Effective date: 12 June 2025
Greetings!
Lviv Chamber of Commerce and Industry (Company Number: 02944886), along with its affiliates, directors, officers, agents, employees, contractors, consultants, and licensors (collectively referred to as the “Company,” “we,” “us,” and “our”), is committed to protecting your privacy and ensuring the security of your Personal Data. This Privacy Notice outlines how we collect, use, disclose, and safeguard your information when you access and use the Platform.
Please note that this Privacy Notice is an integral part of our Terms & Conditions (the “Agreement”). All terms not defined in this Privacy Notice shall have the same meaning ascribed to them in the Agreement.
By accessing and using the Platform, you acknowledge that you have read, understood, and agree to the terms of this Privacy Notice. We encourage you to review this Privacy Notice carefully to understand our practices regarding your Personal Data.
If you do not agree with any part of this Privacy Notice, you are prohibited from using the Platform and must cease any use immediately. Your continued use of the Platform constitutes your acceptance of this Privacy Notice and your consent to our data practices as described herein.
- DEFINITIONS
- Personal Data: Information relating to an identified or identifiable natural person (the data subject), such as names, contact information, or any unique identifier that can be used to distinguish or trace an individual’s identity.
- Data Processing: Any operation or set of operations performed on personal data, whether automated or not. This includes collecting, recording, organizing, storing, altering, retrieving, using, disclosing, or deleting data.
- Data Processing Legal Grounds: The lawful bases under which personal data may be processed, including consent, contractual necessity, legal obligations, protection of vital interests, public interest, and legitimate interests of the data controller or a third party.
- Data Subjects: Individuals to whom personal data pertains, and with rights concerning the collection, use, and protection of their data.
- Cookies: Small files stored on a user’s device by websites they visit. They collect information about their browsing habits, preferences, and device details. Cookies support functionalities such as user authentication, personalization, and analytics.
- Platform: Website https://iac.in.ua and relevant domains.
- Processor: An entity that processes personal data on behalf of the data controller under specific instructions, without ownership of the data or decision-making authority over its use.
- Recipient: Any person, organization, or entity to whom personal data is disclosed, including third parties, except public authorities, who may receive personal data as part of a specific legal investigation.
- PERSONAL DATA
- Personal Data List: The Company, acting as a data controller, collects and processes the following categories of Personal Data from Users in accordance with applicable data protection laws:
- Identification Data: Name, date of birth, nationality, and proof of identity (e.g., passport or government-issued ID).
- Contact Data: Email address, phone number, and postal address.
- Professional Data: Job title and area of professional activity, industry focus and investment interests, company size and project stage, public biographies and descriptions of projects or startups, resumes, pitch decks, and profiles (where uploaded by the User)
- Financial Data: Information on bank cards, payment methods, and transaction history related.
- Technical Data: IP address, browser type, device information, operating system, and activity logs while using the Platform.
- Behavioral Data: User preferences, interaction history with the Platform, and data collected via cookies and similar technologies.
- Note on Scope: The categories of personal data listed below are based on the current functionality and purpose of the Platform. They represent the types of data the Company typically collects and processes, but this list is not exhaustive. Depending on how Users interact with the Platform or use specific features, additional categories of personal data may be processed in accordance with this Privacy Notice and applicable law.
- Legal Grounds: The Company processes Personal Data based on the following legal grounds:
- Contractual Necessity: To process Identification Data, Professional Data, and Contact Data.
- Legal Obligations: To process Financial Data.
- Legitimate Interest: To process Technical Data, Contact Data, and Behavioral Data.
- Consent: To process all other types of Personal Data where applicable.
- Purposes: Personal Data is processed for the following purposes:
- Services Provision and Platform Access: To provide Platform services, create accounts, authenticate Users, secure account access, and manage profiles.
- Compliance with Legal Obligations: To verify identities, conduct due diligence, and adhere to applicable laws, including taxation requirements and data protection legislation.
- Platform Improvement and Personalization: To analyze user behavior, optimize features, and tailor the Platform experience to Users’ needs.
- Marketing and Communications: To inform Users about new features of the Platform, relevant investment opportunities, industry updates, and promotional offers — only where the User has provided prior consent.
- Business Development: To analyze market trends, improve service offerings, develop strategic partnerships, and enhance the Platform’s competitive positioning.
- Processing Time: Personal Data is processed in the following timeframes:
- Identification Data: Retained for the duration of the User’s account on the Platform and up to 3 years post-account deletion, unless otherwise required by law.
- Contact Data: Retained for 3 years after account closure unless otherwise required by law.
- Professional Data: Retained for 3 years after account closure unless otherwise required by law.
- Financial Data: Retained in compliance with financial and tax regulations, generally up to 5 years.
- Technical Data: Retained for up to 2 years or as necessary for security monitoring and fraud prevention.
- Behavioral Data: Retained until Users withdraw consent or for a maximum of 2 years from their last interaction.
- Specific Processing Rules: The Company may process Personal Data in the following specific situations:
- Data Transfers: Personal Data may be transferred to third-party service providers, such as payment processors, cloud storage providers, or compliance vendors, solely to perform the Platform services. These third parties are contractually bound to safeguard the confidentiality and security of Personal Data and may not use it for any purposes other than those specified by the Company.
- Automated Decision-Making and Profiling: The Company may use automated processing, including limited profiling, to support risk assessment, compliance verification, and service optimization. However, no decisions producing legal effects or similarly significant consequences for Users, such as account suspension, access restrictions, or eligibility determinations, are made solely by automated means. All such decisions are subject to meaningful human review by qualified personnel to ensure fairness, transparency, and the ability to contest the outcome.
- Cross-Border Data Transfers: Personal Data may be transferred to countries outside the User’s jurisdiction. Such transfers comply with applicable data protection laws, including the implementation of appropriate safeguards, such as standard contractual clauses or equivalent measures, to protect the rights and freedoms of Users.
- Marketing: The Company may use Personal Data, including contact details and interaction history, to provide Users with relevant marketing and promotional information. Users can opt out of receiving marketing communications at any time. Marketing activities are conducted in compliance with applicable laws, and we respect User preferences regarding the use of Personal Data for marketing purposes.
- Sale of Personal Data: The Company does not sell, lease, or trade Personal Data to third parties for their independent commercial use. Any data sharing with third parties is restricted to purposes directly related to the Platform’s services or regulatory compliance and is governed by strict confidentiality agreements.
- Children’s Data: The Company is not intended for, nor do we knowingly collect data from, individuals under the age of 18. If it is brought to our attention that Personal Data from individuals under this age has been collected, we will take prompt action to delete such data from our systems by applicable law.
- Processing of Special Categories of Personal Data: The Company does not intentionally collect or process special categories of personal data (“sensitive data”) unless explicit consent has been provided by the data subject or such processing is otherwise permitted or required by applicable law. Special categories of personal data may include, but are not limited to:
- data revealing racial or ethnic origin,
- political opinions,
- religious or philosophical beliefs,
- trade union membership,
- genetic or biometric data for the purpose of uniquely identifying a person,
- data concerning health,
- or data concerning a natural person’s sex life or sexual orientation.
If the User voluntarily provides such data (e.g., via uploaded documents or communications), the Company will process it only where necessary and with appropriate safeguards in place, including obtaining the User’s freely given, specific, informed, and unambiguous consent.
Users are advised not to submit sensitive data unless explicitly requested or legally required.
- COOKIES AND TRACKING TECHNOLOGIES
- CMP: We utilize a Consent Management Platform (“CMP”) to ensure compliance with applicable data protection laws concerning cookies and similar technologies on our website. Through the CMP, Users can control which types of cookies they wish to enable, including essential, performance, analytics, functional, and advertising cookies. Users can review and modify their preferences at any time via the CMP interface, accessible on our Platform.
- Cookies Consent: By consenting to the use of cookies, Users authorize the collection, storage, and processing of data as outlined in the CMP. If consent is withheld or revoked, only essential cookies—required for core website functionality—will be utilized. Please be advised that disabling certain cookies may impact the Platform’s functionality and potentially limit the quality of the User experience.
- SECURITY
- General Security: We prioritize the security of Users’ personal data and implement stringent measures to protect against unauthorized access, alteration, disclosure, or destruction of data. Our security protocols are regularly reviewed and updated to safeguard the integrity and confidentiality of our Platform.
- Technical Means: To ensure data security, we utilize advanced technical solutions such as encryption, secure socket layer (SSL) technology, firewalls, and secure server environments. These measures help protect data during transmission and storage, reducing the risk of unauthorized access.
- Organizational Means: Our team is trained in data protection practices, and we enforce strict internal access controls. Only authorized personnel have access to personal data, and they are bound by confidentiality obligations. We also conduct regular audits and risk assessments to identify and mitigate potential vulnerabilities within our systems.
- DATA BREACH NOTIFICATION
- Data Breach General: Under the GDPR and other applicable legislations, a data breach that risks the rights and freedoms of individuals requires specific actions by the data controller, including notification procedures.
- Data Protection Authorities Notification: In the event of a personal data breach that could impact the rights and freedoms of individuals, we will notify the relevant Data Protection Authority (DPA) without undue delay and, if feasible, within 72 hours after becoming aware of the breach. If we cannot meet this deadline, we will include an explanation for the delay. Our notification to the DPA will include:
- The nature of the breach, specifying the type of data involved and, if known, the approximate number of affected records and Users.
- Contact information for our Data Protection Officer (DPO) or other responsible representative.
- An assessment of the likely consequences of the breach.
- Steps we are taking or plan to take to address the breach and mitigate potential risks to individuals.
- Users’ Notification: If the data breach poses a high risk to the rights and freedoms of Users, we will notify affected individuals directly and without undue delay. However, if protective measures, such as encryption, reduce the likelihood of harm, direct User notification may not be necessary, though we will still inform the DPA. The notification to affected Users will include:
- A clear explanation of the breach and the type of information potentially compromised.
- Potential consequences and recommended actions that Users may take to safeguard themselves.
- Contact details for further assistance and information.
- We are implementing measures to resolve the issue and prevent future breaches.
- SUPERVISORY AUTHORITIES
- Ukrainian Supervisory Authority: For Users residing in or subject to the jurisdiction of Ukraine, the competent supervisory authority for matters related to personal data protection is the Ukrainian Parliament Commissioner for Human Rights. The Commissioner is responsible for monitoring compliance with the Law of Ukraine “On Personal Data Protection,” conducting inspections, handling complaints, and initiating corrective actions in case of violations. Official website: https://ombudsman.gov.ua
- EU Supervisory Authorities: For Users located in the European Union or European Economic Area (EEA), the competent supervisory authority is the Data Protection Authority (DPA) of the Member State of residence or habitual location. These authorities are empowered to receive complaints, conduct investigations, and enforce the General Data Protection Regulation (GDPR). A complete and up-to-date list of EU/EEA Data Protection Authorities is available on the official website of the European Data Protection Board (EDPB): https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.
- Procedural Differences: Please note that the procedure for filing and reviewing complaints may vary depending on the rules and practices of each supervisory authority. Users are encouraged to consult the official website of the relevant authority for detailed instructions on how to submit a complaint and what information is required.
- DATA SUBJECT RIGHTS
- Right of Access: Users have the right to request access to the personal data we hold about them. Upon request, we will provide information about the data being processed, the purposes of the processing, data retention periods, and any third-party recipients of the data.
- Right to Rectification: Users have the right to request the correction of inaccurate or incomplete personal data. If any information we hold is incorrect, Users can request that we update or complete their data.
- Right to Erasure (“Right to be Forgotten”): Users can request that we delete their personal data when:
- The data is no longer necessary for the purposes for which it was collected.
- The User withdraws consent (where consent was the basis for processing).
- The User objects to processing, and there are no overriding legitimate grounds.
- The processing was unlawful.
- The data must be erased to comply with a legal obligation.
- Right to Restrict Processing: Users can request a restriction on the processing of their data in specific situations, such as:
- When the accuracy of the data is contested (for a period enabling us to verify accuracy).
- When the processing is unlawful, and the User opposes erasure and requests restriction instead.
- When the data is no longer needed for processing, but the User requires it for legal claims.
- When the User has objected to processing, pending verification of overriding legitimate grounds.
- Right to Data Portability: Users have the right to request a copy of their personal data in a structured, commonly used, and machine-readable format. They may also request that we transmit this data directly to another data controller where technically feasible.
- Right to Object: Users have the right to object to the processing of their personal data on grounds relating to their particular situation, where processing is based on legitimate interests or public interest. If a User objects, we will cease processing unless we demonstrate compelling legitimate grounds for the processing that override their interests, rights, and freedoms, or where processing is necessary for legal claims.
- Right to Withdraw Consent: Where processing is based on consent, Users may withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- Right to Lodge a Complaint: Users have the right to lodge a complaint with a supervisory authority if they believe that their data protection rights under the GDPR have been infringed.
- Scope of Rights: The scope of your rights regarding the processing of your personal data depends on your jurisdiction and the applicable legal framework — namely, the Law of Ukraine “On Personal Data Protection” and, where applicable, the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
8. APPLICABLE LAW AND JURISDICTION
- Applicable Framework: This Privacy Notice is intended to comply with both the Law of Ukraine “On Personal Data Protection” and, where applicable, the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
- Jurisdictional Scope: The Company is primarily established and operates under the jurisdiction of Ukraine, and processes personal data in accordance with Ukrainian data protection legislation. However, the applicable legal framework may vary depending on the User’s country of residence or habitual location.
- Territorial Reach of the GDPR: If the Company offers services to, or monitors the behavior of, individuals located in the European Union or European Economic Area, such processing activities shall be subject to the GDPR in accordance with Article 3(2).
- Prevalence of Higher Standards: Where both Ukrainian law and the GDPR apply concurrently, the Company commits to processing personal data in accordance with the stricter applicable standard or the legal framework that provides the strongest level of protection for the data subject.
- MODIFICATIONS
Review and Update: The Company reserves the right to modify this Privacy Notice at any time. Users will be notified of any material changes via email or through the Platform. Continued use of the Platform after such notifications constitutes acceptance of the revised Privacy Notice.
- CONTACT
Legal Inquiries: For legal inquiries related to the Personal Data, please reach out to our legal team at email: office@cci.lviv.ua.
This Privacy Notice is available in both English and Ukrainian for the convenience of Users. In the event of any discrepancies or inconsistencies between the two versions, the English version shall prevail.


