SECAMMO PRIVACY AND PERSONAL DATA PROCESSING POLICY
Effective date: 11 September 2026
Operator: Tsibulsky Stanislav Andrianovich (Цибульский Станислав Андрианович)
Status: individual applying the special tax regime “Tax on Professional Income” under Russian law
Russian TIN (INN): 772464065125
Contact Email Address: sales@secammo.ru
Website: https://secammo.ru/
Policy URL: https://secammo.ru/en/privacy/
Translation notice. This English version is provided for convenience. In the event of any discrepancy between the Russian and English versions, the Russian version prevails to the extent permitted by applicable mandatory law.
1. General provisions
1.1. This SecAmmo Privacy and Personal Data Processing Policy (the “Policy”) establishes how the individual identified above as the Operator processes and protects personal data.
1.2. This Policy applies to personal-data processing connected with:
- use of the Website;
- use of SecAmmo Products;
- purchase and use of paid versions, Licences and other paid features of SecAmmo Products;
- issue, activation, renewal, termination and restoration of Licences where the relevant mechanism is used;
- payments and refunds;
- automatic Licence renewal where offered;
- support requests;
- use of individual integrations with third-party information services;
- performance of agreements and compliance with the laws of the Russian Federation.
1.3. Personal data is processed in compliance with the laws of the Russian Federation, including Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”.
1.4. This Policy is a publicly available document. The current version is published at https://secammo.ru/en/privacy/.
1.5. If the law requires separate consent from the data subject for a particular type of processing, that consent is requested separately. Acceptance of the SecAmmo Public Offer does not by itself replace separate consent where such consent is required by law.
1.6. The User is not required to provide personal data that is unnecessary for the User's selected action. However, failure to provide data objectively required to enter into or perform an agreement may make the relevant operation impossible.
1.7. If a new or changed SecAmmo Product requires processing of new personal-data categories, new processing purposes or a new data-transfer procedure, the Operator updates this Policy before that processing begins and, where required by law, obtains separate consent or completes other necessary procedures.
2. Definitions
2.1. Personal data means any information relating to a directly or indirectly identified or identifiable individual.
2.2. Processing of personal data means any action or set of actions involving personal data, performed with or without automated means, including collection, recording, organisation, accumulation, storage, correction, retrieval, use, transfer, provision, access, blocking, deletion and destruction.
2.3. User means an individual who uses the Website or one or more SecAmmo Products, purchases a paid version or Licence, or contacts the Operator.
2.4. SecAmmo Product means individual software, a software component, browser extension, desktop application, online service or other software solution of the Operator distributed or provided under the SecAmmo name.
2.5. SecAmmo Products means the set of individual SecAmmo Products existing while this Policy is in force or released later.
2.6. SecAmmo Pro means the paid mode of the current SecAmmo browser extension. The terms of other paid SecAmmo Products may differ and are established by the applicable offer, agreement, product page and/or Payment Page.
2.7. Website means the official SecAmmo website at https://secammo.ru/.
2.8. Payment Service means an independent third party that technically accepts and processes payments.
2.9. BYOK (Bring Your Own Key) means a model for using a particular third-party information service with an API key supplied by the User.
3. Categories of personal-data subjects
3.1. The Operator may process the personal data of the following categories of individuals:
- Website visitors;
- users of SecAmmo Products;
- purchasers and licensees of paid versions and Licences of SecAmmo Products;
- users who have activated automatic renewal;
- persons contacting support;
- individuals acting as representatives of counterparties;
- end users of Licences purchased under an individual arrangement where the relevant data is needed to perform a separate agreement.
4. Data that may be processed
4.1. In the standard placement and fulfilment of a SecAmmo Pro order directly on the Website, the Operator processes the Contact Email Address and a technical request identifier. The following may also be processed in connection with the order:
- the order identifier;
- the date and time of the order;
- the name of the selected SecAmmo Product and the paid-version or Licence option;
- the Licence Term or other paid term;
- the order price and currency;
- the payment status;
- the payment identifier;
- refund information;
- information about activation, status and termination of automatic renewal where used;
- information required to issue and confirm a receipt;
- other payment information to the minimum extent necessary to perform the agreement.
4.2. For a standard purchase of SecAmmo Pro as part of the SecAmmo browser extension, the Contact Email Address is mandatory and is entered by the User on the SecAmmo checkout page before proceeding to the Payment Service. It is used to fulfil the order, provide the Licence Key, identify an existing Licence and renew it. If another successful payment is made to the same Contact Email Address before delivery of the key for the same new Licence is complete, the address is also used to associate the paid periods with that Licence without creating a separate key. The required data for other SecAmmo Products may differ and is disclosed before the relevant action.
4.3. Where a particular SecAmmo Product uses a licensing system, it may process:
- a technical Licence identifier;
- technical activation identifiers;
- the Licence status;
- the start and end dates of the paid period;
- renewal information;
- information about Licence deactivation, restoration or replacement;
- technical information needed to enforce usage restrictions under the Licence;
- the date and time of requests to the licensing system;
- technical request and session identifiers;
- information about detected errors or Licence abuse.
4.4. When the Website, SecAmmo Product server infrastructure or related APIs are accessed, the following may be processed automatically:
- IP address;
- date and time of the request;
- the requested resource;
- the request processing status;
- the technical request identifier;
- the name and version of the relevant SecAmmo Product;
- the browser or other client-software version;
- the operating-system type and version to the extent transmitted through standard network requests;
- User-Agent and comparable standard technical information;
- error information;
- events required to ensure security, detect abuse and diagnose faults.
4.5. As of the effective date of this Policy, the SecAmmo Website does not use advertising systems, third-party web analytics or technologies that track User behaviour for advertising purposes. Standard web-server, hosting and infrastructure logs may nevertheless contain the technical information listed in clause 4.4 of this Policy.
4.6. When the User contacts sales@secammo.ru, the Operator may process:
- the sender's email address;
- the User's name, if provided;
- the content of the request;
- the order identifier;
- information about the Licence or relevant SecAmmo Product;
- technical information and diagnostic materials voluntarily provided by the User;
- files and other materials attached by the User;
- information needed to verify that the order or Licence belongs to the applicant.
4.7. For ordinary order identification, the Operator does not require the full bank-card number, CVV/CVC, PIN or other secret banking details.
4.8. Certain functions of SecAmmo Products may access third-party information services. Depending on the function selected by the User, the technical indicators needed to perform the request may be transferred to a third-party service, for example a domain name, IP address, hash, email address or another analysis object. Only information required to perform the function selected by the User is transferred.
4.9. Certain integrations may use the BYOK model, under which the User independently supplies an API key for a third-party service. The API key is used solely to provide the User-requested interaction with that service and is not used by the Operator for advertising purposes.
4.10. The specific procedure for transferring and, where applicable, storing an integration API key is stated in the relevant SecAmmo Product and/or its extended feature description. This Policy does not imply that an API key is stored where the particular implementation does not provide for storage.
4.11. If an API key or another technical identifier makes it possible to associate information directly or indirectly with a particular individual, the Operator treats it as confidential data and applies appropriate protective measures.
4.12. The User must not transfer third-party personal data through SecAmmo Products unless the User has lawful grounds for the relevant processing or transfer.
5. Data not intentionally collected
5.1. The Operator neither requests nor stores:
- the full bank-card number;
- the bank-card expiry date;
- the CVV/CVC;
- the PIN;
- transaction confirmation codes;
- online-banking passwords;
- 3-D Secure data and comparable secret payment data.
5.2. Bank-card details are entered on the side of the Payment Service and relevant payment infrastructure.
5.3. In standard purchases of paid versions and Licences of SecAmmo Products, the Operator does not intentionally collect passport details, residential address, date of birth, marital status or other data unnecessary to perform the agreement. Such information may be processed only in individual cases where objectively necessary to perform an individual agreement or expressly required by law.
5.4. The Operator does not intentionally collect special categories of personal data concerning race or ethnicity, political opinions, religious or philosophical beliefs, health or intimate life.
5.5. The Operator does not intentionally collect biometric personal data for the purpose of identifying Users.
6. Purposes of processing personal data
6.1. Personal data is processed solely for specific, predetermined purposes:
- entering into and performing licence and other applicable agreements;
- placing and identifying an order;
- processing and confirming payment;
- providing a Licence Key or other access means where applicable;
- activating a paid version or Licence;
- identifying an active Licence by Contact Email Address where that model applies;
- renewing the term of an active Licence;
- operating and terminating automatic renewal;
- processing refunds;
- issuing and delivering receipts;
- performing the Operator's obligations as a payer of Tax on Professional Income;
- technically operating the Website and SecAmmo Products;
- enforcing technical Licence restrictions;
- information security, abuse detection and prevention of unauthorised use of Licences;
- diagnosing faults;
- responding to User requests and providing technical support;
- considering claims and resolving disputes;
- interacting with third-party services within a function selected by the User;
- complying with the laws of the Russian Federation.
6.2. The Operator does not sell Users' personal data.
6.3. Purchase of a paid version or Licence of a SecAmmo Product does not constitute the User's consent to receive advertising.
6.4. Advertising and marketing messages, if ever used, are sent only where a separate legal basis exists and, where required by law, after the User gives separate consent.
7. Legal grounds for processing
7.1. Depending on the circumstances, the legal grounds for processing personal data are:
- entering into and performing an agreement to which the data subject is a party;
- steps taken at the data subject's request before entering into an agreement;
- performance of duties imposed on the Operator by the laws of the Russian Federation;
- exercise and protection of the rights and legitimate interests of the Operator or third parties in cases permitted by law, provided that the rights and freedoms of the data subject are not infringed;
- the data subject's consent where that consent is required.
7.2. The Operator does not rely on consent as a merely formal ground where processing is objectively necessary to perform an agreement already entered into with the User or to fulfil a statutory duty.
8. Processing procedure
8.1. Processing may be performed with or without automated means.
8.2. Within the stated purposes, the Operator may collect, record, organise, accumulate, store, correct, retrieve, use, transfer, provide, access, block, delete and destroy personal data.
8.3. The Operator does not publicly disseminate Users' personal data unless the User has separately and expressly permitted such dissemination or disclosure is required by law.
8.4. Access to data is granted only to the extent necessary to perform specific tasks.
9. Transfer of data to third parties
9.1. To perform individual operations, the Operator may provide or entrust processing of the minimum necessary amount of data to third parties. Such parties may include:
- the Payment Service;
- banks and payment infrastructure;
- authorised services used to issue and deliver Tax on Professional Income receipts;
- hosting and cloud-infrastructure operators;
- email and technical-communication providers;
- third-party information services accessed by the User through a corresponding SecAmmo Product function;
- persons providing technical support for the infrastructure where such access is objectively necessary;
- public authorities in the cases and manner provided by law.
9.2. Information necessary to process payment is provided to the Payment Service or entered directly by the User. The Operator receives from the Payment Service only the amount of information needed to confirm payment and perform the agreement.
9.3. Full bank-card details are not transferred to the Operator.
9.4. Third-party services are also governed by their own terms of use and privacy policies.
9.5. The Operator transfers to third parties only the minimum amount of data necessary for the particular purpose.
10. Localisation and cross-border transfer
10.1. When collecting personal data of citizens of the Russian Federation, the Operator complies with statutory requirements regarding the use of databases located in the Russian Federation.
10.2. The Operator does not transfer personal data across borders without complying with the requirements of the laws of the Russian Federation applicable to the relevant transfer.
10.3. If a particular SecAmmo Product function requires personal data to be transferred to a foreign recipient, such transfer is permitted only after the necessary legal and organisational procedures have been completed and an appropriate legal basis exists.
10.4. The User's own use of a foreign third-party service, including by means of an API key supplied by the User, may additionally be governed by that service's policy and terms.
11. Retention periods
11.1. Personal data is retained no longer than required by the processing purposes, the agreement or the law.
11.2. The principal retention periods are as follows:
- order, Licence and payment data: for the duration of the relevant contractual relationship and up to three years after it ends, unless a longer period is required by law or necessary to address an existing dispute;
- information required to perform tax obligations and confirm settlements: for the period established by applicable tax and other laws;
- automatic-renewal data: while automatic renewal is active and thereafter for the period needed to confirm performance of the relevant payments and consider possible claims;
- support correspondence: for up to three years after the relevant request is completed, unless longer retention is required to address a dispute;
- ordinary technical logs and diagnostic data: generally no longer than 12 months;
- information about an information-security event may be retained longer than ordinary technical logs where needed to investigate an incident, protect rights or comply with legal requirements;
- active-Licence and activation data: for the Licence Term and thereafter to the extent needed to confirm performance of the agreement, consider requests and prevent abuse;
- a BYOK API key, if the particular implementation provides for its storage: only while the relevant integration is active or until the User deletes or replaces the key, unless the technical implementation provides a shorter period.
11.3. If data is no longer needed for the stated purpose and there is no other lawful ground for retaining it, the Operator stops processing it and ensures its deletion or destruction in accordance with the procedure and time limits established by law.
12. User rights
12.1. In the cases provided by law, the User may:
- obtain information about the processing of the User's personal data;
- request correction of the data;
- request blocking or deletion of data that is incomplete, outdated, inaccurate, unlawfully obtained or unnecessary for the stated purpose;
- withdraw consent previously given;
- request termination of processing in cases provided by law;
- challenge the Operator's acts or omissions before Roskomnadzor or a court;
- exercise other rights granted by the laws of the Russian Federation.
12.2. To exercise these rights, the User may contact sales@secammo.ru.
12.3. To identify the User, the Operator may request information sufficient to confirm that the request relates to a particular person, order, Licence or SecAmmo Product. The Operator does not request the full bank-card number, CVV/CVC or PIN.
12.4. Where possible, the User is advised to send the request from the email address used to purchase the relevant paid version or Licence.
12.5. The Operator considers requests and fulfils lawful data-subject requirements within the periods established by the laws of the Russian Federation.
13. Personal data security
13.1. The Operator takes the legal, organisational and technical measures required to protect personal data against unlawful or accidental access, destruction, modification, blocking, copying, provision, dissemination and other unlawful acts.
13.2. Depending on the nature of the data processed, such measures may include:
- minimising the data collected;
- separating access rights;
- using authentication and authorisation controls;
- protecting secrets and access keys;
- protecting data in transit;
- logging security events;
- updating software;
- backing up data where necessary;
- controlling access to infrastructure;
- detecting and investigating incidents;
- deleting data when it is no longer needed.
13.3. This Policy does not disclose details of specific protective mechanisms to an extent that could reduce the security of the SecAmmo infrastructure.
13.4. The User must keep access to the User's email account, Licence Key, third-party API keys and other authentication means belonging to the User confidential.
14. Cookies, analytics and third-party pages
14.1. As of the effective date of this Policy, the SecAmmo Website does not use advertising cookies, behavioural-profiling systems or third-party web-analytics services.
14.2. The Website may locally store the interface language selected by the User, “ru” or “en”, in browser storage solely to retain that preference. The language value is not used for profiling or analytics, is not transferred to third parties and is not linked to the Contact Email Address, payment or Licence.
14.3. Ordinary operation of the web server and hosting may involve processing the technical information listed in clause 4.4 of this Policy.
14.4. When proceeding to the Payment Page, the User leaves the Website's own infrastructure or interacts with an interface of the independent Payment Service. Cookies and other technical means used on that page are also governed by the documents of the relevant Payment Service.
14.5. If technologies requiring separate notice or User consent are introduced on the Website in the future, the Operator will first update the relevant documentation and, where required, implement a mechanism for obtaining such consent.
15. Automated processing
15.1. SecAmmo Products and related information systems may automatically process information to:
- issue and activate a Licence or another access means;
- verify Licence validity;
- renew the term;
- process information about successful payment;
- enforce technical Licence restrictions;
- detect technical errors and abuse.
15.2. The Operator does not use User data for advertising profiling or sale to advertising networks.
16. Processing of third-party data by the User
16.1. Certain SecAmmo Products are technical-analysis tools. When using the relevant functions, the User may independently enter technical indicators or information relating to third parties.
16.2. The User must use SecAmmo Products in compliance with applicable law and independently assess whether lawful grounds exist to process or transfer third-party data.
16.3. This section does not release the Operator from the Operator's own obligations under personal-data law.
17. Changes to this Policy
17.1. The Operator may amend this Policy when the law, the composition or functionality of SecAmmo Products, the categories of data processed, the infrastructure used or the arrangements for interaction with third parties change.
17.2. A new version is published at https://secammo.ru/en/privacy/.
17.3. The effective date of a new version is stated at the beginning of the document.
17.4. A change to this Policy does not by itself create the User's consent to a new type of processing where the law requires separate consent.
18. Contact details
18.1. Questions about personal-data processing, exercise of data-subject rights, correction or deletion of data and other matters related to this Policy may be sent to sales@secammo.ru.
Operator: Tsibulsky Stanislav Andrianovich (Цибульский Станислав Андрианович)
Status: individual applying the special tax regime “Tax on Professional Income” under Russian law
Russian TIN (INN): 772464065125
Email: sales@secammo.ru
Website: https://secammo.ru/
Policy: https://secammo.ru/en/privacy/
