Defend24 Check your risk

Privacy Policy of Defend24

This is a preliminary version: the service is undergoing pilot testing. Final approval by a lawyer will take place before the public launch. This page describes the actual terms of the platform as of today.

The Ukrainian version of this document prevails; this English translation is provided for convenience.

Version of 30 July 2026 · version 1.0 (preliminary — pilot testing)

1. Who processes the data (controller)

The controller of personal data is the individual entrepreneur Yevhen Yevhenovych Shkuridin (Шкурідін Євген Євгенович) (the Defend24 platform); taxpayer identification number (РНОКПП) 3067003719; record in the Unified State Register dated 18.06.2025 No. 2010350010004407526; address for enquiries and correspondence — 31 Oskolska St., office 14, Kyiv, Ukraine. Personal data enquiries: info@defend24.org. Full details — defend24.org/en/rekvizyty.html.

Legal assistance is provided by independent advocates under a separate agreement with you; with regard to the data you give the advocate within such an agreement, the advocate acts independently and keeps advocate–client privilege under Ukrainian law (section 9).

2. What data is collected

The scope of data depends on how you use the service:

  • the website form (“No Telegram”) — the name and phone number you leave for contact;
  • registration in the Telegram bot — the Telegram identifier, name, phone number, city;
  • the account and the dossier — the profile data you enter: full name, taxpayer number, identity document details, protected addresses, trusted contacts and their details;
  • cases and documents — the files you upload, the chronology of case events, the time limits entered into the case;
  • an alert (SOS) — the address and/or geolocation you provide to organise the attendance, the time and course of the call-out;
  • payments — the amounts, dates and statuses of payments and orders. The Platform does not receive and does not store full card details — they are processed by the payment service;
  • technical records — the IP address and time in the acceptance log and the security event log (audit), notification settings.

The website uses no third-party trackers or analytics; only your theme choice is stored locally in your browser.

3. Purpose and legal grounds of processing

The data is processed for: contacting you at your request; concluding and performing the agreement with the Platform (providing the service, dispatching, calling out an advocate, deadline reminders, document storage); making payments and refunds; account security and the recording of legally significant events (acceptances, audit); and the performance of obligations imposed on the Platform by law.

The legal grounds (Article 11 of the Law of Ukraine “On Personal Data Protection”) are: your consent; the necessity of concluding and performing a transaction; the performance of a statutory obligation of the controller.

Consent is recorded at the moment it is given (a timestamp in the account; for acceptances — the acceptance log: date, channel, IP).

4. Who the data is transferred to

The data is transferred only to those without whom the service does not work:

  • the advocate assigned to your enquiry — the call-out and case details needed for the attendance and the work under your agreement with them (the legal ground is the necessity of performing the agreement with you: dispatching and passing the enquiry to the advocate is the essence of the service);
  • the dispatcher on duty and the operational dispatch channel — the call-out data (including the address/geolocation upon an alert) is passed through an operational channel in the Telegram messenger for immediate coordination of the attendance;
  • Telegram (messenger) — as the channel of the bot and of notifications;
  • LiqPay (JSC CB “PrivatBank”) — processing payments and refunds;
  • Netlify — website hosting and intake of the “No Telegram” form;
  • Cloudflare — routing and protection of connections to the Platform’s server;
  • Resend — sending service e-mails (confirmations, notifications); processing in the EU region (Ireland);
  • public authorities — solely in the cases and manner directly established by law.

The Platform does not sell personal data and does not share it for advertising.

Cross-border transfer. The servers of Telegram, Netlify and Cloudflare may be located outside Ukraine; Resend processes mail in the EU region (Ireland). The transfer is carried out in accordance with Article 29 of the Law of Ukraine “On Personal Data Protection”: to states that ensure adequate protection of personal data, and in other cases — on the grounds defined by the law, in particular where the transfer is necessary to provide the service to you (the operation of the Telegram bot is technically impossible without transferring data to that messenger) or with your unambiguous consent.

5. Retention periods

  • Website form request — until the enquiry is handled, then up to one year if you have not become a client;
  • Account and dossier data — for as long as the account exists;
  • Case documents — for as long as the account exists, unless you have deleted them earlier;
  • Acceptance log, security event audit — three years after the agreement ends (the general limitation period);
  • Payment records — the periods established by tax legislation for the accounting of settlements.

After the period expires, the data is deleted or anonymised.

6. Account deletion

Deletion is started by you in the Account: the service shows what exactly will be deleted and asks you to enter a confirmation code (protection against accidental deletion). After confirmation the account is marked for deletion and a cancellation window applies — seven days during which you can change your mind and cancel the deletion in the Account. There is no automatic erasure in the Service: after the cancellation window expires, the deletion is performed manually by an authorised person of the Platform — within thirty days of the expiry of the cancellation window, except for data the law requires to be kept longer (payment accounting, the acceptance log) — it is kept anonymised or separately within the periods of section 5.

For advocates connected to the platform: self-service account deletion is not possible while the advocate has active cases — this is required by the duty to preserve advocate–client privilege; the deletion is performed through an administrator after the cases are completed.

7. How the data is protected

  • document files are encrypted at rest; the encryption keys are stored separately from the data;
  • access is segregated by roles: case materials are visible to the advocate assigned to the case and to authorised staff within their role;
  • data is classified by sensitivity; the most sensitive categories are not relayed as text in messengers;
  • the issuance of protected documents and of protected links to them is recorded in the security event log;
  • connections are protected by HTTPS.

8. Your rights

In accordance with Article 8 of the Law of Ukraine “On Personal Data Protection” you have the right: to know about the processing of your data; to access it (a reply within thirty calendar days); to demand the correction of inaccurate data; to demand deletion (section 6); to object to processing; to withdraw consent at any time; and to complain to the Ukrainian Parliament Commissioner for Human Rights or to a court.

How to exercise them: profile and dossier data is edited in the Account; deletion — section 6; for other requests write to info@defend24.org — we reply within thirty calendar days. Withdrawal of consent does not affect the lawfulness of processing before the withdrawal; the part of the service that needs the withdrawn data becomes unavailable after that.

9. Advocate–client privilege

The matters you bring to an advocate, the content of their advice and the documents drawn up under your agreement with them are covered by advocate–client privilege under Ukrainian law (Article 22 of the Law of Ukraine “On the Bar and Practice of Law”). The Platform does not dispose of this information: it maintains technical boundaries of access (section 7), does not use it for its own purposes and does not disclose it to third parties other than as directly provided by law. In the event of a discrepancy between this Policy and the regime of advocate–client privilege, the privilege regime applies.

10. Cookies and local storage

The website does not use cookies for tracking. Only your theme choice is kept in the browser’s local storage. Prices on the pages are loaded from the Platform’s server without transferring your data.

11. Changes to the Policy

A new version is published on this page with its date; we will notify about material changes through the Account or the channels of the service. Previous versions are provided on request.