Legal and compliance

Personal data policy (Russian law)

Updated: 21 July 2026

This policy describes processing under Federal Law No. 152-FZ of 27 July 2006. EU and international subjects are covered by the separate [GDPR/CCPA Privacy policy](/legal/gdpr/).

1. Operator

The personal-data operator is TrustFlare (trustflare.tech), referred to as “we”. Contact [email protected] for processing enquiries.

The Operator appoints a person responsible for organizing personal-data processing and adopts internal processing policies under Article 18.1 of 152-FZ.

2. Grounds and purposes

Processing is based on Article 6 of 152-FZ: consent, performance of a contract with the subject, or legitimate interests that do not infringe the subject’s rights.

  • Handle pilot requests and contact prospective customers.
  • Provide and support the contracted service.
  • Maintain security and prevent abuse.

3. Subjects and data categories

  • Subjects: website visitors, representatives of prospective and current customers and, within the service, customer employees and contractors.
  • Website data: name, contact details (email, phone or Telegram), company and request content.
  • Cloud-core data (Free, Business and trials): device identifiers and facts, OS username, IP, user agent and allow/deny decisions. With Ultimate these categories remain with the customer. Special categories of personal data are not processed.
  • The Operator does not collect biometric personal data. Face ID and Touch ID checks happen on the user’s device and are not transmitted to the Operator.

4. Processing conditions

Processing may be automated or manual and is limited to the purposes. The Operator does not make decisions with legal consequences solely through automated processing without the possibility of human involvement.

5. Database localization (Article 18(5))

When collecting Russian citizens’ personal data, the Operator records, organizes, accumulates, stores, updates and retrieves the data using databases in Russia.

Following stricter requirements in 2025, initial collection and recording of Russian citizens’ data do not go directly to foreign databases. Russian users are served through a Russian processing environment, such as a Russian provider. Self-hosted customers determine database locations in their own infrastructure.

6. Cross-border transfers

Transfers require a lawful basis and appropriate protection of subject rights. Self-hosted deployments generally do not require transfers because data stay within the customer perimeter.

7. Retention

Data are kept no longer than the purposes require, or until consent is withdrawn, unless law or contract provides otherwise. Trial cores stop after 14 days; their volume and caller key are deleted after 30 days. Data are deleted or anonymized when the purposes are fulfilled.

8. Subject rights

Subjects may obtain information about processing, request correction, blocking or destruction, withdraw consent, and challenge the Operator before Roskomnadzor or a court.

Use the form below or contact [email protected]. Responses are provided within statutory deadlines.

9. Consent and withdrawal

Consent is freely given, specific and informed, without preselected boxes. It may be withdrawn at any time by emailing [email protected].

Consent to dissemination to an indefinite audience is separate from other consent and is not assumed by default (Article 10.1 of 152-FZ).

10. Safeguards, cookies and compliance

See Security for technical and organizational measures and the Cookie policy for cookies.

The Operator declares compliance with 152-FZ, including a responsible person, localization of Russian citizens’ databases and Roskomnadzor notification where required. See Compliance statements.

Data requests

Request your personal data

We will reply to the email you provide within 30 days.