Personal data
Privacy Policy
In short: we process the minimum needed to run the Service. We never store card details. Property access codes are encrypted at rest. We do not sell data and do not use it for advertising.
This is an English translation. The Ukrainian version is the binding text.
1. Who processes your data
The data controller is the individual entrepreneur Hladko O.V., tax number 3109008870, 9 Yablunieva St., Vinnytski Khutory, Vinnytsia district, Vinnytsia region, 23219, Ukraine.
Data questions: [email protected].
Processing is carried out under the Law of Ukraine “On Personal Data Protection” No. 2297-VI and, for people located in the European Union, with regard to the General Data Protection Regulation (GDPR).
2. What data is processed
Account data: Telegram identifier, name, chosen interface language, role in the company and, optionally, phone number and pay notes.
Operational data entered by the Customer: property names and addresses, access codes and entry instructions, check-in and check-out dates, work tasks, checklists, photo reports, and messages exchanged in work chats.
Payment data: an anonymised payment token, amounts, dates and statuses. Card number, expiry date and CVV are never received or stored — they are entered directly on the acquiring bank’s page.
Technical data: request logs needed to diagnose faults and protect against abuse.
3. Purpose and legal basis
Data is processed to: provide and operate the Service; create and dispatch work tasks; deliver messages to workers; take payment and meet tax obligations; provide support; and protect the Service against unauthorised access.
Legal bases: performance of a contract (the public offer), consent, compliance with legal obligations, and the legitimate interest in keeping the Service secure.
Data is not used for advertising, profiling or automated decisions with legal effect, and is not sold to third parties.
4. Roles regarding staff data
Data about staff, contractors and property owners is entered by the Customer. For that data the Customer is the controller and the Provider acts as processor, processing it only on the Customer’s instructions in order to deliver the Service.
The Customer is responsible for having a legal basis to enter such data and for informing the people concerned.
5. Who data is shared with
The following processors are used to run the Service:
| Provider | Purpose | Location |
|---|---|---|
| Telegram | Message delivery, the Service interface | International |
| Supabase | Database and file storage | Frankfurt, EU |
| Cloudflare | Compute and content delivery | International |
| OpenAI | Interface and message translation | United States |
| JSC Universal Bank TM MONOBANK (Plata by mono) | Payment processing | Ukraine |
Access codes, property addresses, names and other specific values are never sent to the translation provider. They are replaced with anonymous placeholders before the request and restored into the text after the reply — the model sees the shape of the sentence, never the values themselves.
Data may also be disclosed to state authorities where Ukrainian law expressly requires it.
6. International transfers
The primary data store is located in the European Union (Frankfurt, Germany). Some providers listed in clause 5.1 may process data outside Ukraine and the EU. Such transfers are made under agreements with those providers and taking account of the safeguards they document.
7. Retention
Task photos are deleted automatically 30 days after upload.
Account and operational data is kept for as long as the Service is used and is deleted on the Customer’s request. Where a subscription is cancelled or refunded, operational data (properties, tasks, team data) is deleted automatically 90 days after access ends. Data required for accounting and tax records is kept for the period set by Ukrainian law.
8. Security
Measures in place include: encryption in transit (TLS) and at rest; separation of access between companies enforced at the database level; and service keys held outside the client application with restricted access.
Property access codes and their notes are stored encrypted (AES-256). The encryption key is held separately from the database, so a copy of the database without that key does not reveal any code.
Please note, however: messages are delivered through Telegram, which is not end-to-end encrypted. Anyone who gains access to a worker’s Telegram account can read the codes sent to them. We recommend locks that issue a code for the length of a guest’s stay and expire it automatically.
9. Your rights
Under Article 8 of the Law of Ukraine “On Personal Data Protection” you have the right to: know the source and location of your data; be informed of the terms on which access to it is granted; access your data; require its correction or deletion; withdraw consent; and seek protection of your rights from the relevant authorities. Where GDPR applies, you additionally have rights of access, rectification, erasure, restriction, portability and objection.
To exercise these rights, write to [email protected]. We respond within 30 calendar days.
Complaints may be made to the Ukrainian Parliament Commissioner for Human Rights or, for people in the EU, to the relevant supervisory authority.
10. Cookies
The str.systems website uses no tracking cookies and sets no advertising or analytics identifiers. The Service itself runs inside Telegram and uses no cookies.
11. Changes to this Policy
This Policy may be amended. A new version takes effect when published on this page with its version date.
- Controller
- Individual entrepreneur
Hladko O.V. - Tax number
- 3109008870
- Address
- 9 Yablunieva St., Vinnytski Khutory,
Vinnytsia district, Vinnytsia region,
23219, Ukraine - [email protected]