Privacy Policy
Translation for convenience. In case of discrepancies, the Russian version of the document shall prevail. Open Russian version
This Policy explains what personal data the 1001site AI service ( 1001site.com, asd.vibevox.pro, and websites created within it) processes, why, on what basis, and what rights you have. We comply with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Law of Ukraine "On the Protection of Personal Data."
1. Data Controller
FOP Danyuk Valeriy Anatoliyovich · EDRPOU 2806513011
Ukraine, Kharkiv, Natalia Uzhviy Street, 64-72
Phone, WhatsApp: +380637610482 Telegram: @GuruAppSheet
Contact for personal data inquiries is the same Telegram and WhatsApp (message subject: “Personal data”).
2. What data do we process?
- Account: email, name (displayed), password (stored as a hash), Google / Telegram IDs if logged in through them, phone number (if specified), language and settings.
- Website and content: titles, texts, images, products, orders and customer contacts, uploaded files, import links (website, Instagram, TikTok, Facebook, Telegram), domain settings.
- AI assistant: your commands (prompts), screenshots and files you send in chat, generation results; API keys of model providers — in encrypted form.
- Payments: subscription status, amounts, dates, Stripe / Monobank transaction IDs, country, and the last four digits of the card number (from the payment provider). We do not receive or store full card details.
- Integrations: Telegram bot tokens and WhatsApp sessions connected by you (encrypted), messages coming through them to your website.
- Technical data: IP address, browser and device type, pages and time of visit, error logs, cookie IDs (see Cookie Policy).
- Requests: correspondence in Telegram / WhatsApp, requests from the “Create a website” form (name, contact, wishes, link).
3. Objectives and legal basis
| Target | Data | Basis (Article 6 of the GDPR) |
|---|---|---|
| Registration, account and website operation, AI assistant, support | account, content, teams, integrations | performance of the contract (6(1)(b)) |
| Payment acceptance, invoices, accounting | payments | contract (6(1)(b)), legal duty (6(1)(c)) |
| Security, protection from abuse, backups, logs | technical data, account | legitimate interest (6(1)(f)) |
| Traffic analytics ( Google Analytics) | cookies, technical data | consent (6(1)(a)) - cookie banner |
| Marketing and Retargeting (Meta/ Instagram Pixel, TikTok Pixel) | cookies, technical data | consent (6(1)(a)) - cookie banner |
| Responses to inquiries, notifications about the operation of the Service | appeals, e-mail | contract / legitimate interest |
| Newsletters about new features and promotions | consent (6(1)(a)); unsubscribe in every letter |
4. To whom the data is transferred (processors and recipients)
- Hostinger International Ltd. (VPS in Lithuania, EU) — hosting servers, databases, and files.
- Cloudflare, Inc. — DNS protection and acceleration for the asd.vibevox.pro domain (US/EU, Data Privacy Framework).
- Stripe Payments Europe, Ltd. (Ireland) and Monobank / Universal Bank (Ukraine) — payment acceptance.
- Google LLC - Login via Google, Google Fonts, Google Analytics (with consent), Gemini models and translations (using your key or the Service key for system functions).
- Anthropic PBC, OpenAI OpCo LLC — AI models if you've connected their keys or MCP client; command data is transmitted to the provider of your choice.
- Meta Platforms Ireland Ltd. ( Facebook / Instagram Pixel) and TikTok Technology Ltd. ( TikTok Pixel) – marketing analytics only with your consent in the cookie banner.
- Telegram FZ-LLC, WhatsApp (Meta), YouTube ( Google) — built-in post and video widgets, bots, and notifications that you enable.
- Government agencies - only upon legal request.
We do not sell personal data or transfer it for third-party marketing.
5. Transfer outside the EU
The data is stored on servers in the EU (Lithuania). The controller is located in Ukraine and accesses the data for contract performance and support purposes (Article 49(1)(b) of the GDPR) using the EU's standard contractual clauses (SCC) in relations with processors. Transfers to US providers ( Google, Meta, Cloudflare, Anthropic, OpenAI, Stripe) are carried out based on an adequacy decision under the EU-US Data Privacy Framework and/or the SCC. AI models only receive the data you submit in commands.
6. Storage periods
- Your account and website content will be deleted while you use the Service; after account deletion or 30 days after the end of an unpaid subscription, your backup copies will be overwritten for a limited time.
- Payment records - 5 years (accounting and tax requirements).
- Server and security logs - up to 12 months.
- AI chat commands are stored in your account history until you delete them; model providers store requests according to their own policies.
- Cookies — according to the terms in the Cookie Policy; the choice in the banner is stored for 12 months.
7. Your rights
You can: access your data and obtain a copy of it (download from the website in your account), correct it, delete it ("right to be forgotten"), restrict processing, object to processing based on legitimate interest, receive data in machine-readable form (data portability), and revoke your consent at any time (in the cookie banner - the "Cookie Settings" button in the footer; in newsletters - the link in the email). Requests are processed within 30 days. You also have the right to file a complaint with the data protection supervisory authority of your EU country or the Ukrainian Parliament Commissioner for Human Rights.
8. Security
All traffic is protected by TLS, including user domains; passwords are stored hashed; API keys and bot tokens are encrypted; server access is secured by keys; database backups are made daily and before each update; data from different users is isolated at the database level. No system provides an absolute guarantee – please notify us immediately if you suspect a leak. In the event of a leak, we will notify the supervisory authority and affected parties within the timeframes set out in Articles 33–34 of the GDPR.
9. Data from visitors to your websites
With respect to visitors and buyers of a website created using the Service, you are the controller; we process their data as a processor in accordance with your instructions (hosting, orders, forms, bots). You are obligated to place your own privacy policy on your website and, if using analytics or pixels, a consent banner.
10. Children
This service is intended for individuals over 18 years of age; we do not knowingly collect data from children.
11. Changes
The current version is always available on this page, along with the update date. We will notify you of any significant changes in your account or by email.
12. Contacts
FOP Danyuk Valeriy Anatoliyovich · EDRPOU 2806513011
Ukraine, Kharkiv, Natalia Uzhviy Street, 64-72
Phone, WhatsApp: +380637610482 Telegram: @GuruAppSheet