Privacy Policy

Join.To.IT LLC

Website: https://jointoit.com

Effective date: December 12, 2019

Last updated: September 11, 2026

This document is a template drafted in line with the requirements of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Law of Ukraine "On Personal Data Protection". As the Company operates both in Ukraine and in the European Union, this Policy is designed to satisfy the requirements of both frameworks at once.

1. INTRODUCTION

At Join.To.IT LLC ("the Company", "we", "us", "our"), we know that trusting a company with your personal information isn't something you do lightly, and we don't take that trust for granted. This Privacy Policy is our attempt to explain, as plainly as a legal document allows, what data we collect when you visit https://jointoit.com or use our services (together, the "Site" or "Service"), why we collect it, what we do with it, and - just as importantly - what say you have in all of this. We'd rather you actually read this than skim past it, so we've tried to keep the legal scaffolding without burying the substance in it. If something here is unclear, or you just want to ask us directly rather than parse a policy document, our contact details are in Section 12 - we're happy to talk it through. By using the Site, you're telling us you've read and understood this Policy. If something in here doesn't sit right with you, we'd rather you not use the Site than use it uneasily. This Policy applies to everyone who visits the Site, wherever they're based. That said, some of what follows - particularly the rights described in Section 10 - is written with individuals in the European Union, the European Economic Area, and the United Kingdom (together, the "EEA") specifically in mind, since the GDPR applies directly to them. Because we also operate in Ukraine, this Policy is written to satisfy both frameworks at once: the GDPR for individuals connected to the EEA, and the Law of Ukraine "On Personal Data Protection" No. 2297-VI (along with the relevant provisions of the Civil Code of Ukraine, in particular on the use of a person's image) for individuals connected to Ukraine. Where the two frameworks differ, we apply whichever standard gives you stronger protection.

2. WHO'S RESPONSIBLE FOR YOUR DATA

The entity responsible for your personal data - the "data controller" in the language of Article 4(7) GDPR - is us: Join.To.IT LLC Address: 25014, Kropyvnytskyi, 174A Ruslana Slobodianiuka street Reg. number: 42795396 Privacy contact email: privacy@jointoit.com.

3. WHAT PERSONAL DATA WE ACTUALLY COLLECT

We try to only ask for what we genuinely need, and what we collect depends a lot on how you're connected to us - whether you're a client, someone we work with as a contractor or vendor, or a candidate applying for a role. Here's a breakdown.

3.1. If You're a Client

When you get in touch about our services, sign a contract with us, or work with our team day-to-day, we'll typically hold your name, job title, company name, and business contact details - your email and phone number. Depending on the engagement, this can extend to billing and invoicing information, details about the project itself, and a record of the conversations and support requests we've had along the way.

3.2. If You're a Vendor

When we bring on a contractor, freelancer, or vendor, we collect what's needed to actually run that relationship properly - the contact person's name, company details, tax identification number, experience, the banking or payment information required to process invoices, the terms we've agreed to, and correspondence about how the work is going.

3.3. If You're a Candidate

If you apply for a role with us, we'll receive whatever you choose to submit as part of that application - your CV or résumé, a cover letter, your contact details, employment history, education, and any references you've included. We may also keep notes from interviews. If we ask whether we can hold onto your application for future roles beyond the one you applied for, that's something we'll only do with your separate consent, and that consent is what lets us keep the data on file.

3.4. If You're a Member of Our Team

We also hold personal data about our employees and individuals engaged by us under gig contracts or other contractual arrangements. The personal data we process in connection with these relationships may include names, job titles or roles, work and personal contact details, date of birth and age, passport or other identification document details, individual tax identification number, residential or registered address, bank and payment details, employment or gig contract information, payroll and remuneration records, tax and accounting records, photo and other records that are reasonably necessary for administering the relevant relationship. The scope of personal data processed for individuals engaged under a gig contract may be substantially the same as for employees. The fact that an individual is engaged under a gig contract rather than an employment agreement does not, by itself, mean that we collect or process a materially different category of personal data. The specific information we require depends on the nature of the engagement and may include identification, contact, address, tax, payment, contractual, and other information necessary to establish and manage the relationship. We generally process this information because it is necessary to enter into and perform the relevant employment or gig contract, to administer the relationship, make and record payments, comply with applicable labour, tax, accounting and other legal obligations, or for other legitimate purposes permitted by applicable law. Accordingly, we do not generally rely on consent for processing personal data that is necessary for these purposes. Consent is not required merely because the individual is an employee or a gig contractor where another lawful basis for processing applies.

3.5. Data We Collect Just by You Being on the Site

Like most websites, ours picks up some information automatically the moment you visit - your IP address, the type of device and browser you're using, your operating system, which pages you looked at, how long you spent there, where you came from, and when you visited. Where it's enabled, we may also work out a rough geographic location from your IP address. This, along with cookies and similar technologies, is covered in more detail in Section 8.

3.6. What We Deliberately Don't Collect

We don't ask for, and don't want, what GDPR calls "special category" data - things like your racial or ethnic origin, political views, religious beliefs, health information, sexual orientation, or biometric and genetic data. If a form on the Site ever seems to be nudging you toward sharing something like that, please don't - it's not something we need.

4. WHY WE'RE ALLOWED TO PROCESS YOUR DATA

Under GDPR, we can't just process personal data because it's convenient - we need a proper legal basis for it, and it always falls into one of these: Consent (Art. 6(1)(a)) - optional cookies, information you choose to submit through a form Performance of a contract (Art. 6(1)(b)) - Delivering a service, managing a client or contractor engagement, meeting our contractual obligations Legal obligation (Art. 6(1)(c)) - Keeping accounting and tax records, responding to lawful requests from public authorities Legitimate interests (Art. 6(1)(f)) - Keeping the Site secure, preventing fraud and abuse, understanding how the Service is used, marketing to existing clients within reasonable limits Whenever we lean on "legitimate interests" as our basis, we genuinely weigh that against your rights and freedoms first - if the balance doesn't tip in our favour, we don't use it. And if you've given us consent for something, you can take it back whenever you like. That won't undo the legality of anything we did with your data before you withdrew it (Article 7(3) GDPR), but it will stop us going forward. The Law of Ukraine "On Personal Data Protection" works on broadly similar logic: processing needs to rest on the data subject's consent, on the performance of a contract to which they're a party, on a legal obligation placed on us, or on another basis set out in Article 11 of that Law. Wherever this Policy refers to a legal basis under GDPR, the equivalent basis under Ukrainian law applies to individuals connected to Ukraine.

5. WHAT WE ACTUALLY DO WITH YOUR DATA

In plain terms, we use the data described above to run and maintain the Site and our services, to handle the enquiries, applications, and requests people send us, to put together and honour contracts with clients and contractors, and - where you've said it's okay, or we have a solid legitimate interest - to send you information or marketing that might be relevant to you, always with an easy way to opt out. We also use data to understand how the Site is used so we can make it better, to keep our systems secure and catch fraud or misuse early, to stay on the right side of legal and regulatory obligations like accounting and tax rules, and, if it ever comes to it, to establish or defend a legal claim. We won't quietly repurpose your data for something unrelated to why we collected it in the first place without asking you first - that's the purpose limitation principle in Article 5(1)(b) GDPR, and it's one we take seriously.

6. WHO ELSE GETS TO SEE IT

We don't sell your data, and we don't hand it to third parties so they can market to you off the back of it, unless you've explicitly said that's fine. Depending on what we're doing with your data, we may share it with the following categories of recipients, each bound by contract to only use it as we've instructed and to protect it to a standard that meets GDPR's requirements: ● Hosting and IT infrastructure providers - to keep the Site and our systems running. ● Payment and invoicing processors - to handle billing for clients and payments to contractors and vendors. ● Communication and collaboration tools (e.g., email, messaging) - to correspond with you. ● Analytics providers - to understand how the Site is used, where you've consented to this. ● Professional advisors - lawyers, accountants, auditors, where their input is genuinely needed. ● Payroll, tax, and accounting service providers - for staff and gig-contractor data specifically. There are also situations where we might have to disclose data even without that kind of arrangement in place - if the law requires it, if a court or a competent authority makes a valid, lawful request, if it's genuinely necessary to protect the rights, property, or safety of the Company, our users, or someone else, or if the Company is ever merged, acquired, or sells off assets - in which case we'd let you know if the entity responsible for your data changes.

7. WHEN YOUR DATA LEAVES THE EEA

Sometimes personal data needs to travel outside the EEA - say, to a country the European Commission hasn't formally recognised as offering an adequate level of data protection. When that happens, we don't just let the data go unprotected; we put safeguards in place under Chapter V GDPR, whether that's the European Commission's Standard Contractual Clauses, relying on an applicable adequacy decision, or another mechanism recognised under Article 46. For transfers falling under Ukrainian law, Article 29 of the Law of Ukraine "On Personal Data Protection" requires that data only be sent to a country that ensures adequate protection of data subjects' rights. Where we're not relying on a recognised adequacy finding, we rely on your consent as the basis for the transfer.

8. COOKIES AND THE LIKE

We use cookies and similar technologies for a few different reasons, and we've grouped them by purpose so it's clear what you're agreeing to: ● Strictly necessary cookies - these keep the Site working properly (e.g., remembering your session, keeping the connection secure). They don't require your consent because the Site can't function without them. ● Analytics cookies - these help us understand how people use the Site, so we can improve it. We only set these with your consent. ● Marketing cookies - these are used to tailor content or offers to your interests. We only set these with your consent, and only if you're an existing client or someone who's opted in. When you first visit the Site, you'll see a cookie banner where you can accept, reject, or customise which non-essential cookies you allow. You can change your mind at any time - either through that same settings panel or through your browser's own cookie controls. We don't currently maintain a separate, more detailed Cookie Policy listing every individual cookie and its exact retention period, but we're happy to provide that information on request via privacy@jointoit.com.

9. HOW LONG WE HOLD ON TO DATA

We don't keep personal data forever - only for as long as it actually serves the purpose we collected it for, or for as long as the law requires. How long that is depends on what kind of data we're talking about; the list below gives you a realistic starting point, though it's worth confirming these against what actually happens in practice. Client account and engagement data - For as long as the relationship lasts, plus 3 years. Contractor and vendor data - For the length of the engagement, plus 3 years. Candidate data (applications that didn't lead anywhere) - 12 months. Accounting and tax records - Whatever applicable law requires. Contact form and support enquiries - 24 months after things are resolved. Analytics and cookie data - 24 months. Staff employment records - For the duration of employment, plus 3 years. Staff photographs used on the Site - Until the employee withdraws consent or leaves the Company, whichever comes first. Anything processed on the basis of consent - Until you withdraw that consent. Once we've held onto something past the point it's actually needed, we delete it or anonymise it so it can no longer be traced back to you.

10. WHAT YOU CAN ASK OF US

GDPR gives you a real set of rights over your own data, and we want you to actually know what they are, not just have them buried in legal text. You can ask to see what we hold on you (the right of access, Article 15), and ask us to fix it if it's wrong (right to rectification, Article 16). You can ask us to delete it altogether - sometimes called the right to be forgotten - under Article 17, where the conditions for that are met, or ask us to just pause processing it for a while (right to restrict processing, Article 18). If you want your data to move somewhere else, you can ask for it in a structured, machine-readable format under the right to data portability (Article 20). You can also object to processing that's based on our legitimate interests, including any profiling, and you can object to direct marketing at any time, no explanation required (Article 21). If a decision about you is ever made entirely by an automated system in a way that has real legal or similarly significant effects on you, you have the right not to be subject to that without human involvement (Article 22) - though in practice, we don't currently use any form of automated decision-making that would trigger this right; we mention it here so you know it's available if that ever changes. And wherever we're relying on your consent, you can withdraw it whenever you like, with no effect on anything we did while it was still in place. To use any of these, just reach out using the contact details in Section 12. We aim to get back to you without unnecessary delay, and no later than a month after we receive your request. If it's a complicated one, or we're dealing with a lot of requests at once, we might need up to two more months - but we'll tell you that's happening and why. We may ask you to confirm who you are before we act on a request. That's not us being difficult; it's to make sure nobody else can access your data by pretending to be you.

11. HOW WE KEEP DATA SAFE

We take reasonable, genuine steps to protect your data, in line with what Article 32 GDPR expects - measures that match the actual risk involved. In practice, that means encrypting data in transit with TLS/SSL, limiting who on our team can access personal data to those who actually need it, regularly checking that our security measures still hold up, keeping backups so data isn't lost, and making sure our people understand how to handle personal data responsibly. If something does go wrong and a breach is likely to put people's rights or freedoms at real risk, we'll notify the relevant supervisory authority within 72 hours of finding out, as required by Article 33 GDPR, and let affected individuals know without undue delay where Article 34 requires it.

12. GET IN TOUCH

Questions about this Policy, about how we handle your data, or want to exercise one of the rights above? We'd genuinely rather you ask than wonder. Join.To.IT LLC Email: privacy@jointoit.com Address: 25014, Kropyvnytskyi, 174A Ruslana Slobodianiuka street

13. IF YOU'RE UNDER 16

The Site isn't built for, and isn't meant to be used by, anyone under 16 (or whatever slightly younger age, between 13 and 16, their own EEA country has set under Article 8 GDPR). We don't knowingly collect data from children. If you're a parent or guardian and think your child has given us information without your say-so, please reach out and we'll take it down.

14. LINKS TO OTHER SITES

You might come across links on our Site that take you elsewhere. We don't run those sites, and once you've clicked through, their rules apply - not ours. We'd encourage you to check their privacy policies before handing over any information.

15. IF THIS POLICY CHANGES

We may need to update this Policy now and then. Whatever's live on this page is the current version, and we'll always date it so you can tell when it last changed. If a change is significant enough to actually affect how your data is processed, we'll let you know ahead of time - by email, or a notice on the Site - before it takes effect, wherever the law requires that.

16. GOVERNING LAW

This Policy has been written to work under two frameworks at once. For individuals connected to the EEA, it's built around the GDPR. For individuals connected to Ukraine, it's built around the Law of Ukraine "On Personal Data Protection" and, where a person's image is involved, Articles 307-308 of the Civil Code of Ukraine. Where these two frameworks would otherwise point in different directions, we follow whichever one protects you more. Anything this Policy doesn't cover falls under the laws of Ukraine.