The PODOCARD service (hereinafter referred to as the Service) pays great attention to the protection of its users' personal data. Users may view the public pages of the Site without registering an account. The procedure for collecting technical information and using cookies is described in this Policy. However, in order to provide the services offered by our Service, we need your contact details so that we can contact you and provide you with the selected services in a high-quality manner. We protect the confidentiality of personal data. It is transferred, or access to it is granted to recipients, only on a proper legal basis, for the defined purposes and to the extent provided for by this Policy.
This policy is governed by the Law of Ukraine ‘On the Protection of Personal Data’ dated 01.06.2010 No. 2297-VI.
Last updated: 3 September 2026.
TERMINOLOGY
The following terms are used in this Privacy Policy:
‘Personal data’ means any information relating directly or indirectly to a specific or identifiable natural person (data subject).
‘Processing of personal data’ means any action (operation) or set of actions (operations) performed with or without the use of automation tools on personal data, including collection, recording, systematisation, accumulation, storage, clarification (updating, changing), extraction, use, transfer (distribution, provision, access), depersonalisation, blocking, deletion, destruction of personal data.
‘Confidentiality of personal data’ - a requirement that must be observed by the Administrator or other person who has access to personal data not to disclose it without the consent of the subject of personal data or the existence of another legal basis.
‘User’ - a person who has reached the age of 18 and who accesses the Service via the Internet and uses the Service.
‘User's Client’ - a natural person whose information is entered by the User into the Service within the scope of providing services in the field of podiatry, cosmetology, hardware pedicure or related areas.
‘Client Profile’ - a set of data entered into the Service about an individual client (full name, contact information, photo, visit history, notes, signed documents, etc.).
‘Administration’ - Private Entrepreneur under the laws of Ukraine Serdiukova Anna, as well as any other persons authorised to maintain the functioning, control and monitor the Service.
‘Service’ - software products, as a result of computer programming, designed to organise internal electronic accounting of clients within the professional activities of relevant specialists, whose servers are located in a secure software and hardware platform of a ‘cloud’ data centre, accessed via a website located on the Internet at http://podocard.com and/or the PodoCard mobile application, which is available for download on Google Play and the App Store, provided for personal use by users.
‘Services’ - access to the tools offered on the Website for use by the User. PodoCard is an electronic accounting tool that allows users to systematise and store customer data within the scope of their professional activities in the field of podiatry, cosmetology, hardware pedicure and related areas (hereinafter referred to as the Tools). The application is not a medical device and is not intended for the provision of medical services, diagnosis or treatment.
SECTION 1: GENERAL PROVISIONS
This privacy policy establishes the procedure for obtaining, storing, processing, using and disclosing users' personal data. We obtain users' personal data from users when they use the Service. Information marked in a special way is mandatory. Other information is provided by the user at their own discretion.
The confidentiality of personal data is a mandatory condition for the Service to comply with access to the personal data of Users and Users' Clients, with the requirement not to allow its dissemination without the user's consent or other legal basis.
Use of the Service by Users implies agreement with this privacy policy and the terms of personal data processing.
If the User does not agree with the terms of the policy, they must stop using the Service.
This policy applies only to the Service and does not control or bear responsibility for third-party websites and services.
The administration does not verify the accuracy of personal data provided by Users to the Service.
By using the Service, the User consents to the Administration processing their personal and registration data and that of their Clients. If the User decides to provide their personal data, as well as the personal data of their Clients, they thereby consent to the transfer and storage of this data.
Use of the Service is only available to persons who have reached the age of majority in accordance with the laws of the country of residence and/or citizenship of such person and who are capable of entering into legally binding contracts in accordance with applicable law. If you do not meet these requirements and/or you have not received the explicit consent of your parents and/or legal representative, please do not use the Service. If you are a parent or legal representative of a child and allow them to use our Service, these terms apply to you and you are responsible for the child's actions on our Service. Any further use of the Service and/or any part thereof means that you have read and understood the Terms of Use and Privacy Policy and agree to comply with all sections of the Terms of Use and Privacy Policy.
SECTION 2: PERSONAL DATA
To use the Service, the User must register an account, providing information such as:
Full name
Phone number
Email address
Please note that we make every effort to protect and not disclose your personal data and photos.
If you provide us with personal information, you understand that we may collect, store, use, and disclose your personal information in accordance with this Privacy Policy.
Our Service collects and analyzes various information. Such information may include the first name, last name, contact phone number, email address, mailing address, residential address and date of birth of you and the Users' Clients, photos, and various information regarding the Users' Clients' procedures (hereinafter referred to as “Personal Information”).
Other information is provided by the User at their discretion.
If we receive personal information about you from a third party, we will protect it in accordance with this Privacy Policy. If you are a third party providing personal information about someone else, you represent and warrant that you have that person's consent to provide us with their personal information.
If you have previously consented to our use of your personal information for direct marketing purposes, you may change your mind at any time by contacting us using the details below and stating “Privacy Request” in the subject line.
You may request details of the personal information we hold about you by contacting us using the details below, specifying “Privacy Request” in the subject line.
If you believe that any information about you is inaccurate, outdated, incomplete, irrelevant, or misleading, please contact us using the details below, specifying “Privacy Request” in the subject line. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading, or outdated.
If you believe that we have violated applicable data protection laws and wish to file a complaint, please contact us using the details below and provide us with full details of the alleged violation, marking your email subject line with “Privacy Request.” We will investigate your complaint immediately and respond to you in writing, setting out the results of our investigation and the steps we will take to address your complaint. You also have the right to contact a regulatory authority or data protection authority in connection with your claim.
The administration has the right to send information, including advertising messages, to the User's email and mobile phone with their consent. The User has the right to refuse to receive advertising and other information without giving reasons for the refusal. Notifications from the Service about orders and the stages of their processing cannot be rejected by the User.
SECTION 3: PURPOSES OF COLLECTING AND PROCESSING USERS' PERSONAL DATA
The purpose of processing personal data is to ensure the implementation of civil law relations and the provision/receipt of Services.
The Service collects and stores only the personal data necessary to provide the Services.
The Service collects data for communication with the User, including notifications about the provision of Services, informing the User about the provision of Services, as well as for processing requests and applications from Users.
The processing of personal data of the User and the Users' Clients is carried out during the period of use of the Service and, after access ends, for the retention periods defined by this Policy. Deletion requests and withdrawals of consent are handled taking into account the legal basis for the processing and the requirements of the law. The withdrawal of consent does not affect the lawfulness of processing prior to the withdrawal and does not terminate processing for which another proper legal basis exists.
If the User confirms a request to delete their account, the use of the account is blocked. If the request is submitted by the owner of a company in the Service, access of all of its employees to the company's account space is also blocked. For 7 (seven) calendar days from the moment the request is confirmed, the data is stored temporarily so that the deletion can be cancelled and access restored.
Before that period expires, the User may cancel the request by contacting support@podocard.com. A timely request suspends the final deletion while the account is being verified as belonging to the applicant. Once the account is confirmed to belong to the applicant, the request is cancelled and access is restored, including access to the company's account space if it was blocked in connection with the request of its owner.
If the request is not cancelled, after 7 (seven) calendar days the account and the related data are deleted without the possibility of recovery. If the account of a company owner is deleted, the company's account space and its data are also deleted. Exceptions relating to payment, accounting, tax and other data that must be stored by law are set out below. This procedure applies to deletion initiated by the User; automatic deletion after the retention periods expire is governed by the separate rules set out below.
Data retention periods after access to the Service ends: if the User has never purchased a paid subscription — 2 (two) months from the end of the trial period; if the User has purchased a paid subscription — 2 (two) years from the end of the last paid period. After that period expires, the User's account and all data entered into it, including the data of the User's Clients, are deleted automatically without the possibility of recovery.
After the trial period or the last paid period ends, the Service notifies the User about the restriction of access, the period of temporary data storage and the scheduled deletion by displaying a message in the application and/or sending a message to the email address specified in the account. Before the relevant period expires, the User may purchase or renew a subscription; once the payment is confirmed, access to the previously stored data is restored.
The deletion of data from an account does not extend to payment, accounting, tax and other documents or information that the Administration is obliged to store in accordance with the law. Such data is stored only for the periods established by law and is used solely to fulfil the relevant legal obligations.
SECTION 4: TERMS OF ACCESS TO THE DATABASE
Within the scope of the relevant functions, access to personal data may be granted to cloud infrastructure providers, payment providers, messaging services and analytics platforms. Information about the payment and analytics services is set out in Section 11 of this Policy. Data is transferred, or access to it is granted, only to the extent necessary, for the defined purposes and on a proper legal basis. In the cases provided for by law, data may be disclosed to authorised state authorities.
To ensure the operation of the Service, the engaged providers process data in accordance with their role, the applicable contractual terms and the law. If the consent of the personal data subject is required for a specific transfer or processing, it is obtained before such processing begins.
In the event of loss or disclosure of personal data, the Service shall immediately inform the User.
The Service takes the necessary organizational and technical measures to protect personal information from unauthorized or accidental access, destruction, blocking, copying, distribution, and other unlawful actions of third parties.
SECTION 5: CHANGING USERS' PERSONAL INFORMATION
The user may at any time change (update, supplement, delete) the personal information provided by them or part thereof by sending a message to the email address posted on the Service at the following address: support@podocard.com.
SECTION 6: CHANGES TO THE PRIVACY POLICY
We reserve the right to change the terms of the privacy policy. In this case, we will replace the version of the document in the “Privacy Policy” section. Please review these terms periodically to stay informed about how the Service protects the personal data of its users.
If the User disagrees with any changes made to the Policy, they must stop using the Service and request that the Administration delete their Personal Data.
SECTION 7: LINKS TO OTHER SITES
The Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Please note that these external sites are not operated by us. Therefore, we strongly recommend that you review the privacy policies of these sites. We do not control and are not responsible for the content, privacy policies, or practices of any third-party sites or services.
SECTION 8: FEEDBACK
All suggestions or questions regarding this policy should be communicated to the Service Administration at the email address provided on the Service at the following address: support@podocard.com.
SECTION 9: USER RIGHTS TO PRIVACY (GDPR)
GDPR - is a European Union law that regulates how companies protect the data of EU residents and gives EU residents more control over their personal data.
The GDPR applies to any international company, not just companies based in the EU and EU residents. Our customers' data is important regardless of where they are located, which is why we have implemented GDPR compliance as a basic standard for all our operations worldwide.
Subject to certain conditions, you have the following rights:
request copies of their personal data;
request correction of information that Users believe to be inaccurate;
request supplementation of information that Users believe to be incomplete;
request deletion of personal information about Users at any time and will take reasonable steps to delete the User's personal information from our current records. If Users request the deletion of User personal information, we will inform Users how this deletion will affect the User's use of the Service or products and services. There may be exceptions to this right for specific legal reasons, which, if possible, will be explained to Users in response to the User's request;
request restriction of processing of the User's personal data if (i) Users are concerned about the accuracy of the User's personal data; (ii) Users believe that the User's personal data has been processed unlawfully; (iii) Users need to retain personal data solely for the purposes of legal proceedings; or (iv) in the process of considering the User's objection to processing based on legitimate interests;
object to the processing of the User's personal data based on Our legitimate interests or public interests. In this case, we are required to provide compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the User in order to continue processing the User's personal data;
request a copy of the personal information provided by the User; the format of such information must be structured, commonly used, and machine-readable.
We have 30 days to respond to you if you have submitted a request. To exercise any of these rights, please contact us with “GDPR Privacy Request” in the subject line.
SECTION 10: USER CLIENT CONSENT
The User is fully responsible for obtaining duly executed consent from its customers (the User's Customers) for the processing of their personal data, including photos, medical information, signatures, and other sensitive information entered into the Service.
The PodoCard Service does not directly collect the personal data of the User's Clients. All such information is entered into the Service by the User, solely for professional purposes. The Service provides the User with an informed consent template, which the User can use as an example for establishing the appropriate legal basis.
With regard to the personal data of the User's Clients, the User independently determines the purpose, composition and means of their processing and acts as the owner (controller) of such data. The Administration processes this data on behalf of and on the instructions of the User as the holder (processor), solely to the extent necessary to provide, support and protect the Service, unless otherwise required by law.
In the event of a request from a personal data subject regarding the processing, deletion, or modification of their data, the User is obliged to take the appropriate actions themselves or forward the request to the Administration.
SECTION 11: OTHER TERMS
The Service may use cookies, third-party SDKs (including but not limited to Google Analytics, Appsflyer, Firebase, etc.), as well as automatically collect technical information about Users (such as IP address, device type, browser, operating system, device ID, etc.). Information about the privacy policies of analytical pixels and third-party SDKs used by the Service will be provided further in this Policy.
The Service uses Meta Pixel to collect statistics and analytics that help improve the functionality and user experience of the Service. More details about Meta’s Privacy Policy can be found at: https://www.facebook.com/privacy/policy.
Subscriptions are paid for on the PodoCard website through the WayForPay payment service. The processing of data on payments previously made through other payment providers may continue to the extent and for the periods necessary for refunds, compliance with accounting and tax obligations and the resolution of disputes. The Service does not collect or store full payment card details of Users — payment data is processed by the respective payment provider in accordance with its privacy policy. After a successful payment, a payment confirmation with an invoice in PDF format is sent to the User's email address.
Within the partner (referral) programme, when a visitor follows a referral link in the form podocard.com/r/{code}, the Service records technical data about the visit (IP address, an anonymised browser (user-agent) hash, platform type, date and time of the visit) and stores a cookie named podocard_ref in the browser for up to 90 days (for the podocard.com domain and its subdomains). This data is used solely to attribute a subsequent registration to the referring partner; on Android devices, the Google Play Install Referrer mechanism may be used for the same purpose, and an installation (registration) may be matched with a recorded visit by IP address within 72 hours. The referring partner sees limited information about referred users in the application: the first name and the first letter of the last name of the account owner, the organisation identifier, the registration date and the subscription status; contact details of referred users are not shared with the partner.
In order to conclude and perform the contract on participation in the partner (referral) programme, the Administration may process the following data of the Partner: surname, first name and patronymic or business name, the status of an individual entrepreneur or legal entity, the taxpayer registration number or EDRPOU code, contact and payment details, the referral code, statistics on referred users, internal balance data, and information on the accrued and paid remuneration.
Such data is processed for the purposes of identifying the Partner, administering the partner programme, recording the results of the referral link, calculating, recording and paying remuneration, fulfilling tax and accounting obligations, and preventing abuse and fraud. The legal bases for the processing are the conclusion and performance of the contract with the Partner, compliance with the Administration's legal obligations, and its legitimate interest in the proper functioning and protection of the partner programme.
All information processed within the Service is provided by the User voluntarily solely for the purpose of using the customer accounting functionality within the scope of their professional activities.
The Administration of the Service reserves the right to implement additional data collection tools in the future, and Users will be notified by means of amendments to this Privacy Policy.
The User undertakes to periodically review the current version of this Privacy Policy.
DETAILS
Private Entrepreneur under the laws of Ukraine Serdiukova Anna
TIN 3117915209
Tel. +380731234011
E-mail: support@podocard.com


