FEMIXFEMIXONE BUSINESS SYSTEM
Legal

Privacy Policy

What data FEMIX collects, why, who receives it and what you can do about it — in plain language, no fine print.

Effective 17 September 2026

This Policy explains what personal data FEMIX collects, why, on what legal basis, and what you can do about it. It covers the femix.one website, the FEMIX platform (the workspace in which a business runs its sales, stock, money and customer conversations), storefronts running on FEMIX, and the messaging and social-media integrations an account owner connects.

1. Who processes the data

The controller of personal data of website visitors and platform users is Ihor Fedianin, sole proprietor (ФОП) registered in Ukraine ("FEMIX", "we").

Ihor Fedianin, sole proprietor (ФОП) registered in Ukraine
Tax ID (РНОКПП): 3184012414
Address: 73003, Ukraine, Kherson, Pokrysheva St. 53, bldg. 4, apt. 71
Email: faimcore@gmail.com
Phone: +38 098 550 77 99

2. Two roles: controller and processor

FEMIX acts in two roles, and which one applies decides whom to contact.

  • Controller — for data of femix.one visitors and of the owners and staff of FEMIX accounts. We are responsible for this data.
  • Processor — for data that a business using FEMIX (the "Customer") enters into its workspace or receives through connected channels: its buyers, orders, counterparties, conversations. The Customer is the controller of that data; we process it only on the Customer's instructions and to the extent needed to provide the service. If you are a buyer of such a business, direct questions about your data to that business first; we will help if it does not respond.

3. What data is collected

Account data. On sign-up — name, email, phone, organisation name and details, a hashed password or a passkey. Afterwards — actions in the workspace recorded by the change log (who changed what in a document, and when).

The Customer's business data. Everything the Customer enters to run its business: products, stock, orders, invoices, payments, counterparties and their contacts, documents. We do not decide what data the Customer collects about its buyers — that is the Customer's decision and responsibility.

Data from connected messengers and social networks. When a Customer connects its Instagram account, Facebook Page, WhatsApp Business, Telegram or Viber to FEMIX, FEMIX receives and stores, through the official APIs of those platforms:

  • inbound and outbound messages and attachments in the Customer's conversations with its buyers, and comments and replies on the Customer's posts;
  • the counterpart's identifier, username, display name and profile photo — as the platform passes them along with the message;
  • event timestamps, delivery and read status;
  • basic data of the Customer's business profile on the platform: identifier, username, name, and the access token issued by the platform.

This data is used solely to show the conversation in the Customer's workspace, to reply to the buyer through the same channel, and to create an order or a customer record. We do not use it for advertising, do not analyse it for profiling, do not sell it and do not share it with third parties. We never ask for or store passwords to social-media accounts: access is granted by the platform through a token the Customer can revoke at any time. Data received from Meta Platforms is processed in accordance with the Meta Platform Terms and Developer Policies.

Technical data. IP address, browser and device details, language, the page from which a form was sent or an action taken — needed for security, abuse prevention and to evidence the fact and circumstances of consent.

Usage statistics. Anonymised events about how the website and workspace are used (which pages are opened, which features are used) via PostHog and, only with consent to analytics cookies, Google Analytics.

We do not collect special categories of data and do not ask for them. The service is not intended for persons under 16.

4. Purposes and legal basis

  • Providing access to the workspace, keeping records and showing conversations — basis: performance of the contract with the Customer.
  • Responding to a contact-form enquiry or demo request — basis: consent, given by submitting the form.
  • Issuing invoices, keeping accounting records — basis: legal obligation.
  • Protecting the service from abuse, investigating incidents — basis: legitimate interest.
  • Understanding how the service is used and improving it — basis: consent to analytics cookies, or anonymised statistics.

Data is not used for automated decisions that have legal effects on you.

5. Who receives the data

We rely on providers without whom the service would not work. Each receives only what its part of the job requires:

  • Hosting and storage — Hetzner Online GmbH (Germany, EU): servers and database; Cloudflare, Inc.: content delivery, attack protection, file storage.
  • Messaging and social platforms — Meta Platforms (Instagram, Facebook Messenger, WhatsApp), Telegram, Viber (Rakuten): pass us the messages the Customer receives from buyers and deliver the Customer's replies.
  • Payments and banks — Monobank (Universal Bank), PrivatBank (LiqPay): subscription payments, online payments on storefronts, statements of accounts the Customer has connected.
  • Delivery — Nova Poshta: shipping labels and tracking.
  • Notifications — email and push-notification providers, Telegram.
  • Analytics — PostHog (EU); Google LLC, if consent to Google Analytics is given.

Data is not shared with any other third party except where the law expressly requires it.

6. Transfers outside Ukraine

Servers are located in the European Union. Some providers (Cloudflare, Meta, Google) also process data in the United States; such transfers rest on agreements with those providers that provide an adequate level of protection, and on their terms.

7. Retention

  • Account data — for as long as the account exists, plus 30 days after deletion (so an accidental deletion can be undone), after which it is erased.
  • The Customer's business data — for as long as the Customer uses the service; after account deletion, 30 days in the recycle bin, then erased. Backups are kept for up to a further 30 days and then overwritten.
  • Conversations from connected messengers — for as long as the channel is connected. After the channel is disconnected or access is revoked on the platform's side, data from that channel is deleted within 30 days.
  • Accounting records — for the period required by law.
  • Anonymised statistics — per the analytics provider's rules.

8. Your rights

Under the Law of Ukraine "On Personal Data Protection" and, where it applies, the GDPR, you have the right to:

  • know who processes your data and for what purpose;
  • access your data and obtain a copy;
  • have inaccurate or incomplete data corrected;
  • have your data erased or its processing restricted;
  • withdraw consent — this applies going forward and does not make prior processing unlawful;
  • lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or your local supervisory authority.

To exercise any of these rights, write to faimcore@gmail.com. Step-by-step deletion instructions are on the Data deletion page. We respond within the period set by law.

9. Cookies

Technical cookies are required to sign in and for the website to work, and store, among other things, your consent choice. Analytics cookies are set only after your consent; until then analytics is not loaded. You can change or withdraw your choice at any time in the cookie settings at the bottom of the page.

10. Security

Connections are encrypted (HTTPS). Customers' data is isolated from one another at the database level. Workspace access is protected by a password or passkey and multi-factor authentication; staff rights are limited by roles. Access tokens for third-party platforms are stored encrypted. Software is kept up to date and backups are taken daily.

In the event of a personal-data breach that poses a risk to your rights, we will notify you and the competent authority in the manner prescribed by law.

11. Changes to this Policy

A new edition is published on this page with a version number and publication date. Your consent is recorded together with the edition you accepted, so it is always possible to establish exactly which text you agreed to.