Contents
01 /

Identity of the Data Controller

This Privacy Policy describes how Dmytro Sheremet, operating as sheremet.dev ("we", "us", "our"), collects, uses, stores, and protects personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and other applicable data protection legislation.

Name Dmytro Sheremet (sheremet.dev)
Location Split, Croatia
Telegram @sheremetdev
Website sheremet.dev
02 /

Scope of This Policy

This Policy applies to all personal data processed by sheremet.dev in connection with:

This Policy does not apply to personal data processed by sheremet.dev as a data processor on behalf of clients. In such cases, the client acts as the data controller and the applicable Data Processing Agreement governs that relationship.

03 /

Personal Data We Collect

3.1 Data You Provide Directly

We may collect the following categories when you contact us or engage our services:

3.2 Data Collected Automatically

When you visit sheremet.dev, basic technical information may be collected by our hosting provider (Cloudflare), including: IP address and approximate geolocation, browser type and version, pages visited and time on site, and referring URL.

This data is processed by Cloudflare under their own privacy policy. We do not use cookies for tracking or advertising purposes. Any analytics are anonymous and aggregated.

3.3 Data from Third Parties

We may receive personal data from LinkedIn, referral partners, or public professional directories when assessing a potential engagement.

04 /

Legal Bases for Processing

We only process your personal data when we have a valid legal basis under Article 6 GDPR:

05 /

Purposes of Processing

06 /

Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy or as required by law:

When data is no longer required, it is securely deleted or anonymised.

07 /

Data Sharing and Recipients

7.1 We Do Not Sell Your Data

We do not sell, rent, or trade your personal data to any third party for commercial purposes, ever.

7.2 Sub-processors and Service Providers

We may share your data with trusted third-party service providers acting as data processors, strictly for the purposes described in this Policy:

7.3 Legal Disclosure

We may disclose personal data to competent authorities when required by applicable law, court order, or to protect our legal rights.

08 /

International Data Transfers

Some of our sub-processors are located outside the European Economic Area (EEA), primarily in the United States. Where personal data is transferred to a third country, we ensure appropriate safeguards are in place, including:

You may request details of the specific safeguards by contacting us at the address above.

09 /

Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration:

In the event of a personal data breach likely to result in risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify you without undue delay.

10 /

Your Rights Under GDPR

As a data subject, you have the following rights which you may exercise free of charge by contacting us:

Art. 15 — Access Request a copy of the personal data we hold about you.
Art. 16 — Rectification Request correction of inaccurate or incomplete data.
Art. 17 — Erasure Request deletion where there is no compelling reason for continued processing.
Art. 18 — Restriction Request that we limit processing of your data in certain circumstances.
Art. 20 — Portability Request a machine-readable copy of data you provided, where applicable.
Art. 21 — Object Object to processing based on legitimate interests, including profiling.
Art. 7(3) — Withdraw Consent Withdraw consent at any time without affecting lawfulness of prior processing.
Lodge a Complaint Complain to AZOP (Croatia) or the supervisory authority of your EU member state.

We will respond to all requests within one calendar month. This may be extended by two further months for complex requests, with prior notice.

11 /

Data Processing Agreement

Where sheremet.dev processes personal data on behalf of a Client as a data processor (e.g. when managing infrastructure that handles the Client's users' data), a separate Data Processing Agreement (DPA) will be executed in accordance with Article 28 GDPR.

Clients who require a DPA should contact us prior to commencement of the relevant services.

12 /

Cookies and Tracking

The sheremet.dev website does not use third-party tracking or advertising cookies. Cloudflare may set functional cookies strictly necessary for security and performance (e.g. bot detection). These cookies are not used to build profiles or track you across other websites.

No cookie consent banner is presented because no non-essential cookies are set.

13 /

Children's Data

Our services are directed exclusively at businesses and professional individuals. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that we have inadvertently collected such data, we will delete it promptly.

14 /

Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. We will notify existing clients of material changes by email at least 30 days before the changes take effect.

The current version is always available at sheremet.dev/privacy. The "Effective Date" at the top indicates when it was last revised.

15 /

Contact and Complaints

For any questions, requests, or concerns regarding this Privacy Policy or our data processing practices:

Data Controller Dmytro Sheremet
Website sheremet.dev
Supervisory Authority
Authority Agencija za zaštitu osobnih podataka (AZOP)
Address Selska cesta 136, 10000 Zagreb, Croatia
Web azop.hr
Email azop@azop.hr

This document was prepared in accordance with GDPR (EU) 2016/679. © 2026 Dmytro Sheremet · sheremet.dev · Split, Croatia