Quevell Privacy Policy

Effective: September 2, 2026
Version: 1.0

This is a reference translation. The Russian version at quevell.com/ru/privacy/ is the legally binding text; if the two diverge, the Russian version prevails.

1. Who we are

1.1. This policy describes how personal data is handled in the Quevell service and on quevell.com, in accordance with applicable Russian data protection law.

1.2. The data operator is Quevell LLC (OOO "KYUVELL"), a company incorporated in the Russian Federation, OGRN 1265900011244, INN 5904419073, address: 6 Revolyutsii st., Perm, Perm Krai, Russia, 614007 ("we").

1.3. The policy applies to all personal data we receive through quevell.com, its subdomains and the Quevell service ("the Service").

1.4. By using the Service or the site you agree to this policy. If you do not agree, do not use the Service.

2. Our two roles

2.1. Data of the Service's users and the site's visitors (registration and account data) we process as the data operator: we decide the purposes and the scope. Sections 3-11 apply to this data.

2.2. Data that a customer organisation puts into the Service about its employees and other people we process on that customer's instructions. The customer is the operator of that data; we process it only as needed to run the Service, under the terms of our agreement with the customer. Requests from the people concerned we forward to the customer.

3. What data we process

3.1. Account data: email address, first and last name (if provided), interface language, timezone, role in the customer's organisation.

3.2. Organisation data: the customer's organisation name and the details provided at registration and in settings.

3.3. Technical data: IP address, browser and device information, logs of actions in the Service, session identifiers.

3.4. Correspondence: the content of messages to our support and your address.

3.5. We do not process special categories of personal data (health, beliefs and similar) or biometric data, and we do not ask for them. Do not put such data into the Service's fields.

3.6. We do not track site visitors with counters or advertising trackers and use no third-party analytics.

4. Why we process data

4.1. To conclude and perform the agreement on access to the Service: creating and maintaining accounts, providing the Service's functions, invoicing.

4.2. To send messages the Service needs to work: address confirmation, access recovery, notifications about events in the Service, notices of changed terms.

4.3. To keep the Service secure: logging, preventing unauthorised access, investigating incidents.

4.4. To comply with legal obligations: accounting, responses to lawful requests of public authorities.

4.5. We do not use personal data for third-party advertising, do not sell it, and make no decisions with legal consequences based solely on automated processing.

5. How we process it

5.1. Processing includes collection, recording, organisation, accumulation, storage, updating, retrieval, use, transfer (provision, access), blocking, erasure and destruction.

5.2. Processing is automated.

6. Where the data lives

6.1. Databases with personal data are located in the Russian Federation, on servers rented from Russian providers.

6.2. We do not transfer personal data across borders.

7. Who else sees the data

7.1. We involve a narrow circle of parties acting on our instructions, to the extent the Service needs:

  • an infrastructure provider (servers and storage in the Russian Federation);
  • an email delivery service (sending transactional messages).

7.2. Personal data may be provided to public authorities on the grounds and in the order established by law.

7.3. We do not share data with anyone else.

8. Cookies

8.1. The site and the Service use only strictly necessary cookies: the session identifier and interface settings (language). Signing in is impossible without them.

8.2. There are no advertising or analytics cookies.

9. How long we keep data

9.1. Account data is processed while the account exists and is deleted or anonymised, within the periods set by the agreement with the customer, after the agreement ends.

9.2. Logs and technical data are kept as long as security purposes require, then deleted or anonymised.

9.3. Data we are legally required to keep (accounting documents, for example) is kept for the legally established periods.

10. Your rights

10.1. You have the right to:

  • learn what personal data of yours we process;
  • have inaccurate data corrected, blocked or destroyed;
  • withdraw consent, where processing is based on consent;
  • complain to the Russian data protection authority (Roskomnadzor) or to a court.

10.2. To exercise these rights, write to the address in section 13. We reply within the periods established by law.

10.3. If your data was put into the Service by the organisation you work for, that organisation is the operator of the data: address your request to it. If the request reaches us, we will pass it on.

11. How we protect data

11.1. We apply legal, organisational and technical measures, including: encryption in transit and encryption of sensitive data at rest, access control at the database level, action logging, regular backups, regular security testing.

12. Changes to this policy

12.1. We may change this policy. A new version is published at quevell.com/en/privacy/ with its effective date. For material changes we notify registered users by email.

13. Contact

Quevell LLC (OOO "KYUVELL")
OGRN 1265900011244, INN 5904419073
6 Revolyutsii st., Perm, Perm Krai, Russia, 614007
Email for personal data matters: privacy@quevell.com