← Back to home

BRUV Data Processing Policy

This Data Processing Policy governs the collection, use, storage, transfer and protection of user data of BRUV services.

1. General provisions

1.1. This Policy defines how BRUV LLC processes data received via the website, mobile app, personal account, API, widgets and other BRUV services.

1.2. The Policy applies to all data BRUV receives:

  • during registration and authorization
  • when placing orders and making payments
  • when contacting support
  • when using subscriptions, auto-charges, bookings and other features
  • when using the website and app
  • when interacting with BRUV partners via the Platform

1.3. Use of BRUV services constitutes acknowledgment of this Policy by the user.

1.4. If the user does not agree with the Policy, they must stop using BRUV services.

2. Terms and definitions

Data — any information received by BRUV in connection with the use of services, including personal, technical, payment, behavioral data, log files, metadata and other information.

Personal data — any information relating to a directly or indirectly identifiable individual.

Anonymized data — data that does not allow direct identification of the user.

User — an individual, sole proprietor or representative of a legal entity using BRUV services.

Data processing — any operation with data, including collection, recording, systematization, storage, refinement, use, transfer, anonymization, blocking and deletion.

Platform — the website, mobile app, personal account, API, widgets and other BRUV technical resources.

3. What data we collect

BRUV may collect the following categories of data:

  • last name, first name, patronymic
  • date of birth
  • phone number
  • email address
  • identity document data, if required by law or to provide the service
  • company details, INN, KPP, OGRN, position and authority of the representative
  • payment details and information about payments
  • service, delivery or booking address
  • history of orders, cancellations, refunds and requests
  • correspondence with support
  • device technical data
  • IP address
  • cookies and other identifiers
  • information about actions in the interface
  • data on sign-in time, actions and navigation
  • anonymized analytical data

BRUV does not request excessive data and processes only the information necessary to operate the services, fulfill orders, comply with the law and protect the interests of BRUV and users.

4. Purposes of data processing

BRUV processes data for the following purposes:

  • user registration and identification
  • providing access to services
  • placing, confirming and fulfilling orders
  • accepting and processing payments
  • refunds, cancellations and recalculations
  • auto-charges and subscriptions
  • user support
  • sending notifications
  • ensuring security
  • preventing fraud and abuse
  • complying with legal requirements
  • analytics and service improvement
  • personalizing the interface and offers
  • developing new products and features
  • maintaining statistics
  • fulfilling agreements with partners

BRUV may use anonymized data for analytics, statistics, model training, service quality improvement, product development, research and internal reports.

5. Legal grounds for processing

BRUV processes data on the following grounds:

  • user consent
  • performance of a contract or offer
  • fulfillment of legal obligations
  • BRUV's legitimate interest
  • the need to protect the rights and interests of BRUV, users and third parties

If separate consent is required, BRUV obtains it through the interface, service documents or another legally permitted method.

6. How we receive data

BRUV receives data:

  • directly from the user
  • from BRUV partners
  • from payment organizations, banks and acquirers
  • from analytics services
  • from telecom operators
  • from third-party technical services
  • automatically when using the website and app

The user is responsible for the accuracy of the data provided.

7. Use of cookies and similar technologies

BRUV uses cookies, pixels, device identifiers, SDKs and similar technologies. They are used for:

  • authorization
  • remembering settings
  • analytics
  • improving functionality
  • personalization
  • fraud protection
  • traffic measurement

The user may restrict the use of cookies in browser or device settings, but this may affect the operation of some features.

8. Transfer of data to third parties

BRUV may transfer data to third parties only when necessary: to fulfill an order, process a payment, enable partner operations, support the service, comply with the law and protect BRUV's rights.

Data may be transferred to:

  • partners and counterparties
  • banks and payment systems
  • cloud and technical infrastructure providers
  • support services
  • analytics services
  • contractors operating the Platform
  • government authorities on legal grounds

BRUV transfers only the amount of data necessary for the relevant purpose.

9. International data transfer

BRUV may carry out cross-border data transfers when necessary for service operation, storage, analytics, technical support or use of third-party infrastructure. Where required, BRUV ensures compliance with applicable laws on cross-border data transfer.

10. Data storage

BRUV stores data only as long as necessary to achieve the purposes of processing, unless a longer period is required by law. Once the purposes are achieved, data is subject to deletion, anonymization or archiving.

Certain data may be stored longer:

  • to fulfill accounting and tax obligations
  • to resolve disputes
  • to protect BRUV's rights
  • to meet AML/KYC requirements, where applicable
  • to maintain a history of operations within the limits of the law

11. Data protection

BRUV takes reasonable organizational and technical measures to protect data from unauthorized access, modification, destruction, blocking, copying, distribution and other unlawful actions.

Protection measures may include:

  • access control
  • encryption
  • action logging
  • backups
  • anti-fraud mechanisms
  • security incident monitoring
  • restricted contractor access to data

The user is responsible for ensuring the security of their credentials, devices and access tools.

12. Automated processing and decisions

BRUV may use automated data processing, including scoring, filtering, recommendations, anti-fraud checks and other algorithms. Such decisions may be used to detect suspicious operations, prevent fraud, moderate content, personalize the experience, improve service quality and optimize the display of offers.

If the law requires additional notice or the ability to contest an automated decision, BRUV provides such opportunity in the established manner.

13. User rights

The user has the right to:

  • receive information about the processing of their data to the extent provided by law
  • request clarification, blocking or deletion of data on legal grounds
  • withdraw consent for data processing, if processing is based on consent
  • object to processing in cases provided by law
  • contact BRUV support on data processing matters
  • appeal BRUV's actions to a competent authority or court if they believe their rights have been violated

14. BRUV's rights

BRUV has the right to:

  • process data within the limits necessary for the operation of services
  • transfer data to partners and contractors if required to provide services
  • store logs, technical records and operation history
  • use anonymized data without a time limit unless prohibited by law
  • restrict access to the service in case of security violations, suspected fraud or other legal grounds

15. Validity of consent

If processing is based on consent, it remains valid until the purposes of processing are achieved or until withdrawn by the user, unless otherwise required by law. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. BRUV may continue processing without consent where permitted by law.

16. Deletion and anonymization of data

After the storage period expires, data is subject to deletion, anonymization or archiving. Anonymized data may be used by BRUV for analytical, statistical and product purposes. If a user requests data deletion, BRUV assesses the possibility of deletion considering mandatory retention periods and other legal grounds.

17. Incidents and leaks

In the event of a security incident, BRUV takes measures to localize, investigate and remediate. If the law requires notice to the user or competent authority, BRUV fulfills such obligations in the prescribed manner. The user must immediately notify BRUV of suspicious access to their account or any other incident.

18. Changes to the Policy

BRUV may unilaterally amend this Policy. A new version takes effect upon publication on the website and/or app, unless another date is specified. Continued use of the services after the changes take effect constitutes the user's consent to the new version.

19. Data-related contacts

For data processing matters, the user may contact us at:

20. Operator details

BRUV LLC

Full name: Limited Liability Company «BRUV»

Legal address: Apt. 79, 17 Meridiannaya Street, Kazan, Republic of Tatarstan, 420124

INN: 1685025534

KPP: 168501001

BIC: 044525411

Bank: «Centralny» Branch of VTB Bank (PJSC)

Correspondent account: 30101810145250000411

Current account: 40702810300810142634