Effective 2026-08-10

Personal data processing policy

Aligned with applicable privacy rules for Service users (including 152-FZ for RU operators).

Template policy. Fill in the controller’s legal entity, retention periods and cross-border details after infrastructure is finalized.

1. Controller

Service Operator: Snikevent, [Operator legal name: LLC / sole trader, registration ID, tax ID], address: [Operator registered address], email: info@snikevent.com, site: https://snikevent.com.

Privacy requests: email the Operator with subject “Personal data”.

2. Data we process

Account data: name, email, password (hashed / delegated via auth provider), role, organization.

Customer-entered data: clients, contacts, documents, projects, finance, warehouse, audit logs as needed for the product.

Technical data: IP, cookies / session IDs, security logs, device info — for operation, security and diagnostics.

Payment card data (when billing is live) is generally handled by the payment provider; the Operator typically does not store full card numbers.

3. Purposes

Provide and support the Service, authentication, perform the offer, billing (when enabled).

Security, abuse prevention, organization audit trails.

Service communications (alerts, invites, password recovery) — no advertising spam without required consent.

Legal compliance and lawful authority requests.

4. Legal bases

Performance of the contract (offer); consent where required (e.g. registration); Operator legitimate interests in securing the Service; legal obligations.

5. Processors and sharing

Infrastructure vendors (hosting, database, auth, email, payments, error tracking) may process data solely to run the Service under contracts / instructions.

Typical categories: cloud hosting (e.g. Vercel), DB / Auth (e.g. Supabase), payment and messaging APIs depending on configuration.

Where the Customer is controller of its clients’ data and Snikevent is processor, the DPA at /dpa applies.

6. International transfers

If vendors or infrastructure are outside the Customer’s country, transfers rely on lawful bases and safeguards required by applicable law. Exact regions are confirmed once infrastructure is fixed in the contract / settings.

7. Retention

Account data while the account is active and for a reasonable period after deletion (backups, claims, legal duties).

Audit and security logs as needed for investigations and compliance.

On Customer request the Operator assists with export and deletion except where retention is legally required.

8. Individual rights

Individuals may request access, correction, restriction or deletion, withdraw consent (where processing is based on consent), and complain to a supervisory authority.

Requests go to the Operator’s email. For Customer clients’ data, contact the Customer first; the Operator assists the Customer within a reasonable time.

9. Security

RBAC, tenant isolation, HTTPS, delegated/hashed passwords, audit of key actions, limited exposure of integration secrets.

The Customer must manage its users’ permissions and not share access with unauthorized persons.

10. Cookies

Necessary cookies / local storage support session, locale and security. Disabling them may prevent sign-in.

11. Changes

Updates are published at https://snikevent.com/privacy. Material changes may also be noticed in-product or by email where appropriate.