Donevia
Pricing
  • Українська
  • English ✓
Sign in Get started
Donevia

Privacy Policy

Version: 2026-09-23

This Privacy Policy explains what personal and technical data is processed when visiting the Donevia website and using the Donevia online service, the purposes for which it is used, to whom it may be disclosed, and the rights available to users.

1. General Provisions

1.1. Where Donevia independently determines the purposes and means of processing, the controller of Donevia users’ personal data is Sole proprietor Yurii Donets, taxpayer registration number 3035106257, address: Ukraine, 63401, Kharkiv Region, Chuhuiv District, Zmiiv, 11 Hrabarivskyi Lane (“Donevia”, “we”, the “Provider”).

1.2. This Policy applies to the public website donevia.net, the user Account and Console, administrative and technical components of the Service to the extent they process user data, and communications with Donevia.

1.3. This Policy supplements the Donevia Public Offer . Terms defined in the Offer have the corresponding meaning in this Policy unless expressly stated otherwise.

1.4. Donevia processes personal data only for specified and lawful purposes and seeks to limit data to what is objectively necessary for operation of the Service, performance of the agreement, security, support, payments, analytics and compliance with legal requirements.

2. Data We May Process

2.1. Account data: name or other name provided by the user, email address, password in protected/hashed form, interface language, role, account status, email verification date, last login time and other data voluntarily provided in the Account.

2.2. Authentication and security data: IP address, login time, session data, technical identifiers, information about login attempts, security events and other data required to protect the Account and Service.

2.3. Applications and Service usage data: Account, Application and technical environment identifiers; Application configuration; number and timing of connections; number of messages; traffic volume; resource-usage indicators; errors; technical logs; quota statistics and other operational metadata.

2.4. Payment and billing data: selected Tariff Plan, billing period, amount, currency, order status, payment provider, provider payment identifier, payment time and information necessary for payment accounting and support. Donevia does not plan to store full payment card numbers or CVV; payment credentials are processed by the relevant payment provider.

2.5. Communications data: support requests, email correspondence, information concerning delivery of service communications and other information provided by a user when communicating with Donevia.

2.6. Public Website data: IP address, browser and device type, operating system, pages and viewing events, referral source, approximate technical session information and other information that may be collected through server logs, cookies and web analytics tools.

3. Purposes of Processing

3.1. Data may be processed to create and administer Accounts; authenticate users; provide and technically support the Service; create and operate Applications; apply Tariff Plans and quotas; generate usage statistics; process and account for payments; send service communications; detect abuse and ensure information security; diagnose errors; improve the Service; analyze use of the public Website; comply with legal, accounting and tax obligations; and protect the rights and legitimate interests of Donevia and users.

3.2. Marketing communications, if used, are separated from mandatory service communications. Where consent is required by law, marketing communications are sent on that basis and users are provided with a way to opt out of further marketing communications.

4. Grounds for Processing

4.1. Depending on the particular operation, Donevia processes data to enter into and perform an agreement with the user, comply with legal requirements, on the basis of consent where required, and to protect legitimate interests of Donevia or third parties where such basis is permitted by applicable law.

4.2. Provision of data without which an Account cannot be created, authentication cannot be performed, an order cannot be completed or a relevant Service function cannot be provided is necessary to obtain that function.

5. Cookies and Similar Technologies

5.1. Donevia uses necessary cookies and similar technical mechanisms for sessions, authentication, CSRF and other attack protection, security, storage of technical preferences, language selection and proper operation of the Website, Console and administrative components.

5.2. Necessary cookies are required for the relevant functionality and are not used as advertising trackers.

5.3. On the public Website, Donevia plans to use web analytics tools to understand traffic and use of pages. Such tools may use cookies or similar identifiers.

5.4. Third-party web analytics are not planned for the Customer Console or administrative panel. Internal technical Service metrics, including connections, messages, traffic and quota usage, are not web-analytics cookies and are processed as operational Service data.

5.5. Where applicable law requires prior consent for optional analytics cookies, Donevia provides an appropriate consent-management mechanism. The specific web analytics provider and list of optional cookies may be specified when the relevant tool is implemented.

6. Payload and Customer End-User Data

6.1. Payload determined by the Customer may pass through Donevia’s WebSocket/API infrastructure. Such Payload may contain personal data of the Customer’s end users.

6.2. Donevia does not acquire ownership of Payload merely because it is transmitted through the Service.

6.3. The basic Service is not intended for persistent Payload storage. Temporary technical processing, buffering, logging or other short-term storage may nevertheless occur where necessary for delivery, operation, protection or diagnostics of the Service.

6.4. Where a Customer transmits personal data of its end users through Donevia, the Customer is responsible for determining a lawful purpose and basis for such processing and for required notices and consents. Within such processing, Donevia acts as a technical provider/processor to the extent it processes data on the Customer’s instructions to provide the Service.

6.5. For particular B2B or international scenarios, the parties may enter into a separate Data Processing Agreement (DPA).

7. Providers and Data Disclosure

7.1. Donevia may engage providers that process data only to the extent required for the relevant Service function, including hosting/cloud providers, network and security infrastructure, email delivery providers, payment providers, technical monitoring and support.

7.2. To support the operation of the Service, Donevia may use third-party network, DNS/CDN and security infrastructure, email delivery services and other technical services. The actual scope of data processing depends on the relevant function and configuration of each service.

7.3. As of the date of this Policy, Donevia’s primary server-side components are hosted on infrastructure controlled by the Provider. In the future, Donevia may use third-party hosting/cloud providers or dedicated servers without changing the principal purposes of data processing.

7.4. Third-party payment providers may be used for paid services. The payment methods actually available are shown before payment. A payment provider may independently process payment credentials in accordance with its own privacy policy and legal obligations.

7.5. Donevia does not sell users’ personal data as a commodity and does not disclose it to third parties for their independent marketing without an appropriate legal basis.

8. International Data Processing

8.1. Some external Donevia providers may have infrastructure, group companies or subprocessors outside Ukraine. Technical processing or transfer of certain data may therefore be international.

8.2. When engaging such providers, Donevia takes into account available contractual and organizational safeguards and the processing terms offered by the relevant provider.

9. Retention

9.1. Data is retained no longer than objectively necessary for the purposes for which it was collected unless a longer period is required by law, accounting or tax requirements, security, dispute resolution or protection of legal rights.

9.2. Active Account data is retained while the Account is used. After closure or deletion, certain records may be retained for the period necessary under clause 9.1.

9.3. Technical logs, raw metrics and other operational data may have different retention periods. Donevia may aggregate or anonymize older technical data and delete detailed records after the applicable operational retention period.

9.4. Where a specific retention period is determined by law, a payment provider or a particular Service feature, the relevant period applies.

10. Data Security

10.1. Donevia applies reasonable technical and organizational measures designed to protect data against unauthorized access, accidental loss, alteration, disclosure or destruction.

10.2. Such measures may include access controls, credential protection, encryption in transit, network security controls, logging, backups, monitoring and restriction of administrative access as appropriate for the Service.

10.3. No information system can guarantee absolute security. Donevia reviews and adapts safeguards according to the nature of the Service and relevant risks.

11. Data Subject Rights

11.1. Users have the rights provided by applicable data-protection law, including the right to know about sources of collection, location and purpose of processing of their personal data; receive information concerning access conditions; request access to their data; request correction or deletion where provided by law; object to processing; and withdraw consent where processing is based on consent.

11.2. To exercise rights, a user may contact support@donevia.net. Donevia may request information necessary to verify identity and prevent unauthorized access to data.

11.3. Exercise of particular rights may be limited where expressly provided by law, including where certain information must be retained to comply with a legal obligation or protect legal claims.

12. Email and Service Communications

12.1. Donevia may send communications required or necessary for use of the Service, including email verification, access recovery, security, payments, Account status, changes to the Service or legal documents, technical incidents and support.

12.2. Donevia uses Brevo for email delivery or another provider about which this Policy may be updated accordingly.

12.3. Opting out of marketing communications does not stop service communications necessary for performance of the agreement, security or operation of the Account.

13. Web Analytics

13.1. The public Website may use a web analytics service to evaluate traffic, referral sources, page popularity, technical session characteristics and effectiveness of public pages.

13.2. Until a particular third-party service is actually implemented, Donevia does not state that any particular analytics provider already receives data. After a provider is selected and implemented, this Policy and the cookie mechanism will be updated where necessary.

13.3. Donevia does not plan to use third-party web analytics to track user behavior inside the Customer Console or administrative panel.

14. Changes to this Policy

14.1. Donevia may update this Policy due to changes in the Service, providers, technologies, law or data-processing practices.

14.2. The current version is published on the Website with its revision date.

14.3. Donevia will notify users of material changes that may materially affect their rights or the nature of processing through the Account, email or another available channel where such notification is appropriate considering the nature of the changes and applicable law.

15. Contact Information

15.1. For privacy, personal-data and data-subject-rights inquiries, contact: support@donevia.net.

15.2. The data controller is the Provider identified in clause 1.1 of this Policy.

© 2026 Donevia
WebSocket infrastructure for applications