Privacy Policy

Last updated: February 25, 2026

This Privacy Policy (hereinafter — the "Policy") describes the procedures for collecting, processing, storing, and protecting the personal data of users of the samreshuuu service (hereinafter — the "Service"), available at samreshuuu.ru. The personal data operator is the entity managing the samreshuuu service (hereinafter — the "Operator").

1. What data we collect

1.1. Data provided during registration

Email address, password (stored in hashed form), first and last name (if provided).

1.2. Profile and company data

Company name, TIN (tax identification number), legal address, preferred contract type, prepayment percentage, business description. All company data is encrypted using the GOST standard (Kuznechik algorithm) and stored in encrypted form.

1.3. Documents

Uploaded files (PDF, DOCX, XLSX, CSV, JSON, XML, images) up to 50 MB. Document contents are encrypted at rest. Metadata includes: file hash (SHA-256), size, upload date, owner ID.

1.4. Session and chat data

Chat history with the AI assistant, including message texts, session titles, timestamps. Data is used to maintain conversation context and improve response quality within your account.

1.5. Integration data

When connecting external services (1C, Bitrix24, AmoCRM, Ozon, Wildberries, Yandex 360, Diadoc) we store connection credentials (API keys, tokens, logins) in encrypted form. Data retrieved from connected systems is processed at the user's request and is not shared with third parties.

1.6. Telegram

When linking a Telegram account, we store your Telegram ID, username, and chat ID to ensure bot functionality. Messages sent via the Telegram bot are processed similarly to messages in the web interface.

2. Purposes of data processing

We process personal data for the following purposes:

  • Providing access to Service features (document analysis, task automation, working with business systems);
  • User identification and authentication;
  • Payment processing and subscription management;
  • Sending notifications about task status and Service operation;
  • Technical support and troubleshooting;
  • Improving Service quality based on anonymized analytics.

3. Data storage and protection

3.1. Storage location

All data is stored on certified servers located in the Russian Federation, in accordance with Federal Law No. 152-FZ "On Personal Data".

3.2. Encryption

Personal data is encrypted at rest using the Kuznechik algorithm (GOST R 34.12-2015). Data transmission uses TLS 1.3 protocol. Encryption keys are managed via a key versioning system.

3.3. Caching

Redis temporary caching is used to improve performance. Cached data is automatically deleted after the set expiration period (from 30 minutes to 30 days depending on the data type).

4. AI usage and data transfer to providers

To operate the AI assistant, your queries and document context are transmitted to language model (LLM) providers. We use multiple providers to ensure service stability. Your data is not used to train AI models. We have data processing agreements (DPA) in place with providers.

5. Payments

Payment processing is handled through the InvoiceBox payment gateway. We do not store bank card data. The payment gateway processes payment information in accordance with PCI DSS standards.

6. Data sharing with third parties

We do not sell or share your personal data with third parties, except in the following cases:

  • Transferring data to connected integrations (1C, CRM, marketplaces) — only at your explicit request and within your configured connections;
  • Payment processing through the payment gateway;
  • Transmitting queries to language model providers for AI assistant operation;
  • Providing data as required by authorized government bodies in accordance with Russian Federation law.

7. Cookies and analytics

The Service uses necessary cookies for authentication and session storage. We use Microsoft Clarity for anonymous user behavior analytics on the site. Analytical data does not contain personal information.

8. User rights

In accordance with Federal Law No. 152-FZ, you have the right to:

  • Obtain information about your personal data processed by the Operator;
  • Request correction, blocking, or destruction of personal data;
  • Delete uploaded documents — they will be permanently deleted at your request;
  • Withdraw consent to personal data processing;
  • Delete your account and all associated data.

9. Data retention period

Personal data is stored for the entire period of Service use and deleted within 30 days after account deletion. Data required to fulfill contractual and legal obligations may be stored longer in accordance with Russian Federation legislation.

10. Changes to the Policy

We reserve the right to amend this Policy. The current version is always available at samreshuuu.ru/privacy. In case of significant changes, we will notify you via email or the Service interface.

11. Contact information

For any questions related to personal data processing, you can contact us:

  • Email: support@samreshuuu.ru