This Personal Data Processing Policy (the “Policy”) sets out how the Operator processes personal data and the measures taken to protect it, in accordance with Russian Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (the “Law”).
The Policy is published pursuant to Article 18.1(2) of the Law and is freely accessible to any person at osm2cdr.com/en/personal-data/.
International aspects of processing (GDPR, CCPA/CPRA, PIPL, LGPD) are covered by a separate document — the Privacy Policy. This translation is provided for convenience; the Russian text prevails.
1. Operator
- Name: Sole proprietor (full name available on request)
- OGRNIP (sole proprietor registration no.): available on request
- INN (taxpayer no.): available on request
- Address: available on request
- E-mail: support@osm2cdr.ru
- Websites: osm2cdr.ru, osm2cdr.com
The duties of the person responsible for organising personal data processing (Article 22.1 of the Law) are performed by the Operator personally.
2. Legal grounds
Processing is carried out under Article 6(1), items 1, 5 and 6 of the Law: with the data subject's consent, for the performance of a contract to which the data subject is a party, and for the Operator's legitimate interests where this does not infringe the subject's rights. Applicable acts also include the Civil Code and the Tax Code of the Russian Federation, Federal Law No. 402-FZ “On Accounting”, Federal Law No. 149-FZ “On Information”, and the Terms of Service (public offer).
3. Purposes of processing
- registration, authentication and authorisation of the User;
- providing access to the Service and performing the contract (generating and delivering export files);
- notifying the User when an ordered file is ready;
- accepting and processing payments, refunds and settlements;
- handling enquiries, questions and bug reports;
- keeping the Service available and secure, detecting and preventing technical abuse and automated attacks;
- complying with statutory obligations, including accounting and tax records;
- improving the Service on the basis of anonymised usage statistics.
Processing for marketing purposes is carried out only with separate prior consent and stops on first request.
4. Categories of data subjects and data
Data subjects: Users of the websites and the Service (including unregistered visitors); persons who submit an enquiry through a contact form; counterparties and their representatives who are natural persons.
Personal data processed: e-mail address; a name or other label supplied by the User (including a name received from an authentication provider); the account identifier at an external authentication provider (Yandex ID, Google, GitHub) and a Telegram user identifier where such a sign-in method is used; the network (IP) address, stored in access logs in anonymised form with the last octet zeroed (/24 precision); software details (User-Agent, browser type, operating system, interface language); order details (requested geographic area, format, style, level of detail, date and outcome); payment details (amount, date, status, payment aggregator transaction id).
The Operator does not process special categories of personal data (racial or ethnic origin, political opinions, religious or philosophical beliefs, health, sex life), biometric personal data, criminal-record data, or precise device geolocation. Personal data of minors is not collected deliberately.
Payment card details are never transmitted to or stored by the Operator — they are entered and processed by the payment aggregator on its own side.
5. Procedure and conditions of processing
Methods: mixed processing — automated by means of computing equipment, and non-automated.
Operations performed: collection, recording, systematisation, accumulation, storage, adjustment (updating, modification), retrieval, use, transfer (provision, access), blocking, deletion and destruction.
Source of data. Personal data is provided by the subject when registering, placing an order or submitting an enquiry, and is also received automatically when the website is accessed (network address, software details). The Operator does not collect personal data from external sources or open databases.
Refusal to provide data is possible: provision is voluntary. Refusal only disables those functions that technically require the data (for example, e-mailing a link to a finished file); other functions remain available.
Retention periods: account data — until the User deletes the account or withdraws consent; access logs (anonymised network address) — 14 days; error logs — up to 7 days; enquiry records — up to 1 year from the date of reply; settlement documents — for the periods required by accounting and tax legislation.
Once the purposes are achieved, upon withdrawal of consent, or upon discovery of unlawful processing, personal data is destroyed or anonymised within the periods set by Articles 21 and 5 of the Law.
6. Place of processing and database localisation
Recording, systematisation, accumulation, storage, adjustment and retrieval of personal data of citizens of the Russian Federation are performed using databases located within the Russian Federation (Article 18(5) of the Law). The Service's servers and databases are hosted in a data centre in the Russian Federation (Moscow). Backups are not exported outside the Russian Federation.
7. Cross-border transfer
Certain technical functions involve foreign providers, so a limited amount of personal data may be transferred across borders:
- Google LLC (USA) — sign-in with a Google account and Google Analytics 4 web analytics — only for Users located outside the Russian Federation (see below);
- GitHub, Inc. (USA) — sign-in with a GitHub account, likewise only for Users located outside the Russian Federation.
Service e-mail delivery is not a cross-border transfer. Messages (address confirmation, password recovery, order-ready notification, replies to enquiries) are sent through Yandex LLC (Yandex 360), whose servers are located in the Russian Federation.
For a User located in Russia, no data is transferred to foreign web analytics at all. Google Analytics 4 is neither offered to such a User nor loaded by their browser under any cookie-banner choice: the Service does not hand out the measurement id to them. The rule follows the User's actual location rather than the site's domain zone, so it applies identically on osm2cdr.ru and osm2cdr.com; where the location cannot be determined, the User is treated as being in Russia. On the same principle, sign-in with Google and GitHub is not offered to such a User (Article 8(10) of Federal Law No. 149-FZ).
Yandex.Metrica analytics and Yandex ID sign-in are performed within the Russian Federation and do not constitute cross-border transfer; they are available to all Users.
Cross-border transfer is carried out after the Operator has notified Roskomnadzor under Article 12(3) of the Law. The User may prevent transfer for analytics purposes by declining analytics cookies, and may choose a sign-in method that does not involve a foreign provider.
8. Cookies and anonymised data
Functional cookies (interface language, theme, map settings) are required for the site to work and are set without separate consent. Analytics cookies are set only after explicit consent given via the banner; until then no analytics counters are loaded. Consent may be withdrawn at any time via the “Cookie preferences” link in the site footer. The browser's Global Privacy Control signal is automatically treated as a refusal of analytics cookies.
9. Security measures
The Operator applies the legal, organisational and technical measures required by Articles 18.1 and 19 of the Law, including: appointing a person responsible for organising processing; adopting and applying internal data protection acts; least-privilege access control and a password policy; storing authentication data as irreversible hashes; TLS encryption of traffic; firewalling and rate limiting; regular backups with restore verification; logging and review of access events; anonymisation of network addresses in access logs; and internal audits of compliance together with an assessment of potential harm to data subjects.
Where unlawful or accidental transfer of personal data infringing subjects' rights is established, the Operator notifies Roskomnadzor within the periods set by Article 21(3.1) of the Law.
10. Rights of the data subject
Under Articles 14–16, 20 and 21 of the Law the data subject may: obtain confirmation that processing takes place and the information listed in Article 14(7); access their personal data; require rectification, blocking or destruction of data that is incomplete, outdated, inaccurate, unlawfully obtained or unnecessary for the stated purpose; withdraw consent; object to processing for marketing purposes; and appeal the Operator's acts or omissions to Roskomnadzor or in court.
11. Making a request and withdrawing consent
Requests are sent to support@osm2cdr.ru and must contain information identifying the subject — the account e-mail address — together with the substance of the request. The Operator may seek additional confirmation where it is not evident that the request comes from the data subject.
The reply period is 10 working days from the date of the request, extendable by no more than 5 working days with notice of the reasons (Article 20(2) of the Law).
Withdrawal of consent is sent to the same address in free form and is actioned within 30 days. After withdrawal, processing stops and the data is destroyed, except where the Law permits processing without consent (in particular, to comply with statutory duties and to protect the Operator's rights). Withdrawal of consent entails deletion of the account.
12. Amendments
The Operator may amend this Policy. The current version, with the date of its approval, is published on this page. Continued use of the Service after a new version is published constitutes acceptance; registered Users are notified by e-mail of material changes.