Privacy Policy

Last updated: August 19, 2026

This Privacy Policy (the "Policy") sets out how the personal data of users of the Samreshuuu software (the "Software") is collected, processed, stored and protected. The Policy covers every form in which the Software is provided: the web version at samreshuuu.com, the mobile and desktop applications, and applications for third-party platforms installed on the user's own portal, including the Samreshuuu application in the Bitrix24 Marketplace catalogue. The data controller is Whatnot Hungary Kft. (registration number 01 09 441632, tax number 32769300-2-41, VAT number HU32769300, registered seat 1053 Budapest, Veres Pálné utca 28. 3. em. 16. ajtó) (the "Controller").

1. What data we collect

1.1. Data provided during registration

Email address, password (stored in hashed form), first and last name (if provided).

1.2. Profile and company data

Company name, TIN (tax identification number), legal address, preferred contract type, prepayment percentage, business description. All company data is encrypted using industry-standard AES-256 encryption at rest and stored in encrypted form.

1.3. Documents

Uploaded files (PDF, DOCX, XLSX, CSV, JSON, XML, images) up to 50 MB. Document contents are encrypted at rest. Metadata includes: file hash (SHA-256), size, upload date, owner ID.

1.4. Session and chat data

Chat history with the AI assistant, including message texts, session titles, timestamps. Data is used to maintain conversation context and improve response quality within your account.

1.5. Integration data

When connecting external systems (1C, Bitrix24, AmoCRM, Ozon, Wildberries, Yandex 360, Diadoc) the Software stores connection credentials (API keys, tokens, logins) in encrypted form. Data retrieved from connected systems is processed at the user's request and is not shared with third parties. When the Software is installed on a third-party platform portal, it additionally receives the portal address and identifier, the identifier and profile of the employee who opened the Software, and the access tokens issued by the platform; the portal data available to the Software is limited to the rights of the employee who set up the connection.

1.6. Telegram

When linking a Telegram account, we store your Telegram ID, username, and chat ID to ensure bot functionality. Messages sent via the Telegram bot are processed similarly to messages in the web interface.

1.7. Push notifications

When you enable push notifications in the mobile or desktop app, we store the device token issued by the delivery service (Apple Push Notification service or Firebase Cloud Messaging) and associate it with your account. The token is used solely to deliver notifications about task status and Software operation, is never used for advertising, and is not shared with third parties other than the notification delivery services themselves. The token is deleted when you turn notifications off, sign out, or uninstall the app.

2. Purposes of data processing

We process personal data for the following purposes:

  • Providing access to Software features (document analysis, task automation, working with business systems);
  • User identification and authentication;
  • Payment processing and subscription management;
  • Sending notifications about task status and Software operation;
  • Technical support and troubleshooting;
  • Improving Software quality based on anonymized analytics.

3. Data storage and protection

3.1. Storage location

Accounts, documents, chat history, company data and integration credentials are stored on servers located in the EU/EEA and are processed in accordance with the GDPR (Regulation (EU) 2016/679).

3.2. Encryption

Personal data is encrypted at rest using AES-256. Data transmission uses the TLS 1.3 protocol. Encryption keys are managed via a key versioning system.

3.3. Caching

Redis temporary caching is used to improve performance. Cached data is automatically deleted after the set expiration period (from 30 minutes to 30 days depending on the data type).

4. Language model providers

For the assistant to answer, the text of your request and the document fragments needed for the answer are transmitted to a language model provider. The provider processes the request and returns an answer; the result is stored in your account. The Software databases stay in the EU/EEA — only the content of a specific request is transmitted, and only for the time it takes to run.

We do not use your documents or conversations to train models — neither third-party nor our own. Providers are prohibited from doing so by the enterprise access terms under which we work with them.

Some providers and other sub-processors are registered outside the EU/EEA. Data is transferred to them under the European Commission's Standard Contractual Clauses (Article 46 GDPR) or an adequacy decision. Such recipients are registered in the USA and China. Information about specific sub-processors is provided on your request at support@samreshuuu.ru.

5. Payments

Payment processing is handled through the Stripe payment gateway. We do not store bank card data: the gateway processes payment information in accordance with PCI DSS standards.

6. Data sharing with third parties

We do not sell or share your personal data with third parties, except in the following cases:

  • Transferring data to connected integrations (1C, CRM, marketplaces) — only at your explicit request and within your configured connections;
  • Payment processing through the payment gateway;
  • Transmitting queries to language model providers for AI assistant operation;
  • Providing data where required by law or by a competent public authority.

7. Cookies and analytics

The web version of the Software uses necessary cookies for authentication and session storage. To find bugs and assess interface usability we use analytics services, including interface session recording (Microsoft Clarity): navigation, clicks and on-screen content are recorded, and input field contents are masked in the recording. Analytics is never used for advertising targeting, and you can withdraw your consent to it in profile settings.

8. User rights

In accordance with the GDPR, you have the right to:

  • Obtain information about your personal data processed by the Operator;
  • Request correction, blocking, or destruction of personal data;
  • Delete uploaded documents — at your request they are removed from the Software; full deletion timelines are set out in section 9;
  • Withdraw consent to personal data processing;
  • Delete your account and all associated data.

9. Data retention period

Personal data is stored for the entire period of Software use and deleted within 30 days after account deletion. Data required to fulfill contractual and legal obligations may be stored longer in accordance with applicable law.

10. Changes to the Policy

We reserve the right to amend this Policy. The current version is always available at samreshuuu.com/privacy. In case of significant changes, we will notify you via email or the Software interface.

11. Contact information

For any questions related to personal data processing, you can contact us:

  • Email: support@samreshuuu.ru
  • Data controller: Whatnot Hungary Kft.
  • Registered seat: 1053 Budapest, Veres Pálné utca 28. 3. em. 16. ajtó
  • You may lodge a complaint with the Hungarian supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), naih.hu