Thank you for the appeal, the message has been sent.
ORDER A CONSULTATION
Thank you for the appeal, the message has been sent.
Telegram
WhatsApp
A GDPR privacy policy for your website, SaaS or app, plus a cookie policy, terms of service, a public offer under Ukrainian law and a DPA, written around how your product actually processes data.
Since 2012 · 50+ jurisdictions · GDPR, Ukraine, US · documents in English, Ukrainian, Russian and other languages
TelegramWhatsApp
In brief
A GDPR privacy policy is a public document that tells users who processes their data, which data, why, on what legal basis, who receives it, how long it is kept and how users can exercise their rights.
It is needed by owners of websites, online stores, SaaS products and mobile apps: founders from Ukraine working with users in the EU and the US, and Ukrainian online businesses selling to customers in Ukraine.
Turnkey, we map your data flows and write the Privacy Policy, a Cookie Policy with banner texts, Terms of Service or a public offer under Ukrainian law, a DPA for B2B clients and with your contractors, a subprocessor list and texts for App Store and Google Play.
Under Article 3(2) GDPR, the regulation applies to a company outside the EU when it offers goods or services to people in the EU or monitors their behaviour in the EU; the content of a privacy notice is listed directly in Articles 13 and 14.
Usually, in our experience, the document package for one product is ready within 1–3 weeks after the data questionnaire is completed. The timeline depends on the case, its details, the work of the authorities and force majeure.
Your situation
Pick the situation closest to yours: a short outline of the route and the first step.
A Ukrainian SaaS starts selling to clients in the EU
We determine where you are the controller and where you process client data as a processor, and write the Privacy Policy, Terms of Service, a DPA for B2B clients and a public subprocessor list. We also check whether you need an EU representative under Article 27.
Example. A booking service for beauty salons received a set of policy, terms of use and DPA before launching in Poland; its first corporate client signed the DPA after one round of edits.
App Store or Google Play rejected the app over privacy
We check which data the app and its SDKs collect, align the policy and the App Privacy and Data safety answers, and place the policy link in the app and in the developer console.
Example. A fitness app was rejected because its policy omitted an analytics SDK that collected the device identifier. After the review and new questionnaire answers, the build was accepted.
An online store in Ukraine needs a public offer and a policy
We prepare a public offer under Ukrainian law with a clear acceptance procedure at checkout, a privacy policy under the Ukrainian personal data protection law, and delivery and returns rules.
Example. A home goods store replaced a public offer copied from another website with a text built around its own payment, delivery and returns, and disputed customer requests started to be handled under clear rules.
An investor asks for GDPR documents before a round
We compile the record of processing, align the policies with how the product really works, put DPAs in place with contractors and prepare answers to the review questions. In parallel we look at the corporate documents.
Example. A B2B procurement marketplace, three weeks before due diligence, received a record of processing, an updated policy and signed DPAs with its hosting and CRM providers.
Our site runs analytics and ad pixels and needs a cookie banner
We inventory cookies and trackers, split them into strictly necessary and consent-based, write the Cookie Policy and banner texts, and give the developer the logic: optional scripts stay off until consent.
Example. An online school using pixels from two ad networks got a banner with “Accept” and “Reject” buttons on the first screen and settings by category.
We check the client's DPA against how you really work: instructions, subprocessors, incident notification deadlines, audits, transfers outside the EU, liability. We prepare redlines and a negotiating position.
Example. An HR platform developer agreed with a European client on a reasonable incident notification deadline and on audits based on reports instead of on-site inspections.
GDPR privacy policy and SaaS documents: what the turnkey service includes
A turnkey GDPR privacy policy starts with a data map of your product: we write the documents once we understand which data you collect, from whom, why, on what legal basis, where you store it and which services you pass it to. Crystal Tax lawyers carry the work from the questionnaire to final texts in the languages you need.
We write the privacy policy, public offer and DPA for your real product
Generators and templates produce a text that describes someone else's product. Regulators, app stores and the lawyers of B2B clients check exactly the gap between the policy and real processing: the text omits analytics running on the site, states a retention period nobody follows, or leaves out the payment provider.
Where a policy most often diverges from the product
Ad pixels and analytics fire before the user consents, while the Cookie Policy promises the opposite.
The policy omits services that actually receive data: the payment provider, the support chat, an AI service, a mobile SDK.
The stated retention period is not followed, or there is no retention period at all.
The public offer and Terms of Service describe one payment model while the site runs another: a subscription with auto-renewal, a trial period, refunds.
Data is stored outside the EU, and the policy says nothing about it or about transfer safeguards.
The App Privacy or Data safety answers differ from the text of the app's privacy policy.
We check each of these points against the data map before handing the texts over for publication.
Data flow audit
Questionnaire and a call with you and your developer: forms, sign-up, payments, mailings, support, analytics, advertising, mobile SDKs.
Data map: categories of data and users, purposes, legal bases, storage locations, processor services (hosting, CRM, email marketing, payments, analytics), retention periods.
Roles: where you are the controller, where you act as a processor on behalf of a B2B client, where you are a joint controller with a partner.
Transfers outside the EU: whether the European Commission has adopted an adequacy decision for the country, and whether standard contractual clauses or other safeguards under Article 46 GDPR are needed.
Public documents
Privacy Policy under Articles 13 and 14 GDPR and, for a Ukrainian audience, in line with the Ukrainian personal data protection law; a privacy policy for an app that meets App Store and Google Play requirements.
Cookie Policy and consent banner texts with settings logic by category. Your developer installs the banner technically; we give them recommendations and check the result against a checklist.
Terms of Service for SaaS, user terms for a website or a public offer under Ukrainian law for a website in Ukraine: subject matter, payment and subscription, refunds, liability, governing law, how terms are changed. The contractual part follows our practice in contract drafting.
A subprocessor list for publication and a procedure for notifying clients of changes to it.
Contracts and internal documents
DPA (data processing agreement) in both directions: you as a processor for your B2B clients and you as a controller with your contractors, covering the mandatory content of Article 28(3) GDPR.
Record of processing activities under Article 30, data retention and deletion rules, a data breach response procedure, and a check of whether a data protection impact assessment (DPIA) is needed.
A procedure for handling user requests: access, rectification, erasure, objection, data portability.
An assessment of whether an EU representative is needed under Article 27; we do not act as the representative ourselves and help you appoint one through specialised providers and partners.
Which document fits which situation
Situation
Documents
Website with forms and analytics, users in the EU
GDPR privacy policy, Cookie Policy and consent banner, DPAs with contractors
SaaS for business clients in the EU and the UK
Terms of Service, Privacy Policy, DPA for clients, subprocessor list, record of processing
Mobile app
Privacy policy for the app linked in the console and inside the app, App Privacy and Data safety answers, user terms
Online store in Ukraine
Public offer under Ukrainian law, privacy policy under Ukrainian law, delivery and returns rules
Users in the US
Privacy Policy reflecting state requirements; for California, a check of whether CCPA and CPRA apply
Languages and updates
We prepare documents in Russian, Ukrainian and English; other languages go through vetted translators, and we proofread the terminology. When the product changes, for example a new payment provider or market appears, we update the data map and the texts as a one-off job or as part of ongoing legal support for startups, which also covers GDPR compliance for startups.
How long it takes to prepare website and app documents
Usually, in our experience, the document package for one product is ready within 1–3 weeks after the data questionnaire is completed. The timeline depends on the case, its details, the work of the authorities and force majeure.
Assessment of the task — within one working day after a short description of the product and markets.
Questionnaire and data call — usually 2–5 working days; most of the time goes into the developer's answers about services and SDKs.
Privacy Policy and Cookie Policy — usually, in our experience, about a week after the data map.
Terms of Service, user terms or public offer — in parallel with the policy; the timing depends on the payment model and the number of plans.
DPA — your own template is prepared together with the package; negotiating a client's DPA depends on the number of rounds of edits with their lawyers.
Translations — add several working days per language after the main version is approved.
The review period for an app in App Store or Google Play is set by the platform itself; we influence only the quality of the answers and how closely the policy matches the real app.
The work takes longer when the developer is external and slow to respond, when the product uses many SDKs with unclear data transfers, when there is health data, children's data or biometrics, or when a B2B client sends its own DPA with strict terms. We name these points at the start.
Cost of a GDPR privacy policy and document package
The cost of a GDPR privacy policy and a document package, including the work a terms and conditions lawyer would do on your Terms of Service, is calculated individually: it depends on how much data and how many services the product uses and which markets it enters.
Number of products: one website, a website plus an app, several SaaS products under one company.
Markets: the EU, the UK, the US, Ukraine, and whether the requirements of several of them apply at once.
Number of data flows and processor services: analytics, advertising, payments, CRM, mailings, hosting, AI services.
Business model: B2C, B2B, a two-sided marketplace.
Special categories of data, children's data, geolocation, biometrics.
Number of documents and languages.
A one-off package or ongoing updates as the product changes.
Describe the product in a few sentences, and we will assess the work within one working day. An introduction and a first answer are available on a free consultation of 10 minutes; if you need a detailed review, there is a 30-minute consultation for 100 euros.
Why founders trust us with GDPR documents
Five reasons founders trust us with their privacy policy, public offer and data contracts.
In business since 2012
We work in 50+ jurisdictions; we know the requirements of registrars, banks, tax offices and the lawyers of large clients from our own cases.
We handle platforms, counterparties and banks
Answering App Store and Google Play remarks, corresponding with the client's lawyers on a DPA and handling bank questions is our job. From you we need information about the product and decisions.
We carry the case to the result
If a platform, a client or a bank sends remarks on the documents, we rework them at no extra charge.
One team for the whole structure
Company, contracts, data documents, bank account, accounting and taxes, including Ukrainian CFC (controlled foreign company) rules and the CFC report, with no need to look for separate contractors.
Contract and confidentiality
We work under a contract, and the confidentiality terms are written into it.
GDPR privacy policy for your website: how we work
The work runs in six steps, and at each one you know what we need from you.
How we prepare a privacy policy, public offer and DPA turnkey
Task and assessment. You describe the product, markets and users; we assess the scope within one working day.
Contract and questionnaire. We sign a contract, and you and your developer fill in the questionnaire on data and services.
Data map. On a call we clarify data flows, roles, legal bases, transfers outside the EU and retention periods.
Document drafts. We write the policy, Cookie Policy, terms or public offer, DPA and subprocessor list.
Review and translations. We make your edits, check the texts against each other and against the product, and translate them into the languages you need.
Publication and updates. We give your developer instructions on placement and the banner, and update the texts when the product changes.
What we need from you for a GDPR privacy policy
To start, we need information about the company, the product and the services it uses; we provide the questionnaire and the list of questions.
About the company and product
Name, country of registration and contact details of the company that owns the website or app.
Links to the website and app, test access to the user account or a build.
Markets and languages, types of users: individuals, companies, children and teenagers.
About data and services
A list of services: hosting, analytics, ad pixels, CRM, mailings, payment systems, support, mobile SDKs.
Which forms and fields users fill in, and what is collected automatically.
Where and for how long data is stored, and who in the team and at contractors has access to it.
Current documents
Your current policy, public offer or terms, if you have them, even if they come from a template.
DPAs sent by clients and data agreements with contractors.
Remarks from App Store, Google Play, a client or an investor, if there have been any.
If other lawyers have already prepared documents for you, send them over: we will check what can stay and what diverges from the product or from other documents in the package.
Reference: what GDPR requires in a privacy policy
Article 13 GDPR lists the information a controller provides when collecting data from the user directly, and Article 14 covers data obtained from other sources.
Identity and contact details of the controller and, where appointed, its EU representative; contact details of the DPO, where there is one.
Purposes of processing and the legal basis for each purpose; for legitimate interests, what that interest is.
Recipients or categories of recipients of the data.
Transfers to a third country: whether there is a European Commission adequacy decision, or which safeguards apply and how to obtain a copy of them.
Retention period or the criteria used to determine it.
User rights: access, rectification, erasure, restriction of processing, objection, data portability.
The right to withdraw consent at any time where processing is based on consent.
The right to lodge a complaint with a supervisory authority.
Whether providing the data is a statutory or contractual requirement and the consequences of not providing it.
Automated decision-making, including profiling, and the logic involved.
Under Article 14, the categories of data and their source are also stated. The information is provided within a reasonable period, at the latest within one month of obtaining the data, and, if the data is used to communicate with the user or disclosed to another recipient, at the latest at the first communication or first disclosure.
The maximum fine for infringing data subjects' rights and the basic principles under Article 83(5) GDPR is up to 20,000,000 euros or, for an undertaking, up to 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher.
Reference: Privacy Policy, Cookie Policy, Terms of Service, public offer and DPA
Each of the five documents has its own job, and in practice they refer to each other, so they are written together.
Document
Purpose
Who needs it
Legal basis
Privacy Policy
Tell users how their data is processed
Any website or app that collects personal data
GDPR, Articles 13 and 14; Law of Ukraine on personal data protection, Article 12; CCPA for California; App Store and Google Play rules
Cookie Policy and banner
Describe cookies and trackers and obtain consent for optional ones
Websites and services with analytics, advertising, third-party chats
Terms of use of the service, payment, liability, disputes
SaaS, platforms, apps
Contract law of the country chosen in the terms, and consumer protection
Public offer (Ukrainian law)
An offer to conclude a contract with anyone who accepts the terms
Online stores and services selling in Ukraine
Civil Code of Ukraine, Articles 633, 641, 642; Law on e-commerce, Article 11
DPA
Terms of processing data on behalf of the controller
B2B SaaS and anyone who passes data to contractors
GDPR, Article 28(3)
A DPA under Article 28(3) must set out the subject matter, duration, nature and purpose of processing, the types of data and categories of data subjects, as well as the processor's obligations: act only on documented instructions, ensure staff confidentiality, take security measures under Article 32, engage subprocessors only with the controller's authorisation, assist with data subject requests and with the obligations under Articles 32–36, delete or return the data after the end of the services, make information available and allow audits.
Under the ePrivacy Directive, consent to cookies is required for storing and reading information on the user's device. The exception is technical storage for transmitting a communication or storage strictly necessary for a service the user has explicitly requested. Under Recital 32 GDPR, silence, pre-ticked boxes and inactivity do not constitute consent.
Reference: public offer under Ukrainian law and online acceptance
Since 2021, following amendments by Law 1667-IX, the Civil Code of Ukraine expressly recognises as an offer documents publicly available on the internet that contain the essential terms of a contract and a proposal to conclude it with anyone who applies, regardless of whether an electronic signature is present.
Public contract, Article 633 of the Civil Code — the business undertakes to sell goods, perform work or provide services to anyone who applies; the terms are the same for all consumers except for benefits provided by law; terms contradicting this are void.
Offer, Article 641 of the Civil Code — the proposal must contain the essential terms and express the intention to be bound once it is accepted. Advertising and other proposals addressed to an indefinite circle of persons are treated as an invitation to make offers unless they state otherwise.
Acceptance, Article 642 of the Civil Code — the response must be full and unconditional; actions in line with the terms of the offer, such as payment, also count as acceptance unless the offer or the law provides otherwise.
Electronic contract, Article 11 of Law 675-VIII — an offer may be published on the internet and incorporate the terms of another electronic document by a link, to which the user must have free access. Acceptance is possible by an electronic message, by filling in a form or by actions whose meaning is clearly explained in the system where the offer is published.
For a privacy policy in Ukraine, the Law on personal data protection 2297-VI applies: Article 11 lists the grounds for processing, including consent, contract and legitimate interest, and Article 12 requires informing the data subject at the time of collection about the data owner, the data collected, their rights, the purpose of collection and the recipients.
The new consumer protection law 3153-IX was adopted in 2023 and enters into force one year after publication, but not earlier than the day martial law is terminated or lifted. As of 27.09.2026 the official portal shows its status as “entering into force”, so the current consumer protection rules apply to public offers.
How to start
Describe the product in a few sentences: what it is, which markets it enters and which services it uses. We will reply within one working day, and on a free 10-minute call we will name the first step right away.
Regulation (EU) 2016/679 (GDPR), Articles 3, 4, 7, 13, 14, 27, 28, 30, 46, 83, Recital 32; Directive 2002/58/EC (ePrivacy) as amended by 2009/136/EC, Article 5(3); Law of Ukraine on Personal Data Protection No. 2297-VI, Articles 11 and 12; Civil Code of Ukraine, Articles 633, 641 as amended by Law 1667-IX, 642; Law of Ukraine on E-Commerce No. 675-VIII, Article 11; Law of Ukraine on Consumer Protection No. 3153-IX, final provisions; Apple, App Review Guidelines, 5.1.1 (i) Privacy Policies; Google Play, User Data policy and Data safety section; California Attorney General, California Consumer Privacy Act; California Privacy Protection Agency, CPI adjustment of CCPA thresholds from 1 January 2025. Checked: 27.09.2026.
Page rating
5 / 5
Frequently asked questions
Is a privacy policy mandatory for a website?
Yes, if the website collects personal data: forms, sign-up, orders, analytics with identifiers. GDPR and the Ukrainian personal data protection law require telling users who processes their data and why, and App Store and Google Play require a policy link from every app.
Does GDPR apply to a company from Ukraine or the US?
Yes, if the company offers goods or services to people who are in the EU or monitors their behaviour in the EU, as Article 3(2) GDPR states directly. The user's citizenship and the company's place of registration are irrelevant here.
Can I use a privacy policy from a generator?
Yes, as a draft; a generator describes a typical product. Reviewers check exactly whether the policy matches your real data, services and retention periods, so the text will still have to be checked against a data map.
How do I write a GDPR privacy policy?
First build a data map: what is collected, why, on what legal basis, who receives it and how long it is kept. Then set this out in plain language following Articles 13 and 14 GDPR; we do this work turnkey.
Do I need a cookie banner if the site only runs analytics?
For users in the EU, usually yes: the ePrivacy Directive requires consent for storing and reading information on the device, except what is strictly necessary for the service to work. Analytics and ad pixels as a rule require consent.
What is a data processing agreement (DPA) and when is it needed?
A DPA is a data processing agreement between a controller and a processor under Article 28 GDPR. It is needed when your SaaS processes client data on their behalf and when you pass data to hosting, CRM or email marketing services yourself.
Do I need an EU representative?
Under Article 27, a company without an establishment in the EU that is subject to GDPR appoints a representative, except where processing is occasional, does not include large-scale processing of special categories of data or criminal records data, and is unlikely to create a risk to people's rights and freedoms. The representative must be located in one of the EU countries where your users are. We assess whether you need one and help you appoint one through specialised providers.
How does a public offer under Ukrainian law differ from user terms?
A public offer under Articles 641 and 642 of the Civil Code of Ukraine is a proposal to conclude a sale or services contract, accepted by payment or another action. User terms govern how the website or service is used and often exist alongside the public offer.
What do App Store and Google Play require from a privacy policy for an app?
Both platforms require a policy link in the developer console and access to it inside the app. The policy must match the answers in Apple's App Privacy and in Google's Data safety section, including data collected by third-party SDKs.
What is the fine for a GDPR breach?
Under Article 83(5) GDPR, up to 20,000,000 euros or, for an undertaking, up to 4 percent of total worldwide annual turnover for the preceding year, whichever is higher. In practice the amount depends on the nature of the breach, the number of people affected and cooperation with the supervisory authority.
Do I need a privacy policy for users in California?
Yes, if the company falls under the CCPA: the law applies to for-profit businesses that do business in California and meet at least one threshold. Since 1 January 2025 the annual revenue threshold is 26,625,000 US dollars, indexed every odd-numbered year; the other thresholds are buying, selling or sharing the data of 100,000 or more California residents or households, or earning half or more of revenue from selling their data. We check applicability at the start.
Do you represent clients before a supervisory authority or in court?
Crystal Tax lawyers prepare the documents, answers and position. If you need representation in court or before a supervisory authority, or a formal legal opinion under the law of a specific EU country, we bring in partners in that country who are entitled to do so.
If you find an error or inaccuracy in the text, select it and press Ctrl + Enter
ORDER A SERVICE
Thank you for the appeal, the message has been sent.
ORDER A CONSULTATION
Thank you for the appeal, the message has been sent.
Telegram
WhatsApp
Maksym Stepanenko
Managing Partner, Crystal Tax
International client projects since 2012: company structures, tax, immigration, DUNS and NCAGE. 50+ jurisdictions.
What clients say
5.0
43 reviews · Google Maps
Client reviews on Google Maps
“Crystal Tax provided invaluable assistance in setting up our company in the United Arab Emirates…”
Yevelina K.2 years ago · Google Maps
“Opening a bank account abroad sounded scary at first, but Crystal Tax made it super easy. They knew exactly which banks to approach, what paperwork was needed…”
Sergei M.a year ago · Google Maps
“As a fast-growing startup, we needed clear, actionable tax advice — and Crystal Tax delivered exactly that. No jargon, no fluff.”
Inna M.a year ago · Google Maps
Order a service
Briefly describe your task: the country, the business activity and the timing. That is enough for us to propose a solution and the order of work.
We reply within one business day.
Or message us
TelegramWhatsApp
Thank you for the appeal, the message has been sent.