EN
EN

Privacy Policy

Last updated: 29 August 2026

1. General Provisions

  1. This Privacy Policy (the “Policy”) governs the collection, processing, storage, use, and protection of the personal data of users of the MEDIATION-HELP.com website (the “Website”) and the Mediation Help mobile application for iOS and Android (together, the “Platform”).
  2. This Policy has been prepared in accordance with the requirements of the following legislation:
  • the Law of Ukraine “On Personal Data Protection” dated 1 June 2010 No. 2297-VI;
  • the Law of Ukraine “On Electronic Communications” dated 16 December 2020 No. 1089-IX;
  • the Law of Ukraine “On Electronic Trust Services” dated 5 October 2017 No. 2155-VIII;
  • the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), which applies to the processing of personal data of individuals in the European Union and in other cases provided for by the GDPR;
  • Directive 2002/58/EC of the European Union (the ePrivacy Directive), insofar as it applies to cookies and similar technologies;
  • the Law of Ukraine “On Electronic Commerce” dated 3 September 2015 No. 675-VIII;
  • other applicable laws and regulations concerning personal data protection and electronic communications.
  1. By using the Platform, the User confirms that they have read this Policy. Where the processing of personal data is based on consent, such consent is requested separately at the relevant time, including when analytical or marketing cookies are used, access to geolocation is granted, or push notifications are enabled.
  2. The Administration reserves the right to amend this Policy. An updated version becomes effective upon its publication on the Platform with the date of the latest revision, unless otherwise specified in the updated version or required by law.
  3. This Policy applies to all individuals who visit the Website or use the Mobile Application, regardless of their location.

2. Terms and Definitions

For the purposes of this Policy, the following terms have the meanings set out below:
  1. User means any natural person who visits the Website or uses the Mobile Application and their functionality.
  2. Specialist means a User who publishes information about themselves on the Platform for the purpose of providing services, including as a mediator, lawyer, notary, translator, or another professional.
  3. Administration means the Public Union “Ukrainian Academy of Mediation”, which operates the Platform and determines the purposes and means of personal data processing in the cases described in this Policy.
  4. Personal Data means any information relating to an identified or identifiable natural person—the data subject.
  5. Processing of Personal Data means any operation or set of operations performed on personal data, including collection, recording, accumulation, storage, structuring, adaptation, alteration, updating, use, transmission, disclosure, anonymisation, restriction, or destruction.
  6. Personal Account means a protected section of the Platform for Specialists that provides access to the profile, related data, enquiries, notifications, and other available functions.
  7. Cookie means a small text file stored on the User’s device when the User visits the Website.
  8. Mobile Application means the Mediation Help software for the iOS and Android mobile operating systems, which forms part of the Platform.
  9. Application Identifier (device_id) means a randomly generated technical identifier created by the Mobile Application to manage, protect, and revoke a mobile session. It is not the device’s advertising identifier, serial number, or IDFA.
  10. Push Token means a technical identifier of a Mobile Application installation provided by a push notification service and used to deliver notifications to the User’s device.

3. Legal Bases for Processing Personal Data

Personal Data is processed on the Platform on the following legal bases:

3.1. Consent of the Data Subject (Article 6(1)(a) GDPR)

This legal basis applies, in particular, when:
  • contact forms are submitted;
  • a person registers as a Specialist;
  • a User subscribes to a mailing list, where such functionality is available;
  • analytical or marketing cookies are used;
  • the Mobile Application is granted access to geolocation;
  • push notifications are enabled.
The User may withdraw their consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

3.2. Performance of a Contract or Taking Steps at the User’s Request (Article 6(1)(b) GDPR)

This legal basis applies, in particular, to:
  • providing a Specialist with access to the Personal Account;
  • authorisation through the Mobile Application;
  • maintaining and refreshing a mobile session;
  • publishing and managing a Specialist’s profile;
  • facilitating communication between a User and a Specialist;
  • providing other Platform functions requested by the User.

3.3. Legitimate Interests (Article 6(1)(f) GDPR)

This legal basis applies, in particular, to:
  • ensuring the stable and secure operation of the Platform;
  • protecting mobile sessions;
  • preventing fraud and unauthorised access;
  • diagnosing technical errors;
  • analysing the use of the Platform in an anonymised or aggregated form;
  • protecting the rights and legitimate interests of Users, Specialists, and the Administration.

3.4. Compliance with a Legal Obligation (Article 6(1)(c) GDPR)

This legal basis applies where the processing or disclosure of Personal Data is required by the laws of Ukraine, the laws of the European Union, or a lawful request from an authorised public authority or court.

4. Categories of Personal Data and Purposes of Processing

4.1. User Data

When an enquiry is submitted through a form on the Platform, the following data may be collected:
  • the name provided in the form;
  • email address;
  • telephone number, if provided;
  • the content of the enquiry;
  • other information voluntarily provided by the User in the enquiry.
Purpose of processing: forwarding the enquiry to the selected Specialist, facilitating communication, and providing the functionality requested by the User. Legal basis: the User’s consent and/or taking steps at the User’s request.

4.2. Specialist Data

Specialists may provide the following data for publication and operation of their profiles:
  • surname, first name, and patronymic;
  • contact details, including email address, telephone number, and office address;
  • education and qualification details;
  • professional information;
  • specialisation and working languages;
  • terms on which services are provided;
  • photograph;
  • other information voluntarily provided by the Specialist for publication in their profile or use of the Personal Account functionality.
Purpose of processing: creating, publishing, and managing the Specialist’s profile, enabling Users to search for Specialists, and allowing Users to contact them. Legal basis: performance of a contract, taking steps at the Specialist’s request, and/or the Specialist’s consent.

4.3. Technical Data

The following data may be processed automatically when the Platform is used:
  • IP address;
  • browser type and version;
  • device type and operating system;
  • Cookie data;
  • pages visited and session duration;
  • technical logs and information concerning errors and security;
  • interface language;
  • other technical data required for the operation and protection of the Platform.
Purpose of processing: operating the Platform, maintaining security, diagnosing technical issues, preventing misuse, and conducting permitted analytics. Legal basis: the legitimate interests of the Administration and, for analytical or marketing cookies, the User’s consent.

4.4. Mobile Application Data

Mobile Authorisation Users sign in to their accounts through a secure Mediation Help webpage. The User’s password is not transmitted to the Mobile Application. Following successful authorisation, the Mobile Application receives technical access and refresh tokens. These tokens are stored in the secure storage provided by the operating system and are used exclusively to maintain authorised access to the Personal Account. Application Identifier During the first mobile authorisation, the Mobile Application creates a random device_id and transmits it to the Mediation Help server. The identifier is used to link, protect, and revoke the mobile session and to prevent unauthorised access. It is not used for advertising, profiling, or tracking the User across other applications or services. Push Notifications After the operating system’s permission has been obtained and the User has separately enabled this function, the Mobile Application may obtain a Push Token and transmit the following information to the Mediation Help server:
  • Push Token;
  • type of mobile operating system;
  • selected interface language.
The Push Token is linked to the authorised account and is used exclusively to send notifications about new enquiries, comments, reviews, and other Personal Account events. It is not used for advertising or cross-service tracking. Expo Push Notification Service and, depending on the operating system, Apple Push Notification Service or Firebase Cloud Messaging may be used to deliver push notifications. The User may disable push notifications at any time in the Mobile Application or in the operating system settings. Once push notifications are disabled, the Mobile Application sends a request to the server to deregister the relevant Push Token. Geolocation Subject to the operating system’s permission, the Mobile Application may access the device’s current location in order to:
  • display nearby Specialists;
  • centre the map;
  • determine the distance to Specialists;
  • define the search area displayed on the map.
The boundaries of the current map area are transmitted to the server in order to obtain a list of Specialists. The storage procedure and retention period applicable to this data are described in Section 8 of this Policy. The User may revoke access to geolocation through the operating system settings. If permission is not granted or the location cannot be determined, the Mobile Application may use a default map area without using the User’s geolocation.

5. Cookies and Similar Technologies

This Section applies to the Website and the webpages opened during mobile authorisation.

5.1. Technical (Strictly Necessary) Cookies

These cookies are required for the proper operation of the Website, including the operation of the Personal Account, authorisation, session maintenance, security, and storage of settings. Such cookies do not require separate consent where they are necessary to provide a service requested by the User.

5.2. Analytical Cookies

These cookies may be used to collect website usage statistics and evaluate the use of the Website, for example through Google Analytics or similar services. They are installed only after the User has provided active consent through the cookie banner, where such consent is required by law.

5.3. Marketing and Advertising Cookies

These cookies may be used to display relevant advertisements and assess the effectiveness of informational or advertising campaigns. They are installed only after the User has provided explicit consent. Where such cookies are not used, they are not installed. Cookie management:
  • the User may provide or withdraw consent to analytical and marketing cookies through the relevant cookie banner interface;
  • Cookie settings may be changed using the Cookie management tool available on the Website or through the browser settings;
  • withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

6. Interaction Through the Platform

  1. The Platform provides the technical means for communication between a User and the selected Specialist.
  2. Personal Data provided by a User in an enquiry is transmitted to the Specialist to whom the enquiry is addressed.
  3. The Administration does not use the content of enquiries for its own incompatible purposes and does not review such content unless necessary. Access to the content of enquiries may occur only for technical maintenance, security, incident investigation, compliance with lawful requirements, or support purposes.
  4. The Specialist to whom an enquiry is addressed is responsible for reviewing the enquiry, maintaining confidentiality, and providing a response within the scope of their independent activities and obligations under data protection law.
  5. By receiving an enquiry through the Platform, the Specialist undertakes to process the Personal Data received in accordance with the law and this Policy and exclusively for the purpose of reviewing the relevant enquiry.

7. Personal Account and Mobile Authorisation

  1. Specialists have access to the Personal Account to manage their profiles, Personal Data, and available Platform functions. The Mobile Application may provide limited access to the profile, new enquiries, reviews, notifications, and other Personal Account events.
  2. Through the Personal Account, a Specialist may:
  • edit personal and professional data;
  • update information about their services;
  • manage the visibility of their profile;
  • view available enquiries, notifications, and other events;
  • manage mobile notification settings;
  • delete the account and associated data or submit a corresponding request.
  1. Changes to a profile may be reviewed by the Administration for compliance with the publication rules before they are published. Such review constitutes technical or editorial moderation and does not amount to verification of the accuracy of the information provided.
  2. The Specialist is responsible for the content, accuracy, lawfulness, and relevance of the information they publish.
  3. Electronic identification methods may be used to identify a Specialist, including a qualified electronic signature in accordance with the Law of Ukraine “On Electronic Trust Services” or the Diia.Signature service.

8. Retention of Personal Data

  1. Personal Data is stored electronically on the servers of the Administration or technical and cloud service providers engaged by it. The exact location of the servers may vary depending on the selected provider. Up-to-date information about the categories of providers and international transfer mechanisms is available upon request. Mobile session tokens and the Application Identifier may also be stored locally in the secure storage provided by the operating system of the mobile device.
  2. Retention periods by data category:
Data Category
Retention Period
Legal Basis
User enquiry data
Until the purpose of the enquiry has been fulfilled and for 6 months thereafter
Legitimate interests (technical archive)
Specialist profile
For the duration of the account and for 1 year after its deletion
Performance of a contract
Technical logs
Up to 90 days
Security and legitimate interests
Analytical cookies
Up to 26 months
Consent
Marketing cookies
Up to 13 months or for the period specified by the relevant provider
Consent
Technical cookies
For the duration of the session or up to 12 months
Provision of Platform functions and legitimate interests
Mobile session tokens
Until expiry, sign-out, revocation of the mobile session, or deletion of the account
Performance of a contract and security
Application Identifier (device_id)
On the device—until the secure storage is cleared; on the server—until the associated mobile session is revoked or the account is deleted
Performance of a contract and legitimate interests (security)
Push Token, operating system type, and language
Until push notifications are disabled, the account is deleted, or the Push Token is determined to be invalid
Consent
Geolocation and map area boundaries
Used only to process the current request and not retained after the request has been completed
Consent
28. At the end of the applicable retention period, Personal Data is destroyed, permanently deleted, or anonymised unless its continued storage is required by law, necessary to comply with a legal obligation, or necessary to protect the legitimate rights and interests of the Administration or other persons.

9. Disclosure of Personal Data to Third Parties

29. Personal Data may be disclosed to third parties only to the extent necessary to achieve the purposes specified in this Policy, including:
  • to the Specialist to whom the User’s enquiry is addressed;
  • to providers of hosting, server infrastructure, content delivery networks (CDNs), backup, technical maintenance, and information security services;
  • to analytics service providers, where an appropriate legal basis and, where necessary, the User’s consent exist;
  • to Expo Push Notification Service, Apple Push Notification Service, and Firebase Cloud Messaging for device registration and delivery of push notifications;
  • to Apple Maps or Google Maps for displaying maps, providing directions, and delivering map-related functionality, depending on the User’s operating system and device;
  • to public authorities, law enforcement authorities, or courts in response to a lawful and duly issued request;
  • to other persons where the data subject has provided explicit consent or another legal basis permitted by law exists.
30. Technical service providers may receive only the Personal Data necessary to provide the relevant service. Depending on the nature of the service, they may act as processors of Personal Data on behalf of the Administration or as independent controllers under their own terms and privacy policies. The Administration takes appropriate measures to ensure that engaged providers maintain the same or an equivalent level of Personal Data protection as that provided by this Policy and applicable law. Where necessary, relationships with providers are governed by data processing agreements, terms of service, and other appropriate contractual safeguards. The Administration does not disclose the Application Identifier, Push Token, or geolocation data for advertising profiling or tracking the User across other applications and services.

9.1. International Transfers of Personal Data

31. The use of cloud infrastructure, analytics, push notification, mapping, and other technical services may involve the processing of Personal Data outside Ukraine or the European Economic Area. Where Personal Data is transferred internationally, the Administration ensures an appropriate level of protection by applying one or more of the following mechanisms:
  • transferring data to a country for which the European Commission has adopted an adequacy decision;
  • entering into Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46 GDPR;
  • applying binding corporate rules or other appropriate safeguards provided for by Article 46 GDPR;
  • relying on a derogation for a specific situation under Article 49 GDPR;
  • relying on another legal basis permitted under Ukrainian law and applicable data protection law.
32. Transfers of Personal Data outside Ukraine are carried out in accordance with Article 29 of the Law of Ukraine “On Personal Data Protection” and other applicable legal requirements. 33. The User has the right to request information about the countries in which Personal Data is processed, the providers involved, and the specific safeguards applied to international transfers. The User may submit such a request to the Administration’s email address specified in the “Contact Information” Section.

10. Rights of Data Subjects

Each User and Specialist has the following rights:
Right
Description and Method of Exercise
Right of access (Article 15 GDPR)
To obtain confirmation as to whether Personal Data is being processed, information about such processing, and a copy of the relevant data. Some information is available through the Personal Account. An additional request may be sent to the Administration’s email address.
Right to rectification (Article 16 GDPR)
To request the correction of inaccurate Personal Data or the completion of incomplete Personal Data. Specialists may edit available data through the Personal Account. In other cases, a request may be sent to the Administration’s email address.
Right to erasure (Article 17 GDPR)
To request the deletion of Personal Data (the “right to be forgotten”) where there are no lawful grounds for its continued retention. A request may be submitted through the Personal Account or sent to the Administration’s email address.
Right to restriction of processing (Article 18 GDPR)
To request the temporary restriction of Personal Data processing in cases provided for by law, including while the accuracy of the data or the lawfulness of processing is being verified.
Right to data portability (Article 20 GDPR)
Where this right applies, to receive the data provided by the User in a structured, commonly used, and machine-readable format or request its transmission to another controller where technically feasible.
Right to object (Article 21 GDPR)
To object to the processing of Personal Data based on the legitimate interests of the Administration. Following receipt of an objection, processing will cease unless the Administration demonstrates compelling legitimate grounds for continuing it.
Right to withdraw consent
To withdraw consent at any time. Analytical and marketing cookies may be disabled through Cookie settings, push notifications may be disabled in the Mobile Application or operating system settings, and access to geolocation may be withdrawn in the operating system settings. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Protection from automated decision-making (Article 22 GDPR)
Not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects, except where expressly permitted by law.
Right to lodge a complaint
To lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or, where the GDPR applies, with the competent supervisory authority in the EU Member State of the User’s habitual residence, place of work, or place of the alleged infringement.
34. A request concerning the exercise of a data subject’s rights will be answered no later than 30 calendar days after its receipt, unless another period is prescribed by law. Where the GDPR applies, a response will be provided within one month. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests. The data subject will be informed of the extension and the reasons for it within one month of receipt of the request.

11. Personal Data Breach Notifications

  1. If a Personal Data breach is identified, the Administration assesses the potential risks to the rights and freedoms of data subjects and, where required by law:
  • notifies the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach (Article 33 GDPR);
  • where the breach is likely to result in a high risk to the rights and freedoms of individuals, notifies the affected data subjects without undue delay (Article 34 GDPR);
  • takes the necessary measures to contain the incident, remedy its consequences, and prevent similar incidents from recurring.
  1. Where notification is required, it includes available information about the nature of the breach, the categories and approximate number of affected data subjects, the likely consequences of the breach, and the measures taken or proposed to address the breach and mitigate its possible adverse effects.

12. Protection of Personal Data

  1. The Administration applies appropriate technical and organisational measures to protect Personal Data processed through the Website and the Mobile Application, including:
  • encrypting data in transit using secure SSL/TLS protocols;
  • restricting access to Personal Data in accordance with the principle of least privilege;
  • using authentication and session management mechanisms for Users and Specialists;
  • storing mobile authorisation tokens in the device’s secure storage where supported by the operating system;
  • backing up data where necessary to maintain and restore the operation of the Platform;
  • maintaining technical logs and monitoring attempts at unauthorised access;
  • limiting the retention of Personal Data according to the purpose for which it is processed.
  1. Despite the measures taken, no method of transmitting or storing data over the Internet can guarantee absolute security. If a vulnerability or incident is identified, the Administration takes the necessary measures to remedy it and reduce its possible adverse consequences.

13. Minors

  1. The Website and the Mobile Application are not intended for independent use by individuals under 18 years of age.
  2. The Administration does not knowingly collect Personal Data from minors. If the Administration becomes aware that a minor’s Personal Data has been provided without an appropriate legal basis or the consent of their legal representative, such data will be deleted within a reasonable period unless its continued retention is required by law.

14. Confidentiality of Information

  1. Personal Data and other confidential information obtained through the Website or the Mobile Application will not be disclosed except where required by law, necessary for the operation of the Platform or performance of a contract, or expressly provided for in this Policy.
  2. Reviews, case studies, or other materials that make it possible to identify an individual will be published only with that individual’s prior written consent, including consent provided electronically.

15. Contact Information

For any questions concerning the processing of Personal Data, the exercise of data subject rights, withdrawal of consent, or the submission of a complaint, please contact:

Public Union “Ukrainian Academy of Mediation”
Email: info@mediation.ua
Website: https://mediation.ua

Ukrainian Parliament Commissioner for Human Rights—the supervisory authority responsible for Personal Data protection in Ukraine:
Website: https://ombudsman.gov.ua