Privacy Policy
1. Who processes your data
The controller of personal data is Neutrome Labs LLC, a company incorporated in the State of Delaware, USA (file number 10217901, address Governors Avenue 1111B S Dover, DE, 19904 US).
The part of the data that relates to work requiring Ukrainian legal capacity — registering and servicing companies, dealing with state registrars, notaries and banks — is processed jointly with us by individual entrepreneur (ФОП) Bondarenko Roman Hryhorovych 3643300456, registered address vul. Kostenka 27, Kriviy Rih, Dnipropetrovska obl., 50065, Ukraine). Both share the same ultimate owner and operate under the trading name LLC.in.ua.
You may address a request to either of them at support@llc.in.ua — it will be handled regardless of which one you approached.
Processing is carried out in accordance with the Law of Ukraine "On Protection of Personal Data" and, for individuals in the European Economic Area, having regard to the General Data Protection Regulation (GDPR).
2. Who this Policy covers
This Policy covers the website https://llc.in.ua, the customer dashboard and all servicing processes. It applies to:
- visitors to the website;
- people who submit an application to register a company — the Customers;
- the owners and directors of companies whose details a Customer enters in an application;
- anyone who corresponds with us.
If you enter another person's details in an application, you must inform them of this Policy and that their data is being passed to us.
3. What data we collect
Account
Name, email address, whether the address is confirmed, a profile image if present, and a password hash. We do not store the password itself and cannot recover it.
Session technical data
When you sign in to the dashboard we store the session identifier, its creation and expiry times, and your browser's IP address and User-Agent string. This is needed for account security and for investigating unauthorised access.
Company application data
Contact email address, website address, business category, a short description of the business, tags, ranges for the number of customers and employees, whether foreign special licences are held, and the list of desired service groups.
Owner and director data
Surname, given name and patronymic, international-format phone number, date of birth, sex, citizenship, role in the company, ownership share, and a full structured residential address: country, postal code, region, city, street, building, unit and additional details.
Company data
Working name, full and short legal names, the EDRPOU code, legal and physical addresses in Ukraine, selected activity codes (KVED), tax regime, structure variant, registration and dissolution dates, status and the manager's comment on the status.
Identity verification data
Verification is carried out by Stripe Identity: the owner submits images of an identity document and a selfie directly to Stripe. We receive the verification result from Stripe, which may contain the document number, its expiry date, date of birth and the identification number shown on the document, together with copies of the document images and the selfie, which we store in our own private storage.
This is the most sensitive category of data we handle. It is used solely to confirm the identity of owners and to meet legal requirements, is never used for advertising or profiling, and is destroyed when company data is deleted at your request.
Payment data
Payment provider name, operating mode, our internal payment reference, payment status, the provider-side payment identifier, amount, currency, failure reason, settlement time and the full technical response from the provider about the transaction.
We do not receive, see or store card details — they are entered on Stripe's or LiqPay's secure page.
Documents
PDF documents that a manager uploads for your company (statute, formation certificate and similar) are held in private storage and are accessible only to you and to authorised staff.
Website usage data
We use PostHog for product analytics, Google Analytics and Google Tag Manager for traffic measurement, and Google Ads to measure advertising performance. These tools receive page views, interface actions, device type, browser, approximate location derived from the IP address, and cookie identifiers. They are activated only after you give consent — see "Cookies and similar technologies".
Correspondence
The content of your messages by email or through the dashboard, and our replies.
4. Where we obtain data
- Directly from you — when completing an application, paying, corresponding and using the dashboard.
- From your website. If you enter a website address during onboarding, we call the Firecrawl service, which reads the publicly available content of that page to pre-fill the company name, category and description. The scan runs once and only where those fields are not already filled; you can change any value manually.
- From payment providers — transaction status and technical payment data.
- From Stripe Identity — the identity verification result.
5. Purposes and legal bases
Performance of the agreement
Registering and servicing a company, creating and maintaining an account, placing and fulfilling orders, preparing documents, providing dashboard access, and support. Basis — necessity for performance of a contract to which you are a party (Art. 11 of the Law of Ukraine "On Protection of Personal Data"; Art. 6(1)(b) GDPR).
Compliance with legal obligations
Keeping accounting and payment records, complying with tax, sanctions and financial law, and responding to lawful requests from public authorities. Basis — compliance with a legal obligation (Art. 6(1)(c) GDPR).
Legitimate interests
Screening owners, preventing fraud and abuse, keeping the Platform secure, maintaining technical logs, defending and enforcing our rights in disputes, and improving the service. Basis — legitimate interests not overridden by your rights and freedoms (Art. 6(1)(f) GDPR). You have the right to object to this processing.
Consent
Analytics and advertising cookies, and marketing emails. Basis — your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time without affecting the lawfulness of processing before withdrawal.
6. Automated processing and owner screening
Before the first registration order is created, we run automated screening of the owners using a language model. Only the internal owner identifier, surname and given name, sex, derived age and citizenship are submitted. Contact details, addresses, documents and payment information are not submitted.
The screening result is advisory and has no legal effect on you by itself: a "requires review" outcome does not block placing or paying for an order and is not a decline. The decision to approve or decline an application is always made by a human manager, and the reason for a decline is given to you verbatim.
Accordingly, we do not make decisions based solely on automated processing within the meaning of Article 22 GDPR. You have the right to obtain an explanation of a screening result, to express your point of view and to request human review — write to us at support@llc.in.ua.
Separately, a language model is used to prepare internal recommendations for the manager (proposed activity codes, tax regime and names) and to format check results into readable text. In the second case the model receives a redacted check result from which technical identifiers, links and secrets have been removed.
8. International transfers
Our infrastructure is global, so data is processed outside Ukraine, in particular in the United States of America and the European Union.
We cannot guarantee that data is stored only within a particular jurisdiction. Transfers rely on the mechanisms provided by law: the European Commission's standard contractual clauses, data processing agreements with our providers, and those providers' own certifications. Copies of the relevant documents can be requested at our contact address.
10. Retention periods
- Account and correspondence — for as long as you use the service and 3 years after it is closed.
- Company, order and payment data — at least 1095 days (three years) from completion of the transaction, as required by Ukrainian accounting and tax law.
- Identity verification material — until company data is deleted at your request; in the absence of such a request, up to 3 years.
- Technical access logs — 30 days.
- Analytics data — according to the settings of the relevant service.
You can dissolve a company and delete its data through the dashboard. Deletion destroys the stored document images and owner selfies and the corresponding check records. Records we are legally required to keep remain until the statutory periods expire.
11. Security
We apply organisational and technical safeguards, including:
- encrypted connections (HTTPS) for all traffic;
- storing passwords only as cryptographic hashes;
- no card data at all in our systems — payment happens on the provider's side;
- private storage for documents and verification material, with no public access;
- use of a restricted access key for sensitive verification results;
- automatic removal of technical identifiers, links and secrets from check data before it is displayed or processed further;
- staff access limited to the minimum necessary.
No system is completely secure. If we become aware of a breach posing a high risk to your rights, we will notify you and the competent authority within the periods set by law.
12. Your rights
You have the right to:
- know what data of yours we process and to obtain access to it;
- request rectification of inaccurate or incomplete data;
- request erasure where there is no lawful basis for continuing to hold it;
- request restriction of processing or object to processing based on legitimate interests;
- receive your data in a structured, machine-readable format (portability);
- withdraw consent to analytics, advertising and mailings at any time;
- request human review of an automated screening result;
- lodge a complaint.
To exercise any of these rights, write to support@llc.in.ua or use the support channel in the dashboard — a request from the dashboard is more convenient, since your identity is already confirmed by signing in. We respond within thirty calendar days. To avoid disclosing data in error, we may ask for further details to confirm your identity.
A complaint may be lodged with the Ukrainian Parliament Commissioner for Human Rights, or, if you are in the European Economic Area, with the data protection supervisory authority where you live.
13. Children's data
The service is intended for people aged 18 or over and is not directed at children. We do not knowingly collect children's data. If you believe a child's data has been given to us, tell us and we will delete it.
14. Changes to this Policy
We may update this Policy. The current version is always available on this page with the date of update. Material changes — broader processing purposes, new recipients of data — are notified by email or by a prominent notice in the dashboard at least ten calendar days before they take effect.
15. Contacts
Neutrome Labs LLC, State of Delaware, USA, file number 10217901, address Governors Avenue 1111B S Dover, DE, 19904 US.
Individual entrepreneur Bondarenko Roman Hryhorovych, tax number 3643300456, address vul. Kostenka 27, Kriviy Rih, Dnipropetrovska obl., 50065, Ukraine.
Email for personal data enquiries: support@llc.in.ua. The terms on which services are provided are set out in the Terms of Use and Public Offer.
The Ukrainian version is authentic: if it differs from this English text, the Ukrainian version prevails. To exercise your rights or ask a question about how your data is handled, write to support@llc.in.ua.