General#
This personal data processing policy (the Policy) is published under part 2 of article 18.1 of Russian Federal Law No. 152-FZ of 27 July 2006 “On personal data” (152-FZ). It sets out how personal data is processed and which protection requirements are in place.
Operator: Akeda LLC — Limited Liability Company «AKEDA» (Акеда, ООО), TIN (ИНН) 5003175505, KPP 500301001, PSRN (ОГРН) 1265000059213. Registered address: 142721, Moscow Region, Vidnoye, Prigorod Lesnoye (Misaylovo), Sovremennikov St. 2, unit 25N, Russia. Chief Executive Officer — Evgenia Sergeevna Oganesyan. Email: hello@akeda.ru.
The Policy covers the erp.akeda.ru website with its subdomains, the Akeda mobile applications, and the Akeda ERP service — a cloud business management system provided by subscription.
Akeda acts in two different roles, and the difference matters. For the data of site visitors and of the people who register a workspace, work in it and pay for the subscription, Akeda is the operator: it defines the purposes and the scope of processing. For the data a client uploads into their own workspace — records about their employees, counterparties and documents — the client remains the operator, and Akeda processes that data on the client's instruction, only to keep the workspace running. A separate section below is devoted to this.
The data subject's consent is given in a separate document — the Consent to the processing of personal data. This Policy describes the processing in full; the Consent records what the subject agrees to.
The Russian version of this document prevails; the English text is provided for convenience.
What data is processed#
Everything Akeda processes is listed by name below. Data not named in this section is not collected.
A site visitor who submitted a request:
- name;
- phone number;
- email address;
- company name;
- the text of the message.
A user of the service — a member of a workspace:
- email address;
- first and last name;
- phone number, if given;
- job title, if given;
- interface language and time zone;
- the workspace, the legal entities access has been opened to, and the role in the workspace;
- sign-in records: date and time, IP address, browser and device details;
- an activity log: date and time, the section and the operation performed;
- the stored password in an irreversibly transformed form — the password itself is never kept in the clear.
A subscription payer:
- the name of the legal entity or sole trader;
- TIN, KPP, PSRN or PSRNSP and the payer's address;
- the full name of the signatory or contact person, if the client gives one;
- the contents, amounts, dates and status of the invoices issued;
- records of payments made and refunds;
- the email address invoices and fiscal receipts are sent to.
Payment details. Akeda neither receives nor stores the card number, its expiry date or the verification code. Those are entered on the payment service's own page. From it Akeda receives only what is needed to recognise the card and pay for the next period:
- the masked card number — the first and last digits;
- the expiry date;
- the card scheme and issuing bank;
- the identifier of the saved payment method held by the payment service.
Technical details of a site visit and of work in the service:
- IP address;
- browser and device details: User-Agent, screen resolution, language;
- cookies and the anonymous visitor identifier assigned by the web analytics service;
- the addresses of pages viewed, the referrer and campaign tags;
- on-page actions: clicks, scrolling, form filling and the session recording made by Webvisor;
- the date and time of the request;
- a device identifier for delivering notifications — for those who installed the mobile app or allowed notifications in the browser.
A conversation with the voice assistant on the site — only if the visitor started it:
- the sound picked up by the microphone for as long as the visitor holds the talk button down;
- the transcript of what was said and the text of the assistant's replies;
- a phone number, if the visitor leaves one in the assistant's panel.
The microphone switches on only when the button is pressed and off when it is released; the browser asks for permission, and it can be refused — the site works either way.
Akeda does not process special categories of personal data or biometric personal data. The sound of speech in a conversation with the assistant is processed only in order to understand what was said and is not used to establish the speaker's identity. No data about minors is collected: the service is intended for organisations and sole traders.
Purposes of processing and legal grounds#
Data is processed only for the purposes named below and is not used for anything else.
- Answering a request from the site — to get in touch with the person who left it and discuss what they need. Ground: the subject's consent (article 6 part 1 clause 1 of 152-FZ).
- Workspace registration, access to the service and support — to grant access, identify the user, restore their access and answer their questions. Ground: performance of the contract to which the subject is a party (article 6 part 1 clause 5 of 152-FZ).
- Subscription, invoices and payments — to issue an invoice, take payment, make a refund and send a fiscal receipt. Grounds: performance of the contract and compliance with duties imposed by law (article 6 part 1 clauses 2 and 5 of 152-FZ), including Federal Law No. 54-FZ of 22 May 2003 and accounting law.
- Service notifications — payment due dates, changes to the terms, maintenance windows, security incidents. Ground: performance of the contract.
- Answers from the voice assistant on the site and the assistant in the workspace — to answer a question about the system. Ground: the subject's consent, given by starting the conversation.
- Security and incident investigation — to detect unauthorised access and abuse. Grounds: the operator's legitimate interests and the requirements of article 18.1 part 1 and article 19 of 152-FZ.
- Anonymous site traffic statistics — to understand which pages are useful. Ground: the subject's consent expressed through browser settings.
Marketing and information mailings are sent only to those who gave separate consent to them; they can be stopped from any letter or by writing to hello@akeda.ru.
Actions performed on data and methods of processing#
The following actions are performed on personal data: collection, recording, systematisation, accumulation, storage, clarification (updating, modification), extraction, use, transfer (provision, access), depersonalisation, blocking, deletion and destruction. Personal data is never disseminated, that is, disclosed to an indefinite group of persons.
Processing is carried out in the following ways:
- automated — by means of computing equipment; this is the main way, because the service is a program;
- without automation — when a request that arrived by email is dealt with, and when the operator keeps its own paperwork;
- mixed, with transfer over the Internet — over a secure channel and only to the recipients named below.
No decision producing legal consequences for the data subject is taken solely on the basis of automated processing. No profiling is carried out. The assistant's answers are not legally significant decisions.
Who receives what, exactly#
Akeda does not sell personal data and does not pass it to third parties for their own purposes. Data is shared only to the extent needed to run the service. Every recipient and exactly what goes to each of them is named below.
- Beget, Russia — object storage for files (a bucket in the ru1 region) and storage for backups. What is shared: the files members upload into a workspace, attachments of letters and documents, the cache of printed forms, and database backups — encrypted before they are sent. The storage operator does not open the content and has no purposes of its own for it.
- The data centre operator hosting the service's servers — for hosting and storage only. It has no purposes of its own for the data and no access to the contents of the databases.
- REG.RU, Russia — delivery of system email through the mail node mail.hosting.reg.ru. What is shared: the recipient's email address and name, the workspace name, and the subject and body of the letter — a sign-in or recovery link, or the number, amount and due date of an invoice.
- Tochka, Russia — acceptance of card and Faster Payments System payments, refunds, and the fiscal receipt required by Federal Law No. 54-FZ of 22 May 2003. What is shared: the invoice number and date, the amount and currency, the payment purpose, the address the payer returns to in the workspace, and the email address the receipt is sent to. The card number, its expiry date and the verification code are entered on the bank's own page; Akeda neither receives nor passes them on.
- Yandex LLC (TIN 7736207543, 16 Lva Tolstogo St., Moscow, 119021), Russia — the Yandex.Metrica service, counter No. 112347336 — counting site visits and judging which pages are useful. What is shared: IP address, browser and device details (User-Agent), the anonymous visitor identifier, the addresses of pages viewed, the referrer and campaign tags, clicks, scrolling, form filling and the session recording made by Webvisor. The visitor's name, phone number and email address are not passed to the counter. Processing terms: yandex.ru/legal/metrica_termsofuse.
- Telegram — notifying an Akeda manager about a request left on the site so that it can be answered the same day. What is shared: the name, phone number, message text and the page the request was sent from. Nothing else is shared.
- Yandex Cloud, Russia — speech recognition and synthesis during a conversation with the voice assistant on the site. What is shared: the sound of the visitor's speech for as long as they hold the talk button down, and the text of the assistant's replies to be voiced. The visitor's name, phone number and email address are not shared.
- The provider of the language model that answers in the assistant — preparing an answer to a question put to the voice assistant on the site or to the assistant inside a workspace. What is shared: the text of the question and of the previous turns of the same conversation and, for the assistant inside a workspace, the workspace records needed to answer that particular question. Sign-in credentials and payment details are not shared. The provider's servers are located outside the Russian Federation.
- The provider of the assistant's video likeness — showing the assistant's speaking face on the site. What is shared: the sound of the assistant's already synthesised speech, so that the image moves its lips in time with it. The visitor's speech, their questions and any information about them are not shared.
- DaData, Russia — filling in the details of a company or sole trader while a counterparty record is being created. What is shared: the string the member typed into the search field — a TIN, a PSRN or a name. No other workspace data is shared.
- Apple Inc., USA — delivering a notification to the Akeda mobile app on iPhone, iPad and Mac. What is shared: the device identifier and the notification's title and text — for example, the sender's name and the beginning of a message. Showing the text inside a notification can be turned off in the app's settings, and notifications themselves in the device's settings.
- Browser notification delivery services (Google, Mozilla or Apple, depending on the browser) — delivering a notification to the desktop. What is shared: the device's subscription address and an encrypted message whose content the delivery service cannot read. The user turns these notifications on themselves and can turn them off at any time.
- Google LLC, USA — loading the typefaces the workspace interface is set in (Google Fonts). What is shared: the IP address and browser details of whoever opened the application. Workspace data, credentials and payment details are not shared.
- Government authorities — in the cases, to the extent and in the manner expressly required by law.
Transfer outside the Russian Federation. Workspace databases, member files and records of invoices and payments are processed and stored in Russia and never cross the border. Only the flows named above leave the Russian Federation, and each of them is narrow and can be switched off: the turns of a conversation with the assistant go to the language model provider; a notification's title and text go to the push delivery service; an IP address and browser details go to the provider of the interface typefaces. Akeda carries out no other cross-border transfer of personal data.
Storage, retention and protection#
Recording, systematisation, accumulation, storage, updating and retrieval of the personal data of Russian citizens are performed using databases located in the Russian Federation (article 18 part 5 of 152-FZ). Every workspace has its own database. Files uploaded by members are kept in object storage located in the Russian Federation.
Retention periods. A service user's data is kept while the workspace subscription is in force and while the person remains a member of it. The data of a disabled workspace is kept for 180 days from the day the workspace stopped working and is then destroyed irreversibly; this period may be changed by agreement with the client. A request from the site is kept for one year from the date it was submitted. Records of invoices, payments and fiscal receipts are kept for the periods set by accounting and tax law — at least five years. Data processed on the basis of consent is kept until the consent is withdrawn, unless the law sets another period.
A conversation with the voice assistant on the site is not stored: it lives in the server's memory only for the length of the conversation and disappears with it; the sound of speech is not recorded after it has been recognised.
Once the purpose of processing is achieved, or the need to achieve it is lost, the data is destroyed or anonymised within thirty days, unless the law provides otherwise.
Protection measures. The operator has taken the measures required by articles 18.1 and 19 of 152-FZ: a person responsible for organising personal data processing has been appointed; internal documents defining the order of processing and destruction have been issued; the employees with access have been identified and briefed on statutory requirements; role-based access control, encrypted transport, encrypted backups, access logging, regular backups and compliance checks are in place.
Data inside a client's workspace#
A client uploads records about their employees, counterparties, deals and documents into their workspace. For that data the client is the operator: the client defines the purposes and the scope of processing, obtains the necessary consents and answers to the subjects of that data.
Akeda processes such data solely on the client's instruction and only in order to provide the service (article 6 part 3 of 152-FZ). Akeda does not define the purposes of this processing, does not disclose the contents of the workspace to third parties — other than the parties engaged to run the service itself, each of them named in the section on sharing — and does not use it for its own benefit. Akeda staff may access workspace contents only to fix a fault or at the client's request; such access is logged and limited to what is necessary.
Connections the client sets up themselves. A client may connect external services to their workspace: a bank for statements and payment orders, an electronic document exchange operator, a marketplace, a calendar, a mailbox and a messenger channel for talking to buyers. The client creates such a connection: they choose the service, enter its credentials and decide the scope of the exchange. Akeda sends data on that instruction and only to the service the client connected; what is sent follows the scenario of the connection — a bank, for example, receives a statement request and the details of a payment order, and a document exchange operator receives the document itself with its details and signatures. The relationship with such a service is the client's own, and the connection can be removed at any time in the workspace settings.
If a data subject contacts Akeda about records held inside a client's workspace, the request is passed to the client as the operator and the subject is told so.
Cookies and statistics#
The site uses cookies. Technical cookies are required for the pages to work: they keep the sign-in session and remember, for example, the chosen language and colour theme. Without them the site will not work. Statistical cookies are used by the web analytics service to count visits anonymously.
Statistics are collected by Yandex.Metrica — a service of Yandex LLC (TIN 7736207543, 16 Lva Tolstogo St., Moscow, 119021, Russia), counter No. 112347336. The counter receives the IP address, browser and device details, the anonymous visitor identifier, the addresses of pages viewed, the referrer and on-page actions — clicks, scrolling, form filling and the session recording made by Webvisor. The visitor's name, phone number and email address are not passed to the counter. Yandex.Metrica's processing terms: yandex.ru/legal/metrica_termsofuse.
Statistical cookies can be refused in the browser settings — by blocking them or deleting the ones already stored — and by installing the “Yandex.Metrica blocker” extension. Refusing technical cookies may leave parts of the site unusable.
Retention: session cookies are deleted when the browser closes; persistent cookies are kept for no more than one year from the last update.
Rights of the data subject#
Under article 14 of 152-FZ a data subject has the right to:
- obtain information about the processing of their data: confirmation that processing takes place, its legal grounds and purposes, the data being processed, its source, the periods of processing and storage, the persons the data is shared with, and the methods of processing used;
- require their data to be corrected if it is incomplete, out of date or inaccurate;
- require blocking or destruction of the data if it was obtained unlawfully or is not necessary for the stated purpose;
- withdraw consent to processing at any time — the procedure is set out in the next section;
- object to processing and require that marketing messages stop;
- appeal against the operator's acts or omissions to the authority responsible for protecting the rights of data subjects — the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor), 7 bldg 2, Kitaygorodsky Proyezd, Moscow, 109074, Russia — or to a court.
A request is sent to hello@akeda.ru or by post to the operator's registered address. It should state the person's full name, information confirming their relationship with the operator (for example, the email address used to sign in, or an invoice number) and what exactly is being asked for. An answer is sent within ten business days of receipt; that period may be extended by no more than five business days, with notice of the reasons. Exercising these rights is free of charge.
How to withdraw consent#
Consent to the processing of personal data may be withdrawn at any time, without giving reasons and free of charge (part 2 of article 9 of 152-FZ). Consent can be withdrawn in either of two ways:
- send a free-form application to hello@akeda.ru with the subject «Withdrawal of consent to the processing of personal data», from the address held in the account, or by post to the operator's registered address;
- delete the account yourself: in the workspace, under Settings → Members, or by asking the workspace administrator to do it.
Timing. Receipt of a withdrawal application is confirmed within 10 business days. Processing stops and the data is destroyed or depersonalised within 30 days of the application being received.
Withdrawal does not affect the lawfulness of processing carried out before it was received. Processing continues only where the operator retains another lawful ground: performance of the contract for as long as the subscription runs, and compliance with a duty imposed by law — records of invoices, payments and fiscal receipts are kept for at least five years regardless of withdrawal.
Withdrawal by a user of the service ends that person's access to the workspace. The contents of the workspace itself are not deleted: the client is its operator and it is the client who disposes of them.
Security incidents#
If the operator discovers an incident in which personal data may have been unlawfully transferred, disclosed or destroyed, it will:
- notify Roskomnadzor within 24 hours of discovery — of what happened, its presumed cause and the presumed harm — and report the findings of its internal investigation within 72 hours (part 3.1 of article 21 of 152-FZ);
- notify the affected data subjects by email: what happened, which data is affected and what has been done;
- carry out an internal investigation, remove the cause, and record the incident in a register with its date, the data involved, the measures taken and the outcome.
Changes to the Policy#
The operator may amend the Policy. A new revision is published on this page and takes effect on the day of publication; the revision number and date are shown in the document heading. Earlier revisions are available on request at hello@akeda.ru.
If the changes affect the purposes of processing or the recipients of data, users of the service are additionally notified by email.
Contacts#
Akeda LLC (Limited Liability Company «AKEDA»)
TIN (ИНН) 5003175505, KPP 500301001
PSRN (ОГРН) 1265000059213
Registered address: 142721, Moscow Region, Vidnoye, Prigorod Lesnoye (Misaylovo), Sovremennikov St. 2, unit 25N, Russia
Chief Executive Officer — Evgenia Sergeevna Oganesyan
Questions about the processing of personal data, requests from data subjects and withdrawal of consent — hello@akeda.ru. The person responsible for organising personal data processing answers at the same address.