Data Protection White Paper
1. Purpose of This Document
This White Paper sets out how IK Pilates in Ukraine, operated by individual entrepreneur Karnaukh Iryna Oleksandrivna, implements the Law of Ukraine "On Personal Data Protection" No. 2297-VI and the related requirements of Ukrainian law across the IK Pilates platform and studio operations.
It is published in the interest of transparency. Our Privacy Policy tells you what we do with your data and what rights you have; this document explains how we govern, secure and evidence that processing. It is written for clients who want detail, for partners carrying out due diligence, and for our own staff.
Where this document and the Privacy Policy differ in emphasis, the Privacy Policy governs the description of processing towards data subjects.
2. Relationship to the General Data Protection Regulation
Our Bulgarian studio is operated by a separate legal person, IK Pilates Studio EOOD, which is an independent controller under Regulation (EU) 2016/679. The two operations are not joint controllers: each determines the purposes and means of its own processing, maintains its own records and answers its own requests.
If you are located in the European Economic Area, the Bulgarian documents and the standard of the Regulation apply to you.
For our Ukrainian operation, Ukrainian law governs. As a matter of practice, however, we have chosen to build the platform to a single technical standard across both countries. The encryption, consent granularity, retention automation, session control and erasure mechanisms described below are identical in Ukraine and in Bulgaria. Ukrainian clients therefore benefit from those measures whether or not the law requires them.
Ukraine is a party to Convention 108 of the Council of Europe. Draft Law No. 8153 "On Personal Data Protection", which would align Ukrainian law with the Regulation, introduce data protection officers, breach notification duties and a framework for cross-border transfers, and establish an independent supervisory authority, passed its first reading in the Verkhovna Rada on 20 November 2024 and is being prepared for a second reading. We monitor its progress and expect the measures described in this document to satisfy its requirements substantially on adoption.
3. Owner of the Personal Data File and Responsible Person
Owner of the personal data file: Individual entrepreneur Karnaukh Iryna Oleksandrivna Taxpayer registration number: 3029410706 Address: prov. Otakara Yarosha 12a, Kharkiv, 61045, Ukraine Contact for data protection matters: privacy@ikpilates.com
Article 24 of the Law requires the owner of a personal data file that processes special categories of personal data to designate a person responsible for organising the work relating to the protection of personal data, and to notify the Ukrainian Parliament Commissioner for Human Rights of that designation. Because we process data concerning health, this requirement applies to us.
The responsible person is designated by internal order and is accountable for maintaining the list of processing operations, handling requests from data subjects, instructing staff, keeping the record of disclosures required by Article 14, and coordinating the response to any security incident. The designation is recorded in our internal documentation and is disclosed to the Ukrainian Parliament Commissioner for Human Rights on request.
4. Principles Applied in Practice
Lawfulness and defined purpose. Every processing operation is mapped to a ground under Article 11 of the Law before it is implemented, and its purpose is stated in the Privacy Policy in plain language, in six languages.
Purpose limitation. Data collected to deliver Sessions is not repurposed for marketing or analytics. Data concerning health is used solely for safe instruction and for features the client has explicitly enabled.
Data minimisation. Onboarding was consolidated so that clients answer a single medical checklist rather than a series of separate medical screens; fields that were not used operationally were removed. IP addresses are stored only as keyed hashes rather than in plain form.
Accuracy. Clients may view and correct their profile, preferences and contact details at any time. Prefilled onboarding data is presented for reconfirmation rather than silently reused.
Storage limitation. Automated retention jobs run on a schedule and delete records whose retention period has elapsed, as set out in Section 8.
Security. The technical and organisational measures in Section 9 implement Article 24 of the Law.
Transparency and accountability. This document, the list of processing operations, the provider register, the retention schedule and the incident log together constitute our accountability file.
5. Processing Operations
We maintain an internal list of processing operations. The principal operations are summarised below, with the ground relied on under Article 11 of the Law.
Client account management - identity, contact and authentication data - performance of a transaction Booking and attendance - booking, attendance and waiting-list data - performance of a transaction Health screening for safe practice - data concerning health - consent under Articles 7 and 11 Mobile health and fitness integration - data concerning health - per-category consent under Articles 7 and 11 Transactional communications - contact data and delivery logs - performance of a transaction Marketing communications - contact data - consent Payments, invoicing and accounting - billing and payment data - permission granted by law Platform security, audit and abuse prevention - hashed IP, session and audit data - legitimate interests of the owner Website performance measurement - aggregate, cookieless counts - legitimate interests of the owner Waiting list and prospective client enquiries - contact and preference data - consent and pre-contractual steps Instructor and staff administration - engagement data - performance of a transaction and permission granted by law
6. Special Categories of Data and the Risk Assessment
Article 7 of the Law prohibits the processing of data concerning health save on the grounds listed in that Article. We rely on the unambiguous consent of the data subject, and we have assessed the risks of that processing and the measures required to address them.
The assessment identified the principal risks as unauthorised access to health records by studio staff without an operational need, exposure of health data in the event of a database compromise, drift towards analytics or marketing use, and consent that is not genuinely granular.
The measures implemented are as follows.
Consent is granular and per category, is recorded on the server, and is enforced on every read. Withdrawing consent for one metric category has no effect on any other. A client who declines all health features retains full use of the platform.
Sensitive values are encrypted at rest at column level. The encryption key for a client's medical fields is derived from a master key together with that client's own identifier, so that keys are not shared between clients.
Access is limited by role. Instructors and studio staff see only the information necessary to supervise a Session safely, and every person with access has signed a confidentiality undertaking as required by Article 10 of the Law.
Health data is excluded by design from marketing, advertising, profiling and third-party sharing. No tracking domains are declared in our mobile applications and no advertising framework is embedded.
Erasure is automated. When a client relationship ends, encrypted medical fields are scheduled for purge and are nulled after a thirty-day grace period, with an audit entry recording the purge.
7. Service Providers and Disclosure
Every provider that processes personal data on our behalf does so under a written agreement requiring processing only on our instructions, confidentiality, appropriate security measures, restrictions on further engagement of sub-providers, assistance with requests from data subjects, notification of incidents, and deletion or return of data at the end of the engagement.
Before engaging a provider we assess its security posture, its hosting locations, its transfer position and its incident notification commitments. The register records, for each provider, the purpose, the categories of data and the hosting region. The current list appears in Section 6 of our Privacy Policy and is reviewed at least annually.
Article 14 of the Law permits disclosure of personal data to third parties only with the consent of the data subject or on the grounds provided by law. Each disclosure to a third party is recorded, together with its date, its recipient and its legal ground, and that record is available to the data subject on request.
8. Retention Schedule and Automated Deletion
Retention periods are enforced by scheduled jobs rather than by manual review, so that expiry is the default outcome rather than an exception.
Contact and enquiry records - 730 days Notification delivery logs - 365 days Security and audit records - 730 days Records of revoked sessions - 90 days Inactive accounts - identified after 24 months of inactivity Account deletion grace period - 30 days, during which the request may be cancelled Medical field purge after end of client relationship - 30 days Booking and attendance records - 3 years, corresponding to the general limitation period under the Civil Code of Ukraine Accounting and tax records - for the periods required by the Tax Code of Ukraine and the rules of the State Archival Service
On deletion, purely personal records are hard-deleted. Records that we are legally required to retain, principally booking and accounting entries, are retained in depersonalised form: the identity record is reduced to a tombstone containing no personal data, which removes the identifying link from every record that references it.
9. Technical and Organisational Security Measures
The measures below implement Article 24 of the Law and are reviewed as part of our periodic security review.
Transport security. All traffic between clients, applications and our servers is encrypted using TLS. A content security policy is enforced on our web properties.
Authentication. Authentication tokens are signed asymmetrically using ES256 with short lifetimes and strict validation of issuer, audience and expiry. Sessions are enumerable and individually revocable by the client, and a server-side denylist enforces revocation before the token would otherwise expire.
Encryption at rest. Sensitive health fields are encrypted at column level using PGP symmetric encryption, with per-client key derivation. Database storage is encrypted at rest by our hosting provider.
Access control. Row-level security is enforced in the database. Application roles follow least privilege, and privileged operations run through defined security-definer functions rather than through broad grants. A role and permission matrix is maintained and tested.
Depersonalisation. IP addresses are hashed with a secret key before storage. Deleted identities become tombstones that depersonalise retained operational records.
Logging and monitoring. Privileged and security-relevant operations are recorded in an audit log with a defined retention period. Rate limiting protects authentication and booking endpoints, and an anti-abuse challenge protects the public contact form.
Organisational measures. Staff and instructors sign confidentiality undertakings covering personal data, receive instruction on engagement, and are granted access strictly according to role. Access rights are reviewed when a role changes and are withdrawn on departure, including revocation of active sessions.
Resilience. Data is stored with a provider offering redundancy and backup outside the territory affected by hostilities, so that records remain available notwithstanding damage to local infrastructure.
Change management. Database changes are applied through numbered, reviewed migrations. Security reviews are conducted periodically and their findings tracked to closure.
10. Security Incident Procedure
Any member of staff who becomes aware of a suspected incident affecting personal data must report it immediately to the responsible person named in Section 3.
The responsible person contains the incident, assesses the categories and approximate number of data subjects and records affected, the likely consequences and the measures taken, and records the incident in the incident log together with the reasoning.
Where the incident may affect the rights of data subjects, we inform the data subjects concerned and the Ukrainian Parliament Commissioner for Human Rights, without undue delay and in clear language, describing the nature of the incident, its likely consequences, the measures taken and the contact point for further information.
Where a provider becomes aware of an incident affecting our data, its agreement requires it to notify us without undue delay so that we can meet these obligations. We apply a target of 72 hours for our own assessment and notification, matching the standard we apply in Bulgaria, notwithstanding that Ukrainian law does not currently prescribe a fixed period.
11. Requests from Data Subjects
Requests may be submitted through the platform or by writing to privacy@ikpilates.com. Many rights are exercisable directly in the account: viewing and editing the profile, reviewing and revoking sessions and devices, managing consents per category, and requesting deletion with a copy of the data.
Every request is logged on receipt. We verify identity proportionately, using the account itself where possible rather than requesting additional identity documents. We respond within thirty calendar days, as required by Article 16 of the Law.
Where we refuse a request in whole or in part, we state the reason and the legal ground, and inform the requester of the right to complain to the Ukrainian Parliament Commissioner for Human Rights and to apply to a court.
Requests are handled free of charge.
12. Cross-Border Transfer
Article 29 of the Law permits transfer to a foreign party where the receiving state provides adequate protection. Member States of the European Economic Area and states party to Convention 108 are deemed by law to provide adequate protection.
Our principal data stores are located in the European Union, which satisfies that condition. Where a limited transfer occurs to a provider outside the European Economic Area, principally for push notification and email delivery, we rely on the safeguards offered by that provider, including the Standard Contractual Clauses of the European Commission, together with encryption in transit and at rest and minimisation of the data transferred.
13. Marketing and Electronic Communications
Transactional messages relating to a booking, a change to a booking, an account security event or a legal notice are sent on the basis of the contract and cannot be unsubscribed from while the account is active.
Marketing messages are sent only with prior consent. Every marketing message contains a functioning unsubscribe mechanism, and consent may be withdrawn at any time in the account settings. Consent records include the time, the channel and the wording presented.
Push notifications require operating system permission in addition to consent recorded in the platform, and may be disabled per category.
14. Review Cycle
This White Paper, the list of processing operations, the provider register, the retention schedule and the designation of the responsible person are reviewed at least annually.
An additional review is triggered by any of the following: introduction of a new category of personal data; engagement of a new provider or a change of hosting region; a security incident; the adoption of Draft Law No. 8153 or other material change in Ukrainian law; guidance issued by the Ukrainian Parliament Commissioner for Human Rights; or a complaint that reveals a gap.
15. Contact and Complaints
Individual entrepreneur Karnaukh Iryna Oleksandrivna Taxpayer registration number: 3029410706 Address: prov. Otakara Yarosha 12a, Kharkiv, 61045, Ukraine Data protection enquiries: privacy@ikpilates.com General enquiries: studio@ikpilates.com Telephone: +380 67 508 4343
You may lodge a complaint at any time with the control body for personal data protection in Ukraine.
Ukrainian Parliament Commissioner for Human Rights Address: vul. Instytutska 21/8, Kyiv, 01008, Ukraine Hotline: 0 800 50 17 20 Email: hotline@ombudsman.gov.ua Website: www.ombudsman.gov.ua
You also have the right to apply to a court for the protection of your rights and for compensation for material and moral damage caused by a breach of personal data protection legislation.
