Fındlee
Agents Demo Features Getting started Pricing FAQ Log in →
EN
Українська English
Log in Try it
Findlee

Privacy Policy

Effective date: September 10, 2026

Version date: 10 September 2026
Effective date: 10 September 2026
Permanent URL: https://findlee.com.ua/privacy/?lang=en

1. Who We Are and Scope of this Policy

1.1. Findlee is a software platform that provides legal entities, individual entrepreneurs and adult individuals with an AI assistant for search and navigation, knowledge-base answers, consultations, comparisons, recommendations, collecting enquiries, and interacting with content on informational, corporate, commercial, personal and other digital resources (the “Service”).

1.2. The owner and provider of the Service is individual entrepreneur Denis Dmytrovych Apekin, Ukrainian taxpayer registration number 3312916352, country of state registration: Ukraine, privacy email: welcome@nextdoorcoders.com (“Findlee”, “we”, “us”).

1.3. This Policy explains how we process personal data in connection with:

  • the findlee.com.ua website and its forms;
  • the dashboard, account, payments, support and administration of the Service;
  • the Findlee widget or other Findlee interfaces on our customers’ websites or channels;
  • integrations, event logs, analytics and Service security.

1.4. This Policy does not replace the Customer’s privacy policy. Where a person interacts with the widget on a Customer’s website, application or other digital resource, the Customer determines why its visitors’ data is used, which data is uploaded to the Service and the applicable legal basis. As a general rule, the Customer is the owner/controller of that data and Findlee is its processor acting on documented instructions.

1.5. For account management, billing, prospective-customer relations, our own website, support, security and legal compliance, Findlee determines the purposes and means of processing and acts as the owner of personal data under the Law of Ukraine “On Personal Data Protection” and, where applicable, as controller under the GDPR.

Related documents: Terms of Use, Data Processing Agreement (DPA) and Cookie Policy.

2. Key Terms

2.1. Customer means a legal entity, individual entrepreneur or adult individual with full legal capacity that orders the Service.

2.2. Dashboard User means an employee, contractor or other Customer representative granted access to the account.

2.3. Visitor means a person who interacts with the Customer’s website, application, channel, other digital resource or widget.

2.4. Customer Data means information submitted to or created through the Service by a Customer or its Visitors, including pages, documents, knowledge-base content, conversations, requests, images, events, leads, integration data and, where applicable, catalogue data.

2.5. Personal data, processing, owner/controller and processor have the meanings given by applicable law.

3. Data We Process

Depending on how the Service is used, we may process the following categories of data.

3.1. Enquiries and prospective customers

  • name;
  • company, organisation, project or other business name;
  • address of a website, application or other digital resource;
  • email, telephone number, username or identifier in Telegram, Viber, WhatsApp or another selected channel;
  • preferred communication channel;
  • comments, enquiry content, enquiry source and communication history.

3.2. Account and contractual relationship

  • Customer Account name, domain, administrator email and, where provided, Customer details and information about its representative;
  • authentication data, roles, permissions, Customer Account settings, tariff and partner association;
  • plan, orders, service documents, invoices, payment status and payment history;
  • available records showing acceptance of documents and payment confirmations, including the selected tariff, order number, amount, currency, date, status, paid term, automatic-renewal setting and a separate request for immediate commencement of paid access, where made.

Card payments are processed by LiqPay. Findlee receives and stores the identifiers and transaction parameters necessary for the payment, including order number, status, payment ID, amount, currency, transaction type and error codes or descriptions. Findlee does not store the full card number, CVC/CVV or payment-authentication credentials.

3.3. Support and communications

  • correspondence, support-request records and attachments;
  • technical diagnostic information;
  • support ratings and product feedback.

3.4. Technical and security data

  • for Dashboard Users: the IP address and User-Agent within the server session, date and time, session and network identifiers;
  • for widget Visitors: a random session identifier; the IP address and User-Agent are used to create a cryptographically hashed fingerprint and are not stored in plain text in the conversation history;
  • error logs, API requests, feature usage and credit consumption;
  • information about suspicious activity, blocks, failures and incidents;
  • cookies, local storage, pixels and similar technologies as described in the Cookie Policy.

3.5. Keys and integrations

  • API keys or tokens added by the Customer in BYOK mode;
  • authorisation tokens, external-system identifiers and integration configuration;
  • technical synchronisation metadata and integration errors.

BYOK keys and integration credentials are stored in encrypted form. After a BYOK key is saved, it is not returned in full to the browser: the interface displays only a masked value. The key can be replaced or deleted. Credentials for certain integrations may remain encrypted after the integration is merely disabled, until the Customer deletes the connection or the entire Customer Account.

3.6. Visitor data in the widget

Depending on Customer settings and Service features, this may include:

  • conversation text, search queries, AI responses and session history;
  • an uploaded image and technical attributes required for image search;
  • viewed pages, materials, services or products, clicks, search and navigation actions, comparisons, recommendations, conversions and other events;
  • session identifier, hashed technical fingerprint, language, date and time;
  • name, email, telephone number, username, lead text or other contact information voluntarily provided by the Visitor;
  • cart, order or customer-profile information where the Customer has connected the relevant integration;
  • pages, documents, knowledge-base content, Customer instructions and other context needed to generate an answer and, where applicable, catalogue data.

The Customer determines the specific data fields. The Customer must not submit special-category data, medical data, biometric data, precise payment credentials, government identifiers or children’s data unless this has been agreed in writing, an appropriate legal basis exists and the Service supports the required safeguards.

3.7. Aggregated data

We may create statistics that do not identify an individual and do not reasonably permit reconstruction of an individual’s identity or a particular Customer’s data. If re-identification is possible, the information remains personal data and is covered by this Policy.

4. Sources of Data

We receive data:

  • directly from a person who completes a form, creates an account or communicates with support or the widget;
  • from the Customer and its authorised users;
  • automatically from a device, browser, logs and cookies;
  • from Customer-connected websites, CMS, CRM, knowledge bases, catalogues, messengers, payment, analytics and other integrations;
  • from infrastructure, security, payment and communication providers within the scope of their functions;
  • from public sources where lawful and necessary for relevant business communication.

5. Why and on What Basis We Process Findlee’s Own Data

For data for which Findlee is the owner/controller, the following purposes and legal bases apply. Legitimate interests are relied on only after assessing that the interests or rights of the individual do not override our interest.

Purpose Categories Primary legal basis
Respond to an enquiry, provide a demonstration and prepare an offer contact details, prospective Customer’s website or other resource, correspondence steps before entering into a contract; legitimate interest in relevant business communication
Create and administer an account and provide the Service account data, roles, settings, usage logs performance of a contract with an individual; for a representative of another Customer, the parties’ legitimate interest in contract performance
Place an order, receive payment, send confirmation and maintain records Customer details, order number, amount, currency, payment status and ID performance of a contract; legal obligation
Support, diagnostics and service restoration requests, files, technical logs performance of a contract; legitimate interest in supporting and improving the Service
Protect accounts and prevent fraud and abuse IP address, login and activity logs, risk indicators legitimate interest in security; legal obligation where applicable
Evidence acceptance, protect rights and resolve disputes document version, time and technical evidence of acceptance, correspondence legitimate interest in establishing and defending rights; legal obligation
Send mandatory Service communications user contact details performance of a contract; legitimate interest
Use essential cookies and local storage technical and session data provision of the requested Service; legitimate interest in security
Analyse the public website Google Analytics online identifiers and events prior consent
Comply with law and lawful authority requests relevant data legal obligation; legitimate interest in protecting rights

Consent is not a condition of the core Service where processing is not necessary for that Service. Consent may be withdrawn prospectively at any time. A privacy policy is a transparency notice, not a form of “consent to everything”.

6. Customer Data: Findlee as Processor

6.1. When a Customer submits personal data of Visitors, users, applicants, buyers, employees or other persons to the Service, Findlee processes it only:

  • to provide, secure and support the Service;
  • on the Customer’s documented instructions;
  • under the Data Processing Agreement (DPA);
  • to comply with a legal obligation, of which we will notify the Customer where legally permitted.

6.2. The Customer is responsible for transparent Visitor notices, selecting a legal basis, configuring retention, obtaining consent for optional cookies and ensuring its instructions are lawful. Findlee remains responsible for its own processor obligations; a contract does not transfer to the Customer obligations imposed directly on Findlee by law.

6.3. If a Visitor contacts us about data in a widget, we will generally direct the Visitor to the relevant Customer and assist the Customer with the request.

7. AI Features, Casual and BYOK

7.1. To generate a response, a query, selected context from pages, documents, the knowledge base or catalogue, instructions and other necessary Customer Data may be sent to an AI model provider.

7.2. In Casual mode, Findlee selects the provider and API account. Depending on settings and availability, OpenAI, Anthropic Claude or Google Gemini may be used.

7.3. In BYOK mode, the Customer selects and connects a provider using its own key. The Customer establishes its own relationship with that provider and reviews its terms, region, retention, training settings, quotas and the lawfulness of transfer. Findlee performs technical routing on the Customer’s instruction but cannot guarantee the policies of a third-party provider selected by the Customer.

7.4. Findlee does not use Customer Data or Visitor conversations to train its own or shared general-purpose AI models.

7.5. AI output may be inaccurate, incomplete or inappropriate. The Customer determines the knowledge base, instructions and permitted scenarios and must arrange human oversight where consequences may be significant.

7.6. Findlee is not intended to independently make decisions that produce legal or similarly significant effects on a person, including decisions about credit, employment, insurance, medical treatment or access to essential services. The Customer must not use it in this manner without a separate written assessment, appropriate legal basis and safeguards.

8. Recipients of Data

To the extent necessary, data may be accessed by authorised Findlee employees and contractors bound by confidentiality obligations, as well as the following providers and categories of recipients:

Recipient or category Function Data and condition of transfer Region
Contabo server infrastructure, database, search and file storage data hosted in the Service EU region
OpenAI, Anthropic, Google Gemini generation of AI responses query, required context, knowledge-base or catalogue data, depending on the selected mode EEA, United States and other regions according to the provider’s product and settings
LiqPay / JSC CB PrivatBank payment acceptance and subscription management payment parameters and information entered by the Customer directly in LiqPay Ukraine
Google SMTP transactional, service and legal email delivery recipient address, subject, message content and technical delivery data EEA, United States and other Google infrastructure regions
Google Analytics analytics on the public landing page only online identifiers and events only after consent EEA, United States and other Google infrastructure regions
Meta, Telegram, eSputnik, recipient SMTP server or Customer webhook delivery of leads and orders at the Customer’s instruction fields entered by the Visitor, order contents and page URL; only where the Customer enables the channel according to Customer choice and the relevant provider’s terms
Google Fonts display of fonts in the dashboard technical browser network request Google infrastructure

Data may also be disclosed to consultants, auditors and professional advisers subject to confidentiality; public authorities or courts where required by law or necessary to protect rights; and a successor in connection with a reorganisation or business transfer subject to appropriate safeguards. Changes to subprocessors are handled in accordance with the DPA.

We do not sell personal data or provide Customer Data to independent advertisers for their own purposes.

9. International Transfers

9.1. Data may be processed in Ukraine and in other countries where properly engaged providers operate. Before a transfer, we assess the applicable legal basis and required safeguards.

9.2. Where the GDPR applies to a particular transfer, Findlee and the Customer will determine and document an appropriate transfer mechanism, having regard to their respective roles, before that transfer begins. This may include the EU Standard Contractual Clauses 2021/914, a transfer assessment and supplementary measures where required. Ukraine is not currently included in the European Commission’s list of countries benefiting from an adequacy decision. This clause does not itself mean that the relevant clauses have already been executed with every Customer or for every data route.

9.3. Transfers governed by Ukrainian law are handled in accordance with Article 29 of the Law of Ukraine “On Personal Data Protection” and other applicable safeguards.

10. Retention Periods

We retain data no longer than necessary for the specified purpose, compliance with law, or the establishment or defence of claims.

Data Retention period
Landing-page application and correspondence with a prospective customer up to 2 years after the last meaningful interaction, or earlier following a justified objection
Support correspondence with an active Customer for the duration of Service use and up to 3 years after the relationship ends, unless a longer period is required for a specific dispute or by law
Minimum contractual records and available acceptance evidence, excluding an active Customer Account for the duration of the contract and up to 3 years after termination, unless a longer period is required by law or for a dispute
Tax, accounting and payment records for the period expressly required by tax and accounting law, which may exceed 3 years
Application log 14 days, except for a record isolated for investigation of a specific incident or legal requirement
Web-server log rotated by volume; the actual period depends on event volume and is generally short
Dashboard User server session active for 12 hours of inactivity; stale technical records are removed by the system mechanism
Customer Account and associated data after access ends up to 180 days from the end date of the most recent access term provided, followed by automatic deletion; warnings are sent approximately 30 and 7 days beforehand
Visitor conversations and associated images 60 days of inactivity; when a conversation is deleted manually, associated images are deleted immediately
Leads and orders until manually deleted by the Customer or the Customer Account is deleted in full
Knowledge base, its sources and search representations until the Customer deletes the source or the Customer Account is deleted in full; a brief technical synchronisation delay may occur after a deletion command
Product catalogue until the catalogue is manually reset or the Customer Account is deleted in full
BYOK keys until replaced or deleted by the Customer or the Customer Account is deleted in full
Integration credentials until separately deleted or the Customer Account is deleted in full; merely disabling certain integrations may not delete encrypted connection data
Visitor session identifier cookie: 30 days and may be renewed; localStorage: until browser data or widget history is cleared; after the associated conversation is deleted, the identifier is no longer linked to server-side history
Optional cookies for the specific periods stated in the Cookie Policy and no longer than necessary

At the end of the applicable period, we delete or securely anonymise data unless continued retention is required by law. Retention may be suspended for specific data while a dispute, investigation or mandatory preservation requirement is ongoing.

11. Security

11.1. We implement organisational and technical measures appropriate to risk, including access segregation, password hashing, encryption of BYOK keys and integration credentials, protection of data in transit, request-rate restrictions, error logging, access control for private images and response to technical incidents. Further details are provided in the DPA.

11.2. No service can guarantee absolute security. The Customer is also responsible for strong credentials, role management, lawful integration configuration and timely revocation of access.

11.3. We do not claim ISO, SOC 2, PCI DSS or other certification unless it has actually been obtained and its scope verified.

12. Individual Rights

Depending on applicable law, an individual may have the right to:

  • know the sources, location, purpose and conditions of processing;
  • access their personal data;
  • require correction of inaccurate or incomplete data;
  • require deletion or restriction of processing where grounds exist;
  • object to processing based on legitimate interests and to direct marketing;
  • withdraw consent prospectively without affecting prior lawfulness;
  • receive their own personal data in a structured, machine-readable format only where and to the extent that the statutory right to portability applies;
  • not be subject to a decision based solely on automated processing where it produces legal or similarly significant effects;
  • obtain information about automated processing mechanisms to the extent provided by law;
  • lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or, where the GDPR applies, a competent EU supervisory authority;
  • seek judicial protection and exercise other rights under Article 8 of the Law of Ukraine “On Personal Data Protection” and the GDPR.

To exercise a right, email welcome@nextdoorcoders.com. We may request information sufficient to verify identity and locate the relevant data, but no more than necessary. We will respond within the period required by applicable law. A request is normally free of charge; a fee or refusal is possible only where expressly permitted by law, for example for manifestly unfounded or excessive repeated requests.

An individual’s applicable right of access or portability concerning their own personal data does not constitute a general export feature for all Customer Account data. The Service does not provide a separate button or standard feature to export conversations, catalogues, leads, orders or the entire Customer Account.

The dashboard does not provide a self-service feature for complete deletion of a Customer Account. The account owner may request complete deletion by emailing welcome@nextdoorcoders.com from the email address associated with the account. We will verify identity and authority, explain the consequences and, following confirmation, delete the Customer Account and all associated data from active systems, except for the minimum records we are legally required to retain.

If a request concerns data in a widget on a particular Customer Resource, please contact the owner or operator of that Resource first. We will assist that party as its processor where required.

13. Marketing and Cookies

13.1. As of this version date, Findlee does not send marketing or advertising emails. Transactional, service, legal and security communications necessary to process a payment, perform the contract or protect the Service are not marketing. Before launching marketing communications, we will update this Policy and implement the required consent or opt-out mechanism.

13.2. Essential technologies are used for requested functions and Service protection. Google Analytics is used only on the public landing page and is loaded only after the user’s consent. Google Analytics is not used in the dashboard or widget. A user may reject analytics or change their choice through the cookie settings. Details are provided in the Cookie Policy.

14. Children

14.1. A Findlee account may be created only by persons aged 18 or over with full legal capacity. The Service is not directed at children. A Customer must not intentionally collect children’s data through the Service without a prior written assessment, an appropriate legal basis, transparent notice and all required permissions.

14.2. If you believe a child’s data has been submitted to the Service improperly, please notify us and the relevant Customer.

15. EU Representative

As of this version date, Findlee directs its advertising and commercial launch to the Ukrainian market and has not appointed an EU representative. This does not prohibit Customers from other countries from using the Service. If the nature of an offering or monitoring brings Findlee within Article 3(2) GDPR and an obligation arises under Article 27 GDPR, this section will be updated before the relevant targeted launch begins.

16. Changes to this Policy

16.1. We may update this Policy to reflect changes to the Service, providers or law. The version date is displayed at the beginning of the document.

16.2. Where material changes significantly affect rights or the manner in which data is used, we will provide a prominent notice in the Service and/or by email before the changes take effect where practicable and legally required.

16.3. If consent is required for a new purpose, we will request it separately. Continued use of the Service does not itself replace consent where law requires a freely given, specific and unambiguous choice.

17. Contact and Complaints

Owner/controller: Individual entrepreneur Denis Dmytrovych Apekin
Ukrainian taxpayer registration number: 3312916352
Country of state registration: Ukraine
Privacy email: welcome@nextdoorcoders.com
General email: welcome@nextdoorcoders.com

For questions about data on a particular Customer Resource, please also contact its owner or operator as the owner/controller.

In Ukraine, a complaint may be submitted to the Ukrainian Parliament Commissioner for Human Rights. Where the GDPR applies, an individual may also lodge a complaint with the EEA supervisory authority for the place of their habitual residence, place of work or place of the alleged infringement.

Fındlee

Helping buyers at every step.

Powered by LiqPay

Product

AgentsFeaturesPricingFAQ

Resources

Getting startedExamples

Company

Contact
© 2026 Findlee. All rights reserved. Privacy Policy Terms of Use DPA Cookie Policy