Personal Data Processing Policy
- General Provisions
- Key Terms Used in the Policy
- Personal Data Processed by the Operator
- Purposes of Personal Data Processing
- Legal Basis for Personal Data Processing
- Procedure for Collecting, Storing, Transferring, and Other Types of Personal Data Processing
- Cross-Border Transfer of Personal Data
- Final Provisions
1.1. This Personal Data Processing Policy is drafted in accordance with Article 8 of the Law of Ukraine "On Personal Data Protection" (available at: https://zakon2.rada.gov.ua/laws/show/2297-17) and defines the procedures for processing personal data and the measures to ensure the security of personal data utilized by Individual Entrepreneur Vitalii Ievpak (hereinafter referred to as the "Operator").
1.2. The Operator considers the observance of human and civil rights and freedoms in the processing of personal data, including the protection of the right to privacy, personal, and family secrets, as its primary goal and condition for conducting its activities.
1.3. This Operator’s Personal Data Processing Policy (hereinafter referred to as the "Policy") applies to all information that the Operator may obtain about visitors to the website https://daisy.travel.
2.1. Automated Processing of Personal Data – The processing of personal data using computing technology.
2.2. Blocking of Personal Data – A temporary suspension of personal data processing (except where processing is necessary to clarify personal data).
2.3. Website – A collection of graphic and informational materials, as well as computer programs and databases, made accessible on the Internet at https://daisy.travel.
2.4. Personal Data Information System – A set of personal data contained in databases and the information technologies and technical means that enable their processing.
2.5. Anonymization of Personal Data – Actions rendering it impossible, without additional information, to attribute personal data to a specific User or other personal data subject.
2.6. Processing of Personal Data – Any action (operation) or set of actions (operations) performed with personal data, whether using automated means or not, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (dissemination, provision, access), anonymization, blocking, deletion, and destruction of personal data.
2.7. Operator – A state body, municipal body, legal entity, or individual, independently or jointly with others, organizing and/or performing the processing of personal data, determining the purposes of processing, the composition of personal data to be processed, and the actions (operations) performed with personal data.
2.8. Personal Data – Any information relating directly or indirectly to an identified or identifiable User of the website https://daisy.travel.
2.9. Personal Data Authorized for Dissemination – Personal data to which unrestricted access has been granted by the personal data subject through consent to the processing of personal data authorized for dissemination, in accordance with the procedure stipulated by the Law on Personal Data (hereinafter referred to as "Personal Data Authorized for Dissemination").
2.10. User – Any visitor to the website https://daisy.travel.
2.11. Provision of Personal Data – Actions aimed at disclosing personal data to a specific person or group of persons.
2.12. Dissemination of Personal Data – Any actions aimed at disclosing personal data to an indefinite group of persons (transfer of personal data) or making personal data accessible to an unlimited number of persons, including publication in mass media, posting on information and telecommunication networks, or otherwise providing access to personal data.
2.13. Cross-Border Transfer of Personal Data – The transfer of personal data to the territory of a foreign state, to a foreign state authority, foreign individual, or foreign legal entity.
2.14. Destruction of Personal Data – Any actions resulting in the irreversible destruction of personal data, with no possibility of restoring its content in the personal data information system and/or the destruction of physical media containing personal data.
3.1. Surname and first name.
3.2. Email address.
3.3. Telephone numbers.
3.4. The Website also collects and processes anonymized data about visitors (including cookies) using Internet analytics services (e.g., Google Analytics and others).
3.5. The aforementioned data are collectively referred to as "Personal Data" throughout this Policy.
4.1. The purposes of processing Users’ personal data include:
Informing the User by sending emails;
Concluding, performing, and terminating civil law contracts;
Providing the User with access to services, information, and/or materials available on the website https://daisy.travel;
Providing the User with access to services, information, and/or materials available in applications for iOS and Android platforms.
4.2. The Operator may also send Users notifications about new products and services, special offers, and various events. Users may opt out of receiving such informational messages at any time by sending an email to the Operator at info@daisy.travel with the subject "Opt-Out of Notifications About New Products, Services, and Special Offers."
4.3. Anonymized User data collected via Internet analytics services is used to gather information about Users’ actions on the Website, enhancing its quality and content.
5.1. The Operator processes Users’ personal data only if such data is provided and/or submitted by the User voluntarily through special forms on the website https://daisy.travel or sent to the Operator via email. By completing the relevant forms and/or submitting personal data to the Operator, the User expresses consent to this Policy.
5.2. The Operator processes anonymized User data if permitted by the User’s browser settings (e.g., if cookie storage and JavaScript usage are enabled).
6.1. The security of personal data processed by the Operator is ensured through the implementation of legal, organizational, and technical measures necessary to fully comply with the requirements of current personal data protection legislation.
6.2. The Operator ensures the confidentiality of personal data and takes all possible measures to prevent unauthorized access to such data.
6.3. Users’ personal data will never, under any circumstances, be transferred to third parties, except in cases related to compliance with applicable legislation.
6.4. If inaccuracies in personal data are identified, the User may update them independently by sending a notification to the Operator’s email address info@daisy.travel with the subject "Personal Data Update."
6.5. The duration of personal data processing is unlimited. The User may withdraw consent to the processing of personal data at any time by sending a notification via email to the Operator’s address info@daisy-tour.com with the subject "Withdrawal of Consent to Personal Data Processing."
7.1. Prior to initiating a cross-border transfer of personal data, the Operator must ensure that the foreign state to whose territory the personal data is to be transferred provides reliable protection of the rights of personal data subjects.
7.2. Cross-border transfer of personal data to territories of foreign states that do not meet the aforementioned requirements may only occur with the written consent of the personal data subject for such transfer and/or in fulfillment of a contract to which the personal data subject is a party.
8.1. Users may obtain clarifications on any questions regarding the processing of their personal data by contacting the Operator via email at info@daisy.travel.
8.2. Any changes to the Operator’s personal data processing policy will be reflected in this document. The Policy remains in effect indefinitely until replaced by a new version.
8.3. The current version of the Policy is freely accessible on the Internet at https://daisy-travel.