This is a translation. The authentic version is the Ukrainian one (https://www.zevshost.net/legal/law-enforcement). In case of discrepancy, the Ukrainian text prevails.
1.1. The Provider cooperates in good faith with authorised state bodies while protecting Customers from unfounded requests. Every request is checked for compliance with the law.
1.2. The Provider does not disclose information about a Customer on the basis of an oral approach, a telephone call, a letter from an unofficial address, an approach by a person who has not evidenced their authority, or a request exceeding the body's competence.
1.3. The Provider does not require the body to justify its suspicion beyond what the law prescribes and does not assess the merits of procedural decisions.
1.4. Addresses for requests: admin@zevshost.net or abuse@hostvds.net. A request sent to either address is deemed received by the Provider. Postal address: 01021, м. Київ, вул. Мечникова, буд. 8, кімн. 22, Печерський район. Responsible officer: Director Yaroslav Vitaliiovych Kravchenko.
| Category of information | Minimum basis |
|---|---|
| The existence of a contractual relationship; the Customer's registration and contact details; the service start date | A written request from an authorised body within its competence, made in accordance with law |
| Payment data, payment history | A ruling of an investigating judge or a court |
| Client Area access IP addresses, connection logs | A ruling of an investigating judge or a court |
| The content of the Customer's Content, server data, disk images | Solely a ruling of an investigating judge or a court on temporary access to items and documents or on search, or another binding decision |
| Preservation of data without disclosure (freeze) | A written request from an authorised body stating the period |
2.1. The Provider discloses only the scope of information expressly identified in the request. Expansive interpretation of a request is not permitted.
2.2. Where a request is drafted too broadly, the Provider seeks clarification from the body without suspending compliance in the part that raises no doubt.
2.3. Reservation as to special statutory powers. The table above states the general rule and the minimum standard the Provider applies. It does not limit the special powers of authorised bodies expressly provided for by law. Where the law imposes on the Provider a duty to supply particular information on a basis other than the one stated in the table, the Provider discharges that duty in the manner prescribed by law and notifies the Customer in the manner set out in Section 5 of this Annex. Nothing in this Annex is to be construed as a waiver by the Provider of duties imposed by law.
3.1. Every request is checked against the following criteria:
1) the request is on official letterhead, signed by an authorised person and sent from
the body's official address;
2) the legal basis is stated (criminal proceedings number, reference to a statutory
provision, ruling particulars);
3) the request falls within the body's competence;
4) the scope of information requested corresponds to the basis;
5) for information requiring a judge's ruling — the ruling is attached or its
particulars are stated so that it can be verified.
3.2. Where the criteria are not met, the Provider issues a written reasoned response stating which condition is not satisfied and inviting the defect to be cured.
3.3. The Provider registers every request: date and time of receipt, body, proceedings number, scope of request, outcome of the check, scope of information provided, date of response, and the Provider's responsible officer. The register is retained for at least 5 years.
| Action | Timeframe |
|---|---|
| Acknowledgement of receipt | 1 business day |
| Compliance check | 2 business days |
| Provision of information under a properly made request | within the period stated in the request; if none — 5 business days |
| Compliance with a temporary access ruling | within the period stated in the ruling |
| Data preservation (freeze) on request | immediately upon receipt |
| Notice to the Customer of disclosure | 5 business days after disclosure, save in the cases under clause 5.2 |
5.1. The Provider notifies the Customer of the fact and scope of disclosure within 5 business days of disclosure (clause 16.3 of the Agreement).
5.2. Notification is not given where:
1) it is expressly prohibited by law;
2) the ruling or request contains a non-disclosure prohibition;
3) notification could prejudice a pre-trial investigation and the request expressly so
states.
5.3. Once the circumstances in clause 5.2 cease, the Provider notifies the Customer at the first opportunity.
6.1. Where indications of the activity described in Section 3 of Annex 1 are detected (in particular indications of the criminal offence under Article 255⁴ of the Criminal Code of Ukraine), the Provider notifies law enforcement authorities by decision of an authorised officer.
6.2. The report states: the indications detected, the time and source of the information, the Customer's identification and contact details, the measures taken, and details of the data preserved and its retention period.
6.3. At the same time the Provider preserves evidence under clause 8.5 of the Agreement: system logs, network data and, where technically feasible, an image of the virtual server — for 90 days, and on the body's demand for the period stated in that demand.
6.4. The Customer agrees (clause 8.6 of the Agreement) that such a report does not constitute a breach of confidentiality and does not require its consent.
6.5. Proactive reporting and active assistance in exposing the persons involved gives effect to the ground for release from criminal liability provided by part seven of Article 255⁴ of the Criminal Code of Ukraine.
7.1. Requests from law enforcement authorities of foreign states are executed solely through mutual legal assistance via the authorised central authority of Ukraine or on the basis of a Ukrainian court decision.
7.2. Direct requests from foreign authorities not following that route are not executed; the requester receives a written response explaining the procedure.
7.3. This restriction does not apply to voluntary responses to reports from foreign CERTs, anti-abuse organisations and rightsholders — such reports are handled under Annex 2 as abuse reports, without disclosure of the Customer's personal data save where expressly required by law.
7.4. Requests addressed to an Infrastructure Operator. The equipment on which a Service is hosted may be located in a foreign jurisdiction (clause 5.6 of the Agreement). Authorities of that jurisdiction may approach the Infrastructure Operator directly, and it complies with such requests under its own procedures, without the Provider's involvement and without notice to the Provider.
The Provider:
1) has no ability to check the lawfulness of such requests and cannot prevent them;
2) notifies the Customer of any such case of which it is aware, in the manner set
out in Section 5 of this Annex;
3) on the Customer's request, provides details of the Infrastructure Operator and
the country where the equipment is located, so that the Customer can protect its
own interests.
7.5. Physical access to equipment. A ruling of a Ukrainian court on temporary
access to items and documents, or on search, that requires physical access to
equipment or seizure of media may be impossible for the Provider to comply with
where the equipment is outside Ukraine and not owned by the Provider. In that case
the Provider:
1) informs the requesting authority without delay, naming the Infrastructure
Operator and the country where the equipment is located;
2) complies with the request to the extent that it is able to (providing Customer
details and system logs in the Provider's possession);
3) explains the mutual legal assistance route.
8.1. The Provider does not challenge procedural decisions on the Customer's behalf but provides the Customer with the information needed to do so itself: the particulars of the request or ruling, the scope of information provided, and the date — save in the cases under clause 5.2.
8.2. The Provider is not liable to the Customer for the consequences of complying with binding decisions of authorised bodies (clause 13.2.6 of the Agreement).
9.1. The Provider includes in its annual transparency report (Section 6 of Annex 2) anonymised statistics on:
9.2. The statistics are published in aggregate form and contain no information allowing identification of particular proceedings or a particular Customer.