Version 2026-10-11
Personal data processing policy
1. Roles and contact
The provider named in Contacts controls Clientora account, support and subscription processing. Contact: support@trassami.ru. Each organization determines the purposes of its customer and staff data; Clientora processes that workspace under its documented instruction and does not use customer data for its own advertising.
2. Data and purposes
Account data includes name, email, password hash, language, organization roles and acceptance records. Subscription data includes amount, time, status and provider transaction ID. The bank receives card details directly. Security uses sessions, token and rate-limit hashes and technical events; IP addresses are processed for connections and protection. Workspace data includes customer/staff contacts, object and vehicle details, bookings, work, object photos, comments, history and internal payment records. Support uses information supplied to resolve a request.
3. Bases and recipients
Necessary processing supports the contract, legal accounting duties and lawful protection of rights. Organizations provide appropriate bases and notices for their data. Voluntary new purposes require a separate choice. The main database, uploads and private backups are in Russia: Timeweb Cloud, Saint Petersburg SPB-3, Dataline, 43 Zhukova Street. Yandex 360 receives recipients and transactional message contents once email is enabled. Registration remains closed until that connection is verified. T-Bank receives requested checkout information once payments are enabled. Staff access is role based; the organization controls customer links. Overseas access and international transfers require a prior assessment. English language does not remove that requirement.
4. Security and retention
Controls include HTTPS, password hashing, request verification, roles, separated organizations, private photos, expiring links and isolated services. Server access and secrets are restricted. Sessions last seven days, verification links 24 hours, reset links one hour and invitations seven days. Expired security records are cleaned daily. Nonpayment acceptance evidence is kept for up to three years from acceptance. Minimal payment/accounting records are kept for at least five years after the reporting year, or longer where law or an open dispute requires it. Service logs rotate within three files of 5 MiB per service, rather than a fixed number of days.
5. Erasure and backups
Closing an account anonymizes contact fields and revokes access. If its last owner leaves, workspace records are deleted; otherwise remaining owners retain the organization. Photos are deleted immediately or through a durable retry queue. Daily private backups are removed when seven days old at the next run; failures are addressed with access restricted. Before reopening a restored system, the operator reapplies later erasure/correction requests and revokes restored sessions and links. Migration copies are deleted within seven days of verified migration. Support correspondence is manually cleared 90 days after resolution except an open dispute or required retention. A backup on the same server does not protect against total server loss.
6. Your rights
Request access information, correction, cessation or erasure where applicable at support@trassami.ru. Account ownership is verified without excessive documents. Workspace customer requests go to the organization; Clientora assists under its instructions. Statutory response/action periods apply. Retention required by law may continue. You may contact the competent regulator or court. New purposes are described before activation.