Skip to content
FeaturesIntegrationsPricingAboutFAQBlog
UALog inTry for freeDemo
  1. Dinea
  2. Privacy Policy
Legal

Privacy Policy

Effective date: 5 May 2026

1.1 Who we are

Dinea is a software CRM system for clothing, footwear and accessories stores, provided by Individual entrepreneur Serhii Viacheslavovych Kiniak, incorporated under the laws of Ukraine, registration number 3388702850, with its registered address at 13A Holosiivska Street, Kyiv, Ukraine.

This Privacy Policy explains which personal data we receive through https://dinea.pro, the application at https://crm.dinea.pro, forms, customer support and connected integrations; why we use it; who may receive it; and which rights users have.

Privacy questions may be sent to policy@dinea.pro.

1.2 Roles of the parties

When a store owner or employee creates a Dinea account, we may act as a data controller for account registration, billing, security, support and website usage information.

When a store uses Dinea to store information about its customers, orders, messages or products, the store is normally the controller and Dinea acts as a processor following the store’s instructions. The store is responsible for the lawful collection of its end customers’ data and for providing any required notices and obtaining any required consents.

1.3 Data we may receive

Account owner and team data

  • name and surname;
  • email address;
  • phone number;
  • store or company name;
  • role, permissions and organisation membership;
  • login and session data, IP address, device and security logs;
  • correspondence with customer support;
  • plan, payment and invoice information.

Data uploaded to the CRM

  • store customer records;
  • phone numbers, email addresses, usernames and delivery addresses;
  • order and purchase history;
  • messages, attachments, comments and internal notes;
  • products, product images, SKUs, sizes, colours, barcodes and stock;
  • payment, return, debt, expense and delivery information;
  • employee, task and action-audit data.

Data from integrations

After explicit user authorisation, we may receive data from connected delivery services, marketplaces, payment providers, fiscal services, banks, messengers and social platforms. The scope depends on the integration and the permissions granted.

For example, Facebook, Instagram or TikTok integrations may provide a business-account identifier, page name, usernames, messages, attachments, message time, delivery or read status, and technical identifiers required to operate a conversation.

Website technical data

  • IP address;
  • browser and device type;
  • operating system;
  • viewed pages, navigation and events;
  • cookies and consent identifiers;
  • UTM parameters;
  • error and performance information.

1.4 How we use data

We may process data to:

  • create and maintain an account;
  • provide CRM functionality;
  • synchronise connected integrations;
  • receive and send messages on behalf of a store;
  • create orders, documents, shipping labels, receipts and reports;
  • manage products, locations, finance and tasks;
  • process subscription payments;
  • provide customer support;
  • protect accounts and prevent abuse;
  • back up and restore data;
  • analyse product performance;
  • send service communications;
  • send marketing communications where permitted by law or consented to;
  • comply with legal obligations.

1.5 Legal bases

Depending on the circumstances, we rely on:

  • performance of a contract;
  • steps taken before entering into a contract;
  • legitimate interests in security, support and product development;
  • user consent;
  • compliance with a legal obligation;
  • customer instructions when Dinea acts as a processor.

1.6 Integrations and third-party platforms

Connecting an integration is optional. The user authorises access through the relevant service and grants Dinea only the permissions displayed during the connection process.

Dinea does not ask for the user’s password to a third-party service. Access and refresh tokens must be stored on the server in encrypted or equivalently protected form.

The user may revoke access in Dinea and/or in the third party’s settings. Revocation stops new synchronisation. Previously received data may remain until it is deleted under this Policy, the contract and applicable law.

1.7 Recipients of data

We may use providers of infrastructure, hosting, backup, email, support, analytics, anti-spam, payment and other technical services. The current list is published on the Subprocessors page.

We provide each supplier only with the data required for its function and enter into appropriate contractual terms where required.

We may also disclose data:

  • in response to a lawful request from a competent authority;
  • to protect rights and safety or prevent fraud;
  • as part of a business reorganisation with appropriate safeguards;
  • on the user’s direct instruction.

We do not sell personal data to advertisers.

1.8 International transfers

Some providers may process data in other countries. Where applicable, we use available legal transfer mechanisms, contractual safeguards and assessments of the level of protection required by applicable law.

1.9 Retention periods

We retain data only for as long as it is required for the purposes described here.

  • active-account data: while the service is used;
  • data after subscription termination: up to 30 calendar days after account termination, unless law or contract requires otherwise;
  • backups: for a limited rotation cycle;
  • security logs: for the period required for investigation and protection;
  • website leads: up to 12 months from receipt of the enquiry or until consent is withdrawn where applicable;
  • financial documents: for the statutory retention period.

Data may be anonymised and kept longer for statistics if it no longer identifies an individual.

1.10 Security

We apply organisational and technical measures including HTTPS, access controls, role separation, logging of critical actions, secret protection, backups, component updates and incident-response procedures.

No system can guarantee absolute security. Users are also responsible for strong passwords, employee access and the security of their devices.

1.11 User rights

Depending on applicable law, a user may have the right to:

  • receive information about processing;
  • obtain a copy of data;
  • correct inaccurate data;
  • delete data;
  • restrict processing;
  • object to processing;
  • receive data in a portable format;
  • withdraw consent;
  • complain to a competent authority.

To make a request, email policy@dinea.pro or use https://dinea.pro/en/legal/data-deletion.

We may ask the requester to verify their identity and their authority to act for the relevant store.

1.12 Store end-customer data

If you are a customer of a store using Dinea, contact that store first. We will help the store handle a lawful request within our role as processor.

1.13 Children

Dinea is not intended for independent use by children. We do not knowingly offer accounts to people below the minimum age for entering into a contract in their country.

1.14 Cookies

Details about cookies, analytics and marketing scripts are provided in the Cookie Policy. Optional scripts load only after the appropriate consent where required.

1.15 Changes to this Policy

We may update this Policy. The current effective date will be displayed on the page. We may notify active users of material changes by email or through the service.

1.16 Contact

Individual entrepreneur Serhii Viacheslavovych Kiniak 13A Holosiivska Street, Kyiv, Ukraine Privacy: policy@dinea.pro Support: support@dinea.pro Phone: +380986845045

CRM for fashion retailers.

Product

FeaturesIntegrationsPricingSecurityDemo

Company

AboutBlogContactSupport

Legal

Privacy PolicyTerms of UseData deletionCookie PolicyDPA

Contact

Individual entrepreneur Serhii Viacheslavovych Kiniaksupport@dinea.propolicy@dinea.pro+38098684504513A Holosiivska Street, Kyiv, Ukraine09:00–18:00 (Europe/Kyiv)
© 2026 Dinea