DATA PROCESSING AGREEMENT (DPA)

Last Updated: June 18, 2026

This Data Processing Agreement (“Agreement” or “DPA”) forms part of the Terms and Conditions and Privacy Policy of Foundry Ukraine (“Company”, “Controller”, “we”, “our”, or “us”), available through the website www.foundry-ua.net.

This Agreement governs the processing of personal data carried out on behalf of customers, partners, suppliers, and website users in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

1. Parties

This Agreement is entered into between:

Data Controller:
Foundry Ukraine
Website: www.foundry-ua.net

and

Data Subject / Customer / User who submits personal information through the website.

2. Purpose of Processing

The Company processes personal data solely for legitimate business purposes, including:

  • Responding to inquiries and requests;
  • Providing quotations and commercial proposals;
  • Processing orders and contracts;
  • Customer communication and support;
  • Improving website functionality and user experience;
  • Marketing communications where consent has been provided;
  • Compliance with legal obligations.

3. Categories of Personal Data

Depending on the interaction with the website, the following data may be processed:

  • Full name;
  • Email address;
  • Telephone number;
  • Company name;
  • Country and city;
  • Information submitted through contact forms;
  • IP address;
  • Browser and device information;
  • Website usage and analytics data.

The Company does not intentionally collect special categories of personal data as defined under Article 9 GDPR.

4. Lawful Basis for Processing

Personal data is processed based on one or more of the following legal grounds:

  • Consent of the data subject;
  • Performance of a contract;
  • Compliance with legal obligations;
  • Legitimate interests of the Company;
  • Protection of vital interests where applicable.

5. Processing Instructions

The Company shall process personal data only:

  • For the purposes specified in this Agreement;
  • In accordance with applicable data protection laws;
  • Following appropriate security measures;
  • Based on documented instructions where applicable.

6. Confidentiality

All employees, contractors, and service providers with access to personal data are subject to confidentiality obligations and are authorized to process personal data only as necessary to perform their duties.

7. Security Measures

The Company implements appropriate technical and organizational measures to protect personal data, including:

  • Secure website connections (SSL/TLS);
  • Access control mechanisms;
  • Password protection;
  • Software and security updates;
  • Data backup procedures;
  • Monitoring and protection against unauthorized access.

8. Subprocessors

The Company may engage third-party service providers (“Subprocessors”) to assist in providing services.

Such subprocessors may include:

  • Website hosting providers;
  • Analytics providers;
  • Customer communication services;
  • Email service providers;
  • Cloud storage providers.

The Company ensures that subprocessors are subject to data protection obligations substantially equivalent to those contained in this Agreement.

9. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), the Company shall ensure that appropriate safeguards are in place, including:

  • European Commission adequacy decisions;
  • Standard Contractual Clauses (SCCs);
  • Other lawful transfer mechanisms recognized under GDPR.

10. Data Subject Rights

Individuals have the right to:

  • Access their personal data;
  • Rectify inaccurate information;
  • Request deletion of personal data;
  • Restrict processing;
  • Object to processing;
  • Request data portability;
  • Withdraw consent at any time;
  • Lodge a complaint with a supervisory authority.

Requests may be submitted using the contact details provided on the website.

11. Data Retention

Personal data shall be retained only for as long as necessary to:

  • Fulfill the purposes for which it was collected;
  • Comply with legal obligations;
  • Resolve disputes;
  • Enforce contractual rights.

After the retention period expires, personal data will be securely deleted or anonymized.

12. Personal Data Breaches

In the event of a personal data breach that may affect the rights and freedoms of individuals, the Company shall:

  • Investigate the incident promptly;
  • Take corrective actions;
  • Notify relevant authorities where required by law;
  • Notify affected individuals when legally required.

13. Audit and Compliance

The Company maintains policies and procedures designed to comply with applicable data protection laws and may provide reasonable information regarding its privacy and security practices upon legitimate request.

14. Limitation of Liability

Nothing in this Agreement shall limit or exclude liability where such limitation is prohibited by applicable law.

15. Amendments

The Company reserves the right to amend this Agreement at any time to reflect changes in legislation, regulatory requirements, or business operations.

Updated versions will be published on the website.

16. Contact Information

For any questions regarding this Data Processing Agreement or the processing of personal data, please contact:

Foundry Ukraine
Website: www.foundry-ua.net

By using the website and submitting personal information, users acknowledge that they have read and understood this Data Processing Agreement.