Privacy Policy
This is a courtesy translation. The Russian version prevails: Политика обработки персональных данных.
This document has been drawn up in accordance with Part 2 of Article 18.1 of Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” and the subordinate regulations of Roskomnadzor (the Russian data protection authority).
1. General provisions
1.1. This Personal Data Processing Policy (the “Policy”) defines the procedure for processing personal data by Krasoft Limited Liability Company (the “Operator”) and the measures taken to ensure the security of such data.
1.2. The Policy has been drawn up in accordance with the Constitution of the Russian Federation, the Civil Code of the Russian Federation, the Labour Code of the Russian Federation, Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”, Federal Law No. 149-FZ of 27 July 2006 “On Information, Information Technologies and Information Protection”, Federal Law No. 242-FZ of 21 July 2014, Decree of the Government of the Russian Federation No. 1119 of 1 November 2012, and the orders of the FSTEC of Russia and the FSB of Russia.
1.3. The Policy is subject to mandatory publication with unrestricted access on the information and telecommunications network “Internet” in accordance with Part 2 of Article 18.1 of Federal Law No. 152-FZ.
2. Operator details
Krasoft Limited Liability Company
- Registered address
- 360001, Kabardino-Balkarian Republic, Nalchik, Mechieva St., bld. 207a, floor 4, Russian Federation
- INN (tax ID)
- 9705142730
- KPP
- 070001001
- OGRN
- 1207700109165 (dated 11 March 2020)
- Corporate website
- https://krasoft.ru
- Service address
- https://zakupki.krasoft.ru
- Telephone
- +7 (495) 540-55-99
- privacy@krasoft.ru
2.1. The Operator is entered in the Register of Operators processing personal data in the manner established by Article 22 of Federal Law No. 152-FZ.
Entry in the Roskomnadzor Register of Operators
- Registration number
- 26-26-052889
- Grounds for entry
- Roskomnadzor Order No. 6 of 19 January 2026
- Notification registration date
- 29 December 2025
- Start date of processing
- 11 March 2020
- Location of databases
- Russian Federation
2.2. In accordance with Part 1 of Article 18.1 of Federal Law No. 152-FZ, the Operator has appointed a person responsible for organising the processing of personal data:
- Full name
- Rustam A. Kunizhev
- Telephone
- +7 (495) 540-55-99
- Postal address
- 360001, Nalchik, Mechieva St., bld. 207a, floor 4, Russian Federation
- info@krasoft.ru
3. Processing principles
The Operator processes personal data on the basis of the following principles:
- lawfulness and fairness;
- limitation of processing to the achievement of specific, predetermined and lawful purposes;
- prevention of the merging of databases processed for incompatible purposes;
- correspondence of the content and volume of the processed data to the stated purposes of processing;
- accuracy, sufficiency and relevance of the data;
- storage of data in a form that permits identification of the data subject for no longer than required by the purposes of processing;
- location of databases containing personal data of citizens of the Russian Federation within the territory of the Russian Federation.
4. Data subjects and data categories
4.1. The Operator processes personal data of the following categories of data subjects (in accordance with entry No. 26-26-052889 in the Roskomnadzor Register of Operators):
- website visitors (anonymous, unauthenticated users);
- customers — users of the “KRASOFT Platform” Service;
- counterparties and representatives of counterparties;
- employees and former employees of the Operator;
- relatives of the Operator’s employees.
4.2. Through the website and the “KRASOFT Platform” Service, the Operator collects the following personal data of website visitors:
- name;
- email address;
- cookies;
- information about the user’s actions on the website;
- information about the user’s device and browser;
- IP address;
- session date and time;
- referrer (address of the previous page).
4.3. For customers of the Service, the following data is additionally processed:
- telephone number;
- country, city, region;
- account credentials (login, password hash, session and refresh token identifiers).
4.4. Within contractual work with counterparties and representatives of counterparties:
- surname, first name, patronymic;
- details of the identity document (type, series, number, date of issue, name of the issuing authority);
- information on registration at the place of residence;
- contact details (telephone number, email address);
- bank details;
- taxpayer identification number (INN).
4.5. The categories of personal data of employees, former employees and relatives of employees are established separately for each purpose of processing in accordance with the entry in the Register of Operators and are processed by the Operator within HR, accounting, tax and other record-keeping processes outside the website and the Service.
4.6. Data processed on behalf of a customer. When using the Service, a customer (acting as an independent operator) places information about its own counterparties, employees and other data subjects. With respect to such data, the Operator acts as a person processing personal data on behalf of the customer in accordance with Part 3 of Article 6 of Federal Law No. 152-FZ; the purposes and the scope of the processed data are determined by the customer.
4.7. The Operator processes special categories of personal data (information on health status, categories of fitness for military service) exclusively in respect of employees and former employees for the purposes specified in the entry in the Register of Operators (compliance with legislation on healthcare, on defence, on social insurance). With respect to website visitors, customers and counterparties, the Operator does not process special categories of personal data or biometric personal data.
5. Purposes of processing
The Operator processes personal data for the purposes declared upon entry in the Register of Operators (entry No. 26-26-052889):
- ensuring compliance with the pension legislation of the Russian Federation;
- ensuring compliance with the legislation on social insurance;
- ensuring compliance with the legislation of the Russian Federation on healthcare;
- ensuring compliance with the legislation of the Russian Federation on defence;
- promotion of goods, works and services on the market (including interaction with website visitors and customers of the Service);
- HR and accounting record-keeping (including contractual settlements with customers and counterparties);
- ensuring compliance with the labour legislation of the Russian Federation;
- conducting contractual work with counterparties;
- ensuring compliance with the tax legislation of the Russian Federation.
Purposes No. 5 (“promotion of goods, works and services on the market”) and No. 6 (“HR and accounting record-keeping”) constitute the grounds for processing personal data collected through the website and the Service in respect of website visitors, customers and counterparties.
6. Legal grounds
Processing is carried out on the following legal grounds:
- consent of the data subject (Clause 1 of Part 1 of Article 6 of Federal Law No. 152-FZ);
- performance of a contract to which the data subject is a party (Clause 5 of Part 1 of Article 6 of Federal Law No. 152-FZ);
- fulfilment of obligations imposed on the Operator by the legislation of the Russian Federation (Clause 2 of Part 1 of Article 6 of Federal Law No. 152-FZ);
- the Operator’s charter, local regulations and concluded civil-law contracts.
7. Methods and retention periods
7.1. Personal data is processed both with and without the use of automation tools and includes: collection, recording, systematisation, accumulation, storage, updating, retrieval, use, transfer, depersonalisation, blocking, deletion and destruction.
7.2. Personal data of citizens of the Russian Federation is stored on servers located within the territory of the Russian Federation in accordance with the requirements of Part 5 of Article 18 of Federal Law No. 152-FZ.
7.3. The retention period is determined by the purposes of processing and amounts to:
- for data processed under the Terms of Use — the term of the agreement and three (3) years after its termination;
- for accounting and tax records — five (5) years from the end of the tax period in accordance with the Tax Code of the Russian Federation and Federal Law No. 402-FZ;
- for employee data — fifty (50) years in accordance with Order of Rosarkhiv No. 236 of 20 December 2019;
- other periods expressly established by the applicable legislation of the Russian Federation.
7.4. Upon achievement of the purposes of processing or upon withdrawal of the data subject’s consent, personal data is subject to destruction or depersonalisation within thirty (30) days.
8. Web analytics and cookies
8.1. To collect visit statistics, analyse user behaviour and improve the operation of the website, the Operator uses the Yandex.Metrica web analytics system (counter number 110540637). Data collection begins only after the visitor has given consent in the cookie banner; if consent is declined, the counter is not loaded.
8.2. Yandex.Metrica collects depersonalised data about visits, in particular:
- cookies;
- IP address;
- device and browser information (User-Agent);
- traffic source (referrer);
- information about visitor behaviour on the page (views, transitions, actions).
8.3. The “Session Replay” (Webvisor) and “Scroll Map” technologies are applied exclusively on public procurement card pages, where the visitor does not enter personal data, and are not applied in the personal account, on sign-in and registration forms, or in other sections of the Service that require authentication.
8.4. When using Yandex.Metrica, YANDEX LLC acts as a person processing personal data on behalf of the Operator in accordance with Part 3 of Article 6 of Federal Law No. 152-FZ. Processing is carried out under the Terms of Use of the Yandex.Metrica service published at yandex.ru/legal/metrica_termsofuse.
8.5. A visitor may refuse data collection by the web analytics system: by clicking “Decline” in the cookie banner, by disabling cookies in the browser settings, or by installing the official browser extension for opting out of Yandex.Metrica.
9. Email communications and mailings
9.1. The Operator sends the following types of messages to the email address provided by the data subject:
- transactional — messages related to the performance of the contract and to actions taken by the data subject: confirmation of registration and of the email address, password recovery, notifications of issued invoices and payments, delivery of documents. Legal ground — Clause 5 of Part 1 of Article 6 of Federal Law No. 152-FZ (performance of a contract to which the data subject is a party);
- service — messages that make the Service work: results of monitoring under the procurement filters configured by the data subject, notifications of events in the account, scheduled maintenance, and changes to the Terms of Use, the price plans and this Policy. Legal ground — Clause 5 of Part 1 of Article 6 of Federal Law No. 152-FZ;
- informational and advertising — information about new features of the Service, price plans, special offers, and the Operator’s educational and analytical materials. Legal ground — consent of the data subject (Clause 1 of Part 1 of Article 6 and Part 1 of Article 15 of Federal Law No. 152-FZ; Part 1 of Article 18 of Federal Law No. 38-FZ of 13 March 2006 “On Advertising”).
9.2. Consent to receive informational and advertising messages is obtained separately from consent to the processing of personal data and from acceptance of the Terms of Use — through a separate, non-pre-ticked form field. Neither registration nor access to the functionality of the Service is conditional upon giving such consent. The consent is recorded in the consent log together with the date and time, IP address, browser details (User-Agent), the address of the page on which it was given, and the full text of the version of the consent in force at that moment.
9.3. Data recorded when sending. For each message sent, the Operator records: the fact of sending and delivery (or the refusal of the recipient’s mail server to accept the message), the fact that the message was opened, the fact that links contained in it were followed, the fact of opting out of the mailing, and any complaint about the message.
9.4. The following are used to record this data: a 1×1 pixel image (a “tracking pixel”) loaded by the recipient’s mail client when the message is opened, and substituted links — a click is routed through the Operator’s server and then automatically redirected to the final address. The pixel and the substituted links are served by the Operator’s own servers; no third-party counters or trackers are embedded in the messages. If the recipient’s mail client does not load images, the opening of the message is not recorded.
9.5. The purpose of processing the data referred to in clause 9.3 is to assess the usefulness of the mailing (which topics and materials are of interest to recipients), to monitor delivery quality and to promptly exclude inactive addresses. The Operator does not take decisions producing legal effects concerning the data subject solely on the basis of automated processing of such data (Article 16 of Federal Law No. 152-FZ).
9.6. Opting out. The data subject may at any time opt out of receiving informational and advertising messages by any of the following means:
- via the “Unsubscribe” link included in every informational and advertising message — including by means of a mail client supporting one-click unsubscribe (the List-Unsubscribe and List-Unsubscribe-Post headers, RFC 8058);
- in the subscription preference centre available from a link in the message and in the personal account — where, instead of opting out entirely, topics and frequency may be adjusted;
- by contacting the Operator’s support service, by writing to privacy@krasoft.ru or by post to the address specified in Section 2 of the Policy;
- by replying to the sender’s address with a request to stop the mailing.
9.7. An opt-out takes effect immediately: the email address is added to a suppression list and informational and advertising messages cease to be sent, with no additional conditions, confirmations or explanation of reasons required.
9.8. Opting out of informational and advertising messages does not affect transactional and service messages: these are sent on a different legal ground (performance of the contract) and continue to be sent for as long as the Terms of Use remain in force. The data subject configures individual service notifications in the personal account.
9.9. Retention periods. Consent log records, including records of the withdrawal of consent, are retained for three (3) years from the date of withdrawal, as evidence of the lawfulness of the processing and of compliance with the data subject’s request. An email address included in the suppression list is retained for as long as necessary to give effect to the opt-out: deleting it would result in the resumption of unwanted mailings. Other data referred to in clause 9.3 is retained for the periods established by clause 7.3 of the Policy.
9.10. Disclosure to third parties. The Operator does not use third-party bulk email service providers: messages are sent by the Operator’s own software from mail servers under its control located within the territory of the Russian Federation. Personal data of mailing recipients is not transferred to third parties, and no cross-border transfer of such data is carried out.
9.11. Every informational and advertising message contains the full name, INN, OGRN and address of the Operator, a contact email address, a link to this Policy, an “Unsubscribe” link, a link to the subscription preference centre, and a statement of the ground on which the recipient received the message.
10. Disclosure of personal data
10.1. The Operator does not transfer personal data to third parties, except in cases provided for by the legislation of the Russian Federation or where the data subject has given consent.
10.2. The Operator has the right to entrust the processing of personal data to third parties on the basis of a contract concluded with them in accordance with Part 3 of Article 6 of Federal Law No. 152-FZ. Such a contract establishes the obligation of the third party to observe the confidentiality and security of personal data.
10.3. The Operator has notified the authorised body for the protection of the rights of personal data subjects of its intention to carry out cross-border transfer of personal data in the manner established by Article 12 of Federal Law No. 152-FZ (entry No. 26-26-052889 in the Register of Operators contains the corresponding indication).
10.4. Databases containing personal data of citizens of the Russian Federation are hosted on servers located within the territory of the Russian Federation in accordance with Part 5 of Article 18 of Federal Law No. 152-FZ.
11. Rights of data subjects
A personal data subject has the right to:
- receive information concerning the processing of their personal data in the manner established by Article 14 of Federal Law No. 152-FZ;
- demand the updating, blocking or destruction of personal data;
- withdraw previously given consent to the processing of personal data at any time;
- appeal against the actions (inaction) of the Operator to Roskomnadzor or in court;
- demand compensation for losses and for moral harm in accordance with the legislation of the Russian Federation.
A request is to be sent to privacy@krasoft.ru and is considered within no more than thirty (30) days from the date of receipt.
12. Security measures
12.1. The Operator takes the necessary legal, organisational and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, dissemination, as well as against other unlawful actions, in accordance with Articles 18.1 and 19 of Federal Law No. 152-FZ, Decree of the Government of the Russian Federation No. 1119 of 1 November 2012, and the orders of the FSTEC of Russia No. 21 of 18 February 2013 and of the FSB of Russia.
12.2. The Operator’s internal regulations on the processing and protection of personal data:
- Regulation on the organisation of personal data processing;
- Regulation on the organisation of personal data processing without the use of automation tools;
- Regulation on ensuring the security of personal data processed in personal data information systems;
- Procedure for responding to information security incidents in personal data information systems.
12.3. Organisational measures include:
- appointment of a person responsible for organising the processing of personal data (see Section 2 of the Policy);
- determination of the personal data protection levels applicable to processing in information systems depending on security threats;
- development of personal data security threat models;
- accounting for machine-readable media containing personal data;
- establishment of rules for access to personal data processed in information systems, and the registration and accounting of all user actions with personal data;
- familiarisation of employees with the provisions of personal data legislation and the Operator’s local acts, and training in the use of information protection tools;
- internal control of the compliance of personal data processing with personal data protection requirements, the Operator’s policy and local acts;
- investigation of instances of unauthorised access to personal data in accordance with the Procedure for responding to information security incidents.
12.4. Technical measures include:
- use of cryptographic information protection tools when transmitting personal data over communication channels (TLS 1.2 and above; the use of encryption tools is declared in entry No. 26-26-052889 of the Register of Operators);
- segregation of access rights based on a role model;
- logging of actions performed with personal data;
- use of protection tools against unauthorised access and malicious code;
- data backup and regular integrity monitoring.
13. Incident response
13.1. In the event of an incident resulting in the unlawful or accidental transfer of personal data that has led to a violation of the rights of data subjects, the Operator notifies Roskomnadzor:
- within twenty-four (24) hours of detecting the incident — with preliminary information;
- within seventy-two (72) hours of detection — with the results of the internal investigation and information about the persons responsible.
This procedure is established by Part 3.1 of Article 21 of Federal Law No. 152-FZ. Affected data subjects are notified of the incident in the manner and within the time limits set out by the legislation of the Russian Federation.
14. Contact information
To exercise their rights, submit requests and obtain clarifications on personal data processing matters, a data subject may contact the Operator:
- by email: privacy@krasoft.ru;
- by post at the Operator’s address specified in Section 2 of the Policy.
The authorised body for the protection of the rights of personal data subjects is Roskomnadzor: rkn.gov.ru.