Privacy policy

PRIVACY POLICY

Version 1.1 | Effective Date: 18 May 2026
Data Controller GLADDROP LTD
Registration Number 17214115 (Companies House, England & Wales)
Jurisdiction England and Wales
Date of Incorporation 12 May 2026
Email hladenko.comp@gmail.com
Website gladdrop.tv

1. GENERAL PROVISIONS

1.1. This Privacy Policy (hereinafter — the "Policy") governs the collection, use, storage and protection of personal data of visitors and users of the website with the domain name gladdrop.tv (hereinafter — the "Website").

1.2. The data controller is GLADDROP LTD — a company registered in England and Wales under number 17214115 (hereinafter — the "Company", "we", "us").

1.3. This Policy has been developed in accordance with the requirements of:

  • UK General Data Protection Regulation (UK GDPR) and UK Data Protection Act 2018 — with respect to data of UK residents;
  • Regulation (EU) 2016/679 (EU GDPR) — with respect to data of residents and data subjects located in EU/EEA Member States;
  • Privacy and Electronic Communications Regulations 2003 (PECR) — with respect to the use of cookies and electronic marketing communications;
  • ePrivacy Directive 2002/58/EC — with respect to data subjects in the EU;
  • Law of Ukraine "On Personal Data Protection" of 1 June 2010 — in relation to the processing of personal data of individuals residing or located in Ukraine.

1.4. The terms "personal data", "processing", "controller", "processor", "data subject", "consent", "legitimate interest" are used in the meanings defined by the UK GDPR and EU GDPR.

1.5. Please read this Policy carefully before using the Website.

2. DEFINITIONS

2.1. Personal data — any information relating to an identified or identifiable natural person (data subject).

2.2. Processing — any operation performed on personal data: collection, recording, organisation, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

2.3. Controller — GLADDROP LTD, which determines the purposes and means of processing personal data.

2.4. Processor — a natural or legal person that processes personal data on behalf of the Controller.

2.5. Data Subject / User — an identified or identifiable natural person whose personal data is being processed (a Visitor to the Website and/or a registered User).

2.6. Website — the website with the domain name gladdrop.tv.

2.7. Cookies — small text files placed on the User's device for the purposes described in Section 8 of this Policy.

2.8. UK GDPR — UK General Data Protection Regulation as retained in UK law pursuant to the European Union (Withdrawal) Act 2018, as amended by the UK Data Protection Act 2018.

2.9. EU GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

2.10. ICO — Information Commissioner's Office, the supervisory authority for data protection in the United Kingdom.

3. CATEGORIES OF PERSONAL DATA COLLECTED

3.1. Data provided directly by the User

  • Full name;
  • Email address;
  • Contact telephone number;
  • Delivery / billing address;
  • Payment data (processed exclusively through PCI DSS-certified payment services; the Company does not store full payment card details);
  • Data required for invoicing and accounting purposes;
  • Content of correspondence with the Company (support messages, emails).

3.2. Data collected automatically

  • IP address and approximate geographic location;
  • Device type, operating system, browser and browser version;
  • Referring URL and exit page URL;
  • Language and regional settings;
  • Date, time and duration of visit; pages viewed;
  • Actions on the Website (clicks, scrolling, form completion);
  • Cookie identifiers and similar technical identifiers (subject to consent in accordance with Section 8).

3.3. Data received from third parties

We may receive personal data from:

  • payment providers — confirmations of transactions;
  • analytical services (Google Analytics) — aggregated and/or anonymised data about interaction with the Website (subject to your prior consent to analytical cookies).

3.4. Special categories of data

The Company does not collect or process special categories of personal data. Where the provision of such data is necessary for a specific service, the Company will obtain the data subject's separate and explicit consent prior to any processing.

3.5. Children

The Website is not intended for persons under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child's data has been collected without the appropriate consent, we will delete it immediately.

4. LEGAL BASES FOR PROCESSING PERSONAL DATA

In accordance with Article 6 of the UK GDPR and EU GDPR, we process your personal data on the following legal bases:

Legal Basis Purpose of Processing Categories of Data
Performance of a contract (Art. 6(1)(b)) Account registration, order processing, delivery, payment processing, technical support Name, email, phone, address, payment data
Legal obligation (Art. 6(1)(c)) Compliance with UK tax, accounting and corporate legislation Invoice data, transactional data
Legitimate interest (Art. 6(1)(f)) Website security and fraud prevention; service improvement; support enquiry logging; intra-group data sharing Technical data, IP address, security logs
Consent (Art. 6(1)(a)) Marketing communications; analytics, functional and marketing cookies Email, cookie data, behavioral data

4.1. Where we rely on legitimate interest as the legal basis, we have carried out a Legitimate Interests Assessment and concluded that our interests do not override the rights and freedoms of data subjects. You have the right to object to such processing (see Section 11).

5. TRANSFERS OF PERSONAL DATA TO THIRD PARTIES

5.1. We transfer your personal data to third parties only in the circumstances set out below and exclusively on the basis of Data Processing Agreements or Standard Contractual Clauses.

5.2. Categories of recipients:

  • Payment providers — for processing transactions (acting as independent controllers or processors in accordance with PCI DSS);
  • Cloud infrastructure and hosting providers — to ensure the operation of the Website;
  • Postal and courier services — for the organisation of order delivery;
  • Marketing and analytics platform providers — for sending communications and Website analytics (subject to your consent);
  • Government authorities and law enforcement — where required by law in accordance with applicable UK or EU legislation.

5.3. In the event of a restructuring, merger or acquisition of the Company, personal data may be transferred to a successor entity, subject to compliance with UK GDPR / EU GDPR requirements and notification to you.

5.4. We do not sell or transfer personal data to third parties for their own marketing purposes without your explicit consent.

6. INTERNATIONAL TRANSFERS OF PERSONAL DATA

6.1. Some of our service providers may be located or process data outside the United Kingdom or the EEA. In such cases, transfers are carried out on the basis of one of the following mechanisms: an Adequacy Decision; Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914); the UK International Data Transfer Agreement (IDTA) approved by the ICO; or Binding Corporate Rules.

6.2. Transfers between the UK and the EU/EEA: the UK has been recognised by the European Commission as a country providing an adequate level of data protection (Adequacy Decision of 28 June 2021). Accordingly, personal data transfers between the UK and the EU take place without the need for additional safeguards.

6.3. Data subjects from Ukraine — transfers to/from Ukraine:

  • Ukraine is not included on the list of countries with an adequate level of data protection by either the United Kingdom (UK Adequacy Regulations) or the European Commission (as at the effective date of this Policy).
  • Transfers of personal data to/from Ukraine are carried out on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) and/or the UK International Data Transfer Agreement (IDTA) approved by the ICO, depending on the applicable jurisdiction.
  • Pursuant to Article 29 of the Law of Ukraine "On Personal Data Protection", the transfer of personal data to the United Kingdom and EU/EEA Member States is lawful, as those jurisdictions provide an adequate level of protection.
  • The Company takes all reasonable measures to ensure that recipients of personal data of Ukrainian data subjects maintain protection standards equivalent to the requirements of the UK GDPR / EU GDPR.

6.4. For further information about the safeguards applied to international data transfers, please contact us using the details set out in Section 14.

7. PERSONAL DATA RETENTION PERIODS

7.1. We retain your personal data for no longer than is necessary to achieve the purposes of its processing or to comply with applicable legal requirements.

Category of data Retention period
Account / User profile data For the duration of the account + 3 years after deletion
Order and transaction data 6 years
Accounting records and invoices 6 years
Security and access logs 12 months
Marketing permissions (consent records) 3 years from the withdrawal of consent
Cookie data (analytics / marketing) In accordance with cookie settings (up to 24 months)
Customer support correspondence 3 years

7.2. Upon expiry of the retention period, personal data is securely deleted or anonymised.

8. COOKIES AND SIMILAR TECHNOLOGIES

8.1. Legal basis: in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and the ePrivacy Directive 2002/58/EC, we place non-essential cookies only after obtaining your explicit, free, specific, informed and unambiguous consent (your consent is recorded via a Cookie Consent Banner / Cookie Preference Centre upon your first visit to the Website).

8.2. Categories of cookies:

Cookie Type Purpose Consent Required? Duration
Strictly Necessary Enable core Website functions (login, basket, security) NO Session / up to 1 year
Analytics Traffic and behaviour analysis (Google Analytics)) YES Up to 24 months
Functional Save language settings and preferences YES Up to 12 months
Marketing Personalised advertising and retargeting YES Up to 24 months

8.3. Managing cookies: you may review and update your cookie preferences at any time via the Cookie Preference Centre on the Website or through your browser settings. Withdrawing consent to non-essential cookies will not affect the lawfulness of any prior processing.

8.4. Google Analytics: where you consent to analytics cookies, we use Google Analytics with IP anonymisation enabled. You may install the Google Analytics opt-out browser add-on: https://tools.google.com/dlpage/gaoptout." target="_blank">https://tools.google.com/dlpage/gaoptout.

9. MARKETING COMMUNICATIONS

9.1. Legal basis: we send marketing emails exclusively on the basis of your explicit and separately obtained prior consent, in accordance with PECR (Regulation 6) and the EU GDPR. The "I agree" checkbox may not be pre-ticked.

9.2. Content of communications: new products and services, promotions, special offers, and useful information.

9.3. Right to unsubscribe: you may withdraw your consent and unsubscribe at any time by:

  • clicking the "Unsubscribe" link in any marketing email;
  • bsubmitting a request using the contact details in Section 14.

9.4. We will cease sending marketing communications promptly upon receipt of an unsubscribe request (and in any event no later than 10 business days). Unsubscribing will not affect transactional emails (order confirmations, delivery notifications, etc.).

10. SECURITY MEASURES

10.1. The Company implements technical and organizational measures in accordance with Article 32 of the UK GDPR / EU GDPR to ensure a level of security appropriate to the risk, including:

  • encryption of data in transit (TLS/SSL) and at rest (encryption at rest);
  • pseudonymisation of personal data where appropriate;
  • access restriction on a need-to-know basis;
  • regular testing and evaluation of the effectiveness of security measures;
  • data protection training for staff;
  • Data Breach Response Plan.

10.2. In the event of a personal data breach that may pose a risk to the rights and freedoms of data subjects, the Company will notify the ICO (and/or the relevant EU supervisory authority) within 72 hours of becoming aware of the incident, in accordance with Article 33 of the UK GDPR / EU GDPR. Where the risk is high, we will also notify affected Users directly.

10.3. Despite the measures in place, no system for transmitting data over the internet is completely secure. We recommend that you use strong passwords and do not disclose your login credentials to third parties.

11. RIGHTS OF DATA SUBJECTS

11.1. In accordance with the UK GDPR and EU GDPR, you have the following rights:

Right Description
Right to be informed To receive clear and transparent information about how we process your data.
Right of access To obtain a copy of your personal data being processed by us (Subject Access Request — SAR).
Right to rectification To require correction of inaccurate or completion of incomplete personal data.
Right to erasure / "right to be forgotten" To require deletion of your data (where there is no lawful basis for its continued retention).
Right to restriction of processing To require the suspension of processing of your data in certain circumstances.
Right to data portability To receive your data in a structured, commonly used, machine-readable format, or to have it transferred to another controller.
Right to object To object to processing based on legitimate interest or for the purposes of direct marketing.
Right to withdraw consent To withdraw your consent at any time; withdrawal does not affect the lawfulness of prior processing.
Rights regarding automated decision-making Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (where applicable).

11.2. Response times: we respond to all valid requests within one (1) month of receipt. For complex or multiple requests, the period may be extended by a further two months (with notification to you within the first month).

11.3. Requests should be submitted using the contact details in Section 14 and must include: your full name; contact details; the nature of the request; and identification information (to confirm your identity).

11.4. Subject Access Requests (SARs) are processed free of charge. Where requests are manifestly unfounded or excessive, we reserve the right to charge a reasonable fee or to refuse the request.

11.5. If you believe that the processing of your personal data violates applicable law, you have the right to lodge a complaint with the relevant supervisory authority:

  • Information Commissioner's Office (ICO) — the UK supervisory authority: www.ico.org.uk | tel. 0303 123 1113;
  • The supervisory authority of the EU Member State where you habitually reside or work (if you are located in the EU);
  • The Ukrainian Parliament Commissioner for Human Rights (Ombudsman) — if you are a data subject residing or located in Ukraine: 21/8 Instytutska Street, Kyiv, 01008 | hot-line@ombudsman.gov.ua | tel. 0800-501-720 (free of charge).

11.6. We encourage you to contact us in the first instance to resolve any issue before lodging a complaint with a regulator.

12. SPECIFIC PROVISIONS FOR DATA SUBJECTS FROM UKRAINE

12.1. This Section applies in addition to the remainder of this Policy where the data subject is a natural person residing or located in Ukraine, or where the processing of personal data falls within the scope of the Law of Ukraine "On Personal Data Protection" of 1 June 2010 (hereinafter — the "Law").

12.2. Legal bases for processing under the Law of Ukraine

Processing of personal data is carried out on the basis of Article 11 of the Law, including:

  • the data subject's consent to the processing of their personal data;
  • the necessity of performing a contract to which the data subject is a party;
  • the necessity of protecting the legitimate interests of the Company or third parties;
  • the fulfilment of the Company's obligations as defined by law.

12.3. Rights of data subjects under Ukrainian law

In addition to the rights set out in Section 11 (UK GDPR / EU GDPR), data subjects located in Ukraine have the following rights pursuant to Article 8 of the Law:

  • to know the location of the personal data database containing their personal data, its purpose and name, and the location and/or place of residence (location) of its owner or administrator;
  • to receive information about the conditions of access to personal data, including information about third parties to whom personal data is transferred;
  • to access their personal data and receive a copy thereof;
  • to submit a reasoned demand for the modification or destruction of their personal data by any owner or administrator of personal data, if such data is processed unlawfully or is inaccurate;
  • to have their personal data protected against unlawful processing and accidental loss, destruction or damage resulting from wilful concealment, non-provision or untimely provision thereof;
  • to lodge complaints regarding the processing of their personal data with the Ukrainian Parliament Commissioner for Human Rights or with a court;
  • to apply legal remedies in the event of a breach of personal data protection legislation;
  • to enter reservations regarding the restriction of the right to process their personal data when giving consent;
  • to withdraw consent to the processing of personal data;
  • to be informed of the mechanism of automated personal data processing;
  • to be protected against an automated decision that produces legal consequences for them.

12.4. Procedure for exercising rights.

Requests for the exercise of rights under the Law of Ukraine should be submitted using the contact details set out in Section 14. The Company will consider such requests within the time limits prescribed by the Law, namely no later than 30 (thirty) calendar days from the date of receipt of the request, unless a different period is prescribed by Ukrainian legislation for a specific category of request.In the event of a refusal to satisfy a request, the Company will provide a reasoned written response stating the grounds for refusal.

12.5. Personal data database registration

In accordance with the Law of Ukraine "On Personal Data Protection", the Company, as a foreign owner of a personal data database processing data of Ukrainian data subjects, takes measures to ensure compliance with the requirements of the Law, including with regard to notifying data subjects of the processing of their personal data and the legal basis for such processing.

12.6. Language of the document

This Policy has been prepared in English as the primary language. The Ukrainian version is an official translation. In the event of any inconsistency between the English and Ukrainian versions of this Policy, the English version shall prevail.

13. CHANGES TO THIS POLICY

13.1. We reserve the right to update this Policy. We will notify you of material changes by:

  • publishing the updated Policy on the Website with the new effective date;
  • sending a notification to your email address (for registered Users) — no less than 30 days prior to the changes coming into effect where such changes materially affect the processing of your data or your rights.

13.2. Where new data processing conditions require your separate consent (for example, new purposes of processing), we will request such consent in the prescribed manner.

13.3. Continued use of the Website after changes that do not require separate consent have come into effect will constitute acceptance of those changes.

14. CONTACT INFORMATION

14.1. For all enquiries relating to the processing of personal data and the exercise of your rights, please contact the Company:

Company GLADDROP LTD
Registration Number 17214115
Jurisdiction England and Wales
Registered Address 3rd Floor Suite, 207 Regent Street, London, W1B 3HH, England, United Kingdom
Email (Privacy) hladenko.comp@gmail.com
Website gladdrop.tv

14.2. Appointment of a Data Protection Officer (DPO): at this stage, the Company is not required to appoint a DPO pursuant to Article 37 of the UK GDPR / EU GDPR. Should such an obligation arise, we will update this Policy and publish the DPO's contact details.

14.3. EU Representative (Article 27 EU GDPR): where the processing of data of EU residents is carried out systematically or on a large scale, the Company will appoint an EU representative in accordance with Article 27 of the EU GDPR and will reflect this in the Policy.

15. GOVERNING LAW AND DISPUTE RESOLUTION

15.1. This Policy is governed by and construed in accordance with the laws of England and Wales.

15.2. For data subjects located in EU Member States, the provisions of the EU GDPR and the relevant national law of the EU Member State also apply.

15.3. For data subjects residing or located in Ukraine, the provisions of the Law of Ukraine "On Personal Data Protection" of 1 June 2010 also apply to the extent that they do not conflict with this Policy. In the event of a conflict of laws, priority shall be given to the legislation that affords the data subject a greater degree of protection.

15.4. All disputes arising in connection with this Policy shall be subject to the jurisdiction of the courts of England and Wales, unless otherwise required by mandatory provisions of EU law, Ukrainian law or the law of the User's country of habitual residence. Data subjects from Ukraine retain the right to apply to the courts of Ukraine or to the Ukrainian Parliament Commissioner for Human Rights in the manner prescribed by the Law.

16. FINAL PROVISIONS

16.1. The invalidity of any individual provision of this Policy shall not affect the validity of the remaining provisions or of this Policy as a whole.

16.2. This Policy is a public document. The current version is always published on the Website.

16.3. This Policy enters into force on 18 May 2026.

Last updated: 18 May 2026 | Version 1.1