Privacy policy
(personal data processing)
Contents
- General provisions
- Terms and definitions
- What personal data we collect
- Purposes of personal data processing
- Legal grounds for processing
- Methods and periods of processing
- Transfer of data to third parties
- Measures to protect personal data
- Rights of the data subject
- Use of cookies
- Data of minors
- Changes to the policy
- Liability
- Contact information
1. General provisions
1.1. This Privacy Policy (hereinafter — the Policy) defines the procedure for processing and protecting the personal data of users of the Service located at https://t.me/cla1ve_boost_bot?start=site.
1.2. The personal data operator is: Sole Proprietor MAMATISAKOV ELMURAT SAPARBEKOVICH, OGRNIP 326690000001430, TIN 690606792301 (hereinafter — the Operator).
1.3. The Policy is developed in accordance with Federal Law No. 152-FZ of 27.07.2006 "On Personal Data" (hereinafter — FZ-152).
1.4. Use of the Service constitutes the User's unconditional consent to this Policy and the personal data processing conditions set out in it.
2. Terms and definitions
2.1. Personal data — any information relating to a directly or indirectly identified or identifiable natural person (the data subject).
2.2. Personal data processing — any action (operation) or set of actions (operations) performed on personal data with or without the use of automation tools.
2.3. Confidentiality of personal data — a requirement, mandatory for the Operator, not to allow the disclosure of personal data without the consent of the data subject.
2.4. User (Data subject) — a natural person using the Service.
2.5. Service — a software system (Telegram bot) providing access to a database of game-service providers.
3. What personal data we collect
3.1. The Operator processes the following categories of Users' personal data:
3.1.1. Data provided by Telegram upon authorization:
- Unique Telegram identifier (User ID)
- Username
- First and last name (if specified in the Telegram profile)
3.1.2. Data provided by the User when using the Service:
- Game account credentials (login – password or other) for the Provider to log in to the game account
- Verification code for the Provider to log in to the account
- Information about orders and preferences
- Message history
3.1.3. Technical data:
- Data on activity in the Service (logs)
- Cookies and similar technologies
Important
3.2. The Operator does NOT process special categories of personal data (racial origin, political views, religious beliefs, health, intimate life).
3.3. The Operator does NOT process biometric personal data.
4. Purposes of personal data processing
4.1. Personal data is processed by the Operator for the following purposes:
- 4.1.1. Providing access to the Service functionality
- 4.1.2. Identifying the User in the system
- 4.1.3. Processing orders and enabling interaction between Customers and Providers
- 4.1.4. Communicating with the User (technical support, order notifications)
- 4.1.5. Resolving disputes and claims
- 4.1.6. Preventing fraud and ensuring security
- 4.1.7. Improving the quality of the Service, analyzing user activity
- 4.1.8. Fulfilling obligations to the User under the offer agreement
- 4.1.9. Complying with the requirements of applicable Russian law
4.2. Personal data is processed on the basis of the User's consent, expressed by starting to use the Service.
5. Legal grounds for processing
5.1. The legal grounds for processing personal data are:
- 5.1.1. Federal Law No. 152-FZ of 27.07.2006 "On Personal Data"
- 5.1.2. The data subject's consent to the processing of their personal data
- 5.1.3. Performance of a contract to which the data subject is a party (Public Offer)
- 5.1.4. The need to process data to protect life, health, or other vital interests
6. Methods and periods of personal data processing
6.1. Personal data is processed both with and without the use of automation tools.
6.2. Processing methods include:
- Collection
- Recording
- Systematization
- Accumulation
- Storage
- Updating (refreshing, modifying)
- Retrieval
- Use
- Transfer (distribution, provision, access)
- Anonymization
- Blocking
- Deletion
- Destruction
6.3. Periods of personal data processing:
6.3.1. Personal data is stored for the entire period of the User's use of the Service.
6.3.2. After an account is deleted, personal data is blocked and subject to destruction within 30 (thirty) days, except where the law requires its retention.
6.3.3. Financial transaction data is stored for 5 (five) years in accordance with the requirements of Russian tax law.
7. Transfer of personal data to third parties
7.1. The Operator may transfer personal data to third parties in the following cases:
- 7.1.1. To Service Providers — to the extent necessary to complete the order (contact information).
- 7.1.2. To payment systems and banks — for processing payments.
- 7.1.3. To the Telegram service — within the use of the Telegram API.
- 7.1.4. To hosting providers and IT contractors — to ensure the operation of the Service.
- 7.1.5. To law enforcement authorities — upon official requests within the framework of applicable Russian law.
7.2. All third parties gaining access to personal data are required to maintain confidentiality and ensure its protection.
7.3. The Operator does NOT transfer personal data to third parties for marketing purposes without the User's separate consent.
7.4. Cross-border transfer of personal data (outside Russia) is NOT carried out, except when using Telegram servers (in which case protective measures are applied in accordance with FZ-152).
8. Measures to protect personal data
8.1. The Operator takes the necessary legal, organizational, and technical measures to protect personal data from unlawful access, destruction, modification, blocking, copying, and distribution.
8.2. Protective measures include:
- 8.2.1. Use of secure data transmission channels (HTTPS, SSL/TLS)
- 8.2.2. Encryption of personal data at rest
- 8.2.3. Restricting access to personal data (access only for authorized persons)
- 8.2.4. Regular data backups
- 8.2.5. Use of antivirus software
- 8.2.6. Training staff in personal data processing rules
- 8.2.7. Developing internal security policies and procedures
8.3. In the event of a leak or unauthorized access
The Operator undertakes to:
- 8.3.1. Immediately take measures to eliminate the consequences
- 8.3.2. Notify Users of the incident
- 8.3.3. Notify Roskomnadzor (within 24 hours of detection)
9. Rights of the data subject
9.1. The User has the right to:
- 9.1.1. Receive information about the processing of their personal data
- 9.1.2. Demand the correction, blocking, or destruction of personal data if it is incomplete, outdated, or inaccurate
- 9.1.3. Withdraw consent to the processing of personal data
- 9.1.4. Access their personal data
- 9.1.5. Demand that the processing of personal data be stopped
- 9.1.6. Appeal the Operator's actions or inaction to Roskomnadzor or in court
9.2. To exercise their rights, the User sends a written request to the Operator: Telegram: @Cla1ve or by email: cla1veisdetta@gmail.com.
9.3. The Operator is obliged to consider the request and provide a response within 30 (thirty) days of receiving it.
9.4. Upon withdrawal of consent to processing, the Operator stops processing and deletes the personal data within 30 days, unless otherwise provided by the contract or Russian law.
10. Use of cookies and similar technologies
10.1. The Service uses cookies and similar technologies to:
- 10.1.1. Ensure the operation of the Service
- 10.1.2. Analytics and usage statistics
- 10.1.3. Improve the user experience
10.2. The User can disable cookies in their browser settings, but this may limit the functionality of the Service.
10.3. The Operator may use web analytics services (e.g. Yandex.Metrica, Google Analytics) to collect anonymized usage statistics of the Service.
See more in the Cookie Policy.
11. Security of minors' data
11.1. The Service is intended for persons aged 18 and over.
11.2. If the User is under 18, use of the Service is only possible with the consent of parents or legal guardians.
11.3. The Operator does not intentionally collect personal data of minors. If the Operator becomes aware that personal data of a person under 18 has been collected without parental consent, such data will be deleted immediately.
12. Changes to the Privacy Policy
12.1. The Operator may unilaterally make changes to this Privacy Policy.
12.2. A new version of the Policy takes effect once it is published in the Service, unless the new version provides otherwise.
12.3. The User is obliged to independently monitor changes to the Privacy Policy.
13. Liability
13.1. In the event of loss or disclosure of personal data through the Operator's fault, the Operator is liable in accordance with applicable Russian law.
13.2. The Operator is not liable for:
- 13.2.1. Loss or disclosure of personal data caused by the User
- 13.2.2. Actions of third parties who gained access to personal data due to the User's use of the Internet
- 13.2.3. Personal data that became publicly available through the User's fault
14. Operator's contact information
14.1. For questions related to the processing of personal data, the User may contact the Operator:
Operator details
14.2. Inquiries regarding personal data protection are reviewed within 30 (thirty) days of receipt.
15. Final provisions
15.1. All disputes related to the processing of personal data are resolved through negotiations. If agreement cannot be reached, the dispute is referred to the courts at the Operator's location in accordance with applicable Russian law.
15.2. Applicable Russian law governs this Policy and the relationship between the User and the Operator.
15.3. This Policy is an integral part of the Public Offer (Agency Agreement).