1. Introduction and scope
1.1 This Privacy Policy explains how the Goodface group collects, uses, shares and protects personal data when you visit our website, contact us, download our materials, book a call with us, apply for a role with us, or engage us as a service provider.
1.2 "Goodface", "we" and "us" in this Policy mean Goodface company OÜ and LLC "GOODFACE" together. The two companies operate under a single brand, share the systems on which personal data is held, and are joint controllers within the meaning of Article 26 GDPR in respect of the processing described in section 2.
1.3 Goodface is a full-cycle digital agency. We provide product strategy and positioning, UX/UI and brand identity design, web and mobile development, and related marketing and consulting services, with a particular focus on financial technology clients. Our clients are businesses. We do not offer consumer financial products and we are not a regulated financial institution.
1.4 This Policy applies to our processing as a controller — that is, where we decide why and how personal data is processed. Section 14 separately explains our role as a processor, which is how we act in relation to personal data contained in our clients' systems and datasets during a delivery engagement.
1.5 This Policy does not apply to third-party websites, platforms or tools that we link to. Their own privacy notices govern your interaction with them.
1.6 Because we target clients in both the EEA and the United Kingdom, this Policy is written to satisfy Regulation (EU) 2016/679 ("EU GDPR") and the UK GDPR together with the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025 ("UK GDPR"). Where the two regimes differ in a way that affects you, we say so.
2. Who we are, and who is responsible for what
2.1 The joint controllers
Goodface is a group operating under a single brand. Two companies are involved in the processing described in this Policy:
2.2 The essence of our joint controller arrangement
2.2.1 The two companies share the systems on which personal data is held, including customer relationship management, email, file storage and project management, and jointly determine the purposes and means of the processing carried out through those systems. They have therefore entered into an arrangement under Article 26 GDPR. This section publishes the essence of that arrangement, as Article 26(2) requires.
2.2.2 Regardless of that allocation, Article 26(3) GDPR entitles you to exercise your rights against either company. Whichever you contact, we will handle your request through the single point of contact below.
2.2.3 You may request further information about the arrangement by writing to the contact address below. We may redact commercially confidential terms.
2.3 Single point of contact
We have assessed Article 37 EU GDPR / UK GDPR and consider that neither company is required to appoint a Data Protection Officer, because our core activities do not consist of large-scale regular and systematic monitoring of data subjects or large-scale processing of special category data. Privacy matters are handled by Maksym Yakubovych, management board member of Goodface company OÜ.
2.4 Representatives
2.4.1 United Kingdom. Neither company is established in the United Kingdom. Because we offer services to individuals in the UK, we have appointed a representative under Article 27 UK GDPR. You may contact the representative on any matter relating to our processing of personal data, in addition to or instead of contacting us:
2.4.2 European Economic Area. LLC "GOODFACE" is not established in the EEA and processes personal data of individuals in the EEA. It has appointed Goodface company OÜ as its representative under Article 27 EU GDPR, at the Tallinn address above.
2.5 You can contact us about anything in this Policy, including to exercise your rights, by email at the privacy contact above, or by post to the Tallinn address.
3. Definitions
We use the terms defined in the EU GDPR and UK GDPR. The following short-hand is used throughout:
- "personal data" means any information relating to an identified or identifiable living individual;
- "processing" means anything done with personal data, including collecting, storing, using, disclosing and deleting it;
- "controller" means the party that decides the purposes and means of processing; "processor" means a party that processes personal data on a controller's instructions;
- "Services" means the strategy, design, development, marketing and consulting services we provide to our business clients;
- "Website" means https://goodface.agency, including the fintech service pages and any sub-domains we operate.
4. The personal data we collect
We group the data we collect by the situation in which we collect it.
4.1 Website visitors
When you visit the Website, our servers and our analytics and tag management tools may receive:
- IP address (which we and our providers may truncate or shorten where the tool supports it);
- device, browser type and version, operating system, screen and language settings;
- pages viewed, referring URL, time and date of visit, time spent on each page, scroll and click interactions;
- approximate location derived from IP address, at city or country level;
- identifiers stored in or read from cookies and similar technologies, where you have consented or where an exception applies.
Cookies and similar technologies are described in detail in our Cookie Policy, which forms part of this Policy.
4.2 Business enquiries and project briefs
When you complete the "Let's talk" or contact form, or the project brief form, we collect:
- name, work email address and, optionally, company website, LinkedIn profile URL and how you found us;
- the content of your project description and any file you attach;
- the fact and content of subsequent correspondence with you.
4.3 Gated content (fintech eBook and similar downloads)
When you request our fintech eBook or other gated material we collect your work email address and LinkedIn profile URL, and we record that you requested that item and when.
4.4 Booking a call
When you book an introductory meeting through our scheduling tool, we collect your name, email address, the time slot you select, your time zone and anything you write in the booking notes. Calendar invitations and, if a meeting is recorded or transcribed, meeting content are also processed. Calls are recorded and transcribed using Fathom (AI notetaker). Participants are informed at the start of the call that it is being recorded; consent is given by that notice and anyone may object, in which case the call proceeds without recording. See the AI Transparency Note (Fathom is listed).
4.5 Marketing communications
If you subscribe to our newsletter or agree to receive marketing, we collect your email address, your preferences, and engagement data such as whether an email was opened and which links were clicked. No third-party email marketing platform is used and we do not send tracked marketing emails; business correspondence is sent from our own mailbox.
4.6 Client and supplier contacts
Where you are a contact person at a client, prospect, partner or supplier, we process your name, job title, business contact details, correspondence, meeting notes, project communications, and billing and payment information relating to your organisation.
4.7 Candidates
If you apply for a role with us, we process the data in your application, CV and portfolio, your interview notes, and assessment or test results. Recruitment is handled through an external applicant tracking system. ATS is Cleverstaff (Cleverstaff LLC, Kyiv, Ukraine). We keep application data for two years after your last activity in that system, and we do not maintain a talent pool.
4.8 Social media and review platforms
If you interact with our pages on professional and social networks or leave a review on a business directory, we see the information those platforms make available to us. We do not control those platforms and they act as separate or joint controllers in respect of their own processing.
4.9 Special category data
We do not seek to collect special category personal data (such as health data, biometric data, or data revealing racial or ethnic origin, political opinions, religious beliefs or trade union membership) through the Website. Please do not include such data in enquiry forms or attachments.
5. Where we get personal data from
- directly from you, when you fill in a form, email us, book a call or apply for a role;
- automatically, from your device and browser when you use the Website;
- from our client organisations, where they give us the contact details of their team members for a project;
- from publicly available business sources for business development purposes, such as company websites, professional networks and business directories. No sales intelligence, contact enrichment or lead generation tool is used. Where we obtain your business contact details from a public source, we will tell you that we hold them, and why, at the latest when we first contact you, as Article 14 GDPR requires.
6. Why we process personal data and on what legal basis
We only process personal data where we have a lawful basis for doing so. The table below sets out each purpose, the data involved, and the basis we rely on.
6.1 Where we rely on legitimate interests, we have carried out a balancing assessment weighing our interest against your rights and freedoms. You can ask us for a summary of that assessment using the contact details in section 2.
6.2 Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
7. Cookies and similar technologies
7.1 We use cookies, pixels, local storage and similar storage and access technologies. Full details, including the categories we use, the specific technologies deployed and how to change your choices, are in our Cookie Policy.
7.2 Non-essential technologies are not placed or read until you have given consent through our consent banner, except where an exception under the applicable law applies. Because the UK and EEA rules now differ on this point, our consent tool applies different rules depending on where you are located. This is explained in the Cookie Policy.
7.3 You can withdraw or change your consent at any time through the "Cookie settings" link in the Website footer.
8. Electronic marketing
8.1 We market to businesses. Whether we need your consent before sending you a marketing email depends on where you are and whether you are a corporate or individual subscriber.
8.2 EEA. We will send marketing email only where you have consented, or where you are an existing customer and we are marketing our own similar services to you and gave you the opportunity to object when we collected your address. National rules within the EEA vary, and in Estonia direct marketing by email requires the recipient's prior consent unless the existing-customer exception applies.
8.3 United Kingdom. Under the Privacy and Electronic Communications Regulations 2003, marketing email to a corporate subscriber — for example a named individual at a company or limited liability partnership — does not require prior consent, although we must identify ourselves and give you a way to opt out. Marketing email to an individual subscriber, including a sole trader or an unincorporated partnership, requires consent or the existing-customer exception.
8.4 Every marketing message we send includes an unsubscribe link. You can also opt out at any time by writing to us.
8.5 Opting out of marketing does not stop us from sending you service and transactional messages relating to an engagement, such as project updates or invoices.
9. Automated decision-making, profiling and artificial intelligence
9.1 We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.
9.2 We carry out limited profiling for marketing purposes, such as segmenting our audience by industry or by engagement with our content. This does not have legal or similarly significant effects, and you can object to it at any time.
9.3 We use artificial intelligence tools in the course of running our business and delivering the Services. Our AI Transparency Note explains where we use AI, how human oversight is applied, and how AI-assisted content is labelled. We do not permit our AI vendors to use personal data we submit to train their models. The AI tools we have approved for use, currently Claude and Fathom, are configured on enterprise or zero retention terms, with model training opted out.
10. Who we share personal data with
10.1 We do not sell personal data. We share it only as described below.
10.2 Every processor we engage is bound by a written data processing agreement meeting Article 28 EU GDPR / UK GDPR. We do not authorise them to use your personal data for their own purposes.
10.3 If our business or any part of it is sold, merged or reorganised, personal data may be transferred to the acquiring party as part of that transaction, subject to appropriate confidentiality protections.
11. International transfers
11.1 We are established in Estonia and personal data is primarily processed within the EEA. Some of our providers, delivery partners and personnel are located outside the EEA, so personal data may be transferred to third countries.
11.2 United Kingdom. Transfers between the EEA and the UK are covered by the European Commission's adequacy decision for the UK, renewed in December 2025 and currently valid until December 2031. No additional safeguard is required.
11.3 United States. Where a provider is certified under the EU-US Data Privacy Framework and, for UK-origin data, its UK Extension, we rely on that certification. Where a provider is not certified, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum for UK-origin data, and we carry out a transfer impact assessment.
11.4 Ukraine. Ukraine is our principal place of processing. Our delivery team works from Ukraine, and LLC "GOODFACE", our joint controller, is established there. Personal data held in our shared systems is therefore routinely accessed from Ukraine.
11.5 Ukraine is not covered by a European Commission adequacy decision, nor by a UK adequacy regulation. Transfers to Ukraine are made under the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum for UK-origin data, supported by a transfer impact assessment and by supplementary technical and organisational measures.
11.6 Our delivery personnel in Ukraine are engaged as independent contractors by Goodface company OÜ. Each is bound by written confidentiality obligations and by data protection terms, and acts only on our documented instructions.
11.7 Other third countries. For any other transfer we rely on an adequacy decision where one exists, and otherwise on the Standard Contractual Clauses or another mechanism permitted by Chapter V of the GDPR.
11.8 You can request a copy of the safeguards we rely on for a specific transfer by contacting us. We may redact commercially confidential terms.
12. How long we keep personal data
We keep personal data only for as long as we need it for the purpose for which it was collected, and then delete or anonymise it. Our standard periods are:
13. Your rights
13.1 Subject to the conditions and exemptions in the applicable law, you have the right to:
- be informed about how we use your personal data — which is what this Policy is for;
- access the personal data we hold about you and receive a copy of it;
- rectify inaccurate personal data and complete incomplete personal data;
- erase your personal data where we no longer have a lawful reason to keep it;
- restrict our processing in certain circumstances, for example while we verify the accuracy of data you have challenged;
- object to processing based on legitimate interests, and to object at any time and without needing to give a reason to processing for direct marketing purposes;
- portability — to receive personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller, where the processing is based on consent or contract and is carried out by automated means;
- withdraw consent at any time, where our processing is based on consent;
- not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you.
13.2 To exercise a right, contact us using the details in section 2. We may need to verify your identity before we act. We will respond within one month. If your request is complex or you have made a number of requests, we may extend that period by up to two further months and will tell you if we do.
13.3 Exercising your rights is free. We may charge a reasonable fee, or refuse to act, if a request is manifestly unfounded or excessive, and we will explain our reasoning if we do.
13.4 If you are unhappy with how we have handled your personal data, please tell us first so that we can try to put it right. We will acknowledge your complaint within 30 days and keep you informed of the outcome.
13.5 You also have the right to complain to a supervisory authority:
14. Our role as processor on client engagements
14.1 When we design or build a product for a client, we may be given access to that client's systems, test environments or datasets, which can contain personal data relating to the client's own customers and staff. In relation to that data the client is the controller and we act as processor.
14.2 In that role we process personal data only on the client's documented instructions, under a data processing agreement satisfying Article 28 EU GDPR / UK GDPR, which covers confidentiality, security measures, sub-processor authorisation, assistance with data subject rights and breach notification, and return or deletion at the end of the engagement.
14.3 If you are an end customer of one of our clients and want to exercise your rights, please contact that client directly, as they control the data. If you contact us, we will forward your request to them and tell you that we have done so, unless the client has instructed us otherwise.
14.4 On some engagements, and in particular on fintech engagements, we are given access to live production data containing personal data relating to our client's own customers and staff. We do not treat that as exceptional, and this Policy does not state otherwise.
14.5 Where live production data is involved, the following controls apply in addition to the data processing agreement described in clause 14.2:
- access to production environments is granted only to the named individuals who need it for a defined task, for a defined period, and is withdrawn when that task ends;
- access is granted through the client's own access management wherever the client's systems allow it, so that the client retains visibility of who has access and can withdraw it at any time;
- production data is not copied into our own environments, and is not used for development or testing, unless the client instructs it in writing;
- where such a copy is authorised, it is limited to the fields needed, held only for as long as the task requires, and deleted or returned at the end of it;
- access to production environments is individually attributed, never shared between people, and protected by multi-factor authentication, and where the client provides access logging in its own systems we work within it;
- where a client makes anonymised, pseudonymised or synthetic data available for a task, we use it in preference to live data.
14.6 The controls that apply to a particular engagement are set out in the data processing agreement and security schedule for that engagement, which prevail over this clause.
15. Case studies, portfolio and group companies
15.1 We publish descriptions of work we have delivered. Where a case study identifies a client organisation, we do so with that organisation's permission. Where a case study includes an individual's name, photograph, role or quotation, we obtain that individual's consent, and they can withdraw it at any time by contacting us, in which case we will remove or anonymise the material within a reasonable period.
15.2 Case studies are published under the single Goodface brand and describe the work of the group as a whole. Projects delivered before 13 January 2026 were delivered by LLC "GOODFACE", which has traded under the Goodface brand since February 2022; projects since then may be delivered by either company. The Legal Notice identifies the companies in the group and states which of them contracts with clients in each market.
15.3 The word mark "Goodface" is registered as a European Union trade mark under no. 019339622, registered on 10 July 2026 in classes 35 and 42, and as a United Kingdom trade mark under no. UK00004365310, entered on the register on 26 June 2026 with effect from 30 March 2026, in the same classes. Both are owned by Maksym Yakubovych and are used by the companies in the group with his permission.
16. Security
16.1 We maintain technical and organisational measures appropriate to the risk. These include:
- encryption of personal data in transit using TLS, and encryption at rest on the managed cloud services we use;
- role-based access control applied on a least-privilege basis, with access reviewed periodically and withdrawn promptly when it is no longer needed;
- multi-factor authentication on business-critical systems;
- separation of client environments from one another;
- written confidentiality obligations and documented data protection terms for everyone who works on our engagements, including independent contractors;
- requirements for the devices used to access our systems, including full-disk encryption, current operating system and security updates, and a prohibition on storing client material in personal cloud accounts;
- security review of a vendor before we engage it, and a written data processing agreement with every processor;
- logging and monitoring of access to our systems;
- security and privacy awareness training for our people.
16.2 We do not hold, and do not currently plan to obtain, ISO/IEC 27001 or SOC 2 certification.
16.3 No method of transmission or storage is completely secure. While we take the security of your personal data seriously, we cannot guarantee absolute security.
16.4 If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where required, and we will notify you directly where the breach is likely to result in a high risk to you.
17. Children
The Website and our Services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
18. Changes to this Policy
18.1 We may update this Policy to reflect changes in our services, our tools or the law. The version and date are shown at the top of this Policy.
18.2 Where a change materially affects you — for example a new purpose or a new category of recipient — we will bring it to your attention before it takes effect, by email where we have your address or by a prominent notice on the Website.
18.3 We keep previous versions of this Policy and will provide an earlier version on request.
19. Contact
Questions about this Policy, or about how we handle personal data, should go to fintech@goodface.agency, or by post to Goodface company OÜ, Vesivärava tn 50-201, 10152 Tallinn, Estonia.



