Data processing policy
This page summarises in English how personal data of Noir users is handled. The policy is written to meet Federal Law No. 152-FZ of 27 July 2006, Russia's personal data law, and covers everything the operator may learn about a user through the service.
Binding version
The Russian-language original is the only legally binding version. In case of any discrepancy between this summary and the Russian original, the Russian original prevails. Read it at heynoir.com/privacy.html.
1. Who the operator is
The operator of your personal data is an individual applying Russia's special "professional income tax" regime (NPD, Federal Law 422-FZ):
| Full name | Vadim Aleksandrovich Tolmachev |
|---|---|
| Tax ID (INN) | 402404547192 |
| hello@heynoir.com |
2. What is collected
To deliver the service: your Telegram user identifier (Telegram ID), your Telegram username if you have set one, and your email address if you gave it voluntarily when paying or to receive a receipt.
In connection with payment: the payment identifier from the payment provider, the amount and date of the payment, and the plan you chose. Your card details (number, expiry date, CVV) are neither processed nor stored by the operator: they are handled by the payment provider on its own side under the PCI DSS standard.
Technical data about your use of the service: anonymised records of connections to the service's servers, meaning session start and end times, the server location selected and the volume of data transferred in aggregate form, plus the version of the client software if it is sent on connection.
The operator keeps no logs of the third-party sites a user visits through the service. The content of traffic carried through the service is not stored and is not examined.
3. Why it is processed
To identify you when delivering the service; to give you access under the subscription you paid for; to account for payments and issue receipts under Federal Law 422-FZ; to provide technical support; to keep the service working and secure and to diagnose incidents; and to tell you about changes to the terms of service.
4. Legal basis
Processing rests on the service contract concluded between the operator and the user, that is the public offer (Article 6(1)(5) of 152-FZ); on the user's consent, given by accepting that offer and using the service (Article 6(1)(1)); on the duties imposed by Federal Law 422-FZ as regards issuing and keeping receipts; and, for data the user has made available to an unlimited audience such as a public Telegram username, on Article 6(1)(10).
5. How long it is kept
| Category of data | Retention period |
|---|---|
| Telegram ID, username | Until the account in the service is deleted at the user's request |
| Until deleted at the user's request, or until the account is deleted | |
| Payment records and receipts | For the period required by Russian tax law |
| Technical connection metrics | No more than 30 calendar days from creation |
Once those periods expire, the data is destroyed or anonymised.
6. Who else sees it
Personal data may be passed to the following third parties, in the minimum volume needed for the purposes above: the payment provider, for settlements and refunds; Telegram (Telegram FZ-LLC), as regards the identifier and the messages in the Telegram service channel needed to deliver the service; the hosting providers of the server infrastructure, for hosting the service's servers; and the Federal Tax Service of Russia, through the "Moy Nalog" app and as regards revenue data, in the manner required by Federal Law 422-FZ.
The operator does not sell users' personal data to third parties for advertising or other commercial purposes.
7. Cross-border transfer
Some of the service's servers sit outside Russia, in Germany, the Netherlands and the United States. When you use the service, the technical connection metrics described above may be transferred to servers in those jurisdictions. The transfer is encrypted. The receiving jurisdictions provide adequate protection of the rights of data subjects, or the transfer is made on the basis of the user's consent.
8. How it is protected
The operator takes reasonable and sufficient legal, organisational and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, copying and other unlawful acts. In particular: data travels between the client device and the service's servers over encrypted connections; access to administrative interfaces is restricted and protected by passwords and two-factor authentication; and payment records and receipts are stored as the payment provider and tax law require.
9. Your rights
You have the right to learn whether the operator holds personal data about you and what it consists of; to require that it be corrected, blocked or destroyed where it is incomplete, inaccurate, out of date or unlawfully obtained; to withdraw your consent to processing at any time by writing to the operator's email address; and to challenge the operator's acts or omissions before Roskomnadzor, Russia's data protection regulator, or in court.
Requests are considered within 30 (thirty) calendar days. If you withdraw consent, your account in the service is deleted and the service stops; financial records that the law requires to be kept continue to be stored for the periods set by law.
10. Cookies
The heynoir.com site uses the minimum set of technical cookies needed for the pages to work. No advertising or tracking cookies are set on the site. Third-party resources such as Google Fonts may set their own cookies under their own policies.
11. Changes to the policy
The operator may amend this policy. A new version takes effect when it is published on the site, and users follow the changes themselves. Continuing to use the service after a new version is published means agreeing to it.
12. Contact
Questions and requests about personal data go to the operator's email address: hello@heynoir.com.