Translation notice. This English translation is provided for convenience only. The legally binding text is the Ukrainian original: Політика конфіденційності.
Controller of personal data: Elektronnyi Obih LLC (ТОВ «електронний Обіг»)
EDRPOU (company code): 46191111
Registered office: 1a Dniprovodska St., office 1, Kyiv, 04077, Ukraine
Contact for personal data matters: privacy@dstucrypt.com.ua
Version dated: 7 August 2026
1.1. This Policy explains which personal data Elektronnyi Obih LLC (hereinafter — we, the Provider) processes in connection with the operation of the DSTUcrypt service, for what purpose, on what legal basis, how long we retain such data, and what rights the data subject has.
1.2. This Policy has been developed in accordance with the Law of Ukraine "On Personal Data Protection" No. 2297-VI (hereinafter — the Law), the Law of Ukraine "On Information", the Law of Ukraine "On Electronic Communications" No. 1089-IX, and the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108).
1.3. This Policy applies to the website https://dstucrypt.com.ua, the personal account area, the embeddable widgets, and the application programming interfaces (APIs) of the service.
1.4. This Policy does not apply to the web resources of our customers. If you encountered a DSTUcrypt widget on a third-party website, the processing of your data by that website is governed by the privacy policy of its owner.
1.5. Terminology. The Law of Ukraine No. 2297-VI uses the terms "volodilets" (owner) of personal data and "rozporiadnyk" (manager) of personal data. Under Regulation (EU) 2016/679 (GDPR), these correspond to "controller" and "processor" respectively. Hereinafter, this document uses the terms of the Law, rendered in English as "Controller" and "Processor".
This is key to understanding everything else. With respect to different categories of data, we have a different status.
| Role | With respect to whose data | What this means |
|---|---|---|
| Controller of personal data | Customers — our clients who purchase a subscription | We ourselves determine the purpose and scope of processing and are directly accountable to you |
| Processor of personal data | End Users — people who sign documents or log in with a qualified electronic signature (QES) on our customers' websites | We process the data on the instructions of the customer. The customer, not we, is the Controller |
In plain words: if you have purchased a subscription from us, you deal with us directly. If you have signed a document on a third-party website via our widget, the "owner of your data" is that website, and we merely carry out a technical operation on its instructions. You should address your rights requests to it, but we are obliged to assist it in doing so.
2.1. Our relationship with customers regarding the processing of End Users' data is governed by a separate Data Processing Agreement (DPA), available at https://dstucrypt.com.ua/en/dpa.
2.2. An important exception. We keep technical security logs and licence verification logs as a Controller, on the basis of our own legitimate interest, and not on the customer's instructions. These logs do not contain the content of requests, signatures, or information about the identity of the signer. See Section 3 for details.
| Category of data | Specifically | Purpose | Legal basis (Article 11 of the Law) | Retention period |
|---|---|---|---|---|
| Identification data | e-mail address | creation and maintenance of an account, passwordless login via a link | conclusion and performance of a transaction to which the data subject is a party | for the entire life of the account + 3 years (1,095 days) after the last activity |
| Account session data | session identifier (cookie), IP address | maintaining the logged-in state of the personal account | performance of a transaction | until the session ends or the user logs out of the account |
| Licence data | domain names, subscription status, start and end dates, paid options | providing access to the service, licence control | performance of a transaction | for the entire subscription term + 3 years (1,095 days) |
| Payment data | amount, date, status, transaction identifier, masked payment card number | accounting for payments, refunds | performance of a transaction; compliance with an obligation imposed by law (tax and accounting records) | 3 years (1,095 days) after the end of the subscription; for primary accounting documents — the periods established by accounting legislation |
| Communications | content of letters and support requests, date, channel | handling requests, confirming arrangements | legitimate interest — handling requests and protecting rights | 3 years (1,095 days) from the date of the last message |
| Technical security and licensing logs | IP address, date and time of the request, value of the Origin header, domain name, type of operation, response code | security, incident investigation, abuse prevention, licence control, diagnostics | legitimate interest — ensuring the security and availability of the service | 90 days, after which automatic deletion or anonymisation |
| Customer's name and trademark | company name, logo | mention in the customer list and marketing materials | consent, given separately (clause 8.4 of the Terms of Use); may be withdrawn at any time | until consent is withdrawn |
3.1. We do not receive or store full payment card details. Payment is processed on the side of the LiqPay payment service (JSC CB "PrivatBank"). We receive only the result of the transaction and the masked card number.
3.2. We do not use your data for profiling, for automated decision-making that produces legal effects, or for transfer to advertising networks. A customer is mentioned in the customer list only with separately given consent.
3.3. The technical logs specified in the table are kept for all requests to the service, including those originating from the web resources of our customers. These logs do not contain request bodies, electronic signatures, document contents, or information about the identity of the signer.
This part concerns people who use DSTUcrypt widgets on our customers' websites.
| Operation | Which data is received | What happens next |
|---|---|---|
POST /api/auth/verify — login with QES | electronic signature, challenge. The response contains: surname, first name, patronymic; registration number of the taxpayer's record card (RNOKPP, personal tax number); EDRPOU company code; name of the trust service provider; time of signing | The data is processed in RAM, the response is delivered to the customer, after which the data is destroyed |
POST /api/verify — authoritative signature verification | electronic signature in base64 encoding; for a detached signature — also the content of the signed data. The response contains information about the signer, status, format, and time | Likewise: processing in memory, destruction after the response is generated |
POST /api/auth/challenge | no personal data is transmitted | The generated one-time challenge is stored on the server until it is used or expires (approximately 300 seconds), after which it is destroyed |
| Timestamping (TSP) | hash value of the data being signed | transmitted via our proxy to third-party timestamp providers; the content of the document is not disclosed in the process |
| Certificate status check (OCSP / CRL) | serial number and identifier of the certificate | transmitted via our proxy to the services of qualified trust service providers |
sign — applying a signature | nothing except the TSP/OCSP/CRL requests specified above | the signature is generated in the browser; neither the document nor the key reaches the servers |
encrypt, decrypt — encryption and decryption | nothing | the operations are performed entirely on the user's device |
cert.inspect — certificate parsing | nothing | parsing is performed on the user's device |
cert.verify — certificate status check | certificate identifiers | requests to OCSP / CRL services via our proxy |
| Domain licence verification | domain name, IP address, Origin | technical log, 90 days — kept by us as a Controller (clause 2.2) |
We do not store the content of requests to POST /api/verify and POST /api/auth/verify. Neither the signature, nor the content of the document, nor the surname, first name and patronymic, nor the RNOKPP (personal tax number), nor the EDRPOU company code is written to databases or log files after the response is generated. This commitment is recorded in the Data Processing Agreement as an obligation of the Provider, not as an advertising claim.
The exceptions are one-time challenges, which contain no personal data, and the technical logs whose composition is defined in Section 3.
The registration number of the taxpayer's record card (RNOKPP) is a direct identifier of a person. Although the Law does not classify it as a special category of data, we treat it with heightened caution: it is transmitted exclusively over a TLS channel, processed in memory, returned only to the customer that initiated the operation, and is not stored.
5.1. The private key of the electronic signature. The key container is selected and opened inside an isolated iframe in the user's browser. Cryptographic operations are performed by a WebAssembly module on the user's device.
5.2. The password to the key container. It is entered inside that same iframe.
5.3. The PIN code of the automatic mode. It is not stored anywhere at all — neither on the device nor on the servers.
5.4. Isolation is ensured by the fact that the iframe is loaded from the domain dstucrypt.io, which is different from the host site's domain. Due to the Same-Origin Policy, the host site has no access to the contents of the iframe even if its own code is compromised.
In plain words: your key and password never leave your computer. But the result of the signing and the information about you from the certificate do — otherwise it would be impossible to verify the signature on the server. We store neither of them.
6.1. This section describes the storage of data in the Automatic mode. A description of all other browser data storage technologies — cookies, interface preferences, the support widget — is provided in the Cookie and Local Storage Policy (https://dstucrypt.com.ua/en/cookies).
6.2. The Automatic mode (session) is enabled by the owner of the integrating website. If it is enabled and the user has consented to it in the widget interface:
| What is stored | Where | How it is protected | For how long |
|---|---|---|---|
| Encrypted private key container | localStorage of the domain dstucrypt.com.ua | AES-GCM-256; the encryption key is derived from the PIN code using PBKDF2-SHA256 with 310,000 iterations. The PIN is not stored | up to 30 days |
| Unlocked "key + password" pair | sessionStorage of the tab | within the browser tab, destroyed when the tab is closed | within the period set by the integrator (ttlMinutes) |
| Record of consent to storage | localStorage of the domain dstucrypt.com.ua | — | together with the container |
6.3. The stored container is strictly bound to the host site's domain: a key stored on site A is inaccessible from site B.
6.4. The data specified in clause 6.2 is not transmitted to our servers and remains on the user's device.
6.5. The user may delete the stored data at any time — via the "forget key" function in the widget (the session.forget() method) or by clearing the site data in the browser settings.
6.6. If the integrator has enabled the mode: 'password' option, only the key file is stored; the password is not stored and is requested every time.
6.7. We provide the interface for obtaining the End User's consent; the legal basis for such processing and the informing of End Users are the responsibility of the website owner as the data Controller.
7.1. We do not sell personal data and do not transfer it for advertising purposes. Data is transferred only to the extent necessary for the operation of the service.
| Recipient | Which data | Why | Status |
|---|---|---|---|
| Provider of server infrastructure hosting services (data centre located in Ukraine) | technical logs, account data, as well as End Users' personal data at the moment of its processing in RAM (details — Annex 3 to the DPA) | hosting of the server infrastructure | active |
| Google Ireland Limited (Google Analytics) | website visitor's IP address, device and browser type, pages viewed; no signing data and no End User data whatsoever | counting visits to the public pages of the website | active |
| LiqPay / JSC CB "PrivatBank" | payment data, amount, e-mail address | accepting subscription payments | active |
| Qualified trust service providers included in the Trust List (TSP, OCSP, CRL services) — located in Ukraine | hash values, serial numbers and identifiers of certificates | generation of timestamps, certificate status checks | active |
| Diia, the Unified State Web Portal of Electronic Services | hash values of the documents you sign and the request identifier; in the opposite direction — the signature and information about the signer | signing and login via Diia.Signature | active |
| JSC CB "PrivatBank" — qualified electronic signature services (Smart ID) | hash values of the documents you sign and the session identifier; in the opposite direction — the signature and information about the signer | signing and login via Smart ID | active |
| Public authorities | within the scope of a lawful demand | compliance with an obligation imposed by law | as required |
| Legal successor in the event of reorganisation or disposal of the service | accounts, licences, payment history | ensuring continuity of service | if it occurs |
7.2. We will update this Policy and the list of sub-processors in the DPA before actually commencing work with any integrations marked as "planned". Customers will be notified in advance in the manner set out in clause 6.4 of the DPA.
7.3. With each recipient acting on our instructions, we have concluded an agreement providing for a confidentiality obligation and restricting the processing to our instructions.
7.3.1. The YouSelfBot support service. The support chat widget operating on the website is a proprietary product of Elektronnyi Obih LLC, not a third-party service. The data you provide in the chat — name, contact details, content of the request — as well as technical session data, is processed by us as a Controller within the "Communications" category (Section 3) and is not transferred outside the company.
7.4. Compliance with Article 21 of the Law. Article 21 of the Law obliges the Controller to notify the data subject of the transfer of their data to a third party within ten business days. This Policy serves as the means of such notification: by publishing an exhaustive list of recipients in clause 7.1 and notifying of its changes in the manner set out in Section 13, we inform data subjects of all transfers in advance. We notify the data subject separately, within the stated period, of any transfer of data made in response to an individual demand of a public authority, except where such notification is prohibited by law or could prejudice an investigation.
8.1. The servers of the DSTUcrypt service are located in Ukraine.
8.2. Customers' personal data and End Users' data received by the verification and authentication endpoints are processed exclusively in Ukraine and are not transferred outside Ukraine.
8.3. The only case of data transfer outside Ukraine is the visit counter for the public pages of the website (Google Analytics). Google Ireland Limited receives the visitor's IP address, device and browser type, and the list of pages viewed; this data may be processed outside Ukraine on the basis of Google's standard contractual clauses. This applies only to browsing the website: nothing is transferred abroad in the course of signing, signature verification, or authentication, and the signing widget contains no counter at all. You can opt out of it using the methods described in Section 7.2 of the Cookie Policy. We carry out no other cross-border transfer of personal data. Requests to the electronic timestamping services (TSP) and certificate status services (OCSP, CRL) are directed to qualified trust service providers included in the Trust List and located in Ukraine. In any event, such requests contain only hash values of data and the serial numbers and identifiers of certificates — not the contents of documents and not information about a person in clear form.
8.4. If in the future it becomes necessary to engage a provider located outside Ukraine, we will ensure compliance with the requirements of Article 29 of the Law, will direct such requests only to states that ensure adequate protection of personal data (member states of the European Economic Area and states parties to Convention ETS No. 108), and will notify customers in the manner set out in clause 6.4 of the DPA.
8.5. We notify customers of any change in the jurisdiction where the servers are hosted in the manner set out in clause 6.4 of the DPA, at least 30 calendar days in advance.
9.1. In accordance with Article 8 of the Law, you have the right:
9.2. How to exercise your rights. Send a request to privacy@dstucrypt.com.ua with the subject line "Personal data". State who you are (a customer or a user of a third-party website) and describe the substance of your demand. We respond within 30 calendar days of receipt of the request.
9.3. We may ask for additional information to verify your identity — solely to avoid disclosing data to an unauthorised person.
9.4. If you are an End User of our customer's website: the Controller of your data is that customer. Please contact them. If you contact us, we will forward the request to the relevant customer within 5 business days and provide them with the necessary assistance. Please note: since we do not store data from signature verification requests, in most cases we physically hold no data of yours that could be provided or deleted.
9.5. A complaint regarding the processing of personal data may be lodged with the Ukrainian Parliament Commissioner for Human Rights — the authority supervising compliance with personal data protection legislation (https://ombudsman.gov.ua) — and the actions of the Controller or Processor may also be challenged in court.
10.1. We apply the following organisational and technical measures:
10.2. Our internal personal data processing procedures are built with due regard to the Model Procedure for the Processing of Personal Data approved by Order of the Ukrainian Parliament Commissioner for Human Rights No. 1/02-14 of 8 January 2014.
10.3. No measure provides absolute security. We do not guarantee that unauthorised access is impossible, but we undertake to act in good faith and to respond to incidents promptly.
11.1. If an incident is detected that has resulted in unauthorised access to, disclosure, alteration, or destruction of personal data, we:
11.2. The 72-hour period has been adopted by us voluntarily as an internal standard. The current Law does not expressly establish such a period.
12.1. With respect to our customers. The personal account and the subscription are intended for business entities. We do not create accounts for persons under the age of 18 and do not knowingly collect their personal data.
12.2. With respect to End Users of the widget. Since a qualified certificate may also be issued to a person under the age of 18, we cannot rule out that such a user may use the widget on our customer's website. We have no technical means of verifying an End User's age. Responsibility for the lawfulness of processing minors' personal data, including obtaining the consent of legal representatives where required, rests with the website owner as the Controller of personal data (clause 12.2 of the DPA).
12.3. If you become aware that a minor's data is being processed by us in breach of the rules, please notify privacy@dstucrypt.com.ua — we will consider the request without delay.
13.1. We may update this Policy. The current version is always available at https://dstucrypt.com.ua/en/privacy with the date indicated.
13.2. We notify customers of material changes — in particular, the appearance of new data recipients or new processing purposes — by e-mail at least 10 calendar days before they take effect. A special notice period defined in clause 6.4 of the DPA applies to sub-processors.
13.3. Previous versions are retained and provided upon request.
Elektronnyi Obih LLC EDRPOU (company code): 46191111 Address: 1a Dniprovodska St., office 1, Kyiv, 04077, Ukraine
| Matter | Address |
|---|---|
| Personal data, data subject rights | privacy@dstucrypt.com.ua |
| Vulnerability reports | security@dstucrypt.com.ua |
| Legal matters, DPA | legal@dstucrypt.com.ua |
| General, commercial | sale@dstucrypt.com.ua |
The person responsible for organising personal data protection work (Article 24 of the Law) has been designated by an internal company order. Requests to this person are sent to privacy@dstucrypt.com.ua; information about this person is provided upon a substantiated request from a data subject or an authorised public authority.
Supervisory authority: the Ukrainian Parliament Commissioner for Human Rights Website: https://ombudsman.gov.ua
Version dated 7 August 2026.