Sole proprietor Elena Leonidovna Saltykova (Individual Entrepreneur, Russian registration number OGRNIP 323350000008567, taxpayer number INN 352813858590), address: 28 Kosmonavta Belyaeva St., Cherepovets, 162616, Russia (the "Platform," "we," "us") is the operator of personal data (data controller) for the CyberPass mobile application (the "App") for iOS and Android.
This Privacy Policy (the "Policy") describes what data we collect through the App, how we use it, who we share it with, and what rights you have. This Policy is provided for information purposes and
does not constitute consent to the processing of personal data.
Consent to the processing of personal data is given separately, at sign-up in the App, by ticking a checkbox in the registration form. The text of the consent is available at
https://cyberpass.tech/en/consent.
1. Data we collectCategory | Examples | Source |
Account data | Name, phone number, email, date of birth | Provided by the user at sign-up |
Authentication data | Phone number | one-time-code (OTP) authentication providers (Zvonok.com, sigmasms.ru) |
User identifier | Unique UUID used to generate your in-app QR code | Generated and stored on our server |
Balance history | Credits and debits of minutes/hours on your digital subscription | Generated as you use the App |
Booking data | Name, phone number, date/time and status of a session booking | Shared with our booking provider BookNow.ru — see Section 3 |
Push notifications | Device token, time-credit notices, personalized notifications | Firebase Cloud Messaging (Android) / Apple Push Notification service (iOS) |
Technical data | Device token, notification content — to the extent needed for push notifications | Collected automatically while the App runs |
Event request data | Name, phone number, email, content of a request for an event or other individual service | Provided by the user when submitting a request |
We do not collect or store payment card data. The App currently does not process subscription payments directly; if in-app payment is introduced in the future, this Policy will be updated accordingly.
Analytics. As of the effective date, the App does not use third-party usage-analytics services. We may in the future integrate analytics tools (such as Yandex Metrica, AppMetrica, Firebase Analytics, or similar) and crash-diagnostic tools (such as Crashlytics or Sentry). If we do, this Policy will be updated, and the current list of tools will be reflected in the App Store's App Privacy disclosure and Google Play's Data safety section.
2. Purposes of processing
- creating, maintaining and identifying your user account;
- authenticating you in the App via phone number;
- providing access to the Service, including crediting and debiting minutes/hours on your digital subscription and generating and displaying your QR code;
- booking gaming sessions with the Service Provider and giving the Service Provider access to the information required to render the service;
- collecting feedback on the quality of the service through the App interface;
- processing your requests for events and other individual services offered by Service Providers — subject to separate consent given at the time the request is submitted;
- sending push notifications about your balance and other service information;
- sending promotional and informational messages about products, offers and special deals of the Platform and of Service Providers — subject to your separate consent;
- handling support requests;
- performing the agreement concluded on the terms of the Public Offer (https://cyberpass.tech/en/user-agreement);
- complying with applicable Russian law.The legal bases for processing are: the data subject's consent (Clause 1, Part 1, Article 6 of Federal Law No. 152-FZ of 27 July 2006 "On Personal Data"), performance of a contract to which the data subject is a party (Clause 5, Part 1, Article 6), and compliance with obligations imposed on the operator by Russian law (Clause 2, Part 1, Article 6).
The legal bases for processing are: the data subject's consent (Clause 1, Part 1, Article 6 of Federal Law No. 152-FZ of 27 July 2006 "On Personal Data"), performance of a contract to which the data subject is a party (Clause 5, Part 1, Article 6), and compliance with obligations imposed on the operator by Russian law (Clause 2, Part 1, Article 6).
3. Who we share data withWe share certain data with third-party services required to operate the App. These providers act as data processors and are contractually limited to using the data only to provide their service to us:
- Zvonok LLC (Zvonok.com) and Media Technology LLC (sigmasms.ru) — one-time-code (OTP) authentication providers; receive only the user's phone number.
- BookNow.ru — booking provider; receives name, phone number, and the date/time/status of the booking. Their privacy policy: booknow.ru/business/page/privacy-policy.html
- Mnogo Prilozheniy LLC (OGRN 1237700094752, 34 Leningradsky Prospekt, unit 36/1P, Moscow, 125040, Russia) — operator of the RuStore push notification service, the primary delivery channel for Android devices. Receives the device token and technical device information. Its servers are located in the Russian Federation. Delivery is carried out through push distributor apps of the VK ecosystem installed on the device (RuStore, Mail, Dzen, Odnoklassniki). Their privacy policy: rustore.ru/help/legal/privacy-policy-users
- Google LLC (Firebase Cloud Messaging) — fallback delivery channel for push notifications on Android when the RuStore service is unavailable.
- Apple Inc. (Apple Push Notification service) — delivery of push notifications on iOS.
Service Providers — the Platform's partner venuesData is made available to Service Providers exclusively through the Platform's software and only to the extent required to render the service: name, QR code, credits and debits of minutes (hours), booking date and time, phone number and email address. Access is limited to authorised staff of the Service Provider and only in respect of that provider's own customers.
Service Providers process this data
on the Platform's instructions under Part 3 of Article 6 of Federal Law No. 152-FZ of 27 July 2006, on the basis of an agreement with the Platform that obliges them to maintain confidentiality and comply with Article 19 of that law. The Platform remains responsible to the user for the Service Providers' actions in this respect.
A Service Provider may not use your contact details to send promotional messages on its own behalf, pass them to third parties, export or copy them outside the Platform's software, or use them for any purpose unrelated to rendering the service.
A Service Provider may process contact details for its own purposes only where you submit a request for an event or another individual service — and only on the basis of a separate consent given at the time the request is submitted, naming the specific Service Provider. In respect of data received through such a request, the Service Provider acts as an independent operator of personal data.
Cross-border data transferThe transfer of technical device identifiers to Google LLC (Firebase Cloud Messaging, the fallback delivery channel on Android) and Apple Inc. (Apple Push Notification service, delivery on iOS), both incorporated in the United States of America, constitutes a cross-border transfer of personal data. The transfer is limited to what is necessary to deliver push notifications: device token, device type, operating system version, app install identifier, and the content of the push notification. Notification of the intention to carry out cross-border transfer of personal data has been submitted to Roskomnadzor under Article 12 of Federal Law No. 152-FZ of 27 July 2006.
We do not sell personal data to third parties and do not share it for purposes unrelated to providing the Service.
4. Where data is storedDatabases containing personal data of citizens of the Russian Federation are hosted on servers located in the Russian Federation, in accordance with Part 5 of Article 18 of Federal Law No. 152-FZ of 27 July 2006.
Certain technical device identifiers are transferred outside the Russian Federation solely for the delivery of push notifications — see Section 3.
5. Retention periodWe retain personal data for as long as your account is active. After account deletion, data is erased within no more than seven (7) calendar days, except where longer retention is required by Russian law (for example, for tax or accounting purposes).
6. Your rightsYou may:
- delete your account yourself in the App's settings;
- request access to, correction of, or deletion of your personal data;
- obtain information concerning the processing of your personal data to the extent provided for in Part 7 of Article 14 of Federal Law No. 152-FZ of 27 July 2006 by writing to support@cyberpass.tech; we will respond within 10 business days;
- withdraw your consent to data processing and to receiving marketing communications;
- file a complaint with Roskomnadzor (for users in Russia) or with your local data protection authority (for users outside Russia).
To exercise these rights, or with any questions about how we process your data, contact us using the details in the "Contact" section.
7. Users outside RussiaThe App is available for download worldwide. If you are located outside Russia, including in the European Union, your data may also be processed in accordance with the General Data Protection Regulation (GDPR) in addition to Russian law. The legal basis for processing is performance of a contract (provision of the Service) and consent. We apply reasonable organizational and technical measures to protect data regardless of your location.
8. Age restrictionThe App is intended for users aged 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.
9. Data securityWe use reasonable technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including access control within our information system, encryption of data in transit (TLS) and regular backups. However, no method of transmission over the internet or electronic storage is 100% secure.
10. Changes to this PolicyWe may update this Policy from time to time, in particular when we integrate new analytics services, payment solutions, or other data-processing tools. The current version of this Policy is always available at
https://cyberpass.tech/en/app-privacy; the effective date and the date of the most recent revision are shown at the top of this document. We recommend that you review the Policy periodically. We will notify users of material changes via push notification, email, or another reasonably available method.
11. ContactElena Leonidovna Saltykova, Sole Proprietor (IE) Registration No. (OGRNIP): 323350000008567 Taxpayer No. (INN): 352813858590 Address: 28 Kosmonavta Belyaeva St., Cherepovets, 162616, Russia Email:
support@cyberpass.techPerson responsible for organising the processing of personal data: Elena Leonidovna Saltykova,
support@cyberpass.tech