Legal
Personal data processing policy
Publication date: 2026-07-31. Last updated: 2026-07-31
This Policy describes how personal data of users of northbyte.fun, personal cabinets and related Northbyte services is processed and protected. It is prepared under Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” and applies to information the Operator receives when the site and Northbyte services are used. Specific features may be governed by additional terms and separate consents.
1. General provisions and Operator details
Personal data operator: Ilya Dmitrievich Pankratov, self-employed under the professional income tax regime; INN: 352830848577; region of activity: Vologda Oblast, city of Cherepovets; privacy email: northbyte-fun@yandex.ru; postal address for requests: Pyatigorsk, Kalinina Avenue 2, building 2, apartment 121.
The Operator independently determines processing purposes, data categories and operations performed.
This Policy applies to northbyte.fun, the personal cabinet and products that expressly reference it.
2. Categories of data processed
2.1. Account data: email; name or display name; account id; password hash; registration, email confirmation and sign-in records; OAuth or Telegram identifiers when that sign-in method is used. Passwords are not stored in plain text.
2.2. Organisation and user data: organisation name; roles and permissions; connected products; cabinet settings; user–org linkage.
2.3. Payment data: amount, date and status; operation id; product/tariff; top-up and debit history; data needed for receipts. Full card details are not received or stored by the Operator — they are processed by the payment provider.
2.4. Product-use data: AI support messages; Content Factory materials and results; IMBA system settings; files and other data the user submits; review/approval results; support correspondence. Users must not submit special-category data, biometrics, medical secrets, bank credentials, passwords or other confidential data unless expressly provided for.
2.5. Form data: name; company; email; Telegram; phone; task description; budget; timelines; attachments and other voluntary fields.
2.6. Technical data: IP; request time; browser/OS; User-Agent; session ids; action/error logs; cookies; page interaction data; device technical id used to limit trial reuse. An irreversible cryptographic value derived from the device id may be stored; the raw device id is not retained unless the user is expressly told otherwise.
3. Processing purposes
Registration and email confirmation; authentication and account management; product access; performance of the contract and public offer; balance, license, usage and payment accounting; receipts; support; implementation/development requests; security and fraud prevention; error diagnostics and service availability; legal duties; analytics where consent is required; informational/marketing messages only with separate consent when required. Marketing consent is not bundled with registration, offer acceptance or mandatory service notices.
4. Legal bases
Contract performance; pre-contract steps at the user’s request; legal duties; the Operator’s legitimate interest in security and service operation where user rights do not override; consent where required. Consent is not required for processing objectively needed to register, perform the contract, take payment, deliver the product or answer a request. Withdrawal of consent does not invalidate prior lawful processing or stop processing on another lawful basis.
5. Processing methods and security
The Operator may collect, record, organise, accumulate, store, update, retrieve, use, grant access to, de-identify, block, delete and destroy personal data, with and without automation. Organisational and technical measures include access control, protected connections, strong password hashes, logging, backups, software updates, infrastructure access control and incident response.
6. Retention and deletion
Data is kept no longer than purposes or law require. Account data — while the account is active and up to 30 days after deletion, except data kept by law. Payment/receipt data — tax and other applicable periods. Leads and correspondence — up to 3 years after interaction ends unless longer needed to protect rights. Security logs — up to 12 months. Error logs — up to 90 days. Backups — for the backup cycle then deleted/overwritten. Analytics — per the service settings. After the purpose ends, data is deleted, destroyed or de-identified unless law or disputes require retention.
7. Third parties and infrastructure
The Operator may engage processors: hosting/cloud, payment providers, email, auth providers, support/monitoring, AI model providers and analytics.
Main processors: Selectel (Russia) — site and databases; Robokassa — payments; Yandex — service email; Telegram — auth/contact if chosen; OAuth Yandex and Google — sign-in; LLM providers — model requests (client BYO keys or the service’s own LLM); Northbyte in-house analytics — with consent where required.
If the user connects their own API key, data may go to that provider under its documents. Only necessary data is shared with processors.
8. Localisation and cross-border transfer
When collecting personal data of Russian citizens online, primary recording, organisation, accumulation, storage, updating and retrieval use databases located in the Russian Federation.
Some auth, communication or AI providers may be outside the RF. Before cross-border transfer the Operator takes steps required by law and assesses protection conditions. If a product does not use cross-border transfer, that may be stated in its settings or docs.
9. Cookies and analytics
Essential cookies support sign-in, sessions, CSRF protection, technical settings and security. Optional analytics cookies load only after consent unless law allows otherwise. Users may change choice via cookie settings or delete cookies in the browser; deleting essential cookies may break some features.
10. User rights
Users may request information about processing, correction of inaccurate/incomplete data, blocking or deletion where lawful, withdraw consent, opt out of marketing, and complain to Roskomnadzor or a court. Requests must allow identification of the applicant. The Operator responds within statutory periods. Deletion may be refused where data must be kept for law, payments, disputes or protection of rights.
11. Organisation users
If an organisation gives employees access, it must have a lawful basis to share their data with Northbyte. Depending on the product, Northbyte may act as an independent operator for account/payment/security data or as a processor for the organisation’s customer/employee/content data. Processor terms are set by a separate agreement or product terms.
12. Policy changes
The Operator may change this Policy when the service or law changes. The current version is at https://northbyte.fun/legal/privacy (and /en/legal/privacy). Material changes may be announced via cabinet or email.
13. Contacts
Personal data requests: northbyte-fun@yandex.ru. Postal address: Pyatigorsk, Kalinina Avenue 2, building 2, apartment 121. Telegram: https://t.me/chpdrx_bot. Please use subject line “Personal data”.
Operator details
Ilya Dmitrievich Pankratov — self-employed (NPD)