1. Who we are
Vladyslav Omelchuk, Individual Entrepreneur (“Vlomkat”, “we”, “us”), is registered in the Republic of Armenia. Our full registration details are in the Imprint.
For personal information collected through this website and our own business operations, Vladyslav Omelchuk, Individual Entrepreneur, acts as the personal data processor under Armenian law and, where the EU or UK GDPR applies, as the data controller. When we process personal information strictly on a client’s instructions during a paid engagement, the roles and safeguards are defined in the engagement agreement.
For any privacy question, contact privacy@vlomkatsolutions.com.
2. What information we collect
We only collect what we need to reply to you and to deliver our consulting services:
- Contact form data: name, business name, country, business type, website or social link, email address, phone or WhatsApp number, your preferred contact method, the topics you ticked, and the message you wrote.
- Email and messaging correspondence: messages you send us directly by email, WhatsApp, or other channels you choose, including any attachments.
- Engagement records: for clients, the documents, configurations, notes, and invoicing records produced during an engagement.
- Technical data: standard server-side request logs (IP address, user-agent, referrer, timestamp) retained for security and abuse-prevention purposes. The .am website does not currently load Google Analytics.
We do not run advertising trackers, social pixels, or optional analytics cookies on this website.
3. Why we use it
We use the information you give us to:
- Reply to your inquiry and arrange an introductory call where relevant.
- Deliver the services you engage us for (assessment, recommendations, implementation).
- Issue invoices and keep accounting and tax records as required by Armenian and other applicable law.
- Operate, secure, and improve this website and our internal tools.
- Maintain security and reliable website operation without optional analytics tracking.
We do not use your contact details for marketing or unsolicited outreach. If we ever introduce a newsletter or similar, it will be strictly opt-in.
4. Legal basis
Where the EU / UK GDPR applies to you, our lawful bases for processing are:
- Steps prior to entering a contract (Art. 6(1)(b)) — when you submit the contact form or correspond with us about a possible engagement.
- Performance of a contract (Art. 6(1)(b)) — when we deliver services under an engagement agreement.
- Legal obligation (Art. 6(1)(c)) — for tax, accounting, and similar record-keeping required by Armenian or other applicable law.
- Legitimate interests (Art. 6(1)(f)) — for basic server logging, IT security, and protecting our business against fraud, abuse, and legal claims. We have weighed these interests against your rights and consider them proportionate.
- Consent (Art. 6(1)(a)) — where we ask you to agree to optional processing. The .am website does not currently load optional analytics cookies.
Processing on this website is also carried out in accordance with the Republic of Armenia Law on Protection of Personal Data, including its requirements on lawful purpose, proportionality, consent where required, security, and cross-border transfer.
5. Who we share information with
We share personal information only with service providers and advisors we need to operate, including:
- Contact-form processing — Formspree delivers submissions from the contact form to us.
- Website measurement — this website does not currently load Google Analytics or other optional analytics cookies.
- Email and productivity — our email and document-storage providers (for sending replies and storing engagement files).
- Messaging — WhatsApp / Meta, if you choose that channel to contact us.
- Cloud infrastructure — reputable hosting providers for this website and our internal tools.
- Font delivery — Google Fonts supplies the site’s typefaces. Loading those resources creates a request to Google with ordinary network metadata such as your IP address, browser, and referrer; it does not depend on analytics consent.
- Professional advisors — accountants, auditors, and lawyers, where strictly required to meet a legal or regulatory obligation or to advise on a specific matter.
- Authorities — where we are legally required to disclose information to a competent regulator, court, or law-enforcement body.
We do not sell, rent, or otherwise commercialise personal information.
6. International transfers
Because the operator is registered in Armenia and some service providers may be located in the United States, the European Economic Area, the United Kingdom, the United Arab Emirates, or other jurisdictions, your personal information may be transferred outside Armenia or your country of residence.
Where Armenian law applies to a transfer from Armenia, we follow Armenian transfer requirements separately from any EU or UK mechanism. We first confirm that the transfer is permitted by the data subject’s consent or is necessary for the stated processing purposes. A transfer may proceed without prior authorisation from the Armenian personal data protection authority only where the destination provides an adequate level of protection under Armenian law, including where the transfer is covered by an international treaty or the destination appears on the authority’s official list. For a destination that does not provide an adequate level of protection, we seek the authority’s prior authorisation and use a contract containing safeguards the authority accepts as sufficient. EU Standard Contractual Clauses or a UK transfer document do not by themselves satisfy or replace these Armenian requirements.
Separately, where the EU GDPR applies to a transfer from the EEA, we use an EU adequacy decision or another valid EU GDPR mechanism, such as the European Commission’s Standard Contractual Clauses, together with any required supplementary safeguards. Where the UK GDPR applies, we use UK adequacy regulations or a valid UK mechanism, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs; EU SCCs alone are not sufficient for a restricted transfer under the UK GDPR. If more than one regime applies, we satisfy each applicable regime rather than treating one mechanism as a substitute for another. You can request a copy of the relevant transfer-mechanism documentation by emailing privacy@vlomkatsolutions.com.
7. How long we keep it
We keep personal information only as long as we need it for the purposes described above:
- Inquiries that don’t turn into engagements: deleted within twelve (12) months of last contact.
- Client engagement records and correspondence: retained for the duration of the engagement and for a reasonable period afterwards to handle follow-up questions and warranty matters — typically up to two (2) years after engagement end.
- Accounting, tax, and invoicing records: retained for the period required by Armenian tax, accounting, and other applicable law.
- Server logs: retained for up to ninety (90) days unless needed longer to investigate a specific security incident.
After these periods, data is deleted or irreversibly anonymised.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- have inaccurate or incomplete information corrected;
- have your information deleted (the “right to be forgotten”);
- restrict or object to certain processing;
- receive your information in a portable, machine-readable format;
- withdraw any consent you previously gave (without affecting the lawfulness of processing before the withdrawal); and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see section 11).
To exercise any of these rights, email privacy@vlomkatsolutions.com. We may need to verify your identity before acting on a request. We handle each request within the deadline required by the law that applies to it. EU / EEA requests under the GDPR and UK requests under the UK GDPR are generally answered within one calendar month, subject to any extension permitted by law.
Where Armenian law applies, written requests for information about or access to personal data, and any reasoned written refusal, are handled within five days. Required completion, updating, correction, blocking, or destruction is carried out immediately or, if immediate action is not possible, within three working days. A withdrawal of consent submitted in writing with a signature, or electronically with a digital signature, requires us to stop processing and destroy the data within ten working days, unless law or a mutual agreement provides otherwise; we notify the individual within three working days after destruction. Other deadlines or verification requirements may apply depending on the request and jurisdiction, and we will explain any lawful extension or limitation.
You also have the right to lodge a complaint with a supervisory authority:
- Armenia — Personal Data Protection Agency: Ministry of Justice of the Republic of Armenia;
- EU / EEA: your local Data Protection Authority;
- UK: the Information Commissioner’s Office (ICO).
We’d appreciate the chance to address your concern directly first — please write to us before contacting a regulator.
9. Cookies & local storage
The .am site does not set cookies and does not use localStorage, sessionStorage, or IndexedDB for optional analytics or marketing. Google Analytics is not loaded.
If optional analytics or marketing tracking is introduced later, we will update this policy and implement any required prior consent before enabling it. We will not add an empty consent banner while no optional tracking exists.
10. Security
We use reasonable, industry-standard measures to protect personal information: HTTPS in transit, access controls on stored data, encrypted storage where supported by the provider, and a strict need-to-know policy inside the business. No system is perfectly secure, but we treat the data you share carefully.
If we become aware of a personal data breach or another incident affecting personal information, we will investigate and contain it, and make any notification, publication, or report required by Armenian law or any other law that applies to the incident. Where Armenian law applies to a leak of personal data from an electronic system, we will immediately publish a notice and simultaneously notify the Police of the Republic of Armenia and the authorised personal data protection body. Depending on the applicable law and circumstances, we may also need to notify other regulators, affected individuals, clients, or other parties. We do not use a GDPR-style risk-to-rights-and-freedoms test as the sole trigger for incident reporting.
11. Automated decisions & profiling
We do not make decisions about you based solely on automated processing (including profiling) that produce legal or similarly significant effects. Any AI tools we may use internally support human decision-making and do not replace it. If this ever changes, we will update this policy and tell you what choices you have.
12. Children’s privacy
Our services and this website are aimed at businesses and adult professionals. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided us with personal information, please contact privacy@vlomkatsolutions.com and we will delete it.
13. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will reflect any change. Material changes will be highlighted clearly and, where required by law, communicated to affected individuals directly.
14. Contact us
Questions about this policy or about how we handle your information? Email privacy@vlomkatsolutions.com. Full company details are in the Imprint.