At Consolline (hereinafter — the Company) we strive to ensure the confidentiality and security of your personal data. This Privacy Policy (hereinafter — the “Policy”) sets out the procedure for the collection, use, storage and other processing of your personal data, and establishes the principles by which the Company is guided when using such information.

Please carefully review this Privacy Policy before providing any personal data to Consolline, so that you understand how your personal data may be processed. If you do not agree with this Policy, please refrain from using this Website.

We reserve the right to make changes to this Policy at any time. To keep the information contained in this provision up to date, we recommend that you review this Policy regularly, so as to stay informed of any changes and the updated procedure for using the information you have provided.

1. Processing of personal data

1.1. Types of personal data

We use cookies on our Website and may process your personal data.

Cookies are text files or fragments of data that a website sends to the user’s browser and stores on their device. Such a device may be a computer, laptop, mobile phone, tablet or other device through which the user accesses the website.

Cookies allow the Website to recognize the user’s device, store certain settings and ensure the correct operation of certain of its functions. Depending on their purpose, cookies may be used to store the chosen language, viewing settings, authorization, traffic analysis and to improve the operation of the Website.

Depending on their purpose, cookies may be necessary, analytical or marketing cookies used to ensure the operation of the Website.

By continuing to use the Website, you agree to the use of cookies in accordance with their purpose and the settings available on the Website. Information about the use of cookies may be updated in connection with changes to the Website’s functionality, the technologies used, or legal requirements.

While visiting our website, Consolline may collect the following personal data (including information that the user enters into a form themselves):

  • Name
  • E-mail
  • Phone
  • Company name
  • Position
  • Country or region
  • Message text
  • Mark of consent to the Policy (the fact, date and time are stored)
  • Mark of consent to the mailing list (not set by default)

We use cookies to collect the personal data specified above. This list may change in accordance with the requirements of the Company and of the law.

Also technical data that is automatically collected:

  • IP address
  • Browser, its version, operating system
  • Device type and screen resolution
  • The language in which the browser and the Website operate
  • Where the user came from (previous page)
  • Page address, date, time and duration of viewing
  • Approximate location by IP

Visitor identifiers are collected while visiting the website. Pseudonymized identifiers that make it possible to recognize the user during repeat visits may be considered personal data, even in the absence of information identifying them by name, namely:

  • Google Analytics identifier (the _ga cookie)
  • The website’s own visitor and session identifier, generated by the site
  • Google Ads identifiers (_gcl_au, gclid in a link)
  • Meta identifiers (_fbp, _fbc, fbclid in a link)
  • LinkedIn identifiers
  • Session recording service identifier

While using the Website, information about the user’s actions may be collected, in particular data on the pages viewed and the order in which they were viewed, the time spent on individual pages and on the Website as a whole, the amount of page content viewed, clicks on buttons and other interactive elements, interaction with forms (starting to fill them in, errors occurring, and submission), as well as clicks on or transitions via phone numbers, e-mail addresses, and links to messengers and social networks. Recording and analysis of the user’s interaction with the Website may take place, in particular cursor movement, keystrokes and clicks.

The Website collects information on the source through which the user arrived at the site. Typically, this is the link’s UTM tags, as well as identifiers. These include: advertisements, campaigns, etc. The “lead and advertising campaign” is stored directly in the lead record.

If an online chat widget is created and used, the Company reserves the right to collect the data entered by the user and to analyze it. This also applies to the e-mail used for mailings, subscription status, e-mail opens and clicks within it.

1.2. Retention period of the personal data provided

Cookies are stored in the user’s web browser on their device and may be used to identify the browser, ensure the operation of the Website, analyze its use and for other purposes defined by this Policy. Personal data is stored for no longer than is necessary in accordance with the purpose of its processing.

Consent_state — set and used by the Website itself. This cookie is used to store the user’s choice in the consent banner. The estimated retention period of this cookie is from 6 to 12 months.

The website’s session cookies — set by the website itself. Necessary to maintain the user’s technical session while they are on the site. As a rule, deleted after the user closes the web browser.

Csrf_token — used to protect forms and set by the Website itself. Estimated retention period — until the user closes the web browser.

_ga, _ga_<ID> — set by Google and used for Google Analytics. The estimated retention period is up to 2 years.

_gcl_au — set by Google, for tracking conversions related to Google Ads advertising campaigns. The estimated retention period is up to 90 days.

_fbp and _fbc — set by Meta. These cookies may be used to recognize the browser for Meta. The estimated retention period of such cookies is up to 90 days.

_clck and _clsk — set by Microsoft for the operation of Clarity. The estimated retention period of _clck is up to 1 year, while _clsk is used mainly for the duration of the relevant session.

LinkedIn cookie — set by LinkedIn, in particular for remarketing purposes. The estimated retention period of such cookies may be up to 12 months.

Anti-spam protection cookie — set by Google. Such cookies may be used as an identifier and event buffer. These cookies are stored until the browser is cleared.

It is also important to note that the Website reserves the right to use localStorage and sessionStorage, which are not technically cookies; however, by visiting the Website, you consent to the processing of your data by these built-in objects.

The Company reserves the right to store information regarding leads submitted on the Website and contacts in the CRM. The estimated retention period for such information is three years from the date the final changes were made.

Users’ actions in the Company’s own database are stored for 14 months; after this period ends, the information is retained only in a pseudonymized numerical format for final analytics, without any identifiers or the ability to identify users.

Aggregated dashboard metrics are stored indefinitely, since they do not contain information about specific users and do not allow their identification.

Information taken from Google Analytics is stored for 14 months, which corresponds to the maximum data retention period available in the service.

Session recordings are stored for 30 days, since this period is sufficient to carry out the necessary analysis.

Server logs are stored for 30 to 90 days, depending on their purpose, in particular to ensure security and to analyze technical failures.

The record of the fact that consent was given is stored for the duration of the consent’s validity and for an additional 1–3 years after it ends, in order to confirm the fact and the ownership of the consent given.

The retention period for chat correspondence depends on the terms and functionality of the relevant service.

The retention periods indicated above are estimated and may differ depending on the specific configuration of the website and its technical changes.

1.3. Data storage

Data used when visiting the Website, information provided when forming (or potentially creating) a lead, as well as backup copies, are stored on servers in the EU.

Employees, as well as authorized third parties whom the Company may engage to fulfill its obligations, have access to information about the client and their lead, and may also view data separately.

Such transnational corporations as Google, Meta, LinkedIn, and Microsoft usually conclude agreements on privacy policy and the processing of personal information with their Irish companies, but the parent companies in the US also have access to the data.

Data contained in the CRM, chat, and mailing list is also stored.

The Company reserves the right to choose the behavioral analytics and website usability research platform, which helps to understand how users interact with web pages.

1.4. Purpose of processing

Your personal data may be processed for the following purposes:

  • ensuring the availability of the website and its functional capabilities, in particular the website’s ability to remember your settings and to improve its operation and the user experience;
  • ensuring the security and proper functioning of the website;
  • promoting our services and providing you with information about our products and services, provided that you have consented to the use of the relevant cookies;

2. Recipients of personal data and use of personal data by third parties

Personal data that you provide through feedback forms, order forms, service request forms or other forms on our website may be transferred to and processed using the CRM system that we use to register, store and manage inquiries from clients, potential clients and other users, and to organize further communication and the provision of services.

To ensure the operation of the CRM system, we may engage a third-party provider of the relevant software and IT services as a processor of personal data.

The following personal data, which you voluntarily provide when filling in the relevant forms, may be transferred to the CRM system, in particular: first name, last name, phone number, e-mail address, information about the request or order, as well as other information contained in your inquiry.

After the information contained in the lead has been processed, this data (the manager’s comments, the outcome of the conversation, the amount and status of the deal) may be placed in the CRM system, to which certain Company employees have access.

Where necessary for the provision of our services, we may transfer your personal data to third parties involved in organizing and carrying out transport and logistics services. Such third parties may include carriers, freight forwarders, logistics partners, agents, subcontractors and other service providers involved in the transportation, handling, delivery or tracking of cargo.

The Company reserves the right to vet counterparties for the purposes of proper legal and reputational assessment.

To ensure the operation, availability, performance and security of our website, we may use the services of third-party hosting and CDN providers. In the course of providing such services, the relevant providers may process personal data transmitted through the website or automatically generated during its use, in particular the IP address, technical identifiers, information about the device and browser, network connection data, the date and time of accessing the website, as well as other technical data necessary to ensure the proper functioning, performance and security of the website.

2.1. Website server and database

To ensure the operation of the website and the processing of user inquiries submitted through the forms on the website, the website’s server and database are used. The website’s hosting is located within the territory of the European Union; the specific hosting service provider will be determined by the Company separately. In the course of the website’s operation, the IP address, browser information, page address, time, and all form data may be processed. The processing of this data is carried out for the purpose of ensuring the proper functioning of the website and storing user inquiries and leads.

Processing category: strictly necessary.

2.2. Own event collection

The website may use its own event collection system, which operates on its own server, without transferring data to third parties. The system may process the visitor identifier, information about the user’s actions on the website, UTM tags and other technical information. Processing is carried out for the purpose of generating internal analytics and evaluating the effectiveness of the website’s operation through the administrative panel.

Processing category: analytical.

2.3. Google Analytics 4

Google Analytics 4, provided by Google Ireland Limited, may be used to analyze website usage.

Within the use of the service, the visitor identifier, IP, information about the user’s actions on the website, as well as technical data may be processed. The purpose of the processing is web data analytics.

Processing category: analytical.

2.4. Google Tag Manager

Google Tag Manager, provided by Google Ireland Limited, may be used.

In the process of loading and operating tags, the IP may be processed to ensure the correct functioning of the relevant tags. This service is used to manage the website’s tags.

Processing category: technical.

2.5. Google Ads

Google Ads, provided by Google Ireland Limited, may be used to measure the effectiveness of advertising campaigns and to carry out remarketing.

Within the operation of the service, the identifier of a click or transition via an advertisement, information on whether a conversion has taken place, and the address of the web page on which the relevant action took place may be processed.

The processing is carried out for the purpose of measuring the effectiveness of advertising campaigns, conversion attribution and forming audiences for remarketing.

Processing category: marketing.

2.6. Meta Pixel and Conversions API

Meta Pixel and Conversions API, provided by Meta Platforms Ireland Limited, may be used to measure the effectiveness of advertising, form advertising audiences and carry out remarketing.

Within the use of these tools, browser identifiers, the IP address, information about the user’s actions on the website, as well as certain contact data, in particular e-mail and phone number, in hashed form, if such data is transmitted via the Conversions API, may be processed.

The processing is carried out for the purpose of measuring the effectiveness of advertising campaigns, tracking conversions and carrying out remarketing.

Processing category: marketing.

2.7. LinkedIn Insight Tag

LinkedIn Insight Tag, provided by LinkedIn Ireland Unlimited Company, may be used to analyze advertising activity and carry out remarketing.

The service may process the visitor identifier, IP address, the address of the web page visited, and information necessary to match the website visit with the corresponding profile on the LinkedIn network.

The processing is carried out for the purpose of analyzing the effectiveness of advertising campaigns and forming audiences for remarketing.

Processing category: marketing.

2.8. Clarity or Hotjar

Microsoft Clarity or Hotjar may be used to analyze user behavior on web pages. The provider of the relevant service may be Microsoft Ireland Operations Limited or Hotjar Ltd (Malta), depending on the tool actually chosen.

Depending on the service’s settings, information about the user’s interaction with the page may be collected and processed, in particular session recordings, clicks, cursor movement, page scrolling and other information about user behavior.

The purpose of such processing is to analyze the usability of the website, identify technical or navigational problems, and improve the structure and functionality of the web pages.

Processing category: analytical.

2.9. Online chat widget

A third-party online chat service may be used to enable prompt communication between users and representatives of the website operator. The name and provider of the relevant service are to be determined separately.

While using the online chat, the content of the correspondence, the IP address, the visitor’s technical identifier, as well as contact and other data that the user voluntarily provides during the conversation, may be processed.

The processing is carried out for the purpose of providing online consultations, responding to user inquiries and ensuring communication with the website operator.

Processing category: functional.

2.10. E-mail newsletter service

A third-party e-mail marketing service may be used to organize and carry out e-mail newsletters. The name and provider of the relevant service are to be determined separately.

Within the use of such a service, the e-mail address, the user’s name, subscription status, as well as information about the opening of and clicks on links within e-mails may be processed.

The processing is carried out for the purpose of sending informational and/or marketing messages, as well as analyzing the effectiveness of the relevant newsletters.

Processing category: marketing.

2.11. CRM system

A third-party provider’s CRM system may be used for recording, systematizing and processing user inquiries, as well as for organizing the sales process. The name and provider of the relevant system are to be determined separately.

The data specified by the user in the lead, UTM tags, information on the status of processing the inquiry, information on concluded deals and their value, as well as other information necessary for the proper organization of work with leads, may be transferred to and stored in the CRM system.

The processing is carried out for the purpose of recording inquiries, organizing interaction with potential and existing clients, as well as managing sales processes.

Processing category: processing outside the website.

2.12. Form anti-spam protection tools

Google Ireland Limited or another similar provider may be used to protect the website and its forms from automated requests, bots, spam and other abuse.

In the course of the operation of such a service, the IP address, information about the user’s behavior on the page, cookies and other technical parameters necessary to determine whether a request is automated may be processed.

The processing is carried out solely for the purpose of ensuring the security of the website and preventing abuse of its functionality.

Processing category: strictly necessary.

2.13. CDN and attack protection tools

A CDN and/or a web infrastructure protection service, in particular Cloudflare or a similar provider, may be used to ensure the proper loading speed of the website, its stable operation and protection from network attacks. The specific provider is to be determined separately.

Within the operation of such a service, the user’s IP address, HTTP request headers and other technical information necessary for routing requests, caching content, detecting threats and ensuring the security of the website may be processed.

The processing is carried out for the purpose of increasing the speed and stability of the website’s operation, as well as preventing unauthorized access, attacks and other threats to information security.

Processing category: strictly necessary.

Buttons or links may be placed on the website for going to third-party messaging services, in particular Telegram, WhatsApp and Viber.

When the relevant button is clicked, the user leaves the website or goes to a third-party application or service. The website operator does not receive or control the data that the user independently provides to the relevant third-party service after the transition, unless such data is transmitted to the operator by another means.

Further processing of personal data within the relevant third-party service is carried out in accordance with its own rules and privacy policy.

The purpose of using such buttons and links is to provide the user with an additional communication channel.

Processing category: transition to a third-party service.

3. Conditions of use of the website

We use cookies and process personal data on the basis of your explicit consent, which you give through the cookie banner settings, as well as on the basis of legitimate interests or the performance of a contract, where applicable. You can withdraw your consent at any time in the cookie settings.

If the User does not agree (fully or partially) with the terms of the Rules, please refrain from using the Website.

Information (which includes various articles and other text materials), photographs, as well as case studies that the Company has decided to publish on the Website, belong to the Owner of the Website.

Unlawful use and distribution of such data is prohibited.

The Company reserves the right, in the event of outdated or obsolete information, to change, edit and delete materials posted on the Website, without prior notice to the user.

The legal entity of the “CONSOLLINE” group that controls the use of personal data, and is also responsible for the processing, storage and deletion of Users’ personal data, is the Ukrainian operator. The owner of the domain consolline.com is the director of CONSOLLINE UKRAINE LLC (EDRPOU Code — 44703904) — Olha Anatoliivna Husak. Registered address: 103 Antonovycha St., office 1, Kyiv, 03150, Ukraine.

Since this company is international, and visitors to the Website may be citizens and residents of the member states of the European Union, as well as of other jurisdictions, the processing of personal data may be carried out in accordance with the requirements of the personal data protection legislation applicable to such processing, in particular the legislation of the EU and other relevant jurisdictions. The company CONSOLLINE complies with all international standards and the requirements of the EU General Data Protection Regulation (GDPR), in particular the provisions of the GDPR, since the protection of natural persons in connection with the processing of personal data is a fundamental right. Article 8 of the Charter of Fundamental Rights of the European Union (the “Charter”) and Article 16 of the Treaty on the Functioning of the European Union (TFEU) provide that everyone has the right to the protection of personal data concerning them.

The principles and rules for the protection of natural persons in connection with the processing of their personal data provide, regardless of their nationality or place of residence, for the observance of their fundamental rights and freedoms, in particular their right to the protection of personal data. This Regulation is intended to contribute to the accomplishment of an area of freedom, security and justice, of an economic union, to economic and social progress, the strengthening and the convergence of the economies within the internal market, and to the well-being of natural persons.

Directive 95/46/EC of the European Parliament and of the Council is aimed at harmonizing the protection of the fundamental rights and freedoms of natural persons in the processing of personal data and ensuring the free movement of personal data between Member States.

Guided by the translation of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), posted on the Official Portal of the Verkhovna Rada of Ukraine, the company CONSOLLINE, in accordance with Art. 16 “Right to rectification”, must ensure the right of the data subject to obtain the rectification of inaccurate personal data concerning him or her, which the controller must carry out without undue delay. Having regard to the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

In accordance with Art. 15 “Right of access by the data subject”, the data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and information on:

  • b. the categories of personal data concerned;
  • c. the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
  • d. where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • e. the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
  • f. the right to lodge a complaint with a supervisory authority;
  • g. where the personal data are not collected from the data subject, any available information as to their source.

In accordance with Art. 17 “Right to erasure (‘right to be forgotten’)”, the data subject shall have the right to obtain the erasure of his or her personal data, which the controller must carry out without undue delay, and the controller shall also be obliged to erase personal data without undue delay where the established grounds arise.

In accordance with Art. 18 “Right to restriction of processing”, the data subject shall have the right to obtain restriction of processing by the controller where one of the following circumstances applies:

  • (a) the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;
  • (b) the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
  • (c) the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
  • (d) the data subject has objected to processing pursuant to Article 21(1) pending the verification whether the legitimate grounds of the controller override those of the data subject.

Where processing has been restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

The controller shall inform the data subject who has obtained restriction of processing under paragraph 1 before the restriction of processing is lifted.

In accordance with Art. 19 “Notification obligation regarding rectification or erasure of personal data or restriction of processing”, the controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.

In the event of the transfer of personal data to third countries, the Company ensures an adequate level of protection by concluding Standard Contractual Clauses (SCCs) approved by the European Commission, or by cooperating with providers certified under the EU-US Data Privacy Framework.

In accordance with Art. 21 “Right to object”, the data subject shall have the right to object, on grounds relating to his or her particular situation, at any time, to the processing of personal data concerning him or her, including profiling. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to the processing of personal data concerning him or her for such marketing, including profiling to the extent that it is related to such direct marketing.

Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

The company CONSOLLINE ensures the proper performance and observance of all articles and provisions of the GDPR (including those not mentioned in this Policy), and ensures the Users’ right to erasure, restriction of processing, and other guaranteed rights by contacting the official e-mail address with the relevant request. This e-mail is active and will guarantee a response to the user’s request within the shortest possible time: smminfo@consolline.com.ua