Menu

Privacy Policy

Last updated 19 June 2026

Privacy Policy

Last updated 19 June 2026

Privacy Policy

Last updated 19 June 2026

General Provisions and Definitions

This website is operated by AMICUM PHARMA LLC, Ukrainian company registration number (EDRPOU) 40866700, a legal entity registered and operating under the laws of Ukraine (the "Company").

The Company respects the confidential (personal) information of every person who visits the Site or uses the services it provides. The Company is committed to protecting the confidentiality of personal data (any information, or set of information, relating to an identified or identifiable natural person), thereby creating and maintaining the most comfortable possible conditions for every user of the Site's services.

This Privacy and Personal Data Protection Policy (the "Policy") sets out how the Company processes personal data, the categories of personal data collected, the purposes of such processing, the Company's interactions with third parties, the security measures in place to protect personal data, the conditions of access to personal data, and contact details for users who wish to access, amend, restrict or delete their personal data, or raise any questions about our data protection practices. This Policy has been developed with regard to the requirements of Regulation (EU) 2016/679 (the "GDPR") and the Law of Ukraine "On Personal Data Protection" (the "Law").

Definition:

Controller (data owner) – AMICUM PHARMA LLC (the "Company"), which determines the purpose and means of processing personal data. Address and contact details of the Controller: 21 Vikentiya Khvoiky St, Kyiv, 04080, Ukraine. Where necessary, the Controller appoints a Data Protection Officer (DPO), whose contact details are also published.

Processor – a legal entity that processes personal data on behalf of, and under instruction from, the Controller. Where processors are engaged, this is set out in a contract in accordance with Article 28 GDPR.

Personal Data (PD) – any information relating to an identified or identifiable natural person. PD is collected voluntarily: directly from the data subject when ordering goods, registering, or subscribing to mailing lists, and (where permitted by law) from open or public sources. Before or during data collection, the Company informs the data subject of the purpose and conditions of processing (Article 12 of the Law).

Processing of personal data – any operation performed on data, including collection, storage, use, transfer, anonymisation, and similar actions. Processing is carried out on lawful grounds in accordance with the GDPR and the Law. In particular, "consent of the data subject" means a voluntary expression of will by an individual to the processing of their data (in written or other form).

Special (sensitive) data (racial, religious, health data, and similar) are not processed without separate, explicit consent and compliance with additional requirements (Article 9 GDPR).

Purpose and legal basis for processing

The company processes personal data for the following primary purposes:

Performance of contracts (purchase/sale of medicines, medical nutrition, related products): processing of buyers' PD is necessary for concluding and performing agreements (legal basis: Article 6(1)(b) GDPR, contract with the data subject).

Legal/administrative obligations: retention of payment and financial records for compliance purposes (tax, accounting, and similar). This processing is legally required (Article 6(1)(c) GDPR, Article 11(3) of the Law).

Legitimate interests: information security (preventing fraud and unauthorised access), website improvement, and analytics (the Company's legitimate interest in improving its services). This basis is provided for under Article 6(1)(f) GDPR; the Company carries out a careful balancing of interests and rights, including a Privacy Impact Assessment where necessary.

Marketing and communications: sending information about new products, promotions, and company news. For B2B clients (doctors, pharmacies), Article 6(1)(f) GDPR (legitimate interest) applies; for broader commercial mailings, Article 6(1)(a) GDPR (consent) applies. The data subject may unsubscribe or exercise the right to object at any time (Article 21 GDPR).

Other purposes: for example, responding to client enquiries, site registration, or participation in educational or medical initiatives, where relevant. Accordingly, under Article 6 GDPR and Article 11 of the Law, every processing activity relies on a clear legal basis: consent, contract, legal obligation, vital interests, or legitimate interest. The Company documents the purposes and legal bases for processing and informs data subjects of them before or during data collection.

Categories of personal data

Main categories of data subjects whose data is processed:

Identification and contact data: full name, date of birth, passport/other identity documents, registered/residential address, phone number, email.

Professional data: company name and details (for B2B relationships), job title, field of activity, and specialisation, where available and necessary for contract performance.

Financial data: bank details, payment history (only where necessary for sales and financial reporting).

Technical information: IP address, cookies, browser and device data (for site statistics and functionality).

Health data: the Company does not collect or process special category health data about users without separate consent. Where a data subject voluntarily provides health-related information (for example, as part of a survey or consultation), such processing is carried out in accordance with Article 9 GDPR, only where there is clear consent and a service-related purpose.

All processed data is strictly minimised: the Company only requests information that is necessary for the stated purposes (the "data minimisation" principle under Article 5(1)(c) GDPR).

Data retention period and storage location

Personal data is retained only for as long as necessary to achieve the purposes of processing, after which it is deleted or anonymised. For example, corporate clients' data is retained for the duration of the contract and for at least a further 3 years after the end of the relevant financial year (for tax reporting purposes).
Marketing data is deleted or anonymised 2 to 3 years after the last interaction, unless the data subject confirms continued interest.
Article 15 of the Law requires that storage cease once the relevant period has ended or upon the data subject's request. These retention periods may be further specified by the Company's internal policies, in line with applicable regulations.
Users' personal data is held in Ukraine. Personal data may be transferred to other countries for the purpose of providing services. For more information on data transfers, see the Data Transfer and International Transfer section below.

Data transfer and international transfer

Data may be transferred to third parties only in compliance with legal requirements. Potential recipients include contracted processors: IT platforms, hosting providers, email marketing services, website analytics providers, and accounting or legal firms. All such recipients are required to protect PD and process it solely on the Controller's instructions, under agreements compliant with Article 28 GDPR. No data is sold or transferred to any party for marketing purposes without explicit consent.

International transfers: where data is transferred outside Ukraine (for example, where a cloud service in another country is used), such transfer is carried out in compliance with the GDPR. We verify an "adequate level of protection" (e.g. a European Commission adequacy decision), rely on Standard Contractual Clauses (Article 46 GDPR), or use another permitted transfer mechanism. Under Ukrainian law, cross-border transfer is permitted only where data protection is ensured (Article 29 of the Law). This Policy identifies partner countries or provides information on the standardised contracts used. Data subjects are informed of transfers under international mechanisms, with relevant documentation available on request.

Rights of the data subject

Data subjects have the following rights (in accordance with Article 8 of the Law and Articles 15–22 GDPR):

Right of access: to obtain confirmation of whether their PD is being processed, a copy of the data, and information on the purpose, legal basis, categories, retention period, recipients, and the source of the data if not collected directly from them.

Right to rectification: to request correction of inaccuracies in their data.

Right to erasure ("right to be forgotten"): to have their data deleted where there is no lawful basis for processing, or where it is no longer necessary for the purposes for which it was collected.

Right to restriction of processing: to restrict processing where the accuracy of the data is contested or the purpose of processing is disputed (data is retained but not used)."

Right to data portability: to receive the data provided in a structured format and transfer it to another controller, where applicable.

Right to object: to object to the processing of their data for specific purposes, including marketing.

Right to withdraw consent: where processing is based on consent, it may be withdrawn at any time without giving a reason; the Controller must then stop future processing.

Right to lodge a complaint: to file a complaint with the national authority (the Ukrainian Parliament Commissioner for Human Rights) or with the courts in the event of a violation of their data protection rights.

To exercise these rights, a data subject may submit a request to the Controller orally or in writing (typically by email). The request should include information identifying the data subject (name and contact details), a description of the information requested, and the preferred method of response. The Company is required to respond within 30 calendar days, in accordance with the Law. If the request is refused, the Company will state its reasons.

Sample data subject request:

To the attention of the Controller, Amicum Pharma LLC (compliance@amicum.com.ua)
From: I. I. Ivanov, contact email: ivanov@__
Subject: Personal Data Access Request
I request information regarding my personal data processed by you: the purpose of processing, the legal basis, the categories of data, the recipients, the retention periods, and a copy of my data for the period from (date) to (date), in accordance with Articles 12–16 of Law No. 2297-VI.
Date, signature

(Upon responding, the Controller will provide further clarification and, where necessary, an access request form.)

Information Protection

The Company implements technical and organisational security measures to protect personal data against unauthorised access, loss, destruction or damage. These include:

  • Use of secure servers, with data encrypted in databases and over SSL/TLS communication channels.

  • Employee access to PD limited to what is necessary (the "least privilege" principle), with all staff undergoing security training.

  • Logging and monitoring systems — access and data change logs are maintained, and periodic audits are conducted.

  • Backup procedures for recovery in the event of a failure, and user authentication.

Agreements with processors include strict confidentiality and security requirements (Article 28 GDPR).

These measures comply with Article 24 of the Law and Article 32 GDPR, both of which require the implementation of "appropriate technical and organisational measures" proportionate to the level of risk."

Cookie Policy

Our website uses cookies and similar technologies (local storage, pixels) to operate its services, analyse traffic, and personalise content. We classify cookies as "strictly necessary", "functional", "analytical", and similar categories. Users can manage cookie settings through their browser, including blocking or deleting cookies. Continued use of the website constitutes consent to the use of cookies. For further details, see the separate Cookie Policy document.

Processing of children's data

This Policy is not intended for the collection of personal data from children (individuals under the age of 18). We do not knowingly collect or request information from individuals under 18 without the prior consent of a parent or guardian. If we become aware that a child's data has been collected without such consent, the Company will delete it immediately. Parents or guardians may request the deletion of a child's data from our systems by contacting the Controller at ccompliance@amicum.com.ua.

Contact person and contact details

The Controller of personal data is Amicum Pharma LLC.
Contact email: compliance@amicum.com.ua
For any questions regarding the processing of PD, you may contact the Data Protection Officer (DPO) at:
Email: compliance@amicum.com.ua
Address: 21 Vikentiya Khvoiky St, Kyiv, 04080, Ukraine

Data subjects also have the right to lodge a complaint regarding a violation of their rights with the Ukrainian Parliament Commissioner for Human Rights (the national data protection authority).

Changes to the Policy

This Policy may be reviewed and updated from time to time. The current version is marked with an update date and published on the website. In the event of material changes, we will notify registered users by email or other available means. Previous versions of the Policy are retained in the Company's reference archive and are available on request.

Automated solutions

The Company does not use decisions based solely on automated data processing, including profiling, that produce legal effects or otherwise significantly affect an individual. Should such processes be introduced in the future, data subjects will be informed in advance of the algorithms and decision-making criteria used, and will be guaranteed the right to request an explanation and human intervention. The GDPR prohibits such automated decision-making without a lawful basis (Article 22).

Processing for marketing and mailings

To communicate with clients, we:

Email newsletters (news, promotions, insights): sent on the basis of the data subject's consent (Article 6(a) GDPR). When registering for a newsletter or subscribing to updates, users are presented with a clear consent form; every message includes instructions for unsubscribing at any time.

Promotional communications (SMS, calls) to existing clients: based on the Company's legitimate interest (keeping clients informed of product/service updates) or on consent, depending on the channel. Under regulatory guidance, communications to existing clients may be considered part of an ongoing relationship (Article 6(f) GDPR); however, every recipient retains the right to opt out (Article 21 GDPR).

In all cases, we strictly adhere to the principle of transparency, stating the legal basis for processing and the data subject's rights in accordance with Articles 13–14 GDPR.

Subcontractors / processors

To operate its websites and services, the Company engages third-party contractors (processors), including:

Hosting and IT infrastructure providers.

  1. Analytics services (such as Google Analytics).

  2. Payment systems for order processing.

  3. Email marketing platforms.

  4. Contractors handling postal or contact data.

Data is transferred to such organisations only under contracts compliant with Article 28 GDPR. These contracts set out clear restrictions: data may only be processed on our instructions, employee confidentiality must be guaranteed, and technical security measures (encryption, backups, and similar) must be applied. All processors are subject to regular security audits. We will provide appropriate notice if subcontractors are engaged or providers change, obtaining additional consent where necessary.

Risks and mitigation

Potential risks in processing PD include database leaks or breaches, unauthorised employee access, careless data destruction, and unlawful disclosure. The consequences of these risks may include financial loss, reputational damage, and regulatory fines.

To mitigate these risks, the Company:

  • Regularly updates security systems (antivirus, operating systems) and conducts testing and audits.

  • Provides staff training on information security and confidentiality.

  • Uses encryption (SSL/TLS, database encryption) and anonymisation methods where possible.

  • Maintains backup and data recovery plans.

  • Reviews legal documents (processor agreements, policies) for compliance with applicable law.

  • Applies a Data Protection Impact Assessment (DPIA) for new high-risk projects, such as biostatistical research or applications involving health data.

These measures reflect the principle of Privacy by Design and the recommendations of Article 32 GDPR on risk assessment and the implementation of appropriate measures.

Ready to Work Together?

Get in touch, and let's discuss your product and possible ways of working together.

Ready to Work Together?

Get in touch, and let's discuss your product and possible ways of working together.

Ready to Work Together?

Get in touch, and let's discuss your product and possible ways of working together.

Create a free website with Framer, the website builder loved by startups, designers and agencies.