to send informational emails if you have subscribed to them.

Conclusion and performance of a transaction to which the data subject is a party (Article 11(1)(3)) — to place an order, process a payment, run a subscription, provide access to the portal, deliver services and communicate about them.

Compliance with a legal obligation of the controller (Article 11(1)(5)) — for accounting and tax records, retention of primary documents and responses to requests from authorised bodies.

Protection of the controller's legitimate interests (Article 11(1)(6)) — for information security, fraud and abuse prevention, technical logging, and defence of our rights in the event of a dispute.

Where processing is based on your consent, you may withdraw it at any time — this does not affect the lawfulness of processing carried out before withdrawal and does not stop processing that rests on another legal basis (for example, mandatory retention of accounting documents).

07

Purposes of processing

Handling and answering your request, preparing a price estimate and a commercial proposal, clarifying technical requirements.

Concluding and performing the contract for digital services, including agreeing scope, handing over the result and providing ongoing support.

Settlements: issuing an invoice, confirming payment, running and automatically renewing a subscription, issuing refunds, handling disputed transactions.

Sending transactional (service) messages: payment confirmations, failed-charge notices, upcoming-charge reminders, portal sign-in links, notices of changes to terms.

Accounting and tax records, compliance with Ukrainian law and responses to lawful requests from authorised bodies.

Service security: detecting and preventing unauthorised access, fraudulent transactions and automated abuse; diagnosing technical failures.

Protecting the Controller's rights and legitimate interests in the event of claims or disputes.

We do not use your data for third-party advertising and do not make decisions on its basis that produce legal effects without human involvement.

08

Retention periods

Personal data is kept in a form permitting identification no longer than necessary for the purpose of processing — under Article 6(8) of the Law of Ukraine "On Personal Data Protection" No. 2297-VI.

Contact form requests that did not lead to an engagement are kept for up to three years from receipt — within the general limitation period — and are then deleted or anonymised.

Data of clients with whom a contract was concluded is kept for the term of the contract and three years after settlements are complete.

Primary payment documents and data needed for accounting and tax records are kept for the periods set by Ukrainian accounting and archival legislation — at least three years, and longer in some cases.

Subscription data and payment history are kept for the term of the subscription and three years after it ends.

Portal access tokens are kept for their lifetime only: a one-time sign-in link for minutes, a session token for up to one day, after which they become invalid.

Server technical logs are kept for the period set by the hosting provider and are overwritten automatically.

After the retention period expires, data is deleted or anonymised so that further identification becomes impossible.

09

Sharing data with third parties

We do not sell, rent or transfer personal data to advertising networks, data brokers or others for marketing. Sharing occurs only in the cases below and only to the extent necessary for the specific purpose.

Payment service: JSC UNIVERSAL BANK (monobank Acquiring / Plata by mono) — to accept payment, tokenise the card, run recurring charges and issue refunds. Name, email address, amount, currency and operational transaction identifiers are shared. The bank acts as an independent controller within payment legislation and card scheme rules.

Email delivery service: Resend, Inc. (USA) — to send transactional emails. The recipient's email address and the message content are shared.

Hosting and infrastructure: OVH SAS, data centres within the European Economic Area — hosting of the application servers and the database. The provider acts as a processor and may not use the data for its own purposes.

Engaged contractors and subcontractors — solely to the extent needed to deliver services to you and under confidentiality obligations.

Authorised state bodies — on the basis of a lawful written request or a court decision, to the extent and in the manner prescribed by law.

Legal successors — in the event of reorganisation or transfer of the business, subject to the terms of this Policy.

We notify you of a transfer of your personal data to a third party within ten business days where Article 21 of the Law of Ukraine "On Personal Data Protection" No. 2297-VI requires it, except where the transfer is expressly provided for by law or is necessary to protect the rights and legitimate interests of others.

10

Cross-border data transfers

Part of the technical infrastructure we use is located outside Ukraine.

The infrastructure of OVH SAS, data centres within the European Economic Area is located in states of the European Economic Area. Such states are recognised as providing an adequate level of personal data protection under Article 29(3) of the Law of Ukraine "On Personal Data Protection" No. 2297-VI.

The email delivery service Resend, Inc. (USA) is registered in the United States — a state not included in the list referred to above. Data is transferred there on the basis of Article 29(4) of that Law — as necessary for the conclusion and performance of a transaction between us and you, and with your consent to processing for that purpose.

In all cases the minimum necessary volume of data is transferred, and contractual confidentiality and security obligations apply to the providers.

If you object to your data being transferred abroad, write to support@avia.ovh — we will tell you which service functions would remain available in that case.

11

Card data and payment security

We do not receive, process or store the full card number, CVV/CVC code or PIN. These are entered only on the acquirer's secure payment page.

Payment data is processed by JSC UNIVERSAL BANK (monobank Acquiring / Plata by mono) in accordance with the Payment Card Industry Data Security Standard (PCI DSS) and the international card scheme rules.

For recurring subscription charges the acquirer stores a card payment token. On our side we store only an encrypted identifier of that token, the masked card number and its expiry date — enough to show you which card the subscription is on, and not enough to make a payment outside our service.

Connections to the site and billing service are secured with TLS. Payment authentication uses 3-D Secure on the issuing bank's side.

You may dispute a payment transaction through your issuing bank under the Law of Ukraine "On Payment Services" No. 1591-IX and the card scheme rules.

12

Data security

We apply the technical and organisational protection measures required by Article 24 of the Law of Ukraine "On Personal Data Protection" No. 2297-VI.

Technical measures: traffic encryption (TLS), encryption of payment tokens in the database, storage of access tokens as cryptographic hashes, limited lifetimes for sign-in links and sessions, protection of session cookies with HttpOnly, Secure and SameSite attributes, verification of the digital signature on incoming payment service messages, idempotency control, request origin restrictions (CORS) and input validation.

Organisational measures: database access is limited to authorised persons of the Controller and to contractors within their assigned tasks; access is granted on a least-privilege basis; staff and contractors are bound by confidentiality obligations.

No system of transmitting data over the internet is completely secure. We cannot guarantee absolute security but take reasonable measures to minimise risk.

In the event of a personal data breach that poses a risk to the rights and freedoms of data subjects, we take steps to contain it and notify the affected individuals and the Ukrainian Parliament Commissioner for Human Rights in the manner prescribed by law.

13

Your rights as a data subject

Article 8 of the Law of Ukraine "On Personal Data Protection" No. 2297-VI gives you the following rights:

To know the sources of collection and the location of your personal data, the purpose of processing, and the location or place of residence of the controller or processor.

To receive information about the terms on which access to personal data is granted, in particular information about third parties to whom it is transferred.

To access your personal data and to receive an answer as to whether your data is being processed — no later than thirty calendar days from receipt of the request.

To submit a reasoned demand objecting to the processing of your personal data, and a demand for the modification or destruction of data that is processed unlawfully or is inaccurate.

To protection against an automated decision that has legal consequences for you, and to enter a reservation restricting the right to process your data when giving consent.

To withdraw consent to processing, to complain to the Ukrainian Parliament Commissioner for Human Rights or to a court, and to use legal remedies in the event of a breach of personal data protection legislation.

To exercise any of these rights, send a request to support@avia.ovh from the email address you used to contact us, or through the contact form on the site. We may ask for additional details to satisfy ourselves that the request comes from you.

We reply within thirty calendar days, free of charge. If we cannot fully satisfy a request (for example, because the data is subject to mandatory retention by law), we will explain why.

14

Marketing and informational mailings

We do not run mass advertising mailings and do not pass your email address to third parties for marketing.

The emails you may receive are transactional (service) messages: payment confirmations, charge and failed-charge notices, portal sign-in links, notices of changes to the terms of service, and replies to your enquiries. These are part of performing the contract, are sent regardless of marketing consent, and cannot be unsubscribed from while the contract or subscription is active.

If we introduce a newsletter or marketing mailing, it will be sent solely on the basis of your separate prior consent — under Article 10 of the Law of Ukraine "On Electronic Commerce" No. 675-VIII, which prohibits sending commercial electronic messages without the addressee's consent.

Every commercial electronic message will be clearly identified as advertising, will contain details of the sender and a working link to opt out of further such messages.

You can withdraw consent to marketing messages at any time — via the link in the email or by writing to support@avia.ovh. Opting out of marketing does not affect transactional messages.

15

Children's personal data

The site and billing service are intended for persons aged eighteen or over with full legal capacity. We do not offer services to children and do not knowingly collect personal data of persons under eighteen.

If we become aware that we have received a child's personal data without the consent of a parent or other legal representative, that data will be deleted as soon as possible.

If you are a parent, adoptive parent or guardian and believe a child has provided us with their data, write to support@avia.ovh and we will delete it.

16

Automated decisions and profiling

We do not make decisions about you based solely on automated processing where those decisions produce legal consequences or significantly affect you.

Only operational processes are automated: validation of the format of entered data, automatic subscription charging on the agreed date, retry attempts on a set schedule, sending of transactional emails, and technical anti-abuse measures.

We do not profile for advertising, do not assess your creditworthiness by automated means and do not build behavioural user profiles.

Decisions affecting the scope, price or terms of the services are made by a human.

17

Changes to this Policy

We may update this Policy — where the law changes, where the set of services we use changes, or where site functionality changes.

The current version is always available at https://avia.ovh/privacy. Current version: 2.0 of 05.08.2026.

We announce material changes affecting the scope of data processed, the purposes of processing or the list of recipients on the site, and notify users with active subscriptions by email as well, no later than thirty calendar days before the changes take effect.

Continued use of the site after a new version takes effect means you have read it. Where changes require your consent, we will ask for it separately.

Previous versions of the Policy are available on request to support@avia.ovh.

Form fields —
and what happens to them.

Data flow

Contact person's name

Request handling · communication

Required

Company name

Task context

Optional

Email

Reply · commercial proposal

Required

Phone or Telegram

Alternative contact channel

Required

Service name

Request routing

Required

Message text

Scope and timeline estimate

Required

Payer name and email

Checkout · subscription · receipt

Payment

Time zone

Next charge date

Payment

Masked card and token

Subscription auto-renewal

Subscription

Payment history

Records · support · refunds

Payment

Portal session cookie

Sign-in to the subscription portal

Technical

Interface language

Browser local storage

Technical

Data is not used for third-party advertising and is never sold. Marketing mailings require separate consent; transactional payment emails are sent as part of performing the contract. We never receive the full card number or CVV.

Data request

Want to access, update or delete your data?

Send a request to support@avia.ovh or use the form on the site — we reply within thirty calendar days and act on it to the extent the law allows.