A GDPR privacy policy for your website, SaaS or app, plus a cookie policy, terms of service, a public offer under Ukrainian law and a DPA, written around how your product actually processes data.

Since 2012 · 50+ jurisdictions · GDPR, Ukraine, US · documents in English, Ukrainian, Russian and other languages

TelegramWhatsApp

In brief

  • A GDPR privacy policy is a public document that tells users who processes their data, which data, why, on what legal basis, who receives it, how long it is kept and how users can exercise their rights.
  • It is needed by owners of websites, online stores, SaaS products and mobile apps: founders from Ukraine working with users in the EU and the US, and Ukrainian online businesses selling to customers in Ukraine.
  • Turnkey, we map your data flows and write the Privacy Policy, a Cookie Policy with banner texts, Terms of Service or a public offer under Ukrainian law, a DPA for B2B clients and with your contractors, a subprocessor list and texts for App Store and Google Play.
  • Under Article 3(2) GDPR, the regulation applies to a company outside the EU when it offers goods or services to people in the EU or monitors their behaviour in the EU; the content of a privacy notice is listed directly in Articles 13 and 14.
  • Usually, in our experience, the document package for one product is ready within 1–3 weeks after the data questionnaire is completed. The timeline depends on the case, its details, the work of the authorities and force majeure.

Pick the situation closest to yours: a short outline of the route and the first step.

A Ukrainian SaaS starts selling to clients in the EU

We determine where you are the controller and where you process client data as a processor, and write the Privacy Policy, Terms of Service, a DPA for B2B clients and a public subprocessor list. We also check whether you need an EU representative under Article 27.

Example. A booking service for beauty salons received a set of policy, terms of use and DPA before launching in Poland; its first corporate client signed the DPA after one round of edits.

Discuss this case →
App Store or Google Play rejected the app over privacy

We check which data the app and its SDKs collect, align the policy and the App Privacy and Data safety answers, and place the policy link in the app and in the developer console.

Example. A fitness app was rejected because its policy omitted an analytics SDK that collected the device identifier. After the review and new questionnaire answers, the build was accepted.

Discuss this case →
An online store in Ukraine needs a public offer and a policy

We prepare a public offer under Ukrainian law with a clear acceptance procedure at checkout, a privacy policy under the Ukrainian personal data protection law, and delivery and returns rules.

Example. A home goods store replaced a public offer copied from another website with a text built around its own payment, delivery and returns, and disputed customer requests started to be handled under clear rules.

Discuss this case →
An investor asks for GDPR documents before a round

We compile the record of processing, align the policies with how the product really works, put DPAs in place with contractors and prepare answers to the review questions. In parallel we look at the corporate documents.

Example. A B2B procurement marketplace, three weeks before due diligence, received a record of processing, an updated policy and signed DPAs with its hosting and CRM providers.

Discuss this case →
Our site runs analytics and ad pixels and needs a cookie banner

We inventory cookies and trackers, split them into strictly necessary and consent-based, write the Cookie Policy and banner texts, and give the developer the logic: optional scripts stay off until consent.

Example. An online school using pixels from two ad networks got a banner with “Accept” and “Reject” buttons on the first screen and settings by category.

Discuss this case →
A large client sent us their own DPA to sign

We check the client's DPA against how you really work: instructions, subprocessors, incident notification deadlines, audits, transfers outside the EU, liability. We prepare redlines and a negotiating position.

Example. An HR platform developer agreed with a European client on a reasonable incident notification deadline and on audits based on reports instead of on-site inspections.

Discuss this case →

A turnkey GDPR privacy policy starts with a data map of your product: we write the documents once we understand which data you collect, from whom, why, on what legal basis, where you store it and which services you pass it to. Crystal Tax lawyers carry the work from the questionnaire to final texts in the languages you need.

Clean desk: a laptop with a blurred web app on the screen, a smartphone with a blurred app screen, a printed document with grey illegible lines, a pen and a small padlock
We write the privacy policy, public offer and DPA for your real product

Generators and templates produce a text that describes someone else's product. Regulators, app stores and the lawyers of B2B clients check exactly the gap between the policy and real processing: the text omits analytics running on the site, states a retention period nobody follows, or leaves out the payment provider.

Where a policy most often diverges from the product

  • Ad pixels and analytics fire before the user consents, while the Cookie Policy promises the opposite.
  • The policy omits services that actually receive data: the payment provider, the support chat, an AI service, a mobile SDK.
  • The stated retention period is not followed, or there is no retention period at all.
  • The public offer and Terms of Service describe one payment model while the site runs another: a subscription with auto-renewal, a trial period, refunds.
  • Data is stored outside the EU, and the policy says nothing about it or about transfer safeguards.
  • The App Privacy or Data safety answers differ from the text of the app's privacy policy.

We check each of these points against the data map before handing the texts over for publication.

Data flow audit

  • Questionnaire and a call with you and your developer: forms, sign-up, payments, mailings, support, analytics, advertising, mobile SDKs.
  • Data map: categories of data and users, purposes, legal bases, storage locations, processor services (hosting, CRM, email marketing, payments, analytics), retention periods.
  • Roles: where you are the controller, where you act as a processor on behalf of a B2B client, where you are a joint controller with a partner.
  • Transfers outside the EU: whether the European Commission has adopted an adequacy decision for the country, and whether standard contractual clauses or other safeguards under Article 46 GDPR are needed.

Public documents

  • Privacy Policy under Articles 13 and 14 GDPR and, for a Ukrainian audience, in line with the Ukrainian personal data protection law; a privacy policy for an app that meets App Store and Google Play requirements.
  • Cookie Policy and consent banner texts with settings logic by category. Your developer installs the banner technically; we give them recommendations and check the result against a checklist.
  • Terms of Service for SaaS, user terms for a website or a public offer under Ukrainian law for a website in Ukraine: subject matter, payment and subscription, refunds, liability, governing law, how terms are changed. The contractual part follows our practice in contract drafting.
  • A subprocessor list for publication and a procedure for notifying clients of changes to it.

Contracts and internal documents

  • DPA (data processing agreement) in both directions: you as a processor for your B2B clients and you as a controller with your contractors, covering the mandatory content of Article 28(3) GDPR.
  • Record of processing activities under Article 30, data retention and deletion rules, a data breach response procedure, and a check of whether a data protection impact assessment (DPIA) is needed.
  • A procedure for handling user requests: access, rectification, erasure, objection, data portability.
  • An assessment of whether an EU representative is needed under Article 27; we do not act as the representative ourselves and help you appoint one through specialised providers and partners.

Which document fits which situation

SituationDocuments
Website with forms and analytics, users in the EUGDPR privacy policy, Cookie Policy and consent banner, DPAs with contractors
SaaS for business clients in the EU and the UKTerms of Service, Privacy Policy, DPA for clients, subprocessor list, record of processing
Mobile appPrivacy policy for the app linked in the console and inside the app, App Privacy and Data safety answers, user terms
Online store in UkrainePublic offer under Ukrainian law, privacy policy under Ukrainian law, delivery and returns rules
Users in the USPrivacy Policy reflecting state requirements; for California, a check of whether CCPA and CPRA apply

Languages and updates

We prepare documents in Russian, Ukrainian and English; other languages go through vetted translators, and we proofread the terminology. When the product changes, for example a new payment provider or market appears, we update the data map and the texts as a one-off job or as part of ongoing legal support for startups, which also covers GDPR compliance for startups.

Usually, in our experience, the document package for one product is ready within 1–3 weeks after the data questionnaire is completed. The timeline depends on the case, its details, the work of the authorities and force majeure.

  • Assessment of the task — within one working day after a short description of the product and markets.
  • Questionnaire and data call — usually 2–5 working days; most of the time goes into the developer's answers about services and SDKs.
  • Privacy Policy and Cookie Policy — usually, in our experience, about a week after the data map.
  • Terms of Service, user terms or public offer — in parallel with the policy; the timing depends on the payment model and the number of plans.
  • DPA — your own template is prepared together with the package; negotiating a client's DPA depends on the number of rounds of edits with their lawyers.
  • Translations — add several working days per language after the main version is approved.

The review period for an app in App Store or Google Play is set by the platform itself; we influence only the quality of the answers and how closely the policy matches the real app.

The work takes longer when the developer is external and slow to respond, when the product uses many SDKs with unclear data transfers, when there is health data, children's data or biometrics, or when a B2B client sends its own DPA with strict terms. We name these points at the start.

The cost of a GDPR privacy policy and a document package, including the work a terms and conditions lawyer would do on your Terms of Service, is calculated individually: it depends on how much data and how many services the product uses and which markets it enters.

  • Number of products: one website, a website plus an app, several SaaS products under one company.
  • Markets: the EU, the UK, the US, Ukraine, and whether the requirements of several of them apply at once.
  • Number of data flows and processor services: analytics, advertising, payments, CRM, mailings, hosting, AI services.
  • Business model: B2C, B2B, a two-sided marketplace.
  • Special categories of data, children's data, geolocation, biometrics.
  • Number of documents and languages.
  • A one-off package or ongoing updates as the product changes.

Describe the product in a few sentences, and we will assess the work within one working day. An introduction and a first answer are available on a free consultation of 10 minutes; if you need a detailed review, there is a 30-minute consultation for 100 euros.

Five reasons founders trust us with their privacy policy, public offer and data contracts.

In business since 2012

We work in 50+ jurisdictions; we know the requirements of registrars, banks, tax offices and the lawyers of large clients from our own cases.

We handle platforms, counterparties and banks

Answering App Store and Google Play remarks, corresponding with the client's lawyers on a DPA and handling bank questions is our job. From you we need information about the product and decisions.

We carry the case to the result

If a platform, a client or a bank sends remarks on the documents, we rework them at no extra charge.

One team for the whole structure

Company, contracts, data documents, bank account, accounting and taxes, including Ukrainian CFC (controlled foreign company) rules and the CFC report, with no need to look for separate contractors.

Contract and confidentiality

We work under a contract, and the confidentiality terms are written into it.

The work runs in six steps, and at each one you know what we need from you.

Six-step diagram: task and assessment, contract and questionnaire, data map, document drafts, review and translations, publication and updates
How we prepare a privacy policy, public offer and DPA turnkey
  1. Task and assessment. You describe the product, markets and users; we assess the scope within one working day.
  2. Contract and questionnaire. We sign a contract, and you and your developer fill in the questionnaire on data and services.
  3. Data map. On a call we clarify data flows, roles, legal bases, transfers outside the EU and retention periods.
  4. Document drafts. We write the policy, Cookie Policy, terms or public offer, DPA and subprocessor list.
  5. Review and translations. We make your edits, check the texts against each other and against the product, and translate them into the languages you need.
  6. Publication and updates. We give your developer instructions on placement and the banner, and update the texts when the product changes.

To start, we need information about the company, the product and the services it uses; we provide the questionnaire and the list of questions.

About the company and product

  • Name, country of registration and contact details of the company that owns the website or app.
  • Links to the website and app, test access to the user account or a build.
  • Markets and languages, types of users: individuals, companies, children and teenagers.

About data and services

  • A list of services: hosting, analytics, ad pixels, CRM, mailings, payment systems, support, mobile SDKs.
  • Which forms and fields users fill in, and what is collected automatically.
  • Where and for how long data is stored, and who in the team and at contractors has access to it.

Current documents

  • Your current policy, public offer or terms, if you have them, even if they come from a template.
  • DPAs sent by clients and data agreements with contractors.
  • Remarks from App Store, Google Play, a client or an investor, if there have been any.

If other lawyers have already prepared documents for you, send them over: we will check what can stay and what diverges from the product or from other documents in the package.

Article 13 GDPR lists the information a controller provides when collecting data from the user directly, and Article 14 covers data obtained from other sources.

  • Identity and contact details of the controller and, where appointed, its EU representative; contact details of the DPO, where there is one.
  • Purposes of processing and the legal basis for each purpose; for legitimate interests, what that interest is.
  • Recipients or categories of recipients of the data.
  • Transfers to a third country: whether there is a European Commission adequacy decision, or which safeguards apply and how to obtain a copy of them.
  • Retention period or the criteria used to determine it.
  • User rights: access, rectification, erasure, restriction of processing, objection, data portability.
  • The right to withdraw consent at any time where processing is based on consent.
  • The right to lodge a complaint with a supervisory authority.
  • Whether providing the data is a statutory or contractual requirement and the consequences of not providing it.
  • Automated decision-making, including profiling, and the logic involved.

Under Article 14, the categories of data and their source are also stated. The information is provided within a reasonable period, at the latest within one month of obtaining the data, and, if the data is used to communicate with the user or disclosed to another recipient, at the latest at the first communication or first disclosure.

The maximum fine for infringing data subjects' rights and the basic principles under Article 83(5) GDPR is up to 20,000,000 euros or, for an undertaking, up to 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher.

Each of the five documents has its own job, and in practice they refer to each other, so they are written together.

DocumentPurposeWho needs itLegal basis
Privacy PolicyTell users how their data is processedAny website or app that collects personal dataGDPR, Articles 13 and 14; Law of Ukraine on personal data protection, Article 12; CCPA for California; App Store and Google Play rules
Cookie Policy and bannerDescribe cookies and trackers and obtain consent for optional onesWebsites and services with analytics, advertising, third-party chatsePrivacy Directive 2002/58/EC, Article 5(3); GDPR consent standard, Articles 4(11) and 7
Terms of Service, user termsTerms of use of the service, payment, liability, disputesSaaS, platforms, appsContract law of the country chosen in the terms, and consumer protection
Public offer (Ukrainian law)An offer to conclude a contract with anyone who accepts the termsOnline stores and services selling in UkraineCivil Code of Ukraine, Articles 633, 641, 642; Law on e-commerce, Article 11
DPATerms of processing data on behalf of the controllerB2B SaaS and anyone who passes data to contractorsGDPR, Article 28(3)

A DPA under Article 28(3) must set out the subject matter, duration, nature and purpose of processing, the types of data and categories of data subjects, as well as the processor's obligations: act only on documented instructions, ensure staff confidentiality, take security measures under Article 32, engage subprocessors only with the controller's authorisation, assist with data subject requests and with the obligations under Articles 32–36, delete or return the data after the end of the services, make information available and allow audits.

Under the ePrivacy Directive, consent to cookies is required for storing and reading information on the user's device. The exception is technical storage for transmitting a communication or storage strictly necessary for a service the user has explicitly requested. Under Recital 32 GDPR, silence, pre-ticked boxes and inactivity do not constitute consent.

Since 2021, following amendments by Law 1667-IX, the Civil Code of Ukraine expressly recognises as an offer documents publicly available on the internet that contain the essential terms of a contract and a proposal to conclude it with anyone who applies, regardless of whether an electronic signature is present.

  • Public contract, Article 633 of the Civil Code — the business undertakes to sell goods, perform work or provide services to anyone who applies; the terms are the same for all consumers except for benefits provided by law; terms contradicting this are void.
  • Offer, Article 641 of the Civil Code — the proposal must contain the essential terms and express the intention to be bound once it is accepted. Advertising and other proposals addressed to an indefinite circle of persons are treated as an invitation to make offers unless they state otherwise.
  • Acceptance, Article 642 of the Civil Code — the response must be full and unconditional; actions in line with the terms of the offer, such as payment, also count as acceptance unless the offer or the law provides otherwise.
  • Electronic contract, Article 11 of Law 675-VIII — an offer may be published on the internet and incorporate the terms of another electronic document by a link, to which the user must have free access. Acceptance is possible by an electronic message, by filling in a form or by actions whose meaning is clearly explained in the system where the offer is published.

For a privacy policy in Ukraine, the Law on personal data protection 2297-VI applies: Article 11 lists the grounds for processing, including consent, contract and legitimate interest, and Article 12 requires informing the data subject at the time of collection about the data owner, the data collected, their rights, the purpose of collection and the recipients.

The new consumer protection law 3153-IX was adopted in 2023 and enters into force one year after publication, but not earlier than the day martial law is terminated or lifted. As of 27.09.2026 the official portal shows its status as “entering into force”, so the current consumer protection rules apply to public offers.

Describe the product in a few sentences: what it is, which markets it enters and which services it uses. We will reply within one working day, and on a free 10-minute call we will name the first step right away.

TelegramWhatsApp

Regulation (EU) 2016/679 (GDPR), Articles 3, 4, 7, 13, 14, 27, 28, 30, 46, 83, Recital 32; Directive 2002/58/EC (ePrivacy) as amended by 2009/136/EC, Article 5(3); Law of Ukraine on Personal Data Protection No. 2297-VI, Articles 11 and 12; Civil Code of Ukraine, Articles 633, 641 as amended by Law 1667-IX, 642; Law of Ukraine on E-Commerce No. 675-VIII, Article 11; Law of Ukraine on Consumer Protection No. 3153-IX, final provisions; Apple, App Review Guidelines, 5.1.1 (i) Privacy Policies; Google Play, User Data policy and Data safety section; California Attorney General, California Consumer Privacy Act; California Privacy Protection Agency, CPI adjustment of CCPA thresholds from 1 January 2025. Checked: 27.09.2026.

Page rating
5 / 5

Frequently asked questions

Is a privacy policy mandatory for a website?
Does GDPR apply to a company from Ukraine or the US?
Can I use a privacy policy from a generator?
How do I write a GDPR privacy policy?
Do I need a cookie banner if the site only runs analytics?
What is a data processing agreement (DPA) and when is it needed?
Do I need an EU representative?
How does a public offer under Ukrainian law differ from user terms?
What do App Store and Google Play require from a privacy policy for an app?
What is the fine for a GDPR breach?
Do I need a privacy policy for users in California?
Do you represent clients before a supervisory authority or in court?
If you find an error or inaccuracy in the text, select it and press Ctrl + Enter
Maksym Stepanenko

Maksym Stepanenko

Managing Partner, Crystal Tax

International client projects since 2012: company structures, tax, immigration, DUNS and NCAGE. 50+ jurisdictions.

What clients say

43 reviews · Google Maps

Client reviews on Google Maps
  • “Crystal Tax provided invaluable assistance in setting up our company in the United Arab Emirates…”

    Yevelina K.2 years ago · Google Maps

  • “Opening a bank account abroad sounded scary at first, but Crystal Tax made it super easy. They knew exactly which banks to approach, what paperwork was needed…”

    Sergei M.a year ago · Google Maps

  • “As a fast-growing startup, we needed clear, actionable tax advice — and Crystal Tax delivered exactly that. No jargon, no fluff.”

    Inna M.a year ago · Google Maps

Order a service

Briefly describe your task: the country, the business activity and the timing. That is enough for us to propose a solution and the order of work.

We reply within one business day.

Or message us

Telegram WhatsApp
Write to Email Write to Telegram Write to Whatsapp