Data Processing Agreement (DPA)

Translation notice. This English translation is provided for convenience only. The legally binding text is the Ukrainian original: Угода про обробку персональних даних.

DSTUcrypt service

Version dated: 5 August 2026

Effective from: 5 August 2026

Published at: https://dstucrypt.com.ua/en/dpa

Preamble

This Data Processing Agreement (hereinafter — the Agreement, the DPA) is concluded between:

Elektronnyi Obih LLC (ТОВ «електронний Обіг») (EDRPOU company code 46191111, registered office: 1a Dniprovodska St., office 1, Kyiv, 04077, Ukraine), hereinafter — the Processor,

and

the person using the DSTUcrypt service on the basis of the Terms of Use and the Public Offer, hereinafter — the Controller,

together — the Parties.

The Agreement is an integral part of the Terms of Use of the DSTUcrypt service (https://dstucrypt.com.ua/en/terms) and is concluded by way of the Controller's accession to it in accordance with Article 634 of the Civil Code of Ukraine. Accession takes place at the moment the Controller begins to use the functions of the service that involve the transmission of End Users' personal data to the Processor's servers.

The Agreement is concluded in fulfilment of the requirements of the Law of Ukraine "On Personal Data Protection" No. 2297-VI (hereinafter — the Law), in particular Articles 4, 6, 10, 11, 16, 21, 24 and 29, and with due regard to the approaches laid down in Regulation (EU) 2016/679 (GDPR), for the benefit of Controllers to whom it applies.

In plain words: when your user signs a document or logs in with a qualified electronic signature (QES) on your website via our widget, their surname, first name, patronymic, and RNOKPP (personal tax number) physically pass through our servers. The owner of that data is you. We merely perform a technical operation on your instructions. This document records exactly what we are obliged to do with that data — and what we have no right to do.

1. Definitions

Personal data — information about a natural person who is identified or can be specifically identified, within the meaning of Article 2 of the Law.

The Customer — has the meaning defined in the Terms of Use of the DSTUcrypt service.

Controller of personal data (Controller) — the Customer, who determines the purpose of processing End Users' personal data, the composition of that data, and the procedures for its processing. In GDPR terminology — the controller.

Processor of personal data (Processor) — Elektronnyi Obih LLC, which processes personal data on behalf of and on the instructions of the Controller. In GDPR terminology — the processor.

End User (Data Subject) — a natural person who interacts with the widgets of the DSTUcrypt service on the Controller's web resource.

Service — the DSTUcrypt software suite as defined in the Terms of Use.

Processing — any action or set of actions performed on personal data, including collection, registration, accumulation, storage, adaptation, alteration, updating, use, dissemination, anonymisation, and destruction.

Sub-processor — a third party engaged by the Processor to process End Users' personal data. In GDPR terminology — a sub-processor.

Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

Zero-retention — a processing mode in which the content of signature verification and authentication requests, electronic signatures, the content of signed data, and the information about the signer's identity obtained from certificates are processed exclusively in RAM for the duration of an individual operation and are destroyed immediately after the response is generated, without being written to databases, file storage, or logs. The zero-retention mode does not apply to technical security and licensing logs (clause 5.2) or to one-time challenges, the composition and retention periods of which are defined in Annex 1.

2. Allocation of the Parties' roles

2.1. With respect to the personal data of End Users transmitted to the Processor's servers in connection with the use of the Service, the Controller acts as the controller of personal data, and the Processor acts as the processor of personal data.

2.2. With respect to the personal data of the Controller itself (e-mail address, domain names, payment data, personal account session data), the Processor acts as an independent controller. These relations are governed by the Privacy Policy (https://dstucrypt.com.ua/en/privacy), not by this Agreement.

2.3. With respect to technical security and licensing logs — records containing the IP address, the date and time of the request, the value of the Origin header, the domain name, the type of operation, and the response code — the Processor acts as an independent controller on the basis of its own legitimate interest in ensuring the security and availability of the Service and in licence control. Such logs are not the subject matter of this Agreement; the procedure for their processing is defined in the Privacy Policy. The logs do not contain request bodies, electronic signatures, document contents, or information about the identity of the signer.

2.4. The Processor does not determine the purposes and means of processing End Users' personal data and does not use such data for its own purposes.

2.5. If the Processor exceeds the scope of the Controller's instructions and begins to independently determine the purpose of processing, it shall, to that extent, be deemed a controller and shall bear the corresponding liability.

3. Subject matter, nature, purpose, and duration of processing

3.1. Subject matter of processing — the personal data of End Users contained in electronic signatures, public key certificates, and signed data.

3.2. Nature of processing — automated processing in RAM for the purpose of performing cryptographic operations: verifying the integrity of an electronic signature, establishing the status of the signer's certificate, confirming identity by electronic signature, and generating electronic timestamps.

3.3. Purpose of processing — providing the Controller with the technical capability to apply and verify electronic signatures and to authenticate End Users on its own web resource.

3.4. Duration of processing — processing lasts exclusively for the duration of an individual operation. Processing as a service is carried out for the duration of the subscription of the Controller (the Customer).

3.5. A detailed description of the processing is set out in Annex 1 to this Agreement.

4. Processing solely on the Controller's instructions

4.1. The Processor processes personal data exclusively on the documented instructions of the Controller.

4.2. The following are deemed the Controller's documented instructions:

4.2.1. this Agreement and the Terms of Use;

4.2.2. the technical documentation of the Service, published at https://dstucrypt.com.ua/docs.html, in the version in force at the time the respective call is made. The Processor retains previous versions of the documentation and provides them to the Controller upon written request within 10 business days;

4.2.3. actual calls to the Service's methods initiated from the Controller's Licensed Domain, including by End Users' browsers; each such call is deemed a separate instruction of the Controller to perform the respective operation;

4.2.4. written instructions of the Controller sent to legal@dstucrypt.com.ua and accepted by the Processor.

4.3. The Processor processes personal data outside the Controller's instructions only where required by the legislation of Ukraine. In such a case, the Processor notifies the Controller of that requirement before commencing the processing, unless such notification is prohibited by law.

4.4. The Processor immediately informs the Controller if, in its opinion, an instruction received contravenes personal data protection legislation, and has the right to suspend the execution of such an instruction until the circumstances are clarified.

5. Obligations of the Processor

The Processor undertakes:

5.1. Not to store personal data. The Processor processes End Users' personal data in zero-retention mode. In particular, the Processor does not write to databases, file storage, or logs:

  • the content of requests to POST /api/verify and POST /api/auth/verify;
  • electronic signatures;
  • the content of signed data transmitted as the content parameter;
  • the surname, first name, patronymic, RNOKPP (personal tax number), EDRPOU company code, and other information about the signer obtained from the certificate.

The data listed above is destroyed immediately after the response to the respective request is generated.

5.2. To limit service logs. The Processor keeps technical logs containing exclusively: the source IP address of the request, the date and time, the value of the Origin header, the domain name, the type of operation, and the response code. The logs do not contain request bodies and do not contain the data specified in clause 5.1. The retention period of the logs is 90 days, after which they are automatically deleted or anonymised. With respect to these logs, the Processor acts as an independent controller in accordance with clause 2.3 of this Agreement.

5.3. To ensure confidentiality. In accordance with Article 10 of the Law, the Processor ensures that persons authorised to process personal data have committed themselves to confidentiality, such commitment remaining in force after the termination of the employment or contractual relationship.

5.4. To apply security measures. The Processor implements the technical and organisational measures set out in Annex 2 to this Agreement.

5.5. Not to transfer data to third parties otherwise than in the manner set out in Section 6 of this Agreement or in compliance with a lawful demand of an authorised body.

5.6. To assist the Controller in fulfilling its obligations, in particular in responding to data subjects' requests (Section 7) and in ensuring the security of processing.

5.7. To provide information necessary to demonstrate compliance with this Agreement, in the manner set out in Section 9.

5.8. To notify of Incidents in the manner set out in Section 8.

5.9. To limit cross-border transfers to the cases set out in Section 10.

6. Sub-processors

6.1. The Controller grants the Processor a general authorisation to engage sub-processors, subject to compliance with this Section.

6.2. The Processor:

6.2.1. concludes with each sub-processor an agreement imposing on it data protection obligations no less stringent than those provided for in this Agreement; 6.2.2. remains fully liable to the Controller for the acts and omissions of sub-processors as for its own; 6.2.3. engages only those sub-processors that provide sufficient guarantees of the implementation of appropriate technical and organisational measures.

6.3. The current list of sub-processors is set out in Annex 3 to this Agreement and is kept up to date at https://dstucrypt.com.ua/en/dpa.

6.4. Procedure for changing the list. The Processor notifies the Controller of its intention to engage a new sub-processor, to replace an existing one, or to change the jurisdiction where the servers are hosted, by e-mail and by updating Annex 3, at least 30 calendar days before the commencement of processing by such sub-processor or before the change of jurisdiction.

6.5. Right to object. The Controller has the right, within 15 calendar days from the date of receipt of the notification, to send a reasoned objection to legal@dstucrypt.com.ua. The Parties shall seek an acceptable solution in good faith. If no solution is found, the Controller has the right to terminate the contract with respect to the relevant function or in its entirety. Refunds for the unused period are made in the manner set out in the Refund Policy (https://dstucrypt.com.ua/en/refund); for the purposes of this clause, such termination is treated as termination of the contract for reasons attributable to the Processor.

7. Assistance in exercising data subjects' rights

7.1. The rights of personal data subjects provided for in Article 8 of the Law are exercised vis-à-vis the Controller as the person determining the purpose of processing.

7.2. If an End User contacts the Processor directly, the Processor:

7.2.1. does not respond to the substance of the request on its own; 7.2.2. forwards the request to the Controller without delay, and no later than within 5 business days, provided the Controller can be identified; 7.2.3. informs the requester of the forwarding.

7.3. The Processor provides the Controller with reasonable assistance in responding to a data subject's request — taking into account the nature of the processing and the information available to the Processor.

7.4. The Parties acknowledge a factual limitation: since the Processor operates in zero-retention mode, it generally holds no personal data of End Users that could be provided, amended, or destroyed in response to a data subject's demand. This limitation is a consequence of the Service's architecture and enhances the level of data protection.

7.5. The assistance under clause 7.3 is provided free of charge, except where the volume of the Controller's requests is manifestly excessive; in such a case, the Parties agree the cost separately.

8. Incidents

8.1. If an Incident concerning End Users' personal data is detected, the Processor notifies the Controller without undue delay, and no later than 72 hours from the moment of detection.

8.2. The notification is sent to the Controller's e-mail address specified in the personal account and contains, to the extent known at the time of notification:

  • a description of the nature of the Incident;
  • the categories and approximate number of data subjects and records affected;
  • the likely consequences;
  • the measures taken or proposed to remedy the Incident and mitigate its consequences;
  • the contact details of a person from whom additional information can be obtained.

8.3. Where it is impossible to provide all the information at the same time, it is provided in phases without undue delay.

8.4. The Processor documents all Incidents and the measures taken and provides this documentation to the Controller upon request.

8.5. The obligation to notify the supervisory authority and the data subjects, should such an obligation arise, rests with the Controller as the person determining the purpose of processing. The Processor provides the necessary assistance for this.

9. Demonstration of compliance and audits

9.1. Upon written request, the Processor provides the Controller with the information necessary to demonstrate compliance with the obligations under this Agreement.

9.2. The Controller has the right to conduct an audit of compliance with the Agreement no more than once every 12 months, except where the audit is conducted following an Incident or at the demand of an authorised public authority.

9.3. An audit is conducted subject to:

9.3.1. written notice of at least 30 calendar days; 9.3.2. agreement by the Parties on the scope, timing, and procedure; 9.3.3. signature by the auditors of a non-disclosure undertaking; 9.3.4. non-disruption of the operation of the Service and preservation of the confidentiality of the data of the Processor's other clients.

9.4. The Processor has the right to satisfy an audit request by providing a current report of an independent auditor, a certificate of compliance, or a completed security questionnaire, provided such documents reasonably cover the subject of the audit.

9.5. The costs of conducting the audit are borne by the Controller, except where the audit reveals a material breach of the Agreement by the Processor.

10. Place of processing and cross-border transfers

10.1. The processing of End Users' personal data is carried out on servers located in Ukraine.

10.2. The content of requests to the signature verification and authentication endpoints, electronic signatures, document contents, and information about the signer's identity are not transferred outside Ukraine.

10.3. No cross-border transfer takes place. Technical requests to the electronic timestamping services (TSP) and certificate status services (OCSP, CRL) are directed exclusively to qualified trust service providers included in the Trust List and located in Ukraine. In any event, such requests contain only hash values of data and the serial numbers and identifiers of certificates — not the contents of documents and not information about a person in clear form.

10.4. The list of sub-processors, indicating the country of hosting, is set out in Annex 3.

10.5. Should a need for a cross-border transfer of personal data arise, the Processor:

10.5.1. ensures compliance with the requirements of Article 29 of the Law and directs such requests only to states that ensure adequate protection of personal data — member states of the European Economic Area and states parties to Convention ETS No. 108; 10.5.2. for Controllers subject to the GDPR, applies standard contractual clauses or another appropriate transfer mechanism; 10.5.3. notifies the Controller in the manner set out in clause 6.4, at least 30 calendar days in advance.

11. Term and consequences of termination

11.1. The Agreement enters into force at the moment of the Controller's accession and remains in force for the duration of its use of the Service.

11.2. After the provision of services ends, the Processor, at the Controller's choice, returns or destroys all End Users' personal data in its possession and destroys existing copies, except where a retention obligation is established by the legislation of Ukraine. If the Controller has not communicated its choice within 30 calendar days from the date of termination, the data is destroyed.

11.3. The Parties acknowledge that, given the zero-retention mode (clause 5.1), the Processor generally holds no personal data of End Users that would be subject to return or destruction. Technical logs are deleted automatically upon the expiry of 90 days.

11.4. Upon the Controller's written request, the Processor provides confirmation of compliance with clause 11.2 within 30 calendar days.

11.5. Clause 5.3 and Sections 8, 9, 10, 11, and 12 survive the termination of the Agreement.

12. Liability

12.1. Each Party is liable for breaches of personal data protection legislation within the scope of its own obligations as defined by this Agreement and the Law.

12.2. The Controller is solely responsible for:

12.2.1. the existence of a legal basis for the processing of End Users' personal data; 12.2.2. informing End Users about the processing, including the transfer of data to the Processor, as well as fulfilling the obligation under Article 21 of the Law to notify data subjects of the transfer of their data to third parties; 12.2.3. the lawfulness and legitimacy of its instructions; 12.2.4. the correct configuration of the Service on its web resource, including the decision to enable the Automatic mode (session) and the informing of End Users about such storage; 12.2.5. the lawfulness of processing the personal data of minor End Users, including obtaining the consent of legal representatives where required.

12.3. The Processor's aggregate liability under this Agreement is limited to the amount defined in clause 12.1 of the Terms of Use. This limitation does not apply to:

12.3.1. intentional breaches and gross negligence of the Processor; 12.3.2. amounts recovered from the Controller by a supervisory authority or a court as a result of a proven breach of this Agreement by the Processor; 12.3.3. cases where a limitation of liability is prohibited by mandatory provisions of law.

12.4. The Controller compensates the Processor for documented losses caused by the Controller's breach of clause 12.2.

13. Final provisions

13.1. The Agreement is governed by the substantive law of Ukraine.

13.2. In the event of a conflict between this Agreement and the Terms of Use on matters of personal data processing, this Agreement prevails, except for matters of liability, which are governed by clause 12.3 of this Agreement in conjunction with Section 12 of the Terms of Use.

13.3. The Processor has the right to amend the Agreement in the manner set out in Section 14 of the Terms of Use. Amendments that reduce the level of personal data protection do not apply to the Controller without its express consent.

13.4. A Controller requiring a signed copy of the Agreement on paper or with a qualified electronic signature applied shall send a request to legal@dstucrypt.com.ua.

13.5. Annexes 1, 2, and 3 are integral parts of the Agreement.

Annex 1. Description of the processing of personal data

1.1. Categories of data subjects

  • natural persons who apply an electronic signature on the Controller's web resource;
  • natural persons who authenticate themselves by electronic signature on the Controller's web resource;
  • natural persons named as signers in the documents being verified;
  • authorised representatives of legal entities whose details are contained in the certificate.

1.2. Categories of personal data

CategoryComposition
Identification data from the certificatesurname, first name, patronymic (fullName)
Tax identifiersregistration number of the taxpayer's record card, RNOKPP (personal tax number) (taxId)
Legal entity dataEDRPOU company code (orgCode), name of the organisation (signerOrg)
Certificate datacertificate identifier (signerCertId), issuer (issuer), indication of the provider's inclusion in the Trust List (accredited, qualified), revocation status (ocspStatus, crlStatus)
Operation datatime of signing (signingTime), timestamp time (timestampTime), signature format
Document contentthe content of the signed data — only in the case of verification of a detached signature, where the Controller passes the content parameter

Technical request data (IP address, Origin, date and time) does not fall within the subject matter of this Agreement — it is processed by the Processor as an independent controller in accordance with clause 2.3 of the Agreement.

1.3. Special categories of data

The processing of special categories of personal data within the meaning of Article 7 of the Law (racial or ethnic origin, political, religious or ideological beliefs, membership of political parties and trade unions, state of health, sexual life, biometric and genetic data, criminal or administrative liability) is not envisaged.

The Controller undertakes not to transmit such data to the Service. If the nature of the Controller's documents implies the presence of special categories of data in their content, the Controller is obliged not to use server-side verification of a detached signature with transmission of the content parameter, and instead to use verification of an attached signature or browser-side verification via the widget's verify() method. This does not remove the requirement of clause 6.3 of the Terms of Use regarding authentication under the server-to-server scheme.

1.4. Processing operations

OperationWhat is transmitted to the ProcessorResultStorage
POST /api/auth/verifysignature, challengeconfirmed identity: full name, RNOKPP (personal tax number), EDRPOU company code, provider, statusnot stored
POST /api/verify (attached)signature in base64signature status, information about the signersnot stored
POST /api/verify (detached)signature + data content (content)signature status, information about the signersnot stored
POST /api/auth/challengeno personal data is transmittedone-time challengethe challenge is stored until it is used or expires (approximately 300 seconds)
sign — applying a signaturenothing except TSP/OCSP/CRL requeststhe signature is generated in the browsernot stored
encrypt, decryptnothing — the operations are performed entirely on the user's deviceencrypted or decrypted data—
cert.inspect — certificate parsingnothing — performed on the user's devicecertificate structure—
cert.verify — certificate statusserial number and identifier of the certificatestatusnot stored
TSP proxyhash value of the dataelectronic timestampnot stored
OCSP / CRL proxycertificate identifierscertificate statusnot stored
GET /api/license, GET /api/licenseddomain name, IP, Originlicence statustechnical log, 90 days — processed by the Processor as an independent controller (clause 2.3)

1.5. Processing on the End User's device

The following is not processing on the Processor's side, but is described for completeness:

DataLocationProtectionPeriod
encrypted private key containerlocalStorage of the domain dstucrypt.com.uaAES-GCM-256, key derived from the PIN via PBKDF2-SHA256 (310,000 iterations), bound to the host domainup to 30 days
unlocked "key + password" pairsessionStorage of the tabwithin the tabttlMinutes, set by the Controller
record of consent to storagelocalStorage of the domain dstucrypt.com.ua—together with the container
PIN codenot stored——
private key and password in clear formbrowser RAM—duration of the operation

The decision to enable the Automatic mode is made by the Controller.

Allocation of consent obligations. The Processor ensures that the widget displays an interface for obtaining the End User's consent to the storage of the key container and records the fact of such consent locally, in the localStorage of the user's device. The legal basis for such processing, as well as the informing of End Users about the enabling of the Automatic mode, is the responsibility of the Controller. Since the record of consent is stored exclusively on the user's device, the Processor has no technical means of providing the Controller with centralised proof of consent.

1.6. Retention periods

WhatPeriod
personal data from verification and authentication requestsnot stored (zero-retention)
one-time challengesuntil used or approximately 300 seconds
technical security and licensing logs (outside the subject matter of the Agreement)90 days

Annex 2. Technical and organisational security measures

2.1. Architectural measures

  1. Origin isolation. Cryptographic operations with the private key are performed inside an iframe loaded from the domain dstucrypt.io, which is different from the Controller's domain. Due to the Same-Origin Policy, the Controller's web resource has no access to the contents of the iframe even if its own code is compromised (including in the event of XSS).
  2. Execution of cryptography on the user's device. A WebAssembly module based on the UAPKI core performs the operations locally; the private key and the password are not transmitted over the network.
  3. Zero-retention. Personal data from verification requests is processed in RAM and is not written to storage.
  4. Domain-based access control. The serving of resources is restricted to licensed domains; the Content-Security-Policy: frame-ancestors directive is applied.
  5. Binding of stored key containers to the host domain — a container stored on one site is inaccessible from another.

2.2. Cryptographic measures

  1. Transmission of data exclusively over a TLS channel.
  2. Encryption of stored key containers: AES-GCM-256.
  3. Derivation of the encryption key: PBKDF2-SHA256, 310,000 iterations, from the PIN code. The PIN is not stored.
  4. Encryption of account data backups at rest.
  5. Support for the national standards: DSTU 4145-2002, DSTU GOST 34.311-95, DSTU 7564:2014 "Kupyna", DSTU 7624:2014 "Kalyna".
  6. One-time challenges with a limited lifetime and protection against reuse.

2.3. Organisational measures

  1. Employee access to systems on the principle of least privilege.
  2. Written non-disclosure obligations of employees and contractors, remaining in force after the relationship ends (Article 10 of the Law).
  3. Keeping of infrastructure access logs.
  4. An internal incident response procedure with defined roles and deadlines.
  5. Regular updating of software components and dependencies.
  6. Backup of configurations and account data with access control over the backups.
  7. Acceptance and handling of vulnerability reports at security@dstucrypt.com.ua; the remediation timeframe is determined by the criticality of the vulnerability.
  8. Periodic assessment of the effectiveness of the technical and organisational measures taken — at least once every 12 months.
  9. A recovery plan for restoring operation after a failure or incident, with defined recovery objectives.
  10. Internal procedures are built with due regard to the Model Procedure for the Processing of Personal Data approved by Order of the Ukrainian Parliament Commissioner for Human Rights No. 1/02-14 of 8 January 2014.

2.4. Measures concerning sub-processors

  1. Assessment of a sub-processor prior to engagement.
  2. Contractual imposition of data protection obligations no less stringent than those in this Agreement.
  3. Maintenance and publication of an up-to-date list.

Annex 3. List of sub-processors

As of 5 August 2026

3.1. Active

Sub-processorFunctionData it has access toCountry of hosting
Provider of server infrastructure hosting services (data centre)hosting of the Service's serverstechnical logs; End Users' personal data at the moment of its processing in RAMUkraine
Qualified trust service providers included in the Trust List — electronic timestamping services (TSP)generation of electronic timestampshash values of dataUkraine
Qualified trust service providers included in the Trust List — OCSP and CRL servicescertificate status checksserial numbers and identifiers of certificatesUkraine

The names of specific sub-processors are provided to the Controller upon written request sent to legal@dstucrypt.com.ua, within 10 business days. The Processor does not publish them for infrastructure security reasons, but ensures that the Controller is able to exercise the right to object provided for in clause 6.5 of this Agreement.

Note on LiqPay / JSC CB "PrivatBank". The payment service processes the data of the Controller (the payer), not of End Users; therefore, with respect to it, Elektronnyi Obih LLC acts as an independent controller. The description is provided in the Privacy Policy, not in this Annex.

Note on the YouSelfBot support service. The support chat widget is a proprietary product of Elektronnyi Obih LLC, not a third-party service, and is not a sub-processor. It has no access to the End Users' personal data processed under this Agreement.

3.2. Planned

The sub-processors listed below are not engaged as of the date of this version and do not process any personal data. They are indicated in advance so that Controllers can take this into account in their own planning. Before processing actually commences, the Processor will send a notification in accordance with clause 6.4 of the Agreement and will update this Annex, specifying the exact composition of the data.

Sub-processorPlanned functionApproximate composition of dataStatus
Ministry of Digital Transformation of Ukraine — Diia, the Unified State Web Portal of Electronic Servicesidentification and signing via state servicesuser identification data — to be specifiedplanned
JSC CB "PrivatBank" — qualified electronic signature servicesadditional methods of applying a signatureuser identification data — to be specifiedplanned

3.3. Currency of the list

The current list of sub-processors is published at https://dstucrypt.com.ua/en/dpa. Controllers wishing to receive notifications of changes shall send a corresponding request to legal@dstucrypt.com.ua.

Requisites and contacts of the Processor

Elektronnyi Obih LLC (ТОВ «електронний Обіг»)

EDRPOU (company code): 46191111 Registered office: 1a Dniprovodska St., office 1, Kyiv, 04077, Ukraine

MatterAddress
This Agreement, objections to sub-processors, auditslegal@dstucrypt.com.ua
Personal data, data subject requestsprivacy@dstucrypt.com.ua
Vulnerability reportssecurity@dstucrypt.com.ua

Related documents

Version dated 5 August 2026.