Translation notice. This English translation is provided for convenience only. The legally binding text is the Ukrainian original: Угода про обробку персональних даних.
DSTUcrypt service
Version dated: 5 August 2026
Effective from: 5 August 2026
Published at: https://dstucrypt.com.ua/en/dpa
This Data Processing Agreement (hereinafter — the Agreement, the DPA) is concluded between:
Elektronnyi Obih LLC (ТОВ «електронний Обіг») (EDRPOU company code 46191111, registered office: 1a Dniprovodska St., office 1, Kyiv, 04077, Ukraine), hereinafter — the Processor,
and
the person using the DSTUcrypt service on the basis of the Terms of Use and the Public Offer, hereinafter — the Controller,
together — the Parties.
The Agreement is an integral part of the Terms of Use of the DSTUcrypt service (https://dstucrypt.com.ua/en/terms) and is concluded by way of the Controller's accession to it in accordance with Article 634 of the Civil Code of Ukraine. Accession takes place at the moment the Controller begins to use the functions of the service that involve the transmission of End Users' personal data to the Processor's servers.
The Agreement is concluded in fulfilment of the requirements of the Law of Ukraine "On Personal Data Protection" No. 2297-VI (hereinafter — the Law), in particular Articles 4, 6, 10, 11, 16, 21, 24 and 29, and with due regard to the approaches laid down in Regulation (EU) 2016/679 (GDPR), for the benefit of Controllers to whom it applies.
In plain words: when your user signs a document or logs in with a qualified electronic signature (QES) on your website via our widget, their surname, first name, patronymic, and RNOKPP (personal tax number) physically pass through our servers. The owner of that data is you. We merely perform a technical operation on your instructions. This document records exactly what we are obliged to do with that data — and what we have no right to do.
Personal data — information about a natural person who is identified or can be specifically identified, within the meaning of Article 2 of the Law.
The Customer — has the meaning defined in the Terms of Use of the DSTUcrypt service.
Controller of personal data (Controller) — the Customer, who determines the purpose of processing End Users' personal data, the composition of that data, and the procedures for its processing. In GDPR terminology — the controller.
Processor of personal data (Processor) — Elektronnyi Obih LLC, which processes personal data on behalf of and on the instructions of the Controller. In GDPR terminology — the processor.
End User (Data Subject) — a natural person who interacts with the widgets of the DSTUcrypt service on the Controller's web resource.
Service — the DSTUcrypt software suite as defined in the Terms of Use.
Processing — any action or set of actions performed on personal data, including collection, registration, accumulation, storage, adaptation, alteration, updating, use, dissemination, anonymisation, and destruction.
Sub-processor — a third party engaged by the Processor to process End Users' personal data. In GDPR terminology — a sub-processor.
Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Zero-retention — a processing mode in which the content of signature verification and authentication requests, electronic signatures, the content of signed data, and the information about the signer's identity obtained from certificates are processed exclusively in RAM for the duration of an individual operation and are destroyed immediately after the response is generated, without being written to databases, file storage, or logs. The zero-retention mode does not apply to technical security and licensing logs (clause 5.2) or to one-time challenges, the composition and retention periods of which are defined in Annex 1.
2.1. With respect to the personal data of End Users transmitted to the Processor's servers in connection with the use of the Service, the Controller acts as the controller of personal data, and the Processor acts as the processor of personal data.
2.2. With respect to the personal data of the Controller itself (e-mail address, domain names, payment data, personal account session data), the Processor acts as an independent controller. These relations are governed by the Privacy Policy (https://dstucrypt.com.ua/en/privacy), not by this Agreement.
2.3. With respect to technical security and licensing logs — records containing the IP address, the date and time of the request, the value of the Origin header, the domain name, the type of operation, and the response code — the Processor acts as an independent controller on the basis of its own legitimate interest in ensuring the security and availability of the Service and in licence control. Such logs are not the subject matter of this Agreement; the procedure for their processing is defined in the Privacy Policy. The logs do not contain request bodies, electronic signatures, document contents, or information about the identity of the signer.
2.4. The Processor does not determine the purposes and means of processing End Users' personal data and does not use such data for its own purposes.
2.5. If the Processor exceeds the scope of the Controller's instructions and begins to independently determine the purpose of processing, it shall, to that extent, be deemed a controller and shall bear the corresponding liability.
3.1. Subject matter of processing — the personal data of End Users contained in electronic signatures, public key certificates, and signed data.
3.2. Nature of processing — automated processing in RAM for the purpose of performing cryptographic operations: verifying the integrity of an electronic signature, establishing the status of the signer's certificate, confirming identity by electronic signature, and generating electronic timestamps.
3.3. Purpose of processing — providing the Controller with the technical capability to apply and verify electronic signatures and to authenticate End Users on its own web resource.
3.4. Duration of processing — processing lasts exclusively for the duration of an individual operation. Processing as a service is carried out for the duration of the subscription of the Controller (the Customer).
3.5. A detailed description of the processing is set out in Annex 1 to this Agreement.
4.1. The Processor processes personal data exclusively on the documented instructions of the Controller.
4.2. The following are deemed the Controller's documented instructions:
4.2.1. this Agreement and the Terms of Use;
4.2.2. the technical documentation of the Service, published at https://dstucrypt.com.ua/docs.html, in the version in force at the time the respective call is made. The Processor retains previous versions of the documentation and provides them to the Controller upon written request within 10 business days;
4.2.3. actual calls to the Service's methods initiated from the Controller's Licensed Domain, including by End Users' browsers; each such call is deemed a separate instruction of the Controller to perform the respective operation;
4.2.4. written instructions of the Controller sent to legal@dstucrypt.com.ua and accepted by the Processor.
4.3. The Processor processes personal data outside the Controller's instructions only where required by the legislation of Ukraine. In such a case, the Processor notifies the Controller of that requirement before commencing the processing, unless such notification is prohibited by law.
4.4. The Processor immediately informs the Controller if, in its opinion, an instruction received contravenes personal data protection legislation, and has the right to suspend the execution of such an instruction until the circumstances are clarified.
The Processor undertakes:
5.1. Not to store personal data. The Processor processes End Users' personal data in zero-retention mode. In particular, the Processor does not write to databases, file storage, or logs:
POST /api/verify and POST /api/auth/verify;content parameter;The data listed above is destroyed immediately after the response to the respective request is generated.
5.2. To limit service logs. The Processor keeps technical logs containing exclusively: the source IP address of the request, the date and time, the value of the Origin header, the domain name, the type of operation, and the response code. The logs do not contain request bodies and do not contain the data specified in clause 5.1. The retention period of the logs is 90 days, after which they are automatically deleted or anonymised. With respect to these logs, the Processor acts as an independent controller in accordance with clause 2.3 of this Agreement.
5.3. To ensure confidentiality. In accordance with Article 10 of the Law, the Processor ensures that persons authorised to process personal data have committed themselves to confidentiality, such commitment remaining in force after the termination of the employment or contractual relationship.
5.4. To apply security measures. The Processor implements the technical and organisational measures set out in Annex 2 to this Agreement.
5.5. Not to transfer data to third parties otherwise than in the manner set out in Section 6 of this Agreement or in compliance with a lawful demand of an authorised body.
5.6. To assist the Controller in fulfilling its obligations, in particular in responding to data subjects' requests (Section 7) and in ensuring the security of processing.
5.7. To provide information necessary to demonstrate compliance with this Agreement, in the manner set out in Section 9.
5.8. To notify of Incidents in the manner set out in Section 8.
5.9. To limit cross-border transfers to the cases set out in Section 10.
6.1. The Controller grants the Processor a general authorisation to engage sub-processors, subject to compliance with this Section.
6.2. The Processor:
6.2.1. concludes with each sub-processor an agreement imposing on it data protection obligations no less stringent than those provided for in this Agreement; 6.2.2. remains fully liable to the Controller for the acts and omissions of sub-processors as for its own; 6.2.3. engages only those sub-processors that provide sufficient guarantees of the implementation of appropriate technical and organisational measures.
6.3. The current list of sub-processors is set out in Annex 3 to this Agreement and is kept up to date at https://dstucrypt.com.ua/en/dpa.
6.4. Procedure for changing the list. The Processor notifies the Controller of its intention to engage a new sub-processor, to replace an existing one, or to change the jurisdiction where the servers are hosted, by e-mail and by updating Annex 3, at least 30 calendar days before the commencement of processing by such sub-processor or before the change of jurisdiction.
6.5. Right to object. The Controller has the right, within 15 calendar days from the date of receipt of the notification, to send a reasoned objection to legal@dstucrypt.com.ua. The Parties shall seek an acceptable solution in good faith. If no solution is found, the Controller has the right to terminate the contract with respect to the relevant function or in its entirety. Refunds for the unused period are made in the manner set out in the Refund Policy (https://dstucrypt.com.ua/en/refund); for the purposes of this clause, such termination is treated as termination of the contract for reasons attributable to the Processor.
7.1. The rights of personal data subjects provided for in Article 8 of the Law are exercised vis-à-vis the Controller as the person determining the purpose of processing.
7.2. If an End User contacts the Processor directly, the Processor:
7.2.1. does not respond to the substance of the request on its own; 7.2.2. forwards the request to the Controller without delay, and no later than within 5 business days, provided the Controller can be identified; 7.2.3. informs the requester of the forwarding.
7.3. The Processor provides the Controller with reasonable assistance in responding to a data subject's request — taking into account the nature of the processing and the information available to the Processor.
7.4. The Parties acknowledge a factual limitation: since the Processor operates in zero-retention mode, it generally holds no personal data of End Users that could be provided, amended, or destroyed in response to a data subject's demand. This limitation is a consequence of the Service's architecture and enhances the level of data protection.
7.5. The assistance under clause 7.3 is provided free of charge, except where the volume of the Controller's requests is manifestly excessive; in such a case, the Parties agree the cost separately.
8.1. If an Incident concerning End Users' personal data is detected, the Processor notifies the Controller without undue delay, and no later than 72 hours from the moment of detection.
8.2. The notification is sent to the Controller's e-mail address specified in the personal account and contains, to the extent known at the time of notification:
8.3. Where it is impossible to provide all the information at the same time, it is provided in phases without undue delay.
8.4. The Processor documents all Incidents and the measures taken and provides this documentation to the Controller upon request.
8.5. The obligation to notify the supervisory authority and the data subjects, should such an obligation arise, rests with the Controller as the person determining the purpose of processing. The Processor provides the necessary assistance for this.
9.1. Upon written request, the Processor provides the Controller with the information necessary to demonstrate compliance with the obligations under this Agreement.
9.2. The Controller has the right to conduct an audit of compliance with the Agreement no more than once every 12 months, except where the audit is conducted following an Incident or at the demand of an authorised public authority.
9.3. An audit is conducted subject to:
9.3.1. written notice of at least 30 calendar days; 9.3.2. agreement by the Parties on the scope, timing, and procedure; 9.3.3. signature by the auditors of a non-disclosure undertaking; 9.3.4. non-disruption of the operation of the Service and preservation of the confidentiality of the data of the Processor's other clients.
9.4. The Processor has the right to satisfy an audit request by providing a current report of an independent auditor, a certificate of compliance, or a completed security questionnaire, provided such documents reasonably cover the subject of the audit.
9.5. The costs of conducting the audit are borne by the Controller, except where the audit reveals a material breach of the Agreement by the Processor.
10.1. The processing of End Users' personal data is carried out on servers located in Ukraine.
10.2. The content of requests to the signature verification and authentication endpoints, electronic signatures, document contents, and information about the signer's identity are not transferred outside Ukraine.
10.3. No cross-border transfer takes place. Technical requests to the electronic timestamping services (TSP) and certificate status services (OCSP, CRL) are directed exclusively to qualified trust service providers included in the Trust List and located in Ukraine. In any event, such requests contain only hash values of data and the serial numbers and identifiers of certificates — not the contents of documents and not information about a person in clear form.
10.4. The list of sub-processors, indicating the country of hosting, is set out in Annex 3.
10.5. Should a need for a cross-border transfer of personal data arise, the Processor:
10.5.1. ensures compliance with the requirements of Article 29 of the Law and directs such requests only to states that ensure adequate protection of personal data — member states of the European Economic Area and states parties to Convention ETS No. 108; 10.5.2. for Controllers subject to the GDPR, applies standard contractual clauses or another appropriate transfer mechanism; 10.5.3. notifies the Controller in the manner set out in clause 6.4, at least 30 calendar days in advance.
11.1. The Agreement enters into force at the moment of the Controller's accession and remains in force for the duration of its use of the Service.
11.2. After the provision of services ends, the Processor, at the Controller's choice, returns or destroys all End Users' personal data in its possession and destroys existing copies, except where a retention obligation is established by the legislation of Ukraine. If the Controller has not communicated its choice within 30 calendar days from the date of termination, the data is destroyed.
11.3. The Parties acknowledge that, given the zero-retention mode (clause 5.1), the Processor generally holds no personal data of End Users that would be subject to return or destruction. Technical logs are deleted automatically upon the expiry of 90 days.
11.4. Upon the Controller's written request, the Processor provides confirmation of compliance with clause 11.2 within 30 calendar days.
11.5. Clause 5.3 and Sections 8, 9, 10, 11, and 12 survive the termination of the Agreement.
12.1. Each Party is liable for breaches of personal data protection legislation within the scope of its own obligations as defined by this Agreement and the Law.
12.2. The Controller is solely responsible for:
12.2.1. the existence of a legal basis for the processing of End Users' personal data; 12.2.2. informing End Users about the processing, including the transfer of data to the Processor, as well as fulfilling the obligation under Article 21 of the Law to notify data subjects of the transfer of their data to third parties; 12.2.3. the lawfulness and legitimacy of its instructions; 12.2.4. the correct configuration of the Service on its web resource, including the decision to enable the Automatic mode (session) and the informing of End Users about such storage; 12.2.5. the lawfulness of processing the personal data of minor End Users, including obtaining the consent of legal representatives where required.
12.3. The Processor's aggregate liability under this Agreement is limited to the amount defined in clause 12.1 of the Terms of Use. This limitation does not apply to:
12.3.1. intentional breaches and gross negligence of the Processor; 12.3.2. amounts recovered from the Controller by a supervisory authority or a court as a result of a proven breach of this Agreement by the Processor; 12.3.3. cases where a limitation of liability is prohibited by mandatory provisions of law.
12.4. The Controller compensates the Processor for documented losses caused by the Controller's breach of clause 12.2.
13.1. The Agreement is governed by the substantive law of Ukraine.
13.2. In the event of a conflict between this Agreement and the Terms of Use on matters of personal data processing, this Agreement prevails, except for matters of liability, which are governed by clause 12.3 of this Agreement in conjunction with Section 12 of the Terms of Use.
13.3. The Processor has the right to amend the Agreement in the manner set out in Section 14 of the Terms of Use. Amendments that reduce the level of personal data protection do not apply to the Controller without its express consent.
13.4. A Controller requiring a signed copy of the Agreement on paper or with a qualified electronic signature applied shall send a request to legal@dstucrypt.com.ua.
13.5. Annexes 1, 2, and 3 are integral parts of the Agreement.
| Category | Composition |
|---|---|
| Identification data from the certificate | surname, first name, patronymic (fullName) |
| Tax identifiers | registration number of the taxpayer's record card, RNOKPP (personal tax number) (taxId) |
| Legal entity data | EDRPOU company code (orgCode), name of the organisation (signerOrg) |
| Certificate data | certificate identifier (signerCertId), issuer (issuer), indication of the provider's inclusion in the Trust List (accredited, qualified), revocation status (ocspStatus, crlStatus) |
| Operation data | time of signing (signingTime), timestamp time (timestampTime), signature format |
| Document content | the content of the signed data — only in the case of verification of a detached signature, where the Controller passes the content parameter |
Technical request data (IP address, Origin, date and time) does not fall within the subject matter of this Agreement — it is processed by the Processor as an independent controller in accordance with clause 2.3 of the Agreement.
The processing of special categories of personal data within the meaning of Article 7 of the Law (racial or ethnic origin, political, religious or ideological beliefs, membership of political parties and trade unions, state of health, sexual life, biometric and genetic data, criminal or administrative liability) is not envisaged.
The Controller undertakes not to transmit such data to the Service. If the nature of the Controller's documents implies the presence of special categories of data in their content, the Controller is obliged not to use server-side verification of a detached signature with transmission of the content parameter, and instead to use verification of an attached signature or browser-side verification via the widget's verify() method. This does not remove the requirement of clause 6.3 of the Terms of Use regarding authentication under the server-to-server scheme.
| Operation | What is transmitted to the Processor | Result | Storage |
|---|---|---|---|
POST /api/auth/verify | signature, challenge | confirmed identity: full name, RNOKPP (personal tax number), EDRPOU company code, provider, status | not stored |
POST /api/verify (attached) | signature in base64 | signature status, information about the signers | not stored |
POST /api/verify (detached) | signature + data content (content) | signature status, information about the signers | not stored |
POST /api/auth/challenge | no personal data is transmitted | one-time challenge | the challenge is stored until it is used or expires (approximately 300 seconds) |
sign — applying a signature | nothing except TSP/OCSP/CRL requests | the signature is generated in the browser | not stored |
encrypt, decrypt | nothing — the operations are performed entirely on the user's device | encrypted or decrypted data | — |
cert.inspect — certificate parsing | nothing — performed on the user's device | certificate structure | — |
cert.verify — certificate status | serial number and identifier of the certificate | status | not stored |
| TSP proxy | hash value of the data | electronic timestamp | not stored |
| OCSP / CRL proxy | certificate identifiers | certificate status | not stored |
GET /api/license, GET /api/licensed | domain name, IP, Origin | licence status | technical log, 90 days — processed by the Processor as an independent controller (clause 2.3) |
The following is not processing on the Processor's side, but is described for completeness:
| Data | Location | Protection | Period |
|---|---|---|---|
| encrypted private key container | localStorage of the domain dstucrypt.com.ua | AES-GCM-256, key derived from the PIN via PBKDF2-SHA256 (310,000 iterations), bound to the host domain | up to 30 days |
| unlocked "key + password" pair | sessionStorage of the tab | within the tab | ttlMinutes, set by the Controller |
| record of consent to storage | localStorage of the domain dstucrypt.com.ua | — | together with the container |
| PIN code | not stored | — | — |
| private key and password in clear form | browser RAM | — | duration of the operation |
The decision to enable the Automatic mode is made by the Controller.
Allocation of consent obligations. The Processor ensures that the widget displays an interface for obtaining the End User's consent to the storage of the key container and records the fact of such consent locally, in the localStorage of the user's device. The legal basis for such processing, as well as the informing of End Users about the enabling of the Automatic mode, is the responsibility of the Controller. Since the record of consent is stored exclusively on the user's device, the Processor has no technical means of providing the Controller with centralised proof of consent.
| What | Period |
|---|---|
| personal data from verification and authentication requests | not stored (zero-retention) |
| one-time challenges | until used or approximately 300 seconds |
| technical security and licensing logs (outside the subject matter of the Agreement) | 90 days |
dstucrypt.io, which is different from the Controller's domain. Due to the Same-Origin Policy, the Controller's web resource has no access to the contents of the iframe even if its own code is compromised (including in the event of XSS).Content-Security-Policy: frame-ancestors directive is applied.As of 5 August 2026
| Sub-processor | Function | Data it has access to | Country of hosting |
|---|---|---|---|
| Provider of server infrastructure hosting services (data centre) | hosting of the Service's servers | technical logs; End Users' personal data at the moment of its processing in RAM | Ukraine |
| Qualified trust service providers included in the Trust List — electronic timestamping services (TSP) | generation of electronic timestamps | hash values of data | Ukraine |
| Qualified trust service providers included in the Trust List — OCSP and CRL services | certificate status checks | serial numbers and identifiers of certificates | Ukraine |
The names of specific sub-processors are provided to the Controller upon written request sent to legal@dstucrypt.com.ua, within 10 business days. The Processor does not publish them for infrastructure security reasons, but ensures that the Controller is able to exercise the right to object provided for in clause 6.5 of this Agreement.
Note on LiqPay / JSC CB "PrivatBank". The payment service processes the data of the Controller (the payer), not of End Users; therefore, with respect to it, Elektronnyi Obih LLC acts as an independent controller. The description is provided in the Privacy Policy, not in this Annex.
Note on the YouSelfBot support service. The support chat widget is a proprietary product of Elektronnyi Obih LLC, not a third-party service, and is not a sub-processor. It has no access to the End Users' personal data processed under this Agreement.
The sub-processors listed below are not engaged as of the date of this version and do not process any personal data. They are indicated in advance so that Controllers can take this into account in their own planning. Before processing actually commences, the Processor will send a notification in accordance with clause 6.4 of the Agreement and will update this Annex, specifying the exact composition of the data.
| Sub-processor | Planned function | Approximate composition of data | Status |
|---|---|---|---|
| Ministry of Digital Transformation of Ukraine — Diia, the Unified State Web Portal of Electronic Services | identification and signing via state services | user identification data — to be specified | planned |
| JSC CB "PrivatBank" — qualified electronic signature services | additional methods of applying a signature | user identification data — to be specified | planned |
The current list of sub-processors is published at https://dstucrypt.com.ua/en/dpa. Controllers wishing to receive notifications of changes shall send a corresponding request to legal@dstucrypt.com.ua.
Elektronnyi Obih LLC (ТОВ «електронний Обіг»)
EDRPOU (company code): 46191111 Registered office: 1a Dniprovodska St., office 1, Kyiv, 04077, Ukraine
| Matter | Address |
|---|---|
| This Agreement, objections to sub-processors, audits | legal@dstucrypt.com.ua |
| Personal data, data subject requests | privacy@dstucrypt.com.ua |
| Vulnerability reports | security@dstucrypt.com.ua |
Version dated 5 August 2026.