PRIVACY POLICY
LIMITED LIABILITY COMPANY
“LIME SYSTEMS”
Last updated: 21.07.2026

1. Introduction
LIMITED LIABILITY COMPANY “LIME SYSTEMS” (“Lime Systems”, “Company”, “we”, “us”, or “our”) respects your privacy and is committed to handling personal data in a transparent, fair, and responsible manner.
This Privacy Policy explains how we collect, use, disclose, store, and otherwise process personal data through our English-language corporate website and related communications.
This website is intended for a business audience. It serves as a corporate information resource and communication channel for banks, financial institutions, partners, vendors, and other business contacts. It is not an e-commerce website and does not provide direct online purchasing functionality.
By using our website, contacting us, or otherwise interacting with us in connection with the website, you acknowledge that your personal data may be processed as described in this Privacy Policy.
2. Controller Information
The controller responsible for the processing described in this Privacy Policy is:
LIMITED LIABILITY COMPANY “LIME SYSTEMS”
Registered address: 4A Verkhniy Val Street, Kyiv, 04071, Ukraine
For privacy-related questions or requests, you may contact us at:
privacy@lime-systems.com
Unless expressly stated otherwise in this Privacy Policy or in separate contractual documentation, Lime Systems acts as the controller of personal data collected through this website and related website communications.
3. Scope of This Privacy Policy
This Privacy Policy applies to personal data collected or received by us:
- through the website and its contact forms;
- through email communications initiated through the website or related business inquiries;
- through analytics, cookies, and similar technologies used on the website;
- when you submit a CV or related career information through the general contact form;
- when you otherwise communicate with us in connection with the website, our business, or potential cooperation.
This Privacy Policy does not govern personal data that we may process solely on behalf of our business customers in the course of delivering separate software, support, or other B2B services under independent contractual arrangements. Where we process personal data on behalf of a customer under such arrangements, the relevant customer remains responsible for its own controller obligations, and such processing is governed by the applicable contract, data processing terms, and service documentation.
4. Personal Data We May Collect
4.1 Data you provide to us directly
We may collect personal data that you choose to provide, including:
- full name;
- email address;
- phone number;
- message content;
- files or documents you upload or attach, if applicable;
- CVs, resumes, cover letters, and related career information submitted through the general contact form;
- any other information you voluntarily provide.
You are not required to submit personal data in order to access and browse the website. However, if you choose not to provide certain information when contacting us, we may be unable to respond to your request or continue the relevant communication.
Please do not submit special category data or other excessive information unless it is strictly necessary and clearly relevant to your communication.
4.2 Data collected automatically through website technologies
When you visit or use the website, certain technical, device, and usage-related data may be collected automatically through the website’s infrastructure and the technologies used on it, including Google Analytics, Google Signals where enabled, Google Tag Manager, Microsoft Clarity, Ahrefs Web Analytics, Google reCAPTCHA, cookies, and similar tools. Such data may include:
- IP address;
- browser type and version;
- device type;
- operating system;
- referring pages and URLs;
- date and time of access;
- pages visited and navigation patterns;
- interaction data, such as clicks, scrolling, mouse movements, and similar on-site engagement signals;
- cookie identifiers and similar online identifiers;
- technical request and response data;
- diagnostic, performance, and error-related information.
We use these technologies to understand how visitors interact with the website, improve the website’s structure, performance, and content, maintain website functionality, and protect the website and its forms against spam, abuse, and malicious activity.
Google Analytics is used to analyse website traffic and usage patterns. Where Google Signals is enabled, Google Analytics may also provide aggregated analytics insights, such as cross-device reporting, approximate demographics, and interests, where such data is available from eligible Google users.
Microsoft Clarity is used to analyse on-site interaction and user experience.
Google reCAPTCHA is used to protect forms and the website from spam and abusive automated activity.
Google Tag Manager is used to deploy and manage website technologies and tags.
Ahrefs Web Analytics is used as a cookie-free analytics tool to analyse website usage, traffic sources, page-level statistics, and aggregated website analytics.
Where applicable law requires consent for non-essential cookies or similar technologies, such tools operate subject to your choices made through our cookie banner / consent mechanism. For more information about cookies, similar technologies, and your choices, please see our Cookie Policy.
5. How and Why We Use Personal Data
We process personal data only where we have an appropriate legal basis and a legitimate business purpose.
5.1 Contact requests and business inquiries
If you submit a request through the website or otherwise contact us regarding our business, services, expertise, cooperation opportunities, or related matters, we may process your personal data to:
- respond to your inquiry;
- communicate with you;
- provide information you requested;
- arrange a call, meeting, presentation, or further discussion;
- take steps prior to entering into a contract.
Legal basis:
- performance of steps taken at your request prior to entering into a contract;
and/or
- our legitimate interests in handling business communications and managing B2B relationships.
5.2 Website operation, analytics, and improvement
We process technical and usage data to:
- operate and secure the website;
- understand how visitors use the website;
- measure engagement and performance;
- receive aggregated analytics insights, including through Google Analytics and Google Signals where enabled;
- improve functionality, structure, and content;
- diagnose technical issues.
Legal basis:
- our legitimate interests in operating, protecting, and improving the website, where strictly necessary processing is involved;
- your consent, where required for analytics cookies, advertising-related analytics features, and similar non-essential technologies.
5.3 Fraud prevention, abuse prevention, and security
We use security-related data, logs, and tools such as Google reCAPTCHA to:
- detect and prevent spam or malicious submissions;
- protect forms and website infrastructure;
- investigate incidents;
- maintain system integrity and security.
Legal basis:
- our legitimate interests in ensuring the security, integrity, and resilience of our website and systems;
- compliance with legal obligations, where applicable.
5.4 CVs and career-related submissions through the general contact form
If you submit a CV, resume, or similar career-related information through the general contact form, we may process such data for the purpose of reviewing your profile in connection with current or future cooperation opportunities.
Because the website does not currently provide a separate dedicated recruitment workflow with a standalone consent mechanism for CV submissions, we do not rely on consent as the main legal basis for this processing.
Legal basis:
- our legitimate interests in reviewing unsolicited candidate inquiries and assessing potential current or future professional cooperation opportunities.
Access to such data is limited internally, on a need-to-know basis, to relevant HR personnel, the relevant department head, and company management.
We do not disclose CVs to third parties for independent use.
5.5 Compliance, legal, accounting, and corporate recordkeeping
We may process personal data where necessary to:
- comply with applicable laws;
- maintain accounting, tax, bookkeeping, audit, and corporate records;
- establish, exercise, or defend legal claims;
- respond to lawful requests from authorities;
- protect our rights, property, systems, and business interests.
Legal basis:
- compliance with legal obligations;
- our legitimate interests in legal protection, corporate administration, and risk management.
6. Cookies and Similar Technologies
We use cookies and similar technologies on the website. These may include strictly necessary, functional, analytics, advertising-related analytics, security, and other categories of technologies depending on the configuration of the website and the tools in use.
Where required by applicable law:
- strictly necessary technologies may operate without consent;
- non-essential analytics, advertising-related analytics, or similar technologies operate only after you give your consent through the website’s cookie banner / consent mechanism.
For detailed information about the categories of cookies, specific tools, retention periods, and your choices, please refer to our separate Cookie Policy.
7. Sources of Personal Data
We generally collect personal data directly from you.
We may also receive technical and usage-related data through the website itself and through the third-party analytics and security tools described above.
In limited cases, we may also receive professional or business contact details from publicly available sources, business correspondence, or business interactions where this is relevant to establishing or maintaining a legitimate B2B relationship.
8. Disclosure of Personal Data
We do not sell personal data.
We may disclose personal data, where necessary and appropriate, to the following categories of recipients:
- website hosting and infrastructure providers;
- analytics and technical service providers;
- security and anti-abuse service providers;
- IT support and system administration providers;
- professional advisers, including legal, audit, accounting, and compliance advisers;
- courts, regulators, law enforcement authorities, or other public authorities where required by law or necessary to protect our rights;
- relevant counterparties involved in a proposed or completed corporate transaction, including a merger, acquisition, investment, or reorganisation, subject to appropriate confidentiality safeguards.
We do not route contact form submissions into third-party CRM or marketing automation platforms unless expressly stated otherwise.
Personal data submitted through website forms is handled through our corporate email environment and related internal handling processes.
9. International Data Transfers
Although our website infrastructure is hosted in Ukraine, certain personal data or technical/usage-related data may be received or processed by third-party analytics and technical providers in jurisdictions outside the user’s country, and in some cases outside the EEA or the UK.
This may occur, for example, in connection with the use of Google Analytics, Google Signals where enabled, Google Tag Manager, Microsoft Clarity, Ahrefs Web Analytics, Google reCAPTCHA, and related technical services. Google states that Analytics collects data from EU-based devices through domains and servers in the EU before forwarding traffic to Analytics servers for processing, and Microsoft documents consent-signal requirements and data handling for Clarity in EEA/UK/CH contexts.
Where personal data is transferred internationally, we seek to ensure that appropriate safeguards are in place as required or permitted by applicable law. Depending on the provider and transfer scenario, such safeguards may include:
- transfers to countries recognized as providing an adequate level of protection;
- reliance on an applicable certification or recognized transfer framework, where available;
- standard contractual clauses or equivalent contractual safeguards;
- other lawful transfer mechanisms or safeguards available under applicable law.
Where appropriate, additional technical and organizational measures may also be used to protect personal data.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
10.1 Contact requests and email correspondence
Contact requests and related email correspondence are retained only for as long as necessary to handle the inquiry, any related follow-up, internal review and recordkeeping connected with the relevant business matter, and thereafter only where retention is required to comply with applicable legal obligations, resolve disputes, or establish, exercise, or defend legal claims.
10.2 CVs and related candidate information
CVs and related candidate information submitted through the general contact form are retained for the period reasonably necessary to review your profile in connection with current or future cooperation opportunities, maintain related internal recruitment or business records, and, where necessary, establish, exercise, or defend legal claims.
If you object to such processing or request deletion of your candidate information, we will review and respond to your request in accordance with applicable law.
10.3 Technical server access logs
Our hosting environment retains technical website access logs for up to approximately 90 days for website security, stability, and troubleshooting purposes.
10.4 Security and administrative access logs
Security, administrative and technical logs may be generated by the website, hosting infrastructure, CMS, FTP access tools, PHP mail functionality, webserver access logs, error logs, or other administrative and security-related systems.
Such logs may include IP address, date and time of access, requested URL or resource, user agent, technical error information, login or access identifier where applicable, action performed where applicable, and other technical information necessary for access control, website security, abuse prevention, troubleshooting, and incident investigation.
Retention period: the retention period depends on the relevant system, hosting provider, tool, or security configuration and is limited to the period reasonably necessary for security monitoring, troubleshooting, incident investigation, website protection, and defence of legal or technical claims.
10.5 Backups
According to the hosting provider’s backup settings, backups are created automatically on a nightly basis.
- Hosting account and website backup copies are retained for the last 12 days, as well as for the first day of the current month and the first day of the previous month.
- Database backup copies are retained for the last 7 days, as well as for the first day of the current month and the first day of the previous month.
Personal data may temporarily appear in backups during these retention periods.
10.6 Accounting, tax, audit, and corporate records
Where personal data forms part of accounting, tax, bookkeeping, audit, legal, or corporate records, it may be retained for the period required under applicable law or for the duration necessary to protect our legal position.
10.7 Analytics and cookie-related data
Retention of analytics and cookie-related data may depend on the configuration of our website, the settings and retention options of the relevant providers, and your consent choices. As currently configured, Google Analytics 4 event-level data is retained for 2 months, while user-level data is retained for 14 months, with the retention period reset upon new user activity. Where Google Signals is enabled, Google Analytics may also provide aggregated analytics insights based on eligible Google users, subject to Google’s applicable settings and the user’s consent choices. Microsoft Clarity generally retains recordings data for 30 days, while labeled or favorited sessions and heatmap data may be retained for up to 13 months. More information about cookies and similar technologies is provided in our Cookie Policy where applicable.
11. Internal Access and Role Limitations
Access to personal data is limited to personnel who need it for legitimate business purposes.
Our IT function is responsible for the technical availability, support, maintenance, and security of the website. It does not separately process website contact submissions, CVs, or business correspondence as part of routine business handling, except to the extent personal data may temporarily appear in technical logs, security logs, or backups within the retention periods described above.
Candidate information submitted through the general contact form is accessible internally only to:
- HR;
- the relevant department head;
- company management,
on a need-to-know basis.
12. Your Rights
Depending on your location and applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- object to certain processing, including processing based on legitimate interests;
- request portability of your personal data, where applicable;
- withdraw your consent at any time where processing is based on consent;
and
- lodge a complaint with a competent data protection or privacy regulator.
To exercise your rights or raise a privacy-related concern, please contact us at:
privacy@lime-systems.com
Depending on your country, region, and the law applicable to your situation, you may also have the right to lodge a complaint with the competent supervisory, data protection, or privacy authority in your place of habitual residence, place of work, or where you believe the relevant issue has arisen.
We may request additional information to verify your identity before responding to your request.
13. Automated Decision-Making
We do not carry out solely automated decision-making, including profiling, that produces legal effects or similarly significant effects on individuals through this website. For the avoidance of doubt, the website may use automated technical and security measures, including tools designed to detect spam, abuse, or malicious activity, but such measures are not used to make legally significant or similarly significant decisions about individuals.
14. Children
This website is intended for a professional business audience and is not directed to children.
We do not knowingly solicit or intentionally collect personal data from children through this website. If you believe that personal data relating to a child has been provided to us in error, please contact us so that we can review and address the issue.
15. Third-Party Websites and Services
The website may contain links to third-party websites, platforms, or resources.
We are not responsible for the privacy, security, or data handling practices of third-party websites or services. We encourage users to review the applicable privacy notices of those third parties.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, business operations, website functionality, or data processing practices.
The current version will always be made available on the website with the updated “Last updated” date.
17. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or our processing of personal data, please contact:
LIMITED LIABILITY COMPANY “LIME SYSTEMS”
Email: privacy@lime-systems.com