Privacy Policy
1. Who we are
Imperium Web Agency ("Imperium", "we", "us", "our") is a web development and digital marketing company with offices in Ukraine, Poland, and the USA, operating through the imperium-agency.com website ("Site"). This Policy describes how we collect, use, and protect your personal data. We act as a Data Controller under GDPR (EU Regulation 2016/679), Ukraine's Data Protection Act, and CCPA (California Consumer Privacy Act) for California residents.
2. What data we collect
We collect: (a) data you provide knowingly via forms (name, email, phone, company, project description, budget); (b) technical data (IP address, browser type, OS, referrer URL, session time); (c) behavioural data via cookies and Google Analytics 4 (page views, clicks, time on page); (d) data you share via messengers (Telegram, WhatsApp, email correspondence). We do NOT collect sensitive categories (medical, religious, orientation) without explicit consent.
3. Legal bases for processing
We process your data on the following bases: (a) consent (Art. 6(1)(a) GDPR) — for marketing emails and analytics cookies; (b) contract performance (Art. 6(1)(b) GDPR) — to respond to your inquiry, prepare a proposal, deliver the project; (c) legitimate interest (Art. 6(1)(f) GDPR) — to improve the site, prevent fraud, run analytics; (d) legal obligation (Art. 6(1)(c) GDPR) — for accounting and tax reporting. You may withdraw consent at any time by writing to info@imperium-agency.com.
4. How long we keep data
Form leads — 24 months from last interaction. Client data under contract — 5 years after project close (legal purposes). Analytics data (GA4) — 14 months. Cookies — from 1 session up to 12 months (see Cookies section). You may request earlier deletion by emailing info@imperium-agency.com.
5. Who we share data with
We share the minimum required amount of data with these categories of processors: (a) hosting & infra — Vercel Inc. (USA, EU-U.S. Data Privacy Framework), Hetzner (EU); (b) email services — Resend (USA), Google Workspace (USA); (c) analytics — Google Analytics 4 (USA, EU-U.S. DPF); (d) messengers — Telegram Bot API. Each has signed a DPA (Data Processing Agreement) with us. We do NOT sell your data to third parties.
6. International transfers
Some processors are based outside the EEA (USA). For such transfers we rely on: (a) EU-U.S. Data Privacy Framework for certified companies; (b) EU Standard Contractual Clauses (SCCs); (c) additional technical measures (encryption). Copies of SCCs are available on request at info@imperium-agency.com.
7. Your rights
Under GDPR and CCPA you have the right to: (a) access; (b) rectification; (c) erasure ("right to be forgotten"); (d) processing restriction; (e) data portability; (f) objection to processing; (g) consent withdrawal; (h) filing a complaint with a supervisory authority (Ukrainian Parliament Commissioner for Human Rights, or your national DPA in the EU). California residents also have CCPA rights: to know, delete, opt out of sale (we don't sell), and be free from discrimination for exercising rights. We respond to all requests within 30 days.
8. Security
We apply technical and organisational safeguards: HTTPS/TLS 1.3, at-rest DB encryption, "least privilege" access, access logs, regular backups, 2FA for staff. In case of a data breach, we notify the supervisory authority within 72 hours and affected individuals without undue delay.
9. Cookies
We use: (a) necessary cookies (session, theme preference — legitimate interest, no consent needed); (b) analytics (Google Analytics 4 — only after your consent in the cookie banner); (c) functional (language, locale — legitimate interest). You can manage cookie settings via the consent banner at the bottom of the site or in your browser settings.
10. Children
Our site is not directed at persons under 16. We do not knowingly collect data from such persons. Parents who suspect their child provided us with data may email info@imperium-agency.com — we will delete it within 30 days.
11. Policy changes
We may update this Policy. Material changes will be announced via a site banner or email (if you provided one). The last-updated date is at the top of the document.
12. Contact
Privacy inquiries: email info@imperium-agency.com. Data Protection Officer (DPO): at this email.