Published and effective: July 12, 2026
This is a courtesy translation. The legally binding version of this document is the Russian one, available at undersec.tech/legal/privacy. In case of any discrepancy, the Russian version prevails.
1. General
This Personal Data Processing Policy (the “Policy”, also referred to as the “Privacy Policy”) is drawn up in accordance with Russian Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (“152-FZ”) and describes how the owner and administrator of the undersec.tech website and the app.undersec.tech service (the “Operator”) processes and protects personal data.
The Policy applies to all information about visitors of undersec.tech (the “Website”) and users of app.undersec.tech (the “Service”) that the Operator may obtain. By using the Website or the Service you confirm that you have read this Policy; by submitting personal data at registration or via contact forms you consent to its processing under the terms described here.
For any personal-data matters, contact hello@undersec.tech.
2. Definitions
The Policy uses the terms defined in Article 3 of 152-FZ: “personal data” means any information relating to a directly or indirectly identified or identifiable natural person (the data subject); “processing” means any operation performed on personal data, with or without automated means, including collection, recording, organisation, storage, clarification, retrieval, use, transfer, blocking, erasure and destruction.
3. Legal grounds
- the data subject’s consent (Art. 6(1)(1) of 152-FZ);
- performance of a contract to which the data subject is a party — the Terms of Service (Art. 6(1)(5) of 152-FZ);
- compliance with obligations imposed on the Operator by the laws of the Russian Federation.
4. Purposes of processing
- user registration, authentication and access to the Service;
- performance of the Terms of Service, including payment acceptance and accounting;
- communication: responses to enquiries, service and technical notifications;
- security of the Service, prevention of fraud and abuse;
- compliance with the laws of the Russian Federation.
The Operator does not use personal data for third-party marketing, does not sell it, and does not make decisions producing legal effects based solely on automated processing (Art. 16 of 152-FZ).
5. Categories of personal data processed
- Account data: email address; password (stored exclusively as a cryptographic hash, never available to the Operator in plain text); display name (optional); company name (optional).
- External authentication (OAuth): when signing in via an external identity provider — the email address and name from that provider’s profile.
- Enquiries: name, email address and message content submitted via the contact form or by email.
- Payment data: payments are handled by external payment providers. The Operator receives only the payment identifier, status and metadata, and does not store full payment credentials (card numbers, account details, etc.).
- Technical data: IP address, browser and device information (user agent), cookies, security event logs.
Special categories of personal data (Art. 10 of 152-FZ) and biometric data (Art. 11 of 152-FZ) are not processed. The Website and the Service are not intended for persons under 18; the Operator does not knowingly collect data of minors.
Data that users upload into the Service while using it (target addresses for analysis, scan results, reports) is processed solely to provide the services, is available within the user’s workspace, and is not used by the Operator for any other purpose.
6. Cookies
The Website and the Service use only technical (strictly necessary) cookies: session support after sign-in, the selected workspace, language and interface preferences. No advertising cookies or third-party analytics trackers are used. You may disable cookies in your browser settings, which may limit the functioning of the Service.
A third-party verification service (CAPTCHA) may be used to protect forms from automated abuse; during verification, technical data (IP address, browser parameters) is transmitted to that provider.
7. Processing terms and disclosure to third parties
Processing is performed using automated means. Access to personal data is limited to the Operator’s authorised personnel, strictly to the extent required by their duties.
Personal data may be disclosed to third parties only:
- to payment providers — to the extent necessary to process a payment;
- to infrastructure (hosting) providers — solely for technical hosting and storage on protected servers;
- to providers of technology services used to operate the Service (form protection against automated abuse — CAPTCHA, Section 6 of this Policy; automated interpretation of scan results, including with the use of artificial-intelligence models) — to the extent necessary for the respective function;
- upon a lawful, substantiated request of competent state authorities;
- in other cases — with the data subject’s separate consent.
8. Retention
Personal data is processed until the purposes of processing are achieved: account data — for the lifetime of the account; enquiry data — for the period needed to respond and keep records; technical logs — for a limited period required for security. Once the purposes are achieved, the contract is terminated or consent is withdrawn (absent other legal grounds), personal data is destroyed within no more than 30 days.
9. Data subject rights
- to obtain information about the processing of your personal data (Art. 14 of 152-FZ);
- to demand rectification, blocking or destruction of inaccurate or unlawfully processed data (Arts. 14, 20, 21 of 152-FZ);
- to withdraw consent (Art. 9(2) of 152-FZ);
- to lodge a complaint with the authorised data-protection authority (Roskomnadzor) or a court (Art. 17 of 152-FZ).
Requests should be sent to hello@undersec.tech in line with Art. 14(3) of 152-FZ. The Operator responds within 10 business days; the period may be extended by no more than 5 business days with notice to the applicant (Art. 20 of 152-FZ).
10. Security measures
In accordance with Arts. 18.1 and 19 of 152-FZ, the Operator takes the necessary legal, organisational and technical measures, including:
- encryption of data in transit (TLS/HTTPS);
- storage of passwords exclusively as cryptographic hashes;
- access control and data isolation at the workspace and database levels;
- infrastructure segmentation and restricted network access between components;
- logging of security-relevant actions;
- regular security assessment of the Operator’s own infrastructure.
11. Changes to this Policy
The Operator may amend this Policy. A new version takes effect upon publication on the Website unless it provides otherwise. The current version is permanently available at undersec.tech/legal/privacy.