Personal data processing policy
Legal force. Only the Russian version of this document has legal effect. This translation is provided for convenience; if the two differ in any way, the Russian original governs — read the original. The service is operated under the law of the Russian Federation, and the Russian text is the one a court, a regulator and the parties rely on.
Before the public launch: the owner of the service must fill in, in section 10, the name of the Operator (or the sole trader’s full name), its tax and registration numbers, its address and a working email address for personal data enquiries. These details are not in the repository, so they have deliberately not been filled in: a policy that does not name the Operator does not satisfy the duty under part 2 of article 18.1 of Federal Law No. 152-FZ.
1. General provisions and scope
1.1. This policy sets out how the owner of the “Kristina AI” service, published at kristina-ai.ru (the “Operator” and the “service” respectively), processes and protects personal data. It is the publicly available document required by part 2 of article 18.1 of Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”.
1.2. The policy applies to the processing of personal data connected with the use of the website and the account area, and with the provision of services under the public offer.
1.3. The Operator processes only data that serves the purposes stated in section 4, and for no longer than those purposes require (article 5 of Law No. 152-FZ).
1.4. The service is intended for use by companies and sole traders and is not designed to be used independently by anyone under eighteen. The Operator does not request the personal data of minors; if it finds such data, it stops processing and destroys it.
2. The roles of the parties
2.1. The service processes two different categories of personal data, and the Operator’s role differs between them. Confusing the two roles is the source of most mistakes in documents of this kind, so they are separated here explicitly.
2.2. Data about users of the service — the people who register a company and work in the account area. For this data the owner of the service is the operator of personal data. The text of the consent given at registration, by a separate tick box, is published here.
2.3. Data about the customers and visitors of the client company, which reaches the service through the connected channels. For this data the client company itself is the operator: it determines the purposes and the scope of processing. The owner of the service processes such data on that company’s instructions (part 3 of article 6 of Law No. 152-FZ), does not determine the purposes of processing and does not use the data for its own purposes.
2.4. It is for the client company to ensure that there is a lawful basis for transferring its customers’ data to the service, to notify those customers about the processing and to obtain the necessary consents. The allocation of roles and the terms of the processing instruction are set out in section 8 of the public offer and in a separate agreement or addendum.
2.5. When processing data on instructions, the Operator complies with part 3 of article 6 and with articles 18.1 and 19 of Law No. 152-FZ, including confidentiality and security measures, to the same standard as for its own data.
3. Categories of data subjects and of data processed
3.1. Users of the service: email address; password held as a cryptographic hash; role in the company and account status; the company name and the user’s link to it; access records — dates of sign-in, email confirmation and password change; plan, payments and access period; the date and revision of the documents accepted.
3.2. Customers and visitors of client companies: what they tell us in an enquiry — name, telephone number, email address, the content of the conversation; details of the enquiry created; the technical identifiers needed for a conversation to continue and for the answer to reach the person who asked.
3.3. Technical data about requests to the service, including the IP address and data stored by the browser, to the extent needed for sign-in, for continuing a conversation and for protection against abuse. What this consists of and why is set out in the cookie policy.
3.4. The Operator does not request and does not deliberately process special categories of personal data or biometric personal data. The client company undertakes not to transfer such data to the service.
4. Purposes of processing and legal grounds
4.1. Processing is carried out solely for the purposes listed below and on the following grounds:
- registration, authentication and provision of access to the service — performance of a contract to which the data subject is a party (clause 5 of part 1 of article 6 of Law No. 152-FZ) and the consent of the data subject (clause 1 of part 1 of article 6);
- taking payment, issuing the fiscal receipt, accounting and tax records — performance of the contract and duties imposed on the Operator by law (clause 2 of part 1 of article 6);
- handling enquiries from the client company’s customers and creating requests — the instruction of the client company (part 3 of article 6);
- dealing with enquiries, complaints and refund requests, and defending the rights of the Operator and its clients — the legitimate interests of the Operator (clause 7 of part 1 of article 6);
- protecting the service against unauthorised access and abuse — the legitimate interests of the Operator (clause 7 of part 1 of article 6);
- proving the fact, the date and the revision of the consent obtained — performance of the duty to demonstrate that consent exists (part 1 of article 9).
4.2. Advertising and marketing messages are sent only where a separate, freely given consent exists. Refusing such consent, or withdrawing it, has no effect on registration, on access to the service or on the terms of the plan.
4.3. No processing is carried out for other purposes. A new purpose requires its own legal basis and an amendment to this policy before such processing begins.
5. Disclosure to third parties
5.1. The Operator does not sell personal data and does not disclose it for advertising purposes.
5.2. Data is disclosed only to those whose involvement is necessary in order to provide the services: hosting and computing providers, the payment service, the messaging services behind the connected channels, language model providers, and the systems into which the client company itself has chosen to export its enquiries. Each disclosure is permitted only where there is a legal basis and a contract obliging the recipient to keep the data confidential and to process it only on the Operator’s instructions.
5.3. Who these recipients are depends on the channels and integrations the company has connected. The current list is provided to the client company on request and recorded in the contract or the processing instruction; it is disclosed before processing begins, not afterwards.
5.4. The content of conversations and personal data are not passed on for the training of artificial intelligence models. The Operator undertakes to include a corresponding prohibition in its contracts with language model providers and not to engage providers who will not accept that term.
5.5. Data is disclosed to state authorities only on the grounds, to the extent and in the manner established by law.
6. Processing and retention periods
6.1. Account and company data is processed for as long as the contract is in force and the account exists.
6.2. Payment-related data is kept for the periods established by the legislation on accounting and on taxes and levies.
6.3. Data about the customers and visitors of a client company is processed for as long as it is needed in order to provide services to that company, and is deleted on that company’s instruction or when the contract with it ends, unless the law requires longer retention.
6.4. Technical data collected to protect against abuse is processed for the period needed for that purpose and is not used for anything else.
6.5. Once the purposes of processing have been achieved, on withdrawal of consent, or on deletion of the account, data is destroyed or de-identified within the periods set by article 21 of Law No. 152-FZ, except for data the Operator is required by law to keep.
7. Cross-border transfers
7.1. Personal data is transferred across borders only where the requirements of article 12 of Law No. 152-FZ are met, including notifying the authorised supervisory authority of the intention to make such a transfer before it begins.
7.2. If a person located outside the Russian Federation is engaged in order to provide the services, the categories of data transferred and the destination country are disclosed to the client company and in this policy before the transfer begins, not after the event.
7.3. The Operator ensures that the recording, systematisation, accumulation, storage, updating and retrieval of the personal data of citizens of the Russian Federation is carried out using databases located within the Russian Federation (part 5 of article 18 of Law No. 152-FZ).
8. Security
8.1. The Operator takes the legal, organisational and technical measures required by articles 18.1 and 19 of Law No. 152-FZ, including: access separated by role, isolation of one company’s data from another’s, storage of passwords solely as an irreversible cryptographic hash, logging of actions performed on personal data, and rate limiting of requests to the service.
8.2. Access to personal data is given only to those employees and engaged persons who need it in order to carry out their duties, and only to the extent those duties require. Such persons are bound by a duty of confidentiality.
8.3. The Operator appoints a person responsible for organising the processing of personal data (article 22.1 of Law No. 152-FZ) and adopts internal documents governing how processing is carried out.
8.4. On establishing that personal data has been transferred unlawfully or accidentally, the Operator notifies the authorised supervisory authority within the periods set by part 3.1 of article 21 of Law No. 152-FZ and informs the client companies affected.
8.5. Transmission of data over the Internet cannot be made absolutely secure. The measures taken reduce the risk but do not remove it, and the Operator does not claim otherwise.
9. The rights of the data subject
9.1. A data subject has the right to: obtain confirmation that processing is taking place and the information listed in part 7 of article 14 of Law No. 152-FZ; require that incomplete or inaccurate data be corrected, blocked or destroyed; withdraw consent where processing is based on consent; object to decisions which produce legal effects and are taken solely on the basis of automated processing (article 16); and complain about the Operator’s actions to the authority responsible for protecting the rights of data subjects or to a court.
9.2. A request is made through the request form or using the contact details in section 10. How requests are handled, and within what periods, is described on the “Data rights and deletion” page.
9.3. Before acting on a request the Operator may ask for information confirming the applicant’s identity and their involvement in a relationship with the Operator (part 3 of article 14 of Law No. 152-FZ). This protects the data subject: acting on a request without establishing who made it would mean disclosing data to a stranger.
9.4. Where data is processed on the instructions of a client company (clause 2.3), the Operator has no authority to deal with it on its own: it passes the request to that company and tells the applicant that it has done so.
10. Operator details and contacts
Mandatory before publication: the full name of the company or the sole trader’s full name, the tax number (INN), the registration number (OGRN or OGRNIP), the registered and postal address, and a working email address and telephone number for personal data enquiries.
The same details are published on the “Contacts” page, in section 1 of the consent to the processing of personal data and in section 11 of the public offer. Details that differ between documents are worse than details missing from all of them.
11. Changes to the policy
11.1. The version in force is always published at this address; its number and date appear at the top of the document.
11.2. Changes affecting the purposes, the legal grounds or the categories of data processed take effect no earlier than their publication and do not apply to processing carried out before that moment.
11.3. The Operator notifies client companies of material changes by a means that allows the fact of notification to be established.