Ship to EU (26)

Privacy policy

Effective date: 11 September 2026

This Privacy Policy explains how Kyiv Stend (FOP Bulak Serhii Serhiiovych, individual entrepreneur registered in Ukraine, hereinafter "we", "us", "our") collects, uses, stores and discloses personal data when you visit kyivstend.com.ua/en/, request a quote, place an order or contact us by email or phone. We act as data controller for the personal data described below.

This Policy is drafted to comply with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR);
  • Directive 2002/58/EC as amended by Directive 2009/136/EC (ePrivacy Directive);
  • Law of Ukraine No. 2297-VI "On Personal Data Protection" of 1 June 2010 as amended.

1. Data controller and contact

Kyiv Stend (FOP Bulak Serhii Serhiiovych), Kyiv, Ukraine.
Email: sales@kyivstend.com.ua
Phone: +38 050 542 80 38

Because we are established outside the EU/EEA and offer goods to data subjects in the EU, we can be contacted for GDPR matters via the email above. Requests are handled by the data controller directly; we currently do not appoint an external representative in the Union.

2. Categories of personal data we process

CategoryExamplesSource
Identification dataFull name, company name, positionYou provide directly via quote form, email, phone
Contact dataEmail, phone, delivery address, billing addressYou provide directly
Order dataProducts ordered, quantities, technical specifications, drawings you uploadYou provide directly
Financial dataIBAN, VAT ID (for B2B invoices), payment referenceYou provide directly / your bank when transferring funds
Technical dataIP address, browser type, device type, pages viewed, referrerAutomatically via cookies and server logs
Communication dataContent of emails, chat messages, call notesYou provide during correspondence

We do not knowingly collect data from children under 16. We do not process special categories of data (health, religion, biometrics) in the ordinary course of business. If your custom order relates to such categories (for example a sign with religious symbols), only the specification data is processed, not any personal data about the intended readers of the sign.

3. Purposes of processing and legal basis

PurposeLegal basis (GDPR Article)
Preparing a quote in response to your requestArt. 6(1)(b) - steps prior to entering into a contract
Fulfilling an order (production, invoicing, shipping)Art. 6(1)(b) - performance of a contract
Complying with Ukrainian tax and accounting law (retention of invoices, primary documents)Art. 6(1)(c) - legal obligation
Fraud prevention and technical security of the websiteArt. 6(1)(f) - legitimate interest
Website analytics (aggregated statistics on usage)Art. 6(1)(a) - consent (via cookie banner)
Sending occasional emails about new products or offersArt. 6(1)(a) - consent, opt-in only

4. Cookies and similar technologies

We use a limited set of cookies. Strictly necessary cookies (session, CSRF token, cookie-consent choice) are set without consent under Art. 5(3) ePrivacy Directive. Analytics and marketing cookies are set only after you click "Accept all" or the corresponding checkbox in the cookie preferences panel. You can withdraw consent at any time by clearing your browser cookies for this domain or by clicking "Cookie preferences" in the footer. Full list of cookies is published in the Cookie Policy.

5. Recipients and disclosure of data

We disclose personal data only to:

  • Carriers - Nova Poshta International, DHL, GLS, DPD - for the sole purpose of delivering your order. Recipient name, address, phone are transferred as part of the shipping label.
  • Banks - Ukrainian bank of Kyiv Stend and your bank - for processing the SEPA/SWIFT transfer.
  • Tax authorities of Ukraine - where required by Tax Code of Ukraine No. 2755-VI.
  • IT infrastructure providers - our hosting provider located in Ukraine, our website analytics provider (Google LLC, only if you consented to analytics cookies).

We do not sell personal data. We do not use personal data for automated decision-making with legal effect (Art. 22 GDPR).

6. International transfers

Personal data is stored on servers located in Ukraine. When you place an order from an EU/EEA country, the data effectively remains in Ukraine (a country outside the EU/EEA that has not received an adequacy decision from the European Commission). The transfer is necessary for the performance of a contract concluded at your request (Art. 49(1)(b) GDPR). We do not further transfer data to third countries beyond what is described in Section 5.

If you consent to analytics cookies, aggregated technical data may be processed by Google LLC in the United States under the EU-US Data Privacy Framework adequacy decision (Commission Implementing Decision (EU) 2023/1795).

7. Retention periods

Data categoryRetention periodBasis
Quote requests without follow-up order12 months from last contactLegitimate interest in re-engagement
Order and invoice data1095 days (3 years) from end of tax reporting periodArticle 44 Tax Code of Ukraine
Warranty claims and correspondence2 years from deliveryDirective 1999/44/EC minimum warranty period
Marketing consent recordsUntil withdrawn + 3 yearsEvidence of consent Art. 7(1) GDPR
Server access logs90 daysSecurity and fraud prevention

8. Your rights under GDPR

If you are located in the EU/EEA, you have the following rights:

  • Right of access (Art. 15) - obtain a copy of data we hold about you;
  • Right to rectification (Art. 16) - correct inaccurate data;
  • Right to erasure (Art. 17) - request deletion, subject to legal retention obligations;
  • Right to restriction (Art. 18) - limit processing in certain cases;
  • Right to data portability (Art. 20) - receive data in a machine-readable format;
  • Right to object (Art. 21) - object to processing based on legitimate interest;
  • Right to withdraw consent (Art. 7(3)) - at any time, without effect on processing before withdrawal;
  • Right to lodge a complaint with a supervisory authority in your Member State of residence (Art. 77).

To exercise any right, email sales@kyivstend.com.ua. We respond within 30 calendar days. We may request additional information to verify your identity before processing sensitive requests.

9. Data security

We implement technical and organisational measures appropriate to the risk (Art. 32 GDPR): TLS 1.3 encryption for all connections, restricted access to the order database, regular backups, staff training on data protection, incident response procedure with 72-hour notification to supervisory authorities in case of a personal data breach (Art. 33 GDPR).

10. Changes to this policy

We may update this Policy from time to time. The "Effective date" at the top will reflect the latest revision. For material changes we will publish a notice on the homepage for at least 30 days. Prior versions are archived and can be requested by email.

11. Governing law and jurisdiction

This Policy is governed by the law of Ukraine. Nothing in this Policy limits your rights under mandatory GDPR provisions or under the consumer protection law of your country of residence.