Home

Legal

Personal data policy

Draft policy for the website, accounts and Mattr workspaces.

Draft · not effective. Legal details and final terms require approval.

Controller and scope

The controller’s name, address and registration details have not been supplied. The controller, enquiry channel and actual processing locations must be identified before approval.

This policy covers website visitors, account owners, workspace members and support contacts. It describes processing and does not itself constitute consent.

Purposes, data and grounds

Account creation and service: name, email, authentication information and user identifier, as necessary to enter into and perform the contract. Passwords must not be disclosed to other users.

Task execution: messages, files, instructions, context, results and permitted integration data. The lawful basis depends on the data, contract and authority of the person providing it.

Billing: payer information, amounts, transactions and records, for contractual and legal obligations. Support: contact information and enquiry contents, to respond to requests.

Technical information and logs: IP addresses, client information and access events necessary to operate and protect the service. Actual fields and retention periods require confirmation.

Company employees and customers

Customers determining the purposes of processing their employees’ or clients’ data need a lawful basis for sharing it. Processing on a customer’s instructions requires an agreed mandate covering the data, actions, safeguards and parties’ obligations. A general offer does not replace that arrangement.

Recipients and AI providers

Task execution uses OpenRouter and Selectel, which may receive the prompt and necessary context. OpenRouter may forward requests to downstream model providers. Legal entities, countries, data categories and contractual grounds must be confirmed before approval. New recipients are disclosed before the relevant transfers.

A fallback provider is also a possible recipient. Hosting the primary server in Russia does not prevent international transfers when an external model is called.

Locations and international transfers

Account databases and user files are hosted on servers in Russia. Specific facilities and international request transfer details have not yet been confirmed. These details must be completed before approval. Consent does not waive applicable localisation or notification requirements.

Retention and ending processing

Data is processed no longer than needed for the purpose and applicable legal obligations. Accounts, messages, files, backups, logs and accounting records require separate retention periods and deletion procedures.

Account deletion or consent withdrawal does not necessarily end processing supported by another lawful basis. Without such a basis, processing stops and data is deleted within the applicable statutory periods.

Rights and enquiries

Individuals may request information about their data, seek correction, restriction or deletion where grounds exist, and withdraw consent for consent-based processing.

Identity checks should avoid excessive collection. Enquiries can be sent to support@mattr.ru. Identity verification and the response procedure must be completed before approval. Individuals may contact the competent regulator or court.

Safeguards and updates

Access is limited by assigned permissions. The operator must confirm the full organisational and technical measures, responsible personnel and incident procedures.

Processing, recipients and retention must not be expanded without appropriate disclosure. Updated policies have a date and version; new consent is requested where required.