Skip to content
LLC in Ukraine

Privacy Policy

Last updated:

1. Who processes your data

The controller of personal data is Neutrome Labs LLC, a company incorporated in the State of Delaware, USA (file number 10217901, address Governors Avenue 1111B S Dover, DE, 19904 US).

The part of the data that relates to work requiring Ukrainian legal capacity — registering and servicing companies, dealing with state registrars, notaries and banks — is processed jointly with us by individual entrepreneur (ФОП) Bondarenko Roman Hryhorovych 3643300456, registered address vul. Kostenka 27, Kriviy Rih, Dnipropetrovska obl., 50065, Ukraine). Both share the same ultimate owner and operate under the trading name LLC.in.ua.

You may address a request to either of them at support@llc.in.ua — it will be handled regardless of which one you approached.

Processing is carried out in accordance with the Law of Ukraine "On Protection of Personal Data" and, for individuals in the European Economic Area, having regard to the General Data Protection Regulation (GDPR).

2. Who this Policy covers

This Policy covers the website https://llc.in.ua, the customer dashboard and all servicing processes. It applies to:

  • visitors to the website;
  • people who submit an application to register a company — the Customers;
  • the owners and directors of companies whose details a Customer enters in an application;
  • anyone who corresponds with us.

If you enter another person's details in an application, you must inform them of this Policy and that their data is being passed to us.

3. What data we collect

Account

Name, email address, whether the address is confirmed, a profile image if present, and a password hash. We do not store the password itself and cannot recover it.

Session technical data

When you sign in to the dashboard we store the session identifier, its creation and expiry times, and your browser's IP address and User-Agent string. This is needed for account security and for investigating unauthorised access.

Company application data

Contact email address, website address, business category, a short description of the business, tags, ranges for the number of customers and employees, whether foreign special licences are held, and the list of desired service groups.

Owner and director data

Surname, given name and patronymic, international-format phone number, date of birth, sex, citizenship, role in the company, ownership share, and a full structured residential address: country, postal code, region, city, street, building, unit and additional details.

Company data

Working name, full and short legal names, the EDRPOU code, legal and physical addresses in Ukraine, selected activity codes (KVED), tax regime, structure variant, registration and dissolution dates, status and the manager's comment on the status.

Identity verification data

Verification is carried out by Stripe Identity: the owner submits images of an identity document and a selfie directly to Stripe. We receive the verification result from Stripe, which may contain the document number, its expiry date, date of birth and the identification number shown on the document, together with copies of the document images and the selfie, which we store in our own private storage.

This is the most sensitive category of data we handle. It is used solely to confirm the identity of owners and to meet legal requirements, is never used for advertising or profiling, and is destroyed when company data is deleted at your request.

Payment data

Payment provider name, operating mode, our internal payment reference, payment status, the provider-side payment identifier, amount, currency, failure reason, settlement time and the full technical response from the provider about the transaction.

We do not receive, see or store card details — they are entered on Stripe's or LiqPay's secure page.

Documents

PDF documents that a manager uploads for your company (statute, formation certificate and similar) are held in private storage and are accessible only to you and to authorised staff.

Website usage data

We use PostHog for product analytics, Google Analytics and Google Tag Manager for traffic measurement, and Google Ads to measure advertising performance. These tools receive page views, interface actions, device type, browser, approximate location derived from the IP address, and cookie identifiers. They are activated only after you give consent — see "Cookies and similar technologies".

Correspondence

The content of your messages by email or through the dashboard, and our replies.

4. Where we obtain data

  • Directly from you — when completing an application, paying, corresponding and using the dashboard.
  • From your website. If you enter a website address during onboarding, we call the Firecrawl service, which reads the publicly available content of that page to pre-fill the company name, category and description. The scan runs once and only where those fields are not already filled; you can change any value manually.
  • From payment providers — transaction status and technical payment data.
  • From Stripe Identity — the identity verification result.

6. Automated processing and owner screening

Before the first registration order is created, we run automated screening of the owners using a language model. Only the internal owner identifier, surname and given name, sex, derived age and citizenship are submitted. Contact details, addresses, documents and payment information are not submitted.

The screening result is advisory and has no legal effect on you by itself: a "requires review" outcome does not block placing or paying for an order and is not a decline. The decision to approve or decline an application is always made by a human manager, and the reason for a decline is given to you verbatim.

Accordingly, we do not make decisions based solely on automated processing within the meaning of Article 22 GDPR. You have the right to obtain an explanation of a screening result, to express your point of view and to request human review — write to us at support@llc.in.ua.

Separately, a language model is used to prepare internal recommendations for the manager (proposed activity codes, tax regime and names) and to format check results into readable text. In the second case the model receives a redacted check result from which technical identifiers, links and secrets have been removed.

7. Who we share data with

We do not sell personal data and do not share it for anyone else's advertising. Data reaches only those without whom the service cannot be delivered:

  • Cloudflare, Inc. (USA) — hosting for the website and API, the database, storage of documents and verification material, technical logs, sending email, and the gateway through which the language model is reached. This is the principal infrastructure provider where the data actually resides.
  • Stripe — card payment acceptance and subscription servicing.
  • Stripe Identity — identity verification of owners; receives the document images and the selfie directly from the owner.
  • LiqPay (JSC CB PrivatBank), Ukraine — alternative card payment acceptance; receives the amount, currency, order reference and a payment description containing the company name.
  • Firecrawl — reads the publicly available content of the website address you provide, to pre-fill fields.
  • PostHog — product analytics (subject to consent).
  • Google — Google Analytics and Google Tag Manager, Google Ads, and sign-in with a Google account if you choose to use it (analytics and advertising subject to consent).
  • Delivery partners — accountants, lawyers, notaries, banks, recruitment and other providers engaged to deliver the services you selected. They receive only the data needed for the specific work.
  • Public authorities and registrars — within documents filed for registration and reporting, or on the basis of a lawful request.

8. International transfers

Our infrastructure is global, so data is processed outside Ukraine, in particular in the United States of America and the European Union.

We cannot guarantee that data is stored only within a particular jurisdiction. Transfers rely on the mechanisms provided by law: the European Commission's standard contractual clauses, data processing agreements with our providers, and those providers' own certifications. Copies of the relevant documents can be requested at our contact address.

9. Cookies and similar technologies

Necessary

  • better-auth.session_token — the session cookie that keeps you signed in to the dashboard. Set for the .llc.in.ua domain with the Secure, SameSite=None and Partitioned attributes, so that one session works both on the website and in the administrative application.
  • sidebar_state — remembers whether the dashboard sidebar is collapsed.
  • The application draft token in browser storage (localStorage) — lets you return to an unfinished application. Only its hash is stored on our side.
  • Checkout handoff data in browser session storage (sessionStorage) — needed to return you correctly from the payment page.

These are required for the service to work and do not need consent.

Analytics and advertising

Cookies and identifiers of PostHog, Google Analytics, Google Tag Manager and Google Ads. They are set only after you consent through the consent banner. Refusing is as easy as accepting and does not restrict access to the service. You can change or withdraw your choice at any time through the consent settings on the website or by clearing cookies in your browser.

10. Retention periods

  • Account and correspondence — for as long as you use the service and 3 years after it is closed.
  • Company, order and payment data — at least 1095 days (three years) from completion of the transaction, as required by Ukrainian accounting and tax law.
  • Identity verification material — until company data is deleted at your request; in the absence of such a request, up to 3 years.
  • Technical access logs — 30 days.
  • Analytics data — according to the settings of the relevant service.

You can dissolve a company and delete its data through the dashboard. Deletion destroys the stored document images and owner selfies and the corresponding check records. Records we are legally required to keep remain until the statutory periods expire.

11. Security

We apply organisational and technical safeguards, including:

  • encrypted connections (HTTPS) for all traffic;
  • storing passwords only as cryptographic hashes;
  • no card data at all in our systems — payment happens on the provider's side;
  • private storage for documents and verification material, with no public access;
  • use of a restricted access key for sensitive verification results;
  • automatic removal of technical identifiers, links and secrets from check data before it is displayed or processed further;
  • staff access limited to the minimum necessary.

No system is completely secure. If we become aware of a breach posing a high risk to your rights, we will notify you and the competent authority within the periods set by law.

12. Your rights

You have the right to:

  • know what data of yours we process and to obtain access to it;
  • request rectification of inaccurate or incomplete data;
  • request erasure where there is no lawful basis for continuing to hold it;
  • request restriction of processing or object to processing based on legitimate interests;
  • receive your data in a structured, machine-readable format (portability);
  • withdraw consent to analytics, advertising and mailings at any time;
  • request human review of an automated screening result;
  • lodge a complaint.

To exercise any of these rights, write to support@llc.in.ua or use the support channel in the dashboard — a request from the dashboard is more convenient, since your identity is already confirmed by signing in. We respond within thirty calendar days. To avoid disclosing data in error, we may ask for further details to confirm your identity.

A complaint may be lodged with the Ukrainian Parliament Commissioner for Human Rights, or, if you are in the European Economic Area, with the data protection supervisory authority where you live.

13. Children's data

The service is intended for people aged 18 or over and is not directed at children. We do not knowingly collect children's data. If you believe a child's data has been given to us, tell us and we will delete it.

14. Changes to this Policy

We may update this Policy. The current version is always available on this page with the date of update. Material changes — broader processing purposes, new recipients of data — are notified by email or by a prominent notice in the dashboard at least ten calendar days before they take effect.

15. Contacts

Neutrome Labs LLC, State of Delaware, USA, file number 10217901, address Governors Avenue 1111B S Dover, DE, 19904 US.

Individual entrepreneur Bondarenko Roman Hryhorovych, tax number 3643300456, address vul. Kostenka 27, Kriviy Rih, Dnipropetrovska obl., 50065, Ukraine.

Email for personal data enquiries: support@llc.in.ua. The terms on which services are provided are set out in the Terms of Use and Public Offer.

The Ukrainian version is authentic: if it differs from this English text, the Ukrainian version prevails. To exercise your rights or ask a question about how your data is handled, write to support@llc.in.ua.