GDPR
TrustFlare processes EU/EEA personal data under GDPR: lawful grounds (Article 6), data minimization, data-subject rights (Articles 15–22), lawful international-transfer mechanisms (SCCs) and incident notifications (Articles 33–34). An Article 28 DPA is available to business customers.
See the GDPR/CCPA Privacy policy.
Russian Federal Law No. 152-FZ
TrustFlare processes personal data under Federal Law No. 152-FZ: a responsible person is appointed and internal policies adopted (Article 18.1); Russian citizens’ personal-data databases are localized in Russia (Article 18(5)); informed consent is obtained, with separate consent for dissemination; and Roskomnadzor is notified where required.
See the Russian Personal data policy.
ISO/IEC 27001
Infrastructure provider Cloudflare holds ISO 27001, SOC 2 Type II and PCI DSS certifications. TrustFlare implements Annex A controls through internal procedures and self-assessment; TrustFlare has no formal certification.
See ISO 27001 and infrastructure for the control mapping.
Data residency with self-hosting
Device facts, access decisions and logs remain in the customer’s infrastructure in a self-hosted deployment. This helps with Russian localization and minimizing GDPR international transfers.
Due diligence
For security questionnaires and compliance questions, contact [email protected]. The Security page describes incident timelines: Roskomnadzor 24/72 hours and GDPR 72 hours.