Privacy Policy
How UMFO collects, uses, and protects personal data. Version 2.0. Effective from [publication date].
Data controller
The controller of your personal data is [LEGAL ENTITY: full name, registration code, registered address], trading as UMFO — Ukrainian Multi-Family Office. All data-related requests go to hello@umfo.eu. Postal address: [LEGAL ENTITY: address]. Person responsible for data protection: [name or “UMFO team”], dpo@umfo.eu.
1. What data we collect
UMFO collects the minimum data required to operate the site and respond to enquiries.
- Contact data you submit through the contact form or by email: name, email, phone, a short description of your task.
- Technical data when you visit the site: IP address, browser type, operating system, pages viewed, time of visit. Stored as de-identified logs.
- Cookies: technical (required for site operation) and analytical (with your consent). Details in our Cookie Policy.
- Data you provide during the Diagnostic or ongoing engagement: information about the family, assets, jurisdictions, goals. Processing is governed by a separate confidentiality agreement with the client.
- Special categories of data (Article 9 GDPR): data concerning health, religion, community membership, political activity. Processed only in the context of a specific client task and only on the basis of your separate explicit consent or performance of a contract.
2. Why we process data
- To respond to your enquiry and hold an introductory conversation.
- To provide family-office services to clients under contract.
- To improve the site and understand what interests visitors (analytics, with consent).
- To meet UMFO’s compliance obligations (client identification — KYC, sanctions screening, fraud prevention).
3. Legal basis
We process your data on the following grounds (under the Law of Ukraine on the Protection of Personal Data and Regulation 2016/679 — GDPR):
- Informational enquiry via the contact form — on the basis of our legitimate interests in responding to enquiries (Article 6(1)(f) GDPR).
- Enquiry from a prospective client and pre-contractual steps — Article 6(1)(b) GDPR.
- Performance of a contract with a client — Article 6(1)(b) GDPR.
- Consent for analytical cookies, marketing communications, and processing of special-category data — Articles 6(1)(a) and 9(2)(a) GDPR. You may withdraw consent at any time.
- Legitimate interests of UMFO in the security of the site, fraud prevention, and compliance with sanctions rules — Article 6(1)(f) GDPR.
- Legal obligations under Ukrainian law — Article 6(1)(c) GDPR.
4. With whom we share data
Your data stays with UMFO. We share it with third parties only in three cases:
- Service providers that help us operate: site hosting ([provider]), email services ([provider]), analytics ([provider]). They act under data-processing agreements and do not use your data for their own purposes.
- External advisers (lawyers, tax advisers, bankers) — only with your separate written permission, in the scope required for the work.
- Government bodies, where required by Ukrainian law or the jurisdictions in which we operate.
UMFO does not sell your data and does not accept commissions from banks, asset managers, or insurers in return for referrals.
5. Retention
- Contact-form enquiries — 24 months from the last contact.
- Client data — for the duration of the engagement plus 7 years (to meet legal and tax obligations).
- Analytics data — in de-identified form, up to 26 months.
- Cookies — per your browser settings or the consent banner.
- Data of deceased individuals: processed within the limits and periods set by this policy, the client contract, and applicable law. The right to be forgotten, the right to portability, and other data subject rights are exercised by heirs or an authorised representative upon documented evidence of authority.
6. Your rights
Under GDPR and the Law of Ukraine on the Protection of Personal Data, you have the right to:
- access the data we process about you;
- have inaccurate or outdated data corrected;
- request erasure (right to be forgotten);
- restrict processing;
- receive your data in a structured format (portability);
- object to processing based on legitimate interests;
- withdraw consent to marketing, analytics, or special-category processing at any time;
- not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you (Article 22 GDPR);
- lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights (Ombudsman), another supervisory authority of Ukraine under applicable law, or the competent supervisory authority of an EU member state.
Send requests to hello@umfo.eu. We respond within one month (Article 12(3) GDPR).
7. Data security
UMFO uses technical and organisational measures: encrypted connections (HTTPS), access to client data restricted to authorised partners and team members on a need-to-know basis, regular backups, and confidentiality agreements with everyone who has access.
8. Transfers outside Ukraine and the EU
UMFO may store data on servers in EU countries. Transfers outside the EU/Ukraine are made on one of the bases provided by Chapter V of the GDPR: (i) European Commission adequacy decision; (ii) EU Standard Contractual Clauses under Decision 2021/914 (SCCs); (iii) in exceptional cases — with your explicit consent (Article 49(1)(a) GDPR). The list of countries to which transfers may be made and the applicable mechanism is available upon request at hello@umfo.eu.
9. Changes to this policy
We may update this policy. The current effective date appears at the top. We notify existing clients of material changes by email.
Contact
Questions about this policy or your data: hello@umfo.eu. Postal address: [LEGAL ENTITY: address].