DSTUcrypt Privacy Policy

Translation notice. This English translation is provided for convenience only. The legally binding text is the Ukrainian original: Політика конфіденційності.

Controller of personal data: Elektronnyi Obih LLC (ТОВ «електронний Обіг»)

EDRPOU (company code): 46191111

Registered office: 1a Dniprovodska St., office 1, Kyiv, 04077, Ukraine

Contact for personal data matters: privacy@dstucrypt.com.ua

Version dated: 7 August 2026

1. What this document is about

1.1. This Policy explains which personal data Elektronnyi Obih LLC (hereinafter — we, the Provider) processes in connection with the operation of the DSTUcrypt service, for what purpose, on what legal basis, how long we retain such data, and what rights the data subject has.

1.2. This Policy has been developed in accordance with the Law of Ukraine "On Personal Data Protection" No. 2297-VI (hereinafter — the Law), the Law of Ukraine "On Information", the Law of Ukraine "On Electronic Communications" No. 1089-IX, and the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108).

1.3. This Policy applies to the website https://dstucrypt.com.ua, the personal account area, the embeddable widgets, and the application programming interfaces (APIs) of the service.

1.4. This Policy does not apply to the web resources of our customers. If you encountered a DSTUcrypt widget on a third-party website, the processing of your data by that website is governed by the privacy policy of its owner.

1.5. Terminology. The Law of Ukraine No. 2297-VI uses the terms "volodilets" (owner) of personal data and "rozporiadnyk" (manager) of personal data. Under Regulation (EU) 2016/679 (GDPR), these correspond to "controller" and "processor" respectively. Hereinafter, this document uses the terms of the Law, rendered in English as "Controller" and "Processor".

2. The two roles in which we act

This is key to understanding everything else. With respect to different categories of data, we have a different status.

RoleWith respect to whose dataWhat this means
Controller of personal dataCustomers — our clients who purchase a subscriptionWe ourselves determine the purpose and scope of processing and are directly accountable to you
Processor of personal dataEnd Users — people who sign documents or log in with a qualified electronic signature (QES) on our customers' websitesWe process the data on the instructions of the customer. The customer, not we, is the Controller

In plain words: if you have purchased a subscription from us, you deal with us directly. If you have signed a document on a third-party website via our widget, the "owner of your data" is that website, and we merely carry out a technical operation on its instructions. You should address your rights requests to it, but we are obliged to assist it in doing so.

2.1. Our relationship with customers regarding the processing of End Users' data is governed by a separate Data Processing Agreement (DPA), available at https://dstucrypt.com.ua/en/dpa.

2.2. An important exception. We keep technical security logs and licence verification logs as a Controller, on the basis of our own legitimate interest, and not on the customer's instructions. These logs do not contain the content of requests, signatures, or information about the identity of the signer. See Section 3 for details.

3. Data we process as a Controller

Category of dataSpecificallyPurposeLegal basis (Article 11 of the Law)Retention period
Identification datae-mail addresscreation and maintenance of an account, passwordless login via a linkconclusion and performance of a transaction to which the data subject is a partyfor the entire life of the account + 3 years (1,095 days) after the last activity
Account session datasession identifier (cookie), IP addressmaintaining the logged-in state of the personal accountperformance of a transactionuntil the session ends or the user logs out of the account
Licence datadomain names, subscription status, start and end dates, paid optionsproviding access to the service, licence controlperformance of a transactionfor the entire subscription term + 3 years (1,095 days)
Payment dataamount, date, status, transaction identifier, masked payment card numberaccounting for payments, refundsperformance of a transaction; compliance with an obligation imposed by law (tax and accounting records)3 years (1,095 days) after the end of the subscription; for primary accounting documents — the periods established by accounting legislation
Communicationscontent of letters and support requests, date, channelhandling requests, confirming arrangementslegitimate interest — handling requests and protecting rights3 years (1,095 days) from the date of the last message
Technical security and licensing logsIP address, date and time of the request, value of the Origin header, domain name, type of operation, response codesecurity, incident investigation, abuse prevention, licence control, diagnosticslegitimate interest — ensuring the security and availability of the service90 days, after which automatic deletion or anonymisation
Customer's name and trademarkcompany name, logomention in the customer list and marketing materialsconsent, given separately (clause 8.4 of the Terms of Use); may be withdrawn at any timeuntil consent is withdrawn

3.1. We do not receive or store full payment card details. Payment is processed on the side of the LiqPay payment service (JSC CB "PrivatBank"). We receive only the result of the transaction and the masked card number.

3.2. We do not use your data for profiling, for automated decision-making that produces legal effects, or for transfer to advertising networks. A customer is mentioned in the customer list only with separately given consent.

3.3. The technical logs specified in the table are kept for all requests to the service, including those originating from the web resources of our customers. These logs do not contain request bodies, electronic signatures, document contents, or information about the identity of the signer.

4. End Users' data: what we process as a Processor

This part concerns people who use DSTUcrypt widgets on our customers' websites.

4.1. What physically reaches our servers

OperationWhich data is receivedWhat happens next
POST /api/auth/verify — login with QESelectronic signature, challenge. The response contains: surname, first name, patronymic; registration number of the taxpayer's record card (RNOKPP, personal tax number); EDRPOU company code; name of the trust service provider; time of signingThe data is processed in RAM, the response is delivered to the customer, after which the data is destroyed
POST /api/verify — authoritative signature verificationelectronic signature in base64 encoding; for a detached signature — also the content of the signed data. The response contains information about the signer, status, format, and timeLikewise: processing in memory, destruction after the response is generated
POST /api/auth/challengeno personal data is transmittedThe generated one-time challenge is stored on the server until it is used or expires (approximately 300 seconds), after which it is destroyed
Timestamping (TSP)hash value of the data being signedtransmitted via our proxy to third-party timestamp providers; the content of the document is not disclosed in the process
Certificate status check (OCSP / CRL)serial number and identifier of the certificatetransmitted via our proxy to the services of qualified trust service providers
sign — applying a signaturenothing except the TSP/OCSP/CRL requests specified abovethe signature is generated in the browser; neither the document nor the key reaches the servers
encrypt, decrypt — encryption and decryptionnothingthe operations are performed entirely on the user's device
cert.inspect — certificate parsingnothingparsing is performed on the user's device
cert.verify — certificate status checkcertificate identifiersrequests to OCSP / CRL services via our proxy
Domain licence verificationdomain name, IP address, Origintechnical log, 90 days — kept by us as a Controller (clause 2.2)

4.2. Non-storage commitment

We do not store the content of requests to POST /api/verify and POST /api/auth/verify. Neither the signature, nor the content of the document, nor the surname, first name and patronymic, nor the RNOKPP (personal tax number), nor the EDRPOU company code is written to databases or log files after the response is generated. This commitment is recorded in the Data Processing Agreement as an obligation of the Provider, not as an advertising claim.

The exceptions are one-time challenges, which contain no personal data, and the technical logs whose composition is defined in Section 3.

4.3. On the RNOKPP specifically

The registration number of the taxpayer's record card (RNOKPP) is a direct identifier of a person. Although the Law does not classify it as a special category of data, we treat it with heightened caution: it is transmitted exclusively over a TLS channel, processed in memory, returned only to the customer that initiated the operation, and is not stored.

5. What we never process

5.1. The private key of the electronic signature. The key container is selected and opened inside an isolated iframe in the user's browser. Cryptographic operations are performed by a WebAssembly module on the user's device.

5.2. The password to the key container. It is entered inside that same iframe.

5.3. The PIN code of the automatic mode. It is not stored anywhere at all — neither on the device nor on the servers.

5.4. Isolation is ensured by the fact that the iframe is loaded from the domain dstucrypt.io, which is different from the host site's domain. Due to the Same-Origin Policy, the host site has no access to the contents of the iframe even if its own code is compromised.

In plain words: your key and password never leave your computer. But the result of the signing and the information about you from the certificate do — otherwise it would be impossible to verify the signature on the server. We store neither of them.

6. Browser local storage and automatic mode

6.1. This section describes the storage of data in the Automatic mode. A description of all other browser data storage technologies — cookies, interface preferences, the support widget — is provided in the Cookie and Local Storage Policy (https://dstucrypt.com.ua/en/cookies).

6.2. The Automatic mode (session) is enabled by the owner of the integrating website. If it is enabled and the user has consented to it in the widget interface:

What is storedWhereHow it is protectedFor how long
Encrypted private key containerlocalStorage of the domain dstucrypt.com.uaAES-GCM-256; the encryption key is derived from the PIN code using PBKDF2-SHA256 with 310,000 iterations. The PIN is not storedup to 30 days
Unlocked "key + password" pairsessionStorage of the tabwithin the browser tab, destroyed when the tab is closedwithin the period set by the integrator (ttlMinutes)
Record of consent to storagelocalStorage of the domain dstucrypt.com.ua—together with the container

6.3. The stored container is strictly bound to the host site's domain: a key stored on site A is inaccessible from site B.

6.4. The data specified in clause 6.2 is not transmitted to our servers and remains on the user's device.

6.5. The user may delete the stored data at any time — via the "forget key" function in the widget (the session.forget() method) or by clearing the site data in the browser settings.

6.6. If the integrator has enabled the mode: 'password' option, only the key file is stored; the password is not stored and is requested every time.

6.7. We provide the interface for obtaining the End User's consent; the legal basis for such processing and the informing of End Users are the responsibility of the website owner as the data Controller.

7. Recipients of data

7.1. We do not sell personal data and do not transfer it for advertising purposes. Data is transferred only to the extent necessary for the operation of the service.

RecipientWhich dataWhyStatus
Provider of server infrastructure hosting services (data centre located in Ukraine)technical logs, account data, as well as End Users' personal data at the moment of its processing in RAM (details — Annex 3 to the DPA)hosting of the server infrastructureactive
Google Ireland Limited (Google Analytics)website visitor's IP address, device and browser type, pages viewed; no signing data and no End User data whatsoevercounting visits to the public pages of the websiteactive
LiqPay / JSC CB "PrivatBank"payment data, amount, e-mail addressaccepting subscription paymentsactive
Qualified trust service providers included in the Trust List (TSP, OCSP, CRL services) — located in Ukrainehash values, serial numbers and identifiers of certificatesgeneration of timestamps, certificate status checksactive
Diia, the Unified State Web Portal of Electronic Serviceshash values of the documents you sign and the request identifier; in the opposite direction — the signature and information about the signersigning and login via Diia.Signatureactive
JSC CB "PrivatBank" — qualified electronic signature services (Smart ID)hash values of the documents you sign and the session identifier; in the opposite direction — the signature and information about the signersigning and login via Smart IDactive
Public authoritieswithin the scope of a lawful demandcompliance with an obligation imposed by lawas required
Legal successor in the event of reorganisation or disposal of the serviceaccounts, licences, payment historyensuring continuity of serviceif it occurs

7.2. We will update this Policy and the list of sub-processors in the DPA before actually commencing work with any integrations marked as "planned". Customers will be notified in advance in the manner set out in clause 6.4 of the DPA.

7.3. With each recipient acting on our instructions, we have concluded an agreement providing for a confidentiality obligation and restricting the processing to our instructions.

7.3.1. The YouSelfBot support service. The support chat widget operating on the website is a proprietary product of Elektronnyi Obih LLC, not a third-party service. The data you provide in the chat — name, contact details, content of the request — as well as technical session data, is processed by us as a Controller within the "Communications" category (Section 3) and is not transferred outside the company.

7.4. Compliance with Article 21 of the Law. Article 21 of the Law obliges the Controller to notify the data subject of the transfer of their data to a third party within ten business days. This Policy serves as the means of such notification: by publishing an exhaustive list of recipients in clause 7.1 and notifying of its changes in the manner set out in Section 13, we inform data subjects of all transfers in advance. We notify the data subject separately, within the stated period, of any transfer of data made in response to an individual demand of a public authority, except where such notification is prohibited by law or could prejudice an investigation.

8. Place of processing and cross-border transfers

8.1. The servers of the DSTUcrypt service are located in Ukraine.

8.2. Customers' personal data and End Users' data received by the verification and authentication endpoints are processed exclusively in Ukraine and are not transferred outside Ukraine.

8.3. The only case of data transfer outside Ukraine is the visit counter for the public pages of the website (Google Analytics). Google Ireland Limited receives the visitor's IP address, device and browser type, and the list of pages viewed; this data may be processed outside Ukraine on the basis of Google's standard contractual clauses. This applies only to browsing the website: nothing is transferred abroad in the course of signing, signature verification, or authentication, and the signing widget contains no counter at all. You can opt out of it using the methods described in Section 7.2 of the Cookie Policy. We carry out no other cross-border transfer of personal data. Requests to the electronic timestamping services (TSP) and certificate status services (OCSP, CRL) are directed to qualified trust service providers included in the Trust List and located in Ukraine. In any event, such requests contain only hash values of data and the serial numbers and identifiers of certificates — not the contents of documents and not information about a person in clear form.

8.4. If in the future it becomes necessary to engage a provider located outside Ukraine, we will ensure compliance with the requirements of Article 29 of the Law, will direct such requests only to states that ensure adequate protection of personal data (member states of the European Economic Area and states parties to Convention ETS No. 108), and will notify customers in the manner set out in clause 6.4 of the DPA.

8.5. We notify customers of any change in the jurisdiction where the servers are hosted in the manner set out in clause 6.4 of the DPA, at least 30 calendar days in advance.

9. Rights of the data subject

9.1. In accordance with Article 8 of the Law, you have the right:

  • to know the sources of collection and the location of your personal data, the purpose of its processing, and the location of the Controller or Processor;
  • to receive information on the conditions of access to personal data, including information on the third parties to whom it is transferred;
  • to access your personal data;
  • to receive, no later than 30 calendar days from the date of receipt of the request, an answer as to whether your data is being processed, and to receive the content of such data;
  • to submit a reasoned demand to the Controller objecting to the processing;
  • to submit a reasoned demand for the amendment or destruction of data if it is processed unlawfully or is inaccurate;
  • to protection against an automated decision that has legal consequences for you;
  • to lodge complaints about the processing of personal data with the Ukrainian Parliament Commissioner for Human Rights or with a court;
  • to apply legal remedies in the event of a breach of personal data protection legislation;
  • to enter reservations concerning the limitation of the right to process your data when giving consent;
  • to withdraw consent to the processing of personal data;
  • to know the mechanism of automatic processing of personal data.

9.2. How to exercise your rights. Send a request to privacy@dstucrypt.com.ua with the subject line "Personal data". State who you are (a customer or a user of a third-party website) and describe the substance of your demand. We respond within 30 calendar days of receipt of the request.

9.3. We may ask for additional information to verify your identity — solely to avoid disclosing data to an unauthorised person.

9.4. If you are an End User of our customer's website: the Controller of your data is that customer. Please contact them. If you contact us, we will forward the request to the relevant customer within 5 business days and provide them with the necessary assistance. Please note: since we do not store data from signature verification requests, in most cases we physically hold no data of yours that could be provided or deleted.

9.5. A complaint regarding the processing of personal data may be lodged with the Ukrainian Parliament Commissioner for Human Rights — the authority supervising compliance with personal data protection legislation (https://ombudsman.gov.ua) — and the actions of the Controller or Processor may also be challenged in court.

10. Security measures

10.1. We apply the following organisational and technical measures:

  • transmission of all data exclusively over a secure TLS channel;
  • architectural isolation of cryptographic operations in a separate origin, making it impossible for the integrating website to access the key and password;
  • processing of End Users' personal data in RAM without writing it to storage;
  • encryption of key containers stored in the browser using the AES-GCM-256 algorithm with key derivation via PBKDF2-SHA256 (310,000 iterations);
  • binding of stored containers to the host site's domain;
  • encryption of account data backups at rest;
  • restriction of employee access to systems on the principle of least privilege;
  • non-disclosure obligations of employees and contractors that remain in force after the relationship ends (Article 10 of the Law);
  • keeping of infrastructure access logs;
  • regular updating of software components and acceptance of vulnerability reports at security@dstucrypt.com.ua;
  • periodic assessment of the effectiveness of the measures taken.

10.2. Our internal personal data processing procedures are built with due regard to the Model Procedure for the Processing of Personal Data approved by Order of the Ukrainian Parliament Commissioner for Human Rights No. 1/02-14 of 8 January 2014.

10.3. No measure provides absolute security. We do not guarantee that unauthorised access is impossible, but we undertake to act in good faith and to respond to incidents promptly.

11. Actions in the event of an incident

11.1. If an incident is detected that has resulted in unauthorised access to, disclosure, alteration, or destruction of personal data, we:

  • immediately take measures to contain and remedy the incident;
  • notify the customers whose data was affected by the incident without undue delay and no later than 72 hours from the moment of detection, in the manner set out in the DPA;
  • provide information on the nature of the incident, its likely consequences, and the measures taken;
  • where there is a high risk to the rights of data subjects, take measures to inform them;
  • cooperate with the Ukrainian Parliament Commissioner for Human Rights within the scope of their powers.

11.2. The 72-hour period has been adopted by us voluntarily as an internal standard. The current Law does not expressly establish such a period.

12. Minors

12.1. With respect to our customers. The personal account and the subscription are intended for business entities. We do not create accounts for persons under the age of 18 and do not knowingly collect their personal data.

12.2. With respect to End Users of the widget. Since a qualified certificate may also be issued to a person under the age of 18, we cannot rule out that such a user may use the widget on our customer's website. We have no technical means of verifying an End User's age. Responsibility for the lawfulness of processing minors' personal data, including obtaining the consent of legal representatives where required, rests with the website owner as the Controller of personal data (clause 12.2 of the DPA).

12.3. If you become aware that a minor's data is being processed by us in breach of the rules, please notify privacy@dstucrypt.com.ua — we will consider the request without delay.

13. Changes to this Policy

13.1. We may update this Policy. The current version is always available at https://dstucrypt.com.ua/en/privacy with the date indicated.

13.2. We notify customers of material changes — in particular, the appearance of new data recipients or new processing purposes — by e-mail at least 10 calendar days before they take effect. A special notice period defined in clause 6.4 of the DPA applies to sub-processors.

13.3. Previous versions are retained and provided upon request.

14. Contacts

Elektronnyi Obih LLC EDRPOU (company code): 46191111 Address: 1a Dniprovodska St., office 1, Kyiv, 04077, Ukraine

MatterAddress
Personal data, data subject rightsprivacy@dstucrypt.com.ua
Vulnerability reportssecurity@dstucrypt.com.ua
Legal matters, DPAlegal@dstucrypt.com.ua
General, commercialsale@dstucrypt.com.ua

The person responsible for organising personal data protection work (Article 24 of the Law) has been designated by an internal company order. Requests to this person are sent to privacy@dstucrypt.com.ua; information about this person is provided upon a substantiated request from a data subject or an authorised public authority.

Supervisory authority: the Ukrainian Parliament Commissioner for Human Rights Website: https://ombudsman.gov.ua

15. Related documents

Version dated 7 August 2026.