Privacy Policy

Last updated: August 28, 2026

This Privacy and Personal Data Protection Policy (the “Policy”) explains what data we may process when you use the ESG SaveEcoBot website, public pages, account area, API, official integrations and other system interfaces, why we need it and what rights the user has.

We process data to the extent necessary to operate the system, perform the Public License Agreement, ensure security and comply with the laws of Ukraine. If you do not agree with this Policy, stop using the relevant service.

1. Who is responsible for processing data

The personal-data controller is ТОВАРИСТВО З ОБМЕЖЕНОЮ ВІДПОВІДАЛЬНІСТЮ «СИСТЕМА ЕКОЛОГІЧНИХ ДАНИХ» (LIMITED LIABILITY COMPANY “ECOLOGICAL DATA SYSTEM”), EDRPOU code 45681049, registered address: 3 Viktora Nekrasova Street, Kyiv, 04136, Ukraine (the “Licensor” or “we”).

For questions about privacy, access to personal data or withdrawal of consent, contact [email protected].

2. What data we may process

2.1. Data provided by the user

Depending on the feature used, the user may voluntarily provide us with their first name, last name, patronymic, date of birth, details of an authorized company representative, company name and particulars, contact telephone numbers, email address, registered address and other contact details.

We may also process account data, including an email address, telephone number, login, authentication data and other information needed to contact the user, provide access and perform the agreement. Passwords and other secrets must be used only for authentication in the relevant interface and must not be shared with external services.

If the user sends us a message, request, document, file or other information through the available communication channels, we may process its content and the technical information needed to respond, provide support and operate the relevant feature.

2.2. Technical and usage data

While the system is operating, we may automatically process an IP address, cookies, user agent, browser type, software, operating system, device type, individual device identifiers, date and time of access, visited page addresses, the address of the previous page and other technical parameters.

Depending on the request route and security settings, requests may pass through Cloudflare. Cloudflare may process the IP address, request headers, browser and device characteristics, security-event data, and identifiers or cookies necessary for traffic routing and protection.

For system operation, security and auditing, technical request logs may be created, including the time, address or interface of the request, operation, session and request identifiers, status, duration, information about limit usage, errors and summarized technical context. Request parameters may contain an EDRPOU code, record identifiers or other values provided by the user for a search. This also applies to requests through the API and ESG SaveEcoBot MCP when the user has connected that interface.

To monitor compliance with the license condition concerning one automated workplace, we may receive background heartbeat requests from an active browser session. Along with them, limited technical parameters of the browser and device may be processed: platform, available browser information, device mobility, screen and window size, orientation, number of touch points, language, time zone, network connection parameters, tab identifier and other similar parameters. These data are needed to control active sessions and compliance with the one-workplace condition, not to track the user’s activities outside the system.

2.3. Cookies and visit analytics

We may use cookies and similar technologies for authentication, session operation, saving settings, security and the correct operation of pages.

Fathom Analytics, a service for visit analytics, may be used on system pages. Depending on the settings of the relevant page and service, information about page visits, the page address, the address of the previous page, technical characteristics of the browser and device, and page interaction events may be processed. This data is used for aggregated visit statistics, analysis of page performance and service improvement.

2.4. Error diagnostics

To identify and fix technical problems, we may send Sentry technical data about errors, transactions and other diagnostic events. This context may contain an error message, request route or method, HTTP status, request or session identifiers, duration, browser or device data and other information needed to debug a specific situation.

We sanitize diagnostic data and should not send passwords, cookies, OAuth tokens, access keys or other secrets to Sentry. However, technical context may be associated with a particular account, session or request if this is necessary to determine the cause of an error.

2.5. Enterprise and document data

When searching or viewing information, the user may provide an EDRPOU code, enterprise name, keywords and record identifiers. The system may process and return data about enterprises, their addresses, permits, licenses, reports, documents, registries, inspections, ESG indicators and other related data. This information may be public data or data about legal entities and does not become the user’s personal data merely because the user performed a search.

If the user provides us with personal data of third parties, the user confirms that they have a lawful basis for doing so. Such data may be processed within the relevant purpose and this Policy.

3. Why we use data

  • register and maintain the account, account area and access to the system;
  • identify the user and verify authentication, plan, permissions and availability of individual features;
  • execute user requests and provide data, documents and technical support;
  • accept and process payments, keep records and perform contractual, tax and accounting obligations;
  • account for views, documents, limits, sessions and other actions in accordance with the plan and the Public License Agreement;
  • monitor compliance with the one-automated-workplace condition and prevent simultaneous use of access in breach of the license;
  • protect the system from unauthorized access, mass requests, fraud and other abuse;
  • analyze page visits using Fathom Analytics and improve service quality;
  • identify and fix errors using technical diagnostics, including Sentry;
  • contact the user, send service messages and, where there is an appropriate basis, informational or marketing materials;
  • comply with the law, respond to lawful requests and protect our rights;
  • operate official APIs, integrations and other connected interfaces when the user uses them.

4. Legal bases for processing

Depending on the situation, processing may be based on the need to perform the Public License Agreement or provide the requested feature, the user’s consent, a legal obligation, or our legitimate interest in ensuring security, preventing abuse, keeping records, performing technical diagnostics and improving the service.

Acceptance of the agreement, registration, use of the system, completion of a form, checking a consent box or another action by which the user grants permission may confirm consent to the relevant processing where consent is required by law. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

5. Who may receive data

To the extent necessary for the operation of the system and in accordance with the law, data may be provided to:

  • providers of hosting, server and cloud infrastructure, data storage, email, payments, technical support and security services that act within the granted authority;
  • WayForPay or another payment provider — for processing online payments, payment status and related transaction information;
  • Cloudflare — for traffic proxying, caching, DDoS protection, WAF, bot protection and other infrastructure and security functions;
  • Fathom Analytics — for aggregated page-visit analytics, if this service is enabled for the relevant page;
  • Sentry — for error monitoring, technical diagnostics and problem resolution;
  • government bodies, courts, law-enforcement and other authorized bodies in the cases and manner provided by law;
  • other persons if the user has directly asked us to transmit the data or has given consent to it;
  • an external client, API integration or other connected interface, including ESG SaveEcoBot MCP, which the user has selected and authorized — only within the particular request and granted rights.

An external AI client or other provider may have its own terms for storing, analyzing and using data. After data is transferred outside ESG SaveEcoBot, its further processing is governed by the provider’s policy, which the user must review before connecting.

6. Retention periods

We retain data no longer than necessary for the relevant purpose, account operation, performance of the agreement, security, technical diagnostics, auditing, dispute resolution and compliance with the laws of Ukraine. The period may depend on the category of data, plan terms and settings of the relevant service.

Session, technical-request, limit-usage and error records may be retained after an individual session ends for auditing, monitoring license conditions, security and protection of rights. After receiving a valid notice of withdrawal of consent, processing is stopped and data is deleted unless further retention is necessary under the law, agreement, security requirements or protection of rights.

7. Security

We apply technical and organizational measures to protect data, including access control, secure authentication, permission checks, parameter sanitization, session controls, request-rate limits, event logging and restrictions on staff access. No method of transmitting or storing data can guarantee absolute security, so please report suspicious events as soon as possible.

8. Transfers outside Ukraine

Some providers of infrastructure, analytics, diagnostics or external clients may process data in other countries. In such cases, we seek to apply appropriate contractual, technical and organizational safeguards in accordance with the law. A user who connects an external service chooses that provider independently and is responsible for reviewing its rules.

9. User rights

Depending on the applicable law, the user may request access to their personal data, correction of inaccuracies, deletion, restriction or termination of processing, withdrawal of consent, unsubscribing from communications and the right to submit a complaint to a competent authority.

To exercise these rights, email [email protected], specify which data concerns you and verify your identity if this is necessary to protect the account. We may retain data to the extent required by law, for performance of the agreement, security, auditing, dispute resolution or protection of rights, and will explain the reason to the extent permitted.

10. Special categories of data and third-party data

We do not intend to process data about racial or ethnic origin, political opinions, religious or other beliefs, membership in public organizations or physiological characteristics that could be used to identify a person. Do not provide such data to us unless it is needed for a lawful and expressly defined purpose.

If the user provides personal data of third parties, the user confirms that they have the right to do so. The user is responsible for unlawfully providing third-party personal data to us.

11. Changes to the Policy

We may update this Policy to reflect changes to the system, law or data-processing methods. The date of the latest update will be shown on this page. If changes materially affect users’ rights, we may additionally notify users through available channels.

12. Contacts

For personal-data and privacy questions, contact ТОВ «СИСТЕМА ЕКОЛОГІЧНИХ ДАНИХ» at [email protected].