PIXEL CORE
  • Home
  • Portfolio
  • Marketplace
  • Pricing
  • Contact
Cabinet

Privacy Policy

Last updated: February 22, 2026

Table of Contents

  1. Introduction
  2. Data Controller
  3. Data We Collect
  4. Purposes of Data Processing
  5. Legal Basis for Processing
  6. Cookies and Analytics
  7. Data Sharing with Third Parties
  8. Data Storage and Protection
  9. User Rights (GDPR / EU)
  10. User Rights (Ukraine)
  11. Children
  12. Data Breach Notification
  13. Policy Changes
  14. Contacts

1. Introduction

PIXEL CORE (hereinafter referred to as "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use, store, and protect it.

This Policy has been developed in accordance with:

  • Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)
  • Law of Ukraine "On the Protection of Personal Data" No. 2297-VI dated 01.06.2010
  • Law of Ukraine "On Electronic Commerce" No. 675-VIII
  • EU Directive 2002/58/EC (ePrivacy) — regarding the use of cookies

By using the Website, you confirm that you have read and accept the terms of this Privacy Policy. If you do not agree with the Policy, please discontinue using the Website.

2. Data Controller

The controller (owner) of your personal data is:

PIXEL CORE
Email: pixelcoregroup@gmail.com
Website: pixelcore.it.com

Personal data processing is carried out only to the extent necessary to provide the Website's services.

The user agrees to this Privacy Policy upon registration, use of the Website, or placing an order.

3. Data We Collect

Data Category Examples Source
Registration data Name, email, password (hash) Registration form
OAuth data Email, name, avatar, provider ID Google, GitHub, Discord, Telegram
Profile data Phone number, avatar, date of birth Personal cabinet
Order data Project description, files, correspondence Order system
Technical data IP address, browser type, OS, visit time Automatically
Cookies Session cookies, JWT token Automatically

We do not collect: payment card data (payment processing is handled through secure payment systems), biometric data, health data, racial or ethnic origin, political opinions, religious beliefs.

4. Purposes of Data Processing

We process your data for the following purposes:

Purpose Legal Basis (GDPR)
Account creation and management Performance of a contract (Art. 6(1)(b))
Order fulfillment and service delivery Performance of a contract (Art. 6(1)(b))
Communication with you (notifications, support) Legitimate interest (Art. 6(1)(f))
Newsletters and promotions Consent (Art. 6(1)(a))
Website security Legitimate interest (Art. 6(1)(f))
Compliance with legislation Legal obligation (Art. 6(1)(c))

We may use automated data processing to ensure system security, prevent fraud, and manage user authorization.

5. Legal Basis for Processing

5.1. GDPR (for EU users)

Data processing is carried out on the following grounds:

  • Consent (Art. 6(1)(a)) — for marketing communications and analytical cookies
  • Performance of a contract (Art. 6(1)(b)) — for service delivery and account management
  • Legal obligation (Art. 6(1)(c)) — for compliance with tax and other legislation
  • Legitimate interest (Art. 6(1)(f)) — for security protection, fraud prevention, and service improvement

5.2. Ukrainian Legislation

Data processing is carried out on the following grounds:

  • Consent of the personal data subject (Art. 6, 11 of Law No. 2297-VI)
  • Necessity for the performance of a contract to which the data subject is a party
  • Necessity to protect the vital interests of the data subject
  • Necessity for the performance of the obligations of the personal data controller

6. Cookies and Analytics

6.1. Types of Cookies Used

Type Purpose Retention Period
Essential Session, authorization (JWT), CSRF protection Until end of session / 7 days
Functional Language, theme, display settings 1 year

6.2. Cookie Management

You can manage cookies through your browser settings. Disabling essential cookies may affect the functionality of the Website.

7. Data Sharing with Third Parties

We may share your data with the following categories of recipients:

Recipient Purpose Safeguards
Google (OAuth) Authorization Privacy Shield / SCC
GitHub (OAuth) Authorization DPA GitHub
Discord (OAuth) Authorization Privacy Policy Discord
Telegram (bot) Authorization, notifications Privacy Policy Telegram
Gmail (SMTP) Sending email notifications Google DPA

We do not sell your personal data to third parties.

Data transfers outside the EU/EEA are carried out only where appropriate safeguards are in place (EU Standard Contractual Clauses, adequacy decisions, etc.).

8. Data Storage and Protection

8.1. Retention Periods

  • Account data — stored as long as the account is active. After account deletion, data is removed within 30 days
  • Order data — stored for 3 years after order completion (accounting requirements)
  • Security logs — stored for 12 months
  • Marketing consents — stored until consent is withdrawn

8.2. Security Measures

We implement the following measures to protect your data:

  • Password encryption (bcrypt with salt)
  • HTTPS encryption for all connections
  • CSRF protection for all data-modifying requests
  • JWT tokens with limited validity period (7 days)
  • Rate limiting to protect against brute-force attacks
  • Regular updates of dependencies and server software
  • Access to server infrastructure restricted on a least-privilege basis

Despite the security measures we implement, we cannot guarantee absolute protection of data against all possible threats, including new and unknown types of attacks. The user understands and accepts the existing technological limitations of Internet security.

9. User Rights (GDPR / EU)

If you are located in the European Union or the European Economic Area, you have the following rights under Regulation (EU) 2016/679:

Right GDPR Article Description
Access Art. 15 Obtain a copy of all your data that we process
Rectification Art. 16 Request correction of inaccurate or incomplete data
Erasure Art. 17 Request deletion of data ("right to be forgotten")
Restriction of processing Art. 18 Restrict data processing in certain cases
Portability Art. 20 Receive data in a machine-readable format (JSON/CSV)
Objection Art. 21 Object to processing based on legitimate interest
Withdrawal of consent Art. 7(3) Withdraw consent for data processing at any time

Data transfer is carried out subject to technical and legal feasibility.

To exercise your rights, contact us at: pixelcoregroup@gmail.com. We will respond within 30 days (Art. 12(3) GDPR).

You also have the right to lodge a complaint with the data protection supervisory authority in your country.

10. User Rights (Ukraine)

In accordance with the Law of Ukraine "On the Protection of Personal Data" (No. 2297-VI), you have the right to:

  • Know about the sources of data collection, the location of your data, the purpose of processing, and the location of the data controller
  • Receive information about the conditions of access to data, including information about third parties to whom the data is transferred
  • Access your personal data
  • Receive a response as to whether your data is being processed, and obtain the content of such data
  • Submit a request for the modification or destruction of data if it is processed unlawfully or is inaccurate
  • Protect your personal data from unlawful processing and accidental loss, destruction, or damage
  • File a complaint with the Ukrainian Parliament Commissioner for Human Rights or with a court
  • Withdraw consent for the processing of personal data

To exercise any of the above rights, send a request to pixelcoregroup@gmail.com with "Personal Data" in the subject line. We will process the request within 30 calendar days.

11. Children

Our Website is not intended for children under the age of 16 (in accordance with Art. 8 GDPR). We do not knowingly collect personal data from children. If we become aware of such collection, the data will be promptly deleted.

Under Ukrainian legislation, the processing of personal data of minors is permitted only with the consent of parents or legal guardians.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to the rights and freedoms of users, we will notify the affected users and, where necessary, the competent supervisory authorities in accordance with GDPR requirements (Art. 33–34).

13. Policy Changes

We may update this Policy to reflect changes in our data processing practices or legislation. The updated version will be published on this page with the current date.

In case of significant changes, we will notify registered users by email no later than 14 days before the changes take effect.

14. Contacts

For all questions related to personal data processing:

  • Email: pixelcoregroup@gmail.com
  • Telegram: @pixelcoreibot
  • Website: pixelcore.it.com

Please also review our Terms of Use for a complete understanding of the rules governing the use of the Website.

This Privacy Policy does not constitute a public offer and is for informational purposes only, unless otherwise expressly provided by applicable law.

© 2026 PIXEL CORE. All rights reserved.