SmartOKS Privacy Policy
Edition of 19 August 2026
Translation notice. This is an English translation provided for convenience. SmartOKS operates under the law of Ukraine, and the Ukrainian version of this Policy is the legally binding one. If the two versions differ, the Ukrainian text prevails.
This Privacy Policy (the "Policy") describes what personal data is processed in connection with use of the smartoks.com.ua website, the SmartOKS web platform on subdomains of the form name.smartoks.com.ua and the SmartOKS Agent inventory application; for what purposes and on what legal grounds; to whom it may be transferred; and what rights data subjects have.
Processing is carried out in accordance with the Law of Ukraine "On Personal Data Protection". For users covered by Regulation (EU) 2016/679 (GDPR), this Policy applies taking its requirements into account.
1. Data controller and contact details
The controller of personal data collected through the website and the Service is Mykhailo Vasylovych Piddubchenko, an individual entrepreneur (FOP), tax number (RNOKPP) 3758905818 ("we", the "Operator").
For any question about the processing of personal data, write to mail@smartoks.com.ua. Full details are set out in the Public Offer.
2. Our two roles: controller and processor
SmartOKS is a multi-tenant platform: each organization has its own isolated data space. Because of this we act in two distinct roles:
- Controller — for account data, payment information, website visitor data, marketing mailings and security logs: we determine the purposes and means of processing this data.
- Processor — for the content an organization enters into its own space (staff records, tickets, equipment and so on): the organization is the controller of that data, and we process it solely on its instructions in order to provide the Service. If your data was entered into the Service by your organization, address questions and requests to its administrator first; we will assist in fulfilling your request.
3. What data we process
Account data
- user name, email address, role within the organization;
- a cryptographic hash of the password — the password itself is unknown to us and is not stored in the system.
Organization and payment data
- organization name, subdomain, settings, plan;
- invoice and payment history. We do not collect or store full payment card details — they are handled by the payment provider; for automatic subscription renewal only a payment token issued by the provider is stored.
Organization content
Tickets, tasks, staff records, workstations, equipment, stock data, the knowledge base, comments and change history. The organization is the controller of this data (see section 2).
SmartOKS Agent data
If an organization has installed the inventory agent on its devices, the agent reports to the Service only technical specifications of the device: computer name, processor, motherboard, graphics card, amount of RAM, drives, network card, MAC address, operating system, and the history of changes to these specifications. The agent does not collect file contents, correspondence, browser history or any data about a person's activity at the computer.
Technical data and logs
- IP address, browser and device type (user agent);
- account sign-in log, action logs within the system, server technical logs.
Sign-in through Google data
If you sign in to the Service through a Google account, we receive from Google your account identifier, your name and your verified email address. Your Google account password is not passed to us.
Marketing data and data from website forms
- email address and the fact that consent to mailings was given or withdrawn, together with technical delivery statuses (delivered, rejected);
- data you voluntarily provide in forms on the website (demo request, feedback): name, email, the content of your message.
4. Purposes and legal grounds for processing
- Providing the Service — registration, authentication, operation of features, technical support: performance of a contract (the accepted offer).
- Settlements — issuing invoices, fiscal receipts, tax accounting: compliance with the Operator's legal obligations.
- Security — sign-in logging, prevention of fraud and abuse, incident investigation: the legitimate interest of the Operator and of users.
- Website analytics — anonymised traffic statistics for the marketing site: legitimate interest; see the Cookie Policy for detail.
- Marketing mailings — solely with your consent, which can be withdrawn at any time via the "unsubscribe" link in every email.
We do not sell personal data and do not pass it to third parties for their own marketing purposes.
5. AI assistant
To operate the AI assistant, user queries and the fragments of organization data needed to compose an answer are sent to the Google Gemini API. That data is used solely to compose the assistant's answer. The feature is available on certain plans; the organization decides for itself whether to use it. AI assistant responses may contain inaccuracies and require verification by the user.
6. Who data may be shared with
Data is shared only with service providers involved in operating the Service, to the extent necessary for them to perform their functions:
- hosting and server infrastructure providers;
- Cloudflare — DNS, CDN, protection against attacks and bots;
- the payment provider (internet acquiring) — accepting payments;
- Google — website analytics (Google Analytics / Tag Manager), sign-in through Google (OAuth), the AI assistant (Gemini API);
- Resend — sending transactional and marketing email;
- technical error monitoring services;
- Telegram — sending notifications, if the organization has enabled that integration.
In addition, data may be disclosed to state authorities on the basis of a lawful request, in the cases and in the manner established by law.
7. Cross-border transfers
Certain providers (in particular Google, Cloudflare and Resend) may process data on servers outside Ukraine and the European Economic Area. Such transfers are made on the basis of contracts with those providers that include data protection safeguards; for users covered by the GDPR, using EU standard contractual clauses or other mechanisms provided for by the GDPR.
8. Retention periods
- account data — for as long as the Service is used;
- organization content — for as long as the organization uses the Service; after a prolonged suspension of access, data may be deleted within the periods and in the manner set out in the Public Offer;
- financial and fiscal documents — for the periods established by the tax law of Ukraine (not less than 1,095 days);
- security logs — for as long as necessary for security purposes and incident investigation;
- marketing data — until consent is withdrawn; a record of the unsubscribe is kept indefinitely so that we do not email you again;
- backups — rotated automatically and kept for a limited period, after which they are replaced by newer ones.
9. Data security
We apply technical and organizational protection measures, including:
- encrypted connections (HTTPS/TLS);
- storing passwords solely as cryptographic hashes;
- session cookies with the HttpOnly, Secure and SameSite attributes;
- an isolated database for each organization and role-based access control;
- logging of account sign-ins;
- daily backups, including an encrypted off-site copy.
In the event of a data breach creating a high risk to the rights of data subjects, we will notify the affected people and the competent authorities in accordance with applicable law.
10. Rights of data subjects
You have the right to:
- obtain information about the processing of your data and access to it;
- request rectification of inaccurate data;
- request erasure of data where there are no lawful grounds for continuing to process it;
- request restriction of processing and object to processing based on legitimate interest;
- withdraw consent (this does not affect the lawfulness of processing before withdrawal);
- data portability — for users covered by the GDPR;
- lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or with a court; for data subjects in the EU, with the supervisory authority of their place of residence.
Send requests to mail@smartoks.com.ua. We respond within 30 calendar days. If your data was entered into the Service by your employer (the organization), the request will be forwarded to its administrator as the data controller, and we will assist in fulfilling it.
11. Cookies
The use of cookies and similar technologies is described in a separate Cookie Policy.
12. Children's data
The Service is intended for professional use by organizations and is not directed at people under 16. We do not knowingly collect children's personal data.
13. Changes to this Policy
We may update this Policy from time to time; the current edition, with its date, is published on this page. We notify users of material changes by email or through the Service interface.
14. Contact
For questions about this Policy and about the processing of personal data: mail@smartoks.com.ua.