Privacy Policy
1. Data Controller
Controller: Danylo Kamyshan, acting as a natural person and resident of Japan. Address: 〒123-0864, Tokyo-to, Adachi-ku, Shikahama 2-40-4, #105 E-mail: [email protected] Phone: +81-80-4635-7027 Website: https://pay.danielviktorovich.com/
2. Categories of personal data processed
The Controller processes the following categories of personal data of Users and Clients:
- Identification data: full name, country of residence;
- Contact data: e-mail, phone number, messenger usernames (Telegram username, etc.);
- Payment data: processed exclusively by Payment Providers (Stripe, PayPal, Wise, Revolut) — the Controller does not store full card details;
- Substantive work data: Client responses in forms, correspondence with Clients, content of coaching sessions, video and audio recordings of sessions (see specific provisions in Section 6);
- Technical data: IP addresses, cookies, data on actions on the site (via third-party analytics — Google Analytics, Meta Pixel, etc.).
3. Purposes of processing
3.1. Conclusion and performance of agreements for the provision of coaching and consulting services.
3.2. Communication with Users and Clients (e-mails, responses to requests).
3.3. Settlements and invoicing.
3.4. Conducting coaching sessions and supporting the Client's Programme.
3.5. Marketing and informing about new services — only with the express consent of the User.
3.6. Compliance with applicable law (tax accounting, responses to requests of competent authorities).
4. Legal bases for processing
In accordance with the GDPR (for EU residents) and analogous norms:
- Contract (Art. 6(1)(b) GDPR) — for the performance of a contract with the Client;
- Consent (Art. 6(1)(a) GDPR) — for marketing newsletters, analytics, consent to video recording of sessions;
- Legitimate interests (Art. 6(1)(f) GDPR) — for protection against disputes (preservation of session recordings), improvement of service quality;
- Legal obligations (Art. 6(1)(c) GDPR) — tax and other accounting.
5. Retention period
5.1. Contact and identification data — no more than 24 (twenty-four) months after the end of provision of services or the last interaction with the User, unless a longer period is required by applicable law or the individual agreement.
5.2. Payment and tax data — within the period established by applicable Japanese tax law (usually at least 7 years).
5.3. Video and audio recordings of coaching sessions — at least 36 (thirty-six) months after completion of the Client's Programme, on the basis of the Client's consent expressed by signing the individual agreement with the Controller. Deletion after this period — at the Client's request within 30 calendar days, in the absence of a legitimate interest in continuing storage.
5.4. Technical data (cookies, analytics) — within the period established by the relevant services (Google Analytics — typically up to 14 months, Meta Pixel — per Meta's rules).
6. Video and audio recordings of coaching sessions
6.1. Recordings of coaching sessions with Clients are made on the basis of the Client's consent expressed by signing the individual agreement. Consent to recording is a material condition of the work.
6.2. Recordings are stored locally on the Controller's devices or in a secured cloud with end-to-end encryption (Proton Drive or equivalent).
6.3. Recordings are not published, not transferred to third parties, and not used for marketing purposes without the Client's separate written consent to the specific form of use.
7. Recipients of data (Third-party Processors)
The Controller transfers personal data to the following categories of recipients only to the extent necessary for processing purposes:
- Payment Providers (Stripe, PayPal, Wise, Revolut) — process payment data in accordance with their own policies and PCI DSS standards. This list names the providers that actually receive personal data and is updated whenever a new provider is engaged; the current payment methods are published in clause 3.4 of the Terms of Service;
- Cloud services: Proton Drive (for storing encrypted recordings), Google Workspace (e-mail);
- Analytics and marketing: Google Analytics, Meta Pixel (on the site) — subject to User consent;
- Communication platforms: Zoom (for conducting sessions), Telegram (by agreement with the Client);
- Controller's professional advisors: lawyers, tax consultants — based on legitimate interest.
A full list of categories of data processed by third parties — upon Client request.
8. Cross-border transfer of data
8.1. Given the international nature of the Controller's activities, personal data may be transferred outside Japan — to the European Union, the USA, CIS countries, and other jurisdictions.
8.2. Upon cross-border transfer, the Controller ensures an adequate level of protection:
- transfer based on EU Standard Contractual Clauses (SCC) or analogous mechanisms;
- use of encrypted connections (TLS, end-to-end encryption for recordings);
- transfer only to the extent necessary for the purposes of processing.
9. Rights of data subjects (Users and Clients)
In accordance with GDPR, APPI, and analogous norms, the User has the right to:
- access (Art. 15 GDPR) — receive a copy of the data processed;
- rectification (Art. 16 GDPR) — request correction of inaccurate data;
- erasure / "right to be forgotten" (Art. 17 GDPR) — subject to restrictions (see Section 5);
- restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR) — receive data in a structured machine-readable format;
- object to processing (Art. 21 GDPR) — especially for marketing purposes;
- withdraw consent at any time;
- lodge a complaint with the supervisory authority of one's country.
To exercise rights, send a request to: [email protected].
The Controller responds to requests within 30 calendar days (with the possibility of extension to 60 days for complex requests under GDPR).
10. Cookies and analytics
10.1. The site uses cookies and third-party analytics services (Google Analytics, Meta Pixel) for analysing User behaviour and improving service quality.
10.2. The User can manage cookies through browser settings or opt-out using the settings of the relevant services.
11. Jurisdictional specifics
11.1. For EU / Cyprus residents. GDPR (Regulation (EU) 2016/679) applies. Supervisory authority — national regulator of the country of residence.
11.2. For Japan residents. 個人情報保護法 (Personal Information Protection Act / APPI) applies. Supervisory authority — 個人情報保護委員会 (Personal Information Protection Commission, PPC).
11.3. For Russia residents. Processing is carried out in accordance with Federal Law No. 152-FZ "On Personal Data". Given the Controller's status as a resident of Japan and the nature of remote services, data transfer to Russia may be carried out with the data subject's consent.
11.4. For US residents. CCPA (California Consumer Privacy Act) provisions apply for California residents — the right to know, delete, and opt out of the sale of personal data. The Controller does not sell personal data.
11.5. Other jurisdictions — national legislation applies; in case of conflict with this Policy, the Controller brings processing into compliance with the stricter standard.
12. Security
The Controller applies legal, organisational, and technical measures to protect personal data, including:
- encryption of data transmission (TLS / HTTPS);
- end-to-end encryption for critically sensitive data (session recordings — Proton Drive);
- restriction of access to data;
- regular updates of systems and security checks.
13. Changes to the Policy
The Controller is entitled to amend this Policy. The current version is published on the site at https://pay.danielviktorovich.com/legal/privacy-policy. Material changes are accompanied by notification of Users by e-mail.
14. Contact
All questions regarding the processing of personal data are sent to:
E-mail: [email protected] Phone: +81-80-4635-7027 Address: 〒123-0864, Tokyo-to, Adachi-ku, Shikahama 2-40-4, #105