1. Who we are
Deep Agency ("Deep Agency", "we", "us", "our") is a digital design and development studio operating the website deepagency.digital (the "Website").
For the purposes of the Ukrainian Law "On Personal Data Protection" No. 2297-VI and, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), we act as the controller (owner) of the personal data described in this Policy.
| Legal entity | [Individual entrepreneur — full name] |
| Registration number | [РНОКПП / tax ID] |
| Registered address | [address], Ukraine |
| General contact | hello@deepagency.digital |
| Privacy requests | privacy@deepagency.digital |
We have not appointed a Data Protection Officer — we are not required to under Article 37 of the GDPR. Privacy requests are handled by the studio's founder.
If you have any question about this Policy or about how we process your data, write to privacy@deepagency.digital. We respond within one month. Where a request is complex or we receive several requests from you, we may extend this by up to two further months, and we will tell you within the first month if we do.
2. What this Policy covers
This Policy explains what personal data we collect through the Website, why we collect it, what we do with it, how long we keep it, and what rights you have.
It applies to:
- visitors to deepagency.digital;
- people who contact us through the contact form, email, Telegram or Instagram;
- representatives of our clients and prospective clients.
It does not cover:
- third-party websites we link to — those have their own policies;
- data we process on behalf of a client while delivering a project (for example, users of a website we build). In those cases the client is the controller, we act as a processor, and the terms of our services agreement or a separate data processing agreement apply.
3. What data we collect
3.1 Data you give us
When you submit the contact form on the Website, we collect:
- your name and company name;
- your preferred contact method and the corresponding contact details (email, Telegram, phone);
- the service you are interested in;
- the budget range you select;
- the project description you write, including anything you choose to include in it.
If you contact us by email, Telegram or Instagram instead, we collect whatever you send us, plus your account name or handle.
If we go on to work together, we additionally collect the information needed for a contract and an invoice: full name or company name, registration and tax details, address, bank details, and signatory contact information.
Which fields are required. In the contact form, your name and preferred contact method are required — without them we cannot reply to you. Company name, service, budget range and project description are optional; leaving them out only means our first reply will be less specific. Providing registration and bank details is a requirement for entering into a contract and for our tax obligations: without them we cannot conclude an agreement or issue an invoice.
Data we receive about you from a client. If you are an employee or representative of our client, we may receive your contact details from that client rather than from you. In that case we obtain your name, role and business contact details, and we inform you within 30 working days of receiving them, unless you already have this information.
3.2 Data collected automatically
When you visit the Website, we and our service providers automatically collect:
- IP address (in Google Analytics, in truncated form);
- device type, operating system, browser and screen resolution;
- pages viewed, time on page, referring source, approximate location at city level;
- cookie identifiers and similar technologies.
3.3 What we do not collect
We do not deliberately collect special categories of data (health, religion, political views, biometrics, and so on). Please do not include such information in the project description field — if you do, we will delete it.
We do not collect payment card data. Payments are made by bank transfer directly to our account; we never see or store card details.
4. Why we process your data and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Responding to your enquiry, preparing a proposal | contact form data, correspondence | Steps prior to entering a contract — GDPR Art. 6(1)(b); Art. 11(3) of the Ukrainian Law (conclusion and performance of a transaction) |
| Performing a contract: delivering the project, communication, handover | contact details, project data, contract details | Performance of a contract — GDPR Art. 6(1)(b) |
| Issuing invoices, accounting and tax records | name, registration details, payment records | Legal obligation — GDPR Art. 6(1)(c) |
| Website analytics and improving the site | cookies, usage data | Consent — GDPR Art. 6(1)(a) |
| Security, preventing abuse and spam | IP, technical logs | Legitimate interests — GDPR Art. 6(1)(f) |
| Publishing project case studies | project materials, client name, testimonial | Consent given in the services agreement — GDPR Art. 6(1)(a); withdrawable at any time |
| Defending legal claims | correspondence, contract records | Legitimate interests — GDPR Art. 6(1)(f) |
Where we rely on consent, you may withdraw it at any time — see Section 9. Withdrawal does not affect processing carried out before withdrawal.
5. Cookies and analytics
The Website uses cookies — small files stored by your browser.
Strictly necessary cookies keep the Website working (session state, security, load balancing). These are used on the basis of our legitimate interest and cannot be switched off.
Analytics cookies are set by Google Analytics 4 (Google Ireland Limited). They tell us how many people visit the Website, which pages they read and where they came from. They are only set after you give consent through the cookie banner. IP addresses are truncated before storage, and we do not use Google Analytics data to identify individual visitors.
You can withdraw cookie consent at any time, as easily as you gave it: use the "Cookie settings" link in the Website footer, which reopens the banner and lets you change your choice. You can also block or delete cookies in your browser settings. Blocking strictly necessary cookies may break parts of the Website.
A full list of the cookies we set — name, provider, purpose and lifetime — is available in the cookie banner and on request at privacy@deepagency.digital.
If we add other tracking tools later — for example the Meta pixel or a chat widget — we will update this Policy and the cookie banner before they go live.
6. Who we share your data with
We do not sell your personal data and we do not pass it to third parties for their own marketing.
We share data with the following categories of recipients, each acting as our processor under a contract:
| Recipient | What for | Where data is processed |
|---|---|---|
| Vercel Inc. | Website hosting and delivery | USA / EU |
| Supabase Inc. | Storage of Website media and form submissions | EU / USA |
| GoDaddy | Domain registration | USA |
| Google Ireland Ltd. | Analytics, business email | EU / USA |
| Telegram, Meta (Instagram) | Communication, where you choose that channel | International |
[accountant / bookkeeping service] | Accounting and tax reporting | Ukraine |
| Our team members and subcontractors | Delivering your project | Ukraine, EU |
We may also disclose data where we are legally required to — to courts, law enforcement or regulators acting within their powers — and where necessary to establish or defend legal claims.
Every team member and subcontractor with access to client data is bound by a confidentiality obligation, imposed by contract.
This section constitutes notice of transfer of your personal data to third parties for the purposes of Article 21 of the Ukrainian Law "On Personal Data Protection". If we begin sharing data with a recipient not listed here, we will update this Policy.
7. International transfers
Some of our providers process data outside Ukraine and outside the European Economic Area, primarily in the United States.
There is no European Commission adequacy decision covering the United States generally. For transfers falling under the GDPR we rely on the European Commission's Standard Contractual Clauses, on the EU–US Data Privacy Framework where the provider is certified under it, and on the providers' own supplementary technical measures. You may obtain a copy of the safeguards applied to a specific transfer by writing to privacy@deepagency.digital.
For transfers from Ukraine we rely on Article 29 of the Law "On Personal Data Protection": transfer to states that ensure an adequate level of protection (members of the European Economic Area and parties to Convention 108), and, for other states, on the grounds in Article 29(4) — your consent, and the necessity of the transfer for concluding or performing a contract in your interest.
EU representative. We have no establishment in the European Union. We consider our processing of EEA residents' data to be occasional, not to involve special categories of data on a large scale, and unlikely to result in a risk to individuals — and therefore covered by the exemption in Article 27(2)(a) of the GDPR. Should that assessment change, we will appoint a representative and name them here.
8. How long we keep your data
| Data | Retention period |
|---|---|
| Enquiries that did not lead to a project | 12 months from last contact |
| Correspondence with clients | 3 years from project completion |
| Contracts, invoices, accounting records | 1095 days from the filing of the related tax return, under Art. 44.3 of the Tax Code of Ukraine (2555 days for controlled transactions), and thereafter as required by the archival rules for primary documents |
| Project files and source code | 2 years from handover, then archived or deleted |
| Analytics data | 14 months (Google Analytics 4 retention set to the maximum available for event data; the product default is 2 months) |
| Cookie consent records | 12 months |
When a retention period ends, data is deleted or irreversibly anonymised. If a deletion request arrives while we still have a legal obligation to keep a record — for example a tax document — we restrict processing of that record instead of deleting it, and delete it when the obligation expires.
9. Your rights
Under Article 8 of the Ukrainian Law "On Personal Data Protection" you have the right to:
- know where your data is held, for what purpose, and who processes it;
- access your data and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data, including where it is processed unlawfully or is no longer needed;
- restrict processing, and object to it;
- withdraw consent at any time, where processing is based on consent;
- be protected against automated decisions that have legal consequences for you;
- lodge a complaint about the handling of your data.
Where the GDPR applies, you additionally have the right to:
- data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller;
- object (Art. 21) to processing based on legitimate interests, including profiling;
- restriction of processing (Art. 18) on the specific grounds listed there.
To exercise any of these, write to privacy@deepagency.digital from the address you used to contact us, or tell us how we can otherwise verify that the request is yours. We do not charge for this. We may ask for additional identification if we genuinely cannot confirm your identity, and we may refuse manifestly unfounded or excessive repeated requests.
Complaints. If you believe we have handled your data unlawfully, you may complain to the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua), or — if you are in the EEA — to the supervisory authority of your country of residence or workplace.
10. Security
We apply measures appropriate to the risk, including: access to client data limited to the team members who need it; two-factor authentication on all studio accounts; a password manager rather than shared passwords; encrypted connections (HTTPS/TLS) on the Website; and separate accounts for each team member instead of shared logins.
No system is completely secure, and we cannot guarantee absolute security of data transmitted over the internet. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and inform you without undue delay where the risk to you is high.
11. Children
The Website is aimed at businesses and is not intended for children. We do not knowingly collect data from persons under 16. If you believe a child has provided us with personal data, write to privacy@deepagency.digital and we will delete it.
12. Automated decision-making
We do not use automated decision-making or profiling that produces legal effects for you or similarly significantly affects you.
13. Changes to this Policy
We may update this Policy — for example when we add a new tool or service. The current version, with its date and version number, is always published at deepagency.digital/privacy-policy. If we make a change that materially affects your rights, we will notify you by email where we have your address, and will where practical give notice before the change takes effect.
14. Contact
Deep Agency
Privacy requests: privacy@deepagency.digital
General enquiries: hello@deepagency.digital
[Registered address], Ukraine