Back to home

Privacy Policy

Last updated: 23 August 2026

This Privacy Policy explains how Uplo processes personal data submitted through uplo.services, our corporate website. The contact form is the Site's only point of data collection. Our AEO Analyzer product at aeo.uplo.services operates its own accounts, payment processing and cookies, and is governed by a separate privacy policy.

1. Scope and Application

This Policy applies exclusively to personal data collected through uplo.services (the “Site”), the corporate and marketing website operated by Uplo (“Uplo”, “we”, “us”). It sets out the categories of personal data we process, the purposes and legal bases for that processing, the recipients of the data, the applicable retention periods, and the rights available to you as a data subject.

This Policy does not apply to the Uplo AEO Analyzer, our software-as-a-service product at aeo.uplo.services. That service operates a separate account system, payment infrastructure and cookie framework, and is governed by its own privacy policy. Where you interact with both properties, each is governed by the notice applicable to it.

We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”), which applies to the offering of our services to individuals in the European Economic Area by virtue of Article 3(2), and with the Law of Ukraine “On Personal Data Protection” No. 2297-VI, which governs our processing as an entity established in Ukraine. Where the two frameworks impose differing standards, we apply the higher.

The Site is addressed to business users and is not directed at children. We do not knowingly collect personal data from individuals under the age of 16.

2. Data Controller Information

The controller responsible for the processing described in this Policy, within the meaning of Article 4(7) GDPR, is Uplo, 60 Shevchenka Street, Lviv, Ukraine. All correspondence relating to data protection should be sent to hello@uplo.services.

Data protection contact. We have not appointed a Data Protection Officer. Our processing is limited in scope, does not involve large-scale processing of the special categories of data referred to in Article 9 GDPR, and does not involve regular or systematic monitoring of data subjects on a large scale; the criteria for mandatory designation under Article 37(1) GDPR are therefore not met. Accountability for data protection is retained at management level, and requests, enquiries and complaints sent to hello@uplo.services are handled directly by Uplo's founders as the designated data protection contact.

Representative in the Union. Processing under this Policy is occasional, does not include special categories of data or data relating to criminal convictions and offences, and is unlikely to result in a risk to the rights and freedoms of data subjects. We therefore rely on the derogation in Article 27(2)(a) GDPR and have not appointed a representative in the Union. Should the nature or scale of our processing change, we will appoint a representative and update this Policy accordingly.

3. Data We Collect and Purpose of Processing

We apply the principle of data minimisation under Article 5(1)(c) GDPR: we collect only the personal data you actively submit through the contact form, and only to the extent necessary to respond to your enquiry. The Site carries out no background collection, no profiling, no enrichment from third-party sources, and no pre-population of form fields from any other origin.

The categories of personal data processed, and the purpose of each, are as follows:

  • Identification and contact data — the name and email address you enter. Purpose: to identify you as the sender, to respond to your enquiry, and to send an automated acknowledgement confirming receipt of your submission.
  • Enquiry content — the message you write and the service categories you select. Purpose: to assess your request, to route it to the appropriate member of our team, and to prepare a substantive response or proposal.
  • Attachments — a single optional file, processed only where you choose to upload one. Purpose: to review supporting material you consider relevant to your enquiry.
  • Technical and security data — request metadata generated automatically by our infrastructure, including IP address. Purpose: to apply rate limiting and to protect the Site and our systems against abuse.
  • Usage and campaign data — the pages you request, the site or campaign that referred you, including the utm_source, utm_medium, utm_campaign and related parameters carried in the link you followed, and coarse technical attributes such as browser, device type and the country inferred from your IP address. Purpose: to measure which channels and campaigns bring visitors to the Site, and which pages hold their attention. Collected in one of the two forms described below, according to your answer to the cookie banner.

Attachments. Please do not submit special categories of personal data within the meaning of Article 9 GDPR, personal data relating to third parties, or confidential material you are not authorised to disclose. Where an attachment necessarily contains third-party personal data, you confirm that you have a lawful basis for disclosing it to us.

Technical logs. Where request metadata is written to our application logs, email addresses are masked and IP addresses truncated before the record leaves our server, so that log data cannot be attributed to an identified individual without additional information that we do not hold.

Cookies and analytics. With your consent, the Site uses Google Analytics 4, provided by Google Ireland Limited, to measure how it is found and used. Consent is managed through Google Consent Mode: for visitors in the European Economic Area, the United Kingdom, Switzerland, Brazil and Quebec, analytics and advertising storage are set to “denied” before any Google script is loaded, and a consent banner is presented. Nothing is written to or read from your device unless you accept. Where you accept, Google Analytics sets the cookies “_ga” and “_ga_<id>”, which distinguish one session from another and recognise a returning browser, and which expire two years after they are last set. Where you decline, or leave the banner unanswered, those cookies are never set: Google Analytics continues to send a reduced signal recording the page requested, the site that referred you and any campaign parameters in the link you followed, together with coarse technical attributes such as browser, device type and the country inferred from your IP address. That signal is accompanied by no identifier for you and involves no storage on your device. You may change your answer at any time by clearing this Site's data in your browser, which restores the denied default and presents the banner again.

Local storage. Two values are kept on your device, each under a key we set directly, and neither is transmitted to us: your language preference, under “uplo.locale”, so that the Site opens in the language you last selected; and your answer to the cookie banner, under “uplo.consent”, so that you are not asked again on every visit.

Limits on use. We do not use contact form data for marketing purposes, do not add enquirers to mailing lists, and do not sell personal data or make it available to third parties for their own purposes. We carry out no automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

4. Legal Basis for Processing

Each processing operation described in Section 3 is carried out on one or more of the following legal bases under Article 6(1) GDPR:

  • Article 6(1)(b) — steps taken at the request of the data subject prior to entering into a contract. Where your enquiry concerns our services, responding to it, scoping the engagement and preparing a proposal are pre-contractual steps carried out at your request.
  • Article 6(1)(f) — legitimate interests. Where an enquiry does not lead to a contract, we rely on our legitimate interest in responding to business correspondence, maintaining a record of that correspondence, and protecting our infrastructure against abuse. We have balanced those interests against your interests, rights and freedoms and consider that processing limited to data you chose to send us does not override them.
  • Article 6(1)(a) — consent. This is the basis on which analytics cookies are stored on and read from your device, where you accept the cookie banner; and the basis for an attachment or additional information you voluntarily supply beyond what is necessary for us to respond. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Article 6(1)(c) — compliance with a legal obligation, where retention of records is required of us, for example under applicable tax and accounting law once a contractual relationship has been established.

Measurement without storage. Where you decline the banner or leave it unanswered, the reduced signal described in Section 3 is processed on the basis of our legitimate interests under Article 6(1)(f) in understanding how the Site is reached and which content serves its visitors. Nothing is stored on or read from your device for that purpose, so no consent is required for it under Article 5(3) of Directive 2002/58/EC; the signal carries no identifier capable of singling you out, and we have balanced that processing against your interests, rights and freedoms accordingly.

Under the Law of Ukraine “On Personal Data Protection”, the corresponding grounds are those set out in Article 11: the consent of the data subject, the conclusion and performance of a transaction to which the data subject is a party, and the legitimate interests of the controller.

Provision of your name, email address and message is neither a statutory nor a contractual requirement. It is, however, necessary for us to respond: if you do not provide it, we cannot process your enquiry.

Right to object. Where we rely on legitimate interests, you may object to the processing at any time under Article 21 GDPR, as described in Section 8.

5. Data Retention and Security

We retain personal data only for as long as necessary for the purposes for which it was collected, in accordance with Article 5(1)(e) GDPR. The following periods apply:

  • Contact enquiries and attachments — retained for the duration of the correspondence and for a maximum of 24 months from your last communication with us, after which they are deleted. Attachments are deleted together with the enquiry to which they relate.
  • Records relating to a concluded contract — retained for the period required by applicable tax, accounting and limitation-period rules, after which they are deleted or irreversibly anonymised.
  • Technical logs — retained on a short rolling operational basis and held in masked form, with email addresses obscured and IP addresses truncated before storage.
  • Analytics data — event-level records are retained by Google for no longer than 14 months from collection, in accordance with the retention period configured on our property, after which they are deleted. Aggregated reports derived from them are not time-limited and contain no data relating to an identified or identifiable person.

Early erasure. You may request erasure before the end of the applicable retention period at any time, and we will comply unless we are required or entitled to retain the data on one of the grounds set out in Article 17(3) GDPR. You are not required to give a reason for the request.

Security measures. We implement technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. These include encryption of data in transit (TLS) between your browser, the Site and our infrastructure; access to submitted enquiries restricted to Uplo's founders through authenticated administrative accounts; storage of attachments on a dedicated volume outside the application database, subject to a file-type allow-list and a maximum file size; validation and sanitisation of uploaded file names; rate limiting on submission endpoints; and masking of identifiers in application logs.

Personal data breaches. In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will communicate it to you directly in accordance with Article 34 GDPR.

6. Third-Party Processors and Infrastructure

We engage a limited number of service providers who process personal data on our behalf. Each acts as a processor within the meaning of Article 4(8) GDPR, solely on our documented instructions and under a data processing agreement meeting the requirements of Article 28 GDPR. None of them is authorised to process your data for its own purposes.

  • Cloudflare, Inc. (Cloudflare Pages) — delivery of the Site's static content and network-level protection of inbound traffic.
  • DigitalOcean, LLC — hosting of the application server that receives and stores contact form submissions and any attachment.
  • Resend — transactional email delivery: routing your enquiry to our team inbox with your address set as reply-to, and sending your acknowledgement of receipt.
  • Grafana Labs (Grafana Cloud) — storage and analysis of technical logs, which are masked and truncated before transmission as described in Section 3.
  • Google Ireland Limited (Google Analytics 4) — measurement of Site traffic, in whichever of the two forms described in Section 3 applies to your visit. Google processes that data on our behalf under the Google Ads Data Processing Terms; where storage is denied, it receives only the reduced, cookieless signal.

We do not sell personal data, do not share it with data brokers, and do not disclose it for third-party advertising. We may disclose personal data to our professional advisers where necessary for the establishment, exercise or defence of legal claims, and to a competent authority or court where we are required to do so by law.

This list reflects our processors as at the date of this Policy. Where we engage an additional or replacement processor, we will update this Section before or promptly upon the change taking effect.

7. International Data Transfers

Uplo is established in Ukraine, and the providers listed in Section 6 operate infrastructure outside Ukraine, including in the European Economic Area and the United States. Your personal data may therefore be transferred to, and processed in, those jurisdictions.

Transfers from the EEA. Where personal data is transferred from the European Economic Area to a country not benefiting from an adequacy decision, we rely on the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR, as incorporated into our data processing agreement with each provider, supplemented where applicable by the provider's certification under the EU–U.S. Data Privacy Framework. Those safeguards are accompanied by the technical measures described in Section 5, including encryption in transit and the masking of identifiers before data is written to logs.

Transfers from Ukraine. Transfers are made in accordance with Article 29 of the Law of Ukraine “On Personal Data Protection”: to states party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108) and to other states recognised as ensuring adequate protection, on that basis; and to any other state on the basis of the contractual safeguards in our processor agreements and the necessity of the transfer for the purposes set out in this Policy.

A copy of the transfer safeguards applicable to a given processor is available on request to hello@uplo.services.

8. Your Rights as a Data Subject

Subject to the conditions and exceptions set out in Chapter III GDPR, you have the following rights in relation to your personal data:

  • Right of access (Article 15) — to obtain confirmation as to whether we process personal data concerning you, a copy of that data, and information about the purposes, recipients and retention periods.
  • Right to rectification (Article 16) — to have inaccurate personal data corrected and incomplete data completed.
  • Right to erasure (Article 17) — to obtain the deletion of your personal data where one of the grounds in Article 17(1) applies.
  • Right to restriction of processing (Article 18) — to have processing limited while a matter such as the accuracy of the data or an objection you have raised is resolved.
  • Right to data portability (Article 20) — to receive the personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller, where the processing is based on consent or contract and is carried out by automated means.
  • Right to object (Article 21) — to object at any time to processing based on our legitimate interests. We will cease the processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.
  • Right to withdraw consent (Article 7(3)) — where processing is based on consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint (Article 77) — with a supervisory authority, in particular in the EEA member state of your residence, place of work or the place of the alleged infringement; in Ukraine, with the Ukrainian Parliament Commissioner for Human Rights.

How to exercise your rights. Send your request to hello@uplo.services. We will respond within one month of receipt. Where a request is complex, or where a number of requests have been made, we may extend that period by up to two further months in accordance with Article 12(3) GDPR, informing you of the extension and the reasons for it within the first month.

Fees and verification. Requests are handled free of charge. Where a request is manifestly unfounded or excessive, we may charge a reasonable administrative fee or decline to act on it, as permitted by Article 12(5) GDPR. Where we have reasonable doubts as to the identity of the person making a request, we may ask for additional information necessary to confirm it under Article 12(6) GDPR; that information is used solely for verification and is deleted once the request has been resolved.

9. Changes to This Policy

We review this Policy periodically and will amend it whenever our processing activities, our processors or our retention practices change. The version in force is always published at this address, and the “Last updated” date at the top of the page identifies it.

Changes that materially affect the basis on which we process your personal data will be reflected in this Policy before the change takes effect. As the Site operates no mailing list, that date is the authoritative record of revision; we recommend reviewing this page before submitting an enquiry.

10. Contact and Inquiries

Questions about this Policy, requests to exercise the rights described in Section 8, and complaints about our handling of personal data should be addressed to Uplo, 60 Shevchenka Street, Lviv, Ukraine, or by email to hello@uplo.services.

We treat data protection correspondence as a priority and will acknowledge receipt of your request. If you are not satisfied with our response, you retain the right to lodge a complaint with the competent supervisory authority as described in Section 8.

Requests to exercise your rights, and any questions about this Policy, may be addressed to hello@uplo.services