Legal information

Privacy Policy

How Tellem CRM processes information and personal data.

Current version

01

Preamble

This Privacy Policy explains how MIRRO LLC (the "Company") processes information when users access Tellem websites, applications, CRM tools, Telegram Web Apps, and related services (the "Services"). This English text is provided for convenience. If it differs from the Russian version, the Russian version prevails.

02

General provisions

1.1. This Policy governs the processing of information relating to users of the Services, including personal data, account information, technical data, and information supplied through the Services.

1.2. By using a Service, the User confirms that they have read this Policy. Where consent is required by law, the Company requests it separately through the relevant interface or document.

1.3. The Company processes information in accordance with the laws of the Russian Federation and other applicable requirements.

1.4. Separate Services may have additional privacy notices. If a specific notice conflicts with this Policy, the specific notice applies to that Service.

1.5. The Company may process information directly or through authorized processors that provide hosting, communications, analytics, support, security, or other operational services.

03

Information we process

2.1. Depending on the Service, the Company may process: information provided during registration or use; contact details; account and organization details; customer and order data uploaded by an authorized business user; communications and support requests; information generated by actions in the Service; cookies and similar technologies; device, browser, IP address, log, and diagnostic data; and aggregated analytics.

2.2. The specific categories of information depend on the functionality used. If a Service has a separate notice, that notice contains the more detailed list.

2.3. The Company does not intentionally request biometric data or special categories of personal data unless a specific feature and lawful basis expressly require them.

2.4. Where a Service allows information to be displayed to other users, the User controls publication through the available settings and understands that published information may become accessible to an indefinite number of Internet users.

2.5. The Company generally relies on the accuracy of information supplied by Users. Users should keep their information current and correct.

2.6. Cookies and similar technologies may be used to authenticate sessions, maintain settings, analyze use, detect errors, improve performance, prevent abuse, and personalize functionality.

2.7. Mobile applications may process additional technical information described in the applicable application notice and platform permissions.

2.8. Location information may be processed when enabled by the User or required by a requested feature, for service delivery, personalization, and analytics.

04

Processing conditions and purposes

3.1. The Company processes information lawfully, fairly, transparently, and only to the extent necessary for specified purposes. Incompatible databases and purposes are not combined without an appropriate legal basis.

3.2. Processing purposes include providing and administering the Services; creating and maintaining accounts; performing agreements; processing payments; importing and analyzing customer data; building RFM segments and recommendations; sending communications initiated by authorized business users; providing support; securing the Services; preventing fraud and abuse; complying with law; improving products; and producing anonymized analytics.

3.3. Information may be collected when the User registers, edits an account, uploads data, submits a form, connects an integration, sends a request, or uses the Services.

3.4. Information is not disclosed to third parties except where necessary to provide the Services, where the User has authorized disclosure, where a processor acts under the Company's instructions, in connection with a lawful corporate transaction, or where disclosure is required by a competent authority or applicable law.

3.5. Authorized recipients may include hosting and infrastructure providers, communication and email providers, analytics and security providers, professional advisers, contractors supporting the Services, and public authorities with a lawful request.

3.6. The Company may create anonymized or aggregated information to evaluate demand, improve functionality, measure campaigns, and conduct statistical analysis. Such information is not intended to identify an individual.

3.7. Information is retained only for as long as required for the purposes described above, contractual obligations, security, dispute resolution, and mandatory legal retention periods. After that, it is deleted or anonymized.

05

User rights and obligations

Users may, subject to applicable law:

4.1. Request information about the processing of their personal data.

4.2. Access personal data available through the relevant Service.

4.3. Correct or update inaccurate or incomplete information.

4.4. Request restriction, blocking, deletion, or destruction of information where legal grounds exist.

4.5. Withdraw consent where processing is based on consent, without affecting the lawfulness of earlier processing.

4.6. Object to processing where the law provides that right.

4.7. Submit a complaint to the competent data protection authority or court.

4.8. Users must provide accurate information, protect account credentials, respect the rights of other persons, and avoid uploading data without a lawful basis.

06

Security measures

5.1. The Company applies organizational, legal, and technical safeguards designed to prevent unauthorized or accidental access, destruction, modification, blocking, copying, disclosure, or distribution of information.

5.2. Safeguards are selected with regard to applicable legal requirements, current technology, the nature of the information, and the likelihood and severity of risks.

5.3. Access by employees and contractors is limited to what they need for their duties and is subject to confidentiality and security requirements.

5.4. No Internet service can guarantee absolute security. Users should use strong credentials, restrict account access, and promptly report suspected incidents.

07

Limitation of liability

6.1. The Company is not responsible for disclosure caused by a User's publication settings, transfer of information to another person, failure to protect credentials, unlawful actions of third parties, or circumstances beyond the Company's reasonable control, except where liability is imposed by mandatory law.

6.2. Third-party websites, platforms, and integrations have their own privacy practices. The Company is not responsible for those practices unless it acts as the relevant controller or processor under applicable law.

08

Requests

7.1. A User or authorized representative may submit a request concerning personal data using the Company's published contact details.

7.2. The request should contain enough information to identify the applicant, describe the relevant Service and request, and confirm authority where a representative acts for another person.

7.3. The Company may request additional verification where reasonably necessary to protect information from unauthorized disclosure.

7.4. Consent may be withdrawn by a written request sent to the Company's registered address or another method permitted by law. Some processing may continue where another legal basis applies.

09

Changes to this policy

8.1. The Company may update this Policy. The new version is published on the website and takes effect on the stated date or, if no date is stated, on the day after publication unless the law requires otherwise.

8.2. If a User does not accept a change, the User should stop using the affected Services. Continued use after the effective date may constitute acceptance where permitted by law.

8.3. This Policy is governed by the laws of the Russian Federation. Matters not covered by it are governed by applicable law and the relevant user or license agreements.