Dasy Privacy Policy
Rules for Processing and Storing Personal Data
Version 1.0 · effective 24.08.2026This Policy explains how the Dasy online platform, accessible at dasy.com.ua (hereinafter “Dasy”, the “Platform”), collects, uses, stores, transfers, and protects the personal data of users, representatives of organizations, specialists (masters), and individuals for whom a specialist creates a booking.
1.1. Data Controller
The personal data controller is Serhii Volodymyrovych Kurinnyi, Ukraine.
- Email: serkurinniy@gmail.com
- Telegram for inquiries: https://t.me/DasyReservation
- Website: https://dasy.com.ua
1.2. What Is Dasy
Dasy is an online information platform for searching for organizations, specialists, and services, viewing available time slots, and creating bookings. Dasy does not provide the services published by organizations and is not a party to settlements between the client and the organization.
1.3. What Data We Process
- Account Data: Name, email, phone number; surname and gender if specified by the user.
- Profile Picture (Avatar): If the user chooses to add or change a profile picture, Dasy may receive the photo from the device camera or photo library.
- Settings: Country, city, time zone, interface language, and user role.
- Usage Data: Favorites, booking history, reviews, complaints, and support inquiries.
- Authorization Data: Technical access and refresh tokens, information required for signing in via email/OTP or a Google account.
- Organization Data: Name, description, address, coordinates, phone, email, website, Instagram, photos, services, prices, and available schedule.
- Specialist Data: Name, surname, photo, connection to the organization, and available slots. By default, the organization’s details are used for contact.
- Unregistered Client Data: Name, surname, phone, email, and booking details entered by a specialist at the request or with the consent of the client.
- Technical Security and Error Logs: Processed in the minimal volume necessary for operating and protecting the Platform. Dasy does not construct sign-in history or conduct profiling based on browser or device.
Dasy does not store search query history and does not collect precise user geolocation. Address coordinates of an organization may be published by the organization itself.
Access to the camera and photo library is used solely at the user’s choice to take or select a profile picture. Dasy does not access the camera or photo library in the background.
1.4. Data Sources
- Directly from the user during registration, sign-in, booking, publishing a review, or contacting support;
- From the device camera or photo library — only when the user chooses to add or change a profile picture;
- From the organization owner or specialist who creates a specialist profile or a booking for an unregistered client;
- From Google in case of Google Sign-In, within the scope authorized by the user;
- Automatically, through strictly necessary cookies and technical system logs.
1.5. Purpose and Legal Basis
- Account creation, authorization, and session maintenance;
- Service discovery, creating, rescheduling, and canceling bookings;
- Transferring necessary booking details to the organization;
- Sending service notifications regarding bookings, security, and operational changes;
- Creating and publishing pages for organizations, specialists, services, prices, and reviews;
- Enabling users to add, edit, and display profile pictures;
- Content moderation, complaint resolution, fraud and violation prevention;
- Technical support, error diagnostics, backup, and Platform security;
- Compliance with legal requirements and protection of the legitimate rights of Dasy and its users.
Processing is carried out based on user consent, the necessity to provide requested functionality, legitimate interests in security and proper operation of the Platform, and requirements of Ukrainian legislation.
1.6. Public Data
Pages of organizations and specialists may be accessible without registration and indexed by search engines. Publicly visible information may include the organization name, description, address, coordinates, contacts, website, Instagram, photos, services, prices, specialist name, surname, photo, reviews, and available slots.
Organization owners must have a legal basis to publish data and photos of employees and third parties. An invited specialist can see the invitation and join the organization. Personal phone numbers and emails of specialists are not published in place of organization contacts without a separate choice or consent.
1.7. Unregistered Clients
A specialist may manually create a booking for an individual without an account. In this case, the specialist confirms that the client provided their name, surname, phone, and email for a specific booking and agreed to receive related notifications. A booking confirmation and a link to this Policy are sent to the client’s email.
Dasy does not use these contact details for promotional purposes. Unregistered clients may change or cancel their booking by contacting the specialist or organization, and may also request data correction or deletion via Dasy contact channels.
1.8. Minor Users
Users aged 14 to 18 may use Dasy to book services they are legally entitled to request under Ukrainian law. If a specific service requires parental or legal guardian consent, the user and the organization must ensure it is obtained. Bookings for individuals under 14 must be created by their legal representative or by the organization upon request of such representative.
Organizations independently verify age restrictions for medical, cosmetological, tattoo, piercing, and other specialized services. Dasy does not determine whether a specific procedure is permissible for a minor.
1.9. Third-Party Data Sharing
- To organizations and specialists as necessary for booking management and fulfillment;
- To Google Cloud and other providers of hosting, databases, image storage, email delivery, and technical infrastructure (including profile picture storage);
- To Google when using Google Sign-In;
- To professional advisors or state authorities when required by law or necessary to protect legal rights;
- To a new owner of the service in the event of a lawful reorganization or project transfer, with user notification.
Service providers may process data outside of Ukraine. Dasy transfers only the minimum data required for the relevant function and applies contractual and technical safeguards where available.
1.10. Data Retention Periods
- Active Account Data: Stored for the duration of Dasy usage; a 7-day recovery grace period applies after a deletion request.
- Organization Data: Retained during active operations and for 7 days after deletion is initiated by the owner.
- Completed, Canceled, and Rescheduled Bookings: 1 year from the date of the relevant event.
- Unregistered Client Data: 1 year from the booking date.
- Reviews: Kept while published or as long as the corresponding page exists; kept for up to 1 year in moderation archives after deletion.
- Complaints and Support Inquiries: 1 year after resolution.
- Technical Logs: Generally up to 90 days.
- OTP: Retained only during the short validity period set by the system; used or expired OTPs become invalid.
- Access Tokens: Retained for the designated short technical duration.
- Refresh Tokens: Retained up to 30 days or until sign-out/revocation.
- Backups: Up to 90 days after creation.
- Proof of Document Acceptance and Materials Needed to Protect Legal Rights: Up to 3 years after termination of relations or resolution of a dispute.
- Profile Picture: Retained for the lifespan of the account or until replaced/deleted by the user; upon account deletion, the photo is deleted under the procedure and within the periods set out in this Policy, subject to backups.
After retention periods expire, data is deleted or anonymized, unless the law or an unresolved dispute requires longer retention.
1.11. Account Deletion
Users can initiate account deletion in their account settings. The account enters a 7-day pending deletion state. Signing in during this period cancels the deletion request. Users receive a notification specifying the scheduled deletion date.
Future bookings associated with the account are canceled. If the account belongs to the sole owner of an organization, the organization, its public pages, and future bookings are deleted or deactivated after the 7-day period. Data may temporarily remain in backups and is deleted according to standard backup cycles.
1.12. User Rights
- Request information regarding data processing;
- Request correction of inaccurate or outdated data;
- Withdraw consent when processing relies on consent;
- Request deletion or restriction of processing where provided by law;
- Object to unlawful data processing;
- File a complaint with Dasy, the Ukrainian Parliament Commissioner for Human Rights, or a competent court.
To safeguard data, Dasy may request identity verification prior to processing requests.
1.13. Security
Dasy implements organizational and technical safeguards, including access control, secure connections, permission management, backups, and error monitoring. However, no information system can guarantee absolute security.
1.14. Cookies
Dasy uses only strictly necessary authorization cookies containing access and refresh tokens required for sign-in, session maintenance, and security. Analytical, advertising, and marketing cookies are not used in the current version. Details are provided in the Cookie Policy.
1.15. Changes and Contacts
Dasy may update this Policy. In the event of material updates, users will be notified via the Platform or email, and the version number and date will be updated. Questions and requests can be sent to serkurinniy@gmail.com or https://t.me/DasyReservation.