1. General
The data controller is Individual Entrepreneur Grigory Nikolaevich Melnikov (the Controller, Killbot Group).
This policy applies to killbot-group.com, linked registration and account pages, website forms and Killbot Group support channels.
Processing is governed by applicable law, including Russian Federal Law No. 152-FZ on Personal Data where it applies to the Controller.
2. Data we process
The information depends on how you use the service and may include:
- your name, email address and preferred contact method;
- company and billing details required for contracts, invoices and accounting documents;
- account information and support messages;
- website addresses, project settings, service statistics and technical logs;
- IP address, request headers, cookies and technical browser or device signals;
- other information you choose to submit.
Please do not send sensitive personal data unless it is specifically required by law or a separate agreement.
3. Purposes and legal grounds
- responding to enquiries, providing audits and preparing proposals;
- registering and managing accounts and access;
- performing contracts, accepting payments and issuing documents;
- providing support, protecting accounts and preventing abuse;
- sending essential service, subscription and technical notices;
- meeting legal duties and protecting legitimate interests.
Processing may be based on consent, a contract, a legal obligation or a legitimate interest in operating and securing the service.
4. Processing and sharing
The Controller may collect, record, organise, store, update, use, restrict and delete information by automated and non-automated means.
Access is limited to staff and authorised contractors who need it for support, development, sales, accounting or service operation.
We do not sell personal data or share it for third-party advertising. Data may be shared when needed to perform a contract, process a payment, run the infrastructure or comply with law, subject to appropriate confidentiality.
5. Retention and deletion
Personal data is retained only as long as needed for the stated purposes, a contract and mandatory record-keeping periods. It is then deleted or anonymised unless the law requires longer retention.
Technical data from protected websites is retained for no longer than 30 calendar days and is usually deleted automatically within 14–21 days. See Data Security for details.
6. Your rights
You may ask what personal data we process, request correction, restriction or deletion, withdraw consent, and use any other rights available under applicable law.
Withdrawing consent does not affect processing already performed lawfully and does not override retention required by law or an active contract.
7. Contact and updates
For a personal-data request, include your name, the contact method you used and enough detail to link the request to your account or previous enquiry.
This policy may be updated. A new version applies when published here unless it states a later effective date.