Privacy Policy of ADV Group Ukraine
This edition is effective as of the date of publication on advokat-online.in.ua. The document has been prepared on the basis of the Law of Ukraine “On the Protection of Personal Data” of 01.06.2010 No. 2297-VI, the Law of Ukraine “On the Bar and Practice of Law” of 05.07.2012 No. 5076-VI, and with regard to the requirements of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) — since a significant share of ADV Group’s clients reside in and seek services from the European Union and other countries.
1. General Provisions
This Privacy Policy (hereinafter — the Policy) sets out the procedure and conditions for processing the personal data of persons who contact ADV Group Ukraine (hereinafter — the Company, ADV Group, we) through the website, messengers, email, or within the provision of legal assistance. The Policy has been developed in accordance with Article 8 of the Law of Ukraine “On the Protection of Personal Data” No. 2297-VI, under which a data subject has the right to know the purpose and conditions of processing their data before it is collected.
By using the advokat-online.in.ua website or contacting the Company through any other communication channel, you confirm that you have read and understood the terms of this Policy. If you do not agree with any provision of the Policy, please do not provide us with your personal data.
2. Personal Data Controller
The controller of personal data in accordance with Article 4 of Law No. 2297-VI is ADV Group Ukraine — a legal entity (a law office/bar association) that determines the purpose of processing personal data, the composition of such data, and the procedures for its processing. The Company’s contact details for inquiries regarding personal data are provided in Section 14 of this Policy.
3. Categories of Personal Data Processed
The Company processes the following categories of personal data:
- Identification data: surname, first name, patronymic, date of birth, identity document details (passport, ID card), citizenship.
- Contact data: phone number, email address, messenger accounts (WhatsApp, Telegram, Viber, Messenger), postal address, country and time zone of residence.
- Case data: information about the legal matter, documents provided for consultation or representation, details of inheritance cases, real estate ownership rights, marital status, and other information necessary to provide legal assistance.
- Technical data: IP address, cookie data, device and browser type, website behavior data (visit analytics).
- Financial data: payment details for services (full payment card data is not stored — payments are processed through certified payment systems).
4. Purpose of Processing Personal Data
Personal data is processed for the following purposes:
- providing legal assistance and legal consultations under the concluded agreement;
- identifying the client and verifying their legal status in the case;
- communication regarding the status of the case, document flow, and organizational matters;
- compliance with legal requirements (including financial monitoring requirements, where applicable);
- website analytics and improvement (exclusively in aggregated, de-identified form);
- marketing communications — only with the separate, explicit consent of the data subject.
5. Legal Grounds for Processing Personal Data
Personal data is processed on the grounds provided for in Article 11 of Law No. 2297-VI:
- consent of the data subject — given voluntarily by filling out a website form, signing an agreement, or through correspondence;
- conclusion and performance of the agreement on legal services to which the data subject is a party;
- the legitimate interest of the data controller — in particular, to protect the client’s rights within the scope of the mandate given;
- compliance with a legal obligation — in cases where the provision of certain information is required by law (for example, notarial or court procedures).
The processing of personal data is always carried out in accordance with the principles of lawfulness, purpose limitation, data minimization, accuracy, storage limitation, and integrity and confidentiality of data.
6. Attorney-Client Privilege — A Higher Level of Protection Than General Confidentiality
Separately from the general personal data protection regime, all information that becomes known to ADV Group’s lawyers in connection with the practice of law is subject to the regime of attorney-client privilege under Article 22 of the Law of Ukraine “On the Bar and Practice of Law” No. 5076-VI.
Attorney-client privilege covers any information about the client that becomes known to the lawyer, their assistant, trainee, or a person employed by the lawyer, as well as the matters the client raised, the content of advice and consultations, documents drawn up (including in electronic form), and any other information obtained in the course of legal practice. The duty to maintain attorney-client privilege is unlimited in time and applies to all Company employees involved in working on the case. This information may not be disclosed without the client’s written consent, except in cases directly provided for by law (for example, a lawyer defending their own rights in a dispute with a client).
Practical significance for the client: the protection of your case at ADV Group is not limited to technical cybersecurity measures (encryption, access control) — it is further reinforced by a legal imperative that operates independently of technical systems and obliges every lawyer and employee of the Company to keep the secrecy of your case for life.
7. Third Parties to Whom Data May Be Transferred
Personal data may be transferred exclusively to the following categories of third parties and only to the extent necessary to achieve the purpose of processing:
- notaries, state registrars, courts, and public authorities of Ukraine — in cases where data transfer is a necessary step in resolving the client’s legal matter under their mandate;
- partner lawyers or experts engaged in a specific case (translators, property appraisers) — under separate confidentiality agreements;
- technical service providers (hosting, payment systems, CRM) — exclusively to the extent necessary for the website’s operation and payment processing, and subject to contractual data protection guarantees from such providers.
The Company does not transfer or sell clients’ personal data to third parties for marketing or any other purpose unrelated to the provision of legal assistance.
8. Cross-Border Transfer of Personal Data
Since a significant share of ADV Group’s clients contact the Company from abroad — from countries of the European Union and other states — the Company takes into account the legal requirements for the cross-border transfer of personal data.
Under Law No. 2297-VI, cross-border transfer of personal data is possible provided that the recipient state ensures an adequate level of personal data protection; the law considers such states to include member states of the European Economic Area and states that have joined Council of Europe Convention No. 108. Data transfer is also permitted where the data subject has given unambiguous consent, in connection with the conclusion or performance of a transaction in their interest, to protect the vital interests of the data subject, or to defend legal claims.
For clients who are residents of the European Union or whose data falls within the scope of the GDPR, ADV Group ensures that personal data processing takes into account GDPR principles — lawfulness, transparency, data minimization, storage limitation, and integrity and confidentiality — even in cases where the Company is not formally a data controller within the meaning of Regulation (EU) 2016/679.
9. Personal Data Retention Periods
Personal data is retained for the period necessary to achieve the purpose of its processing, namely:
- data related to the performance of the legal services agreement — for the term of the agreement and additionally for the period established by law for retaining the lawyer’s case file and for the possible appeal of case outcomes;
- data of persons who requested a consultation but did not conclude an agreement — no longer than 12 months from the last contact, unless consent has been given for a longer retention period;
- technical data (cookies, analytics) — in accordance with the periods established in Section 11 of this Policy.
Upon expiry of the relevant period, personal data is deleted or de-identified, except in cases where the law expressly requires longer retention.
10. Technical and Organizational Data Protection Measures
ADV Group applies a set of technical and organizational measures to protect clients’ personal data, in line with modern approaches to information security:
- encryption in transit — all data transmitted between the client’s browser and the Company’s servers is protected by HTTPS and TLS 1.3 protocols;
- encryption at rest — stored files and databases are protected using the AES-256 algorithm;
- access control — multi-factor authentication (MFA) and a role-based access model, under which each employee has access only to the information necessary to perform their tasks in a specific case;
- organizational measures — the duty to maintain attorney-client and professional secrecy, internal document handling regulations, and regular review of access rights.
Important: Confidentiality Limitations When Communicating via Messengers
The Company uses WhatsApp, Telegram, Viber, and Messenger as convenient channels for prompt communication with clients; however, the level of protection these platforms offer varies and does not always match the level of protection the Company provides on its own systems:
- WhatsApp encrypts all personal chats, calls, and files end-to-end by default.
- Since 2023, Viber has also encrypted personal and group chats end-to-end by default, but backups and chatbot messages are not covered by this protection.
- Telegram encrypts end-to-end only separately activated “Secret Chats”; regular chats and groups are stored on the developer company’s servers in a form accessible to it.
- Messenger applies end-to-end encryption, the level of which depends on the type of chat and the app’s settings.
Recommendation: messengers are suitable for arranging online meetings and organizational matters. For transmitting documents, details, and any confidential case information, we recommend using the Company’s secure client portal or email. By sending confidential information via messengers on their own initiative, the client acknowledges the technical limitations of these channels described above.
11. Cookies
The advokat-online.in.ua website uses cookies to ensure the website functions correctly, to analyze traffic, and to improve the user experience. Technical (essential) cookies do not require user consent, as the website cannot function without them. Analytical and marketing cookies are installed only with the user’s consent, which can be withdrawn at any time through the cookie settings on the website or in the browser settings.
12. Rights of the Data Subject
In accordance with Article 8 of Law No. 2297-VI, the data subject has the right to:
- know the sources of collection, the location of their personal data, the purpose of its processing, and the location of the data controller;
- receive information about the conditions for granting access to personal data, including information about third parties to whom the data is transferred;
- access their personal data;
- receive, no later than thirty calendar days from the date the request is received, a response as to whether their personal data is being processed;
- submit a reasoned request to the data controller objecting to the processing of their personal data;
- submit a reasoned request for the modification or destruction of their personal data if it is processed unlawfully or is inaccurate;
- protection of their personal data from unlawful processing and accidental loss or destruction;
- withdraw consent to the processing of personal data at any time;
- file complaints regarding the processing of personal data with the Ukrainian Parliament Commissioner for Human Rights or with a court.
For clients whose data falls within the scope of the GDPR, the rights to data portability, restriction of processing, and the right to lodge a complaint with the relevant data protection authority in their country of residence are additionally guaranteed.
To exercise any of the rights listed above, the client may contact the Company using the details provided in Section 14.
13. Procedure for Amending the Policy
The Company may update this Policy in connection with changes in legislation or internal data processing procedures. The current version is always published on advokat-online.in.ua, indicating the date of the last update. Material changes affecting the scope of the client’s rights are additionally communicated to existing clients by email.
14. Contacts for Personal Data Processing Matters
For questions related to the processing of personal data, the exercise of data subject rights, or this Policy, please contact us:
- through the contact form on advokat-online.in.ua;
- at the Company’s official email address listed on the “Contact” page;
- by post to the legal address of ADV Group Ukraine specified in the legal services agreement.
Note on the application of this document: this text is a baseline, legally sound version reflecting the current requirements of Law of Ukraine No. 2297-VI, Law No. 5076-VI, and general GDPR principles. Before publication, it is recommended that the document be reviewed by a practicing ADV Group lawyer, taking into account the Company’s specific organizational and legal form (law office/bar association/sole proprietorship), the actual list of services used (CRM, payment systems, hosting), and the current version of the legislation at the time of publication.