This Privacy Policy has been drawn up in accordance with the requirements of the applicable legislation of Ukraine and the European Union and other laws and regulations governing the collection, processing, storage and use of personal data, including Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. As the controller of personal data is a company registered in the United Kingdom, this Policy also follows the UK GDPR and the UK Data Protection Act 2018.

This Privacy Policy is intended to inform users of the Web Service about the rules for collecting, processing, storing and using the personal data they provide when using the Web Service (filling in registration forms, etc.).

Web Service – the website https://crystal.tax/, through which Users can order services. Users can view the list of services offered on the Web Service, receive the services and obtain the bank account details of the persons providing them.

Personal Data Controller – INNOVA CG LTD, a company registered in England and Wales under company number 17390819, registered office: 124-128 City Road, London, EC1V 2NX, United Kingdom. The Controller determines the purposes and means of processing Users' personal data. Contact for personal data requests and data subject rights: m@crystal.tax.

Web Service Administrator – INNOVA CG LTD (Crystal Tax brand), contact: m@crystal.tax. The Administrator provides access to the Web Service on the terms set out in this Privacy Policy, the Public Offer, the User Agreement and the Regulations on the internal business process for identifying users and tracking their real data.

Personal Data Processors – service providers that process personal data on behalf of and on the instructions of the Controller (hosting, e-mail delivery, web analytics, CRM systems).

User – a legally capable individual aged 18 or over, or a legal entity, that has an Account (User Account/Personal Account) on the Web Service or performs actions indicating use of the Web Service.

Account/User Account/Personal Account – a record on the Web Service containing the User's authorisation data (login and password) required to identify the User when using the Web Service, and other data provided by the User.

1. COLLECTION AND USE OF PERSONAL INFORMATION

Personal Information – data that make it possible to identify the User of the Web Service and are necessary for providing the requested services and communicating with the User.

When using the Web Service, you may be asked to provide certain information about yourself. Providing such information is optional, as the Administrator does not require you to provide any personal data. However, if you refuse to provide certain personal information, you will not be able to use some of the functions and features of the Web Service.

Personal data are processed and stored only after the User has given explicit consent to such actions.

The Web Service uses personal information provided by the User directly or, with the User's consent, obtained through interaction with other information platforms.

Information that the Web Service may request:

  • Personal e-mail address
  • Phone number
  • Information provided in correspondence with the Web Service technical support
  • User's IP address
  • User's bank account number
  • Delivery address (place)

The Web Service may request data from other social networks and resources for quick login to the site and uploading photos. The User receives a clear list of the requested data; this list is exhaustive, and the data are used solely for the stated purposes.

The Web Service provides a list of social networks, applications and resources that may transfer the User's personal data: Facebook, Google.

The scope of data obtained from other social networks, applications and resources is governed by the privacy policies of the respective social networks, applications and resources.

The User's consent to the transfer of data from other social networks, resources and applications is clearly worded and accessible. Consent is given by clicking the confirmation button in the corresponding information window.

Questions about the scope and type of data transferred from other social networks, applications and resources are resolved by contacting the technical and information support services of the respective social networks, applications and resources.

PURPOSES OF USING PERSONAL DATA:

  1. Personal e-mail address – for sending important messages confirming operations performed through the Web Service, important information about the operation of the Web Service, notices to Users about changes in the operation of the Web Service, and informational, news and advertising messages.
  2. Phone number – for identifying the client as a registered user of the Web Service, for communication between the Web Service manager and the User, for preventing third parties from accessing your personal data and for preventing any fraudulent activity.
  3. Information provided in correspondence with the Web Service technical support – for providing technical support to users on matters related to the Web Service: registration or deletion of registration data, restoring access to personal data (recovering a lost password or login, restoring a closed account), and assistance with other issues arising when using the Web Service.
  4. User's IP address – for compiling statistics of visits to the Web Service, preventing fraudulent activity and identifying the User.
  5. User's bank account number – may become known to the Administrator when the User pays for services received on the Web Service.
  6. Delivery address (place) – for the proper performance of services by the Contractor in accordance with the Public Offer posted on the Web Service and made available to the User for review.

Personal data are processed and stored to achieve the purposes stated above.

Attention! Information that you voluntarily disclose on your personal data page or on forums becomes publicly available to other users of the Web Service. The Controller (Administrator) and the processors are not responsible for the dissemination and use of personal information that you have made visible to other users of the site. Such information loses the status of personal data.

By registering on the Web Service and accepting this Policy, the User grants the Administrator the right to mention the User as a user of the Administrator's services and to refer to the User for advertising purposes.

Entering and confirming personal data that become available to other Users with subsequent publication is deemed to be consent to their disclosure to other users of the Web Service.

The User may freely view, change and delete the identifying data provided on the Web Service. However, deleting certain identifying data may make it impossible to use certain resources of the Web Service. Changes and deletions of data are made in accordance with the User Agreement and are carried out by the Controller, including through the processors acting on its instructions.

The Controller has the right to notify the User of the need to retain identifying data in the cases provided for by applicable law and Section 3 of this Privacy Policy.

The User has the right to delete his or her account and the information provided in the personal account by sending a corresponding letter or request to the Technical and Information Support Service of the Web Service at m@crystal.tax.

The User has the right to request and receive confirmation from the Controller as to whether his or her personal data are being processed, as well as information on the full scope of personal data held by the Controller, including data processed by processors on its behalf. The Controller provides a copy of such data free of charge within 30 days of the request. Where a large amount of data is requested, the Controller may extend the response period to 60 days. Requests should be sent to m@crystal.tax.

The Administrator has the right to refuse a request for personal data where such requests are unfounded or excessive. A refusal must be reasoned and communicated to the User.

In the event of loss or disclosure of personal data, the Controller must notify the User and the supervisory authority within 72 hours.

Personal data of Users of the Web Service are protected by means of data encryption, anonymisation, strengthening the resilience of the database and control by the Administrator over physical and virtual access to personal data.

Personal data are not transferred for use or review to third parties that do not cooperate with the Web Service and/or Users of the Web Service, except where such data are disclosed lawfully and by a court decision, or where the User abuses his or her rights to use the Web Service.

Employees of the Web Service and third parties providing services and/or cooperating with the Web Service on other contractual terms conclude non-disclosure agreements regarding information that becomes known to them while working with the content of the Web Service.

The Controller is responsible for the lawful processing of personal information, its storage and use for the necessary purposes; processors process personal data only on the Controller's instructions.

The User has the right to:

  • know the location of personal data, the purpose of their processing and the location of the Controller or processor of personal data, or instruct persons authorised by the User to obtain this information, except as otherwise provided by law;
  • receive information about the conditions of access to personal data, in particular information about third parties to whom his or her personal data are transferred;
  • access his or her personal data;
  • receive, no later than thirty calendar days from the date of receipt of the request, except as otherwise provided by law, a reply as to whether his or her personal data are stored in the relevant personal database, and receive the content of such personal data;
  • submit a reasoned objection to the Controller against the processing of his or her personal data;
  • submit a reasoned request to the Controller or any processor to change or destroy his or her personal data if these data are processed unlawfully or are inaccurate;
  • protection of his or her personal data against unlawful processing and accidental loss, destruction or damage due to deliberate concealment, failure to provide or untimely provision of the data, as well as protection against the provision of information that is inaccurate or damages the honour, dignity and business reputation of an individual;
  • lodge complaints about the processing of his or her personal data with public authorities and officials responsible for personal data protection, or with a court;
  • apply legal remedies in case of violation of personal data protection legislation;
  • make reservations restricting the right to process his or her personal data when giving consent;
  • withdraw consent to the processing of personal data;
  • know the mechanism of automated processing of personal data;
  • protection against a decision of the Controller that has negative legal consequences for the data subject and is aimed at disclosing personal data.

The User may also lodge a complaint with a data protection supervisory authority; in the United Kingdom, this is the Information Commissioner's Office (ICO).

2. COLLECTION AND USE OF NON-PERSONAL INFORMATION

We may ask you to provide data that are not confidential but may help us provide better services. Such information may include the language you use, your country and city of residence, time zone, browser type, dates and times of the User's requests, the “history” of the User's actions on the Web Service, the User's device type, system fonts, screen size, cookies, etc.

We may also collect non-personal information, that is, information that does not identify a specific user of the Web Service. This includes, for example, information from third parties that collect and provide such information for advertising purposes. However, we are not responsible for the accuracy of such information, as we do not control the activities of such third parties. We are also not responsible for the collection by third parties of analytical and statistical information about the use of the Web Service if such information is obtained by third parties from open sources and does not contain personal information about you.

We may also store data about how you use our Web Service. This helps developers improve the product.

3. PROVIDING THIRD PARTIES WITH ACCESS TO YOUR INFORMATION

Except in the cases listed below, the Administrator undertakes not to disclose, exchange or otherwise transfer your personal data outside the Administrator, its subsidiaries, affiliates and strategic partners without your express consent, unless there are legal grounds for such transfer.

The Administrator may provide personal information to subsidiaries, affiliated companies and strategic partners where this is necessary to provide the ordered services. Such companies undertake to comply with the rules for protecting personal information received from the Administrator. We may also give access to your personal data to processors acting on the Controller's instructions, to statistics collection systems (Google Analytics, etc.) and to the social networks specified in this Policy.

We may access, process, store and disclose personal information about you when we believe in good faith that this is necessary to:

  • comply with applicable law, enforce legal process or comply with lawful requests from law enforcement agencies, public authorities or other competent authorities;
  • prevent and stop an attack aimed at your devices or system with the intent to cause you harm;
  • ensure compliance with the general requirements and rules for the operation of the Web Service in order to prevent users from violating them;
  • protect users of the Web Service from possible actions aimed at spreading spam or committing deceptive and fraudulent acts against users;
  • prevent death or serious injury to any person;
  • protect private property, intellectual property rights and other rights of the Administrator, other users and the public, in the form and to the extent required or permitted by applicable law.

In the above cases, access to confidential information about you is provided without your consent.

4. MERGER OR SALE OF THE ADMINISTRATOR'S COMPANY

If the Administrator takes part in a restructuring (merger, acquisition or sale of assets), users' personal data (as one of the Administrator's assets) may be transferred to other participants in such restructuring. You will be notified in advance of any change to the Privacy Policy resulting from the Administrator's restructuring.

5. CHANGES TO THE PRIVACY POLICY

The Administrator informs you that this version of the Privacy Policy is final at the time of publication. From time to time we will make changes and additions to these rules, which may be related to the development of new software products and web services or to the introduction or modification of functions of existing software. Changes to the Privacy Policy may also be made based on users' suggestions. At the end of this Privacy Policy we state the date of its last revision.

If you continue to use our software products after changes have been made to the Privacy Policy, you will receive an e-mail asking you to confirm the processing of your personal data in accordance with the terms of the updated Privacy Policy.

We recommend that you review the Privacy Policy from time to time to stay informed about how personal information about you is collected, used and stored.

Last revised: 25.09.2026

Write to Email Write to Telegram Write to Whatsapp