Legal
Privacy Policy
This page describes what personal data we collect, why, who we share it with, and how long we keep it. We have tried to be specific — naming actual fields and actual services rather than speaking in generalities.
We do not sell your data. We do not pass it to advertising networks. We set no analytics or marketing cookies.
Who is responsible for your data
The data controller is Individual Entrepreneur Myroslava Chepchurenko. Send any question about your data to femmesenses.cooperation@gmail.com — a person answers it, not an autoresponder.
Processing is governed by the Ukrainian Personal Data Protection Act. If you are in the EU, the GDPR applies to you as well.
What we collect when you order
- Contact details
- Full name, email address, phone number. The phone is required because the carrier needs it to deliver.
- Delivery
- Delivery method, city, Nova Poshta branch or locker — or country, address and postal code for an international parcel. Plus your delivery note, if you left one.
- The order
- Which works, in which formats, quantities, amounts, currency, the language you ordered in, and the tracking number once it ships.
- Consents
- The fact that you accepted the Purchase Terms, the Return Policy and this Policy, with the date, time and IP address. This is the proof of consent — without it we could not show you ever gave it.
We never receive your card details
You enter your card number, expiry date and CVV on the bank's page, not on our site. They never reach us in any form and are stored nowhere on our side.
From the payment service we receive only a payment identifier and its status. That is enough to match a payment to an order and, if needed, to refund it.
Technical data
Our hosting keeps standard request logs — IP address, time, page, browser type. Every server does this: without it you can neither spot a fault nor stop an attack.
We keep an audit log of admin actions — who in the studio changed what, and when. It exists for security and holds staff data, not buyers'.
Cookies
Every cookie we set is strictly necessary: your language choice, a marker that you have already seen the welcome screen, your acknowledgement of the cookie notice, and — for private gallery clients — the viewing session. No analytics, no marketing, no third-party trackers.
Separately: the contents of your cart are kept in your browser and never reach our server until you place an order. The Cookie Notice has the full list.
Why we process it
- Performing the contract
- Taking your order, receiving payment, printing, packing, shipping, sending you the tracking number, handling returns. Without this data an order is simply impossible.
- Legal obligation
- Tax and accounting records for paid orders, and keeping the evidence of the consents you gave.
- Our legitimate interest
- Protecting against fraud and abuse, rate-limiting checkout, and notifying the studio of a new order so it gets packed quickly.
Who we share it with
Only those without whom an order could not work. Each acts as a processor on our instructions.
- Payment service
- Payments are taken by plata by mono (Universal Bank JSC) — you see it when you reach the payment page. It receives the amount, the currency and a reference to the order. Your card details belong to the bank, not to us.
- Delivery service
- Within Ukraine, Nova Poshta. We query their directory of cities and branches without sending any of your data — the service does not know who is looking up an address. Your name, phone and branch reach the carrier only when we actually create a parcel. For international orders the chosen postal service receives the details.
- Hosting and database
- The site runs with a cloud hosting provider, and orders and photographs are stored in a cloud database. They process the data technically, on our instructions, with no right to use it for their own purposes.
- Email delivery
- Your confirmation email is sent through a transactional email service. It receives your address and the contents of the message.
- Studio notifications
- We are alerted to a new paid order through a messaging app, in the studio owner's private chat. The message carries your name, email, phone, the works ordered, the delivery method and address, and your note, so the order gets packed without delay.
We name outright the parties you deal with directly — the bank and the carrier. The rest are technical suppliers; we will provide the current list on request to the email in the section above. That way you get the full picture without this document going stale every time we change a technical supplier.
Some of these services operate outside Ukraine. We pass your data to no one else — not to advertising networks, not to data brokers, and not for training artificial-intelligence systems.
Private galleries
If you booked a session, we keep your photographs and show them to you through a personal link.
Each opening of a gallery is recorded in a log — IP address and time — for security. The terms your own gallery runs under come with the link.
We do not publish your photographs in the portfolio without your separate consent.
How long we keep it
Records relating to paid orders must be kept for tax accounting — at least 1095 days from the filing of the relevant return, as the Tax Code of Ukraine requires. We cannot act on an erasure request for those records before that period ends.
An unpaid order is kept until we clear it or until you ask us to delete it — a request we act on immediately, since an unpaid order carries no tax obligation for us. Private gallery photographs are kept for as long as our arrangement with you runs, or until you ask us to delete them.
Your rights
- Find out what data we hold about you, and get a copy of it.
- Have inaccurate data corrected.
- Have data deleted — except records we are legally required to keep for tax purposes.
- Restrict processing, or object to it.
- Withdraw consent where processing rests on it.
- Complain to the Ukrainian Parliament Commissioner for Human Rights, or — if you are in the EU — to your national supervisory authority.
To exercise any of these, write to femmesenses.cooperation@gmail.com. We reply within 30 days.
Security
The site runs only over an encrypted connection. Database access is constrained by row-level policies. Signing in to the admin panel requires two-factor authentication — a password alone is not enough. Secret keys are stored encrypted.
Perfect security does not exist. If a breach occurs that puts your rights at risk, we will tell you and the competent authority as quickly as the law requires.
Children
The shop is not intended for anyone under 18 and we do not knowingly collect their data. Where children were photographed in a session, the gallery is given to the parents or guardians, and it is they who decide what happens to those photographs.
Changes to this policy
If we start collecting something new, or add a new service, we will update this page and change the date at the top. Where a change is significant — analytics appearing, for instance — we will ask for your consent separately rather than burying it in the text.