Privacy notice
Who we are
Andrii Co. is a Washington for-profit corporation employing one or more Notaries Public licensed in the State of Washington, USA. We provide mobile notarization and apostille services across the Greater Seattle area, with an office in Bothell, WA, where we meet clients by appointment. We also do business as Bellevue Notary (bellevuenotary.net, +1 425 800 8688), a trade name of Andrii Co. on file with the Washington State Department of Revenue; this notice covers it too, including texts to and from that number.
The person responsible within the meaning of the GDPR and other national data protection laws of the member states as well as other data protection regulations is:
Andrii Co.Mailing address (post only — not an office or a meeting place):
816 Evergreen Point Rd Unit 288
Medina, WA 98039-4780
UBI number: 604505773
D-U-N-S® Number: 117198250
Email: privacy@andrii.co
Customer portal
If you create an account in our customer portal (hosted at andrii.net, separate from this marketing site), we process the personal data you enter there to schedule and deliver your services:
- Account details — your name, email address, and phone number.
- Passkey credentials — we use passkeys (WebAuthn) instead of passwords. Your device keeps the private key, and biometrics such as Face ID, Touch ID, or Windows Hello never leave your device; we store only the matching public key and a device label.
- Appointment details — the service you book, the date and time, and any meeting address you enter (including a customer address for mobile signings).
- Order, document, and shipment details — the documents you add to an order (type and apostille destination), any draft you upload, the resulting notarized or apostilled files, and the recipient name, address, phone, and email for any shipment.
We are the controller of this portal data. It is stored on our application backend at andrii.net, and a sign-in token is kept in your browser's localStorage (not a cookie) to keep you signed in. We use this data only to provide, schedule, perform, ship, and account for the services you request, and we do not sell it or share it with advertising networks.
Retention. We keep your account and order records for as long as your account is active and for as long as professional, tax, and legal recordkeeping requires. Entries in the notarial journal are kept for 10 years under RCW 42.45.180, and audio-video recordings of any remote online notarization are retained for the period required by Washington's notary rules (chapter 308-30 WAC).
Identity verification
Notarial work requires us to establish who is signing, and the paperwork for a power of attorney, a consent, or an apostille has to repeat a person's details exactly as their identity documents show them — often in the destination country's own script. When the service you ask for needs them, we therefore record, in addition to the account details above:
- Your name in full — both in its native script (for example Cyrillic) and in Latin letters, because the destination country's document usually requires a particular one of them.
- Your date of birth.
- Your taxpayer number, where the destination document requires one — for example a Ukrainian ІПН/РНОКПП or a Russian ИНН.
- Your identity document — which kind it is, its number, the country that issued it, and when it expires (a passport, or a driver's licence or ID card).
- Your registration (residence) address, where the document requires it.
- Our own working notes about your matter.
Most of this you give us directly. Some of it we read from the document itself: rather than retype it, our notary may scan the machine-readable strip of a passport or the barcode on a driver's licence, which is quicker and avoids transcription mistakes. Documents you upload to an order — and the finished notarised or apostilled files — also routinely contain identity details, scans, and signatures.
If your passport has a chip. With your agreement, our app can read it on the device in front of you. The photograph and the signature held in the chip never leave that device and we never receive them. What reaches our server is only the chip's cryptographic security data, which lets the server check for itself that the passport is genuine and unaltered. We keep the result of that check — confirmed, or not proven, and why — not the data it was performed on.
How we protect it. This profile is encrypted in our database under a key kept apart from it. It is visible only to the notary: it never appears in your account pages, in any list, in a booking made through an AI assistant, or in anything a courier or other third party receives. The one exception is you — "Download my data" on the Account page includes your own profile (our internal working notes excepted).
Legal bases. Performing the service you asked for — Art. 6(1)(b) GDPR — and, for the notarial act itself, our legal obligation as a Washington notary — Art. 6(1)(c) GDPR, RCW 42.45.
How long we keep it. For as long as your account exists; it is erased when the account is deleted. The exception is the notarial journal: an entry already recorded there must be kept for 10 years under RCW 42.45.180 and cannot be deleted on request.
Booking through an AI assistant
We publish a connector that lets an AI assistant — ChatGPT, Claude, or another that supports one — look up our availability, quote a price, and send us a booking request on your behalf. Using it is entirely your choice, and nothing else in this notice depends on whether you do.
What reaches us. Only what you ask the assistant to send: the service you want, your full legal name, an email address and/or a phone number, the meeting address for a mobile signing, your preferred time, how many documents and of what kind, and any note you add. A booking made this way is a request, not a confirmed appointment — we follow up to confirm it.
What we send back. Availability, prices, turnaround estimates, and general apostille guidance carry no personal data. For a request you have already made, a status check returns only its reference, the service, its status and its times — deliberately never the meeting address, the names on the order, or our notes, so that none of those can be copied into a chat transcript. If you additionally sign in through the assistant, it can list, book, reschedule and cancel your own bookings, and that listing does include each booking's location.
No payment ever happens in the chat. We take no card or bank details through an assistant.
The assistant's provider sees your conversation. Whatever you type to ChatGPT, Claude, or any other assistant is processed by that provider under its own privacy policy and its own terms with you, before any of it reaches us. We are not the controller of that conversation and we cannot delete it for you — ask the provider. Once your request reaches us it becomes an ordinary booking record, covered by the rest of this notice.
Text messages (SMS)
We text a mobile number only as described in the “Text messages (SMS)” section of our Terms, from +1 833 876 5431, +1 877 987 7987, and +1 425 800 8688 (our Bellevue Notary line).
When we text you. Account texts — sign-in and verification codes, account and appointment notifications, and order status and delivery updates — go only to a number that has agreed to them: by ticking the account-texts box on our booking or sign-up form or on the customer portal's profile page, or by texting us from that number the verification code our website shows you, or START. When you text us, we reply in that conversation. The first time a number texts us or agrees to our texts we send it one welcome text, and never more than one in any 12 months for that number. Marketing texts go only to customers who separately opted in to them.
What we record. Your mobile number; each consent decision with the form or text it came from, the version of the wording you saw, and the time; the texts we send you and the texts you send us; and, if you reply STOP, the number and the time of the opt-out.
Legal bases. Your consent — Art. 6(1)(a) GDPR — for account and marketing texts; performance of a contract — Art. 6(1)(b) GDPR — for answering a text you send us about your booking or order; our legitimate interest — Art. 6(1)(f) GDPR — in keeping the record of each consent and of each opt-out, so that we can show why we texted a number and never text a number that said STOP.
Who receives it. Only the providers that carry our texts — Telnyx and, for texts to a number we used previously, Infobip — which receive your number and the messages only to deliver them and to register our numbers with the mobile carriers. We never sell, rent, or share your mobile number as a texting contact, or your text-messaging consent, with anyone else, for marketing or for any other purpose.
How long we keep it. The texts we send you and the texts you send us, 12 months; consent records, for as long as the account or booking they belong to exists; an opt-out, until you reply START.
Stopping. Reply STOP to any of our numbers to stop every text from all three, START to resume, HELP for help. A keyword is acted on automatically when it is the whole message; if you ask us in other words to stop texting you, a person reads it and we stop. To stop only marketing texts, use Communication preferences in the customer portal.
Data we collect
- Request logs. Our hosting provider records the IP address, user agent, and timestamp for every page request. Kept for 14 days, used only for security, abuse prevention, and debugging.
- Error reports. When something breaks in your browser — a script fails, a file will not load — the page sends us a short technical description: the error message, the file and line, and the address of the page you were on. Web addresses are cut off before any
?or#, so the identifiers and one-time links they can contain are never sent, and anything resembling an email address or a security token is masked out of the message. Your IP address is not stored and nothing identifies you or your session; identical reports are merged into a single counter. Kept for at most 30 days on our own server, and used only to find and fix faults. Legal basis: our legitimate interest in a working service — Art. 6(1)(f) GDPR. - Cookie choice. A single JSON record in your browser's
localStorage. Never transmitted to us. See the cookie table below. - Analytics (only if you opt in). Google Analytics 4 measures aggregate visits and pages viewed. When you reject, GA receives only a cookieless modeling ping with no identifier.
- Information you send us. Names, document text, contact details, and any attachments — only what you choose to email to notary@andrii.co or text to our numbers (see "Text messages (SMS)").
- Payment data. When you use the "Buy" Stripe button, card details go straight to Stripe — we never see them.
- Booking, identity, and order data. If you actually engage us, we process more than the above — see "Customer portal", "Identity verification", and "Booking through an AI assistant" for what, why, and for how long.
Purposes and legal bases
Where the GDPR or a similar law applies, we process personal data only on a legal basis. In short:
| Processing | Legal basis |
|---|---|
| Account, booking, and order data — scheduling, performing, shipping, and invoicing the services you request. | Performance of a contract — Art. 6(1)(b) GDPR. |
| Establishing who is signing, and recording the identity details a notarial act, an apostille, or a consular document has to carry. | Performance of a contract — Art. 6(1)(b) GDPR; and, for the notarial act itself, legal obligation — Art. 6(1)(c) GDPR, RCW 42.45. |
| Keeping the notarial journal and the audio-video recordings of remote online notarizations. | Legal obligation — Art. 6(1)(c) GDPR; RCW 42.45.180 and chapter 308-30 WAC. |
| Security logs, sign-in IP and device history, and fraud prevention. | Our legitimate interest in keeping the service secure — Art. 6(1)(f) GDPR. |
| Analytics cookies, and texts to your mobile number — account texts and, only if you opted in to them, marketing texts. | Consent — Art. 6(1)(a) GDPR; off by default and withdrawable at any time. |
Cookies and similar technologies
Cookies are small text files placed on your device to store data that can be recalled by a web server in the domain that placed the cookie. We use cookies — and equivalent browser storage (localStorage) — for storing and honoring your preferences and settings and, with your permission, for analyzing how this site performs. We do not use cookies for advertising, social-media targeting, or sign-in. Our separate customer portal does have a sign-in, but it keeps its sign-in token in your browser rather than in a cookie — see the “Customer portal” section below.
This site uses only the storage listed below. Optional categories are off by default; choose them via the cookie banner on first visit, or at any time via the "Cookie settings" link in the footer of any page. Where required, we obtain your consent before placing or using optional cookies that are not (i) strictly necessary to provide the website, or (ii) for the purpose of facilitating a communication.
| Name | Provider | Purpose | Retention |
|---|---|---|---|
consent_v1 | Andrii Co. (this site) | Stores your cookie choice as a single JSON record in localStorage. | 13 months in your browser only. |
pap_lang | Andrii Co. (this site) | Remembers your last selected language so we don't ask again. | Until you clear your browser data. |
_ga, _ga_RS49EHPYXJ | Google Analytics 4 (Google LLC) | Distinguishes users and persists session state for aggregate traffic measurement. | 2 years — set only after you opt in. |
andrii_portal_token | Andrii Co. (customer portal) | Keeps you signed in to the customer portal — a sign-in token in localStorage (not a cookie), set only when you sign in. | Until you sign out or the token expires (14 days). |
andrii_apple_resume:booking | Andrii Co. (this site) | Briefly saves your in-progress booking form so it can be restored after a sign-in round-trip or a reload. Never contains your cookie choice or a sign-in token. | 15 minutes in your browser only. |
If your browser sends a Global Privacy Control (GPC) signal, we honor it as a rejection of optional cookies — we record an automatic "reject all" without asking you again.
You also have browser-level tools to control cookies and similar technologies. Most browsers let you limit which sites can set cookies, clear cookies that have already been set, or block them entirely; you can use those controls to withdraw your consent at any time. Doing so may break parts of this site that depend on the storage marked "Always on" above (language switching, payment processing).
Third parties
- Google Analytics 4 (Google LLC). We use Consent Mode v2: when you reject analytics, GA receives only a cookieless modeling ping without your identifier. Google privacy policy.
- Stripe (Stripe, Inc.). If you pay online via a Stripe-hosted checkout, Stripe receives your payment details directly — we never see your card. Stripe privacy notice.
- CDN providers —
unpkg.comfor Phosphor Icons,fonts.googleapis.comandfonts.gstatic.comfor typefaces. These providers see your IP address as a side effect of serving their files. - Firebase Hosting (Google LLC). Serves this site and produces the request logs described above.
- Google Maps Platform (Google LLC). Address lookup and routing for bookings — when you type a meeting or delivery address, our server sends it to Google to suggest and locate addresses.
- Google Cloud (Google LLC). Hosts our application backend at
andrii.netand stores its encrypted backups. - Google Workspace / Gmail (Google LLC). Delivers our transactional email — verification codes, booking confirmations, receipts.
- Infobip (Infobip Ltd.). No longer sends our SMS. Inbound texts to a previously used number may still transit their network.
- Telnyx (Telnyx LLC). Sends and receives our SMS — sign-in and verification codes, the verification code you text us to confirm your number, the one-time welcome text, account and appointment notifications, order status and delivery updates, the texts you send us and our customer-service replies, the automatic STOP, HELP and START answers and, only for customers who opted in to them, marketing texts — and handles the toll-free and A2P messaging registration for our numbers. It receives your mobile number and the content of those messages, which we give it only so that it can deliver them.
- Apple (Apple Inc.). Sign in with Apple, if you choose it, and push notifications for our iOS app.
- AI assistant providers (for example OpenAI, Anthropic) — only if you choose to reach us through an assistant. That provider processes your conversation under its own privacy policy before any of it reaches us; we send it nothing on our own initiative and have no access to your chat history. See "Booking through an AI assistant" above.
- MaxMind GeoLite2. Approximate location of a visitor's IP address, resolved locally on our own server — no data is sent to MaxMind.
- Nova Poshta (including its Ukrainian domestic service). Receives the recipient name, phone, and address of shipments you request.
- CDEK. The same, for deliveries to the CIS region.
- FedEx, DHL Express, UPS, USPS, and Canada Post. The same, for mail and courier shipments to other destinations.
- RON platforms (Proof / BlueNotary). Will be named here when remote online notarization launches — the session then runs on the platform under its own terms.
- SANS Internet Storm Center / DShield (SANS Institute, USA). Our server exposes a decoy ("honeypot") service that no customer ever reaches: it authenticates nobody, holds no data, and exists only to observe attacks on us. The sign-in attempts made against it are submitted to the Internet Storm Center, a public attack-telemetry dataset used by security researchers — the time, the source IP address, and the username and password the attacker offered, which are often credentials stolen from someone else and replayed. ISC publishes what it receives and states that submitted data cannot be deleted, so a submission is permanent, public, and beyond our power to recall. No customer data is involved: nothing from your account, your documents, or anything you send us is ever submitted. Legal basis: our legitimate interest in network and information security (Art. 6(1)(f) GDPR). ISC privacy policy.
- AbuseIPDB (AbuseIPDB LLC, a Pennsylvania limited liability company, USA). A public IP-reputation database that network operators query before deciding whether to block an address. When an address attacks us, we may file a report against it: the address, the time, and a short description of what was attempted, written from a fixed vocabulary. Anyone who looks that address up can read the report, AbuseIPDB's terms let it republish reports, and reports do not expire — only their weight decays over time. Our reports deliberately carry no credentials, no typed input, and nothing else supplied by the reported party. AbuseIPDB operates a takedown-request procedure for a report you believe was made in error. Legal basis: our legitimate interest in network and information security (Art. 6(1)(f) GDPR). AbuseIPDB privacy policy.
We do not sell your personal data and do not share it with advertising networks. No mobile information will be sold or shared with third parties or affiliates for promotional or marketing purposes. Your text-messaging opt-in data and consent (your mobile number and your agreement to receive texts) are never sold, rented, or shared with any third party or affiliate, for any purpose. The only exception is the carriers that deliver for us: the providers that carry our texts (Telnyx, and Infobip for inbound texts to a number we used previously) receive them only to carry them, and for a shipment you ask for, the courier delivering it receives the recipient's phone number with the address — never your consent to texts. Marketing texts are sent only to customers who separately opted in to them (the marketing box on our booking form, or the Communication preferences in the customer portal); that consent is recorded with your account and can be withdrawn there or by replying STOP at any time.
If someone ships documents to you
A customer may ask us to deliver notarized or apostilled documents to you. In that case we received your name, delivery address, phone number, and possibly email address from that customer — not from you. We use these details only to deliver that shipment: they are passed to the carrier handling it (for example FedEx, DHL Express, UPS, USPS, Canada Post, Nova Poshta, or CDEK) and are kept as part of the order record.
You have the same rights over these details as our customers — access, correction, deletion, objection — described under "Your rights" below. To exercise them, email privacy@andrii.co.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Correct or delete it;
- Object to processing based on our legitimate interests, and ask us to restrict processing while your request is checked;
- Withdraw consent at any time — use the "Cookie settings" link in the footer of any page; for texts, reply STOP or use Communication preferences in the customer portal;
- Receive a copy of your data in a portable format;
- Complain to a regulator — for example, the Washington State Attorney General, the U.S. Federal Trade Commission, or your local EU/UK data protection authority.
If you have a portal account, the two most common requests are self-service: "Download my data" on the Account page gives you a copy of your data, and "Delete my account" deletes your account.
To exercise any right, email privacy@andrii.co. We aim to respond within 14 days.
International transfers
We are based in Washington State, USA. If you contact us from outside the United States, your personal data is transferred to the US. We rely on your consent and on contractual safeguards with sub-processors (e.g., Google's Standard Contractual Clauses for Analytics and Firebase Hosting).
Retention
- Cookie record: 13 months in your browser only.
- Request logs: 14 days.
- Sign-in IP and device history: 180 days.
- API request logs: kept in size-rotated files on our own server — when the fixed space fills, the oldest entries are overwritten.
- Identity profile (names, date of birth, taxpayer number, identity-document details, registration address): kept while your account exists, erased when it is deleted — except anything already recorded in the notarial journal.
- Notarial journal entries: 10 years, as required by the Revised Code of Washington 42.45.180.
- Email correspondence: deleted within 18 months after the matter is closed, unless we are required to keep it longer.
- Text messages: the texts we send you and the texts you send us, 12 months; consent and opt-out records as described under "Text messages (SMS)".
Children
This site is not directed at children under 13, and we do not knowingly collect their data.
Changes to this notice
We update this notice when our practices change. The "Last updated" date above always reflects the current version.