At Consolline (hereinafter – the Company), we strive to ensure the confidentiality and security of Your personal data. This Privacy Policy (hereinafter – the “Policy”) sets out the procedure for the collection, use, storage and other processing of Your personal data, and establishes the principles by which the Company is guided when using such information.
Please read this Privacy Policy carefully before providing any personal data to Consolline, so that You understand how Your personal data may be processed. If You do not agree with this Policy, please do not use this Website.
We reserve the right to amend this Policy at any time. To stay up to date with the information contained herein, we recommend that You review this Policy regularly in order to be aware of any changes and of the updated procedure for the use of the information You have provided.
1. Processing of personal data
1.1. Types of personal data
We use cookies on our website and may process Your personal data.
Cookies are text files or fragments of data that a website sends to the user’s browser and stores on the user’s device. Such a device may be a computer, laptop, mobile phone, tablet or any other device through which the user accesses the Website.
Cookies enable the Website to recognise the user’s device, store certain settings and ensure the proper operation of some of its functions. Depending on their purpose, cookies may be used to save the selected language, display settings and login details, to analyse traffic and to improve the performance of the Website.
Depending on their purpose, cookies may be necessary, analytical or marketing cookies that support the operation of the Website.
By continuing to use the Website, You consent to the use of cookies in accordance with their purpose and the settings available on the Website. Information on the use of cookies may be updated in connection with changes to the Website’s functionality, the technologies applied or legal requirements.
When You visit our website, Consolline may collect the following personal data (including information that the user enters into the form themselves):
- Name
- Phone number
- Company name
- Job title
- Country or region
- Message text
- Consent to the Policy checkbox (the fact, date and time of consent are stored)
- Consent to receive newsletters checkbox (not ticked by default)
We use cookies to collect the personal data listed above. This list may change in accordance with the Company’s requirements and applicable law.
The following technical data is also collected automatically:
- IP address
- Browser, browser version, operating system
- Device type and screen resolution
- Language of the browser and of the Website
- Referral source (previous page)
- Page address, date, time and duration of the visit
- Approximate location based on IP address
Visitor identifiers are collected during visits to the Website. Pseudonymised identifiers that make it possible to recognise a user on repeat visits may be regarded as personal data even in the absence of information about the user’s name, namely:
- Google Analytics identifier (cookie
_ga) - The Website’s own visitor and session identifier generated by the Website
- Google Ads identifiers (
_gcl_au,gclidin the link) - Meta identifiers (
_fbp,_fbc,fbclidin the link) - LinkedIn identifiers
- Session recording service identifier
While the Website is being used, information about the user’s actions may be collected, in particular about the pages viewed and the sequence in which they were viewed, the time spent on individual pages and on the Website as a whole, the scroll depth of pages viewed, clicks on buttons and other interactive elements, interactions with forms (starting to fill in, errors and submission), as well as clicks on or taps of phone numbers, e-mail addresses, and links to messengers and social networks. The user’s interaction with the Website may be recorded and analysed, including cursor movements, taps and clicks.
The Website collects information about the source through which the user arrived at the Website. Typically, these are UTM tags in the link, as well as identifiers. These include advertisements, campaigns, etc. The “Request and advertising campaign” data is stored directly in the request record.
If an online chat widget is created and used, the Company reserves the right to collect and analyse the data entered by the user. This also applies to the e-mail address used for newsletters, subscription status, e-mail opens and clicks within e-mails.
1.2. Retention period of personal data provided
Cookies are stored in the web browser on the user’s device and may be used to identify the browser, ensure the operation of the Website, analyse its use and for other purposes defined in this Policy. Personal data is stored for no longer than is necessary for the purpose of its processing.
Consent_state – set and used by the Website itself. This cookie is used to store the user’s choice in the consent banner. The approximate retention period of this cookie is 6 to 12 months.
Website session cookies – set by the Website itself. Necessary to maintain the user’s technical session while the user is on the Website. As a rule, deleted once the user closes the web browser.
Csrf_token – used to protect forms and set by the Website itself. Approximate retention period: until the user closes the web browser.
_ga, _ga_<ID> – set by Google and used for Google Analytics. The approximate retention period is up to 2 years.
_gcl_au – set by Google to track conversions related to Google Ads advertising campaigns. The approximate retention period is up to 90 days.
_fbp and _fbc – set by Meta. These cookies may be used to recognise the browser for Meta. The approximate retention period of these cookies is up to 90 days.
_clck and _clsk – set by Microsoft for the operation of Clarity. The approximate retention period of _clck is up to 1 year, whereas _clsk is used mainly for the duration of the relevant session.
Cookie LinkedIn – set by LinkedIn, in particular for remarketing purposes. The approximate retention period of these cookies may be up to 12 months.
Anti-spam Cookies – set by Google. Such cookies may be used for an identifier and an event buffer. These cookies are stored until the browser is cleared.
It is also important to note that the Website reserves the right to use localStorage and sessionStorage, which are not, strictly speaking, cookies; however, by visiting the Website, You consent to the processing of Your data by these built-in objects.
The Company reserves the right to store information on requests submitted via the Website, as well as contact details, in its CRM. The approximate retention period for such information is three years from the date of the last changes made.
User actions are stored in the Company’s own database for 14 months; upon expiry of this period, the information is stored only in anonymised numerical form for final analytics, without any identifiers and without the possibility of identifying users.
Aggregated metrics in the dashboard are stored indefinitely, as they contain no information about specific users and do not allow them to be identified.
Information obtained from Google Analytics is stored for 14 months, which corresponds to the maximum data retention period available in the service.
Session recordings are stored for 30 days, as this period is sufficient to carry out the necessary analysis.
Server logs are stored for 30 to 90 days, depending on their purpose, in particular to ensure security and to analyse technical failures.
The record of consent having been given is stored for the period during which the consent is valid and for an additional 1–3 years after its withdrawal, in order to confirm the fact and validity of the consent given.
The retention period of chat correspondence depends on the terms and functionality of the relevant service.
The retention periods specified above are approximate and may vary depending on the specific configuration of the website and its technical changes.
1.3. Data storage
Data used when visiting the Website, information provided when submitting (or potentially creating) a request, as well as backup copies, are stored on servers in the EU.
Employees, as well as authorised third parties whom the Company may engage to fulfil its obligations, have access to information about the client and the client’s requests, and may also view the data remotely.
Multinational corporations such as Google, Meta, LinkedIn and Microsoft usually conclude agreements on privacy policy and the processing of personal information with their Irish companies; however, their parent companies in the USA also have access to the data.
Data contained in the CRM, the chat and the newsletter service is also stored.
The Company reserves the right to choose a behavioural analytics and website usability research platform that helps to understand how users interact with web pages.
1.4. Purpose of processing
Your personal data may be processed for the following purposes:
- ensuring the accessibility of the website and its functionality, in particular enabling the website to remember your settings and to improve its performance and the user experience;
- ensuring the security and proper functioning of the website;
- promoting our services and providing you with information about our products and services, provided that you have consented to the use of the relevant cookies;
2. Recipients of personal data and use of personal data by third parties
Personal data that You provide through feedback forms, order forms, service request forms or other forms on our website may be transferred to and processed by means of a CRM system that we use to register, store and manage enquiries from clients, prospective clients and other users, as well as to organise further communication and the provision of services.
To ensure the operation of the CRM system, we may engage a third-party provider of the relevant software and IT services as a personal data processor.
The personal data transferred to the CRM system may include, in particular, the following personal data that you voluntarily provide when completing the relevant forms: first name, surname, phone number, e-mail address, information about the request or order, as well as other information contained in your enquiry.
After the information contained in the request has been processed, this data (manager’s comments, outcome of the conversation, deal amount and status) may be entered into the CRM system, to which certain employees of the Company have access.
Where necessary for the provision of our services, we may transfer your personal data to third parties involved in organising and performing transport and logistics services. Such third parties may include carriers, freight forwarders, logistics partners, agents, subcontractors and other service providers involved in the transportation, handling, delivery or tracking of cargo.
The Company reserves the right to vet counterparties for the purpose of proper legal and reputational assessment.
To ensure the functioning, availability, performance and security of our website, we may use the services of third-party hosting and CDN providers. In the course of providing such services, the relevant providers may process personal data transmitted through the website or automatically generated during its use, in particular the IP address, technical identifiers, device and browser information, network connection data, the date and time of access to the website, as well as other technical data necessary to ensure the proper functioning, performance and security of the website.
2.1. Website server and database
To ensure the functioning of the website and the processing of user enquiries received through the forms on the website, the website’s server and database are used. The website is hosted within the European Union; the specific hosting provider will be determined by the Company separately. During the operation of the website, the IP address, browser information, page address, time and all form data may be processed. The processing of the said data is carried out for the purpose of ensuring the proper functioning of the website and storing user enquiries and requests.
Processing category: strictly necessary.
2.2. First-party event collection
The website may use a proprietary event collection system that runs on the Company’s own server without transferring data to third parties. The system may process the visitor identifier, information about the user’s actions on the website, UTM tags and other technical information. The processing is carried out for the purpose of generating internal analytics and assessing the performance of the website via the admin panel.
Processing category: analytical.
2.3. Google Analytics 4
The Google Analytics 4 service, provided by Google Ireland Limited, may be used to analyse the use of the website.
In the course of using the service, the visitor identifier, IP address, information about the user’s actions on the website and technical data may be processed. The purpose of the processing is web analytics.
Processing category: analytical.
2.4. Google Tag Manager
Google Tag Manager, provided by Google Ireland Limited, may be used.
During the loading and operation of tags, the IP address may be processed to ensure the proper functioning of the relevant tags. This service is used to manage the website’s tags.
Processing category: technical.
2.5. Google Ads
Google Ads, provided by Google Ireland Limited, may be used to measure the effectiveness of advertising campaigns and to carry out remarketing.
Within the operation of the service, the identifier of a click-through on an advertisement, information on whether a conversion has taken place and the address of the web page on which the relevant action occurred may be processed.
The processing is carried out for the purpose of measuring the performance of advertising campaigns, attributing conversions and building remarketing audiences.
Processing category: marketing.
2.6. Meta Pixel and Conversions API
Meta Pixel and the Conversions API, provided by Meta Platforms Ireland Limited, may be used to measure advertising effectiveness, build advertising audiences and carry out remarketing.
When using these tools, browser identifiers, the IP address, information about the user’s actions on the website, as well as certain contact details, in particular e-mail address and phone number in hashed form, may be processed if such data is transmitted via the Conversions API.
The processing is carried out for the purpose of measuring the performance of advertising campaigns, tracking conversions and carrying out remarketing.
Processing category: marketing.
2.7. LinkedIn Insight Tag
The LinkedIn Insight Tag, provided by LinkedIn Ireland Unlimited Company, may be used to analyse advertising activity and to carry out remarketing.
The service may process the visitor identifier, IP address, the address of the web page visited and the information required to match the website visit with the relevant LinkedIn profile.
The processing is carried out for the purpose of analysing the effectiveness of advertising campaigns and building remarketing audiences.
Processing category: marketing.
2.8. Clarity or Hotjar
Microsoft Clarity or Hotjar may be used to analyse user behaviour on web pages. The provider of the relevant service may be Microsoft Ireland Operations Limited or Hotjar Ltd (Malta), depending on the tool actually selected.
Depending on the service settings, information about the user’s interaction with the page may be collected and processed, in particular session recordings, clicks, cursor movements, page scrolling and other information about user behaviour.
The purpose of such processing is to analyse the usability of the website, identify technical or navigation issues and improve the structure and functionality of web pages.
Processing category: analytical.
2.9. Online chat widget
A third-party online chat service may be used to enable prompt communication between users and representatives of the website operator. The name and provider of the relevant service shall be determined separately.
When using the online chat, the content of the correspondence, IP address, technical visitor identifier, as well as contact and other data that the user voluntarily provides during the conversation, may be processed.
The processing is carried out for the purpose of providing online consultations, responding to user enquiries and ensuring communication with the website operator.
Processing category: functional.
2.10. E-mail newsletter service
A third-party e-mail marketing service may be used to organise and send e-mail newsletters. The name and provider of the relevant service shall be determined separately.
When using such a service, the e-mail address, the user’s name, subscription status, as well as information on e-mail opens and link clicks, may be processed.
The processing is carried out for the purpose of sending informational and/or marketing communications, as well as analysing the effectiveness of the relevant newsletters.
Processing category: marketing.
2.11. CRM system
A third-party CRM system may be used to record, organise and process user enquiries, as well as to organise the sales process. The name and provider of the relevant system shall be determined separately.
The data specified by the user in the request, UTM tags, information on the processing status of the enquiry, information on concluded deals and their value, as well as other information necessary for the proper handling of requests, may be transferred to and stored in the CRM system.
The processing is carried out for the purpose of recording enquiries, organising interaction with prospective and existing clients, and managing sales processes.
Processing category: processing outside the website.
2.12. Anti-spam form protection
Google Ireland Limited or another similar provider may be used to protect the website and its forms against automated requests, bots, spam and other abuse.
During the operation of such a service, the IP address, information about the user’s behaviour on the page, cookies and other technical parameters necessary to determine whether a request is automated may be processed.
The processing is carried out solely for the purpose of ensuring the security of the website and preventing abuse of its functionality.
Processing category: strictly necessary.
2.13. CDN and attack protection
A CDN and/or web infrastructure protection service, in particular Cloudflare or a similar provider, may be used to ensure proper website loading speed, stable operation and protection against network attacks. The specific provider shall be determined separately.
Within the operation of such a service, the user’s IP address, HTTP request headers and other technical information necessary for request routing, content caching, threat detection and ensuring website security may be processed.
The processing is carried out for the purpose of improving the speed and stability of the website, as well as preventing unauthorised access, attacks and other information security threats.
Processing category: strictly necessary.
2.14. Messenger buttons and links
The website may contain buttons or links leading to third-party messaging services, in particular Telegram, WhatsApp and Viber.
When the relevant button is clicked, the user leaves the website or is redirected to a third-party application or service. The website operator does not receive or control the data that the user independently provides to the relevant third-party service after being redirected, unless such data is transmitted to the operator by other means.
Further processing of personal data within the relevant third-party service is carried out in accordance with that service’s own rules and privacy policy.
The purpose of using such buttons and links is to provide the user with an additional communication channel.
Processing category: redirection to a third-party service.
3. Terms of use of the website
We use cookies and process personal data on the basis of Your explicit consent, which you give via the cookie banner settings, as well as on the basis of legitimate interests or the performance of a contract, where applicable. You may withdraw your consent at any time in the cookie settings.
If the User does not agree (in whole or in part) with the terms of the Rules, please do not use the Website.
Information (including various articles and other text materials), photographs, as well as case studies that the Company has decided to publish on the Website, belong to the Owner of the Website.
Unlawful use and distribution of such data is prohibited.
The Company reserves the right, in the event that information becomes irrelevant or outdated, to change, edit and delete materials posted on the Website without prior notice to the user.
4. Website operator details (Legal notice / Impressum)
The legal entity of the “CONSOLLINE” group that controls the use of personal data and is responsible for the processing, storage and deletion of Users’ personal data is the Ukrainian operator. The owner of the consolline.com domain is the Director of LLC CONSOLLINE UKRAINE (EDRPOU Code 44703904), Gusak Olga Anatoliivna. Registered address: Ukraine, 03150, Kyiv, Antonovycha Street, Building 103, Office 1.
Since this company is international and visitors to the Website may include citizens and residents of the Member States of the European Union and of other jurisdictions, personal data may be processed in accordance with the requirements of the data protection legislation applicable to such processing, in particular EU legislation and the legislation of other relevant jurisdictions. CONSOLLINE complies with all international standards and the requirements of the EU General Data Protection Regulation (GDPR), in particular the provisions of the GDPR, since the protection of natural persons in relation to the processing of personal data is a fundamental right. Article 8 of the Charter of Fundamental Rights of the European Union (the “Charter”) and Article 16 of the Treaty on the Functioning of the European Union (TFEU) provide that everyone has the right to the protection of personal data concerning him or her.
The principles of, and rules on, the protection of natural persons with regard to the processing of their personal data should, whatever their nationality or residence, respect their fundamental rights and freedoms, in particular their right to the protection of personal data. This Regulation is intended to contribute to the accomplishment of an area of freedom, security and justice and of an economic union, to economic and social progress, to the strengthening and the convergence of the economies within the internal market, and to the well-being of natural persons.
Directive 95/46/EC of the European Parliament and of the Council seeks to harmonise the protection of fundamental rights and freedoms of natural persons in respect of processing activities and to ensure the free flow of personal data between Member States.
Guided by the translation of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), published on the Official Web Portal of the Verkhovna Rada of Ukraine, CONSOLLINE, pursuant to Article 16 “Right to rectification”, shall ensure the right of the data subject to obtain the rectification of inaccurate personal data concerning him or her, which the controller shall carry out without undue delay. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
Pursuant to Article 15 “Right of access by the data subject”, the data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, if that is not the case, access to the personal data and information on:
- b. the categories of personal data concerned;
- c. the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
- d. where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
- e. the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
- f. the right to lodge a complaint with a supervisory authority;
- g. where the personal data are not collected from the data subject, any available information as to their source.
Pursuant to Article 17 “Right to erasure (‘right to be forgotten’)”, the data subject shall have the right to obtain the erasure of personal data concerning him or her, which the controller shall carry out without undue delay, and the controller shall have the obligation to erase personal data without undue delay where one of the established grounds applies.
Pursuant to Article 18 “Right to restriction of processing”, the data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:
- (a) the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;
- (b) the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
- (c) the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
- (d) the data subject has objected to processing pursuant to Article 21(1) pending the verification whether the legitimate grounds of the controller override those of the data subject.
Where processing has been restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
A data subject who has obtained restriction of processing pursuant to paragraph 1 shall be informed by the controller before the restriction of processing is lifted.
Pursuant to Article 19 “Notification obligation regarding rectification or erasure of personal data or restriction of processing”, the controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves incompatible consequences. The controller shall inform the data subject about those recipients if the data subject requests it.
In the event of a transfer of personal data to third countries, the Company ensures an adequate level of protection by concluding Standard Contractual Clauses (SCCs) approved by the European Commission, or by cooperating with providers certified under the EU-U.S. Data Privacy Framework.
Pursuant to Article 21 “Right to object”, the data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her, including profiling. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object to such processing of personal data, including profiling to the extent that it is related to such direct marketing.
Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
CONSOLLINE ensures the proper implementation of and compliance with all articles and provisions of the GDPR (including those not mentioned in this Policy), and ensures Users’ rights to erasure, restriction of processing and other guaranteed rights upon submission of a relevant request to the official e-mail address. This e-mail address is active and guarantees a response to the user’s request within the shortest possible time: [email protected]