Privacy Policy and Consent to Personal Data Processing

for attorney Anna Bondarenko (Ukraine/EU/Spain)

1. General Provisions

1.1. This Policy regulates the processing of clients' personal data in accordance with:

● GDPR (EU Regulation 2016/679);● Spanish Law 3/2018 (LOPDGDD);● Law of Ukraine №2297-VI "On Personal Data Protection";● Law of Ukraine "On Advocacy and Advocacy Activities".

1.2. The Attorney acts as a data controller for clients from the EU/Spain and a data owner for clients from Ukraine.

2. Principles of Data Processing

Data processing is carried out on the basis of:

● Consent (for marketing communications);● Contract performance (provision of legal services);● Legitimate interests (protection of rights in court)

3. Categories of Processed Data

Data Type

Contact data (name, email, phone)

Documents (passport, contracts)

Special categories* (criminal records, medical data)

Processing Purpose

Communication, contract conclusion

Transaction legalization, court proceedings

Protection of client interests in court

Legal Basis

Contract performance[1][3][5]

Legitimate interests[2][7]

Consent + GDPR exceptions (Art. 9.2.f)[3][11]

*Processing of special categories of data is possible only with the client's explicit consent.

4. International Data Transfer

4.1. Data of clients from Ukraine may be transferred to the EU on the basis of:

● EU adequacy decision (Ukraine, 2025);● Standard Contractual Clauses (SCCs).

4.2. Data of clients from the EU/Spain is stored on servers in Germany (GDPR-compliant hosting).

5. Data Storage Periods

Personal data of clients — 5 years after the end of cooperation

Court documents — 10 years (statute of limitations)

Financial transactions 7 years (tax law requirements)

6. Client Rights (GDPR + Ukrainian legislation)

Clients have the right:

● To access their data (Art. 15 GDPR, Art. 8 of the Law of Ukraine);● To correct/delete data (Art. 16-17 GDPR);● To restrict processing (Art. 18 GDPR);● To data portability (Art. 20 GDPR);● To withdraw consent at any time.

To exercise rights:

● EU/Spain clients: contact the DPO (moc.lagel-anna%40opd);● Ukrainian clients: send a request to the attorney's email.

7. Security Measures

● Data encryption (TLS 1.3 for online communications);● Two-factor authentication for database access;● Regular audits for compliance with ISO 27001 and GDPR.

Consent to Personal Data Processing (Consent Form)

I, [Client's full name], confirm:

1. Consent to the processing of my personal data, including:

● Contact data;● Documents necessary for the provision of legal services;● Special categories of data (if marked ✔️: ______).

2. Processing purposes:

● Provision of legal services;● Performance of the offer agreement;● Information about changes in legislation (if consent to mailing ✔️: ______).

3. Data transfer to third parties:

● Notaries, translators, IT providers — only for the purposes of contract performance.

4. International transfers:

● Data may be transferred to the EU/Ukraine in compliance with GDPR and Ukrainian legislation requirements.

Right to withdraw consent:

Consent can be withdrawn through:

Email: moc.elpmaxe%40lagel.annaTelegram: @anna_bondarenko_legal

Notes:

● For clients from the EU, the form is available in Ukrainian, Spanish and English languages.● Consent is integrated into the application process on the website (checkbox + electronic signature).● Separate consent is required for processing data of minors and incapacitated persons.